The license overview looks neat and tidy. Twenty-five workstations, all with the same protection package, all showing green in the console. Then someone asks about the file server. It’s been running in the corner, unchanged since the move to the new server room, and no one knows off the top of their head whether anything is even installed on it. If it is, then it’s probably the same license as on the workstations—installed at some point because it was handy at the time.
This is the most common blind spot in small and medium-sized environments. It has two distinct causes—one related to licensing and one technical—and both lead to the same result: The device where the data is actually stored is less well protected than the laptops used to access it. This article explains why this is the case, what products are available for file servers, Exchange, NAS systems, and virtual machines, and what people regularly overlook when making purchasing decisions.
For two unrelated reasons. The first is licensing: Most vendors offer server licenses as separate products. Sophos and ThreatDown sell separate products for workstations and servers; ESET has its own line, ESET Server Security, alongside its endpoint products; and Bitdefender offers Security for Servers as a standalone product alongside Security for Workstations. Using a workstation license on a server is therefore not only inadvisable but simply not covered by the license.
The second reason is technical in nature and carries greater weight in day-to-day operations: A workstation product is designed for a device used by a human user. It displays notifications, prompts for user input when making decisions, schedules updates for after work hours, and expects the system to be restarted occasionally. None of this applies to a server that runs without a logged-in user and whose reboot is a scheduled event with advance notice. A server product, on the other hand, provides what matters in that context: preconfigured exclusions for server roles, scanning behavior that takes open files and databases into account, support for installations without a graphical user interface, and policies designed for systems that run continuously.
Taken together, this means that anyone who installs a workstation license on a server saves on one line item in the quote but ends up with a device that, in the worst case, is either misconfigured or shouldn’t be running at all.
The most visible difference is the exclusions. A real-time scanner that encounters an open database file can lock it or move it to quarantine—and then the service stops working. Server products therefore come with predefined settings for common roles or detect them automatically. Sophos describes this as automatic scan exclusions; other vendors address it through role templates in the policy.
In addition, there are features that simply don’t exist on workstations. Sophos Intercept X Advanced for Server includes Server Lockdown, an application lock that, after an initial capture phase, locks the server to its current state: After that, nothing starts that wasn’t already there. On a workstation, this would be impractical because new software is constantly being added. On a server that has been running the same four services for three years, however, it is one of the most effective measures available. This edition also includes file integrity monitoring, which alerts you if someone modifies critical files.
And finally, the platform question: Server products generally support installations without a graphical user interface and Linux distributions. AVG File Server Business Edition, for example, explicitly lists only 64-bit Windows servers as supported systems and excludes Server Core installations. Anyone using Server Core needs to be aware of this before placing an order.
Because that’s where the data is stored that someone would pay a ransom for. An encrypted laptop takes half a day to reinstall. An encrypted file server brings operations to a standstill.
One crucial detail that’s often overlooked is this: The encryption doesn’t even have to take place on the server itself. It starts on an infected workstation and works its way through the shared folders via the connected network drive. From the server’s perspective, a normally logged-in user is accessing and modifying their files—technically, this looks completely normal. This is precisely why server products include protection mechanisms against remotely executed encryption. Sophos calls this component CryptoGuard and explicitly describes the scenario where the ransomware runs on a connected endpoint rather than on the server itself.
An endpoint product running on the server does not have this perspective. It monitors locally executed processes, not access patterns via shared folders.
Partially, and the conditions vary. Bitdefender includes a server component in its GravityZone packages: The scope of coverage specifies desktops and laptops, as well as up to thirty percent file servers. Another important point from the same source is that Linux systems are always counted as servers, even if they are workstations. Anyone operating many Linux devices will thus shift their ratio without realizing it.
Sophos and ThreatDown do not use this mechanism. There, servers are consistently treated as separate product lines, from the entry-level tier to the managed service option. If you upgrade your workstations to a certain tier, you should upgrade your servers to the same tier—otherwise, the chain breaks exactly where the damage occurs.
Practical implication for evaluating solutions: Don’t count your devices by the number of users, but rather in three groups—workstations, servers, and anything on which an agent cannot be installed. The third group is almost always overlooked.
The products that secure a Windows file server are comparable. The table does not include standalone email and storage products, because they serve a different purpose and are covered in separate sections below, nor does it include managed services, which are a service offering rather than a server product.
| Feature | ESET Server Security | Bitdefender Security for Servers | SOPHOS Intercept X Advanced for Server | AVG File Server Business Edition |
|---|---|---|---|---|
| Windows Server | ✓ | ✓ | ✓ | ✓ |
| Linux Server | ✓ | ✓ | Two versions | ✕ |
| Windows Server Core | See note | See note | See note | ✕ |
| Exchange Protection | About Mail Plus | Proprietary product | Proprietary product | Other Edition |
| Application Lock for Servers | See note | See note | ✓ | ✕ |
| File Integrity Monitoring | See note | As an add-on | ✓ | ✕ |
| Console can be operated locally | ✓ | ✓ | ✕ | ✓ |
| Detection and Response for Servers | ✓ | ✓ | Custom version | ✕ |
Regarding the open fields: Whether an installation without a graphical user interface is supported depends on the product version used for all three major providers and should therefore be verified before ordering—only AVG explicitly excludes Server Core. Application blocking and file integrity monitoring are included in Sophos’s Advanced tier for servers; with Bitdefender, integrity monitoring is an add-on module that must be purchased separately; and for ESET, there is no clear manufacturer specification at the product level regarding these two features. Sophos offers two deployment options for Linux with different feature sets that are mutually exclusive—the smaller option essentially includes malware protection and detection of malicious traffic.
For mixed environments with Windows and Linux servers and a console that can also run on-premises, ESET Server Security ⧉ is the obvious choice. The product was formerly known as ESET File Security for Microsoft Windows Server; anyone still searching under the old name will be redirected here. It is managed via the same platform as the workstations, which significantly simplifies operations.
If you’re already using GravityZone and want to license the servers separately, choose Bitdefender GravityZone Security for Servers ⧉—this way, you’ll keep the server licenses included in your workstation packages available in case you add Linux devices later.
For Windows file servers in a small environment without Linux and without the need for application blocking, AVG File Server Business Edition ⧉ is sufficient. The limitations are clearly stated: 64-bit Windows servers only, no Server Core installations, no Linux. If you run Linux servers, you’ll need a separate product from the same family.
Sophos tiers its server products in the same way as its endpoint products, and the differences are particularly noticeable for servers.
SOPHOS Central Intercept X Essentials for Server ⧉ provides protection against malware and encryption attacks. What’s missing is precisely what distinguishes servers from workstations: no application lockdown, no file integrity monitoring, and no multiple configurable policies.
SOPHOS Central Intercept X Advanced for Server ⧉ adds server lockdown and file integrity monitoring, as well as device, web, and application control. For a server running a stable software version, this is the tier that delivers the greatest practical security benefit.
SOPHOS Central Intercept X Advanced for Server with XDR ⧉ is an option if workstations are already running at the XDR level. Leaving servers at a lower level means that the reconstruction of an attack ends exactly where things get interesting.
Because a file scanner and an email scanner operate at different points in the system. File protection on the server checks what is being written to the hard drive. It therefore cannot see what is in the mail queue, what is currently passing through the transport service, or what is stored in a mailbox without ever existing as a single file. An email product integrates into the email flow and filters there—including spam and phishing detection, which a file scanner naturally cannot provide.
That’s why every vendor offers a separate product for this purpose. For Bitdefender, it’s GravityZone Security for Exchange Servers ⧉. For ESET, it’s ESET PROTECT Mail Plus ⧉. Kaspersky offers Kaspersky Security for Mail Server ⧉. G DATA solves this through bundles, such as G DATA Client Security Business with Exchange Mail Security ⧉, where email protection is an integral part of the package from the start—often the simpler procurement option for businesses that don’t want to manage two separate products side by side.
With AVG, Exchange protection is not included in the File Server Business Edition but in a separate edition for mail servers. This is the classic scenario where a company licenses the file server and assumes that Exchange is covered as a result.
Microsoft publishes a list of folders, processes, and file extensions for Exchange that should be excluded from the file scanner—database and transaction log files, queues, content conversion, and more. The reason is clear: if the scanner blocks an open database or log file, it can lead to unexpected database disconnections and, in the worst case, corrupted data. To implement this, Microsoft provides a PowerShell script that determines the actual paths used by the installation, rather than requiring you to type them in manually.
The dangerous part is the other way around. In 2023, Microsoft explicitly revoked four previously recommended exclusions: the folders for temporary ASP.NET files and Inetsrv, as well as the PowerShell.exe and w3wp.exe processes. The reasoning was that these very exclusions prevented the detection of IIS webshells and backdoor modules—which were the most common form of attack against Exchange at the time. Anyone who has adopted an exclusion list from an older manual is still running their Exchange server with a vulnerability in its most sensitive area.
In practical terms, this means: Do not copy the exclusion list; instead, verify it against the current manufacturer documentation for the specific version of Exchange you are using.
Support for Exchange Server 2016 and 2019 ended on October 14, 2025. Since then, Microsoft has stopped providing security updates, bug fixes, and technical support for these versions. The only on-premises version still supported is the Exchange Server Subscription Edition, which has been generally available since July 1, 2025. The limited-time program offering extended security updates for 2016 and 2019 ran until April 14, 2026, and has therefore also expired.
This has two implications for security. First, an email security product cannot compensate for the lack of security updates for the server. The serious Exchange incidents of recent years exploited vulnerabilities in the server itself, not in email attachments. Second: Before purchasing, check whether the email security product even still supports your version. Vendor specifications regarding supported Exchange versions sometimes lag behind the Subscription Edition, and a product that is officially approved only up to Exchange 2019 will not help you with a migration.
For those planning a migration anyway: The time when you switch Exchange versions is also the right time to reassess your email protection, rather than dragging an existing license along with you.
Yes, but not the same product. The Exchange products mentioned here rely on a locally hosted Exchange server. If your email traffic runs through Exchange Online, there’s no server on which an agent could be installed—protection must start where the mailboxes are located, meaning through a connection to the cloud service.
The vendors offer separate products for this purpose. With Bitdefender, Security for Email is a standalone add-on module; with ESET, PROTECT Mail Plus covers both on-premises Exchange and Microsoft 365. It’s important to distinguish between these options when purchasing: A product with “Exchange” in its name usually refers to the on-premises server. If you’re working in a hybrid environment with on-premises Exchange and mailboxes in the cloud, you may need both.
Use a product that scans the storage from the outside. A NAS system or storage array runs a closed operating system on which no protection agent can be installed. The scan must therefore run through an interface provided by the storage system itself: It notifies a scanning service of the access request, and the service then scans the file and either approves or blocks it.
There are dedicated products for exactly this purpose—Bitdefender GravityZone Security for Storage ⧉ as an add-on module, and Kaspersky Security for Storage ⧉ as a standalone product. This is the third device group from the section above that is almost always missing from product offerings: The company uses a NAS to store design data; everyone accesses it, and nothing is scanned there.
Whether such add-on modules require a specific base license and how Base, Base Plus, and Add-On differ is a separate question that should be clarified before placing an order.
As a rule, each virtual machine is counted as a separate server because each runs an operating system that needs to be protected. For more densely populated environments, there are alternative models: Bitdefender GravityZone Security for Virtual Environments ⧉ is licensed by CPU rather than by machine, which pays off as soon as many virtual systems are running on a few hosts.
Technically, there’s a second consideration. If twenty virtual machines on the same host start a scheduled scan at the same time, the performance of the entire host drops significantly. Vendors solve this through offloaded scanning: a lightweight agent in the virtual machine forwards the scan to a central security instance. Sophos offers a dedicated version for Windows servers on VMware ESXi and Microsoft Hyper-V, which is intended as an alternative to the full server agent.
When evaluating solutions, this means: Clarify whether licensing is per machine or per processor, and whether the central scanning instance requires its own license.
The domain controller is the server whose compromise renders everything else worthless—whoever controls it controls every account and every share. It requires the same server protection as a file server, with the same role-specific exclusions for the directory database and the associated log files.
In practice, however, it often falls through the cracks because it doesn’t store any user data and is therefore not perceived as worth protecting. This is a fallacy: In an encryption attack, the domain controller isn’t the target, but rather the tool—the malware is subsequently distributed to all other systems via it. A server product with application blocking is particularly effective here because the software version of a domain controller practically never changes.
If workstations have logging and investigation capabilities, then servers certainly do as well. The reason is the same as with the license tier: An attack that begins on a laptop ultimately affects the server. If logging ends at the server edge, it’s impossible to reconstruct afterward what happened to the data—and that’s exactly the question that will be asked in the event of an incident.
All major providers offer server versions for this purpose, such as ThreatDown Advanced Server ⧉ as the server counterpart to the workstation package of the same name. When comparing two offers, make sure the server licenses are at the same level as the workstation licenses. A quote appears more affordable if the servers have been quietly calculated at the entry-level tier.
Which tier makes sense for your business and how the acronyms differ is determined independently of the server issue and is deliberately not covered here.
Since April 1, 2025, Switzerland has had a mandatory reporting requirement for cyberattacks on critical infrastructure, based on the revised Information Security Act and the Cybersecurity Ordinance. This applies to government agencies and organizations as defined in Art. 74b of the Information Security Act (ISG), including energy and drinking water utilities, transportation companies, listed hospitals, cloud service providers, and data centers, as well as cantonal and municipal administrations. The initial report must be submitted to the Federal Office for Cybersecurity within 24 hours of discovery; any missing information may be provided within 14 days. The ordinance provides for exceptions for smaller organizations and incidents with minor impacts.
One thing is paramount for the report: you must be able to specify which systems were affected and whether data was compromised. This is determined at the server level, not at the workstation. A server product with file integrity monitoring and logged access behavior provides verifiable information for this purpose. An unprotected server or one equipped only with a workstation license does not provide this information—and in that case, the report will contain only an assumption.
What server protection does not do: It does not determine whether your organization is subject to reporting requirements; it does not replace a designated responsible person or a well-established reporting chain; and it provides no information about what data was actually stored on the affected server. This determination is an organizational task.
For organizations with locations or customers in the European Union, the NIS 2 Directive is authoritative. It requires categories of measures, not specific software: risk analysis and security policies, incident response, business continuity and backup management, supply chain security, vulnerability management, effectiveness assessment policies, training, as well as access control and multi-factor authentication. No single product ensures compliance.
On the server side, the following are supported: incident response, vulnerability management (to the extent that vulnerability assessment and patch management are extended to servers), and access control at the system level. The directive’s tiered reporting requirements—early warning within 24 hours, notification within 72 hours, and a final report within one month—are based on the same records as the Swiss reporting requirement.
Not covered are backup and recovery, supplier management, employee training, and management-level accountability. Those who must comply with both sets of regulations in parallel—because their business is based in Switzerland and supplies the EU—can find a detailed comparison elsewhere.
Most of what actually prevents or minimizes server downtime. A security product is no substitute for data backup with tested restore procedures, and in the event of a successful encryption attack, recovery—not detection—determines the duration of the outage. It also does not replace proper management of access rights: If every user has write access to every shared folder, ransomware will encrypt everything that user can access.
Two additional factors come into play. First, remote desktop access reachable from the internet without two-factor authentication—a common entry point that a file scanner cannot prevent because the attacker logs in normally. Second, the server’s own update status. The serious incidents of recent years exploited known, unpatched vulnerabilities in server-side services.
How to not only implement patch management on servers but also demonstrate it to third parties is a topic in its own right and will not be covered here.
Start by taking inventory across four groups, not by preparing a proposal. First, the workstations. Second, the servers, separated into Windows and Linux and noting which ones run without a graphical user interface. Third, the roles that require their own product—Exchange, databases, Terminal Services. Fourth, everything on which an agent cannot be installed: NAS systems, storage arrays, devices with closed operating systems.
Only then is it worth looking at the products. And then a simple rule applies: Servers receive the same level of protection as workstations, not a lower one. Anything else reverses the priorities—access would then be protected, but not what is being accessed.
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies