Getting started with WithSecure™ Elements Exposure Management

Follow the steps below to get started with WithSecure™ Elements Exposure Management.

You need a WithSecure™ Business Account to access Elements Security Center ↗, the unified management platform for all WithSecure™ Elements products. There are two scenarios:

  • When you purchase the product from a WithSecure partner, the partner typically creates a Business Account for the first administrator in your organization. You will have received an email from WithSecure with a temporary password and a link to log in.
  • If your account has not yet been created but you have received a subscription key from your partner, go to elements.withsecure.com/self-register ↗ to create one.

Log in to Elements Security Center ↗ and connect your assets so that XM can build a picture of your digital perimeter. Onboard as many of the following as apply to your environment.

Devices
  • Install Elements Agent on Windows devices for continuous vulnerability scanning. If devices already run Elements Agent for EPP, go to Environment > Devices > Computers and enable vulnerability scanning from there — no reinstall needed.
  • Install a Scan node on a Windows Server or Linux server to scan devices where agent installation isn’t possible. For internet-facing devices, cloud scan nodes are available at no extra cost.
Cloud
  • Add your Azure tenant under Environment > Cloud to bring in cloud infrastructure and identity data. Entra ID identity scanning starts automatically.
  • Add your AWS accounts under Environment > Cloud to scan AWS infrastructure.
External attack surface
  • Configure External Attack Surface (EASM) under Security Configurations > Scans to discover and monitor your internet-facing assets from the outside in.
Need more detail? The XM user guide ↗ has step-by-step instructions for every onboarding path, including scan node installation and authenticated scanning.

Once assets are onboarded and scans have run, go to Home > Exposure to see your dashboard.

  1. Select the top item from the Highest impact recommendations list. Each recommendation shows the affected assets, identified findings, an attack path visualization, and the actions needed to fix it.
  2. Apply the fix using the actions in the left sidebar — Look for patchesElevate to WithSecure for expert help, or Notes to log progress and ticket IDs.
  3. Update the recommendation Status as you work through it (Open, Acknowledged, Accepted Risk, False Positive, or Done) and monitor the dashboard as your exposure score improves.
Note: Recommendation descriptions are generated by an LLM. By default no organization-specific data is sent — organizations can opt in to receive descriptions tailored to their environment.

Further reading

Here are links to some common resources to get additional information about the use of WithSecure products.

User guide — Elements XM

Full documentation covering asset onboarding, vulnerability scanning, Azure and AWS cloud integration, external attack surface discovery, and exposure management

WithSecure Community

Stay up to date with product announcements and changelogs, get answers to your questions, and share product ideas

Knowledge base

Troubleshooting and how-to articles covering asset onboarding, scan nodes, cloud integrations, and exposure recommendations