<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Hybrid Cloud Security Enterprise Server Base?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Multi-layer malware protection</strong> – File, process and memory protection with behavioural detection.<br /> <strong>Anti-Cryptor for shared folders</strong> – Blocks remotely initiated encryption against shared network folders.<br /> <strong>Application Control for servers</strong> – Default deny lockdown of software on server operating systems.<br /> <strong>File Integrity Monitoring</strong> – Tracks changes to critical system files and directories.<br /> <strong>Public cloud API integration</strong> – Discovers and protects workloads in AWS, Azure and Google Cloud.<br /> <strong>Important</strong> – No EDR component; detection and response is a separate product.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Hybrid Cloud Security Enterprise Server Base?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Hybrid Cloud Security Enterprise, Server is the higher of two tiers of Kaspersky's workload protection for physical servers, virtual servers and public cloud instances, managed centrally from Kaspersky Security Center. The virtualization component is still shipped under the older Kaspersky Security for Virtualization (KSV) name that many buyers search for, and the product is now positioned as part of the Kaspersky Cloud Workload Security offering alongside Kaspersky Container Security.<br /><br /> <strong>Single management console</strong> – Physical, virtual and cloud servers under one policy set.<br /> <strong>Lower virtualization overhead</strong> – Light agent uses a shared SVM for scanning verdicts.<br /> <strong>Hardening with evidence</strong> – Default deny plus file integrity monitoring creates a documented baseline.<br /> <strong>Log Inspection</strong> – Scans server log files for suspicious operational events.<br /> <strong>SIEM connectors</strong> – Forwards security events into an existing SIEM system.<br /> <strong>Migration flexibility</strong> – Server licences also activate Kaspersky Endpoint Security for Business applications.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where the built-in Windows protection stops and which gaps a managed security product has to close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Hybrid Cloud Security Enterprise Server Base suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you run a server estate worth managing centrally. A company with two physical servers and no hypervisor layer gets little value from default deny, file integrity monitoring and SIEM export, and is better served by a standard endpoint product. From the point where virtual servers are created and destroyed regularly, or where workloads run in AWS, Azure or Google Cloud next to on-premises hardware, the console and the cloud API integration start saving real administration time.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Common</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Virtualized or public cloud server estate</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Common</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Hybrid Cloud Security Enterprise Server Base meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Swiss obligation applies to operators of critical infrastructure named in the revised Information Security Act, including energy and water suppliers, transport, health, telecommunications, finance, cantonal and municipal administrations, and manufacturers whose hardware or software is used by those operators. Since 1 April 2025 they must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with missing details supplied within 14 days. This product supports the detection and evidence side of that deadline: log inspection and file integrity monitoring record what changed on a server and when, and the SIEM connectors push those events into a system where an initial report can be assembled quickly. What it does not do is classify an incident as reportable, produce the report, or reconstruct an attack path across the estate, because there is no EDR component and no managed monitoring service in this licence. It also covers servers only, so workstations, mobile devices and backup remain outside its scope and outside your evidence chain. This text is not legal advice; whether your organisation falls under the reporting obligation should be assessed with qualified legal counsel.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Hybrid Cloud Security Enterprise Server Base meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No software product makes a company compliant with the NIS 2 Directive, which obliges essential and important entities to implement risk management measures and incident reporting and makes management accountable for them. The directive names measure categories including incident handling, business continuity and backup management, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, policies on cryptography, and access control with multi-factor authentication. This product maps to part of that list: vulnerability assessment and patch management for system maintenance, application control and file integrity monitoring for hardening and integrity, and central policy enforcement with role-based access in the console. It contributes nothing to backup and restore, encryption of data at rest, multi-factor authentication, supplier risk assessment, staff training, or the documented processes the directive expects. Treat it as one technical control inside a broader programme rather than as a compliance package.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">In June 2024 the U.S. Department of Commerce Bureau of Industry and Security issued a Final Determination prohibiting new sales of Kaspersky software in the United States; sales stopped on 20 July 2024 and updates for US customers ended on 29 September 2024. Germany's Federal Office for Information Security (BSI) published a warning against Kaspersky antivirus software on 15 March 2022 recommending replacement products; it is a warning and not a sales ban, it remains in force, and since December 2025 it rests on Section 13 of the amended BSI Act, with Kaspersky publicly pressing for its withdrawal in early 2026. Kaspersky's position is that these decisions are political rather than the result of a technical assessment of its products, and that it is a private company without ties to any government. Independent testing has continued regardless: Kaspersky business endpoint products were part of the AV-Comparatives Business Security Test for the first half of 2026 and hold current AV-TEST certifications for corporate Windows clients. Practically, this affects buyers with US entities or US federal supply chain requirements, public sector procurement in the countries that restrict it, and any company whose large customers ask about vendor country of origin; commercial sale and updates in Switzerland and the European Union are not restricted.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Compares detection results and functionality of both vendors for buyers weighing up an alternative.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Hybrid Cloud Security Enterprise Server Base help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and mostly in the server hardening and change control sections. It gives you a documented answer for malware protection on physical, virtual and cloud servers, for application allowlisting in default deny mode, for file integrity monitoring on critical system files, for log inspection, for vulnerability and patch status, and for central policy management with role-based access and SIEM export. It answers nothing in the sections on endpoint detection and response, telemetry retention, 24/7 monitoring, disk encryption, mobile device management, multi-factor authentication, identity governance, backup and restore testing, or penetration testing, and it will not answer the country-of-origin question that increasingly appears in supplier questionnaires. The cheapest way to close the technical gaps is usually inside the same vendor family, since Kaspersky Container Security, Kaspersky Next EDR Expert and the Kaspersky SIEM platform share the same management approach, but the origin question is a procurement decision rather than a product decision. Answer honestly what the product covers and name the compensating controls for the rest; auditors accept a documented gap far more readily than an overstated capability.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Kaspersky Hybrid Cloud Security Standard and Kaspersky Hybrid Cloud Security Enterprise?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The single decisive difference is server hardening: Application Control for server operating systems, which enables default deny, exists only in the Enterprise tier. Around it sit the three capabilities that auditors ask about, file integrity monitoring, log inspection and NextGen IDS/IPS for VMware NSX, all Enterprise only. The Standard tier delivers the protection engine itself for physical, virtualized and cloud workloads, so if your requirement is malware protection rather than lockdown and evidence, Standard is the honest answer. Neither tier is sold or updated in the United States.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Standard</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Enterprise</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Protection for physical, virtual and cloud workloads</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Cloud API integration with AWS, Azure, Google Cloud</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Application Control for server operating systems</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">File Integrity Monitoring</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Log Inspection</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NextGen IDS/IPS for VMware NSX</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">EDR component</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Sales and updates in the United States</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Not available</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Not available</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Security for Virtualization Agentless has reached end of life: technical support ended on 31 July 2026, only database updates are available between 1 August 2026 and 1 February 2027, and from 2 February 2027 no support of any kind is provided, while new licences include KSV Light Agent only. The product is not sold or updated in the United States, which is the single most important regional restriction for groups with American subsidiaries or American supply chain requirements. Container and Kubernetes protection is not part of this licence; that is Kaspersky Container Security, a separate product within the Kaspersky Cloud Workload Security offering. There is no EDR component, no encryption management and no backup function, so investigation of an incident, notebook encryption and restore capability all require additional products. The Server licensing object covers physical and virtual servers, virtual desktops belong to the Desktop object, and combining Standard and Enterprise licences requires approval from the vendor.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Shows why server protection without a working backup strategy leaves the most expensive gap open.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Hybrid Cloud Security Enterprise Server Base</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is this a new licence or a renewal?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Base denotes the standalone new licence for the Enterprise tier with the Server licensing object. Kaspersky uses a separate Renewal licence type for existing customers, including customers who move between the Standard and Enterprise tiers at renewal.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the Server licensing object also cover virtual desktops?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. The Server object covers physical servers and virtual servers, both persistent and non-persistent. Virtual desktops are covered by the Desktop object, and environments where you control the hypervisor can alternatively be licensed per CPU or core.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which management console does it use?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Management runs through Kaspersky Security Center, which handles policy assignment, agent rollout, role-based access and reporting for on-premises, virtualized and public cloud workloads in one place. The cloud API integration discovers workloads in AWS, Azure and Google Cloud so that agents can be deployed and policies applied without maintaining a separate inventory.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,sec-cloud,sec-console" data-audience="b2b" data-count="3"> </div>