<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender GravityZone Security for Storage Add-On?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>ICAP scan service</strong> – Security Server checks files requested from the storage system.<br /><strong>Storage Protection policy</strong> – Module enabled and tuned in GravityZone Control Center.<br /><strong>Verdict-based actions</strong> – Storage allows access, denies access, or deletes the file.<br /><strong>Multi-vendor platform support</strong> – ICAP-compatible NAS and SAN plus Nutanix Files and ShareFile.<br /><strong>Exclusions and reporting</strong> – Custom exclusions, default actions, reports and real-time notifications.<br /><strong>Important</strong> – No endpoint agent, EDR or backup; requires a GravityZone base product.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender GravityZone Security for Storage Add-On?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Security for Storage is an add-on that scans files on ICAP-compatible network-attached storage and file-sharing systems using one or more Bitdefender Security Server virtual appliances. It is managed centrally from the same GravityZone Control Center as the rest of the platform, so storage policies sit next to endpoint policies instead of in a separate tool.<br /><br /><strong>Blocks infected files</strong> – Malware is stopped before it spreads across shares.<br /><strong>No agent required</strong> – The NAS needs no installed Bitdefender software.<br /><strong>One estate, one deployment</strong> – Mixed NAS vendors share the same scanning infrastructure.<br /><strong>Load balancing</strong> – The ICAP client spreads requests across several servers.<br /><strong>Audit-ready reports</strong> – Scheduled reports and notifications document storage scanning activity.<br /><strong>Placement flexibility</strong> – Security Servers can run close to cloud NAS.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender GravityZone Security for Storage Add-On suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether shared storage is central to daily work and whether that storage speaks ICAP. A ten-person engineering office with a Dell NAS holding all project data has a stronger case than a hundred-person company that keeps everything in endpoints and cloud services.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Likely</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Sometimes</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">ICAP-capable shared storage in use</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Only with NAS</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Storage Add-On meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The Swiss reporting obligation applies to operators of critical infrastructure, not to every company, so the first question is whether your organisation is in scope at all. Under the revised Information Security Act (ISG), an affected operator must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Security for Storage supports that deadline in one narrow but practical way: when a Security Server returns a malicious verdict, the event lands in GravityZone Control Center with the file, the storage system and the timestamp, which is the kind of detail a first report has to contain. It does not reconstruct the attack path, it covers no endpoints, mailboxes or identities, and it produces no incident timeline, so the decision to report still rests on your other monitoring. This text is general information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified adviser.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Storage Add-On meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational risk management, not software features. NIS 2 requires essential and important entities to put in place measures covering areas such as incident handling, business continuity and backup, supply chain security, access control and the use of cryptography. Security for Storage contributes to exactly one of those areas: malware handling on shared storage, by blocking infected files at the moment the storage system is asked to serve them. It contributes nothing to backup and recovery, access control, supplier assessment, cryptography or staff training, and it plays no part in incident reporting workflows. Treat it as one technical control inside a wider management system rather than as a compliance measure in its own right.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Security for Storage Add-On help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for a small and specific set of items. It gives you a documented answer on malware scanning of shared storage: which systems are scanned, which detection layers run against each file, and who is allowed to change the policy, with scheduled reports from Control Center that can be attached as evidence. It answers nothing about backup and restore testing, encryption of data at rest, access rights reviews, patch levels, log retention periods or incident response times, and a questionnaire that asks about those will still come back with gaps. Where those gaps matter, closing them with a higher GravityZone edition or the matching GravityZone add-ons is usually cheaper to run and easier to evidence than mixing vendors, because the proof then comes out of a single console in a single format.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Explains why malware scanning and a tested backup answer different questions, and what an outage actually costs.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The add-on only protects storage that can act as an ICAP client, so a plain Windows or Linux file server without ICAP support is not covered by this module and still needs the ordinary GravityZone endpoint agent. Platform support is version-specific: Bitdefender lists Nutanix Files 3.x up to 4.2.1, Citrix ShareFile, Citrix ADC VPX and F5 BIG-IP VE ASM alongside ICAP-compatible NAS and SAN systems from Dell, EMC, IBM, Hitachi, HPE and Oracle, so the firmware version on your array is worth checking before you order. You also need somewhere to run the Security Server appliances, ideally on a host close to the NAS, and for a cloud NAS deployment they belong in that same environment. Scanning is not backup: an infected file is blocked or deleted on access, but a file already encrypted by ransomware can only come back from a restore. Finally, this is an add-on and not a standalone purchase, so it has to sit on top of an existing GravityZone product.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Looks at where built-in Windows protection stops and which layers a business environment still has to cover itself.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender GravityZone Security for Storage Add-On</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">How many Security Servers are needed?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">One Security Server is technically enough to perform ICAP scanning. Bitdefender nevertheless recommends installing and configuring at least two, so that the first can redirect surplus scan requests to the second when it is overloaded.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What happens when a user opens an infected file?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">When someone opens, reads, writes or closes a file, the NAS or file-sharing system acts as the ICAP client and sends a scan request to the Security Server. The Security Server returns a verdict and the storage system then allows access, denies access, or deletes the file, depending on the configured action.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Is Nutanix Files supported under its former name?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Bitdefender certifies Security for Storage with Nutanix Files, which was previously called Acropolis File Services (AFS). If your documentation still uses the older name, it refers to the same supported platform.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,sec-console" data-audience="b2b" data-count="3"> </div>