<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Kaspersky Security for Storage Server Base Plus?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>NAS protection engine</strong> – Scans files on NetApp, Dell EMC, Hitachi, IBM and Oracle storages.<br /> <strong>ICAP and RPC connectors</strong> – Link the storage system to the scanning server.<br /> <strong>NetApp FPolicy integration</strong> – Real-time anti-ransomware for NetApp ONTAP volumes.<br /> <strong>Kaspersky Security Center</strong> – On-premises console for policies, tasks, reports and alerts.<br /> <strong>Quarantine and backup</strong> – Stores an untouched copy before any disinfection or deletion.<br /> <strong>Important</strong> – No EDR, patch management or encryption is included here.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Kaspersky Security for Storage Server Base Plus?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Kaspersky Security for Storage Server Base Plus is an anti-malware licence for network attached storage systems and Windows file servers, delivered through the Kaspersky Security for Windows Server application, which is the name administrators actually see at installation. It is managed centrally from the on-premises Kaspersky Security Center console rather than configured storage system by storage system.<br /><br /> <strong>No endpoint dependency</strong> – Files stay scanned even when uploaded by unmanaged devices.<br /> <strong>Storage stays responsive</strong> – iSwift and iChecker skip files already scanned and unchanged.<br /> <strong>Three security levels</strong> – Switch between maximum performance, recommended and maximum protection.<br /> <strong>Fault-tolerant scanning</strong> – Several scan servers share the load for one storage.<br /> <strong>Evidence-ready reporting</strong> – Console reports and event logs document every single detection.<br /> <strong>Granular admin rights</strong> – Separate privilege levels per protected server administrator.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where the built-in Windows protection stops and why shared storage is one of the places it does not reach.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Kaspersky Security for Storage Server Base Plus suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Suitability follows the storage architecture, not the headcount. If files sit on a NAS appliance or a central file share that several people write to, this product has something to protect. If everything lives on individual laptops or in a SaaS service, it does not.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasionally</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Central NAS or file share in daily use</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">If NAS present</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Storage Server Base Plus meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Not on its own, and no security product does. Under the revised Information Security Act (ISG), operators of critical infrastructure in Switzerland — among them energy and drinking water utilities, transport operators, listed hospitals, data centre and cloud providers, and cantonal and municipal administrations — must report a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report. Towards that deadline the product delivers the detection event and the file-level detail: the console records which storage system, which file and which verdict triggered the alert, which is usually the first hard fact an initial report needs. What it does not deliver is the attack path — there is no endpoint telemetry, no process tree and no root-cause analysis, so working out how the malware reached the share needs a separate tool. It also does not judge whether an incident is reportable, and it leaves endpoints, mailboxes and identity systems uncovered, which is where reportable incidents usually start. This text is not legal advice, and whether your organisation falls under the reporting obligation should be assessed formally and documented in writing.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Storage Server Base Plus meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product creates NIS 2 compliance for a buyer, because the directive addresses organisational risk management rather than software features. The NIS 2 Directive requires essential and important entities to implement measures across defined categories: incident handling, business continuity and backup management, supply chain security, access control and asset management, cryptography, vulnerability handling, security testing, staff training, and reporting of significant incidents to the competent authority. This product maps onto exactly one of those categories and part of a second: malware protection for stored data, and the detection half of incident handling for files written to protected storage. It contributes nothing to backup and recovery, business continuity planning, encryption, access control and multi-factor authentication, supply chain assessment, vulnerability handling or staff training, and it produces no incident report on its own. Buyers in scope should treat it as one control inside a management system, not as a substitute for one.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What should you know about official assessments of Kaspersky?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Two official measures are relevant and both are still in force. Germany's Federal Office for Information Security (BSI) has warned against the use of Kaspersky antivirus software since 15 March 2022; the warning is now issued under Section 13 of the BSI Act, the authority reviewed and maintained it again in 2026, and it is a recommendation to replace the software, not a sales ban. In the United States, the Department of Commerce's Bureau of Industry and Security issued a Final Determination in June 2024 prohibiting Kaspersky from supplying cybersecurity and antivirus products to US persons, and from delivering updates to existing US installations after 29 September 2024. Kaspersky rejects the reasoning, states that the assumed risks have remained hypothetical with no confirming security incident, points to its Global Transparency Initiative and its data processing in Switzerland, and has formally asked the BSI to withdraw the warning while reserving legal steps. Independent laboratory testing is a separate track: Kaspersky products have continued to appear in AV-TEST and AV-Comparatives test cycles through 2025 and 2026, and those results are unaffected by the regulatory measures. In practical terms this matters for public sector tenders, for operators of critical infrastructure, for subsidiaries bound by a German or US parent company policy, and for suppliers whose customers screen vendor country of origin; in Switzerland and the European Union the product remains on sale and fully updated.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="norton-vs-kaspersky-2025"><strong>Norton vs. Kaspersky – Which antivirus program offers the best protection in 2025?</strong><br />Compares the detection results and feature scope of both vendors, useful if vendor origin is a factor in your decision.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Kaspersky Security for Storage Server Base Plus help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly, and it is worth knowing which lines it actually fills in. It answers the items on malware protection for stored data: on-access scanning of every file read from or written to the protected storage, scheduled on-demand scans, central policy enforcement from a single console, separated administrator privilege levels, and an exportable detection record that can be attached as evidence. It answers none of the items on endpoint protection, endpoint detection and response, vulnerability and patch status, disk or file encryption, multi-factor authentication, mobile device management, email filtering, or tested backup and restore — and a questionnaire asking for incident response times will not accept a detection log as an answer. The cheaper route to closing those gaps is usually to add an endpoint tier from the same vendor family, such as Kaspersky Next EDR Optimum, rather than mixing vendors, because a second management console doubles the reporting work for every future questionnaire. Be aware that questionnaires from large customers increasingly ask about vendor country of origin and regulatory status; the section above sets out what is on record there.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The most important one is regional: following the US Final Determination, the product is not available to buyers in the United States, while it remains on sale and fully updated in Switzerland and the European Union — relevant if you operate a US subsidiary and were planning one standard across all sites. The scanning component runs on Windows Server, so a Linux-only environment cannot host the protection for its NAS. Storage compatibility is version-specific rather than vendor-specific: NetApp Data ONTAP, Dell EMC Celerra and VNX via the CAVA agent, Dell EMC Isilon on OneFS, Hitachi HNAS, IBM System Storage N series, Oracle ZFS Storage Appliance, Dell Compellent FS8600 and HPE 3PAR with File Persona are supported at documented minimum versions, so an older firmware release is the usual reason an integration fails. On ICAP-connected storages there is a known behaviour to plan around: when the Kaspersky Security Network returns an untrusted verdict, the application cannot delete or block the file, because it has no direct access to the storage system's network folders. Finally, this is detection and removal, not recovery — it does not roll back or restore files that ransomware has already encrypted, which is the single most common reason for a follow-up purchase.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the recovery side that anti-malware scanning does not address, including how to plan restore capability for shared storage.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Kaspersky Security for Storage Server Base Plus</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Where does the scanning actually run?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Not on the storage appliance. A Windows Server hosts the Kaspersky scanning service, and the NAS hands files over to it via ICAP, RPC or the EMC CAVA agent for a verdict. Where one scan server cannot keep up, several can be connected to the same storage system, which then distributes the requests between them.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it protect Windows file servers as well as NAS appliances?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The same application protects file operations on a conventional Windows file server directly, without any ICAP or RPC connection, which is the common case for companies that have a central file share but no dedicated NAS hardware.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is this a new licence or a renewal?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Base Plus is an initial licence type in Kaspersky's business licensing scheme, not a renewal of an existing one, and it does not require any other Kaspersky base product to work. Note that the licence must permit network attached storage protection; without that entitlement the NAS protection tasks start but return an error instead of scanning.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,sec-console,compliance-ch-isg" data-audience="b2b" data-count="3"> </div>