What are the core benefits of WithSecure Consulting & Training?
Central management – Supports your centrally managed WithSecure environment.
Scoped projects – Each engagement is scoped to your own environment.
Upgrade assistance – On-call help during upgrades and configuration changes.
Health checks – Quarterly reviews and annual updates on your behalf.
Custom training – Tailored product sessions for your own IT staff.
Important note – No licences included; requires existing WithSecure products.
Scoped consulting projects – Deployment, upgrade and management projects tailored to your environment.
On-call upgrade support – Expert availability during upgrades and changes in your environment.
Remote configuration help – Remote connection to assist with configurations, settings and management.
Quarterly health checks – Quarterly reviews plus annual updates performed on your behalf.
Customised training sessions – Product and service training built for your IT organisation.
Important – No protection licences included; an existing WithSecure environment is required.
WithSecure Consulting & Training is a professional services engagement in which WithSecure product experts scope and run deployment, upgrade, management and training projects inside your existing, centrally managed WithSecure environment. WithSecure was previously F-Secure Business, so older internal documentation and purchase records may still list these services under the F-Secure name.
Faster rollout – Experts handle configuration instead of your team learning first.
Fewer upgrade outages – On-call assistance during the change window itself.
Documented maintenance – Quarterly reviews create dated evidence of regular platform care.
Skills stay internal – Training builds capability your own administrators keep afterwards.
Single escalation path – One contact who already knows your environment.
Right-sized scope – You pay only for the project work needed.
Because the service is bought as scoped project work, suitability depends less on headcount than on whether you already run WithSecure products and have someone internally to hand the results to. The table shows how often each requirement typically applies in practice; it does not mean the law itself depends on company size.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | Often |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | Sometimes | Often | ✓ |
| Own staff to receive the knowledge transfer | ✕ | Partial | ✓ |
| This product fits | Limited | ✓ | ✓ |
Since 1 April 2025, operators of critical infrastructure in Switzerland must report significant cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, under the revised Information Security Act. The obligation follows sector and function rather than company size, so a mid-sized energy supplier or IT service provider can be in scope while a larger retailer is not. WithSecure Consulting & Training supports the obligation indirectly: a correctly configured detection deployment shortens the gap between compromise and discovery, and the quarterly health checks leave dated records showing the environment was actually maintained. What the service does not do is detect the attack for you, decide whether it is reportable, or submit the report, because that remains an internal process with named responsibilities and a defined escalation chain. It also cannot produce the incident timeline BACS expects, since that comes from your own logging and case records rather than from a consulting engagement. This text is general information and not legal advice; assess your own reporting obligation with qualified legal support.
No product or service creates NIS 2 compliance, because the directive addresses organisational duties rather than software features. NIS 2 requires essential and important entities to maintain risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in the acquisition and maintenance of systems, procedures to assess whether measures are effective, basic cyber hygiene and training, and access control. This service maps directly to two of those categories: the training measure, through sessions built for your own IT organisation, and security in system acquisition and maintenance, through scoped deployment and upgrade projects. The quarterly health checks and annual updates also feed the requirement to assess whether existing measures still work. What the service does not provide is incident handling as a managed service, business continuity or crisis management planning, supply chain security assessment, or access control across systems outside the WithSecure environment. Those measures stay with your own organisation or require separate services.
Partly, and mostly in the operational sections rather than the technical ones. It gives you concrete answers on patch and configuration management for your security stack, on staff security training, and on whether your protection platform is reviewed on a defined schedule, because the quarterly health check produces a dated record you can cite instead of a claim you have to defend. It does not answer questions on certification status, penetration testing results, secure software development, data processing locations, sub-processor lists, business continuity testing, or 24/7 monitoring coverage. One boundary catches buyers out: WithSecure sold its offensive security consulting business in May 2025, so penetration testing and red teaming are no longer WithSecure services and must be sourced elsewhere. If your open questionnaire items are about monitoring and response rather than deployment quality, adding detection and response from the same WithSecure family, with its built-in Elevate threat-hunting service, closes more items than extra consulting days and keeps console and reporting consistent.
The decisive difference is continuity: Product Consulting and Training is bought as scoped projects with a defined start and end, while a WithSecure Technical Service Manager is a named ongoing contact who follows your environment continuously. The Technical Service Manager acts as your main point of contact for technical matters, proactively watches your open support cases, guides solution decisions, assists with projects and configurations, and gets your support cases prioritised. Product Consulting and Training gives you the same class of expertise but inside an agreed project, together with the quarterly health checks and the customised training sessions. Premium Support sits alongside both and covers reactive 24/7 priority access to technical experts rather than advisory work. Choose the project service when you have a specific rollout, upgrade or training need, and the Technical Service Manager when the real problem is continuous ownership.
| Capability | Consulting & Training | Technical Service Manager |
|---|---|---|
| Engagement model | Per project | Continuous |
| Deployment and configuration help | ✓ | ✓ |
| Scheduled health checks | ✓ | Not stated |
| Customised training sessions | ✓ | Not stated |
| Support case prioritisation | Not stated | ✓ |
Not stated means WithSecure does not list the item for that service, which is not the same as ruling it out. Confirm anything marked this way during scoping.
The central limitation is scope: this is expert time, not protection software, so it has no effect until you already run WithSecure products, and it adds no licences, no console and no detection capability of its own. WithSecure publishes no fixed deliverable catalogue for it because every project is separately scoped, which means you cannot compare it line by line against a competing offer before speaking to WithSecure or your reseller. No country or region restriction on this service could be verified; what is clear is that it is started through a contact form rather than delivered instantly, so delivery language and lead times are agreed during scoping instead of being published. A second frequent surprise is the boundary with offensive security: WithSecure divested its cyber security consulting business on 31 May 2025 and it now operates independently as Reversec, so penetration testing, red teaming and attack simulation are no longer part of the WithSecure portfolio. Buyers who actually need continuous ownership rather than project work usually end up adding a Technical Service Manager or Premium Support afterwards.
The service itself includes customised training sessions about WithSecure products and services for your IT organisation, with the format agreed during project scoping. Separately, WithSecure offers expert-level paid onsite or classroom training on subjects such as security architecture, forensics and incident response, security assessment, and phishing and behavioural science.
Yes. It belongs to WithSecure partner success services alongside partner training, and the WithSecure Elements platform it supports is cloud-based and multi-tenant, so a provider can apply the same configuration standard and health-check routine across several customer tenants from one console. Commercial terms for partners are agreed separately with WithSecure.
WithSecure experts run scoped deployment, upgrade and training projects with quarterly health checks. Requires existing WithSecure products.
WithSecure Consulting & Training, WithSecure Product Consulting and Training, WithSecure, F-Secure, security consulting service, deployment support, technical training, health check
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies