LUCIDTextjet - Print logo

WithSecure Co-Monitoring Service Out of Office

Short Description

Open HTML

What are the key advantages of WithSecure Co-Monitoring Service Out of Office?
Console-managed service – Runs inside the WithSecure Elements Security Center, no extra software.
After-hours coverage – Analysts watch severe-risk EDR detections when your team is off.
Human validation – Threat analysts separate true incidents from false positives.
Direct escalation – Confirmed attacks go straight to your partner or on-call contact.
Containment guidance – Concrete advice such as isolating hosts or stopping malicious processes.
Important note – Requires Elements EDR; WithSecure advises, your team executes response.

Long Description

Open HTML

What is included in WithSecure Co-Monitoring Service Out of Office?

Severe-risk detection monitoring – WithSecure analysts watch severe-risk Elements EDR detections outside your business hours.
Validation and investigation – Each detection is checked and classed as true or false positive.
Timely escalation – Confirmed incidents are escalated to your partner or designated on-call contact.
Containment and remediation advice – Analysts recommend steps such as network isolation or killing malicious processes.
Elevate for other detections – Lower-rated detections you are unsure about can be escalated for review.
Important – No endpoint agent or hands-on response included; Elements EDR is required separately.

What are the main benefits of WithSecure Co-Monitoring Service Out of Office?

WithSecure Co-Monitoring Service Out of Office is an add-on for WithSecure Elements EDR in which WithSecure's Detection and Response Team monitors severe-risk detections during the hours your own team is off duty. It is activated and used through the cloud-based Elements Security Center, so there is no separate console or agent to deploy.

Closes the night gap – Attacks starting at night or on weekends are reviewed by analysts.
Keeps daytime control – Your own team keeps handling detections during normal working hours.
Less alert fatigue – False positives are closed by analysts instead of waking your on-call staff.
Faster first response – On-call contacts receive a validated incident with concrete containment steps.
European analyst team – WithSecure states its Detection and Response Team operates entirely within Europe.
Path to incident response – Major incidents can escalate to WithSecure incident response, bought separately.

Best antivirus? Why Windows Defender alone is not enough
Explains why relying on the built-in Windows Defender alone leaves security gaps.

Which company size is WithSecure Co-Monitoring Service Out of Office suitable for?

This service fits organisations that already run Elements EDR and have someone reviewing detections during the working day, but nobody on duty at night or on weekends. The deciding factor is less the headcount than whether a person with authority can act on an escalation at any hour, because the service provides containment advice while carrying out the response remains with you or your IT partner.

RequirementSmall businessMedium-sized companyLarge company
Reporting obligation Switzerland Rarely By sector By sector
NIS 2 in the European Union Rarely By sector By sector
Security questionnaire from large customers Occasional Common Standard
Own staff reviewing detections in office hours Often via partner ✓ ✓
This product fits With IT partner ✓ Daytime SOC only

Does WithSecure Co-Monitoring Service Out of Office meet the requirements of Swiss cybersecurity legislation?

Under the revised Information Security Act, operators of critical infrastructure in Switzerland, for example in energy, healthcare, transport, finance, telecommunications and public administration, must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Most SMEs outside these sectors are not directly subject to this obligation, although they can be affected indirectly as suppliers. For affected operators, Co-Monitoring Out of Office supports the part that is hardest to staff: noticing and validating a serious endpoint attack at night or on a weekend, so it is confirmed promptly rather than on the next working day. It does not decide whether an incident is reportable, does not file the report, does not cover systems without the Elements EDR sensor, and does not automatically monitor detections below severe risk. This information does not constitute legal advice; please have your specific obligations assessed by a qualified specialist.

Does WithSecure Co-Monitoring Service Out of Office meet the requirements of European cybersecurity legislation?

No product makes an organisation compliant with the NIS 2 Directive, which requires essential and important entities to implement cybersecurity risk-management measures and to send an early warning of significant incidents within 24 hours. The required measure categories include risk analysis policies, incident handling, business continuity and crisis management, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication. Co-Monitoring Out of Office supports incident handling, specifically detection, triage and containment guidance for severe endpoint threats outside office hours, which helps an entity recognise a significant incident early enough for the early-warning deadline. It does not cover business continuity, backup, vulnerability or patch management, access control, multi-factor authentication, encryption or staff training, and it does not submit notifications to authorities.

Does WithSecure Co-Monitoring Service Out of Office help with security questionnaires from large customers?

Partly: it gives you a documented answer to whether endpoint security events are monitored outside business hours, and by whom. It answers questionnaire items on after-hours monitoring of endpoint detections, human validation of alerts, defined escalation to named contacts, and access to incident response expertise through an optional retainer. It does not answer items on external monitoring during business hours, containment carried out by the provider, published response-time SLAs (WithSecure publishes these for its MDR service, not in the Co-Monitoring material), identity or cloud monitoring, vulnerability management, backup or multi-factor authentication. If the only gap is daytime coverage, the 24/7 Co-Monitoring Service closes it; if a customer explicitly requires round-the-clock managed detection and response with provider-executed containment, WithSecure Elements MDR within the same platform is usually simpler than combining services from different vendors.

What is the difference between WithSecure Co-Monitoring Service and Co-Monitoring Service Out of Office?

The decisive difference is the monitoring window: the standard WithSecure Co-Monitoring Service watches severe-risk detections 24/7, while the Out of Office variant covers only the hours outside your business hours. Both variants use the same Detection and Response Team, the same validation and escalation process and the same containment advice. The Out of Office variant therefore assumes that someone in your organisation or at your IT partner reviews Elements EDR detections during the working day. If that daytime coverage is not reliable, the 24/7 variant is the safer choice.

FeatureCo-Monitoring ServiceCo-Monitoring Out of Office
Monitoring window 24/7 Off-hours only
Severe-risk detection monitoring ✓ ✓
Analyst validation and investigation ✓ ✓
Escalation to on-call contact ✓ ✓
Containment advice ✓ ✓
Monitoring during business hours ✓ ✕
Response executed by WithSecure ✕ ✕
Requires Elements EDR ✓ ✓

Which limitations should you know before buying?

The service works only on top of WithSecure Elements EDR, so endpoints without the EDR sensor are not monitored, and detections from other Elements modules such as Identity Security or Collaboration Protection are outside the described scope. Automatic monitoring is limited to severe-risk detections; lower-rated detections are only reviewed when you actively elevate them. WithSecure provides advice rather than carrying out isolation or remediation, so an on-call contact at your company or IT partner must be reachable and authorised to act outside office hours. Full incident response, forensics or on-site assistance is not included and requires a separately purchased WithSecure incident response service or retainer. WithSecure's material shows no country-specific feature restrictions for this service.

Frequently asked questions about WithSecure Co-Monitoring Service Out of Office

Does Co-Monitoring Out of Office require installing additional software?

No. The service is activated for an existing Elements EDR environment in the Elements Security Center and works with the detections the EDR sensors already generate.

How does Co-Monitoring differ from WithSecure Elevate?

Elevate is an on-demand, token-based service in which you choose individual detections to send to WithSecure analysts. Co-Monitoring works the other way round: analysts actively watch all severe-risk detections during the agreed monitoring window, and you can still elevate other detections you want reviewed.

 

Meta Description

Add-on for WithSecure Elements EDR: analysts validate severe-risk detections outside office hours. Your team still covers daytime and response.

Keywords

WithSecure Co-Monitoring Service Out of Office, WithSecure, WithSecure Elements, WithSecure Co-Monitoring, Elements EDR add-on, managed detection service, after-hours threat monitoring, severe-risk detection validation, remediation guidance

  

   

COMPANY NAME | First Name, Last name | Address | Phone 0000 - 00 00 00 | Email info@kundendomain.com

By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about 
cookies

I agree