What are the key benefits of WithSecure Email and Server Security Corporate?
Central management – Policies and reporting through WithSecure Policy Manager.
Exchange protection – Scans mail in transport and in mailboxes.
Spam control – Adjustable filtering level with searchable email quarantine.
SharePoint scanning – Checks documents on upload and on download.
Ransomware protection – DataGuard folder shielding, included in the Premium edition.
Important note – No EDR included, detection and response sold separately.
Server malware protection – Real-time scanning with DeepGuard behaviour analysis on Windows servers.
Exchange transport protection – Filters inbound, outbound and internal mail before delivery.
Exchange storage scanning – Manual and scheduled scans of mailboxes and public folders.
Spam control – Adjustable filtering level, with quarantine, forward or delete actions.
SharePoint document scanning – Checks files on upload and download, blocks infected documents.
Important – No EDR, no encryption and no backup are included.
WithSecure Email and Server Security Corporate is on-premises protection software for Windows servers, Microsoft Exchange and Microsoft SharePoint, sold under the name F-Secure Email and Server Security before the company split. It runs standalone with a local web console, or centrally managed from WithSecure Policy Manager, the on-premises management server of the Business Suite range.
Single server agent – Covers file server duties and mail scanning together.
Mail stopped early – Transport scanning removes threats before they reach mailboxes.
Searchable quarantine – Administrators can release, reprocess or delete held messages.
Ransomware folder shielding – DataGuard blocks unknown applications from protected folders, Premium only.
Script attack visibility – AMSI integration inspects PowerShell and Office script activity.
Outbound disclaimers – Adds standard legal text to all outgoing messages.
Sector and mail architecture decide more than headcount. The product only makes sense if you still run Exchange or file and SharePoint servers yourself; if all mailboxes sit in Microsoft 365, it protects nothing.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Rare | By sector | Usually |
| Security questionnaire from large customers | Increasing | ✓ | ✓ |
| Central policy management needed | Optional | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partial |
The Swiss reporting obligation applies to operators of critical infrastructure, so sector membership decides whether you are affected, not company size. Under the revised Information Security Act, an affected operator must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, which means the clock starts at detection and not at clean-up. This product supports that step in a narrow way: administrator alerts on malware findings, quarantine threshold alerts and Policy Manager reporting give you the detection time and the affected host, which are the first fields a report asks for. It does not write the report, does not cover Linux or macOS systems, and keeps no long-term forensic telemetry, so reconstructing how an attacker got in usually needs a separate detection and response product. This text is not legal advice, and whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product makes a company NIS 2 compliant, because the directive addresses organisational risk management rather than software features. NIS 2 asks in-scope entities for measures across several categories, among them incident handling, business continuity and backup, supply chain security, cyber hygiene and training, cryptography, and access control. This product contributes to a small part of that list: malware protection on servers and mail, spam and unsafe URL filtering, and quarantine records that support incident handling and evidence gathering. It does not provide backup, encryption, multi-factor authentication, identity and access control, or supplier risk assessment, and it protects Windows systems only. Patch status for third-party applications is covered only in the Premium edition through Software Updater, so buyers of the standard edition close that category elsewhere.
Partly, and mostly in the malware and email sections. It answers questions about malware protection on servers and mail servers, centrally enforced and locked security policies, email attachment and content filtering, quarantine handling with defined retention periods, and administrator alerting on detections. It does not answer questions about backup and restore testing, encryption of data at rest, multi-factor authentication, endpoint detection and response or 24/7 monitoring, mobile device management, asset inventory, or protection of non-Windows systems. If the gaps that block you are patch status and application control, moving from the standard edition to Premium within the same family is normally the cheaper route than adding a second vendor, because policy management and reporting stay in one console. Detection and response is the one gap Premium does not close, and that requires a separate product regardless of edition.
The decisive difference is DataGuard, the folder-level ransomware protection that only allows trusted applications to write to protected folders. Premium adds two further pieces that matter in audits: Software Updater for third-party patching, and application control for restricting which programs may run on the server. Everything on the mail side is identical, so both editions scan Exchange transport and storage, run spam control and manage the email quarantine. If ransomware protection for file server shares is the reason for the purchase, the standard edition does not deliver it.
| Feature | Email and Server Security | Email and Server Security Premium |
|---|---|---|
| Malware protection and DeepGuard | ✓ | ✓ |
| DataGuard ransomware folder protection | ✕ | ✓ |
| Application control | ✕ | ✓ |
| Software Updater | ✕ | ✓ |
| Exchange and SharePoint protection | ✓ | ✓ |
| Spam control and email quarantine | ✓ | ✓ |
| Firewall and browsing protection | ✓ | ✓ |
This is Windows server software, so Linux servers, macOS machines and mobile devices are outside its scope entirely. The web console on a standalone installation manages only the Exchange and SharePoint settings, while the antivirus settings are limited to a subset in the local interface, which means full central policy control requires WithSecure Policy Manager as a separate on-premises component. AMSI integration, which catches script-based attacks in PowerShell and Office, is documented for Windows Server 2016, 2019 and 2022, so check your server generation before you count on that specific layer. A clean installation has to be performed locally on each server, and only upgrades can be pushed through policy, which affects rollout planning if you run many servers. Business Suite products follow a fixed lifecycle of at least three years from the release of a major version, or one year after its successor, so confirm the current supported version status before you standardise on this product for a long period.
No. This product installs on your own Windows server and protects an on-premises Microsoft Exchange installation. Mailboxes hosted in Microsoft 365 are covered by WithSecure Collaboration Protection for Microsoft 365, which is a separate product.
The feature set is the same, with the Exchange and SharePoint protection components added on top. If you only need to protect file servers, terminal servers or application servers without a mail role, Server Security covers the same ground.
No. This product belongs to the on-premises Business Suite range and is managed with WithSecure Policy Manager, which you install and operate yourself. WithSecure Elements is the separate cloud-managed product line with its own agents.
Protects Windows servers plus Microsoft Exchange and SharePoint with malware scanning, spam control and email quarantine. On-premises only.
WithSecure Email and Server Security Corporate, WithSecure, WithSecure Business Suite, F-Secure Email and Server Security, server antivirus, exchange protection, sharepoint protection, spam filter, email quarantine
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies