What are the key advantages of Kaspersky Embedded Systems Security Base?
Central management – Policies and reporting via Kaspersky Security Center.
System hardening – Default Deny blocks any unapproved application launch.
Legacy support – Runs on Windows XP SP2 through Windows 11.
Device control – Blocks unauthorised USB devices on unattended machines.
Low footprint – Anti-malware can be switched off on weak hardware.
Important note – File integrity monitor needs the Compliance Edition.
Download: Kaspersky Embedded Systems Security Base
Application Launch Control – Default Deny mode permits only approved programs to run.
Device and Update Control – Restricts USB peripherals and unapproved software update sources.
Opt-in anti-malware – On-demand and real-time scanning, disabled on weak hardware.
Exploit Prevention – Blocks memory exploits including fileless and zero-day techniques.
Network Threat Protection – Stops port scanning and brute force attacks on devices.
Important – File Integrity Monitor and Log Inspection require the Compliance Edition.
Kaspersky Embedded Systems Security protects ATMs, point-of-sale terminals, ticketing machines, medical equipment and legacy endpoints that cannot carry a standard endpoint agent. It is managed centrally through Kaspersky Security Center, either on-premises or from the vendor-hosted cloud console, and additionally offers a local GUI and command line for isolated devices.
Runs on old hardware – Supports Windows XP SP2 up to Windows 11.
Linux device coverage – Separate agent protects Linux-based embedded devices and kiosks.
Works offline – Protection stays stable during long periods without connectivity.
Firewall management – Configures the OS firewall on devices outside the domain.
SIEM export – Forwards events by syslog to your existing SIEM.
Anti-Cryptor protection – Detects and stops ransomware encrypting files on the device.
Company size matters less here than device inventory. The product is worth buying when you operate machines that a normal endpoint agent cannot run on: self-service terminals, checkout systems, fuel dispensers, medical devices or production PCs still on an unsupported Windows version. A single retail branch with four checkouts has the same technical requirement as a bank with two thousand ATMs.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | Sometimes | Often | ✓ |
| Central console for dispersed devices | Optional | ✓ | ✓ |
| This product fits | If embedded devices | ✓ | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, and has been enforceable since 1 April 2025; affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Meeting a 24-hour deadline depends on noticing the incident in the first place, and this is where an embedded device fleet is usually the weak point, because terminals in branches and public locations are rarely watched as closely as office endpoints. Kaspersky Embedded Systems Security supports this by detecting malware and network attacks on the device itself and by forwarding its events via syslog to a SIEM, so that an alarm from an ATM or checkout system reaches the same queue as everything else. What it does not deliver in the Base licence is audit-ready evidence of what changed on the device: File Integrity Monitor and Log Inspection are reserved for the Compliance Edition, and even there they run on Windows only. It also does not cover the organisational side of the obligation, meaning the reporting process, the named responsible person and the incident documentation, all of which you have to build yourself. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses risk management measures and governance rather than software features. NIS 2 requires, among others, incident handling, business continuity including backup and crisis management, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, access control and asset management, cryptography, multi-factor authentication and staff training. Kaspersky Embedded Systems Security contributes to a narrow set of these: incident detection and event forwarding for incident handling, application and device control for access control at device level, exploit prevention as mitigation where a system can no longer be patched, and system hardening as basic cyber hygiene on machines that would otherwise run unprotected. It contributes nothing to backup and business continuity, encryption, multi-factor authentication, supply chain assessment or awareness training, and it performs no patch management, so vulnerability handling remains a separate process. Treat it as one measure among many, and specifically as the measure that closes the gap on devices your standard endpoint product cannot reach.
In Switzerland, the Federal Office for Cybersecurity has issued no warning and no ban concerning Kaspersky products, has stated that it has received no reports of misuse in Switzerland, and leaves the decision to each organisation; there is also no internal federal directive prohibiting the products. In Germany, the Federal Office for Information Security (BSI) issued a formal warning on 15 March 2022 recommending that Kaspersky antivirus products be replaced with alternatives, and that warning remains in force, now anchored in Section 13 of the amended BSI Act since 6 December 2025. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting the sale of Kaspersky security software and, from 29 September 2024, the delivery of signature and codebase updates to US persons; this prohibition is still in force. Kaspersky rejects the allegations, states that the decisions reflect the geopolitical situation rather than an assessment of its products, processes threat data from European users on servers in Switzerland, and operates a Transparency Center in Zurich where authorised partners and government stakeholders can review source code and detection rules. Independent testing has not been withdrawn: the independent laboratories have continued to include Kaspersky products in their public test cycles. Practically, this matters if you sell to the public sector, supply German public bodies or critical infrastructure operators, answer supply chain questionnaires that ask about vendor country of origin, or operate any entity subject to US rules; for a private Swiss retailer or hospitality operator with no such exposure, it is a documentation question rather than an obstacle.
Partly, and it is worth knowing in advance which boxes it lets you tick. It answers questions on malware protection for all endpoints including legacy systems, application allowlisting, removable media and USB restrictions, host firewall configuration, protection against network-based attacks, central policy enforcement, and forwarding of security events to a SIEM. It does not answer questions on endpoint detection and response, patch and vulnerability management, disk or removable media encryption, multi-factor authentication, backup and restore testing, mobile device management, or file integrity and log audit evidence, since the last of these belongs to the Compliance Edition. The awkward items in practice are usually integrity monitoring and EDR, because auditors ask for proof of what changed on a payment-handling device and how quickly you could reconstruct an incident. If those two come up, the cheaper route is normally to move the same fleet to the Compliance Edition for integrity monitoring and log inspection, and to add an EDR product from the same vendor family so that everything stays in one console, rather than introducing a second vendor and a second agent onto hardware that is already resource-constrained.
The single decisive difference is system inspection: the Compliance Edition is the extended licence that unlocks two additional components, File Integrity Monitor and Log Inspection, which the standard edition does not activate. Everything else, including application, device and update control, anti-malware, exploit prevention, network threat protection and central management, is identical between the two. Both are sold as separate licences and neither is part of a bundle, so this is a decision you make at purchase rather than an upgrade you toggle later. Choose the Compliance Edition when an auditor or a large customer asks you to evidence changes to critical files and to inspect event logs on payment-handling or regulated devices. Note that both inspection components are available for Windows only, so a Linux-based device fleet gains nothing from the upgrade.
| Component | Embedded Systems Security | Compliance Edition |
|---|---|---|
| Application, device and update control | ✓ | ✓ |
| Anti-malware and Exploit Prevention | ✓ | ✓ |
| Network Threat Protection | ✓ | ✓ |
| File Integrity Monitor | ✕ | Windows only |
| Log Inspection | ✕ | Windows only |
| Management via Kaspersky Security Center | ✓ | ✓ |
| Sale and updates in the United States | ✕ | ✕ |
The clearest regional limitation is the United States: since 29 September 2024 Kaspersky may neither sell its security software there nor supply signature and codebase updates to US persons, so devices operated by a US entity or on US soil cannot be covered by this licence. Platform coverage is uneven in one specific respect: the integrity and logging components, along with the proprietary application-level firewall, exist for Windows only, while Linux devices receive protection and hardening but not system inspection. The most common cause of a follow-up purchase is the edition split, because buyers discover during an audit that File Integrity Monitor and Log Inspection sit in the Compliance Edition rather than in the standard licence. Beyond that, this is a hardening and protection product, not a detection and response platform: it contains no EDR component, no patch management, no encryption management and no mobile device coverage, and central management assumes you run or subscribe to Kaspersky Security Center.
Yes, and Kaspersky documents this scenario explicitly as an alternative to its regular endpoint product for legacy machines. Because support reaches back to Windows XP SP2, a production PC or laboratory workstation that cannot be upgraded can stay protected and centrally managed instead of being excluded from the security policy.
Base is the new-licence variant of the product. Renewal variants of the same product are listed separately, so select Base when the devices are not yet covered by an existing licence of this product.
| Operating Systems | Windows 11 64-bit Windows 10 32-bit / 64-bit Windows 8 32-bit / 64-bit Windows 7 32-bit / 64-bit Windows Server 2019 64-bit Windows Server 2016 64-bit Windows Server 2012 R2 64-bit Windows Server 2012 64-bit Windows Server 2008 R2 64-bit Windows Server 2008 64-bit Windows XP Embedded Windows Embedded POSReady 2009 Windows 7 Embedded Windows 8 Embedded Windows 10 IoT Windows 11 IoT |
| Processor | Minimum 1.4 GHz single-core / Recommended 2.4 GHz quad-core |
| Memory RAM | Minimum 1 GB / Recommended 4 GB for full installation of all components |
| Storage | Minimum 2 GB free disk space for full installation / Recommended 4 GB free disk space for full installation |