What are the core benefits of Kaspersky Hybrid Cloud Security Desktop Base Plus?
Central management – All virtual desktops managed from one console.
Light agent – Scanning offloaded to a shared security virtual machine.
Broad hypervisors – VMware, Citrix, Hyper-V, KVM and Proxmox supported.
Ransomware rollback – Reverses malicious changes made inside protected desktops.
Desktop controls – Application, device and web control per policy.
Important note – No EDR, patch management or server coverage.
Virtual desktop protection – File, memory and process scanning inside each virtual workstation.
Light Agent architecture – Databases and scan engine run on a shared security virtual machine.
Kaspersky Security Center – One console for policies, tasks, roles and reporting.
Endpoint controls – Application, device and web control for desktop operating systems.
Anti-cryptor and rollback – Blocks encryption attempts and reverses malicious file changes.
Important – No EDR, patch management, encryption management or server coverage.
Kaspersky Hybrid Cloud Security Desktop Base Plus protects virtual workstations in a VDI environment and is administered centrally from Kaspersky Security Center. The underlying technology is Kaspersky Security for Virtualization Light Agent, the name many administrators still search for, and Kaspersky now groups the product under its Cloud Workload Security range alongside Kaspersky Container Security.
Lower hypervisor load – Shared scan cache avoids repeated scanning of identical files.
Non-persistent desktop support – Protection applies to desktops created and destroyed on demand.
Windows and Linux – Both guest operating system families are covered by one agent.
Role-based administration – Separate helpdesk and security duties without sharing one login.
Multi-tenancy mode – Service providers separate customer infrastructures inside one console.
Web and mail filtering – Blocks phishing links and attachments before users open them.
The Desktop licensing object is aimed at organisations that already run a virtual desktop infrastructure. If your users work on physical notebooks and PCs, this is the wrong product and a classic endpoint suite is the correct answer instead.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Runs a virtual desktop infrastructure | Rarely | Often | ✓ |
| This product fits | ✕ | ✓ | ✓ |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so the first question is whether your organisation is in scope at all. Affected operators must report a significant cyber attack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Kaspersky Security Center supports that deadline in one concrete way: detections from every protected virtual desktop arrive in a single event log with timestamps, machine names and verdicts, which is the raw material an initial report needs and is far faster to assemble than pulling logs from individual machines. What the product does not supply is the rest of the picture, because it has no EDR component to reconstruct an attack path across systems, and it covers neither physical endpoints, nor servers, nor network devices, nor cloud services under this licence, while a report has to describe the whole incident and not only the VDI part. It also does not create the incident response process, the named reporting contacts or the escalation rules that the obligation assumes are already in place. This text is a product description and not legal advice; have your own reporting obligations confirmed by qualified legal counsel.
No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses risk management, governance and management accountability rather than a list of tools. NIS 2 requires measures across categories including risk analysis and information system security policies, incident handling, business continuity and backup management, supply chain security, security in acquisition and development, procedures to assess whether measures actually work, basic cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. This product contributes to a narrow slice of that: incident handling in the detection sense, basic cyber hygiene on virtual workstations through application, device and web control, and access control at device level. It contributes nothing to business continuity and backup, nothing to cryptography or multi-factor authentication, nothing to supply chain security, and nothing to the training and governance duties for which management is personally accountable. Whether your organisation falls in scope depends on the sector and size thresholds set at directive level and on how they have been transposed where you operate.
In March 2022 the German Federal Office for Information Security (BSI) issued a formal warning against the use of Kaspersky antivirus software and recommended replacing it with alternative products. That warning is still in force in 2026 and now sits under the amended warning provision of the BSI Act; it is a recommendation, not a prohibition, and Germany has not banned the software. In June 2024 the Bureau of Industry and Security at the US Department of Commerce issued a Final Determination prohibiting Kaspersky from providing cybersecurity products in the United States or to US persons, with new sales ending on 20 July 2024 and signature and codebase updates ending on 29 September 2024; that measure remains in force. Neither applies in Switzerland: the Federal Office for Cybersecurity (BACS) has stated that it issues no product recommendations, has no internal directive on Kaspersky, and has no indication of misuse in Switzerland, leaving the decision with each organisation. Kaspersky rejects the allegations, points to its Global Transparency Initiative with source code review in its transparency centres, to data processing in Switzerland, and to external audits including SOC 2 Type II and ISO/IEC 27001 certification covering its Zurich data centre, and has publicly asked the BSI to withdraw the warning. Independent detection testing by AV-TEST and AV-Comparatives has continued throughout and those results are unaffected by the regulatory measures. In practice this matters most if you bid for public sector contracts, have US operations or US customers, or answer supplier questionnaires that ask about vendor country of origin; for a purely Swiss or EU organisation without those constraints it is a risk decision rather than a legal obstacle.
Yes, for a specific and fairly narrow set of items. It answers questions about malware protection on end-user workstations, centrally enforced policies, application and device control, web and mail filtering, protection of non-persistent desktops that are rebuilt on every logon, role separation between helpdesk and security staff, and the existence of a central console that produces exportable event logs and reports. The items it leaves open are the ones most questionnaires weight heavily: with no EDR or managed detection component, questions on detection and response capability, mean time to detect, threat hunting and round-the-clock monitoring go unanswered; with no patch or vulnerability management, questions on patch service levels and remediation evidence go unanswered; with no encryption management, questions on data at rest go unanswered; and there is no multi-factor authentication, no backup, and no mobile device coverage. Vendor country of origin is a separate item, addressed in the section above. The cheaper route to closing these gaps is usually to stay inside the same vendor family and add a Kaspersky endpoint suite that includes vulnerability and patch management plus encryption management, and a dedicated Kaspersky detection and response product, rather than running two consoles from two vendors and doubling the agent conflicts on every image.
The decisive difference is hardening depth: only the Enterprise tier gives you application control on server operating systems, which is what a full default-deny implementation needs. Enterprise then adds the audit-oriented components on top, namely File Integrity Monitor and Log Inspection, which are typically the components an auditor asks for by name. Container image scanning and CI/CD pipeline integration are Enterprise only, so a host used for container security tasks has to carry an Enterprise licence. Enterprise also covers network-level intrusion prevention for VMware NSX and the optimisations for very large deployments. For a straightforward VDI estate that is not running default deny and not building containers, the standard tier behind this product is the tier that matches the workload.
| Component | Hybrid Cloud Security | Hybrid Cloud Security Enterprise |
|---|---|---|
| Application control, desktop OS | ✓ | ✓ |
| Anti-cryptor for shared folders | ✓ | ✓ |
| Application control, server OS | ✕ | ✓ |
| File Integrity Monitor | ✕ | ✓ |
| Log Inspection | ✕ | ✓ |
| Container security and CI/CD integration | ✕ | ✓ |
| IDS/IPS for VMware NSX | ✕ | ✓ |
| Large scale environment support | ✕ | ✓ |
The significant regional restriction is the United States, where the 2024 Final Determination bars sales to US persons and where signature and codebase updates stopped on 29 September 2024, so a Swiss or European group with US subsidiaries cannot standardise on this product across the whole estate. The Desktop object covers virtual workstations only, which means physical servers and virtual servers are a separate line on the order and a mixed VDI project normally needs both. Kaspersky ended technical support for the agentless deployment option on 31 July 2026, so VMware NSX estates originally built agentless have to move to the Light Agent architecture, which places an agent inside every guest operating system and changes the golden image. Missing components are the usual source of a follow-up purchase: there is no EDR, no patch or vulnerability management, no encryption management and no mobile coverage, each of which is a separate product. The product also assumes you run Kaspersky Security Center as a management server, an on-premises component you have to install, patch and back up yourself.
No. Base denotes a new licence rather than a renewal, so no existing licence of the same product is required. It does require Kaspersky Security Center as the management server, which is a separate installation in your own infrastructure.
No. The Desktop object covers virtual workstations in a virtual desktop infrastructure, both persistent and non-persistent. Physical PCs and notebooks need a Kaspersky endpoint product instead.
Kaspersky Security for Virtualization Light Agent supports VMware vSphere, Microsoft Hyper-V, Citrix Hypervisor, KVM, Proxmox VE, Nutanix Acropolis and OpenStack among others, and covers VDI on VMware Horizon, Citrix Virtual Apps and Desktops and Hyper-V. Check the current compatibility list against your exact hypervisor and guest OS versions before ordering, because individual platform entries change between releases.
| Operating Systems | Windows 11: Home / Pro / Pro for Workstations / Education / Enterprise Windows 10: Home / Pro / Pro for Workstations / Education / Enterprise / Enterprise multi-session Windows 8.1: Professional / Enterprise Windows 8: Professional / Enterprise Windows 7: Home / Professional / Ultimate / Enterprise Service Pack 1 or later |
| Processor | CPU 1 GHz workstation / SSE2 instruction set support |
| Memory RAM | Workstation x86: 1 GB / Workstation x64: 2 GB |
| Storage | 2 GB available disk space |
| Architecture | Arm architecture is not supported |