What are the key advantages of WithSecure Client Security Corporate?
Centrally managed – Policies and rollout via on-premises Policy Manager.
Platform coverage – Protects Windows desktops, laptops and Mac computers.
Behavioural protection – DeepGuard blocks unknown malware by observed behaviour.
Botnet blocker – Stops DNS queries to command-and-control domains.
Edition scope – Patch management and DataGuard require Premium.
Important note – No EDR, and Business Suite ends September 2028.
Multi-engine anti-malware – Real-time scanning with reputation lookups from WithSecure Security Cloud.
DeepGuard 6 – Behavioural analysis that intercepts harmful actions before damage occurs.
Managed firewall – WithSecure expert rules layered on the Windows rule engine.
Browsing and web protection – Scans HTTP traffic and blocks harmful sites before download.
Botnet blocker – Blocks DNS queries to known command-and-control domains at host level.
Important – No EDR component; patch management and DataGuard are Premium only.
Client Security is the Windows and macOS endpoint product of WithSecure Business Suite, the vendor's on-premises line that carried the name F-Secure Client Security until the business unit was renamed WithSecure in 2022. It is a base product: the agent protects the workstation, while installation, policies, updates and reporting are driven from WithSecure Policy Manager, a console you run on your own server instead of a vendor cloud portal.
Full on-site control – Policy and reporting data stay on your own server.
Active Directory sync – Console mirrors your AD structure and flags unmanaged hosts.
Central remote installation – Push agents and version upgrades from the console.
Offline site support – Policy Manager Proxy serves updates to remote networks.
Windows and Mac agents – One console covers both desktop platforms centrally.
Mature firewall ruleset – Rules cover ransomware propagation and lateral movement.
The deciding factor is not headcount but whether you can run and maintain a management server. Policy Manager is an on-premises console that needs its own host, patching and backup, so a company without an administrator or an external IT partner will struggle with it. Where that server already exists, the same console scales from a few dozen to several thousand endpoints.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | ✓ |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Own server for the management console | Often a hurdle | ✓ | ✓ |
| This product fits | ✕ | ✓ | Only with EDR |
The Swiss reporting obligation does not apply to every company: it applies to operators of critical infrastructure, including energy and drinking water supply, transport undertakings and cantonal and municipal administrations. Since 1 April 2025 the revised Information Security Act (ISG) requires those operators to report a cyber attack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with a further 14 days to complete the report, and since 1 October 2025 a failure to report can be fined up to CHF 100,000. Client Security supports the factual part of that first report: Policy Manager holds detection events, infection history and host inventory in one place, so you can state which machines were affected and at what time the detection occurred without collecting evidence from individual laptops. What it does not do is reconstruct the attack chain, because there is no EDR component recording process ancestry or lateral movement, so the question of how the attacker entered usually stays open. It also does not create the organisational side of the obligation: someone has to be named as responsible, the console alerts have to be watched, and the 24-hour clock has to be tracked. This text is general product information and not legal advice; whether your organisation is subject to the reporting obligation must be clarified individually.
No software product makes a company NIS 2 compliant, because the directive addresses management responsibility, risk processes and reporting duties rather than the presence of a particular tool. NIS 2 requires categories of measure that include risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cyber hygiene and staff training, cryptography, access control, and multi-factor authentication. Client Security contributes to the cyber hygiene and access control categories through malware prevention, the managed firewall, web traffic scanning and device control, and the Premium edition adds vulnerability handling through automatic patching of Windows and third-party Windows applications. The gaps are substantial and should be planned separately: there is no backup or business continuity function, no disk encryption management, no multi-factor authentication, no supplier risk assessment, no awareness training, and no detection and response capability that would support the incident handling category. Treat the product as one technical control among several, not as a NIS 2 package.
Partly, and it is worth knowing in advance which questions it will not answer. It answers the endpoint protection block cleanly: which anti-malware product is deployed, whether it is centrally managed, whether policies are enforced rather than left to users, whether a host firewall is active with administrator-defined rules, whether removable media can be restricted through device control, and whether a central inventory shows unprotected machines. With the Premium edition you can additionally answer the third-party patching question and the application allow-listing question, both of which appear in most supplier questionnaires. It does not answer the questions on endpoint detection and response, log retention periods, disk encryption of laptops, multi-factor authentication, backup and restore testing, or server and mobile device coverage, and answering those with a stretched interpretation of what Client Security does is the fastest way to fail a follow-up audit. If patching and application control are what is blocking you, moving up to Client Security Premium within the same family is normally cheaper and less disruptive than adding a second vendor, because you keep one agent and one console. If the blocking questions are EDR, encryption or mobile coverage, Client Security cannot be extended to cover them and you are looking at the WithSecure Elements line or a separate product.
The single most decisive difference is patch management: Software Updater, which patches Windows and third-party Windows applications automatically, is Premium only. Premium also adds DataGuard, which places high-risk folders such as downloads, documents and temp directories under additional anti-ransomware monitoring, plus Application Control for blocking unauthorised executables and scripts, Connection Control for elevating security during sensitive browser sessions, and Web Content Control for category-based web filtering. The Standard edition contains the full protection engine, so the malware detection quality itself is not the differentiator. In practice, buyers who intend to retire a separate patch management tool need Premium, and buyers who only need managed anti-malware and a controlled firewall can stay on Standard.
| Feature | Standard | Premium |
|---|---|---|
| Malware and spyware protection | ✓ | ✓ |
| DeepGuard 6 | ✓ | ✓ |
| Managed firewall | ✓ | ✓ |
| Web traffic scanning | ✓ | ✓ |
| Browsing protection | ✓ | ✓ |
| Botnet blocker | ✓ | ✓ |
| Web Content Control | ✕ | ✓ |
| Connection Control | ✕ | ✓ |
| Patch management | ✕ | ✓ |
| DataGuard | ✕ | ✓ |
| Application Control | ✕ | ✓ |
The most important one is the product lifecycle: WithSecure has announced that Business Suite, including Client Security, Server Security, Linux Security and Policy Manager, will be retired on 30 September 2028, after which the product and every component of it become fully unsupported. This date is region-dependent in one case, as customers in Japan reach the same milestone on 31 December 2027, and the vendor names WithSecure Elements as the replacement line. The coverage boundary is the second point: Client Security protects Windows and macOS desktops and laptops only, so file servers need WithSecure Server Security, Linux hosts need WithSecure Linux Security, and mobile devices are not covered at all. The patch management in the Premium edition is described by the vendor as covering the Windows operating system and third-party applications, so do not plan it as a cross-platform patching solution for your Macs. Finally, central management is not a hosted service: Policy Manager runs on a server you provide, patch and back up yourself, which is exactly the trade-off you accept in exchange for keeping policy and reporting data in your own environment.
After that date WithSecure provides no security fixes and no non-security fixes for the product, and virus definition updates are no longer tested against it, which the vendor warns can lead to reduced detection reliability, conflicts with third-party software and false results. WithSecure names Elements as the successor line and publishes a transition support package for moving managed hosts across. If your planning horizon extends past 2028, factor the migration effort in now rather than at renewal time.
No. Client Security is the desktop and laptop product; Windows servers are covered by WithSecure Server Security and Linux systems by WithSecure Linux Security, both separate products in the same Business Suite line. They are managed from the same Policy Manager console, so a mixed estate still means one console, but it does mean more than one product decision.