What are the core benefits of Kaspersky Security Awareness Essential Base?
Central console – One web console manages all training groups.
Automated assignment – Lessons, tests and phishing simulations run automatically.
Phishing simulator – Test staff before, during and after training.
Two courses – Detailed main course or short express course.
Per-employee reporting – Dashboard and one-click PDF for management.
Important note – This is training only, no antivirus included.
Automated Security Awareness Platform – Kaspersky ASAP, the online platform this licence covers.
Main course – Micro-lessons grouped into complexity levels for each risk group.
Express course – Short audio-video training to refresh basic cyber hygiene.
Phishing simulator – Simulated attacks before, during and after the training cycle.
Reporting and dashboards – Per-employee progress plus a one-click PDF for management.
Important – No antivirus, EDR, mail filtering or patch management included.
Kaspersky Security Awareness Essential Base is a licence for the Kaspersky Automated Security Awareness Platform (ASAP), the vendor's online training platform for employees. It is managed centrally from a browser console and runs as a cloud service or, where internal policy requires it, as an on-premises installation inside your own infrastructure.
Automated training cycle – Lessons, reinforcement, tests and simulations are assigned without admin work.
Active Directory and SSO – Enrols staff automatically instead of maintaining user lists manually.
Risk-based grouping – Rules sort staff by role, department or risk profile.
Evidence for auditors – Completion records per employee, exportable as a PDF report.
SIEM and XDR integration – Assign training from real security events via Kaspersky integrations.
Multi-tenant administration – Separate admin roles for subsidiaries or service provider clients.
Awareness training is bought for two different reasons: to cut the number of staff who click a phishing link, and to produce written evidence that training actually happened. The second reason is what usually decides the company size question, because evidence is what auditors, insurers and large customers ask for.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | ✕ | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | ✓ |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Automatic enrolment via Active Directory or SSO | Rarely needed | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partly |
Large organisations usually also want the executive workshop and the IT-staff course from the same Kaspersky Security Awareness portfolio, and those are separate programmes rather than part of this platform licence.
The reporting obligation under the revised Information Security Act has applied since 1 April 2025 and affects operators of critical infrastructure, for example energy and drinking water suppliers, transport companies, listed hospitals, data centre and cloud providers, and cantonal and communal administrations; the Cybersecurity Ordinance exempts organisations below defined sector thresholds, so most ordinary SMEs are not directly in scope. Those who are in scope must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report, and since 1 October 2025 a failure to report can be sanctioned with a fine of up to CHF 100,000. This platform supports that duty on one specific point: the incident-response modules and the phishing simulations train staff to recognise a suspicious email or a compromised account and to escalate it internally instead of staying quiet, which is what starts the 24-hour clock in the first place. What it does not do is detect the attack, produce the report, or supply the technical evidence BACS asks for, because it collects training data and not security telemetry, and a training completion record is proof of instruction, not proof of incident handling. Buyers subject to the obligation therefore still need detection, logging and a written incident response process alongside this licence. This text describes product capabilities and is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified legal adviser.
No software product makes a company compliant with the NIS 2 Directive, because the Directive addresses organisational risk management and management accountability rather than any single tool. NIS 2 requires a set of measure categories that includes risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cryptography, access control and multi-factor authentication, and basic cyber hygiene practices together with cybersecurity training. This platform maps to exactly one of those categories: basic cyber hygiene and training, delivered through the main course, the express course and repeated phishing simulations, with per-employee completion records that can be exported as evidence of the training measure. It contributes nothing to incident handling, continuity and backup, supply chain controls, vulnerability handling, cryptography, access control or multi-factor authentication, and it does not cover the separate NIS 2 expectation that management bodies themselves undergo training, since the executive programme is a different Kaspersky offering. Treat it as one documented building block in a NIS 2 programme, not as the programme.
Two official measures are relevant and both are still in force. In March 2022 the German Federal Office for Information Security (BSI) issued a public warning recommending that Kaspersky antivirus software be replaced with alternative products; it was not a sales ban, the products remain legally available in Germany, Switzerland and the European Union, and as of early 2026 the BSI has confirmed it maintains the warning and that its reasons are unchanged. Separately, on 20 June 2024 the US Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting Kaspersky from providing antivirus and cybersecurity products or services in the United States or to US persons, with new sales stopping on 20 July 2024 and updates ending on 29 September 2024, and it added three Kaspersky entities to the Entity List. Kaspersky rejects the allegations, states that the decision reflects the geopolitical climate and theoretical concerns rather than an evaluation of its products, and had offered independent third-party verification of its software; the company also states that the US determination does not affect its ability to sell training offerings in the United States. It is worth noting factually that the BSI warning is directed at antivirus software with deep system access, whereas this licence covers a browser-delivered training platform. The buyers this actually affects in practice are those bidding for public-sector contracts, those with US parent companies or US persons in scope, and those whose large customers screen suppliers against sanctions and country-of-origin criteria in their questionnaires; if none of those apply to you, the measures have no direct operational effect on a Swiss or EU purchase, and you should make the call yourself.
Yes, but only for the training block, which is typically three or four questions out of forty. It answers, with exportable evidence: whether all staff receive security awareness training, whether the training is recurring rather than a one-off induction, whether phishing resistance is tested by simulation, whether training is differentiated by role or risk, and whether completion is tracked per individual. The underlying competency model covers more than 500 practical skills across topics including phishing and vishing, passwords and accounts, confidential and personal data, mobile devices, social media, supply chain attacks and incident reporting, and lessons map to MITRE ATT&CK techniques, which is useful when a questionnaire asks what the training is actually based on. It answers nothing about endpoint protection, backup and restore testing, patch and vulnerability management, encryption of laptops, multi-factor authentication, log retention, access reviews or a documented incident response plan, and it cannot show that management itself was trained. The cheapest way to close the training-adjacent gaps is usually to stay inside one vendor family rather than mixing suppliers: pair this licence with a Kaspersky endpoint or EDR product for the technical questions, and add the executive workshop from the same Security Awareness portfolio if the questionnaire asks about board-level awareness.
The decisive limitation is scope: this is a training platform and nothing on it scans, blocks or removes anything, so a phishing email that reaches an inbox is still delivered and a trained employee who clicks it is still infected. It does not replace endpoint protection, mail filtering, EDR, encryption or patch management, and it produces no security telemetry, which means it cannot feed an incident report or an audit trail of technical controls. Reporting is training reporting: dashboards show progress, delays and underperformance per employee and generate a PDF for management, but they will not tell you which device was compromised. The executive workshop, the interactive team simulation for decision-makers and the first-level incident response course for generalist IT staff belong to the wider Kaspersky Security Awareness portfolio and are bought separately, which is the most common follow-up purchase for larger organisations. Finally, the practical outcome depends on running the cycle repeatedly rather than once, so budget for it as an ongoing programme, not a single rollout.
Yes. Alongside the standard SaaS delivery, Kaspersky offers the platform as an on-premises installation on the customer's own servers, and Kaspersky states that this variant can operate without an internet connection. This is aimed at organisations whose internal policy or sector regulation rules out cloud-hosted training.
Yes. Administrators can add their own logo, brand the completion certificates, enrich lessons with internal slides, documents or company policies, upload custom SCORM and PDF modules, and adjust the structure of tests. That makes it possible to train your own acceptable-use or data-handling policy in the same cycle as the standard content.
The platform interface and course content are localised into a range of languages including German, French, Italian and English, which covers the usual Swiss multilingual case where staff in different regions need the same programme in their own language. Phishing simulation templates are available in the platform languages as well, so the simulated emails are not obviously foreign to the recipient.
| Operating Systems | Desktop computers: Windows 10 Desktop computers: Windows 7 Desktop computers: Mac OS latest version at launch Mobile devices: iOS latest version Mobile devices: Android 5 or later |
| Web Browser | Microsoft Edge latest version at launch / Mozilla Firefox latest version at launch / Google Chrome latest version at launch / Safari for Mac OS latest version at launch / Safari iOS / Google Chrome Android |
| End User Processor | 1 GHz |
| End User Memory RAM | 1 GB |
| End User Network | Network bandwidth 1 Mb/s |
| End User Storage | 20 MB available disk space |
| Admin Operating Systems | Windows 10 / Windows 7 / Mac OS latest version at launch |
| Admin Web Browser | Microsoft Edge latest version at launch / Mozilla Firefox latest version at launch / Google Chrome latest version at launch / Safari for Mac OS latest version at launch |
| Email Client | Apple Mail 10 or later / Microsoft Outlook 2010 or later for Windows / Microsoft Outlook 2010 or later for macOS |
| Web Email Client | Gmail / Google Apps / Office 365 / Outlook.com / Yahoo! |
| Admin Processor | 1.5 GHz |
| Admin Memory RAM | 2 GB |
| Admin Network | Network bandwidth 1 Mb/s |
| Admin Storage | 20 MB available disk space |