<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Embedded Systems Security Base?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Application Launch Control</strong> – Default Deny mode permits only approved programs to run.<br /> <strong>Device and Update Control</strong> – Restricts USB peripherals and unapproved software update sources.<br /> <strong>Opt-in anti-malware</strong> – On-demand and real-time scanning, disabled on weak hardware.<br /> <strong>Exploit Prevention</strong> – Blocks memory exploits including fileless and zero-day techniques.<br /> <strong>Network Threat Protection</strong> – Stops port scanning and brute force attacks on devices.<br /> <strong>Important</strong> – File Integrity Monitor and Log Inspection require the Compliance Edition.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Embedded Systems Security Base?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Embedded Systems Security protects ATMs, point-of-sale terminals, ticketing machines, medical equipment and legacy endpoints that cannot carry a standard endpoint agent. It is managed centrally through Kaspersky Security Center, either on-premises or from the vendor-hosted cloud console, and additionally offers a local GUI and command line for isolated devices.<br /><br /> <strong>Runs on old hardware</strong> – Supports Windows XP SP2 up to Windows 11.<br /> <strong>Linux device coverage</strong> – Separate agent protects Linux-based embedded devices and kiosks.<br /> <strong>Works offline</strong> – Protection stays stable during long periods without connectivity.<br /> <strong>Firewall management</strong> – Configures the OS firewall on devices outside the domain.<br /> <strong>SIEM export</strong> – Forwards events by syslog to your existing SIEM.<br /> <strong>Anti-Cryptor protection</strong> – Detects and stops ransomware encrypting files on the device.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where the protection built into Windows stops, and which attack techniques need a dedicated security agent.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Embedded Systems Security Base suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Company size matters less here than device inventory. The product is worth buying when you operate machines that a normal endpoint agent cannot run on: self-service terminals, checkout systems, fuel dispensers, medical devices or production PCs still on an unsupported Windows version. A single retail branch with four checkouts has the same technical requirement as a bank with two thousand ATMs.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Usually</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Central console for dispersed devices</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Optional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">If embedded devices</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Embedded Systems Security Base meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every company, and has been enforceable since 1 April 2025; affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Meeting a 24-hour deadline depends on noticing the incident in the first place, and this is where an embedded device fleet is usually the weak point, because terminals in branches and public locations are rarely watched as closely as office endpoints. Kaspersky Embedded Systems Security supports this by detecting malware and network attacks on the device itself and by forwarding its events via syslog to a SIEM, so that an alarm from an ATM or checkout system reaches the same queue as everything else. What it does not deliver in the Base licence is audit-ready evidence of what changed on the device: File Integrity Monitor and Log Inspection are reserved for the Compliance Edition, and even there they run on Windows only. It also does not cover the organisational side of the obligation, meaning the reporting process, the named responsible person and the incident documentation, all of which you have to build yourself. This is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Embedded Systems Security Base meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes a company compliant with the NIS 2 Directive, because the directive addresses risk management measures and governance rather than software features. NIS 2 requires, among others, incident handling, business continuity including backup and crisis management, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, access control and asset management, cryptography, multi-factor authentication and staff training. Kaspersky Embedded Systems Security contributes to a narrow set of these: incident detection and event forwarding for incident handling, application and device control for access control at device level, exploit prevention as mitigation where a system can no longer be patched, and system hardening as basic cyber hygiene on machines that would otherwise run unprotected. It contributes nothing to backup and business continuity, encryption, multi-factor authentication, supply chain assessment or awareness training, and it performs no patch management, so vulnerability handling remains a separate process. Treat it as one measure among many, and specifically as the measure that closes the gap on devices your standard endpoint product cannot reach.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In Switzerland, the Federal Office for Cybersecurity has issued no warning and no ban concerning Kaspersky products, has stated that it has received no reports of misuse in Switzerland, and leaves the decision to each organisation; there is also no internal federal directive prohibiting the products. In Germany, the Federal Office for Information Security (BSI) issued a formal warning on 15 March 2022 recommending that Kaspersky antivirus products be replaced with alternatives, and that warning remains in force, now anchored in Section 13 of the amended BSI Act since 6 December 2025. In the United States, the Department of Commerce issued a Final Determination on 20 June 2024 prohibiting the sale of Kaspersky security software and, from 29 September 2024, the delivery of signature and codebase updates to US persons; this prohibition is still in force. Kaspersky rejects the allegations, states that the decisions reflect the geopolitical situation rather than an assessment of its products, processes threat data from European users on servers in Switzerland, and operates a Transparency Center in Zurich where authorised partners and government stakeholders can review source code and detection rules. Independent testing has not been withdrawn: the independent laboratories have continued to include Kaspersky products in their public test cycles. Practically, this matters if you sell to the public sector, supply German public bodies or critical infrastructure operators, answer supply chain questionnaires that ask about vendor country of origin, or operate any entity subject to US rules; for a private Swiss retailer or hospitality operator with no such exposure, it is a documentation question rather than an obstacle.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection?</strong><br />Compares the detection performance and feature scope of both vendors if you are weighing alternatives.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Embedded Systems Security Base help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and it is worth knowing in advance which boxes it lets you tick. It answers questions on malware protection for all endpoints including legacy systems, application allowlisting, removable media and USB restrictions, host firewall configuration, protection against network-based attacks, central policy enforcement, and forwarding of security events to a SIEM. It does not answer questions on endpoint detection and response, patch and vulnerability management, disk or removable media encryption, multi-factor authentication, backup and restore testing, mobile device management, or file integrity and log audit evidence, since the last of these belongs to the Compliance Edition. The awkward items in practice are usually integrity monitoring and EDR, because auditors ask for proof of what changed on a payment-handling device and how quickly you could reconstruct an incident. If those two come up, the cheaper route is normally to move the same fleet to the Compliance Edition for integrity monitoring and log inspection, and to add an EDR product from the same vendor family so that everything stays in one console, rather than introducing a second vendor and a second agent onto hardware that is already resource-constrained.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the backup and restore questions this product does not answer, and what auditors typically expect to see.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Kaspersky Embedded Systems Security and the Compliance Edition?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single decisive difference is system inspection: the Compliance Edition is the extended licence that unlocks two additional components, File Integrity Monitor and Log Inspection, which the standard edition does not activate. Everything else, including application, device and update control, anti-malware, exploit prevention, network threat protection and central management, is identical between the two. Both are sold as separate licences and neither is part of a bundle, so this is a decision you make at purchase rather than an upgrade you toggle later. Choose the Compliance Edition when an auditor or a large customer asks you to evidence changes to critical files and to inspect event logs on payment-handling or regulated devices. Note that both inspection components are available for Windows only, so a Linux-based device fleet gains nothing from the upgrade.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Component</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Embedded Systems Security</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Compliance Edition</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Application, device and update control</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Anti-malware and Exploit Prevention</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Network Threat Protection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">File Integrity Monitor</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows only</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Log Inspection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Windows only</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Management via Kaspersky Security Center</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Sale and updates in the United States</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The clearest regional limitation is the United States: since 29 September 2024 Kaspersky may neither sell its security software there nor supply signature and codebase updates to US persons, so devices operated by a US entity or on US soil cannot be covered by this licence. Platform coverage is uneven in one specific respect: the integrity and logging components, along with the proprietary application-level firewall, exist for Windows only, while Linux devices receive protection and hardening but not system inspection. The most common cause of a follow-up purchase is the edition split, because buyers discover during an audit that File Integrity Monitor and Log Inspection sit in the Compliance Edition rather than in the standard licence. Beyond that, this is a hardening and protection product, not a detection and response platform: it contains no EDR component, no patch management, no encryption management and no mobile device coverage, and central management assumes you run or subscribe to Kaspersky Security Center.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="antivirus-programs-windows-2025"><strong>Test: Best antivirus programs for Windows</strong><br />Useful if your fleet turns out to be standard PCs rather than embedded devices and you need a conventional endpoint product.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Embedded Systems Security Base</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can it protect ordinary PCs that still run an old Windows version?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, and Kaspersky documents this scenario explicitly as an alternative to its regular endpoint product for legacy machines. Because support reaches back to Windows XP SP2, a production PC or laboratory workstation that cannot be upgraded can stay protected and centrally managed instead of being excluded from the security policy.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What does Base mean in the product name?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Base is the new-licence variant of the product. Renewal variants of the same product are listed separately, so select Base when the devices are not yet covered by an existing licence of this product.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-endpoint,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>