What are the key advantages of WithSecure Co-Monitoring Service?
Central console – WithSecure analysts work in your Elements console.
EDR add-on – Requires WithSecure Elements EDR as base.
24/7 monitoring – Severe-risk detections watched outside your office hours.
Human validation – Analysts separate true positives from false alarms.
Incident escalation – Confirmed attacks escalated with concrete containment advice.
Important note – WithSecure advises, your team performs the response.
24/7 detection monitoring – WithSecure watches severe-risk detections from Elements EDR continuously.
Out-of-hours option – Monitoring can cover only evenings, weekends and holidays.
Human threat validation – Analysts confirm whether a detection is a real incident.
Named contact escalation – Confirmed incidents go to people authorised to act.
Remediation guidance – Advice such as isolating hosts or stopping malicious processes.
Important – WithSecure gives instructions, it does not execute response actions.
WithSecure Co-Monitoring Service is an add-on to WithSecure Elements EDR in which the vendor's own Detection and Response Team reviews your severe-risk detections and tells your staff what to do about them. It is delivered through the Elements cloud console you already use, by the vendor formerly operating as F-Secure Business.
Night coverage without hiring – Closes the gap when nobody is on shift.
Fewer false alarms – Analysts close false positives before they reach you.
Faster incident start – A validated verdict removes the first hour of guesswork.
European delivery team – The Detection and Response Team operates within Europe.
MSP-friendly escalation – Confirmed attacks can be routed to your service provider.
Path to incident response – Cases can be escalated to WithSecure incident response services.
The deciding factor is not headcount but whether anyone in your organisation is watching detections at three in the morning. Companies that already run Elements EDR but have no shift rota are the intended buyers.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | Often |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| In-house monitoring around the clock | ✕ | Rare | ✓ |
| This product fits | If EDR in use | ✓ | Out-of-hours cover |
The reporting duty under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so most SMEs are not directly affected. Organisations that are affected must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. The hard part of that deadline is discovery itself: a clock that starts on a Friday evening runs out before Monday, and Co-Monitoring addresses precisely this by having an analyst review severe-risk detections at night and at weekends and escalate a confirmed incident to a named contact. What the service does not do is file the report, draft its content, or judge whether your organisation falls under the obligation at all. It also sees nothing outside the reach of the Elements EDR agent, so network equipment, OT systems and SaaS platforms remain unmonitored. This text describes product capabilities and is not legal advice; if you need certainty about your own obligations, have them assessed by a qualified lawyer.
No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses governance, documented processes and management accountability at least as much as technology. NIS 2 requires measures across risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, and access control including multi-factor authentication. Co-Monitoring contributes directly to exactly one of those categories, incident handling, by supplying continuous review of detections, a human verdict on whether an event is a real incident, and a documented escalation path to a responsible person. It contributes nothing to backup and business continuity, vulnerability handling, staff training, cryptography, access control or supplier governance, and it does not produce the incident register or notification texts the directive expects. Treat it as one component inside an incident-handling process that still has to be written down and owned internally.
Yes, for a narrow but frequently asked group of questions. It gives you a defensible answer to whether security alerts are monitored outside business hours, whether a qualified human reviews them rather than an automated rule, whether there is a defined escalation path to a named responsible person, and whether you have access to incident response expertise. It answers none of the questions about penetration testing, patch and vulnerability management, backup and restore testing, encryption of devices, access control and multi-factor authentication, security awareness training, or your own certification status. It also does not generate the evidence documents themselves, so the reporting you attach still comes out of the Elements console and your own records. If a questionnaire turns out to demand documented response actions and a contractual response time rather than advisory monitoring, the cheaper route is normally to move up within the same family to WithSecure Elements MDR rather than to add a second vendor alongside your existing EDR.
The decisive difference is who touches the machine. With Co-Monitoring, WithSecure investigates and then hands you instructions, which means somebody on your side has to be reachable and authorised to act on them at any hour. With Elements MDR, the Detection and Response Team carries out containment on your behalf, and WithSecure states an SLA-backed response time of 60 minutes for 90 percent of cases. Co-Monitoring can also be bought as out-of-hours cover only, which suits a team that watches its own console during the working day.
| Capability | Co-Monitoring Service | Elements MDR |
|---|---|---|
| Monitoring window | 24/7 or out-of-hours | 24/7 continuous |
| Human validation of detections | ✓ | ✓ |
| Containment and remediation advice | ✓ | ✓ |
| Response actions taken by WithSecure | ✕ | ✓ |
| Published response time SLA | Not published | 60 minutes, 90 percent |
| Access to forensics specialists | Via retainer | Conditional |
This is an add-on, not a standalone product: without WithSecure Elements Endpoint Detection and Response underneath it there is nothing for the analysts to monitor. Its field of view is limited to detections raised by the Elements EDR agent, so a device without the agent, a firewall, an industrial control system or a third-party cloud service produces no signal the service can act on. The service scope is severe-risk detections rather than every event, which keeps the noise down but means low-severity findings stay with your own team. Because WithSecure advises rather than intervenes, the value collapses if there is no one reachable and authorised to act at the moment of escalation, so the on-call arrangement is a prerequisite and not an optional extra. No availability restriction to specific countries was found in the vendor material, and the Detection and Response Team is described as operating within Europe, which is relevant if data processing location is part of your procurement criteria.
Yes. WithSecure offers the monitoring either around the clock or only outside office hours, so a team that watches its own detections during the working day can buy cover for evenings, nights and weekends alone.
Yes. Confirmed attacks are escalated either to the partner managing the environment or to an on-call contact at the customer, which is why service providers use it to extend their own coverage without staffing a night shift.
The service can be extended so that a case is handed over to WithSecure incident response services. That handover is a separate engagement, either through a retainer or on demand, and is not included in the monitoring itself.
Add-on for WithSecure Elements EDR: the vendor Detection and Response Team validates severe-risk detections 24/7 and advises on containment.
WithSecure Co-Monitoring Service, WithSecure, WithSecure Elements, F-Secure, edr monitoring service, threat validation, incident escalation, out-of-hours monitoring, remediation guidance
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies