What are the core benefits of Kaspersky Security for Storage User Base Plus?
Central management – Policies and reports run in Kaspersky Security Center.
NAS protection – Scans storage traffic via ICAP, RPC and CAVA.
Ransomware blocking – Anti-Cryptor blocks encrypting hosts on NetApp shares.
Broad compatibility – NetApp, Dell EMC, Hitachi, IBM, Oracle, HPE.
Scan control – On-access and on-demand tasks with exclusion rules.
Important note – Covers storage only, not endpoints or mailboxes.
NAS anti-malware engine – Scans every file opened or written on connected storage.
ICAP, RPC and CAVA – Three integration paths for different storage vendor platforms.
Anti-Cryptor for NetApp – Blocks hosts that start encrypting files on shares.
Kaspersky Security Center – On-premises console for deployment, policies, tasks and reports.
Load balancing – Several scanning servers can share one storage system.
Important – No EDR, patch management, encryption or mobile coverage.
Kaspersky Security for Storage is a dedicated anti-malware layer for network attached storage and file servers, managed centrally from the on-premises Kaspersky Security Center console. The protection component itself is Kaspersky Security for Windows Server, the name many administrators still search for.
Scanning off the NAS – The appliance keeps serving files while Windows scans.
Fewer duplicate scans – iSwift and iChecker skip files already checked.
Ransomware containment – Blocked hosts are listed for the administrator to review.
Mixed vendor estates – Same product protects NetApp, Isilon, Hitachi and ZFS.
Evidence for audits – Scan and detection events export from the console.
Continuity on failure – Protection restarts automatically after an unexpected shutdown.
The deciding factor is not headcount but whether file data sits on a NAS appliance rather than on a Windows share. A company with one Windows file server and no NAS gets no value here, because the licence covers network storage protection and not general server protection. Once NetApp, Isilon, Hitachi, ZFS or 3PAR appliances are in use, no endpoint agent sees those files at all.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | Common |
| NIS 2 in the European Union | Rarely | Often | ✓ |
| Security questionnaire from large customers | Often | ✓ | ✓ |
| NAS appliance in productive use | Rarely | ✓ | ✓ |
| This product fits | ✕ | If NAS present | ✓ |
The reporting duty under the revised Information Security Act applies to operators of critical infrastructure, not to every company, and it has been in force since 1 April 2025. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the first hour is spent establishing what was touched and when. Kaspersky Security for Storage supports that specific step for file data: each detection is written to the Kaspersky Security Center event log with a timestamp, the affected storage path and the verdict, and Anti-Cryptor entries name the host that was blocked, so the report can state which share was hit and from where. What it does not deliver is the rest of the picture, because there is no endpoint telemetry, no root-cause analysis and no incident case management, so the attack path from the first compromised workstation to the storage system has to be reconstructed from other tools. It also does not produce the report itself or track the 24-hour deadline. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.
No product makes a company compliant with the NIS 2 Directive, because the directive asks for organisational measures, documented processes and management accountability, not for a specific piece of software. NIS 2 requires, among other categories, risk analysis and information security policies, incident handling, business continuity and backup management, supply chain security, cyber hygiene, cryptography and access control. Kaspersky Security for Storage contributes to two of these: malware protection for file data as part of cyber hygiene, and the detection and logging side of incident handling for storage assets. It contributes nothing to backup management, cryptography, access control, multi-factor authentication or supply chain governance, and it holds no vulnerability or patch data. Buyers evaluating NIS 2 readiness should treat this as one control over one asset class, and expect the backup, identity and patching measures to be covered by separate products and by written procedure.
Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security (BSI) published a warning against the use of Kaspersky anti-virus software on 15 March 2022 and recommends replacing it with alternative products; the warning was originally issued under section 7 of the BSI Act and has been governed by section 13 since the amended act took effect on 6 December 2025. Separately, the U.S. Department of Commerce issued a Final Determination on 20 June 2024 prohibiting new sales of Kaspersky products to U.S. persons from 20 July 2024 and ending signature and code updates for U.S. customers on 29 September 2024. Kaspersky rejects the BSI warning as not based on an objective technical analysis and points to its Global Transparency Initiative, under which threat data processing was moved to Switzerland and source code is available for review in its transparency centres; the company has also pursued legal action over the warning. Independent laboratory results are a separate matter and have remained strong throughout, with continued top ratings in AV-TEST and AV-Comparatives cycles. In practical terms this affects public sector tenders, organisations that answer supply chain questionnaires from customers with German or U.S. security requirements, and any group with U.S. entities that would fall under the prohibition. Companies without those exposures are unaffected by either measure, and Kaspersky remains normally available and updated in Switzerland and the European Union.
Partly, and it is worth knowing in advance which lines it fills in and which it leaves blank. It answers the malware protection questions for file data: real-time scanning of every read and write on the storage system, scheduled full scans, a maintained detection engine with automatic database updates, quarantine and backup of objects before action is taken, and centrally enforced policy with role-based administrator privileges. It also answers the logging question for that asset class, since detections and blocked hosts are exportable from the console as dated evidence. It answers none of the following: backup and restore testing, encryption of data at rest, multi-factor authentication, vulnerability and patch status, endpoint detection and response, mobile device management, and secure development. Two of those gaps regularly cause failed questionnaires, namely backup evidence and patch reporting. The cheaper route to close them is usually to add the corresponding modules from the same vendor family and keep one console, rather than introducing a second management server that then has to be documented and audited on its own.
The decisive difference is which machine is protected. Kaspersky Security for Storage protects data held on a NAS appliance by scanning requests the appliance sends over ICAP, RPC or the CAVA agent, while Kaspersky Endpoint Security for Business protects the Windows machines themselves through an agent installed on each one. This became a hard line on 30 June 2025, when limited support for Kaspersky Security for Windows Server under the Kaspersky Security for Business licence ended; the application continues to be supported under the Kaspersky Security for Storage licence, but only for network storage protection. In practice that means a company with both NAS appliances and Windows servers needs both products, and buyers who expect the storage licence to also cover the scanning server will be caught out.
| Capability | Security for Storage | Endpoint Security for Business |
|---|---|---|
| NAS scanning via ICAP, RPC, CAVA | ✓ | ✕ |
| Anti-Cryptor for NetApp | ✓ | ✕ |
| Windows server and workstation protection | ✕ | ✓ |
| Kaspersky Security Center console | ✓ | ✓ |
| EDR functionality | ✕ | Separate product |
The clearest regional limitation is the United States: under the U.S. Department of Commerce prohibition, Kaspersky products may not be sold to U.S. persons and U.S. customers have received no updates since 29 September 2024, so a Swiss or European group with U.S. entities cannot roll this out globally. Technically, the scanning does not run on the appliance but on a separate Windows server that talks to it, which means a Windows host has to exist, be maintained and be patched, and that host is not itself protected by this licence. Anti-Cryptor against active encryption is a NetApp feature delivered through FPolicy; on ICAP-connected platforms such as Isilon or Hitachi in ICAP mode, protection is on-access scanning of individual file operations rather than host blocking. The most common follow-up purchases are a backup product, because nothing here restores an encrypted file, and endpoint protection, because the workstation that carried the malware onto the share is outside this product's scope entirely. Storage platform support is also version-bound, so an appliance running firmware older than the supported baseline can fall outside the integration.
No. Nothing is installed on the storage appliance. The scanning service runs on a Windows server, and the appliance forwards file operations to it over ICAP, RPC or the CAVA agent and applies the verdict it receives back.
On NetApp systems, Anti-Cryptor detects the encryption pattern coming from a connected host and blocks that host from the shares, which stops the run mid-way. On other platforms, each file operation is scanned individually, so known malicious files are caught but the encrypting process itself keeps running on the workstation until an endpoint product deals with it.
| Operating Systems | Windows Server 2019: Essentials / Standard / Datacenter / Core Windows Storage Server 2019 Windows Hyper-V Server 2019 Windows Server 2016: Essentials / Standard / Datacenter / Core Windows Storage Server 2016 Windows Hyper-V Server 2016 Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter / Core Windows Storage Server 2012 R2 Windows Hyper-V Server 2012 R2 Windows Server 2012: Foundation / Essentials / Standard / Datacenter / Core Windows Storage Server 2012 Windows Hyper-V Server 2012 Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter / Core Windows Hyper-V Server 2008 R2 Windows Server 2008: Standard / Enterprise / Datacenter / Core Windows Server 2003 R2: Foundation / Standard / Enterprise / Datacenter Windows Server 2003: Standard / Enterprise / Datacenter Windows 10 Enterprise multi-session |
| Processor | Minimum 1.4 GHz single-core / recommended 2.4 GHz quad-core |
| Memory RAM | Minimum 1 GB / recommended 2 GB |
| Storage | 4 GB free disk space / 100 MB for installing all components / 2 GB recommended for antivirus databases / 400 MB recommended for quarantine and backup / 1 GB recommended for logs |
| System Component | Microsoft Windows Installer 3.1 |
| Storage Platforms | NetApp: Data ONTAP 7.x and 8.x in 7-mode / Data ONTAP 8.2.1 in cluster-mode / Data ONTAP 9.x from 9.0 to 9.7 in cluster-mode / Dell EMC Celerra and VNX: EMC DART 6.0.36 or higher / Celerra Antivirus Agent CAVA 4.5.2.3 or higher / Dell EMC Isilon: OneFS 7.0 or later / Hitachi HNAS: via ICAP 12.0 or later / via RPC 11.2 or later / IBM System Storage N series / Oracle ZFS Storage Appliance / Dell Compellent FS8600: FluidFS 6.x / FluidFS 5.x / HPE 3PAR File Persona 3.3.1 |