What are the key advantages of WithSecure Client Security Premium Corporate?
Central management – All endpoints managed from one on-premises server.
Patch management – Software Updater patches Windows and third-party applications.
Ransomware protection – DataGuard shields chosen folders from untrusted applications.
Application control – Rules block unwanted programs, scripts and USB devices.
Mac coverage – Windows and Mac workstations under one console.
Important note – No EDR console included; retires September 2028.
Multi-engine anti-malware – Signature, reputation and emulation scanning with DeepGuard behavioural analysis.
DataGuard folder protection – Blocks untrusted applications from altering high-risk folders and documents.
Software Updater patching – Patches Windows and third-party applications from the Policy Manager console.
Application and device control – Rules restrict which programs, scripts and USB devices may run.
Web and connection control – Category filtering plus hardened browser sessions for banking sites.
Important – No EDR component; detection and response needs a separate subscription.
WithSecure Client Security Premium is the workstation protection component of WithSecure Business Suite, covering Windows and Mac desktops and laptops that are managed from an on-premises WithSecure Policy Manager server rather than a vendor cloud portal. It was sold as F-Secure Client Security before the business unit was renamed WithSecure, and many buyers still search for it under the old name.
Data stays on site – Policies, logs and reports remain on your own server.
Works in isolated networks – Definition updates can be imported manually without internet access.
Patching without extra tools – Software Updater removes the need for separate patch software.
Active Directory sync – The domain tree follows AD and flags unmanaged hosts.
Syslog and SIEM export – Alerts forward to third-party syslog servers over TCP or UDP.
Scheduled reports – Per-domain reports document endpoint status for audits and reviews.
The deciding factor is not headcount but whether you are willing to run and maintain a management server yourself. Companies with an internal IT team or a managed service provider get full value; a business without server administration will find the Policy Manager requirement a real obstacle.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Increasing | ✓ | ✓ |
| Own server for the management console | Often a hurdle | ✓ | ✓ |
| This product fits | Limited | ✓ | With EDR added |
The reporting obligation introduced by the revised Information Security Act applies to operators of critical infrastructure, for example energy and drinking water suppliers, transport companies, healthcare providers and cantonal and communal administrations, not to companies in general. Since 1 April 2025 these organisations must submit an initial report of a qualifying cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with the remaining details following within 14 days. Client Security Premium supports that deadline in one specific way: DeepGuard and DataGuard detections raise timestamped alerts in Policy Manager, which can forward them by email and to a syslog or SIEM server, so the moment of discovery is recorded rather than reconstructed from memory. What it does not do is investigate the incident, reconstruct the attack chain across hosts, or retain forensic telemetry, because there is no EDR component in this licence; it also does not cover servers, mailboxes or mobile devices, which are the systems most reporting cases actually revolve around. Filing the report, assessing whether a given incident is reportable and documenting the follow-up remain organisational tasks that no endpoint product performs. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No software product makes a company compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk analysis and documented processes rather than the presence of a specific tool. NIS 2 requires categories of measures including risk analysis and information system security policies, incident handling, business continuity and backup management, supply chain security, security in the acquisition and maintenance of systems including vulnerability handling, cyber hygiene practices, access control and asset management, cryptography, and multi-factor authentication. Client Security Premium contributes to three of those categories: vulnerability handling, because Software Updater installs missing Windows and third-party patches on a schedule; cyber hygiene, because device, web and application control constrain what runs and what connects; and the detection half of incident handling, because malware and behavioural alerts reach a central console and can be exported to a SIEM. It contributes nothing to business continuity and backup, cryptography and disk encryption, multi-factor authentication, supply chain assessment, or staff training, and it does not extend to servers, mail systems or mobile devices. Buyers should treat it as one measure among many rather than as a NIS 2 answer in itself.
Partly, and it is worth knowing in advance which half. It answers questions about centrally managed anti-malware on all workstations, real-time and scheduled scanning, removable media and USB restrictions, web content filtering, application and script restriction, patch levels for Windows and third-party software with scheduled per-domain reports as evidence, alert forwarding to a syslog or SIEM system, and administrative access control, since Policy Manager supports admin and read-only roles with users imported from Active Directory. It does not answer questions about endpoint detection and response, 24/7 monitoring or a managed detection service, forensic log retention beyond what the console holds, disk encryption, multi-factor authentication, mobile device management, server and mailbox protection, or backup and recovery, and questionnaires from large customers routinely ask about all of these. The cheaper route to closing those gaps is usually to stay inside the same vendor family rather than to run two agents on the same endpoint: WithSecure Server Security for file and application servers, Email and Server Security for Exchange, and a WithSecure Elements subscription where the questionnaire explicitly demands detection and response. Backup and encryption have to come from elsewhere in any case, so plan those as separate line items rather than expecting an endpoint product to cover them.
The decisive difference is Software Updater: only Premium installs missing patches for Windows and third-party applications, which for most buyers replaces a separately purchased patch management tool. Premium additionally adds DataGuard, the folder-level ransomware hardening that blocks untrusted applications from modifying protected document and download folders, plus Application Control for rule-based blocking of programs and scripts, Web Content Control for category-based web filtering, and Connection Control, which restricts other connections while a browser session with a banking or other sensitive site is open. The standard edition covers multi-engine anti-malware, DeepGuard behavioural analysis, browsing protection, firewall management, device control and Botnet Blocker, and is managed from the same Policy Manager console. Both editions are part of WithSecure Business Suite and share the same management model, so the choice is purely about the five additional components.
| Component | Client Security | Client Security Premium |
|---|---|---|
| Central management via Policy Manager | ✓ | ✓ |
| Anti-malware and DeepGuard | ✓ | ✓ |
| Device control and Botnet Blocker | ✓ | ✓ |
| Software Updater patch management | ✕ | ✓ |
| DataGuard folder protection | ✕ | ✓ |
| Application Control | ✕ | ✓ |
| Web Content Control | ✕ | ✓ |
| Connection Control | ✕ | ✓ |
| EDR and response console | ✕ | ✕ |
The most important one is the product lifecycle: WithSecure has announced that Business Suite, including Client Security, Server Security, Linux Security and Policy Manager, will be retired on 30 September 2028, after which the product and all its components become fully unsupported, with the replacement being the cloud-managed WithSecure Elements. There is a regional variation here that European buyers rarely see stated: for customers in Japan the retirement date is 31 December 2027, roughly nine months earlier. The second limitation is structural rather than temporary: installation packages are exported from Policy Manager, so you must operate your own management server on Windows or Linux, and even a client configured to fetch definitions directly from the WithSecure update server is still built and given its initial policy by Policy Manager. Third, this licence covers workstations only, so file and application servers, Exchange mailboxes, Linux systems and mobile devices each require a different WithSecure product, and that is the single most common cause of a follow-up purchase. Finally, Software Updater patches Windows and Windows third-party applications; the Mac client provides malware and browsing protection, so a mixed fleet still needs another route to keeping macOS software patched.
No. Policy Manager distributes malware definitions to managed hosts inside your own network, and for isolated environments with no route to the WithSecure update server, definition packages can be imported manually. Reputation lookups against WithSecure Security Cloud improve detection speed when the endpoint does have internet access, but protection does not stop without it.
Not really. The MSI installer is exported from Policy Manager together with an initial policy, and that policy can be configured to let the client fall back to the WithSecure update server when Policy Manager is unreachable. That covers laptops and off-network machines, but you still need a Policy Manager server to produce the installer and to change settings afterwards.
The software keeps running but receives no fixes and no tested definition updates, which is why WithSecure treats the date as full retirement rather than a soft end of support. The migration path is WithSecure Elements, and a migration tool exports Policy Manager settings and converts them into Elements profiles, though it does not carry over subscriptions, device records or profile assignment rules.