What are the core benefits of Kaspersky Hybrid Cloud Security Enterprise Desktop Base Plus?
Central management - All protected desktops are managed from Kaspersky Security Center.
VDI focus - Covers virtual desktops, persistent and non-persistent alike.
Light agents - Save up to 40 percent in private clouds.
Enterprise tier - Adds patch management, file integrity monitoring and SIEM export.
Ransomware rollback - Reverses malicious changes made inside protected workloads.
Important note - Servers need their own Server or CPU licence.
Virtual desktop protection - File, process and memory protection on every virtual desktop.
Kaspersky Security Center - One console for policies, tasks and protection status.
KSV Light Agent - A central virtual machine holds databases and returns verdicts.
Patch management - Enterprise tier assesses vulnerabilities and distributes patches automatically.
SIEM connectors - Enterprise tier forwards security events to your SIEM.
Important - This licence covers virtual desktops, not servers.
Kaspersky Hybrid Cloud Security Enterprise Desktop is the virtual desktop licensing object of Kaspersky's hybrid cloud workload product, managed centrally from Kaspersky Security Center or its cloud console rather than per device. The protection actually deployed under it is Kaspersky Security for Virtualization Light Agent, which is the name many administrators still search for.
Lower resource use - Light agents save up to 40 percent in private clouds.
Golden image ready - Non-persistent desktops are protected the moment they are created.
Hardening baseline - Application control on desktop operating systems limits what runs.
Ransomware rollback - The remediation engine reverses changes made during an attack.
Evidence for audits - File integrity monitoring and log inspection record system changes.
Swiss data processing - European threat data is processed in two Zurich datacentres.
The deciding factor is not headcount but whether you run a virtualisation or VDI platform. An organisation with physical workstations only has no use for this licensing object, while a company operating a few hundred virtual desktops gets the resource saving that justifies it.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Runs a virtualisation or VDI platform | ✕ | Sometimes | ✓ |
| This product fits | ✕ | Only with VDI | ✓ |
The revised Information Security Act obliges operators of critical infrastructure to report significant cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and that duty has applied since 1 April 2025. Whether it applies to you depends on your sector, not on your size, so most companies buying virtual desktop protection are not in scope at all. Where the product helps is in the material such a report is built from: in the Enterprise tier, log inspection and file integrity monitoring record what changed on a virtual desktop and when, and the SIEM connectors move those events somewhere they can be read after the fact. What it does not do is recognise that a report is due, produce the notification, or guide the response, and its record covers only the virtual desktops licensed under it, so servers, mailboxes and mobile devices leave no trace in it. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.
No product makes an organisation compliant with the NIS 2 Directive, because most of what the directive asks for is organisational rather than technical. NIS 2 requires risk-management measures across defined categories: risk analysis and security policies, incident handling, business continuity and backup, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, cyber hygiene and training, cryptography, access control, and multi-factor authentication. This licence contributes to vulnerability handling through the Enterprise tier's vulnerability assessment and patch management, to incident handling through log inspection, file integrity monitoring and event export to a SIEM, and to access control through role-based administration in Kaspersky Security Center. It contributes nothing to business continuity and backup, to cryptography, to multi-factor authentication or to staff training, and it says nothing about your suppliers beyond the workloads it protects. Treat it as one technical measure among several, not as a directive-level answer.
In Switzerland there is no restriction on the vendor. The National Cyber Security Centre, today the Federal Office for Cybersecurity, stated on 17 March 2022 that it does not issue recommendations on the use of individual products and that no misuse of Kaspersky antivirus software had been reported to it in Switzerland. In Germany the Federal Office for Information Security (BSI) issued a formal warning against the use of Kaspersky antivirus software on 15 March 2022; it remains in force and has been based on Section 13 of the BSI Act since 6 December 2025. In the United States, the Department of Commerce issued a final determination in June 2024 that stopped new sales from 20 July 2024 and barred signature and codebase updates and the operation of the Kaspersky Security Network for US persons from 29 September 2024. Kaspersky's position is that the German warning is unjustified and was not based on an objective technical analysis of its software, and the company points to its Global Transparency Initiative, under which threat data from European users is processed in two datacentres in Zurich and product assembly was relocated to Switzerland. Independent testing has continued in parallel: Kaspersky business products remained part of the AV-Comparatives Business Main-Test Series in the March to June 2026 round. In practice this matters most to German public bodies and their suppliers, to organisations with United States entities or contracts, and to anyone whose customers ask about vendor origin in supplier questionnaires; for a private Swiss or wider European buyer it is a procurement question rather than a legal one.
Yes, for the endpoint and hardening sections, and not at all for several others. It answers the questions on malware protection for all workstations, central policy enforcement, application allowlisting on desktop operating systems, vulnerability assessment and patch distribution, file integrity monitoring, log retention and forwarding to a SIEM, and role-based administrative access, all of which can be evidenced with reports out of Kaspersky Security Center. It does not answer the questions on backup and restore, disk encryption, multi-factor authentication, mobile device management, email gateway filtering, or continuous detection and response with an analyst behind it, and on a Desktop licence it says nothing about your servers. One further item is worth preparing for: questionnaires increasingly ask about the country of origin of security vendors, and this is the section where the assessments described above will come up. To close the technical gaps, staying inside the same family is usually the cheaper route than mixing vendors, since Kaspersky Next EDR Expert or Managed Detection and Response cover the detection and response items, Kaspersky Container Security covers container workloads, and a Server or CPU licence of the same product covers the server side under the same console.
The single decisive difference is that vulnerability assessment and patch management sit in the Enterprise tier only, which is what turns the product from protection into something an auditor can be shown. Enterprise adds the components that produce a record rather than a block: file integrity monitoring, log inspection and SIEM connectors. It also adds application control for server operating systems and network intrusion detection for VMware NSX, neither of which a Desktop licence will exercise on its own. Standard remains the right tier if you only need protection with central management and have no audit or SIEM requirement.
| Component | Standard | Enterprise |
|---|---|---|
| File, process and memory protection | ✓ | ✓ |
| Application control for desktop operating systems | ✓ | ✓ |
| Anti-Cryptor for shared folders | ✓ | ✓ |
| Vulnerability assessment and patch management | ✕ | ✓ |
| SIEM connectors | ✕ | ✓ |
| File integrity monitoring and log inspection | ✕ | ✓ |
| Application control for server operating systems | ✕ | ✓ |
| IDS/IPS for VMware NSX | ✕ | ✓ |
| Bundled maintenance agreement with Plus licences | By region | By region |
The licensing object is the decisive limitation: it counts the maximum number of virtual desktops that might exist, persistent and non-persistent together, and it does not cover servers, which need a Server or CPU licence of the same family. Regional availability matters for the Plus part of the name: Kaspersky states that the bundled maintenance service agreement is offered in different forms depending on the country and that terms have to be confirmed locally, and the vendor's products are not available to United States persons at all following the 2024 prohibition. The agentless deployment option has been retired, so technical support for Kaspersky Security for Virtualization Agentless ended on 31 July 2026, only database updates are issued between 1 August 2026 and 1 February 2027, and nothing at all afterwards; new licences ship the Light Agent, which requires an agent inside each guest. Finally, this is workload protection and not a detection and response platform: there is no EDR component, no backup, no encryption management and no mobile coverage, and those are the four purchases that most often follow.
Kaspersky states that Desktop and Server licences allow the activation of Kaspersky Endpoint Security for Business applications, which is what lets an organisation protect physical machines while it migrates them to VDI. The licensing object itself is still counted in virtual desktops, so plan the count around the target state rather than the current one.
Base identifies a new licence rather than a renewal or an add-on to an existing product, so nothing else has to be in place before it is used. The Plus part refers to Kaspersky's Plus licence types, which are supplied together with a premium maintenance service agreement; Kaspersky notes that the available forms of that agreement differ by country.
You can run Kaspersky Security Center on your own infrastructure or use the Kaspersky Security Center Cloud Console workspace instead; both administer the same licence and the same policies. The choice usually comes down to whether you want administration data held in your own environment.