What are the key advantages of Kaspersky Express Course Base?
Cloud console – All training is assigned and tracked centrally.
Express format – Short audio-video lessons with a test.
Directory sync – Import staff from Active Directory or Entra.
Progress evidence – Per-user reports export as PDF or XLSX.
Own questions – Add company slides and your own test questions.
Important note – Express course contains no simulated phishing attacks.
Download: Kaspersky Express Course Base
Express course units – Short audio-video lessons across 21 cybersecurity topics.
Knowledge tests – Ten questions per topic by default, unlimited retakes.
ASAP cloud console – Central platform for groups, schedules and progress tracking.
User import – Manual entry, XLSX upload, Active Directory or Entra sync.
Reports and certificates – Per-user PDF reports, XLSX history export, training certificates.
Important – Simulated phishing attacks are not part of the express course.
Kaspersky Express Course Base is the short-form training track of the Kaspersky Automated Security Awareness Platform, which Kaspersky also refers to as Kaspersky ASAP. Administration runs entirely in the vendor cloud console, and employees learn in a browser, so nothing is installed on workstations.
Fast rollout – Groups, start dates and duration are set per department.
Short lessons – Suits shift staff and people without desk time.
Refresher training – Reviews the basics for staff trained in earlier years.
Own content – Add company slides and your own test questions.
Individual evidence – Export per-employee completion records into your audit file.
Directory and SSO – Entra ID or Active Directory sync plus single sign-on.
The express course is aimed at companies that need every employee trained quickly and need a record of it afterwards. Very small firms can run it without an IT department because there is no server to operate; larger organisations usually treat it as the refresher layer next to a deeper program for high-risk roles such as finance and IT.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Directory sync and single sign-on needed | ✕ | ✓ | ✓ |
| This product fits | ✓ | Partly | As refresher |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, and it requires a cyberattack to be reported to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. The 24-hour clock starts when someone notices the incident, which is why the express unit on how employees should respond to an incident is the part of this product that actually supports the obligation: staff learn to escalate a suspicious email or a locked file immediately instead of waiting a day. Training records also give you dated evidence that the workforce was instructed on that reporting path. What the product does not do is detect the incident, keep logs, reconstruct a timeline, or file the report; that still requires endpoint or network detection, an internal escalation process, and a named person who submits the report through the BACS form. It also does not cover the technical and organisational measures expected around the obligation, such as backup, access control and business continuity planning. This text is not legal advice, so have your own reporting obligations assessed by qualified legal counsel.
No software product creates NIS 2 compliance, because the directive addresses organisations and their processes rather than a purchased tool. The NIS 2 Directive requires risk-management measures across several categories, and it names basic cyber hygiene practices and cybersecurity training explicitly alongside incident handling, business continuity and backup, supply chain security, access control, and the use of multi-factor authentication. This product maps onto exactly one of those categories: it delivers the staff training and cyber hygiene content, including units on passwords, mobile devices, remote working and supply chain attacks, and it documents who completed what. It does not contribute to incident handling, backup and continuity, access control, multi-factor authentication, or the security of your own supply chain. The directive also expects management bodies themselves to follow training, and a general staff course is not a substitute for that management-level obligation.
In Switzerland, BACS has published no warning and no sales restriction concerning Kaspersky. It has stated that Kaspersky software is no longer in use in the federal administration and that there is no internal directive banning it, leaving the decision to each organisation. In Germany, the Federal Office for Information Security (BSI) issued a warning on 15 March 2022 against the use of Kaspersky antivirus software and recommended replacing it; the warning is still in force in 2026 and now sits under Section 13 of the amended BSI Act. BSI limited that warning to antivirus software and stated that it made no assessment of other products in the Kaspersky portfolio, which is relevant here because a browser-based training platform installs no agent with system privileges. In the United States, the Department of Commerce prohibited the sale of Kaspersky software in 2024, and updates to US customers ended on 29 September 2024; that prohibition remains in force. Kaspersky rejects the assessments, points out that no vulnerability was demonstrated, refers to source code review at its Transparency Centre in Zurich, and has publicly demanded that the German warning be withdrawn. In practice this affects three groups of buyers: public sector bodies and their suppliers, companies whose large customers exclude vendors with Russian ties in their supplier questionnaires, and any organisation with United States operations. For everyone else the practical question is narrower, namely whether employee names, email addresses and training results may be processed by this vendor in the storage region you select.
Yes, for the awareness section, and only for that section. It answers the recurring items directly: whether all employees receive security awareness training, how often, which topics are covered, whether completion is documented per person, and whether the training includes a knowledge check. The per-user report exports as PDF and the activity history as XLSX, so you can attach dated evidence instead of describing a policy. It does not answer the items that questionnaires usually place next to those questions: phishing simulation click rates over time, role-specific training for privileged users and developers, training for the management body, and every technical control question on multi-factor authentication, patching, backup, encryption and endpoint detection. There is also no email reinforcement between lessons, so you cannot evidence continuous reinforcement from this course alone. If a customer questionnaire demands measured phishing resilience, the cheaper route is usually the main course of the same platform, which includes simulated phishing campaigns and reinforcement emails, rather than adding a second vendor and a second employee list to maintain.
The decisive difference is simulated phishing: the express course contains none, while the main course delivers phishing attacks and email reinforcements automatically as part of the program. The express course is the shorter audio-video version of each topic, built for speed and for periodic refreshers, and Kaspersky recommends running phishing campaigns separately for employees who take it. The main course splits topics into difficulty levels and adds lessons of roughly five to fifteen minutes with reinforcement between them. Both run in the same console, both can be extended with your own slides and test questions, and both can run for the same user at the same time. Choose the express course to get everyone through the basics quickly, and the main course when you need measured behaviour change in higher-risk groups.
| Capability | Express Course | Main Course |
|---|---|---|
| Lesson format | Audio-video units | Lessons 5 to 15 minutes |
| Difficulty levels | Limited | Beginner to Advanced |
| Email reinforcements | ✕ | ✓ |
| Simulated phishing attacks | ✕ | ✓ |
| Own slides and test questions | ✓ | ✓ |
| Typical use | Basics and refresher | Full training program |
Regional availability is the first point to check: Kaspersky software may not be sold in the United States following the 2024 prohibition, so this is not an option for a group with US entities, and the platform offers data storage in Europe, Russia, Kazakhstan or Uzbekistan, with no Swiss storage location. The second point is language coverage, because express units are not all translated into every portal language at the same time, and new units have appeared in a single language first, which matters if you need identical content in German, French and Italian on the same date. Several express units address Russian federal legislation and are irrelevant outside that market, so plan to switch them off for your groups. Functionally, the absence of simulated phishing is the limitation that most often triggers a follow-up purchase, since a customer or insurer asking for measured phishing resilience cannot be answered with course completion alone. Finally, this is training only: it installs nothing, blocks nothing, and needs an endpoint security product alongside it.
No. Employees open the training portal in a browser on a computer or phone, either through a personal link from the invitation email or through single sign-on with your identity provider. Administrators work in the same cloud console, so there is no training server to maintain.
You choose the storage region when the company account is registered, and the available options are Europe, Russia, Kazakhstan and Uzbekistan. The data involved is employee names, email addresses, group assignment and training results, so treat the region choice as a data protection decision and record it before rollout.
The express course itself contains no phishing attacks, and Kaspersky recommends running phishing campaigns as a separate activity for these users. The platform side of that includes more than one hundred email templates, custom templates, attachment and QR code scenarios, and a report phishing plug-in for Outlook, OWA, Microsoft 365 and Thunderbird. Confirm with your reseller which of these your licence covers before you promise a click-rate report to a customer.
| Operating Systems | Windows 10 Windows 7 macOS current version iOS latest version Android 5 or later |
| Browser | Microsoft Edge / Mozilla Firefox / Google Chrome / Safari for macOS / Safari for iOS / Google Chrome for Android |
| Processor | CPU 1 GHz |
| Memory RAM | 1 GB |
| Network | Network bandwidth 1 Mb/s |
| Storage | 20 MB disk space |