Shibu K.
SK
Shibu K.
Security Engineer
Information Technology and Services
Mid-Market (51-1000 emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Sophos NDR gives us visibility we never had before - it catches things our firewall and endpoint."
5/5
What do you like best about Sophos NDR?

I have been using Sophos NDR for a good amount of time now as part of my daily work as a network security engineer at Vibs Infosol Pvt Ltd. As an admin, I check this platform every day, and it has become a very important layer in our overall security setup, because we deal with thousands of clients and almost all our communication happens through email and calls, and any hidden attacker sitting quietly in our network could cause serious damage before we even notice. Sophos NDR has given us the visibility we were missing before.

The biggest value I get is Early Threat Detection. Before NDR, our firewall and endpoint protection were good at stopping known threats, but anything unusual that quietly moved inside our network was harder to catch in time. Now NDR monitors network traffic constantly and flags suspicious behavior early, before it turns into an actual damaging attack. I have personally seen alerts for unusual traffic patterns that I would not have noticed just by looking at firewall logs alone.

Reduced Dwell Time is something I value a lot, because in security, the longer an attacker stays hidden in your network, the more damage they can do. NDR helps me find suspicious activity faster, which means I can act on it quickly instead of discovering a problem weeks later. This has genuinely improved my response speed compared to before.

Better Visibility is a feature I rely on daily, since NDR monitors all network traffic, not just what passes through the firewall or endpoint. This gives me a complete picture of what is actually happening across our network, including devices and traffic that other tools might not fully cover.

AI-Based Detection is something I find really useful for catching unknown attacks. Traditional signature-based tools only catch threats that are already known, but attackers keep changing their methods. NDR's AI based approach helps detect unusual behavior even when it does not match any known signature, which gives me an extra layer of protection against new or evolving threats.

Compliance support is very helpful for us too, since some of our clients and industry standards expect proof of proper network monitoring. Having NDR's detailed detection and audit trail makes compliance conversations and audits much smoother for me.

Faster Incident Response is a direct benefit I experience regularly. When something suspicious is detected, NDR gives me enough detail to investigate and act quickly, instead of spending hours manually piecing together what happened from scattered logs.

Asset Discovery is a feature I check regularly, since it helps me identify both managed and unmanaged devices on our network. This has actually helped me find a few devices that were connected to our network without proper security controls, which I then brought under proper management.

Insider Threat Detection is something I did not expect to value as much as I do now. It monitors for suspicious behavior even from within the organization, not just external attacks, which is important because not every risk comes from outside.

Data Protection through detecting data exfiltration attempts gives me real confidence, especially since we handle sensitive information for thousands of clients, and preventing that data from silently leaving our network is a top priority for me.

What I really appreciate is how well NDR integrates with the rest of our Sophos setup. It works together with Sophos Firewall by sharing network insights and security events, so both tools are smarter together than separately. It correlates with Sophos Intercept X, connecting endpoint and network detections, which gives a fuller picture instead of two separate stories. We also get support from Sophos MDR, where their expert team does 24/7 threat hunting and response, which is extremely valuable for a team like ours that cannot monitor everything manually round the clock. And since everything is managed through Sophos Central, I don't need a separate login, I manage NDR from the same centralized dashboard I already use daily for firewall, endpoint, and email.

An unexpected benefit I found is that NDR has actually helped me spot unmanaged or forgotten devices on our network that nobody was actively tracking, which is something I did not expect to discover through a network detection tool. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

Even though Sophos NDR has genuinely improved our network visibility and threat detection, there are a few areas I feel could be improved, through these are not big enough to change my overall positive experience.

The first thing is that understanding and correctly interpreting all the alerts initially took some time. Since NDR monitors a large volume of network traffic, in the beginning I got a good number of alerts, and figuring out which ones were truly critical versus normal unusual behavior required some learning and fine tuning of settings.

Second, setting up the integration properly across Sophos Firewall, Intercept X, and Central took a bit of planning and time initially, to make sure everything was correlating data correctly. Once it was set up properly it works smoothly, but the initial configuration phase needed careful attention.

Third, I feel the reporting dashboard, while detailed, could offer a bit more simplified summary view for quick daily checks, since sometimes I want a fast high level status without going too deep into technical details, especially when I am short on time.

Fourth, regarding pricing, since NDR is an additional layer on top of our existing firewall and endpoint protection, the licensing cost adds up when combined with our other Sophos products. Once I explained the ROI clearly to management, based on the visibility and faster detection it provides, the cost was justified, but the initial pricing conversation required clear reasoning and data from my side.

Fifth, support response time is generally fine for critical issues, but for smaller configuration or tuning doubts, sometimes I wait a bit longer than expected to get a detailed technical answer.

Even with these small points, I want to be fair, these issues are minor compared to the overall visibility and protection NDR gives our organization daily. Review collected by and hosted on G2.com.

Rafael L.
RL
Rafael L.
Cybersecurity Analyst
Computer & Network Security
Small-Business (50 or fewer emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"Visibilidad completa y detección avanzada en tiempo real"
4.5/5
What do you like best about Sophos NDR?

Me gusta mucho Sophos NDR por su visibilidad completa en la red y su capacidad para detectar amenazas avanzadas en tiempo real. También valoro su integración con otros productos de Sophos, lo cual ha sido muy útil para mi trabajo, ya que pueden actuar por sí mismos y ayudar a mitigar posibles ataques. La detección de comportamientos anormales y movimientos laterales también funciona muy bien, con alertas precisas y buena integración con Sophos Central. Además, encuentro que el despliegue es fácil siempre y cuando leas bien la documentación para cumplir con los requisitos mínimos y óptimos. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

Puede generar falsos positivos al principio, los informes son limitados y depende mucho de una implementación correcta. Review collected by and hosted on G2.com.

SK
Santosh K.
Technical Engineer
Information Technology and Services
Small-Business (50 or fewer emp.)
"Network Awareness That Adds Real Depth to Security"
5/5
What do you like best about Sophos NDR?

What I found most valuable about Sophos NDR is the level of awareness it brings to the network. It doesn’t just look for obvious threats — it pays attention to behavior. Seeing how devices communicate internally helped us understand our own environment better, not just from a security angle but from an operational one as well. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

There isn’t much to dislike. The initial period requires some observation while the system learns normal traffic patterns, but that’s expected for any behavior-based solution. Once that learning phase is complete, alerts become meaningful and well-prioritized, requiring very little tuning. Review collected by and hosted on G2.com.

PM
pawan m.
Technical Engineer
Information Technology and Services
Small-Business (50 or fewer emp.)
"Sophos NDR – Deep Network Intelligence That Sees What Others Miss"
5/5
What do you like best about Sophos NDR?

What I like most about Sophos NDR is its ability to uncover hidden network threats with incredible accuracy. It gives full visibility into traffic patterns and lateral movements that traditional firewalls or endpoint tools might overlook. The integration with Sophos Central is a major plus — all detections, alerts, and responses appear in a unified dashboard. It’s like having an extra layer of intelligence continuously analyzing network behavior, helping us detect potential compromises early. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

There’s honestly not much to dislike. The only small point is that, during the initial deployment, fine-tuning detection policies requires some time to ensure alerts are relevant to your environment. Once it’s adjusted, the alerts become highly precise, and false positives drop significantly. The value it brings after setup easily outweighs the initial learning curve. Review collected by and hosted on G2.com.

SK
Shruti K.
Technical support
Information Technology and Services
Small-Business (50 or fewer emp.)
"Network Security with Real-Time Detection and alert."
4.5/5
What do you like best about Sophos NDR?

What I like best about Sophos NDR is its ability to provide clear and real-time visibility into network traffic, making it easy to detect unusual patterns and potential threats without needing advanced expertise. The intuitive dashboard helps us monitor activity efficiently, and the detailed alerts allow us to respond quickly to incidents, improving our overall network security and reducing the risk of breaches. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

Occasionally, we notice some false positive alerts, and it would be nice if the reports had more customization options. But overall, these are small issues compared to the valuable visibility and strong protection Sophos NDR gives us. Review collected by and hosted on G2.com.

PG
Pournima G.
IT Networking sales
Information Technology and Services
Small-Business (50 or fewer emp.)
"Great tool for monitoring and securing our network. Detects issues before they become problems."
5/5
What do you like best about Sophos NDR?

I like how easy it is to use and how quickly it alerts us about suspicious network activity. The dashboard is clear and helps us stay on top of potential threats. It gives detailed insights into traffic patterns, making it easier to understand what’s happening in our network and customer support has been helpful when we needed assistance. We use it regularly to keep an eye on unusual network behavior. Overall, it has improved our ability to detect and respond to issues much faster. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

At times, the alert system can be a bit overwhelming with too many minor issues flagged. Review collected by and hosted on G2.com.

VD
Vishal D.
Technical
Information Technology and Services
Small-Business (50 or fewer emp.)
"Brings Extra Visibility into IoT and Unmanaged Devices."
5/5
What do you like best about Sophos NDR?

Sophos NDR gives us visibility into devices that aren’t covered by endpoint protection, like printers, IoT, and unmanaged systems. It integrates smoothly with Sophos Firewall and XDR, so everything shows up in a single console. I also like the automated detection and AI-driven analysis it reduces manual effort and helps our team spot threats we would have missed otherwise. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

There’s a small learning curve in the beginning, and some reports could be more detailed out of the box. However, once you get familiar with the console, it becomes much easier to manage. Review collected by and hosted on G2.com.

Prasad G.
PG
Prasad G.
Senior Network Administrator
Small-Business (50 or fewer emp.)
"Helps Identify Hidden Threats Quickly."
5/5
What do you like best about Sophos NDR?

Sophos NDR is easy to use once you get used to the dashboard and integrates smoothly with Firewall and XDR. Customer support is responsive, and we use it regularly for monitoring and investigations. Its AI-driven detections, visibility into unmanaged devices, and seamless ecosystem integration make it a valuable addition to our security setup. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

The solution works well, but there is a bit of a learning curve in the beginning to fine-tune alerts. Some of the reports could be more detailed out of the box, which would save time for smaller IT teams. These are minor areas for improvement, and overall it’s a strong product. Review collected by and hosted on G2.com.

PM
pavan m.
Technical Engineer
Small-Business (50 or fewer emp.)
"Sophos NDR: Turning Network Blind Spots into Clear Visibility"
5/5
What do you like best about Sophos NDR?

What I like best about Sophos NDR is its ability to provide deep visibility into network traffic without requiring intrusive changes to the existing environment. It detects suspicious lateral movements, encrypted threats, and hidden command-and-control traffic that traditional firewalls and endpoint tools might miss. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

The only challenge with Sophos NDR is that the level of insight it provides can feel overwhelming at the start, especially for teams new to network detection tools. However, this quickly turns into a benefit once you get familiar with the platform, because the rich context allows security teams to investigate faster and with greater confidence. Review collected by and hosted on G2.com.

DG
Devraj G.
Technical
Information Technology and Services
Small-Business (50 or fewer emp.)
"A Strong Tool for Network Visibility and Security."
4.5/5
What do you like best about Sophos NDR?

What I like most about Sophos NDR is that it gives us clear visibility into our network, quickly detects hidden threats, and fits in well with our existing Sophos setup. It was easy to deploy, the dashboard is simple to use, and the real-time alerts really help us stay ahead of potential issues. Review collected by and hosted on G2.com.

What do you dislike about Sophos NDR?

There isn’t much to dislike about Sophos NDR, but I feel the product has so many features that it takes some time to explore everything fully. With regular use, though, it becomes easier to manage and really adds value. Review collected by and hosted on G2.com.