What are the essential features of WithSecure Server Security Premium Corporate?
Central management – Runs from the on-premises Policy Manager console.
Windows servers – Covers Windows Server 2016 through 2025 only.
Software Updater – Patches Windows and third-party server applications.
DataGuard protection – Shields chosen folders from ransomware encryption attempts.
Terminal servers – Protects Citrix and RDP session hosts.
Important note – No EDR, encryption or Exchange mailbox protection.
Malware protection – Real-time and scheduled scanning on Windows file servers.
DeepGuard behavioural analysis – Blocks unknown applications that alter system settings or processes.
DataGuard folder shielding – Premium only: guards selected folders against ransomware encryption.
Software Updater – Premium only: patches Windows and third-party server software.
Offload Scanning Agent – Moves scanning off virtual machines to a scanning server.
Important – No EDR, no encryption management, no Exchange or Linux coverage.
WithSecure Server Security Premium is the Windows server anti-malware component of WithSecure Business Suite, sold to commercial buyers as the Corporate licence variant rather than the educational or governmental one. It was called F-Secure Server Security before the company rebranded to WithSecure, and it runs either centrally managed from the on-premises Policy Manager console or locally through its own web console.
On-premises management – Keeps policies and logs inside your own network.
Patching without extra tools – Software Updater removes the need for a separate patch server.
Ransomware folder control – DataGuard limits which applications may write to data shares.
Offline update path – Isolated servers update definitions from a Policy Manager package.
Terminal server support – Covers Citrix XenApp, Virtual Apps and RDP session hosts.
Windows Server 2025 ready – Supported on Server 2016, 2019, 2022 and 2025 editions.
The deciding factor is not headcount but whether you already run an on-premises management server. A company with two Windows file servers and no Policy Manager installation carries the console overhead for very little gain, while a company with fifteen servers, a terminal server farm and a policy that data must stay in-house gets the most out of it.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | If supplying | ✓ | ✓ |
| Own on-premises management server | Often too much | ✓ | ✓ |
| This product fits | Limited | ✓ | Partly |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure named in Article 74b ISG, such as energy and drinking water suppliers, transport companies, hospitals and cantonal and communal administrations, not to every Swiss company. Those operators must submit an initial report to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering a cyberattack, with the remaining detail following within 14 days. Server Security Premium supports the discovery half of that clock: the event history and the Policy Manager alerts record which server was hit, which detection fired and at what time, which is the minimum a first report needs. It does not support the reconstruction half, because there is no EDR telemetry, no attack timeline and no long-term event retention, so the 14-day follow-up report has to be assembled from Windows event logs or a separate logging system. Software Updater helps on the preventive side by closing known vulnerabilities in Windows and third-party server software before they are exploited. This description is not legal advice; whether your organisation falls under the reporting obligation should be clarified with a qualified legal adviser.
No software product creates NIS 2 compliance, because the directive obliges the organisation, not the tool. NIS 2 requires categories of measure that include risk analysis and security policies, incident handling, business continuity and backup management, supply chain security, vulnerability handling, cryptography, access control and multi-factor authentication. Server Security Premium contributes to vulnerability handling through Software Updater, to incident prevention through malware protection and DeepGuard, and to data protection through DataGuard folder controls. It contributes nothing to backup and business continuity, nothing to encryption or key management, nothing to multi-factor authentication, and nothing to supplier risk management, so those measures need separate products or processes. The directive also expects that measures are assessed for effectiveness, and reporting from Policy Manager can serve as partial evidence for the endpoint protection and patching categories only.
Yes, for the server-hardening block of a typical questionnaire, and not much beyond it. It answers questions about anti-malware on servers, behavioural detection, ransomware controls on file shares, application control, centrally enforced security policy, and whether operating system and third-party patches are applied on a defined schedule, all with a report you can export from Policy Manager. It does not answer questions about multi-factor authentication, encryption at rest, backup and tested restores, log retention or SIEM export, network vulnerability scanning, mobile device management, email filtering, or 24/7 monitoring and incident response, and pretending otherwise tends to surface badly during a customer audit. The cheapest way to close the largest gaps is usually to stay inside the same vendor family rather than mix suppliers: WithSecure Email and Server Security adds Exchange and SharePoint scanning, Business Suite Endpoint Detection and Response adds the detection and response layer, and the cloud-managed WithSecure Elements line adds vulnerability management and collaboration protection. Backup remains a separate purchase in every case.
The decisive difference is Software Updater: only the Premium edition can find and install missing Windows and third-party patches on the protected server, which is the feature that removes a separate patch tool from your stack. Premium also adds DataGuard, which restricts write access to nominated folders and is aimed squarely at ransomware on file shares, and Application control. Everything else, including malware protection, DeepGuard, browsing protection, web traffic scanning and the Offload Scanning Agent, is identical in both editions. Neither edition contains Microsoft Exchange or SharePoint protection; that is the separate WithSecure Email and Server Security product.
| Feature | Server Security | Server Security Premium |
|---|---|---|
| Malware protection and DeepGuard | ✓ | ✓ |
| Software Updater patching | ✕ | ✓ |
| DataGuard folder protection | ✕ | ✓ |
| Application control | ✕ | ✓ |
| Browsing protection and web traffic scanning | ✓ | ✓ |
| Offload Scanning Agent for virtual servers | ✓ | ✓ |
| Exchange and SharePoint protection | Separate product | Separate product |
The most important point is lifecycle rather than feature scope: WithSecure has announced the end of life of the entire Business Suite line, including Server Security, for 30 September 2028, with an earlier date of 31 December 2027 for customers in Japan, and names the cloud-managed WithSecure Elements as the replacement, so this is a product with a defined runway rather than an open-ended platform choice. Platform coverage is Windows Server 2016, 2019, 2022 and 2025 only, on x86-64; there is no Linux agent in this product, no macOS support, no ARM support and no Windows Server 2016 Nano support. Central management is not a cloud portal but an on-premises Policy Manager server that you install and maintain yourself, and the deployment package for the agent is exported from the Policy Manager Console, so plan that component in even if you only have a handful of servers. The firewall function relies on Windows Firewall rather than an own filtering engine, and browsing protection and web content control depend on a browser extension being present, which matters on locked-down terminal servers. The follow-up purchases that catch buyers out most often are Exchange and SharePoint scanning, detection and response, and backup, none of which are part of this product.
Yes, in practice you do. The installation package is created in the WithSecure Policy Manager Console, either as a JAR package pushed remotely to selected hosts or as an exported MSI that you run locally or distribute through another deployment system. Even a local installation on a single server therefore starts with the Policy Manager export tool.
Microsoft Windows Terminal and RDP Services on the supported Windows Server versions, plus Citrix XenApp 5.0, 6.0 and 6.5, Citrix XenApp 7.5, 7.6, 7.14 and 7.15, and Citrix Virtual Apps and Desktops 2009. On virtualised hosts the Offload Scanning Agent moves the scanning work to a separate Scanning and Reputation Server, which is what keeps session hosts responsive during scans.
Policy Manager ships with a definitions update tool that you run on a machine with internet access to build a single archive of the latest malware definitions. You transfer that archive to the isolated server and apply it with the fsaua-update tool included in the Server Security installation, which is the supported route for segmented production or OT networks.