What are the core benefits of Trend Micro Worry-Free Services + EDR Add-On?
Cloud console – All endpoints managed centrally from one hosted web console.
Attack tracing – Root cause analysis shows entry point and spread.
Endpoint isolation – Cut suspicious Windows devices off the network in one click.
Threat sweeping – Search all endpoints for indicators of compromise.
Multi-platform protection – Windows, macOS, iOS and Android protected from one console.
Important note – No email security; EDR telemetry covers Windows only.
Worry-Free Services protection – Anti-malware, behaviour monitoring, machine learning, firewall and web reputation.
Endpoint Sensor (EDR) – Records Windows endpoint activity for investigation and threat hunting.
Threat Investigation – IoC sweeping and colour-coded root cause analysis across endpoints.
Response actions – Isolate endpoints, block suspicious objects and submit samples to sandbox.
Device and data control – Device control, application control, endpoint DLP and full disk encryption.
Important – No email security, no patch management, no 24/7 managed monitoring.
Trend Micro Worry-Free Services + EDR Add-On combines the cloud-hosted Worry-Free Services endpoint protection with the Endpoint Detection and Response add-on, and both are managed centrally from the same Worry-Free web console. Trend Micro documentation still lists the base product as Worry-Free Business Security Services, and since March 2026 Trend Micro's enterprise business operates under the name TrendAI.
Faster incident answers – Root cause view shows how a threat entered and spread.
Remote containment – Isolate a compromised endpoint from the console while investigating.
One agent, one console – EDR runs inside the existing Security Agent, no second product.
Unknown file analysis – Suspicious samples are submitted to the Trend Micro cloud sandbox.
Proactive threat hunting – Sweep all endpoints for indicators taken from new threat reports.
Built-in virtual patching – Vulnerability protection shields known Microsoft application flaws before patching.
The package fits small and medium-sized companies that need investigation and containment on Windows endpoints without running their own security operations centre. The IT administrator or a managed service provider handles alerts in the same console used for daily endpoint management. Large companies usually need correlation across email, network and cloud, plus round-the-clock monitoring, and this package provides neither.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Common | Common | Standard |
| EDR investigation on Windows endpoints | ✓ | ✓ | Partial |
| This product fits | ✓ | ✓ | Limited |
Since 1 April 2025, the revised Information Security Act has required operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Most small and medium-sized companies are not directly subject to this obligation, but suppliers to operators of critical infrastructure are often asked to demonstrate comparable incident handling. The Threat Investigation and root cause analysis of the EDR add-on supply the facts such a report needs: which Windows endpoints are affected, how the attack entered and when it was detected. Endpoint isolation documents that containment started. The product does not submit reports to BACS, does not see attacks that arrive by email, and includes no staffed round-the-clock monitoring, so the 24-hour deadline depends on how quickly someone reviews the alerts. This information does not constitute legal advice; the specific obligations of a company should be clarified with a qualified legal adviser.
No software product makes a company compliant with the NIS 2 Directive, because the directive requires organisational risk-management measures as well as technical ones. The directive's measure categories include incident handling, business continuity, supply chain security, vulnerability handling, cryptography and access control. Trend Micro Worry-Free Services + EDR Add-On supports incident handling through EDR investigation and isolation, cryptography through full disk encryption, and vulnerability handling in part through virtual patching of known Microsoft application flaws. It does not cover backup and business continuity, multi-factor authentication, third-party patch deployment, email security or staff awareness training, all of which need separate measures.
Yes, for the endpoint section of a typical supplier questionnaire, but not for the whole questionnaire. The product lets you answer yes to centrally managed anti-malware on all devices, EDR capability with investigation and isolation on Windows endpoints, full disk encryption, device control, application control and endpoint DLP. It does not let you answer yes to email and phishing protection, third-party patch management, 24/7 security monitoring, backup, or multi-factor authentication. The most economical way to close the gaps within the same family is Worry-Free XDR, which adds email security and correlation between email and endpoint, or Worry-Free with Managed XDR, which adds 24/7 detection and response by Trend Micro analysts. Backup and multi-factor authentication require separate products in every Worry-Free edition.
The decisive difference is email. Worry-Free XDR adds a cloud email gateway, API-based protection for Microsoft 365 and Google Workspace, and the ability to trace an endpoint threat back to the email it came from. The EDR add-on correlates activity on endpoints only. Endpoint protection, mobile coverage, disk encryption and cloud sandboxing are identical across both editions, and neither includes 24/7 managed detection, which requires Worry-Free with Managed XDR.
| Feature | Worry-Free Services | Services + EDR Add-On | Worry-Free XDR |
|---|---|---|---|
| Windows and macOS protection | ✓ | ✓ | ✓ |
| iOS and Android protection | ✓ | ✓ | ✓ |
| Full disk encryption | ✓ | ✓ | ✓ |
| Endpoint Sensor (EDR) | ✕ | ✓ | ✓ |
| Endpoint isolation | ✕ | ✓ | ✓ |
| Cloud sandboxing | ✕ | ✓ | ✓ |
| Email and Microsoft 365 protection | ✕ | ✕ | ✓ |
| Threat correlation | ✕ | Endpoint only | Endpoint and email |
| 24/7 managed detection | ✕ | ✕ | ✕ |
Endpoint Sensor, isolation and sample submission are configured in the Windows policy, so EDR investigation and response apply to Windows desktops and servers. macOS, iOS and Android devices receive protection but deliver no EDR investigation data. The documented platform scope covers Windows, macOS, iOS and Android, and Linux servers are not part of it. Email is not covered: phishing and business email compromise protection for Microsoft 365, Google Workspace or Exchange requires Worry-Free Services Advanced or Worry-Free XDR, and this is the most common follow-up purchase. Vulnerability protection shields known flaws but does not deploy third-party patches, and 24/7 analyst monitoring is only available with Worry-Free with Managed XDR.
No. The EDR add-on is assigned to a specific Worry-Free Services instance and activates the Detection and Response features inside that console. This package combines the base protection and the add-on, so no separate base product is needed.
Yes. Trend Micro operates a separate Worry-Free Services web console for the Europe, Middle East and Africa region alongside the instance for North America and other regions.
Yes. A Worry-Free instance can be registered in TrendAI Vision One with an enrolment token, and it then forwards detection logs and Security Agent information to the platform. This connection is the basis for using Cyber Risk Exposure Management on top of Worry-Free.
Cloud-managed endpoint protection with EDR for Windows: root cause analysis, IoC sweeping and one-click isolation. Email security not included.
Trend Micro Worry-Free Services + EDR Add-On, Trend Micro, TrendAI, Worry-Free Business Security Services, endpoint detection and response, cloud endpoint security, root cause analysis, endpoint isolation
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies