<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in WithSecure Server Security for Linux Corporate?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Real-time malware scanning</strong> – Checks files in defined paths on open, close and execution.<br /> <strong>Manual and scheduled scans</strong> – Weekly full-system scans from Policy Manager or the fsanalyze command.<br /> <strong>Integrity checking (HIPS)</strong> – Cryptographically signed baseline blocks or reports tampering with protected files.<br /> <strong>Cloud reputation lookups</strong> – WithSecure Security Cloud (ORSP) adds file reputation to local detection.<br /> <strong>Command-line administration</strong> – lsctl utility configures standalone hosts without Policy Manager connection.<br /> <strong>Important</strong> – No EDR, firewall, patch management or Windows server coverage included.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of WithSecure Server Security for Linux Corporate?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">WithSecure Server Security for Linux Corporate is the Linux server component of WithSecure Business Suite, technically delivered as Linux Security 64 and sold as F-Secure Linux Security before the corporate business of F-Secure was renamed WithSecure in 2022. It is managed on premises through WithSecure Policy Manager, or locally from the command line on hosts without a console connection.<br /><br /> <strong>On-premises control</strong> – Policies, alerts and updates run through your own Policy Manager Server.<br /> <strong>Rootkit and tamper detection</strong> – Modified system utilities or account files trigger administrator alerts.<br /> <strong>Package-aware baseline</strong> – Baseline updates automatically during apt or dnf package upgrades, avoiding false alarms.<br /> <strong>Air-gapped deployment</strong> – Content packages install and update hosts without internet access.<br /> <strong>Syslog-ready alerting</strong> – Alerts carry syslog priorities, from informational up to security alert.<br /> <strong>Path to Elements</strong> – Built-in migrator moves hosts to WithSecure Elements when requirements grow.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is WithSecure Server Security for Linux Corporate suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The product fits organisations that operate their own Linux web, file or application servers and administer them centrally with WithSecure Policy Manager, often alongside other Business Suite components for Windows. Small businesses with one or two Linux hosts can run it standalone via the lsctl command line, but then carry the configuration work themselves, because real-time scanning covers no files until an administrator defines the paths to protect.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Common</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Standard</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Central policy for Linux servers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Optional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Limited</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">As one layer</td>
</tr>
</tbody>
</table>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does WithSecure Server Security for Linux Corporate meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Since 1 April 2025, the revised Information Security Act obliges operators of critical infrastructure in Switzerland to report cyberattacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery; most other companies are not directly subject to this obligation. The product supports the documentation side of such a report: detections from real-time scanning are recorded in access.log, and all product services write events to syslog, so the time and type of a malware finding on a Linux server can be traced. Integrity checking alerts additionally show when a protected system file was modified, which helps establish when an intrusion was noticed. The product does not detect attacks that use no malicious files, does not correlate events across several hosts, and neither handles the incident nor submits the report to BACS. This information does not constitute legal advice; whether and how your organisation is affected should be assessed by a qualified specialist.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does WithSecure Server Security for Linux Corporate meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No security product creates NIS 2 compliance on its own, because the directive requires risk management measures that the management body of an organisation must approve and oversee. The NIS 2 Directive lists measure categories such as incident handling, business continuity, supply chain security, vulnerability handling, basic cyber hygiene, cryptography, and access control. WithSecure Server Security for Linux Corporate contributes to cyber hygiene through malware protection on Linux servers and to incident handling through detection alerts and syslog records. Its integrity checking helps detect unauthorised changes to system files on protected hosts. It does not cover vulnerability and patch management, backup and continuity, multi-factor authentication, encryption, or endpoint detection and response, so these measures need other tools and processes.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does WithSecure Server Security for Linux Corporate help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Partly: it answers the questions on malware protection and file integrity for Linux servers, but not those on detection and response, patching, or Windows systems. Questions it can answer with a clear yes are whether anti-malware runs on the Linux servers with automatically updated definitions, whether protection is centrally managed with settings users cannot override, whether critical system files are monitored for unauthorised changes, and whether security events are logged. Questions it cannot answer are those about EDR or continuous monitoring, vulnerability and patch management, host firewalling, protection of Windows servers and workstations, backup, and multi-factor authentication. Where a customer demands EDR, the more economical route is usually to stay with the same vendor and move the Linux hosts to WithSecure Elements with the built-in migrator, rather than running a second vendor's agent on the same servers. Windows endpoints can be covered by other Business Suite products managed from the same Policy Manager.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">WithSecure's documentation lists no country- or region-limited features for this product. With default settings, real-time scanning does not scan any files: only the files and folders an administrator enters in Policy Manager or via lsctl are protected, so an untuned installation offers far less protection than it appears to. Only 64-bit distributions that are still supported by their vendor are covered, and SELinux is supported only on the listed distributions, while other distributions require SELinux to be disabled. The current version has no web interface, so administration runs through Policy Manager Console or the command line. The follow-up purchases most often needed are EDR, protection for Windows servers, and a patch management tool.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about WithSecure Server Security for Linux Corporate</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does WithSecure Server Security for Linux Corporate need an internet connection?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Cloud-based detection requires internet access, and the hosts must be able to reach all addresses under *.fsapi.com. Managed hosts normally receive updates from Policy Manager Server and fall back to WithSecure update servers directly if Policy Manager cannot be reached.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it detect Windows malware on Linux file servers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, WithSecure states that the product protects mixed environments against both Windows and Linux malware, and real-time scanning also covers files on network drives. This matters for Samba or NFS file servers that store files later opened on Windows workstations.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can scanning be offloaded from busy servers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, the product supports offload scanning, sending scan requests to one or more ICAP servers with a configurable response timeout. This reduces the scanning load on servers that handle large numbers of file accesses.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-server,sec-console,compliance-supplier" data-audience="b2b" data-count="3"> </div>