LUCIDTextjet - Print logo

Kaspersky Hybrid Cloud Security Server Base Plus

Short Description

Open HTML

What are the core benefits of Kaspersky Hybrid Cloud Security Server Base Plus?
Central management – All servers managed from Kaspersky Security Center.
Server protection – File, process and memory protection for Windows and Linux.
Virtualization support – Light agents for vSphere, Hyper-V and Citrix.
Cloud integration – Finds unprotected instances in AWS and Azure.
Ransomware defence – Anti-Cryptor blocks encryption of shared folders.
Important note – No SIEM export, patch management or EDR.

Long Description

Open HTML

What is included in Kaspersky Hybrid Cloud Security Server Base Plus?

Central management console – Kaspersky Security Center on premises or as cloud console.
Server workload protection – File, process and memory protection for Windows and Linux servers.
Anti-Cryptor for shares – Blocks encryption of shared folders from other network hosts.
Light Agent virtualization – Optimized agents for vSphere, Hyper-V and Citrix Hypervisor guests.
Public cloud API – Native integration with AWS, Microsoft Azure and Google Cloud.
Important – No SIEM connectors, patch management or file integrity monitoring.

What are the main benefits of Kaspersky Hybrid Cloud Security Server Base Plus?

This is the Standard tier of Kaspersky's workload protection for physical, virtual and public cloud servers, managed centrally from Kaspersky Security Center rather than device by device. It took the place of Kaspersky Security for Virtualization, which Kaspersky no longer sells, and today forms the Kaspersky Cloud Workload Security ecosystem together with Kaspersky Container Security.

One console – Physical, virtual and cloud servers under one policy set.
Lower host load – Shared cache and light agents free hypervisor resources.
Ransomware containment – Anti-Cryptor stops encryption arriving from other network hosts.
Cloud inventory – API discovery reveals unprotected instances in AWS and Azure.
Migration headroom – Same licence covers physical servers moving into virtualization.
Auto-scaling coverage – New cloud instances receive protection through auto-scaling policies.

Best antivirus? Why Windows Defender alone is not enough
Explains where the protection built into Windows stops and why server estates usually need a dedicated product.

Which company size is Kaspersky Hybrid Cloud Security Server Base Plus suitable for?

The deciding factor is not headcount but how mixed the server estate is. A company running a handful of physical servers is served by a normal endpoint product; this licence starts to pay off once physical servers, hypervisor guests and cloud instances have to follow the same policy and appear in the same report. Reporting duties depend on sector rather than size, but larger operators are more often designated as critical infrastructure.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland Rarely By sector Usually
NIS 2 in the European Union Rarely By sector Usually
Security questionnaire from large customers Occasionally ✓ ✓
Mixed physical, virtual and cloud servers Rarely ✓ ✓
This product fits ✕ ✓ Often Enterprise

End of Support for Windows Server 2022: Windows Server 2025 vs. 2022 vs. 2019: Is It Worth Upgrading?
Compares the supported Windows Server versions and shows when an upgrade of the server estate becomes due.

Does Kaspersky Hybrid Cloud Security Server Base Plus meet the requirements of Swiss cybersecurity legislation?

Swiss cybersecurity law does not apply to every company. The revised Information Security Act obliges operators of critical infrastructure to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Kaspersky Security Center supports the first report directly, because detection events, protection status and task results from every protected server are collected centrally, which answers what was detected, on which system and at what time. It does not support the follow-up work: the Standard tier has no log inspection and no SIEM connectors, so Windows security event logs are not evaluated and events cannot be forwarded automatically to a SIEM or syslog collector, and without an EDR component there is no attack chain reconstruction to explain how the incident began. Companies with a reporting duty therefore still need separate log collection and retention alongside this product. This information is not legal advice; whether your company is subject to a reporting obligation must be assessed case by case.

Does Kaspersky Hybrid Cloud Security Server Base Plus meet the requirements of European cybersecurity legislation?

No software product creates NIS 2 compliance, because the directive addresses organisational risk management, not tooling. NIS 2 requires measures in categories such as risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling and disclosure, cyber hygiene, cryptography and access control. This product covers part of the incident handling category through detection and central alerting on server workloads, and part of cyber hygiene through enforced protection settings, device control and web control on Windows and Linux servers. It does not cover backup and business continuity, multi-factor authentication, encryption, supply chain assessment or staff training at all, and it covers vulnerability handling only in the Enterprise tier, where vulnerability assessment and patch management are included. Buyers should treat it as one technical measure among several, not as a NIS 2 package.

What should you know about official assessments of Kaspersky?

In March 2022 the German Federal Office for Information Security (BSI) issued a warning recommending that Kaspersky virus protection products be replaced with alternative products, on national security grounds; the BSI confirmed after the 2024 US measures that this warning remains valid, and it is a recommendation, not a sales ban. In June 2024 the US Department of Commerce, Bureau of Industry and Security, issued a Final Determination prohibiting new sales of Kaspersky software to US persons from 20 July 2024 and prohibiting signature and codebase updates as well as operation of the Kaspersky Security Network in the United States from 29 September 2024. Kaspersky rejects the allegations, states that the decisions were based on the geopolitical situation rather than on technical evidence of its products, and points to its Global Transparency Initiative, under which threat data from European users is processed in data centres in Zurich and source code can be reviewed in a Transparency Center there. Independent laboratory results are a separate matter and continue to be published by test institutes. In practice this affects two groups of buyers concretely: organisations with US entities or US customers, where the prohibition applies directly, and organisations bound by public sector procurement rules or by customer supply chain requirements that name the BSI recommendation. For a private company in Switzerland or the European Union with no such ties, no purchase restriction follows from either measure.

Does Kaspersky Hybrid Cloud Security Server Base Plus help with security questionnaires from large customers?

Partly, and it is worth knowing in advance which items it leaves open. It answers the questions on malware protection for servers, central policy enforcement, protection of virtual and cloud workloads, anti-ransomware measures for file shares, device and web control on servers, and where threat data is processed, since Kaspersky processes European threat data in Zurich. It does not answer the questions on log retention and SIEM or syslog export, file integrity monitoring, application allowlisting on server operating systems, patch and vulnerability management evidence, endpoint detection and response, multi-factor authentication, encryption and backup. The cheapest way to close the first four of those gaps is the Enterprise tier of the same family, which adds file integrity monitoring, log inspection, SIEM connectors, application control for server operating systems and vulnerability assessment with patch management under one console; mixing a second vendor in usually costs more in agent conflicts and administration time than the licence difference. Detection and response, authentication and backup remain separate purchases in either tier.

What is the difference between the Standard tier and the Enterprise tier?

The single most decisive difference is evidence: the Enterprise tier adds file integrity monitoring, log inspection and SIEM connectors, which is what auditors and large customers ask for, while the Standard tier stops at protection and central reporting. The second difference is hardening, because application control on server operating systems, including default deny scenarios, is Enterprise only. The third is scope, since container security, DevOps pipeline integration and vulnerability assessment with patch management also sit in the Enterprise tier. Both tiers share the same protection engines, the same console and the same cloud API integration, so an upgrade later does not mean a different product.

CapabilityStandardEnterprise
File, process and memory protection ✓ ✓
Anti-Cryptor for shared folders ✓ ✓
Cloud API integration with AWS, Azure, Google Cloud ✓ ✓
Application control for server operating systems ✕ ✓
File Integrity Monitor ✕ ✓
Log inspection ✕ ✓
SIEM connectors ✕ ✓
Vulnerability assessment and patch management ✕ ✓
Container security and DevOps integration ✕ ✓
NextGen IDS/IPS for VMware NSX ✕ ✓

Which limitations should you know before buying?

This is workload protection, not detection and response: there is no EDR component, so alerts show what was blocked but not how an attacker moved through the estate, and adding EDR means a separate Kaspersky product. Agentless protection for virtual machines is being retired, with Kaspersky ending technical support for Kaspersky Security for Virtualization Agentless on 31 July 2026 and pointing customers to the Light Agent, which is already covered by the licence but has to be rolled out into the guest systems. The regional point that matters for buyers with a US presence: since the 2024 US prohibition, Kaspersky products may not be sold to, or updated for, US persons, so a company with US subsidiaries or US federal customers cannot standardise on this product globally. The gaps that most often trigger a follow-up purchase are SIEM export, file integrity monitoring and patch management, all three of which sit in the Enterprise tier rather than in this one.

Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?
Compares detection results and features of both vendors for buyers who want to weigh alternatives first.

Frequently asked questions about Kaspersky Hybrid Cloud Security Server Base Plus

Does this licence also protect virtual desktops?

No. The Server licensing object covers physical and virtual servers. Virtual desktops are covered by the Desktop licensing object, or by CPU licensing where the customer controls the hypervisor layer.

Is Kaspersky Hybrid Cloud Security the same thing as Kaspersky Container Security?

No, they are two separate products that together form the Kaspersky Cloud Workload Security ecosystem. Container scanning and DevOps pipeline integration are not part of the Standard tier of Hybrid Cloud Security.

 

System requirements

Operating Systems Windows Server 2025: Standard / Datacenter 64-bit
Windows Server 2022: Standard / Datacenter / Datacenter: Azure Edition / Server Core mode 64-bit
Windows Server 2019: Essentials / Standard / Datacenter / Server Core mode 64-bit
Windows Server 2016: Essentials / Standard / Datacenter / Server Core mode 64-bit
Windows Server 2012 R2: Foundation / Essentials / Standard / Datacenter / Server Core mode 64-bit
Windows Server 2012: Foundation / Essentials / Standard / Datacenter / Server Core mode 64-bit
Windows Server 2008 R2: Foundation / Standard / Enterprise / Datacenter Service Pack 1 or later 64-bit
Windows Web Server 2008 R2: Service Pack 1 or later 64-bit
Windows Small Business Server 2011: Essentials / Standard 64-bit
Windows MultiPoint Server 2011 64-bit
Processor CPU 1.4 GHz server or higher / SSE2 instruction set support
Memory RAM Server: 2 GB / 8 GB when installing the application with a built-in agent for integration with Kaspersky Anti Targeted Attack Platform
Storage 2 GB available disk space

Meta Description

Protects physical, virtual and cloud Windows and Linux servers from one console. SIEM export and patch management sit in the Enterprise tier.

Keywords

Kaspersky Hybrid Cloud Security Server Base Plus, Kaspersky, Kaspersky Hybrid Cloud Security, Kaspersky Security for Virtualization, server protection, workload protection, virtualization security, cloud workload security, anti-cryptor

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree