Kaseya Ransomware Protection uses VSA 10 to monitor endpoint files for behavioral signs of crypto-ransomware. It can alert administrators when files are encrypted, isolate an affected device from most network connections, and try to end suspected malicious processes. Policies can cover all local drives or selected drives and paths, apply exclusions, set alert priority, and attempt to shut down an infected system. An isolated endpoint can still reach VSA 10, so administrators can use VSA management features to investigate and remediate it remotely. Kaseya says detection can work with its BCDR tools to restore endpoints to a pre-attack state from backup snapshots. The monitor supports Windows 8.1 and later; network drives, removable drives, and USB mass-storage devices are not monitored. Use requires an active VSA subscription and Ransomware Detection license, an enabled policy, and a communicating VSA 10 Agent on monitored endpoints. Pricing is customized and available by request.
Who it is for
Kaseya describes its ransomware resilience strategy for small and medium-sized businesses and VSA monitoring for MSPs managing targeted devices at scale. It suits organizations already using the required VSA subscription, license, and agent.
What is good
- Can isolate affected endpoints while retaining VSA 10 access.
- Policies can select drives, paths, exclusions, and responses.
- Remote triage and remediation remain available for isolated devices.
- BCDR tools can restore endpoints from backup snapshots.
What to know first
- Monitoring supports Windows 8.1 and later only.
- Network, removable, and USB mass-storage drives are excluded.
- Requires active VSA and Ransomware Detection subscriptions or licenses.
Verdict
Kaseya combines file-behavior monitoring, endpoint isolation, remote remediation, and a stated recovery path through BCDR snapshots. Check the Windows-only monitoring scope and required VSA setup before requesting customized pricing.
Get started with Kaseya Ransomware Protection
- Visit Kaseya's ransomware protection page
- Request a quote for pricing
- Obtain an active VSA subscription and Ransomware Detection license
- Install the VSA 10 Agent on monitored Windows 8.1 or later endpoints
- Enable a policy and configure drives, paths, exclusions, and responses
Limits to know first
Monitoring is limited to Windows 8.1 and later endpoints. Network drives, removable drives, and USB mass-storage devices are excluded; use also requires an active VSA subscription, a Ransomware Detection license, an enabled policy, and a communicating VSA 10 Agent.
Questions about Kaseya Ransomware Protection
How is Kaseya Ransomware Protection priced?
Pricing is on request and customized to customer needs.
Which platforms are supported?
The listed platforms are macOS, web, and Windows. The ransomware monitor itself supports Windows 8.1 and up only.
What is required to use the ransomware monitor?
It requires an active VSA subscription, an active Ransomware Detection license, an enabled policy, and a VSA 10 Agent on monitored endpoints that can communicate with the VSA instance.
Does it monitor network or USB drives?
No. Network drives, removable drives, and USB mass-storage devices are excluded from monitoring.
Can it help restore an infected endpoint?
Kaseya says detection can work with its BCDR tools to restore endpoints to a pre-attack state using backup snapshots.
Which integrations are named?
VSA 10 documentation names Autotask, BMS, and ConnectWise for alerting, and Datto BCDR for restoring a device to a previous state.
Kaseya Ransomware Protection plans and pricing
All plansCompared on ransomware protection software
- Rollback or recovery
- Yes
- Behavioral detection
- Yes
- Automatic isolation
- Yes
- Immutable recovery copy
- Yes
- EDR included
- Yes




