Product Avatar Image

Sophos

Show rating breakdown
2,660 reviews
  • 19 profiles
  • 32 categories
Average star rating
4.6
#1 in 18 categories
Grid® leader
Serving customers since
1985
Profile Filters

All Products & Services

Product Avatar Image
Sophos PhishThreat

28 reviews

Sophos Phish Threat is a cloud-based security awareness training and phishing simulation platform designed to educate employees on identifying and responding to phishing attacks. By simulating realistic phishing scenarios and providing interactive training modules, it helps organizations strengthen their human firewall against cyber threats. Key Features and Functionality: - Realistic Phishing Simulations: Offers hundreds of customizable templates that mimic real-world phishing attacks, enabling organizations to test and improve employee vigilance. - Automated Training Modules: Provides over 30 interactive training courses covering security and compliance topics, automatically enrolling users who fall for simulated attacks. - Comprehensive Reporting: Delivers actionable insights through intuitive dashboards, tracking user susceptibility, training progress, and overall organizational risk levels. - Multi-Language Support: Available in nine languages, ensuring accessibility for diverse workforces. - Seamless Integration: Integrates with Sophos Central, allowing unified management alongside other security solutions like email and endpoint protection. Primary Value and Problem Solved: Sophos Phish Threat addresses the critical challenge of human error in cybersecurity by transforming employees into proactive defenders against phishing attacks. By combining realistic simulations with targeted training, it reduces the likelihood of successful phishing attempts, thereby enhancing the organization's overall security posture and minimizing the risk of data breaches and financial loss.

Product Avatar Image
Sophos Cloud Optix

22 reviews

Sophos Cloud Optix is an AI-powered security and compliance platform designed to provide comprehensive visibility and control over public cloud environments. It offers real-time inventory management of cloud assets, including servers, storage, and network components, enabling organizations to monitor security, manage resources, and ensure compliance with industry standards through a unified interface. Key Features and Functionality: - Multi-Cloud Visibility: Supports monitoring across AWS, Azure, Google Cloud, and Kubernetes, offering detailed inventories and visualizations to detect security risks, over-privileged access, and spending anomalies. - Security Monitoring: Conducts scheduled, daily, and on-demand scans to identify vulnerabilities and compliance issues, providing contextual alerts with remediation steps. - Compliance Management: Automates assessments and generates audit-ready reports for standards such as CIS, ISO 27001, GDPR, HIPAA, and PCI DSS, streamlining compliance processes. - DevSecOps Integration: Integrates security checks into the development pipeline, scanning container images and Infrastructure-as-Code templates to prevent vulnerabilities before deployment. - Cost Optimization: Monitors cloud service expenditures, provides recommendations to reduce costs, and identifies indicators of compromise to prevent financial losses. Primary Value and Problem Solved: Sophos Cloud Optix addresses the challenges of managing complex, multi-cloud environments by offering a centralized platform for security monitoring, compliance management, and cost optimization. It reduces the complexity and cost associated with governance, risk, and compliance by providing continuous assessments and collaboration tools that integrate seamlessly into existing processes. By automating security and compliance tasks, it enables organizations to proactively detect and remediate vulnerabilities, ensuring robust protection of cloud assets and adherence to regulatory requirements.

Product Avatar Image
Sophos NDR

19 reviews

Sophos NDR works together with your managed endpoints and firewalls to monitor network activity for suspicious and malicious patterns they cannot see. It detects abnormal traffic flows from unmanaged systems and IoT devices, rogue assets, insider threats, previously unseen zero-day attacks, and unusual patterns deep within the network.

Product Avatar Image
Sophos Professional Services

17 reviews

Sophos delivers the best IT security and data protection for businesses. We produced our first encryption and antivirus products back in the 1980s. And today our products protect over 100,000 businesses and 100 million users, in more than 150 countries.

Product Avatar Image
SophosLabs Intelix

14 reviews

SophosLabs Intelix is a cloud-based threat intelligence and analysis platform that empowers developers and security professionals to enhance their applications and infrastructure with advanced cybersecurity capabilities. By leveraging over 30 years of threat research, machine learning models, and vast datasets, Intelix provides real-time assessments of files, URLs, and IP addresses, enabling informed security decisions. Accessible via RESTful APIs, it integrates seamlessly into existing systems, offering detailed analyses and just-in-time verdicts for suspicious objects. This platform is designed to support informed decisions by providing detailed, explainable, and proven threat intelligence. Key Features and Functionality: - High-Fidelity Threat Intelligence: Delivers comprehensive threat classification and deep analysis for known clean and malicious objects, including files, web pages, and IP addresses. - Incremental Protection: Integrates with Sophos products like Sophos Firewall and Sophos Email to submit suspicious files for deep analysis, accurately detecting zero-day threats. - Detailed Analysis: Provides threat hunters and security analysts with timely and relevant information, reducing the time required to make informed decisions. - API Integration: Offers easy integration into any application or environment through API requests, available via AWS Marketplace or OEM partnerships. Primary Value and Problem Solved: SophosLabs Intelix addresses the critical need for real-time, high-fidelity threat intelligence in the rapidly evolving cybersecurity landscape. By providing detailed analyses and classifications of potential threats, it enables organizations to proactively identify and mitigate risks, enhancing their overall security posture. The platform's seamless integration capabilities allow businesses to incorporate advanced threat detection into their existing systems without significant overhead, ensuring robust protection against both known and emerging cyber threats.

Product Avatar Image
HitmanPro

13 reviews

HitmanPro digs deep to rid your computer of any lingering infections. Quick, specialized scanning, with easy removal, gets your computer back to a pre-infected state in no time. It can also run right alongside your current security software if you’re looking for another layer of security, or a second opinion on how that security is performing.

Product Avatar Image
Secureworks Taegis XDR

6 reviews

SCWX is a cybersecurity company that works to provide an early warning system for evolving cyber threats, enabling to prevent, detect, rapidly respond to and predict cyberattacks.

Product Avatar Image
Secureworks Cybersecurity Services

5 reviews

Our Intelligence Driven Information Security Solutions Help Organizations of All Sizes Prevent, Detect, Respond To, and Predict Cyberattacks

Product Avatar Image
Secureworks Taegis VDR

1 review

Secureworks® Taegis™ VDR is a cloud-native vulnerability management solution designed to help organizations identify, prioritize, and remediate critical vulnerabilities efficiently. By leveraging advanced machine learning and continuously updated threat intelligence from the Secureworks Counter Threat Unit™, Taegis VDR offers a risk-based approach that focuses on the most significant threats within your unique environment. This proactive strategy enhances your organization's security posture by reducing the time and effort required to address vulnerabilities, thereby minimizing the risk of breaches. Key Features and Functionality: - Risk-Based Prioritization: Taegis VDR assesses over 40 internal and external risk factors to prioritize vulnerabilities, ensuring that remediation efforts are focused on the most critical threats. - AI-Driven Asset Discovery: Utilizing machine learning, the platform continuously discovers and assesses all assets within your IT environment, providing comprehensive coverage. - Continuous Vulnerability Assessment: Taegis VDR offers ongoing scanning and evaluation to promptly detect new vulnerabilities, keeping your security measures up to date. - Seamless Integration: The solution integrates with existing vulnerability scanners and security infrastructures, allowing for a unified approach to vulnerability management. - Automated Remediation Guidance: Taegis VDR provides actionable insights and recommendations to effectively address identified vulnerabilities, streamlining the remediation process. Primary Value and Problem Solved: Taegis VDR addresses the challenge of managing an overwhelming number of vulnerabilities by intelligently prioritizing them based on their potential impact on your organization. This targeted approach reduces remediation efforts by up to 15 times, allowing security teams to focus on the most significant risks. By integrating threat intelligence and machine learning, Taegis VDR enhances your organization's ability to proactively defend against attacks, ultimately improving your overall security posture.

Profile Name

Star Rating

2121
459
58
14
10

Sophos Reviews

Review Filters
Profile Name
Star Rating
2121
459
58
14
10
Shibu K.
SK
Shibu K.
Network Security Engineer | Firewall & Security Policy Management | Tufin | AlgoSec | Allot Secure | Cybersecurity Enthusiast | Continuous Learner
08/05/2026
Validated Reviewer
Verified Current User
Review source: Organic Review from User Profile

Sophos UTM gave us one complete security box instead of managing five different tools separately

I have been using Sophos UTM for a good amount of time now as part of my daily work as a network security engineer at Vibs Infosol Pvt Ltd. As an admin, I manage this platform every day, and it has because we deal with thousands of clients and almost all our communication happens through email and calls, and having one solid layer of protection at the network level was very important for us. The biggest thing I like about Sophos UTM is Centralized Security. Instead of managing firewall, VPN, IPS, web filtering, and email security as separate products with separate logins, everything is available from one single platform. Earlier when I worked with separate tools for each function, I had to switch between different consoles constantly, which used to break my workflow and waste time. Now I configure and monitor everything from one interface, which has genuinely made my daily routine much smoother and faster. Reduced Hardware Costs is a real benefit we experienced when we chose UTM. Instead of buying and maintaining separate hardware or software for firewalling, VPN, IPS, web filtering, and email security, we consolidated all of that into one appliance. This directly reduced our infrastructure cost and also reduced the physical space and maintenance effort needed to keep multiple systems running. Better Visibility is something I rely on daily through the comprehensive dashboards, logs, and reports UTM provides. I don't have to check five different tools to understand what is happening in our network, I get one consolidated view of traffic, threats, and activity, which makes my daily monitoring much faster and more accurate. Improved Security through layered protection is the core value UTM gives us. Since it combines firewall, IPS, web filtering, and other protections together, threats get checked at multiple levels instead of relying on just one line of defense. I have seen this layered approach catch things that a single point solution might have missed. Easier Administration through a single management interface has genuinely saved me hours every week. Earlier, applying a policy change across different tools meant repeating the same task in multiple places. Now I make the change once in UTM and it applies consistently, which has cut my policy update time significantly, what used to take a good part of my day now takes much less time. Secure Remote Access through VPN is something I use regularly, since we have employees and branch offices that need to connect securely to our main network. UTM handles this smoothly, and I have not faced major issues with stability even when multiple users connect remotely at the same time. Compliance Support is very helpful for us too, since our clients and industry requirements often expect proper reporting and logging as proof of good security practice. UTM's reporting and logging features make audits and compliance conversations much easier for me, since the data is already organized and available. Business Continuity through High Availability is a feature that gives me real peace of mind. Knowing that if one unit has an issue, the other can take over and minimize downtime, means our network stays protected and functional even during unexpected hardware problems. This has helped us avoid major disruption to our business operations. On the networking side, UTM supports VLANs, Static Routing, Dynamic Routing like OSPF and BGP in supported scenarios, Link Aggregation, Multi-WAN, and Load Balancing. I use VLANs regularly to separate different departments logically for better security and traffic management. Multi-WAN and Load Balancing have been especially useful for us, since we don't want to depend on a single internet connection, and if one link has an issue, traffic can shift smoothly without our whole office losing connectivity. The reason we chose Sophos UTM in the first place was exactly this, instead of managing separate products for firewalling, VPN, IPS, web filtering, email protection, and reporting, we wanted one complete solution where I as an administrator can configure and monitor everything from a single interface. This has reduced my operational complexity a lot, improved my overall visibility into security events, and helped me protect our users, applications, and data more efficiently than before. An unexpected benefit I found is that having everything unified actually made training easier when a new team member joined, since they only had to learn one platform instead of five different tools, which reduced onboarding time for my own team as well.
Shibu K.
SK
Shibu K.
Network Security Engineer | Firewall & Security Policy Management | Tufin | AlgoSec | Allot Secure | Cybersecurity Enthusiast | Continuous Learner
08/05/2026
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review

Sophos NDR gives us visibility we never had before - it catches things our firewall and endpoint.

I have been using Sophos NDR for a good amount of time now as part of my daily work as a network security engineer at Vibs Infosol Pvt Ltd. As an admin, I check this platform every day, and it has become a very important layer in our overall security setup, because we deal with thousands of clients and almost all our communication happens through email and calls, and any hidden attacker sitting quietly in our network could cause serious damage before we even notice. Sophos NDR has given us the visibility we were missing before. The biggest value I get is Early Threat Detection. Before NDR, our firewall and endpoint protection were good at stopping known threats, but anything unusual that quietly moved inside our network was harder to catch in time. Now NDR monitors network traffic constantly and flags suspicious behavior early, before it turns into an actual damaging attack. I have personally seen alerts for unusual traffic patterns that I would not have noticed just by looking at firewall logs alone. Reduced Dwell Time is something I value a lot, because in security, the longer an attacker stays hidden in your network, the more damage they can do. NDR helps me find suspicious activity faster, which means I can act on it quickly instead of discovering a problem weeks later. This has genuinely improved my response speed compared to before. Better Visibility is a feature I rely on daily, since NDR monitors all network traffic, not just what passes through the firewall or endpoint. This gives me a complete picture of what is actually happening across our network, including devices and traffic that other tools might not fully cover. AI-Based Detection is something I find really useful for catching unknown attacks. Traditional signature-based tools only catch threats that are already known, but attackers keep changing their methods. NDR's AI based approach helps detect unusual behavior even when it does not match any known signature, which gives me an extra layer of protection against new or evolving threats. Compliance support is very helpful for us too, since some of our clients and industry standards expect proof of proper network monitoring. Having NDR's detailed detection and audit trail makes compliance conversations and audits much smoother for me. Faster Incident Response is a direct benefit I experience regularly. When something suspicious is detected, NDR gives me enough detail to investigate and act quickly, instead of spending hours manually piecing together what happened from scattered logs. Asset Discovery is a feature I check regularly, since it helps me identify both managed and unmanaged devices on our network. This has actually helped me find a few devices that were connected to our network without proper security controls, which I then brought under proper management. Insider Threat Detection is something I did not expect to value as much as I do now. It monitors for suspicious behavior even from within the organization, not just external attacks, which is important because not every risk comes from outside. Data Protection through detecting data exfiltration attempts gives me real confidence, especially since we handle sensitive information for thousands of clients, and preventing that data from silently leaving our network is a top priority for me. What I really appreciate is how well NDR integrates with the rest of our Sophos setup. It works together with Sophos Firewall by sharing network insights and security events, so both tools are smarter together than separately. It correlates with Sophos Intercept X, connecting endpoint and network detections, which gives a fuller picture instead of two separate stories. We also get support from Sophos MDR, where their expert team does 24/7 threat hunting and response, which is extremely valuable for a team like ours that cannot monitor everything manually round the clock. And since everything is managed through Sophos Central, I don't need a separate login, I manage NDR from the same centralized dashboard I already use daily for firewall, endpoint, and email. An unexpected benefit I found is that NDR has actually helped me spot unmanaged or forgotten devices on our network that nobody was actively tracking, which is something I did not expect to discover through a network detection tool.
kaushal p.
KP
kaushal p.
Network Security Engineer at VIBS Infosol ltd.Firewall | Cybersecurity | Networking | CCNA
08/04/2026
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review

Reliable Ransomware protection that actually scales past 500 endpoints

I've been using Sophos Intercept X across our environment for a little over 2 3 years now, covering more than 500 endpoints, so I've had enough time to actually put in through its paces rather than just going off a demo. The thing that's kept me sold on it is Crypto Guard. Ransomware protection is one of those features every vendor claims to have, but this is one of the few times I've actually seen it do what it says - it rolls back encrypted files automatically without me having to manually restore from backup, which has saved us real cleanup time more than once. Day to Day, the Sophos Central console is what makes managing 500+ machines actually manageable for a small security team. I can push policies, check endpoint health, and pull threat reports from one dashboard instead of jumping between tools. Deployment to new machines is straightforward too - it doesn't need a ton of handholding once the base policy is set.

About

Contact

HQ Location:
Oxfordshire

Social

@Sophos

What is Sophos?

Sophos delivers IT security and data protection for businesses. They produced our first encryption and antivirus products back in the 1980s.

Details

Year Founded
1985
Ownership
LSE:SOPH
Website
www.sophos.com