What are the key advantages of Kaspersky Hybrid Cloud Security Desktop Base?
Central management – One console for virtual desktops and cloud workloads.
Light agent – Scanning moves to a dedicated secure virtual machine.
Virtual desktops – Covers persistent and non-persistent VDI machines alike.
Remediation engine – Rolls back malicious changes inside the guest OS.
Endpoint controls – Device, web and application control per desktop.
Important note – Patch management and SIEM export need the Enterprise tier.
Light Agent protection – File, process and memory protection inside each virtual desktop.
Secure virtual machine – Holds the scan engine and databases on each hypervisor.
Endpoint controls – Device, web and application control for desktop operating systems.
Network protection – Host IPS, IDS and firewall management on each machine.
Anti-Cryptor for shares – Blocks encryption of shared folders from an infected machine.
Important – Vulnerability assessment, patch management and SIEM connectors require the Enterprise tier.
Kaspersky Hybrid Cloud Security Desktop Base is a first-purchase licence for the Standard tier, counted per virtual desktop and managed centrally through Kaspersky Security Center. It grew out of the Kaspersky Security for Virtualization line that many buyers still search for by name, and KSV Light Agent remains the component installed inside each protected desktop.
Console consolidation – One policy set covers virtual desktops and cloud workloads.
Lower resource use – Light agents cut resource consumption by up to 30 percent.
Non-persistent coverage – The licence counts persistent and non-persistent virtual desktops alike.
Platform independence – Runs on vSphere, Hyper-V, KVM, Proxmox and Nutanix Acropolis.
Migration headroom – The same licence activates Kaspersky Endpoint Security for Business.
Multitenancy mode – Service providers can separate tenant infrastructures in one deployment.
The deciding factor is not headcount but whether you actually run virtual desktops. The Desktop licensing object counts virtual desktops, so a company with only physical PCs is buying the wrong licensing object no matter how many employees it has.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Virtual desktop infrastructure in use | Rare | ✓ | ✓ |
| This product fits | Only with VDI | ✓ | ✓ |
The Swiss reporting obligation does not apply to every company, only to operators of critical infrastructure: since 1 April 2025 the revised Information Security Act requires organisations such as energy and drinking water suppliers, transport companies and cantonal and communal administrations to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. Where your virtual desktops fall inside that scope, the part of the obligation this product supports is discovery and documentation: Light Agent detections, task results and per-machine reports in Kaspersky Security Center supply the timestamp, the affected virtual machine and the detection verdict that an initial report needs within one working day. What it does not do is equally concrete. It sees only the virtual desktops you licensed, so an incident that starts on a physical server, a network device or an unlicensed workload is invisible to it, and the Standard tier has no SIEM connector, so the correlated log trail an incident report benefits from must be built elsewhere. It also cannot tell you whether you are in scope at all, because the Cybersecurity Ordinance sets sector thresholds and exemptions that no software evaluates for you. This is not legal advice; whether the reporting obligation applies to your organisation should be clarified with a qualified legal adviser.
No product creates NIS 2 compliance, because the directive addresses organisational measures and management accountability, not software features. NIS 2 requires categories of measures including risk analysis and security policies, incident handling, business continuity and backup management, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, basic cyber hygiene and training, cryptography, access control, and multi-factor authentication. This product contributes to two of those categories for virtual desktops specifically: incident handling, through malware detection and rollback of malicious changes inside the guest operating system, and cyber hygiene, through device control, web control, application control and host firewall policies enforced centrally rather than per machine. The gaps are wide and worth naming before purchase. It contributes nothing to backup and business continuity, nothing to supply chain security, and nothing to multi-factor authentication, and in the Standard tier it has no vulnerability handling and no patch management, which the directive lists explicitly under security in acquisition, development and maintenance.
Two official assessments are relevant and both are still in force. Germany's Federal Office for Information Security issued a formal warning on 15 March 2022 recommending that Kaspersky antivirus software be replaced with alternative products; the office has confirmed since that its assessment has not changed, and the warning is now anchored in section 13 of the German BSI Act following the revision that took effect on 6 December 2025. There is no sales ban in Germany. In the United States, the Department of Commerce's Bureau of Industry and Security issued a Final Determination on 20 June 2024 prohibiting new sales from 20 July 2024 and signature or code-base updates after 29 September 2024, and added AO Kaspersky Lab, OOO Kaspersky Group and Kaspersky Labs Limited to the Entity List. Switzerland has taken a different position: the Federal Office for Cybersecurity has issued no warning against Kaspersky, states that no misuse has been reported in Switzerland, and does not issue product recommendations either way. Kaspersky rejects the assessments as politically rather than technically grounded, points out that no security vulnerability was demonstrated in its software, and refers to its Zurich data centres processing European user data since 2018, its Zurich Transparency Center, a SOC 2 audit by a Big Four auditor and ISO 27001 certification by TÜV Austria. Independent laboratory testing of Kaspersky products by AV-TEST and AV-Comparatives has continued throughout. In practice this matters most in three situations: public sector tenders, supply chain questionnaires from customers who reference the German warning, and any group with United States entities, which cannot be covered by this licence at all. For a purely Swiss commercial environment with no such contractual exposure, it is a risk assessment your own management makes, not a legal barrier.
Partly, and the split is predictable. It answers the endpoint protection block cleanly: anti-malware on every virtual desktop with centrally enforced policy rather than local configuration, behavioural detection and exploit prevention, rollback of malicious changes, removable media and device control, web control, application control on desktop operating systems, host firewall and intrusion prevention, and a per-machine protection status report you can attach as evidence. It does not answer the blocks that questionnaires increasingly weight most heavily. There is no endpoint detection and response component, so questions on detection coverage, alert triage and root-cause analysis stay unanswered. There is no vulnerability or patch SLA evidence, no log retention or SIEM export, no disk or removable media encryption, no multi-factor authentication, no backup and restore testing, no mobile device coverage, and no server coverage unless you license the Server or CPU object separately. For most of these, moving up to the Enterprise tier of the same family is the cheaper route than mixing vendors, because it adds vulnerability assessment and patch management, SIEM connectors, file integrity monitoring and log inspection under one console and one support contract. Encryption, multi-factor authentication and backup will require separate products regardless of tier, so plan those as their own line items rather than expecting a tier upgrade to close them.
The single most decisive difference is vulnerability assessment and patch management, which sits in the Enterprise tier only and is the capability most often assumed to be included. Everything the Standard tier offers is protection and control at the moment of attack; the Enterprise tier adds the evidence and hardening layer around it, namely SIEM connectors, file integrity monitoring, log inspection and application control for server operating systems. Both tiers share the same core protection engine, so an upgrade changes scope rather than detection quality. Container security and DevOps integration are also Enterprise-only, which matters if the same infrastructure later hosts build pipelines.
| Capability | Standard | Enterprise |
|---|---|---|
| File, process and memory protection | ✓ | ✓ |
| Application control for desktop OS | ✓ | ✓ |
| Vulnerability assessment and patch management | ✕ | ✓ |
| SIEM connectors | ✕ | ✓ |
| File integrity monitoring and log inspection | ✕ | ✓ |
| Container security and DevOps integration | ✕ | ✓ |
| Sale and updates in the United States | ✕ | ✕ |
The regional restriction is absolute rather than partial: Kaspersky software cannot be sold to or updated for United States persons following the Commerce Department determination, so a Swiss or European group with American subsidiaries cannot cover those seats with this licence and needs a second vendor for that region. On the technical side, this is not an install-and-forget agent; the architecture requires a secure virtual machine to be deployed on each hypervisor, which is what holds the scan engine and databases and is also the component administrators most often report needing to redeploy after version changes. There is a version split that catches VDI buyers off guard: Kaspersky Security for Virtualization 6.x Light Agent protects Linux guest operating systems, while Windows guest desktops are protected by the Light Agent for Windows component from version 5.2, so a mixed estate runs two agent generations. Agentless protection is no longer a fallback, because technical support for KSV Agentless ended on 31 July 2026 and Kaspersky directs customers to Light Agent, which the licence already covers. Finally, the Desktop licensing object counts virtual desktops only, so physical servers, virtual servers and cloud instances are separate purchases under the Server or CPU object and are the most common follow-up cost.
Base identifies the licence type for a first purchase, as distinct from a Renewal or an Add-on. It is not a reduced feature level, and it does not require an existing licence; the feature scope is set by the tier, Standard or Enterprise.
The Desktop object counts virtual desktops, both persistent and non-persistent. Kaspersky does allow Desktop and Server licences to activate Kaspersky Endpoint Security for Business applications, which is how a phased migration from physical desktops to VDI is supported without buying twice.
Kaspersky Security for Virtualization Light Agent supports VMware vSphere, Microsoft Hyper-V, KVM, Proxmox VE, Nutanix Acropolis and further platforms. On the VDI broker side, Windows and Linux guest systems are supported in VMware Horizon, Citrix Virtual Apps and Desktops and Hyper-V environments.
No. Neither tier of Kaspersky Hybrid Cloud Security includes endpoint detection and response. Telemetry retention, alert triage and root-cause analysis require a separate product from the Kaspersky Next EDR or XDR line, which is the usual answer when a customer questionnaire asks about detection and response coverage.
| Operating Systems | Windows 11: Home / Pro / Pro for Workstations / Education / Enterprise Windows 10: Home / Pro / Pro for Workstations / Education / Enterprise / Enterprise multi-session Windows 8.1: Professional / Enterprise Windows 8: Professional / Enterprise Windows 7: Home / Professional / Ultimate / Enterprise Service Pack 1 or later |
| Processor | CPU 1 GHz or higher / SSE2 instruction set support |
| Memory RAM | Workstation 32-bit: 1 GB / Workstation 64-bit: 2 GB |
| Storage | 2 GB available disk space |
| Architecture | Arm architecture is not supported |