Product Avatar Image

Sophos

Show rating breakdown
2,660 reviews
  • 19 profiles
  • 32 categories
Average star rating
4.6
#1 in 18 categories
Grid® leader
Serving customers since
1985
Profile Filters

All Products & Services

Profile Name

Star Rating

2120
459
58
14
10

Sophos Reviews

Review Filters
Profile Name
Star Rating
2120
459
58
14
10
Shibu K.
SK
Shibu K.
Network Security Engineer | Firewall & Security Policy Management | Tufin | AlgoSec | Allot Secure | Cybersecurity Enthusiast | Continuous Learner
08/05/2026
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review

Sophos NDR gives us visibility we never had before - it catches things our firewall and endpoint.

I have been using Sophos NDR for a good amount of time now as part of my daily work as a network security engineer at Vibs Infosol Pvt Ltd. As an admin, I check this platform every day, and it has become a very important layer in our overall security setup, because we deal with thousands of clients and almost all our communication happens through email and calls, and any hidden attacker sitting quietly in our network could cause serious damage before we even notice. Sophos NDR has given us the visibility we were missing before. The biggest value I get is Early Threat Detection. Before NDR, our firewall and endpoint protection were good at stopping known threats, but anything unusual that quietly moved inside our network was harder to catch in time. Now NDR monitors network traffic constantly and flags suspicious behavior early, before it turns into an actual damaging attack. I have personally seen alerts for unusual traffic patterns that I would not have noticed just by looking at firewall logs alone. Reduced Dwell Time is something I value a lot, because in security, the longer an attacker stays hidden in your network, the more damage they can do. NDR helps me find suspicious activity faster, which means I can act on it quickly instead of discovering a problem weeks later. This has genuinely improved my response speed compared to before. Better Visibility is a feature I rely on daily, since NDR monitors all network traffic, not just what passes through the firewall or endpoint. This gives me a complete picture of what is actually happening across our network, including devices and traffic that other tools might not fully cover. AI-Based Detection is something I find really useful for catching unknown attacks. Traditional signature-based tools only catch threats that are already known, but attackers keep changing their methods. NDR's AI based approach helps detect unusual behavior even when it does not match any known signature, which gives me an extra layer of protection against new or evolving threats. Compliance support is very helpful for us too, since some of our clients and industry standards expect proof of proper network monitoring. Having NDR's detailed detection and audit trail makes compliance conversations and audits much smoother for me. Faster Incident Response is a direct benefit I experience regularly. When something suspicious is detected, NDR gives me enough detail to investigate and act quickly, instead of spending hours manually piecing together what happened from scattered logs. Asset Discovery is a feature I check regularly, since it helps me identify both managed and unmanaged devices on our network. This has actually helped me find a few devices that were connected to our network without proper security controls, which I then brought under proper management. Insider Threat Detection is something I did not expect to value as much as I do now. It monitors for suspicious behavior even from within the organization, not just external attacks, which is important because not every risk comes from outside. Data Protection through detecting data exfiltration attempts gives me real confidence, especially since we handle sensitive information for thousands of clients, and preventing that data from silently leaving our network is a top priority for me. What I really appreciate is how well NDR integrates with the rest of our Sophos setup. It works together with Sophos Firewall by sharing network insights and security events, so both tools are smarter together than separately. It correlates with Sophos Intercept X, connecting endpoint and network detections, which gives a fuller picture instead of two separate stories. We also get support from Sophos MDR, where their expert team does 24/7 threat hunting and response, which is extremely valuable for a team like ours that cannot monitor everything manually round the clock. And since everything is managed through Sophos Central, I don't need a separate login, I manage NDR from the same centralized dashboard I already use daily for firewall, endpoint, and email. An unexpected benefit I found is that NDR has actually helped me spot unmanaged or forgotten devices on our network that nobody was actively tracking, which is something I did not expect to discover through a network detection tool.
kaushal p.
KP
kaushal p.
Network Security Engineer at VIBS Infosol ltd.Firewall | Cybersecurity | Networking | CCNA
08/04/2026
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review

Reliable Ransomware protection that actually scales past 500 endpoints

I've been using Sophos Intercept X across our environment for a little over 2 3 years now, covering more than 500 endpoints, so I've had enough time to actually put in through its paces rather than just going off a demo. The thing that's kept me sold on it is Crypto Guard. Ransomware protection is one of those features every vendor claims to have, but this is one of the few times I've actually seen it do what it says - it rolls back encrypted files automatically without me having to manually restore from backup, which has saved us real cleanup time more than once. Day to Day, the Sophos Central console is what makes managing 500+ machines actually manageable for a small security team. I can push policies, check endpoint health, and pull threat reports from one dashboard instead of jumping between tools. Deployment to new machines is straightforward too - it doesn't need a ton of handholding once the base policy is set.
Prateek  T.
PT
Prateek T.
08/04/2026
Validated Reviewer
Verified Current User
Review source: Organic Review from User Profile
Incentivized Review

Smooth Sophos Central Onboarding with Automated Campaigns and One-Click Outlook Reporting

Having everything tied directly into the Sophos Central dashboard made initial onboarding smooth for our small it teams . From an admin perspective, setting up automated campaigns takes under 20 minutes ,and the active directory integration handle user syncing without needing manual CSV uploads every week . On the end user side, the reporting add-in for outlook work surprisingly well it turn security in simple one click action for aur employees instead of them forwarding clutter to our help desk . The pre build templet library covers real world scenarios and when someone inevitable clicks a link the interactive micro-learning module is assigned automatically Over six months, our click through failure rates dropped significantly across high risk departments.

About

Contact

HQ Location:
Oxfordshire

Social

@Sophos

What is Sophos?

Sophos delivers IT security and data protection for businesses. They produced our first encryption and antivirus products back in the 1980s.

Details

Year Founded
1985
Ownership
LSE:SOPH
Website
www.sophos.com