What are the key advantages of Kaspersky Hybrid Cloud Security Server Base?
Central management – All agents managed from Kaspersky Security Center.
Server licensing – Covers physical and virtual servers alike.
Cloud inventory – Finds AWS, Azure and Google Cloud instances.
Ransomware blocking – Anti-Cryptor stops encryption of shared folders.
Light agent – Offloads scanning to one machine per host.
Important note – No EDR, patch management or SIEM connector.
Server workload protection – File, process and memory protection for physical and virtual servers.
Kaspersky Security Center – Central console manages policies, tasks and reports for every agent.
Public cloud API – Inventories AWS, Azure and Google Cloud instances automatically.
Anti-Cryptor shared folders – Blocks ransomware encrypting file shares from an infected client.
Light agent virtualisation – Offloads scanning to one security virtual machine per host.
Important – No EDR, patch management, file integrity monitoring or SIEM connector.
Kaspersky Hybrid Cloud Security Server Base is the Standard tier of Kaspersky's workload protection product, licensed per server and managed centrally from Kaspersky Security Center. The light-agent virtualisation protection formerly sold as Kaspersky Security for Virtualization is part of this licence, which is why buyers searching for that older name arrive here.
Licensing object – One server licence covers physical and virtual server workloads.
Auto-scaling policies – Auto-scaling policies protect newly created machines without manual steps.
Lower host load – Shared scan cache reduces duplicate scanning across guests.
Endpoint activation included – Server licences also activate Kaspersky Endpoint Security for Business.
Single reporting point – One console produces incident reports across cloud and datacentre.
Upgrade path – Standard licences can be upgraded to the Enterprise tier.
The deciding factor is not headcount but server count and how mixed the estate is. A company running three physical servers gains little from a central console; a company running forty virtual machines across a hypervisor and a public cloud account gains a lot. Large organisations usually need the Enterprise tier instead, because auditors and SOC teams ask for file integrity monitoring and log forwarding that the Standard tier does not have.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Increasing | ✓ | ✓ |
| Mixed physical and virtual servers | Rarely | ✓ | ✓ |
| This product fits | Rarely | ✓ | Enterprise tier better |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company: since 1 April 2025 the revised Information Security Act (ISG) requires them to report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. This product supports that deadline in one specific way: the console holds detections from every protected server, so whoever files the report can state when the attack was detected and which systems were affected without walking machine to machine. What it does not deliver at the Standard tier is evidence of change: there is no file integrity monitoring and no log inspection, so proof that a configuration file or binary was altered on a server has to come from elsewhere. There is also no SIEM connector at this tier, so detections cannot be forwarded automatically into a central log platform for the 14-day follow-up. The organisational half is entirely outside the product: who reports, through which escalation path, and who signs off is something the company defines. This text is not legal advice; whether your organisation falls under the reporting obligation should be confirmed with your own legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses the organisation and its management, not the software it buys. NIS 2 requires entities in scope to have measures across defined categories: risk analysis and information system security policies, incident handling, business continuity and backup management, supply chain security, security in acquisition and development, vulnerability handling and disclosure, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This product contributes to two of them: incident handling, through detection and blocking of malware, exploits and network attacks on server workloads with a central record of what was found, and access control on the server itself, through device control and web control. It contributes nothing to business continuity and backup, cryptography, multi-factor authentication, supply chain security or staff training. Vulnerability handling is also outside this tier, because vulnerability assessment and patch management exist only in the Enterprise tier of the same family.
Switzerland has issued no warning. The Federal Office for Cybersecurity (BACS) does not publish product warnings and has stated that no misuse of Kaspersky software has been reported in Switzerland, although Kaspersky software is no longer in use in the federal administration. Germany is different: the Federal Office for Information Security (BSI) warned against the use of Kaspersky antivirus software on 15 March 2022, German courts upheld the warning in interim proceedings the same year, and the BSI confirmed during 2026 that it stands, now issued under Section 13 of the German BSI Act. In the United States, the Bureau of Industry and Security prohibited new sales of Kaspersky products from 20 July 2024 and updates ceased at the end of September 2024. Kaspersky rejects the assessments as politically motivated rather than technical, points to the processing of European customer data in its Zurich data centres and transparency centre, has asked the BSI to withdraw the warning and has reserved the right to take legal action. Independent testing is a separate matter and has continued: Kaspersky's business endpoint products were tested and certified by AV-TEST and by AV-Comparatives through 2026. Practically, this affects three groups of buyers: anyone bidding for public sector contracts, anyone supplying German customers who mirror the BSI position in their own procurement rules, and anyone whose customers ask about vendor country of origin in a supply chain questionnaire. For a Swiss company with none of those constraints, this is a documented risk decision rather than a prohibition.
Partly, and it is worth knowing in advance which lines you can tick. It answers: malware and ransomware protection on servers, centrally enforced by policy rather than configured per machine; host firewall and intrusion prevention; device control; web control; and a console that produces protection-status and detection reports covering the whole estate, which is what auditors usually mean by evidence. It does not answer: patch and vulnerability status, file integrity monitoring, forwarding of security events to a SIEM, detection and response with root-cause analysis, backup and recovery, encryption and key management, multi-factor authentication, or mobile device coverage. Where several of those are blocking a deal, the Enterprise tier of the same family closes four of them at once — patch management, file integrity monitoring, log inspection and SIEM connectors — under the same console and the same agent, which is normally cheaper and far less work than bolting on a second vendor with a second agent to maintain. Backup, encryption and multi-factor authentication sit outside this product family entirely and need separate products whichever tier you choose.
The decisive difference is evidence, not detection. Both tiers use the same protection engine and stop the same threats; Enterprise adds the components that prove what happened and what state a server is in — file integrity monitoring, log inspection, and application control for server operating systems in default-deny scenarios. Enterprise also adds vulnerability assessment with patch management and SIEM connectors, which is why organisations with an audit obligation or a SOC generally start there. Server Base is the right choice when the requirement is protection and central administration; Enterprise is the right choice when someone external will ask for proof.
| Component | Server Base (Standard) | Enterprise, Server |
|---|---|---|
| Cloud API for AWS, Azure, Google Cloud | ✓ | ✓ |
| Anti-Cryptor for shared folders | ✓ | ✓ |
| Application control for server OS | ✕ | ✓ |
| File integrity monitoring | ✕ | ✓ |
| Log inspection | ✕ | ✓ |
| Vulnerability assessment and patch management | ✕ | ✓ |
| SIEM connectors | ✕ | ✓ |
There is a hard regional limitation: Kaspersky products may not be sold in the United States, where the Bureau of Industry and Security prohibited new sales from 20 July 2024, so a Swiss or European group cannot extend this rollout to a US subsidiary and will need a second vendor there. On the platform side, the agentless variant of Kaspersky Security for Virtualization reached the end of technical support on 31 July 2026; new licences ship with the light agent only, existing installations receive database updates until 1 February 2027, and no support of any kind is provided from 2 February 2027, so a VMware environment still running agentless needs a migration plan rather than a renewal. The Server licensing object covers physical and virtual servers only, which means virtual desktops require Desktop licences and hypervisor-level coverage requires the separate CPU model. The two follow-up purchases that catch buyers out most often are the Enterprise tier, once an auditor asks for patch status, file integrity or log forwarding, and an EDR or MDR add-on, because no detection and response component is included at this tier at all.
No. The Server object covers physical servers and virtual servers. Virtual desktops and VDI are covered by the Desktop object, and CPU licensing is the alternative model where you control the hypervisor yourself.
Yes. Server licences allow activation of Kaspersky Endpoint Security for Business applications, which is what makes a staged migration from physical machines to virtual workloads workable without running two parallel licence types during the transition.
No. Kaspersky Security Center is part of the product. You install it on your own Windows-based or Linux-based server, or use the Cloud Console instead if you prefer not to run the administration server yourself.
| Operating Systems | Windows Server 2025: Standard / Datacenter 64-bit Windows Server 2022: Standard / Datacenter / Datacenter: Azure Edition / Server Core mode 64-bit Windows Server 2019: Essentials / Standard / Datacenter / Server Core mode 64-bit Windows Server 2016: Essentials / Standard / Datacenter / Server Core mode 64-bit Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter / Server Core mode 64-bit Windows Server 2012: Foundation / Essentials / Standard / Datacenter / Server Core mode 64-bit Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter / Web Server Service Pack 1 or later 64-bit Windows Small Business Server 2011: Essentials / Standard 64-bit Windows MultiPoint Server 2011 64-bit |
| Processor | CPU 1.4 GHz or higher / SSE2 instruction set support required |
| Memory RAM | 2 GB / 8 GB when installing the application with a built-in agent for integration with Kaspersky Anti Targeted Attack Platform |
| Storage | 2 GB available disk space |
| Architecture | x86-64 compatible / Arm architecture not supported |