<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in WithSecure Co-Monitoring Service?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>24/7 detection monitoring</strong> – WithSecure watches severe-risk detections from Elements EDR continuously.<br /> <strong>Out-of-hours option</strong> – Monitoring can cover only evenings, weekends and holidays.<br /> <strong>Human threat validation</strong> – Analysts confirm whether a detection is a real incident.<br /> <strong>Named contact escalation</strong> – Confirmed incidents go to people authorised to act.<br /> <strong>Remediation guidance</strong> – Advice such as isolating hosts or stopping malicious processes.<br /> <strong>Important</strong> – WithSecure gives instructions, it does not execute response actions.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of WithSecure Co-Monitoring Service?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">WithSecure Co-Monitoring Service is an add-on to WithSecure Elements EDR in which the vendor's own Detection and Response Team reviews your severe-risk detections and tells your staff what to do about them. It is delivered through the Elements cloud console you already use, by the vendor formerly operating as F-Secure Business.<br /> <br /> <strong>Night coverage without hiring</strong> – Closes the gap when nobody is on shift.<br /> <strong>Fewer false alarms</strong> – Analysts close false positives before they reach you.<br /> <strong>Faster incident start</strong> – A validated verdict removes the first hour of guesswork.<br /> <strong>European delivery team</strong> – The Detection and Response Team operates within Europe.<br /> <strong>MSP-friendly escalation</strong> – Confirmed attacks can be routed to your service provider.<br /> <strong>Path to incident response</strong> – Cases can be escalated to WithSecure incident response services.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-defender-not-enough"><strong>Best antivirus? Why Windows Defender alone is not enough</strong><br />Explains where basic endpoint protection stops and why detection and human review are needed on top of it.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is WithSecure Co-Monitoring Service suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The deciding factor is not headcount but whether anyone in your organisation is watching detections at three in the morning. Companies that already run Elements EDR but have no shift rota are the intended buyers.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Often</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">In-house monitoring around the clock</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rare</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">If EDR in use</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Out-of-hours cover</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does WithSecure Co-Monitoring Service meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting duty under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so most SMEs are not directly affected. Organisations that are affected must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. The hard part of that deadline is discovery itself: a clock that starts on a Friday evening runs out before Monday, and Co-Monitoring addresses precisely this by having an analyst review severe-risk detections at night and at weekends and escalate a confirmed incident to a named contact. What the service does not do is file the report, draft its content, or judge whether your organisation falls under the obligation at all. It also sees nothing outside the reach of the Elements EDR agent, so network equipment, OT systems and SaaS platforms remain unmonitored. This text describes product capabilities and is not legal advice; if you need certainty about your own obligations, have them assessed by a qualified lawyer.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does WithSecure Co-Monitoring Service meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses governance, documented processes and management accountability at least as much as technology. NIS 2 requires measures across risk analysis and security policies, incident handling, business continuity and backup, supply chain security, vulnerability handling, cyber hygiene and training, cryptography, and access control including multi-factor authentication. Co-Monitoring contributes directly to exactly one of those categories, incident handling, by supplying continuous review of detections, a human verdict on whether an event is a real incident, and a documented escalation path to a responsible person. It contributes nothing to backup and business continuity, vulnerability handling, staff training, cryptography, access control or supplier governance, and it does not produce the incident register or notification texts the directive expects. Treat it as one component inside an incident-handling process that still has to be written down and owned internally.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data loss is expensive: How backups help you avoid outages</strong><br />Covers the backup and continuity side that a monitoring service does not address, including what an outage actually costs.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does WithSecure Co-Monitoring Service help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for a narrow but frequently asked group of questions. It gives you a defensible answer to whether security alerts are monitored outside business hours, whether a qualified human reviews them rather than an automated rule, whether there is a defined escalation path to a named responsible person, and whether you have access to incident response expertise. It answers none of the questions about penetration testing, patch and vulnerability management, backup and restore testing, encryption of devices, access control and multi-factor authentication, security awareness training, or your own certification status. It also does not generate the evidence documents themselves, so the reporting you attach still comes out of the Elements console and your own records. If a questionnaire turns out to demand documented response actions and a contractual response time rather than advisory monitoring, the cheaper route is normally to move up within the same family to WithSecure Elements MDR rather than to add a second vendor alongside your existing EDR.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What is the difference between Co-Monitoring and WithSecure Elements MDR?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive difference is who touches the machine. With Co-Monitoring, WithSecure investigates and then hands you instructions, which means somebody on your side has to be reachable and authorised to act on them at any hour. With Elements MDR, the Detection and Response Team carries out containment on your behalf, and WithSecure states an SLA-backed response time of 60 minutes for 90 percent of cases. Co-Monitoring can also be bought as out-of-hours cover only, which suits a team that watches its own console during the working day.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Capability</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Co-Monitoring Service</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Elements MDR</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Monitoring window</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">24/7 or out-of-hours</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">24/7 continuous</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Human validation of detections</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Containment and remediation advice</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Response actions taken by WithSecure</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #d9534f; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✕</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Published response time SLA</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Not published</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">60 minutes, 90 percent</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Access to forensics specialists</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Via retainer</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Conditional</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">This is an add-on, not a standalone product: without WithSecure Elements Endpoint Detection and Response underneath it there is nothing for the analysts to monitor. Its field of view is limited to detections raised by the Elements EDR agent, so a device without the agent, a firewall, an industrial control system or a third-party cloud service produces no signal the service can act on. The service scope is severe-risk detections rather than every event, which keeps the noise down but means low-severity findings stay with your own team. Because WithSecure advises rather than intervenes, the value collapses if there is no one reachable and authorised to act at the moment of escalation, so the on-call arrangement is a prerequisite and not an optional extra. No availability restriction to specific countries was found in the vendor material, and the Detection and Response Team is described as operating within Europe, which is relevant if data processing location is part of your procurement criteria.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about WithSecure Co-Monitoring Service</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can the service be limited to out-of-office hours?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. WithSecure offers the monitoring either around the clock or only outside office hours, so a team that watches its own detections during the working day can buy cover for evenings, nights and weekends alone.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it work if an IT service provider manages our environment?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. Confirmed attacks are escalated either to the partner managing the environment or to an on-call contact at the customer, which is why service providers use it to extend their own coverage without staffing a night shift.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What happens if an incident is larger than the service can handle?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The service can be extended so that a case is handed over to WithSecure incident response services. That handover is a separate engagement, either through a retainer or on demand, and is not included in the monitoring itself.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-edr,compliance-ch-isg,compliance-nis2" data-audience="b2b" data-count="3"> </div>