What are the key advantages of Kaspersky Hybrid Cloud Security Enterprise Desktop Base Plus?
Central management – All virtual desktops managed from Kaspersky Security Center.
Light agent – Slim agent per VM, scanning offloaded to SVM.
Application control – Default deny allowlisting for virtual desktop images.
Patch management – Vulnerability assessment and patching included in Enterprise tier.
Broad hypervisors – VMware, Hyper-V, Citrix, KVM, Proxmox and Nutanix.
Important note – No EDR module and no encryption management.
Light Agent protection – File, process and memory protection on each virtual desktop.
Application Control – Allowlisting and default deny for desktop operating systems.
Vulnerability and patch management – Scans installed software and distributes missing updates centrally.
File Integrity Monitor – Records changes to protected files and registry keys.
SIEM connectors – Forwards security events to an existing SIEM system.
Important – No EDR component; detection and response require a separate product.
Kaspersky Hybrid Cloud Security Enterprise, Desktop is the Enterprise tier licence for protecting virtual desktops, built on the Kaspersky Security for Virtualization Light Agent architecture that the line grew out of and that is still shipped as part of the product. Protection is administered centrally from Kaspersky Security Center, either on premises or through the Cloud Console.
Lower VM overhead – Scanning moves to a shared secure virtual machine.
One policy set – Same console rules for physical and virtual desktops.
Migration cover – Desktop licences also activate Kaspersky Endpoint Security for Business.
Audit evidence – File integrity and log inspection produce reviewable change records.
Hypervisor choice – VMware, Hyper-V, Citrix, KVM, Proxmox and Nutanix are supported.
Fewer scan storms – Scan tasks are queued instead of starting simultaneously.
The deciding factor is not headcount but whether you actually run virtual desktops. A company with fifteen physical notebooks and no hypervisor gains nothing from this licensing object, while a medium-sized company running a Citrix or VMware Horizon desktop pool for branch staff is exactly the intended case.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | ✓ |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Virtual desktops already in use | Rarely | ✓ | ✓ |
| This product fits | ✕ | ✓ | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, so the first step is to establish whether your organisation falls inside that scope at all. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the practical question is how quickly you can tell that something happened and describe it. Application Control, the File Integrity Monitor and Log Inspection help here in a concrete way: allowlisting blocks unauthorised executables on the desktop images, file integrity records show which protected files or registry keys were altered and when, and the SIEM connectors push those events out of Kaspersky Security Center into whatever system your team already watches. What the product does not do is close the loop for you. There is no EDR component to reconstruct an attack chain, no incident case management, no automatic drafting of a report, and nothing that covers servers, mailboxes or mobile devices under this Desktop licensing object. This information is a technical overview and not legal advice; have your own reporting obligations assessed by qualified legal counsel.
No software product makes an organisation compliant with the NIS 2 Directive, because the directive addresses governance, risk management and organisational process, and buying a licence changes none of those. NIS 2 requires categories of measure such as risk analysis and information system security policies, incident handling, business continuity and backup, supply chain security, security in system acquisition and maintenance including vulnerability handling, access control and asset management, and the use of cryptography where appropriate. This product maps onto a subset of them: vulnerability assessment and patch management support the vulnerability handling measures, Application Control and the Light Agent support system security on the desktop layer, File Integrity Monitor and Log Inspection feed the incident handling and detection measures, and role-based administration in Kaspersky Security Center supports access control on the management side. The gaps are equally clear. There is no backup or continuity function, no encryption or key management, no multi-factor authentication, no supply chain assessment tooling, and no coverage of servers, email or mobile endpoints under this licensing object. Directors remain personally accountable for the management measures under NIS 2, and that accountability cannot be transferred to a vendor.
In June 2024 the Bureau of Industry and Security of the US Department of Commerce issued a Final Determination prohibiting Kaspersky from supplying antivirus and cybersecurity products in the United States or to US persons. Since 29 September 2024 resale, integration and the provision of signature and codebase updates have been prohibited there, and three Kaspersky group entities were added to the Entity List. The determination remains in force. In Germany, the Federal Office for Information Security (BSI) issued a warning under section 7 of the BSI Act in March 2022 recommending that Kaspersky antivirus products be replaced with alternatives; the BSI confirmed after the US measures that this warning still stands, and it is a recommendation rather than a sales ban. Italy and the Netherlands have restricted Kaspersky in government procurement contexts. Switzerland has taken no such step: the Federal Office for Cybersecurity issues warnings only where it holds confirmed technical evidence of a security risk, states that no misuse of Kaspersky software has been reported to it, and has published no warning; data from European customers is processed in Kaspersky's Swiss transparency infrastructure. Kaspersky rejects the allegations, denies ties to any government, and has proposed an independent verification framework covering its solutions, database updates and detection rules; its products continue to appear in the public test programmes of AV-TEST and AV-Comparatives. In practice this matters most if you sell into US markets, hold public sector contracts, or answer supply chain questionnaires from customers who screen vendors by country of origin. It matters less for a purely domestic Swiss or EU environment. That assessment is yours to make.
Partly, and the split is predictable. It answers the malware protection question for virtual desktops, the application allowlisting question through Application Control in default deny mode, the vulnerability and patch management question through the integrated scanning and update distribution, the change monitoring question through the File Integrity Monitor, the logging question through Log Inspection, and the centralised administration and role separation question through Kaspersky Security Center. Event export to an existing SIEM is available through the connectors, which is usually enough for the log forwarding item. It does not answer several items that appear on almost every questionnaire: there is no endpoint detection and response capability and therefore no answer to questions about threat hunting, alert triage or root cause analysis; no disk or removable media encryption and no key management; no multi-factor authentication; no mobile device management; no email or Exchange protection; and no backup or recovery function. Server workloads, cloud instances and container hosts are outside the Desktop licensing object and need the Server or CPU object instead. The cheapest way to close the biggest of those gaps is usually to stay inside the Kaspersky family rather than mixing vendors: the Server or CPU licensing object for workloads and DevOps scenarios, Kaspersky Container Security where Kubernetes is in scope, and a dedicated EDR product where the questionnaire demands detection and response. Mixing vendors means running two consoles and two agent stacks, which most questionnaires will eventually ask you to justify.
The single most decisive difference is Application Control for server operating systems combined with the File Integrity Monitor, which is what makes a full default deny hardening baseline possible. Beyond that, the Enterprise tier is where vulnerability assessment and patch management, Log Inspection, SIEM connectors and container security live. Both tiers share the same anti-malware core, the same public cloud API integration for AWS, Microsoft Azure and Google Cloud, and the same host firewall and IPS management. Application Control for desktop operating systems is present in both, so a company that only needs desktop allowlisting and anti-malware does not automatically need the Enterprise tier. Container security and DevOps integration also require an Enterprise licence on the host, and those scenarios use the Server or CPU licensing object rather than Desktop.
| Feature | Standard | Enterprise |
|---|---|---|
| File, process and memory protection | ✓ | ✓ |
| Application Control for desktop OS | ✓ | ✓ |
| Application Control for server OS | ✕ | ✓ |
| File Integrity Monitor | ✕ | ✓ |
| Log Inspection | ✕ | ✓ |
| Vulnerability assessment and patch management | ✕ | ✓ |
| SIEM connectors | ✕ | ✓ |
| Container security and DevOps integration | ✕ | Server or CPU |
| NextGen IDS/IPS for VMware NSX | ✕ | ✓ |
| EDR and encryption management | ✕ | ✕ |
The Desktop licensing object is tied to the virtual desktop scenario. Public cloud workloads and DevOps or container scenarios are covered by the Server and CPU objects instead, so a company that expects to protect cloud instances with this licence will need to buy again. There is a hard regional restriction: because of the US Department of Commerce prohibition, Kaspersky products cannot be sold, resold, integrated or updated in the United States or for US persons, which rules this product out for any environment with US-based staff or US entities, while Switzerland, the European Union and the United Kingdom are unaffected. Functionally, the most common reasons for a follow-up purchase are the absence of an EDR component, the absence of encryption and key management, and the absence of any mobile or email protection. On the infrastructure side, Kaspersky Security Center is required for deployment and administration, and a Secure Virtual Machine must be deployed on each hypervisor host, so a very small virtualisation footprint carries a disproportionate amount of infrastructure. Supported platforms include VMware vSphere, NSX and Horizon, Microsoft Hyper-V, Citrix Hypervisor and Virtual Apps and Desktops, KVM, Proxmox VE, Nutanix Acropolis and Huawei FusionSphere, with documented limitations on several less common platforms.
Yes. Desktop licences permit activation of Kaspersky Endpoint Security for Business applications, which is deliberate: it lets a company migrate from physical desktops to virtual desktop infrastructure gradually without running two separate licence types during the transition.
Both Windows and Linux virtual machines are supported. The Linux Light Agent is Kaspersky Endpoint Security for Linux, and the current release generation uses Kaspersky Endpoint Security for Windows 12.10 and Kaspersky Endpoint Security for Linux 12.3 as its agents.
Kaspersky processes data from European customers in Switzerland, in the infrastructure it established under its Global Transparency Initiative. This is one of the few concrete facts available on the data processing question, and it is worth quoting directly when a customer questionnaire asks where telemetry goes.