Sophos MDR Reviews (506)

Reviews

Sophos MDR Reviews (506)

4.7
506 reviews

What do users say?

Generated using AI from real user reviews
Users consistently praise the 24/7 monitoring and proactive threat detection provided by Sophos MDR, highlighting the peace of mind it offers through expert oversight and rapid incident response. Many appreciate the seamless integration with existing security tools, which enhances operational efficiency. However, a common concern is the high cost associated with the service, which may be a barrier for smaller organizations.

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
kaushal p.
KP
kaushal p.
Network Security Engineer
Computer & Network Security
Mid-Market (51-1000 emp.)
"Proactive 24/7 Threat Detection and Fast Containment with Sophos MDR"
5/5
What do you like best about Sophos MDR?

We've been using Sophos MDR for about 18 months across an environment of roughly 150-200 endpoints spread across Indore head office and smaller branch locactions in Delhi and Bhopal. It's become the backbone of our 24/7 security monitoirng since our internal IT team isn't large enough to staff a round-the-clock SOC ourselves.

The best thing I like is Threat detection and response. The analysts don't just alert and walk away — they actively investigate and take containment actions. We had an incident about 4 months ago where a workstation showed signs of suspicious PowerShell activity at around 2 AM; the Sophos team isolated the host and had a full incident summary in our inbox before our own team even logged on that morning. That kind of proactive containment has genuinely prevented what could have been a lateral-movement situation across network.

Reporting: The monthly threat summary reports are detailed enough that we've been able to use them directly in our quarterly security reviews with leadership, without needing to rebuild the data ourselves. It's saved our small security team probably 4-5 hours a month that to go into compiling that information manually.

Support: We've raised maybe 3-4 tickets over the past year for tuning false positives on a couple of internal applications. and teach was resolved within a day, usually with a clear explanation of why the detection fired in the first place. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

There isn't a major drawback we've run into, but a few smaller things stand out. The client portal, while functional, feels like it lags a generation behind some of the more modern dashboards we've seen from competitors - filtering and searching through historical incidents can take a few extra clicks compared to what we'd expect from a more polished UI.

We've also occasionally had a slight delay - maybe 10-15 minutes - in getting a callback during a mid-severity incident versus the near-instant response we get for critical ones, which is reasonable given prioritization, but worth knowing if you're expecting the same SLA across all severity tiers.

Neither of these has caused an actual security gaps for us. They're more operational friction than genuine shortcomings. For a team our size without a dedicated SOC, the value has far outweighed these minor inconveniences. Review collected by and hosted on G2.com.

Evren Kürşat .
E
Evren Kürşat .
Director of IT & Cyber Security Departments | Cloud & Infrastructure • Cybersecurity • IT Strategy
Mid-Market (51-1000 emp.)
"Sophos MDR Delivers 24/7 Monitoring and Rapid Response with Actionable Alerts"
5/5
What do you like best about Sophos MDR?

Sophos MDR is the 24/7 threat monitoring and rapid response capabilities provided by the security team. It significantly reduces the workload on our internal IT team while improving our overall security posture. The visibility and actionable alerts help us respond to incidents more quickly and effectively. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

Sophos MDR is that it does not offer Turkish language support, which can make management and communication less convenient for our team. Review collected by and hosted on G2.com.

HK
Harsh K.
Technical Consultant
Mid-Market (51-1000 emp.)
"Feels Like a Real 24/7 Security Team Backing You Up"
4/5
What do you like best about Sophos MDR?

What I like most about Sophos MDR is that it genuinely feels like having a real security team backing you up 24/7, rather than just another tool that throws alerts at you. It takes a lot of pressure off because it actually investigates and responds to threats, instead of leaving you to handle everything on your own. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

What I dislike is that the initial setup and fine-tuning can feel a bit complex at first, especially if you’re new to MDR services. Also, some of the deeper insights and controls seem limited unless you’re fully invested in the Sophos ecosystem. Review collected by and hosted on G2.com.

SA
Shahid A.
SOC and Endpoint Lead
Enterprise (> 1000 emp.)
"Reliable 24/7 Threat Response Across 2000+ Endpoints"
5/5
What do you like best about Sophos MDR?

Sophos MDR scales effortlessly, we have over 2000 endpoints and the coverage remains consistent and reliable. Proactive communication from the MDR team during high-severity incidents really sets them apart. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

The MDR portal interface could be more intuitive, navigating past threat cases and filtering alerts isn't as smooth as it could be. Review collected by and hosted on G2.com.

VC
vladimir C.
Infrastructure Security analist
Transportation/Trucking/Railroad
Mid-Market (51-1000 emp.)
"Total Peace of Mind with Sophos MDR: 24/7 Security and Clear Alerts"
5/5
What do you like best about Sophos MDR?

What I appreciate most about Sophos MDR is that, essentially, I have a team of cybersecurity experts watching my network 24/7, without needing to hire my own staff. Let's be honest: I don't have the budget or the knowledge to maintain a security team that is alert at 3 in the morning monitoring threats.

What really gives me peace of mind is that they not only detect suspicious activities, but they also act immediately. I've been through a couple of situations where they notified me that they had blocked something suspicious and had already taken action before I even found out. It's like having a digital bodyguard that never rests.

Moreover, something that seems simple but is extremely valuable: the alerts I receive make sense. It's not a bombardment of incomprehensible technical notifications that only overwhelm. They clearly explain what happened, what actions they took, and if I need to do anything on my part. For someone who doesn't work in cybersecurity all day, that's priceless. It allows me to focus on my business, knowing that aspect is in the hands of professionals. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

Honestly, what impacts me the most is the price. It's not cheap at all, and for a small or medium-sized company like ours, it represents a considerable investment that really affects the monthly budget. Sometimes I question whether we really need such a high level of protection or if we're overpaying, although then I remember the scares we've had and my doubts fade away.

Another thing that frustrates me is the feeling of being too dependent on them. I feel like I've lost some direct control over our own infrastructure. If I want to make any changes or adjust the security settings, I have to request it from their team. Although they usually respond quickly, it's not the same as being able to do it myself at the moment I need it.

Also, at the beginning, the learning curve was quite steep. We had to modify some internal processes and there was some friction with the IT team, as they felt they were being "replaced" or supervised. That created tensions that we had to resolve with a lot of diplomacy.

Lastly, the monthly reports are sometimes too technical. When I have to present them to the board of directors, they don't want to see terms like "IOCs" or "lateral movement"; what they want to know, in clear and simple Spanish, is whether we are protected or not. Review collected by and hosted on G2.com.

EQ
Eric Q.
Administrador de Ciberseguridad
Enterprise (> 1000 emp.)
"24/7 coverage and incident response ideal for companies without an internal SOC"
5/5
What do you like best about Sophos MDR?

Utility: 24/7 coverage before incident response for teams or institutions that do not have an active or mature SOC, or for those who cannot hire an internal cybersecurity team to address complex threats. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

For now, there is nothing to dislike; the service offered by MDR Sophos is positive and its use has translated into fewer risks, costs, and protection for the institution's image. Review collected by and hosted on G2.com.

Elias Alejandro A.
EA
Elias Alejandro A.
Coordinador de seguridad de sistemas
Mid-Market (51-1000 emp.)
"Excellent product and easy to use"
5/5
What do you like best about Sophos MDR?

I like how efficient and quick it is when responding or detecting; overall, it works swiftly and meets my needs. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

The reporting section, the presentation of results, and the statistics. Review collected by and hosted on G2.com.

RAJ K.
RK
RAJ K.
Sales & Digital Marketing
Information Technology and Services
Mid-Market (51-1000 emp.)
"Advanced Threat Detection and Response Made Simple"
5/5
What do you like best about Sophos MDR?

Sophos MDR gives us 24/7 security monitoring with fast response to threats. Their team takes action quickly, even while we’re offline. The dashboard is clean and easy to understand. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

Initial setup took some time and required help from support. The pricing can be a bit high for small companies. A more flexible plan would help. Review collected by and hosted on G2.com.

Verified User in Financial Services
AF
Verified User in Financial Services
Mid-Market (51-1000 emp.)
"Quick Response and 24/7 Monitoring that Provide Peace of Mind"
3.5/5
What do you like best about Sophos MDR?

What I value most about Sophos MDR is the speed with which it identifies and responds to incidents. The team conducts constant monitoring 24 hours a day, 7 days a week, and maintains clear communication, which gives me a lot of peace of mind and helps reduce risks. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

The only thing that doesn't convince me is that certain notifications are somewhat technical, and to understand all the details, it's necessary to check the console. It would be better if it were more accessible for those who don't have technical knowledge. Review collected by and hosted on G2.com.

Andy K.
AK
Andy K.
Vice President
Small-Business (50 or fewer emp.)
"Peace of Mind with Proactive Human Oversight"
5/5
What do you like best about Sophos MDR?

What I like best is peace of mind. The human layer on top of software detection so that if something is off, its investigated instead of juust generating noise. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

Obviously cost is an isssue, it's much more pricey than some other services. Also, there's a pretty big learning curve especially if you're not already in the Sophos ecosystem. Review collected by and hosted on G2.com.