What are the key advantages of Kaspersky Security for Storage Server Base Plus?
Central management – All storage policies run from Kaspersky Security Center.
NAS integration – Connects via ICAP, RPC or EMC CAVA.
Ransomware defence – Blocks crypto-malware on NetApp through FPolicy.
On-access scanning – Every file read or written is checked.
Load balancing – Several scan servers share one storage system.
Important note – No endpoint, EDR or patch management included.
NAS protection engine – Scans files on NetApp, Dell EMC, Hitachi, IBM and Oracle storages.
ICAP and RPC connectors – Link the storage system to the scanning server.
NetApp FPolicy integration – Real-time anti-ransomware for NetApp ONTAP volumes.
Kaspersky Security Center – On-premises console for policies, tasks, reports and alerts.
Quarantine and backup – Stores an untouched copy before any disinfection or deletion.
Important – No EDR, patch management or encryption is included here.
Kaspersky Security for Storage Server Base Plus is an anti-malware licence for network attached storage systems and Windows file servers, delivered through the Kaspersky Security for Windows Server application, which is the name administrators actually see at installation. It is managed centrally from the on-premises Kaspersky Security Center console rather than configured storage system by storage system.
No endpoint dependency – Files stay scanned even when uploaded by unmanaged devices.
Storage stays responsive – iSwift and iChecker skip files already scanned and unchanged.
Three security levels – Switch between maximum performance, recommended and maximum protection.
Fault-tolerant scanning – Several scan servers share the load for one storage.
Evidence-ready reporting – Console reports and event logs document every single detection.
Granular admin rights – Separate privilege levels per protected server administrator.
Suitability follows the storage architecture, not the headcount. If files sit on a NAS appliance or a central file share that several people write to, this product has something to protect. If everything lives on individual laptops or in a SaaS service, it does not.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | ✕ | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Central NAS or file share in daily use | Sometimes | ✓ | ✓ |
| This product fits | If NAS present | ✓ | ✓ |
Not on its own, and no security product does. Under the revised Information Security Act (ISG), operators of critical infrastructure in Switzerland — among them energy and drinking water utilities, transport operators, listed hospitals, data centre and cloud providers, and cantonal and municipal administrations — must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Towards that deadline the product delivers the detection event and the file-level detail: the console records which storage system, which file and which verdict triggered the alert, which is usually the first hard fact an initial report needs. What it does not deliver is the attack path — there is no endpoint telemetry, no process tree and no root-cause analysis, so working out how the malware reached the share needs a separate tool. It also does not judge whether an incident is reportable, and it leaves endpoints, mailboxes and identity systems uncovered, which is where reportable incidents usually start. This text is not legal advice, and whether your organisation falls under the reporting obligation should be assessed formally and documented in writing.
No product creates NIS 2 compliance for a buyer, because the directive addresses organisational risk management rather than software features. The NIS 2 Directive requires essential and important entities to implement measures across defined categories: incident handling, business continuity and backup management, supply chain security, access control and asset management, cryptography, vulnerability handling, security testing, staff training, and reporting of significant incidents to the competent authority. This product maps onto exactly one of those categories and part of a second: malware protection for stored data, and the detection half of incident handling for files written to protected storage. It contributes nothing to backup and recovery, business continuity planning, encryption, access control and multi-factor authentication, supply chain assessment, vulnerability handling or staff training, and it produces no incident report on its own. Buyers in scope should treat it as one control inside a management system, not as a substitute for one.
Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022; the warning is now issued under Section 13 of the BSI Act, the authority reviewed and maintained it again in 2026, and it is a recommendation to replace the software, not a sales ban. In the United States, the Department of Commerce's Bureau of Industry and Security issued a Final Determination in June 2024 prohibiting Kaspersky from supplying cybersecurity and antivirus products to US persons, and from delivering updates to existing US installations after 29 September 2024. Kaspersky rejects the reasoning, states that the assumed risks have remained hypothetical with no confirming security incident, points to its Global Transparency Initiative and its data processing in Switzerland, and has formally asked the BSI to withdraw the warning while reserving legal steps. Independent laboratory testing is a separate track: Kaspersky products have continued to appear in AV-TEST and AV-Comparatives test cycles through 2025 and 2026, and those results are unaffected by the regulatory measures. In practical terms this matters for public sector tenders, for operators of critical infrastructure, for subsidiaries bound by a German or US parent company policy, and for suppliers whose customers screen vendor country of origin; in Switzerland and the European Union the product remains on sale and fully updated.
Partly, and it is worth knowing which lines it actually fills in. It answers the items on malware protection for stored data: on-access scanning of every file read from or written to the protected storage, scheduled on-demand scans, central policy enforcement from a single console, separated administrator privilege levels, and an exportable detection record that can be attached as evidence. It answers none of the items on endpoint protection, endpoint detection and response, vulnerability and patch status, disk or file encryption, multi-factor authentication, mobile device management, email filtering, or tested backup and restore — and a questionnaire asking for incident response times will not accept a detection log as an answer. The cheaper route to closing those gaps is usually to add an endpoint tier from the same vendor family, such as Kaspersky Next EDR Optimum, rather than mixing vendors, because a second management console doubles the reporting work for every future questionnaire. Be aware that questionnaires from large customers increasingly ask about vendor country of origin and regulatory status; the section above sets out what is on record there.
The most important one is regional: following the US Final Determination, the product is not available to buyers in the United States, while it remains on sale and fully updated in Switzerland and the European Union — relevant if you operate a US subsidiary and were planning one standard across all sites. The scanning component runs on Windows Server, so a Linux-only environment cannot host the protection for its NAS. Storage compatibility is version-specific rather than vendor-specific: NetApp Data ONTAP, Dell EMC Celerra and VNX via the CAVA agent, Dell EMC Isilon on OneFS, Hitachi HNAS, IBM System Storage N series, Oracle ZFS Storage Appliance, Dell Compellent FS8600 and HPE 3PAR with File Persona are supported at documented minimum versions, so an older firmware release is the usual reason an integration fails. On ICAP-connected storages there is a known behaviour to plan around: when the Kaspersky Security Network returns an untrusted verdict, the application cannot delete or block the file, because it has no direct access to the storage system's network folders. Finally, this is detection and removal, not recovery — it does not roll back or restore files that ransomware has already encrypted, which is the single most common reason for a follow-up purchase.
Not on the storage appliance. A Windows Server hosts the Kaspersky scanning service, and the NAS hands files over to it via ICAP, RPC or the EMC CAVA agent for a verdict. Where one scan server cannot keep up, several can be connected to the same storage system, which then distributes the requests between them.
Yes. The same application protects file operations on a conventional Windows file server directly, without any ICAP or RPC connection, which is the common case for companies that have a central file share but no dedicated NAS hardware.
Base Plus is an initial licence type in Kaspersky's business licensing scheme, not a renewal of an existing one, and it does not require any other Kaspersky base product to work. Note that the licence must permit network attached storage protection; without that entitlement the NAS protection tasks start but return an error instead of scanning.
| Operating Systems | Windows Server 2019: Essentials / Standard / Datacenter Windows Server 2019 Core Windows Storage Server 2019 Windows Hyper-V Server 2019 Windows Server 2016: Essentials / Standard / Datacenter Windows Server 2016 Core: Standard / Datacenter Windows Server 2016 MultiPoint Microsoft Windows MultiPoint Server 2016 Windows Storage Server 2016 Windows Hyper-V Server 2016 Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter Windows Server 2012 R2 Core: Foundation / Essentials / Standard / Datacenter Windows Storage Server 2012 R2 Windows Hyper-V Server 2012 R2 Windows Server 2012: Foundation / Essentials / Standard / Datacenter Windows Server 2012 Core: Foundation / Essentials / Standard / Datacenter Windows Storage Server 2012 Windows Hyper-V Server 2012 Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter SP1 or later Windows Server 2008 R2 Core: Standard / Enterprise / Datacenter SP1 or later Windows Hyper-V Server 2008 R2 SP1 or later Windows Server 2008: Standard / Enterprise / Datacenter SP1 or later Windows Server 2008 Core: Standard / Enterprise / Datacenter SP1 or later Microsoft Small Business Server 2011: Essentials / Standard Microsoft Small Business Server 2008: Standard / Premium Microsoft Windows MultiPoint Server 2012: Standard / Premium Microsoft Windows MultiPoint Server 2011: Standard / Premium Windows Server 2003: Standard / Enterprise / Datacenter SP2 or later Windows Server 2003 R2: Foundation / Standard / Enterprise / Datacenter SP2 or later Windows 10 Enterprise multi-session |
| Processor | x86 or x64 compatible system / 1.4 GHz single-core minimum / 2.4 GHz quad-core recommended |
| Memory RAM | 1 GB minimum / 2 GB recommended |
| Storage | 4 GB free disk space / 100 MB for installing all application components / 2 GB recommended for antivirus databases / 400 MB recommended for quarantine and backup / 1 GB recommended for logs |