What are the key advantages of Kaspersky Embedded Systems Security Base Plus?
Central management – Managed centrally through the Kaspersky Security Center console.
Default deny – Blocks every application you have not explicitly allowed.
Legacy support – Runs on Windows versions that vendors no longer patch.
Device control – Restricts USB storage connected to ATMs and terminals.
SIEM export – Forwards application events to syslog and SIEM systems.
Important note – File integrity monitoring needs the Compliance Edition licence.
Application Launch Control – Default deny allowlisting that blocks any unapproved executable.
Device Control – Governs which USB storage devices may connect to hardware.
Optional anti-malware engine – Signature and cloud-assisted scanning that can be switched off.
Windows Firewall management – Configures the local firewall from Kaspersky Security Center.
SIEM and syslog export – Converts application events into formats your SIEM can read.
Important – File Integrity Monitor and Log Inspection require the Compliance Edition.
Kaspersky Embedded Systems Security Base Plus is a hardening-first security product for low-power embedded devices such as ATMs, payment terminals, self-service kiosks and medical equipment. It is managed centrally through the on-premises Kaspersky Security Center console, and can also be driven from a local GUI or the command line on devices that sit in isolated network segments.
Runs on unsupported Windows – Protects devices whose operating system stopped receiving patches.
Low resource footprint – Designed for hardware that cannot run standard endpoint agents.
Trusted installer updates – Software updates run without manual re-approval of each file.
Works in isolated networks – Local console manages agents where no domain exists.
Exploit prevention – Guards process memory on systems that cannot be patched.
Evidence for audits – Exports device and application events for auditor review.
The deciding factor is not headcount but whether you operate purpose-built devices that cannot be patched or replaced, and whether a Kaspersky Security Center installation already exists to manage them. A retailer with a handful of tills and no server room will find the console requirement heavier than the protection is worth; an operator with distributed terminals across many sites is exactly the intended case.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | Sometimes | Often | Usually |
| Kaspersky Security Center console in place | ✕ | Partial | ✓ |
| This product fits | Limited | ✓ | ✓ |
The reporting obligation under the revised Information Security Act has applied since 1 April 2025 and concerns operators of critical infrastructure, for example energy and drinking water supply, transport companies, listed hospitals and cantonal and communal administrations, not every Swiss company. Affected organisations must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. Kaspersky Embedded Systems Security Base Plus supports the detection side of that duty: it records application launches, device connections and blocked actions per device and forwards those events to a syslog server or SIEM, which shortens the time needed to describe what actually happened on a terminal. It does not correlate an attack across your network, does not reconstruct root cause, and does not produce or submit the BACS report, so the reporting workflow itself has to exist in your incident response plan. The two components most often used as after-the-fact evidence, File Integrity Monitor and Log Inspection, are not part of this licence. This is a product description and not legal advice; have a qualified adviser confirm whether your organisation falls under the reporting obligation.
No software product makes a company NIS 2 compliant, because the directive addresses organisational measures that entities in scope must implement across processes and responsibilities, not only through tools. NIS 2 names measure categories including risk analysis and information system security policies, incident handling, business continuity, supply chain security, security in the acquisition, development and maintenance of systems including vulnerability handling, access control and asset management, basic cyber hygiene, cryptography, and multi-factor authentication. This product contributes to a narrow part of that list: technical hardening of individual devices, access control for removable media, and event logging that feeds incident handling. It contributes nothing to multi-factor authentication, cryptography and key management, vulnerability and patch handling, backup and business continuity, or staff training, all of which the directive names explicitly. Integrity monitoring, which assessors frequently expect as evidence under the acquisition and maintenance category, requires the Compliance Edition rather than this licence.
On 20 June 2024 the US Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting Kaspersky from providing anti-virus and cybersecurity products or services in the United States or to US persons, citing risks arising from Russian jurisdiction over the company. New sales were barred from 20 July 2024 and signature and codebase updates, along with operation of the Kaspersky Security Network, from 29 September 2024; three Kaspersky entities were also added to the Entity List. The determination remains in force and is specific to the United States and US persons. Germany's Federal Office for Information Security issued a warning in March 2022 recommending that Kaspersky products be replaced, and confirmed after the US action that this warning still stands, without any German sales ban; Italy and the Netherlands restricted use in government procurement rather than in the private sector. Kaspersky rejects the allegations, states that the decision reflects the geopolitical climate and theoretical concerns rather than a technical evaluation of its products, and has proposed independent third-party verification of its software and updates. Independent laboratory testing by AV-TEST and AV-Comparatives has continued throughout. In practice this matters most if you bid for public sector contracts, supply organisations with US ownership or US customers, or answer supply chain questionnaires that ask about country of origin; for a privately held Swiss or EU operator with no such obligations, it is a documentation question rather than a blocker.
Partly, and it is worth knowing in advance which boxes stay empty. It answers questions on malware protection for endpoints, application allowlisting and default deny, removable media control, host firewall configuration, centralised policy management, and forwarding of security events to a SIEM. It does not answer questions on file integrity monitoring, log inspection, multi-factor authentication, disk or removable media encryption, patch and vulnerability management, endpoint detection and response, mobile device management, or backup and recovery, and it will not satisfy a country-of-origin or sanctions-screening question about the vendor. The cheapest way to close the integrity monitoring and log inspection gap is the Compliance Edition of the same family rather than adding a second product, because it uses the same agent and the same console; the remaining gaps in encryption, patch management and detection and response genuinely require separate products, so budget for them rather than assuming the embedded licence covers them.
The single decisive difference is system integrity monitoring. Kaspersky sells the two as separate licences for the same application, and the Compliance Edition unlocks File Integrity Monitor, Log Inspection and Registry Access Monitor, which the standard licence leaves disabled. Protection components are otherwise identical, so the choice comes down to whether an auditor or a card scheme expects you to evidence unauthorised changes to files, registry keys and event logs. If PCI DSS or SWIFT assessments apply to the devices you are protecting, the standard licence will leave a documented gap.
| Component | Base Plus | Compliance Edition |
|---|---|---|
| Application Launch Control | ✓ | ✓ |
| Device Control | ✓ | ✓ |
| Anti-malware and exploit prevention | ✓ | ✓ |
| Windows Firewall management | ✓ | ✓ |
| File Integrity Monitor | ✕ | ✓ |
| Log Inspection | ✕ | ✓ |
| Registry Access Monitor | ✕ | ✓ |
Regional availability is the first thing to check: the product cannot be sold to or used by US persons under the US Department of Commerce determination, and updates and Kaspersky Security Network access are blocked there, so a Swiss or EU operator with US subsidiaries or US-based devices cannot deploy it group-wide. Platform coverage is limited to Windows and Linux embedded devices through two separate applications with different component sets; there is no macOS agent, no mobile device management, and the Windows-specific components described above belong to the Windows application. The most common follow-up purchases are the Compliance Edition for integrity monitoring and log inspection, a separate product for endpoint detection and response, and separate products for patch management and encryption, none of which this licence contains. Central management also assumes a Kaspersky Security Center installation you host and maintain yourself, which is real administrative work rather than a checkbox, and the local GUI and command line are the fallback where a console is not reachable.
Base identifies a new licence rather than a renewal or an add-on to an existing product, so it does not require you to already own anything. Plus identifies the support level: under Kaspersky's licensing scheme the Plus licence types include the premium support tier instead of standard support. The licence type does not change which protection components you get.
Yes. It can be operated from a local graphical console or the command line on the protected device, which is how it is usually run on segmented or offline networks. Central policy management, update distribution and consolidated reporting require Kaspersky Security Center.
Kaspersky ships the solution as two applications, one for Windows and one for Linux embedded systems, and updated both in a codebase overhaul released in late November 2025 that added a behavioural analysis engine and Automatic Exploit Prevention. Component names and available features differ between the two, so confirm which application your devices need before ordering.
| Operating Systems | Windows XP 2001: Professional SP2 32-bit / 64-bit / Professional SP3 32-bit Windows 7 2009: Home / Professional / Enterprise / Ultimate SP1 32-bit / 64-bit Windows 8 2012: Pro / Enterprise 32-bit / 64-bit Windows 8.1 2013: Pro / Enterprise 32-bit / 64-bit Windows 10 2015: version 1507 Home / Pro / Education / Enterprise 32-bit / 64-bit / LTSC 2015 version 1507 32-bit / 64-bit Windows 10 2016: version 1607 Home / Pro / Education / Enterprise 32-bit / 64-bit / LTSC 2016 version 1607 32-bit / 64-bit Windows 10 2017: version 1703 Home / Pro / Education / Enterprise 32-bit / 64-bit / version 1709 Home / Pro / Education / Enterprise 32-bit / 64-bit Windows 10 2018: version 1803 Home / Pro / Education / Enterprise 32-bit / 64-bit / version 1809 Home / Pro / Education / Enterprise 32-bit / 64-bit / LTSC 2019 version 1809 32-bit / 64-bit Windows 10 2019: version 1909 Home / Pro / Education / Enterprise 32-bit / 64-bit Windows 10 2021: version 21H2 Home / Pro / Education / Enterprise 32-bit / 64-bit / LTSC 2021 version 21H2 32-bit / 64-bit Windows 10 2022: version 22H2 Home / Pro / Education / Enterprise 32-bit / 64-bit Windows 11 2021: version 21H2 Home / Pro / Education / Enterprise 64-bit Windows 11 2022: version 22H2 Home / Pro / Education / Enterprise 64-bit Windows 11 2023: version 23H2 Home / Pro / Education / Enterprise 64-bit Windows 11 2024: version 24H2 Home / Pro / Education / Enterprise 64-bit Windows Server 2003: SP2 Standard / Enterprise 32-bit / 64-bit Windows Server 2003 R2: SP2 Standard / Enterprise 32-bit / 64-bit Windows Server 2008: SP2 Standard / Enterprise 32-bit / 64-bit Windows Server 2008 R2: SP1 Standard / Enterprise 64-bit Windows XP Embedded: SP2 WEPOS 32-bit / 64-bit Windows Embedded POSReady 2009: XP Embedded SP3 32-bit Windows 7 Embedded 2009: SP1 POSReady 7 32-bit / 64-bit Windows 8 Embedded 2012: Embedded Industry Pro 32-bit / 64-bit Windows 8.1 Embedded 2013: Embedded Industry Pro 32-bit / 64-bit Windows 10 IoT 2015: IoT Enterprise version 1507 32-bit / 64-bit Windows 10 IoT 2016: IoT Enterprise version 1607 32-bit / 64-bit Windows 10 IoT 2017: IoT Enterprise version 1703 32-bit / 64-bit / IoT Enterprise version 1709 32-bit / 64-bit Windows 10 IoT 2018: IoT Enterprise version 1803 32-bit / 64-bit / IoT Enterprise version 1809 32-bit / 64-bit Windows 10 IoT 2019: IoT Enterprise version 1909 32-bit / 64-bit Windows 10 IoT 2021: IoT Enterprise version 21H2 32-bit / 64-bit Windows 10 IoT 2022: IoT Enterprise version 22H2 32-bit / 64-bit Windows 11 IoT 2021: IoT Enterprise version 21H2 64-bit Windows 11 IoT 2022: IoT Enterprise version 22H2 64-bit Windows 11 IoT 2023: IoT Enterprise version 23H2 64-bit Windows 11 IoT 2024: IoT Enterprise version 24H2 64-bit |
| Processor | Minimum 1.4 GHz single-core / Recommended 2.4 GHz quad-core |
| Memory RAM | Minimum 2 GB for full installation of all components / Recommended 4 GB for full installation of all components |
| Storage | Minimum 2 GB free disk space for full installation of all components / Recommended 4 GB free disk space for full installation of all components |