Product Avatar Image

Sophos

Show rating breakdown
2,660 reviews
  • 19 profiles
  • 32 categories
Average star rating
4.6
#1 in 18 categories
Grid® leader
Serving customers since
1985
Profile Filters

All Products & Services

Product Avatar Image
Sophos Firewall

869 reviews

Ultimate enterprise firewall performance, security, and control.

Product Avatar Image
Sophos Endpoint

837 reviews

Sophos Intercept X is the world’s most comprehensive endpoint protection solution. Built to stop the widest range of attacks, Intercept X has been proven to prevent even the most advanced ransomware and malware by leveraging a unique combination of next-generation techniques. This includes the ability to detect never-before-seen malware with deep learning, stop ransomware with Sophos anti-ransomware technology, and deny attacker tools with signatureless exploit prevention. Intercept X also includes root cause analysis to provide insight into threats, and instant malware removal to ensure no attack remnants remain.

Product Avatar Image
Sophos MDR

506 reviews

Sophos provides cloud-native and AI-enhanced solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cybercriminal tactics and techniques, including automated and active-adversary breaches, ransomware, malware, exploits, data exfiltration, phishing, and more.

Product Avatar Image
Sophos United Threat Management

90 reviews

The global network of highly skilled researchers and analysts, protecting businesses from known and emerging malware - viruses, rootkits and spyware.

Product Avatar Image
Sophos Central

70 reviews

Sophos Central is a comprehensive, cloud-based cybersecurity management platform that unifies all Sophos next-generation security solutions into a single, intuitive interface. Designed to simplify and enhance cybersecurity management, it enables organizations to efficiently oversee and secure their IT infrastructure with advanced AI-driven protection and real-time data insights. Key Features and Functionality: - Unified Management Console: Provides centralized control over all Sophos security products, including endpoint, server, mobile, public cloud, firewall, email, wireless, and Zero Trust Network Access (ZTNA). - AI-Powered Cyber Defenses: Utilizes advanced artificial intelligence to deliver proactive threat detection and automated incident response, ensuring robust protection against evolving cyber threats. - Deep Data Analytics: Offers synchronized cross-product telemetry and access to SophosLabs Intelix threat intelligence, facilitating comprehensive cross-product investigations and informed decision-making. - High Availability and Scalability: Built on a cloud-native architecture hosted on public cloud platforms like AWS and Azure, ensuring high availability, seamless failover, and the ability to scale security measures as organizational needs grow. - Secure Architecture: Features a secure design with global services for identity and session management, scalable regional API and product services, and strict access controls to maintain data integrity and confidentiality. Primary Value and Solutions Provided: Sophos Central addresses the challenges IT administrators face in managing multiple security tools, responding to complex threats, and ensuring consistent protection across networks. By consolidating security management into a single platform, it reduces administrative burden, automates threat responses, and provides real-time insights, leading to: - Time and Effort Savings: Customers report a 50% reduction in time and effort spent managing IT security. - Enhanced Security Posture: Achieves an 85% reduction in security incidents through integrated and automated defenses. - Faster Issue Identification: Realizes a 90% reduction in time to identify issues, enabling swift remediation and minimizing potential damage. By integrating all security solutions into a cohesive system, Sophos Central empowers organizations to proactively defend against cyber threats, streamline security operations, and adapt to the dynamic cybersecurity landscape effectively.

Product Avatar Image
Secureworks Taegis MDR

48 reviews

Taegis ManagedXDR is Secureworks' Managed Detection and Response (MDR) offering. Powered by the Secureworks Taegis XDR platform, ManagedXDR delivers superior detection and proactive response as a managed cybersecurity solution with direct, live access to our security experts 24/7. ManagedXDR includes access to our Taegis EDR Agents for Windows, MacOS, and Linux/Unix, Taegis On-Premise and Cloud Data Collectors for AWS, Azure, and Google, API and SDK access, and 1 year retention of all telemetry sent to Taegis. All customers receive routine threat hunting, security posture advisory, and a name customer success manager to help continuously improve their security posture. Scoping and pricing the service is simple and transparent for the basic service and available add-ons. ManagedXDR is also available for OT (Operational Technology) environments for customers with OT needs.

Product Avatar Image
Sophos Email

42 reviews

Sophos Email is a comprehensive email security solution designed to protect organizations from advanced threats such as phishing, business email compromise (BEC), and malware. By integrating multiple layers of defense, including over 20 AI and machine learning models, it ensures robust protection for email communications. The solution seamlessly integrates with existing email platforms like Microsoft 365 and Google Workspace, enhancing security without disrupting current workflows. Additionally, Sophos Email offers deep visibility and control through its integration with Sophos Managed Detection and Response (MDR) and Extended Detection and Response (XDR) services, providing a unified approach to threat detection and response. Key Features and Functionality: - Advanced Threat Protection: Utilizes AI and machine learning to detect and block sophisticated phishing and BEC attacks. - Email Filtering: Effectively filters spam and malicious emails, ensuring only legitimate communications reach users. - Data Loss Prevention (DLP): Automatically scans emails and attachments for sensitive data, applying encryption or blocking messages as needed. - Encryption Options: Offers various encryption methods, including TLS, S/MIME, and portal-based encryption, to secure sensitive communications. - Integration with Security Services: Works in tandem with Sophos MDR and XDR for enhanced threat detection, investigation, and response capabilities. - User Awareness Training: Includes Sophos Phish Threat to simulate phishing attacks and provide training modules, enhancing user awareness and reducing susceptibility to attacks. Primary Value and User Solutions: Sophos Email addresses the critical need for robust email security by protecting organizations from evolving threats that exploit email as an attack vector. By combining advanced threat detection, data protection, and user training, it reduces the risk of data breaches and financial loss. Its seamless integration with existing email platforms and security services ensures comprehensive protection without adding complexity, allowing organizations to maintain secure and efficient communication channels.

Product Avatar Image
Sophos Mobile

37 reviews

We can help you simply secure and manage all your devices and protect the sensitive data on them.

Product Avatar Image
Sophos Intercept X

37 reviews

Sophos Intercept X is a comprehensive endpoint security solution designed to protect organizations from a wide range of cyber threats. Utilizing advanced technologies such as deep learning and anti-exploit measures, it effectively detects and prevents both known and unknown malware, ransomware, and zero-day exploits. Managed through the cloud-based Sophos Central platform, Intercept X offers streamlined deployment and management, ensuring robust protection with minimal system impact. Key Features and Functionality: - Deep Learning Technology: Employs advanced machine learning to identify and block new and previously unseen malware without relying on traditional signatures. - Anti-Ransomware with CryptoGuard: Detects and halts malicious encryption processes, automatically restoring affected files to their original state to mitigate ransomware attacks. - Exploit Prevention: Blocks over 60 exploit techniques used by attackers to compromise systems, steal credentials, and distribute malware. - Behavioral Analysis: Monitors system behavior to identify and stop malicious activities, including fileless attacks that operate directly from memory. - Managed Threat Response (MTR): Provides 24/7 threat hunting, detection, and response services delivered by a team of Sophos experts. - Centralized Management: Offers a unified management console via Sophos Central, simplifying policy configuration, reporting, and alert management. Primary Value and User Benefits: Sophos Intercept X delivers a multi-layered defense strategy that addresses the evolving landscape of cyber threats. By integrating deep learning and exploit prevention technologies, it proactively stops attacks before they can cause harm. The inclusion of CryptoGuard ensures that ransomware threats are neutralized, with automatic file restoration minimizing downtime and data loss. The MTR service adds an extra layer of security by providing continuous monitoring and expert intervention when necessary. With its centralized management through Sophos Central, organizations can efficiently oversee their security posture, ensuring comprehensive protection with reduced administrative overhead.

Profile Name

Star Rating

2119
459
58
14
10

Sophos Reviews

Review Filters
Profile Name
Star Rating
2119
459
58
14
10
Prateek  T.
PT
Prateek T.
08/01/2026
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review

Synchronized Security That Saves Time: Real-Time Endpoint-to-Firewall Protection

The Standout feature for me is Synchronized Security / security Heartbeat functionality across our endpoints and firewalls . Having Intercept X talking directly to the Sophos XGS firewall in real -time has saved out team multiple times . if users laptop pick something suspicious or triggers an alert, the firewall immediately isolates that host from the rest of the VLAN without requiring us to jump in manually out of hours . from a management standpoint : Centralized Policy Deployment : Pushing global polices or overriding settings for specific user groups (like developers vs general staff) is straightforward once you understand policy inheritance. Live Discover(XDR): Being able to execute quick sql queries across our entire fleet to look for specific IOCs or missing KB updates saves us from running separate PowerShell scripts via RMM. BitLocker Recovery: Helpdesk agents can grab BitLocker recovery keys in under 10 seconds straight from the users object page, which trimmed down our lock out ticket times significantly . Threat Graphs : The root cause analysis visualization (Showing process parentage , modified files , and network connections) makes post-incident write-ups fast and easy to explain to non technical managers .
Prateek  T.
PT
Prateek T.
08/01/2026
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review

Top-Tier Endpoint Protection with Powerful Automation and Root Cause Analysis.

From an operational standpoint, the biggest win with Sophos Endpoint is how much work Sophos Central Handles automatically without requiring constant manual intervention. Ransomware & Anti-Exploit Defense : The behavioral engines (CryptoGuard and exploits mitigation) are genuinely strong. It catches fileless threats , malicious PowerShell Scripts, and unauthorized process injection at execution time rather than relying solely on legacy signature updates. Root Cause Analysis (RCA) Graphs: When threat or suspicious file gets flagged, the threat graphs shows precisely where the vector originated , which child processes were spawned , what registry key were touched. It cuts incident triage time down from hours to minutes. Automated Device Isolation : If an endpoint exhibits malicious behavior , Sophos isolates the machine from the local network while maintaining a management tunnel back to Sophos central. This gives as breathing room to remediate without risking lateral movement across our subnets or VPN . Centralized Policy Management : Pushing global policies , web filtering , and USB control across remote and on premise endpoints is straightforward once you structure your device groups properly.
Shibu K.
SK
Shibu K.
Network Security Engineer | Firewall & Security Policy Management | Tufin | AlgoSec | Allot Secure | Cybersecurity Enthusiast | Continuous Learner
07/30/2026
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review

Sophos Mobile keeps every employee device secure & compliant & takes lot of manual work off my plate

I have been using Sophos Mobile for a good amount of time now as part of my daily work as a network security engineer at Vibs Infosol Pvt Ltd. As an admin, I manage this platform every day, and it has become a very important tool for us, because our employees communicate with thousands of clients through email and calls, and a lot of that communication now happens through mobile devices, not just laptops or desktops. Protecting these mobile devices was becoming a real challenge, and Sophos Mobile has made this much more manageable for me. The feature I use most regularly is Device Enrollment. Whenever a new employee joins or gets a new company device, I enroll it into Sophos Mobile, and from that point onward I have full visibility and control over that device. Earlier, without a proper MDM solution, onboarding a new device used to be a manual and inconsistent process, sometimes security settings would get missed. Now enrollment is standardized, every device goes through the same secure setup process, which has reduced human error significantly. Policy Management is something I configure and update regularly. I can create policies for different departments or user groups, instead of applying the same rule to everyone. For example, our sales team who travel a lot need different Wi-Fi and VPN settings compared to our office based staff. Being able to customize policies per group instead of a generic one-size rule has made our security setup much more practical and effective for real daily use. Application Management is another feature I rely on daily. I can control which apps are allowed or blocked on company devices, and push required business apps directly to employee devices remotely. This has saved me a lot of time, because earlier I had to physically ask employees to install specific apps themselves, which was inconsistent and slow. Now I push it centrally and it happens automatically. Device Encryption Enforcement gives me real peace of mind. I can make sure every company device has encryption enabled, so even if a device is lost or stolen, the data on it stays protected and unreadable to anyone who doesn't have proper access. Given that our employees carry sensitive client communication on their phones and laptops, this feature directly protects our clients' trust as well. Password & Screen Lock Policies are something I enforce across all devices, so no device stays unlocked or unprotected even if left unattended for a moment. This small feature has actually prevented a few situations where devices were misplaced temporarily in the office, and having lock policies already active prevented any unauthorized access during that time. Compliance Monitoring is a feature I check regularly, since it shows me which devices are following our security policies and which are not compliant, maybe because of an outdated OS version or a disabled security setting. I can immediately follow up on non-compliant devices and get them fixed before they become a real risk. Wi-Fi & VPN Configuration is pushed directly through Sophos Mobile, so employees don't have to manually configure secure network settings themselves, which used to cause a lot of support tickets earlier when done manually. Now it happens automatically and correctly every time. Alerts & Reporting keeps me updated in real time about any risky or non-compliant device, and I use the reporting data directly for my monthly security reports to management, saving me hours of manual data collection every month. Sophos Central Integration is probably the biggest daily convenience for me, since I manage Sophos Mobile from the same Sophos Central console I already use for firewall, endpoint, and email protection. I don't need a separate login, everything is connected, which genuinely saves me time every single day and reduces the mental switching between different tools. An unexpected benefit I found is that since implementing proper mobile management, our support tickets related to lost devices or configuration issues have reduced noticeably, since most things are now handled centrally and proactively instead of reactively.

About

Contact

HQ Location:
Oxfordshire

Social

@Sophos

What is Sophos?

Sophos delivers IT security and data protection for businesses. They produced our first encryption and antivirus products back in the 1980s.

Details

Year Founded
1985
Ownership
LSE:SOPH
Website
www.sophos.com