What are the core benefits of Bitdefender GravityZone Security for Storage Add-On?
Central management – Configured in the GravityZone Control Center console.
ICAP scanning – Protects NAS and file-sharing systems in real time.
Multi-vendor coverage – One deployment protects Dell, IBM and Hitachi storage.
Layered detection – Machine learning, heuristics, signatures and cloud lookup.
Scalable throughput – Add ICAP servers as scan volume grows.
Important note – Requires an existing GravityZone base product.
ICAP scan service – Security Server checks files requested from the storage system.
Storage Protection policy – Module enabled and tuned in GravityZone Control Center.
Verdict-based actions – Storage allows access, denies access, or deletes the file.
Multi-vendor platform support – ICAP-compatible NAS and SAN plus Nutanix Files and ShareFile.
Exclusions and reporting – Custom exclusions, default actions, reports and real-time notifications.
Important – No endpoint agent, EDR or backup; requires a GravityZone base product.
Security for Storage is an add-on that scans files on ICAP-compatible network-attached storage and file-sharing systems using one or more Bitdefender Security Server virtual appliances. It is managed centrally from the same GravityZone Control Center as the rest of the platform, so storage policies sit next to endpoint policies instead of in a separate tool.
Blocks infected files – Malware is stopped before it spreads across shares.
No agent required – The NAS needs no installed Bitdefender software.
One estate, one deployment – Mixed NAS vendors share the same scanning infrastructure.
Load balancing – The ICAP client spreads requests across several servers.
Audit-ready reports – Scheduled reports and notifications document storage scanning activity.
Placement flexibility – Security Servers can run close to cloud NAS.
The deciding factor is not headcount but whether shared storage is central to daily work and whether that storage speaks ICAP. A ten-person engineering office with a Dell NAS holding all project data has a stronger case than a hundred-person company that keeps everything in endpoints and cloud services.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Rare | By sector | Likely |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| ICAP-capable shared storage in use | Rare | ✓ | ✓ |
| This product fits | Only with NAS | ✓ | ✓ |
The Swiss reporting obligation applies to operators of critical infrastructure, not to every company, so the first question is whether your organisation is in scope at all. Under the revised Information Security Act (ISG), an affected operator must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Security for Storage supports that deadline in one narrow but practical way: when a Security Server returns a malicious verdict, the event lands in GravityZone Control Center with the file, the storage system and the timestamp, which is the kind of detail a first report has to contain. It does not reconstruct the attack path, it covers no endpoints, mailboxes or identities, and it produces no incident timeline, so the decision to report still rests on your other monitoring. This text is general information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.
No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management, not software features. NIS 2 requires essential and important entities to put in place measures covering areas such as incident handling, business continuity and backup, supply chain security, access control and the use of cryptography. Security for Storage contributes to exactly one of those areas: malware handling on shared storage, by blocking infected files at the moment the storage system is asked to serve them. It contributes nothing to backup and recovery, access control, supplier assessment, cryptography or staff training, and it plays no part in incident reporting workflows. Treat it as one technical control inside a wider management system rather than as a compliance measure in its own right.
Yes, for a small and specific set of items. It gives you a documented answer on malware scanning of shared storage: which systems are scanned, which detection layers run against each file, and who is allowed to change the policy, with scheduled reports from Control Center that can be attached as evidence. It answers nothing about backup and restore testing, encryption of data at rest, access rights reviews, patch levels, log retention periods or incident response times, and a questionnaire that asks about those will still come back with gaps. Where those gaps matter, closing them with a higher GravityZone edition or the matching GravityZone add-ons is usually cheaper to run and easier to evidence than mixing vendors, because the proof then comes out of a single console in a single format.
The add-on only protects storage that can act as an ICAP client, so a plain Windows or Linux file server without ICAP support is not covered by this module and still needs the ordinary GravityZone endpoint agent. Platform support is version-specific: Bitdefender lists Nutanix Files 3.x up to 4.2.1, Citrix ShareFile, Citrix ADC VPX and F5 BIG-IP VE ASM alongside ICAP-compatible NAS and SAN systems from Dell, EMC, IBM, Hitachi, HPE and Oracle, so the firmware version on your array is worth checking before you order. You also need somewhere to run the Security Server appliances, ideally on a host close to the NAS, and for a cloud NAS deployment they belong in that same environment. Scanning is not backup: an infected file is blocked or deleted on access, but a file already encrypted by ransomware can only come back from a restore. Finally, this is an add-on and not a standalone purchase, so it has to sit on top of an existing GravityZone product.
One Security Server is technically enough to perform ICAP scanning. Bitdefender nevertheless recommends installing and configuring at least two, so that the first can redirect surplus scan requests to the second when it is overloaded.
When someone opens, reads, writes or closes a file, the NAS or file-sharing system acts as the ICAP client and sends a scan request to the Security Server. The Security Server returns a verdict and the storage system then allows access, denies access, or deletes the file, depending on the configured action.
Yes. Bitdefender certifies Security for Storage with Nutanix Files, which was previously called Acropolis File Services (AFS). If your documentation still uses the older name, it refers to the same supported platform.
Add-on that scans NAS and file-sharing systems for malware over ICAP, managed from GravityZone. Requires an existing GravityZone product.
Bitdefender GravityZone Security for Storage, Bitdefender, GravityZone, storage security, NAS protection, ICAP scanning, file share malware scanning, storage add-on
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies