What are the core benefits of Kaspersky Security for Storage Server Base?
Central management – All storage nodes controlled from Kaspersky Security Center.
NAS coverage – EMC, NetApp, Dell, Hitachi, Oracle and IBM.
On-access scanning – Every file checked when launched or modified.
Anti-Cryptor protection – Blocks hosts encrypting NetApp shares via FPolicy.
Base licence – New standalone purchase, not a renewal.
Important note – No EDR, patch management or encryption included.
Storage protection engine – Scans NAS files on access and on demand.
Kaspersky Security Center – Central console for installation, policies, updates and reports.
Multi-protocol NAS integration – Connects through the CAVA agent, RPC and ICAP.
Anti-Cryptor for NetApp – Blocks a host that starts encrypting NetApp shares.
Quarantine and backup – Unmodified copy stored before any action on an object.
Important – No EDR, patch management, encryption or mobile components.
Kaspersky Security for Storage is a dedicated anti-malware layer for network attached storage and Windows file servers, delivered as Kaspersky Security for Windows Server together with the Kaspersky Security Center console. The earlier generation was sold as Kaspersky Anti-Virus for Storage, and Base here means a new stand-alone licence rather than a renewal or an add-on to an existing licence.
Scanning off the endpoint – NAS files checked without an agent per client.
Ransomware host blocking – Encrypting hosts are blocked, then unblocked after 30 minutes.
Scan load control – Trusted zones and iSwift or iChecker reduce rescans.
Fault tolerant operation – The service restarts automatically after a forced shutdown.
Role based administration – Privilege levels assigned per server administrator account.
Evidence capable reporting – Graphical reports plus Windows and console event logs.
The deciding factor is not headcount but whether a NAS appliance or a central file server actually holds your working data. A company with ten staff and a NetApp or Hitachi appliance has a stronger case for this product than a company with two hundred staff whose files sit entirely in a cloud service.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Usually |
| NIS 2 in the European Union | Rarely | By sector | Usually |
| Security questionnaire from large customers | ✕ | ✓ | ✓ |
| Dedicated NAS or central file server in use | Sometimes | ✓ | ✓ |
| This product fits | Only with NAS | ✓ | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company: energy and drinking water suppliers, transport operators, listed hospitals, data centre and cloud providers, and cantonal or communal administrations are the typical addressees, with thresholds in the Cybersecurity Ordinance exempting smaller organisations. Since 1 April 2025 those organisations must report a significant cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. What this product contributes to that deadline is detection evidence: an encryption attempt on a protected NetApp share raises a critical event, blocks the originating host and writes a timestamped entry to the Kaspersky Security Center log, which is exactly the material a first report needs within one day. What it does not contribute is the process around it, because it does not determine whether you are subject to the obligation, does not produce the report, and does not see endpoints, mail or identity systems where most incidents actually begin. It also gives no attack timeline beyond file operations on storage, so root cause work still depends on other logs. This text is not legal advice, and whether your organisation falls under the reporting obligation should be assessed with your own legal counsel.
No product makes an organisation NIS 2 compliant, because the directive places obligations on entities and their management, not on software. NIS 2 requires categories of measure including risk analysis and security policies for information systems, incident handling, business continuity and backup management, supply chain security, and procedures to assess whether the measures are effective. This product maps to two of those: it is a technical protection measure for stored data, and its logging and host blocking feed incident handling. It contributes nothing to backup and recovery, nothing to supply chain assessment of your own suppliers, nothing to governance or management training, and nothing to vulnerability handling. For an entity in scope, storage anti-malware is one control in a much larger set, and the gaps above have to be closed with separate tooling and documented processes.
On 15 March 2022 the German Federal Office for Information Security (BSI) published a product warning against the use of Kaspersky antivirus software, reasoning that antivirus products hold deep system rights and therefore require trust in the manufacturer's reliability and independent capacity to act. The warning is still in force in 2026 and is now governed by Section 13 of the amended BSI Act, which took effect on 6 December 2025. Kaspersky rejects the assessment, states that it rests on political rather than technical grounds, has formally asked the BSI to withdraw it, and reserves the right to take legal steps. Separately, the United States Bureau of Industry and Security prohibited new sales in 2024 and antivirus updates from 29 September 2024, and added Kaspersky entities to the Entity List, which is why the product is neither sold nor updatable there. In Germany and Switzerland this is a recommendation rather than a ban, so the practical question is contractual: public sector tenders, critical infrastructure operators and supplier questionnaires from large customers increasingly ask about vendor country of origin, and a company facing those clauses will find this product hard to defend regardless of its technical merits. A company without such clauses is under no legal restriction, and the decision belongs to the buyer.
Partly, and the gaps are as important as the answers. It answers questions on malware protection for storage systems, on ransomware protection for network shares, on centrally enforced policies, on role-based administrator rights, on automatic signature updates, and on logging and reporting, because reports can be exported from Kaspersky Security Center and from the Windows event log. It does not answer questions on endpoint detection and response, on vulnerability and patch management, on encryption at rest and key custody, on multi-factor authentication, on backup and restore testing, on mobile device management, on email security, or on structured SIEM integration. It also does not answer the vendor origin question, which is the one item where moving up within the same family does not help. For the technical gaps, a higher tier in the Kaspersky Next range that adds detection and response is normally cheaper and simpler to operate than mixing vendors; for the origin question, no edition change closes it, and that is worth knowing before you fill in the form.
Regional availability is the first limitation: following the United States prohibition, the product cannot be sold or updated there, so it is not an option for a US site of an international group. The scanning component runs on Windows Server, which means a Windows node has to exist even when the storage itself is a Linux-based appliance. Encryption blocking is also not uniform across platforms, because the FPolicy-based Anti-Cryptor is a NetApp feature and is not supported on FlexGroup volumes, Windows shared folders are covered by the general Anti-Cryptor component, and other NAS platforms receive malware scanning over ICAP or RPC without that blocking layer. The components that most often trigger a follow-up purchase are simply absent: there is no EDR, no patch management, no encryption management, no mobile coverage and no mail server scanning, and storage protection does not replace endpoint protection. Finally, Base is a new stand-alone licence and is not the correct article for extending an existing licence of the same product.
Kaspersky Security Center runs in your own infrastructure and is operated through its administration console or web console. The protected server can additionally be managed locally through the application console or from the command line.
No. The scanning component runs on a Windows server, and the storage system talks to it through the CAVA agent, RPC or ICAP. The appliance sends each file operation for a verdict and then applies the answer it receives.
Kaspersky Security for Windows Server is also offered within Kaspersky Endpoint Security for Business, so check what your existing agreement already covers before ordering. This article is a new stand-alone licence for the storage product and does not extend an existing one.
| Operating Systems | Windows Server 2019: Essentials / Standard / Datacenter Windows Server 2019 Core Windows Storage Server 2019 Windows Hyper-V Server 2019 Windows Server 2016: Essentials / Standard / Datacenter Windows Server 2016 Core: Standard / Datacenter Windows Server 2016 MultiPoint Microsoft Windows MultiPoint Server 2016 Windows Storage Server 2016 Windows Hyper-V Server 2016 Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter Windows Server 2012 R2 Core: Foundation / Essentials / Standard / Datacenter Windows Storage Server 2012 R2 Windows Hyper-V Server 2012 R2 Windows Server 2012: Foundation / Essentials / Standard / Datacenter Windows Server 2012 Core: Foundation / Essentials / Standard / Datacenter Windows Storage Server 2012 Windows Hyper-V Server 2012 Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter SP1 or later Windows Server 2008 R2 Core: Standard / Enterprise / Datacenter SP1 or later Windows Hyper-V Server 2008 R2 SP1 or later Windows Server 2008: Standard / Enterprise / Datacenter SP1 or later Windows Server 2008 Core: Standard / Enterprise / Datacenter SP1 or later Microsoft Small Business Server 2011: Essentials / Standard Microsoft Small Business Server 2008: Standard / Premium Microsoft Windows MultiPoint Server 2012: Standard / Premium Microsoft Windows MultiPoint Server 2011: Standard / Premium Windows Server 2003: Standard / Enterprise / Datacenter SP2 or later Windows Server 2003 R2: Foundation / Standard / Enterprise / Datacenter SP2 or later Windows 10 Enterprise multi-session |
| Processor | x86 or x64 compatible system / 1.4 GHz single-core minimum / 2.4 GHz quad-core recommended |
| Memory RAM | 1 GB minimum / 2 GB recommended |
| Storage | 4 GB free disk space / 100 MB for installing all application components / 2 GB recommended for antivirus databases / 400 MB recommended for quarantine and backup / 1 GB recommended for logs |
| System Component | Microsoft Windows Installer 3.1 |
| Storage Platforms | NetApp: Data ONTAP 7.x and 8.x in 7-mode / Data ONTAP 8.2.1 in cluster-mode / Data ONTAP 9.x from 9.0 to 9.7 in cluster-mode / Dell EMC Celerra and VNX: EMC DART 6.0.36 or higher / Celerra Antivirus Agent CAVA 4.5.2.3 or higher / Dell EMC Isilon: OneFS 7.0 or later / Hitachi HNAS: 12.0 or later via ICAP / 11.2 or later via RPC / IBM System Storage N series / Oracle ZFS Storage Appliance / Dell Compellent FS8600: FluidFS 6.x / FluidFS 5.x / HPE 3PAR: File Persona 3.3.1 |