What are the core benefits of WithSecure Client Security for Linux Corporate?
Central management – Policies distributed from the on-premises WithSecure Policy Manager.
Real-time scanning – Blocks malware on file access in defined paths.
Integrity checking – Detects and blocks tampering with baselined system files.
Broad distributions – RHEL, Ubuntu, Debian, SUSE and more on AMD64.
Isolated networks – Offline update packages for hosts without internet access.
Important note – No EDR; Linux EDR requires a WithSecure Elements subscription.
Real-time scanning – Scans files on open, close and execute within configured paths.
Manual and scheduled scans – Full-system scans started from Policy Manager, the shell or weekly schedule.
Integrity checking (HIPS) – Cryptographically signed baseline blocks or reports changes to protected files.
PUA and archive scanning – Detects unwanted applications and scans inside ZIP, RAR and TAR archives.
Offline update packages – Content and update archives keep air-gapped Linux hosts current without internet.
Important – No EDR or patch management; current admin guide documents no firewall module.
WithSecure Client Security for Linux Corporate is sold as the Linux client licence of WithSecure Linux Security 64, part of the on-premises WithSecure Business Suite and managed centrally through WithSecure Policy Manager. The product line was previously sold as F-Secure Linux Security, before F-Secure's corporate business was renamed WithSecure in 2022.
One policy, many hosts – Scan paths, exclusions and malware actions are set once per Policy Manager domain.
Tamper alerts for admins – Added user accounts or replaced system binaries trigger an administrator alert.
Package manager aware – Baseline updates automatically after apt or dnf installs, avoiding false tamper alerts.
Controlled update timing – Updates apply on arrival, daily, weekly, or stay pinned to a tested version.
Syslog-ready event logs – Services log to journal and syslog; Policy Manager forwards alerts to syslog servers.
Migration path to Elements – A built-in migrator moves managed hosts to the WithSecure Elements cloud console.
Infrastructure decides the fit more than headcount. Installation packages are built in WithSecure Policy Manager, so the product suits organisations that already run, or are willing to run, an on-premises Policy Manager server, typically alongside WithSecure Client Security on Windows. A small company without its own server infrastructure is usually better served by a cloud-managed console. Larger organisations with detection and response requirements need EDR in addition to this product.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Exceptions only | By sector | By sector |
| Security questionnaire from large customers | Occasional | Common | Standard |
| EDR on Linux hosts | Optional | Often requested | Expected |
| This product fits | With Policy Manager | ✓ | Plus EDR |
Since 1 April 2025, the revised Information Security Act obliges operators of critical infrastructure, such as energy, healthcare, finance, transport and parts of public administration, to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Most private companies outside these sectors are not directly affected, but often receive comparable requirements from customers who are. On Linux hosts, WithSecure Client Security for Linux Corporate supports the detection side of this obligation: real-time scanning, integrity-checking alerts, the access.log scan record and syslog forwarding from Policy Manager provide a timestamped record of what was found on which host. It does not submit reports to BACS, does not reconstruct an attack chain the way EDR does, and cannot assess whether an incident meets the reporting threshold. This information does not replace legal advice.
No product makes a company compliant with the NIS 2 Directive, because the directive requires organisational risk management rather than a specific tool. The directive names measure categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication. On Linux hosts, WithSecure Client Security for Linux Corporate contributes to incident handling and basic cyber hygiene through malware detection, tamper detection on protected files and centrally enforced policies. It covers none of backup, vulnerability or patch handling, encryption, access control or multi-factor authentication, and it collects no EDR telemetry for investigating incidents. Those measures need separate products and processes.
Partly: it answers the questionnaire items on Linux malware protection, but not those on detection and response. You can confirm that Linux systems run centrally managed anti-malware with real-time scanning, that critical system files are protected by file integrity monitoring, that policy settings can be locked so users cannot switch protection off, and that security events reach a syslog or SIEM system. You cannot confirm EDR or continuous monitoring of Linux hosts, patch and vulnerability management, disk encryption, multi-factor authentication or backup, because the product includes none of these. If a customer requires EDR on Linux, the usually cheaper route is migrating the same hosts to WithSecure Elements with the built-in migrator, rather than running a second vendor's agent next to this one.
With default settings, real-time scanning scans no files at all, so paths must be defined in Policy Manager before a rollout actually protects anything. Installation packages are created in WithSecure Policy Manager, and the current 64-bit version has no web user interface, so an on-premises Policy Manager belongs to the setup. Only 64-bit distributions still supported by their vendor are covered, and ARM64 coverage is narrower than AMD64: SUSE Linux Enterprise Server 15 and Ubuntu 20.04, for example, are listed for AMD64 only. Retail price lists also carry a separate Server Security for Linux licence, so check which licence type your servers need before ordering. The most frequent follow-up purchase is EDR, which on Linux requires a WithSecure Elements subscription rather than this Business Suite licence.
Yes. Real-time scanning covers files on local disks, removable media and network drives, and integrity checking fully supports NFS and CIFS alongside Ext4, ZFS and Btrfs. Scanning files on network file systems takes longer than local scanning.
By default, settings changed locally with the lsctl tool override values from Policy Manager. A setting locked in Policy Manager is always enforced and cannot be changed locally, and a separate policy option controls whether users may stop the product services.
Cloud-based reputation lookups require an internet connection and access to all addresses under the fsapi.com domain. When the product cannot reach Policy Manager for updates, it falls back to the WithSecure update servers directly; fully isolated hosts are updated with offline archives instead.
Linux anti-malware with file integrity checking, managed from the on-premises WithSecure Policy Manager. Suits existing Business Suite users.
WithSecure Client Security for Linux Corporate, WithSecure, WithSecure Business Suite, WithSecure Linux Security 64, F-Secure Linux Security, WithSecure Policy Manager, linux anti-malware, linux endpoint protection, file integrity checking
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies