What are the core benefits of Kaspersky Hybrid Cloud Security Enterprise Server Base Plus?
Central management – All servers managed from Kaspersky Security Center.
Hybrid coverage – Protects physical, virtual and public cloud servers.
Application control – Default deny lockdown for server operating systems.
Integrity monitoring – File integrity monitoring and log inspection included.
Container scanning – Container image scanning for CI/CD pipelines.
Important note – EDR is not included and licensed separately.
Server workload protection – Covers physical, virtual and public cloud servers under one licence.
Application control – Default deny lockdown for Windows and Linux server operating systems.
File integrity monitoring – Flags changes to critical system files and configuration data.
Patch management – Automated vulnerability assessment and patch distribution for protected servers.
Container security – Scans container images and registries before they reach production.
Important – No EDR component; it requires a separate Kaspersky licence.
This is the Enterprise tier of Kaspersky's server workload product, licensed per server and administered centrally through Kaspersky Security Center rather than machine by machine. It includes the Kaspersky Security for Virtualization components that many buyers still search for under that older name, and Kaspersky now groups the product with Kaspersky Container Security under its Cloud Workload Security offering; it is sold as a base licence, not as a renewal or an upgrade from the Standard edition.
One console – Physical, virtual and cloud servers under one policy set.
Light agent design – Lower virtualization overhead than a full endpoint agent.
Ransomware rollback – Reverses encryption of shared folders after a blocked attack.
Default deny hardening – Restricts servers to a known good application list.
SIEM export – Forwards server security events into an existing SIEM.
Multi-tenant management – Separate customer views for providers and group IT departments.
The Enterprise tier earns its price where a server estate is genuinely mixed: bare metal in a rack, virtual machines on a hypervisor, and workloads in AWS, Azure or Google Cloud, all needing one policy and one audit trail. A company running two Windows file servers rarely needs application control in default deny mode or container image scanning, and is served better by the Standard edition. The dividing line is not headcount but whether anyone in the organisation has to prove, in writing, what runs on a server and what changed on it.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Mixed physical, virtual and cloud servers | Rarely | ✓ | ✓ |
| This product fits | Limited | ✓ | ✓ |
No security product meets those requirements on its own, because the obligation falls on the organisation and not on the software. Since 1 April 2025 the revised Information Security Act obliges operators of critical infrastructure to report significant cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report; fines have applied since 1 October 2025. What the product contributes to that deadline is evidence: file integrity monitoring records which system files changed and when, log inspection surfaces tampering in server logs, and the Kaspersky Security Center console exports those events to a SIEM so the initial report is not assembled from memory. What it does not do is decide whether an incident is reportable, submit the report, or cover anything outside the servers it protects, so laptops, mailboxes and network devices remain outside its evidence trail. It also provides no encryption management and no mobile device coverage, both of which appear in the broader organisational measures expected of critical infrastructure operators. This text is commercial information and not legal advice; whether your organisation falls within the reporting obligation should be confirmed with your own legal counsel.
No product creates NIS 2 compliance, because the directive requires management accountability, documented processes and supply chain governance alongside technical controls. The NIS 2 Directive requires measures in categories including risk analysis and information system security, incident handling, business continuity and backup management, supply chain security, vulnerability handling and disclosure, and the use of cryptography where appropriate. This product maps directly onto two of those categories: vulnerability handling, through its vulnerability assessment and patch distribution for protected servers, and information system security, through default deny application control and file integrity monitoring on server operating systems. It contributes partial evidence for incident handling, since its console and SIEM export document detection and response actions on the server layer. It does not address business continuity or backup management at all, provides no cryptography or key management function, and does nothing for supply chain governance, which remains a contractual and organisational task.
Switzerland has issued no warning and no ban. The Federal Office for Cybersecurity (BACS) has stated that no misuse of Kaspersky protection software has been reported to it in Switzerland, that it holds no internal directive against the software, and that it would inform the public if it obtained confirmed evidence of misuse; as a matter of policy it does not issue product recommendations. In Germany, the Federal Office for Information Security (BSI) published a warning against the use of Kaspersky virus protection software on 15 March 2022, which remains in force and is now regulated under Section 13 of the amended BSI Act since 6 December 2025. In the United States, the Department of Commerce issued a Final Determination in June 2024 prohibiting new sales from 20 July 2024 and the supply of updates to US customers from 29 September 2024. Kaspersky's own position is that the German warning is not justified and was not based on an objective technical analysis of its products, and it has continued to pursue legal remedies; the company operates a transparency centre in Opfikon near Zurich where source code can be reviewed. Independent laboratory testing has continued in parallel, and Kaspersky products have gone on being submitted to and rated by AV-TEST and AV-Comparatives. Practically, this matters most to buyers bidding for public sector contracts, to Swiss subsidiaries of German parent companies whose group policy follows BSI guidance, and to suppliers whose customers impose country-of-origin clauses; for a Swiss company with no such exposure, no authority currently restricts the purchase.
Yes, for the server and workload sections, and not much beyond them. It answers questions on malware protection for servers, application whitelisting and default deny configuration, integrity monitoring of critical files, log review, vulnerability scanning and patch distribution cadence, role-based administrative access, and forwarding of security events to a SIEM. Container image scanning lets you answer the build pipeline questions that increasingly appear in questionnaires from software customers. It leaves several standard blocks unanswered in equal measure: there is no endpoint detection and response capability, so questions on threat hunting, root cause analysis and retained telemetry cannot be answered from this product; there is no disk or file encryption management, so the data-at-rest section stays empty; there is no mobile device management; there is no backup or recovery function, so business continuity questions must be answered from another tool; and email and collaboration platform security is out of scope entirely. Closing those gaps is usually cheaper inside the same vendor family than by mixing suppliers, because a second console means a second set of policies, a second reporting format and a second integration to maintain: EDR is available as a separate Kaspersky licence that installs a key alongside the existing one, and encryption and mobile coverage sit in Kaspersky's endpoint product line rather than in the workload line.
The decisive difference is application control for server operating systems: only the Enterprise tier can lock a server down in default deny mode, which is the control most often demanded in hardening baselines and audit findings. Both tiers share the same detection engine, cloud API integration with AWS and Azure, and the same anti-cryptor protection for shared folders, so the Standard tier is not weaker at blocking malware. Enterprise adds the evidence and hardening layer on top: file integrity monitoring, log inspection, container security with its integration interfaces, next generation IDS/IPS for VMware NSX, and large scale environment support for tuning data exchange and load balancing in very large deployments. Kaspersky documents an upgrade path from the Server licensing model of the Standard tier to the Server licensing model of Enterprise, so starting on Standard does not strand you. Container security and DevOps integration require an Enterprise tier licence on the host where the agent runs, which is the single most common reason buyers move up.
| Capability | Standard | Enterprise |
|---|---|---|
| Cloud API integration with AWS and Azure | ✓ | ✓ |
| Anti-cryptor for shared folders | ✓ | ✓ |
| Application control for server OS | ✕ | ✓ |
| File integrity monitoring | ✕ | ✓ |
| Log inspection | ✕ | ✓ |
| Container security and integration interfaces | ✕ | ✓ |
| Next generation IDS/IPS for VMware NSX | ✕ | ✓ |
| Large scale environment support | ✕ | ✓ |
| Endpoint detection and response | ✕ | Separate licence |
The most important regional limitation concerns the United States, where the Department of Commerce prohibited new sales of Kaspersky products from 20 July 2024 and the delivery of updates to US customers from 29 September 2024; a Swiss or European company with US subsidiaries or US-based servers cannot cover those systems with this licence. The agentless deployment option is gone: Kaspersky ended technical support for Kaspersky Security for Virtualization Agentless on 31 July 2026 and directs customers to the Light Agent deployment, which is already covered by the licence but requires an agent inside each protected machine rather than a security virtual appliance. The absence of an EDR component is the limitation that most often triggers a follow-up purchase, because prevention logs alone will not answer an auditor asking how an incident was investigated. Coverage is also narrower than the product name suggests to some buyers: this licensing scope covers physical and virtual servers, not virtual desktops, which are licensed under a separate object, and it provides no encryption management, no mobile device coverage and no email gateway or mailbox protection.
No. The Server licensing object covers physical servers together with virtual servers. Virtual desktops fall under the separate Desktop licensing object in the same product family, and Kaspersky permits the Desktop variant to be purchased alongside Enterprise Server without special approval.
Yes. Kaspersky documents an upgrade path from Hybrid Cloud Security Server to Hybrid Cloud Security Enterprise Server, and the equivalent path for the CPU licensing model. Running a mixture of Standard and Enterprise licences across the same infrastructure requires prior approval from Kaspersky.
No, they are two products within the same Cloud Workload Security offering. The Enterprise tier includes container security and the integration interfaces needed to hook image scanning into a CI/CD pipeline, and Kaspersky requires an Enterprise tier licence on any host performing those tasks. Kaspersky Container Security is a separate product aimed at runtime protection of orchestrators and nodes.