What are the key advantages of WithSecure Business Suite Premium?
Centrally managed – From your own on-premises Policy Manager server.
Endpoint protection – Covers Windows desktops, laptops and macOS clients.
Server coverage – Windows file, Citrix, terminal and Linux servers.
Exchange scanning – Email and Server Security covers Exchange and SharePoint.
Integrated patching – Software Updater closes third-party application vulnerabilities.
Important note – No EDR component; detection and response needs Elements.
Policy Manager – On-premises management console that you host and operate yourself.
Client Security – Endpoint protection for Windows desktops, laptops and macOS computers.
Server and Linux Security – Covers Windows file servers, Citrix, terminal and Linux.
Email and Server Security – Scans Microsoft Exchange and SharePoint, including spam filtering.
Software Updater – Patches Windows and third-party applications from the console.
Important – No EDR component; detection and response requires WithSecure Elements.
WithSecure Business Suite Premium is an on-premises security bundle for Windows, macOS and Linux systems, managed entirely from a Policy Manager server that runs inside your own network. The same product line was previously sold as F-Secure Business Suite, and many buyers still search for it under that name.
Full on-site control – Policies, logs and update distribution stay inside your network.
DataGuard – Adds ransomware monitoring to document, download and temp folders.
Application Control – Blocks applications and scripts by rules you or WithSecure define.
Connection Control – Raises the security level during sensitive intranet or banking sessions.
Web Content Control – Restricts browsing categories per policy without a separate proxy.
Bandwidth-friendly updates – Policy Manager Proxy distributes definition updates across remote sites.
The deciding factor here is not headcount but whether you have a Windows server to run Policy Manager on and an administrator who maintains it. Regulatory exposure follows sector and role rather than company size, so a small operator in a supply-critical sector can carry heavier duties than a larger company outside those sectors.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | Occasionally | Often | Standard |
| Own server for Policy Manager | Rarely | Usually | ✓ |
| This product fits | Limited | ✓ | ✓ |
The Swiss reporting obligation follows sector and role, not company size. Under the revised Information Security Act, operators of critical infrastructure must report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. WithSecure Business Suite Premium supports that duty at the detection stage, because Policy Manager collects alerts, scan results and policy status from every managed client in one place, which is usually the first evidence an administrator reaches for when the clock starts. What it cannot do is reconstruct the attack chain: without an EDR component there is no recorded process telemetry, so questions about entry point, lateral movement and dwell time have to be answered from other sources. The report itself stays a manual, organisational task, and no endpoint product performs it for you. This description is not legal advice, so if you are unsure whether your organisation falls under the obligation, have that assessed by a qualified specialist.
No security product makes an organisation NIS 2 compliant, because the directive addresses management accountability, risk management and process, not software features. NIS 2 requires measures across defined categories, among them risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, access control, cryptography and staff training. Business Suite Premium contributes to a narrow set of those: vulnerability handling through Software Updater, incident detection and containment through the endpoint, server and mail components, and access control at device and application level through Device Control and Application Control. It contributes nothing to business continuity and backup, encryption and key management, multi-factor authentication, supplier assessment or staff training, all of which need separate tools and written procedures. Treat the suite as evidence for the technical measures on endpoints and servers, not as coverage of the directive.
Partly, and the split is predictable enough to plan around. It answers the endpoint block directly: whether anti-malware runs on all workstations and servers, whether it is centrally enforced rather than locally configurable, whether removable media is restricted, whether unapproved applications and scripts can be blocked, whether operating system and third-party patching is automated, and whether mail servers are scanned. Policy Manager exports that state per host, which is what a reviewer usually asks for instead of a feature description. It does not answer the items that questionnaires now weight most heavily: continuous endpoint detection and response with retained telemetry, 24/7 monitoring or a managed service, defined log retention with SIEM forwarding, multi-factor authentication, disk encryption with central key recovery, tested backup and restore, mobile device management, and network-wide vulnerability scanning. If those gaps hold up a contract, the cheaper route is normally to stay inside the WithSecure family and move to Elements, which adds EDR and vulnerability management on the same agent base, rather than adding a second vendor console alongside an on-premises deployment.
The decisive difference is patching: Software Updater is Premium only, so the Standard edition leaves third-party application vulnerabilities to a separate tool or to manual work. Premium also adds the control layers that most administrators buy this suite for, namely DataGuard, Application Control, Web Content Control and Connection Control. Both editions share the same detection stack, including DeepGuard behavioural analysis, browsing protection, Botnet Blocker and spam control for Exchange. If you already run a patch management product, the practical gap between the editions narrows sharply; if you do not, Premium is the only edition that closes it.
| Feature | Business Suite Standard | Business Suite Premium |
|---|---|---|
| DeepGuard behavioural analysis | ✓ | ✓ |
| Browsing protection and Botnet Blocker | ✓ | ✓ |
| Spam control for Exchange | ✓ | ✓ |
| DataGuard ransomware protection | ✕ | ✓ |
| Application Control | ✕ | ✓ |
| Software Updater patching | ✕ | ✓ |
| Web Content Control | ✕ | ✓ |
| Connection Control | ✕ | ✓ |
The most important one is the end of the product line: WithSecure has announced that Business Suite reaches end of life on 30 September 2028, after which the product and every component of it become fully unsupported, with 31 December 2027 applying to customers in Japan. The named replacement is WithSecure Elements, which is cloud-managed, so a later migration also means giving up the on-premises console that is the main reason to choose this suite in the first place. There is no EDR component and no mobile device coverage, and that is where follow-up purchases usually start. Software Updater patches Windows and third-party Windows applications, so macOS and Linux systems still need their own update process. Backup, encryption management and multi-factor authentication are not part of the suite at all.
No. Management runs entirely through Policy Manager, which you install and maintain on your own server. Cloud-based management of WithSecure agents is a feature of WithSecure Elements, not of Business Suite.
Business Suite is the on-premises line built around a self-hosted Policy Manager, while Elements is the cloud-managed platform and the officially named successor. Elements also carries the components Business Suite does not have, in particular endpoint detection and response and vulnerability management.
Client Security covers Windows desktops and laptops as well as macOS, Server Security covers Windows file, Citrix and terminal servers, and Linux Security covers Linux servers from the same console. Email and Server Security adds scanning for Microsoft Exchange and SharePoint. Mobile platforms such as Android and iOS are not covered.
On-premises endpoint and server protection managed from your own Policy Manager server. Premium adds patch management. No EDR component.
withsecure business suite premium, WithSecure, Business Suite, F-Secure Business Suite, endpoint protection, policy manager, software updater, on-premises antivirus, server protection
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies