What are the core benefits of Kaspersky Security for Storage User Base?
Central management – All storage scanning policies run from one console.
NAS integration – Connects through ICAP, RPC and NetApp FPolicy.
Ransomware blocking – Anti-Cryptor stops encryption attempts on NetApp shares.
On-access scanning – Every file checked when opened or changed.
Safe quarantine – Untouched copy stored before any file is cleaned.
Important note – No EDR, patch management or endpoint coverage.
Download: Kaspersky Security for Storage User Base
NAS anti-malware engine – Scans files on supported storage systems in real time.
ICAP and RPC integration – Connects to Dell EMC, Hitachi, IBM and Oracle storage.
Anti-Cryptor for NetApp – Blocks encryption of shares from an infected network host.
Kaspersky Security Center – Central console for policies, remote install and reporting.
Quarantine and backup – Unmodified copy kept before any object is disinfected.
Important – No EDR component, patch management or encryption management included.
Kaspersky Security for Storage is a dedicated anti-malware layer for network attached storage and Windows file servers, managed centrally through Kaspersky Security Center rather than device by device. It succeeds the earlier Kaspersky Anti-Virus for Storage line, and Base identifies a new licence rather than a renewal of an existing one.
No agent on NAS – Storage is scanned without installing software on the appliance.
Protects unmanaged uploads – Catches files placed on shares by contractors or guests.
Tunable scan load – Trusted zones exclude backup jobs and database files.
Fault tolerant scanning – Protection restarts automatically after a forced shutdown.
Evidence ready reports – Console shows storage protection status for audit questions.
Still maintained product – Kaspersky continues the storage engine for network storage protection.
The deciding factor is not headcount but whether you run a NAS appliance that no endpoint agent can be installed on. A company with ten staff and a NetApp filer has the same gap as a company with a thousand.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Likely |
| NIS 2 in the European Union | Rare | By sector | Likely |
| Security questionnaire from large customers | Sometimes | Often | Standard |
| NAS that no endpoint agent can protect | ✕ | ✓ | ✓ |
| This product fits | Only with NAS | ✓ | ✓ |
The obligation that matters here applies to operators of critical infrastructure under the revised Information Security Act, in force since 1 April 2025, and not to every Swiss company. Those operators must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the fuller report following within 14 days. The product supports that deadline in one specific way: an infection or a blocked encryption attempt on a protected share is recorded centrally in Kaspersky Security Center, so the affected share and the time of detection can be named quickly instead of being reconstructed from the storage system's own logs. What it does not do is tell you how far an attacker moved through your network, since it has no endpoint telemetry, no timeline reconstruction and no root-cause analysis; the storage event alone rarely answers the questions BACS asks in the 14-day report. It also does not cover the organisational side at all, meaning the decision path, the named responsible person and the rehearsed process that determine whether you actually make the 24-hour window. This information is not legal advice, and whether your organisation falls within the reporting obligation should be clarified with qualified legal support.
No software product makes a company compliant with the NIS 2 Directive, because the directive addresses management responsibility and organisational process rather than tooling. NIS 2 requires essential and important entities to put in place measures across categories including incident handling, business continuity and backup management, supply chain security, basic cyber hygiene, access control and the use of cryptography. This product contributes to two of them: malware protection as part of cyber hygiene on file storage, and the detection half of incident handling for files written to protected shares. It does not contribute to backup and business continuity, because it scans data rather than copying it, and a cleaned file that was never backed up is still a lost file. It also contributes nothing to supply chain security, access control, encryption or staff training, and it produces no evidence at all about systems other than the storage it protects. Buyers should treat it as one measure inside a much larger set, not as a NIS 2 answer.
In Switzerland, the Federal Office for Cybersecurity (BACS) has issued no warning and no ban concerning Kaspersky. It has stated that it warns only where it holds confirmed technical evidence that a product creates security risks, that no misuse of Kaspersky software in Switzerland has been reported to it, and that it would inform the public immediately if that changed; it has also confirmed there is no internal federal directive prohibiting the products, leaving the decision with each buyer. In Germany, the Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022 and the warning remains in force, now regulated under Section 13 BSIG following the amendment of 6 December 2025. The BSI's stated reasoning is not a demonstrated flaw in the software but the risk that a Russian manufacturer could be compelled to act, or be abused, given the deep system permissions and the permanent encrypted connection antivirus software requires. The BSI itself notes that use of the products is not prohibited in Germany and recommends an individual assessment. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting the sale of Kaspersky software to US persons from 20 July 2024 and the supply of updates from 29 September 2024, and added Kaspersky entities to the Entity List; the company subsequently wound down its US operations. Kaspersky rejects the German warning as not based on an objective technical analysis, has formally asked for its withdrawal and reserves legal steps, and points to its data processing for European customers in Switzerland, its Zurich transparency centre where source code can be reviewed, and its holding structure in London. German courts rejected urgent applications against the warning in 2022. In practice this matters most if you sell into the German public sector, supply German customers who pass BSI recommendations down their supply chain, hold US government contracts, or answer supplier questionnaires that ask about vendor country of origin. For a company with none of those exposures, the decision is a normal risk assessment.
Partly, and only for a narrow set of items. It answers the question of whether malware protection covers your file storage and not just workstations, which is a common follow-up when a questionnaire asks about anti-malware coverage of all systems holding customer data. It answers whether that protection is centrally managed and centrally reported, because policies and protection status come from Kaspersky Security Center. It also answers whether ransomware controls exist at the storage layer, which the Anti-Cryptor component for NetApp addresses directly. What it does not answer is equally important. It gives you nothing on endpoint detection and response, patch and vulnerability management, disk or file encryption, multi-factor authentication, mobile device management, email filtering, log retention periods or SIEM forwarding, and nothing on backup and restore testing, which is often the single most heavily weighted item on the form. It also does not address the vendor-origin question described in the section above, which increasingly appears on questionnaires from German and US-linked customers. To close the technical gaps, the cheaper route is usually a higher edition within the Kaspersky business range for endpoint, patch and encryption coverage, keeping one console and one support contact, rather than adding a second vendor for each missing item.
The clearest regional limitation is the United States, where sales and updates are prohibited under the Commerce Department determination described above; the product is sold and updated normally in Switzerland and the European Union. The scanning component runs on a Microsoft Windows Server host, so there is no Linux-based scanning host and you need a Windows Server available for the role even if the storage itself is an appliance. Support is tied to a specific list of storage platforms, primarily NetApp, Dell EMC Celerra, VNX and Isilon, Hitachi HNAS, IBM System Storage N series, Oracle ZFS Storage Appliance, Dell FluidFS and HPE 3PAR File Persona, plus other systems that speak ICAP or RPC, which means a consumer or small-office NAS is generally out of scope and should be checked before you buy. The Anti-Cryptor protection against encryption of shares is a NetApp integration and does not extend to every supported platform. The most common cause of a follow-up purchase is scope: this licence protects storage only, so workstations, laptops, mail servers and mobile devices still need separate cover, and there is no backup function anywhere in the product.
No. The scanning component runs on a Windows Server host and the storage system hands files to it over ICAP, RPC or, for NetApp, FPolicy. Nothing is installed on the storage appliance itself, which is why appliances that cannot run an agent can still be protected.
Yes. Alongside the central console, the application can be configured locally through its own Application Console or from the command line. Central management is the practical choice once more than one scanning host is involved, because policies and reporting are otherwise maintained per host.
An endpoint licence protects the Windows file server it is installed on. This licence adds protection for network attached storage appliances reached over ICAP, RPC or FPolicy, which an endpoint agent cannot reach because it cannot be installed on the appliance. Kaspersky continues to maintain the storage engine specifically for network storage protection.
| Operating Systems | Windows Server 2019: Essentials / Standard / Datacenter / Core Windows Storage Server 2019 Windows Hyper-V Server 2019 Windows Server 2016: Essentials / Standard / Datacenter / Core Windows Storage Server 2016 Windows Hyper-V Server 2016 Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter / Core Windows Storage Server 2012 R2 Windows Hyper-V Server 2012 R2 Windows Server 2012: Foundation / Essentials / Standard / Datacenter / Core Windows Storage Server 2012 Windows Hyper-V Server 2012 Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter / Core Windows Hyper-V Server 2008 R2 Windows Server 2008: Standard / Enterprise / Datacenter / Core Windows Server 2003 and 2003 R2: Standard / Enterprise / Datacenter Windows 10 Enterprise multi-session |
| Processor | Minimum 1.4 GHz single-core / recommended 2.4 GHz quad-core |
| Memory RAM | Minimum 1 GB / recommended 2 GB |
| Storage | 4 GB free disk space / 100 MB for installing all components / 2 GB recommended for antivirus databases / 400 MB recommended for quarantine and backup / 1 GB recommended for logs |
| Storage Platforms | NetApp: Data ONTAP 7.x and 8.x in 7-mode / Data ONTAP 8.2.1 in cluster-mode / Data ONTAP 9.x from 9.0 to 9.7 in cluster-mode / Dell EMC Celerra and VNX: EMC DART 6.0.36 or higher / Celerra Antivirus Agent CAVA 4.5.2.3 or higher / Dell EMC Isilon: OneFS 7.0 or later / Hitachi HNAS: 12.0 or later via ICAP / 11.2 or later via RPC / IBM System Storage N series / Oracle ZFS Storage Appliance / Dell Compellent FS8600: FluidFS 6.x / FluidFS 5.x / HPE 3PAR: File Persona 3.3.1 |