<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky CyberSafety for IT Online Base?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Six training modules</strong> – Malware, unwanted programs, investigation basics, phishing, servers, Active Directory.<br /> <strong>Practical exercises</strong> – Each module holds four to ten hands-on exercises.<br /> <strong>Administrator portal</strong> – Invite trainees by email and assign modules individually.<br /> <strong>Progress statistics</strong> – Administrators track assignments, trainees see their own results.<br /> <strong>Cloud or SCORM</strong> – Run the course hosted or inside your own LMS.<br /> <strong>Important</strong> – No antivirus, no agent, no phishing simulation included.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains why the built-in Windows protection leaves gaps that training alone cannot close.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky CyberSafety for IT Online Base?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky CyberSafety for IT Online Base is a browser-based training course that teaches general IT staff and service desks first-line incident response; Kaspersky documents the same course as Cybersecurity for IT Online (CITO). Training is managed centrally, because an administrator creates trainee accounts and assigns modules, and Base marks the initial purchase rather than a renewal of an existing licence.<br /><br /> <strong>Closes the skills gap</strong> – Between basic awareness training and expensive expert courses.<br /> <strong>Faster incident handover</strong> – The service desk collects evidence before it disappears.<br /> <strong>Fewer premature all-clears</strong> – Staff stop closing suspicious tickets with a reboot.<br /> <strong>Real tool practice</strong> – Exercises use Autoruns, Process Hacker, Nmap and Autopsy.<br /> <strong>Paced over a year</strong> – Kaspersky recommends roughly one exercise per week.<br /> <strong>Documented completion</strong> – A personal certificate follows each finished module.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky CyberSafety for IT Online Base suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether you employ IT staff who handle the first look at a suspicious machine. A company whose IT is fully outsourced trains nobody with this course; a company with a service desk or two system administrators gets the most out of it.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Mostly excluded</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Own IT staff or service desk to train</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often none</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky CyberSafety for IT Online Base meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so the first question is whether your sector is named at all. Affected operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, and that clock starts with whoever first looks at the affected machine. This course supports exactly that step: the investigation module teaches staff to collect volatile and non-volatile evidence and to read event logs instead of rebooting, which is what keeps a report factual rather than speculative. What it does not do is detect the incident, produce the telemetry, hold logs for later analysis, or file anything with BACS, and it contains no technical control that a supervisory review would count. It also does not define who inside your organisation is allowed to declare an incident, which is an organisational decision the training assumes has already been made. This is general product information and not legal advice; assess your own reporting duties with qualified advisors.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the recovery side of an incident, which training and reporting duties do not address.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky CyberSafety for IT Online Base meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance, because the directive addresses organisations and their risk management, not the software they buy. NIS 2 requires a set of measure categories: risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, procedures to assess how well the measures work, cryptography, access control and asset management, and basic cyber hygiene together with cybersecurity training. This course maps to the training category and, in part, to incident handling, because it builds the practical skill of recognising and documenting an incident at the point where it first surfaces. It does not address risk analysis, business continuity, supply chain security, cryptography, access control or multi-factor authentication in any form, and it produces no technical evidence for the effectiveness review. The directive also expects management bodies themselves to be trained, and this course is aimed at IT staff rather than at leadership.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Germany's Federal Office for Information Security (BSI) issued a warning about Kaspersky virus protection software on 15 March 2022 and recommended replacing it with alternative products. The warning is still in force and has been governed by Section 13 of the BSI Act since 6 December 2025, following the German law implementing the NIS 2 Directive. The BSI limited the warning to the antivirus portfolio and stated that it made no assessment of other Kaspersky products, which matters here because this course installs nothing and includes no scanning engine. In the United States, the Department of Commerce issued a final determination in June 2024 that prohibits Kaspersky from providing cybersecurity and antivirus products and services to US persons, effective 29 September 2024. Kaspersky rejects the BSI warning as not based on an objective technical analysis of its software and has continued to contest it. In Switzerland, the Federal Office for Cybersecurity has issued neither a warning nor a ban and has stated that no misuse of Kaspersky software has been reported to it, leaving the decision with each organisation. In practice this affects buyers who bid for public sector contracts, who supply German or US customers, or whose group parent maintains a vendor exclusion list; for other buyers the decisive question is whether a Russian-headquartered vendor is acceptable in their supply chain documentation.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Compares the two vendors on detection performance, for readers weighing Kaspersky as a supplier.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky CyberSafety for IT Online Base help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and only in one section of a typical questionnaire. It answers the items asking whether IT personnel receive role-specific security training beyond general awareness, whether that training covers incident recognition and escalation, and whether completion is documented, since a certificate is issued for each finished module and the administrator view shows who was assigned what. It does not answer anything about all-employee awareness training, phishing simulation results, endpoint protection, patch levels, encryption, multi-factor authentication, log retention, backup testing, or an information security management system, and none of those gaps can be closed by adding more trainees to this course. If the questionnaire fails on the awareness items rather than the IT items, the cheaper route is usually another product in the same Kaspersky Security Awareness family instead of a second vendor, because you keep one contract and one reporting model. If it fails on technical controls, no training product will help and you need the corresponding endpoint or management product.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Cybersecurity for IT Online and the Automated Security Awareness Platform?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is the audience: this course trains the people who investigate an incident, while the Automated Security Awareness Platform trains everyone who might cause one. That also decides which questionnaire items each one answers. Phishing simulation is part of the Automated Security Awareness Platform and is not part of this course, which teaches phishing analysis instead, meaning how to read a message header and remove a confirmed phishing mail from mailboxes. Companies that need both usually buy both; neither replaces the other.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Property</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Cybersecurity for IT Online</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Automated Security Awareness Platform</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Target audience</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">IT staff, service desk</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">All employees</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Main goal</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">First-line incident response</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Everyday cyber hygiene</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Covers non-IT employees</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Phishing simulation</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Delivery</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Cloud or SCORM</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Cloud platform</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The current edition of the training is built around the Windows corporate environment, so teams running mainly macOS or Linux endpoints will find parts of the exercises, particularly the Active Directory and server modules, of limited use. Regional availability is restricted: the retail packages sold in this region are the European Edition, and the United States prohibition on Kaspersky cybersecurity products and services means this is not an option for organisations that must be able to supply US entities from the same contract. Trainees need internet access and the Chrome browser, and a module in progress does not save its state if the window is closed or left inactive for two hours before all sections are finished, which is worth telling people before they start a 45-minute exercise. The two limitations that most often trigger a follow-up purchase are the absence of any protection software, since this is a course and not an agent, and the absence of awareness training for non-IT employees, which is where most security questionnaires actually fail.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky CyberSafety for IT Online Base</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">How much time does the training take per person?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Each module contains between four and ten exercises, and a single exercise takes between 5 and 45 minutes. Kaspersky designs the programme to be spread across a year at roughly one exercise per week, so it is planned as continuing education rather than a one-off workshop day.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the course run in our own learning management system?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Kaspersky delivers the training either from its own cloud platform or in SCORM format. If you take the SCORM route, assignment and completion tracking live in your own LMS, which is usually the better choice when your training evidence has to come out of one system for an audit.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is the course connected to other Kaspersky products?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky makes the training available to Kaspersky Endpoint Security Cloud Pro users directly from the Business Hub. It is otherwise independent, and buying it does not require or activate any other Kaspersky product.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="compliance-ch-isg,compliance-nis2,compliance-supplier" data-audience="b2b" data-count="3"> </div>