Overview
Sophos provides powerful and effective cybersecurity, designed to be accessible and manageable for any organization - from schools, hospitals, local government, healthcare, and businesses of every shape and size. Available through the Sophos Central platform, a single pane of glass, born in the cloud, natively synchronizing the management of an entire ecosystem of adaptive security defenses. Start with Sophos Firewall, and next-gen endpoint or workload protection and grow. Sophos Endpoint: Security for endpoints, servers, and EC2. Combining malware protection, XDR, MDR, and more. Firewall: Protect networks from advanced threats and maintain web-app availability. https://soph.so/xg-firewall-payg Cloud Optix: Visualize cloud resources, monitor compliance, and analyze configurations to optimize security. https://soph.so/cloud-optix Mobile: Secure UEM solution to protect and manage mobile devices. Email: Stop spam, phishing, and data loss. Phish Threat: Security awareness training with phishing simulations. Encryption: Full disk encryption for Windows and macOS. -- Managed Services -- Managed Detection & Response: 24/7 threat hunting, detection, and response. https://soph.so/MTR Rapid Response: Incident response service during an attack. https://soph.so/rapid-response Looking for custom pricing options? Contact us publiccloudsales@sophos.com
Highlights
- Easy to deploy, manage, and highly effective at stopping cyberattacks. Sophos products and services provide cloud security best practices and compliance, threat detection and response, network security, host and endpoint security in a single console.
- Block ransomware: Endpoint and Server anti-ransomware technology detects malicious encryption processes and shuts them down before they spread. Any files encrypted are rolled back to a safe state automatically.
- Sophos synchronized security allows organizations to link endpoints, cloud workloads, and firewall to relay health status, immediately isolate compromised devices or workloads, and respond to threats on your network automatically.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(2)


Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Sophos EDR | Malware/Ransomware/Exploits/Viruses | $69.96 |
Sophos XDR | Sophos EDR features plus Extended Detection and Response tools | $136.60 |
Sophos MDR | Central MDR Complete including XDR | $239.64 |
Sophos EDR - Server | EDR features/Server Lockdown/Cloud Optix standard: for Server OS | $153.56 |
Sophos XDR - Server | EDR Server features plus Extended Detection and Response tools | $222.66 |
Sophos MDR - Server | Central MDR Complete Server includes EDR and XDR | $390.72 |
Mobile Advanced | Secure Unified Endpoint Management for Windows 10, macOS, iOS, Android | $93.48 |
Cloud Optix Advanced | Cloud Native App Protection for AWS, Azure, GCP, K8s | $140.04 |
Sophos Email Advanced | Sophos Email Security | $66.96 |
Sophos Phish Threat | Sophos Phish Threat, Phishing Simulation and Training: Per user | $37.80 |
Vendor refund policy
Please refer to the Sophos EULA for details on our refund policies.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Sophos support portal for licensed customers with an existing SophosID: https://support.sophos.com Toll Free: 1-888-SOPHOS-9 (1-888-767-4679)International: 1-781-494-5800 To contact Support, please log into your Sophos Central Dashboard, click on HELP in the upper right corner, then click on CREATE SUPPORT TICKET. Or, visit https://www.sophos.com/en-us/support.aspx to go to the Sophos Community to find information and resolutions on common questions and issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Centralized threat blocking has reduced manual monitoring but still needs better exclusions and logs
What is our primary use case?
My main use case for Sophos Central involves utilizing it as an endpoint, EDR, and email gateway.
In my day-to-day work, I use Sophos Central by installing the agent on our clients. We have around 40 to 50 clients that are using Sophos as their EDR. We have created the alerting system in our ServiceNow , which is integrated with Sophos Central, so we get tickets in ServiceNow whenever something is triggered. I log into Sophos to investigate the alert, reviewing the alerts on that device from Sophos, and if required, I manually log into the device to check the alert and take actions accordingly.
Regarding my main use case or how I use Sophos Central day to day, the most useful feature is that Sophos blocks threats. As a senior engineer, my main work involving Sophos is handling situations when it blocks something that is legitimate, such as a ServiceNow MID Server. Every time this happens, Sophos blocks it as a malicious file, so we dive into Sophos and create exclusions, especially path exclusions, and if necessary, we also create hash exclusions to ensure that the legitimate file can be accessed and run by the user without any issues.
What is most valuable?
The best features Sophos Central offers, in my opinion, involve its excellent ability to block threats in endpoint protection. While it is not as effective in handling exclusion cases, it excels at successfully blocking almost all files that seem suspicious, which is really good and provides strong security.
What I appreciate most about the blocking features in Sophos Central is its real-time detection and the variety of threat types it can catch. Many other endpoints miss files that don't have a bad reputation, but Sophos finds a way to catch those malicious files, and if there's even a small suspicion, it blocks them. The real-time detection is really great in Sophos Central.
Sophos Central has positively impacted our organization by being a desired EDR solution for our many clients. As an MSSP , we have a significant number of clients utilizing Sophos Central, and it provides excellent service as an EDR. Even when we use it as an email gateway, it continues to perform well, making it beneficial for our organization with a wide client base.
What needs improvement?
One way Sophos Central can be improved is in its exclusion capabilities. When we try to exclude legitimate files, we find that it requires a lot of effort, as we cannot simply exclude one file from every detection. Due to the layered approach, it takes time to exclude even one file, indicating that the exclusion process could definitely be enhanced.
I would add that the logs in Sophos Central should be more detailed. Sometimes, when we're checking the logs, they simply state that a file is blocked, but we can't find out why that is the case. More detailed logs could significantly improve the log collecting aspect.
Areas for improvement in Sophos Central are log collection, exclusion processes, and customer support. Aside from these points, I believe the overall product is great.
For how long have I used the solution?
I have been using Sophos Central for the last six years.
What do I think about the stability of the solution?
Sophos Central is stable, which is a positive attribute.
What do I think about the scalability of the solution?
I believe Sophos Central's scalability is good compared to other EDR solutions that we have.
How are customer service and support?
Customer support for Sophos Central is a bit slow. When I create a support ticket, it takes a while for them to respond. In my recent experience with a support ticket, the engineer was not very effective and took longer than I expected. When we reach out to the support team, we anticipate quick answers, especially since the client is waiting for a resolution. The vendor seems to take time contacting other teams, so I feel the support team could improve their response times.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before using Sophos Central, we had utilized CrowdStrike; however, due to an outbreak, some clients wanted to switch away from CrowdStrike. We provided clients with options, including Sophos Central and SentinelOne, with SentinelOne being fairly costly. Ultimately, most clients preferred Sophos Central, leading us to switch a few clients from CrowdStrike to Sophos Central.
What was our ROI?
I have seen a return on investment with Sophos Central in terms of needing fewer employees because Sophos Central is handling many tasks itself. Previously, we had to monitor other endpoints and faced issues integrating with ServiceNow, requiring separate monitoring. After adopting Sophos Central, we can easily integrate with ServiceNow, which means fewer employees, and that translates to money saved.
Which other solutions did I evaluate?
Before choosing Sophos Central, we evaluated other options such as SentinelOne and Microsoft Defender.
What other advice do I have?
My advice to others looking into using Sophos Central is that it is beneficial in terms of cost efficiency and time efficiency. I recommend using Sophos Central and digging into the logs more thoroughly, and if possible, incorporating syslogs or other kinds of logs. I would rate this product a 7 out of 10.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized security management has streamlined remote protection for diverse customer networks
What is our primary use case?
I am still using Sophos Central for everything. I am a reseller of Sophos Central products.
For end-customer workstations, I use Sophos Central for antivirus through the central administration console and installation. I also import all of my firewalls into Sophos Central for remote management and those functions.
I do work with Intercept X technology.
What is most valuable?
Intercept X technology helps with my malware detection and response. If it detects malware, it blocks it and then it sends it through to Sophos Central, which then sends me an email notification that one of the workstations picked up an infection or encountered an issue.
Synchronization security capability contributes to threat identification in my company.
I assess the benefit of a single pane of glass interface positively.
What needs improvement?
On a couple of older machines, Intercept X does tend to slow a computer down significantly, but on new, modern Windows 11 machines, I have not detected this issue yet.
Intercept X tends to pick up a very common program, Hard Disk Sentinel , as malware, specifically the executable file. For the purpose of installation, I have to disable Intercept X from Sophos Central to complete the install. Once the install is done, I can re-enable it and everything works fine. It creates extra work to make something function, but that is all.
For how long have I used the solution?
I have been dealing with the product for approximately six to eight years.
What do I think about the stability of the solution?
I give a stability score of ten.
What do I think about the scalability of the solution?
I would give a scalability score of ten for the product.
How are customer service and support?
If I interact with technical support, I would give them a score of ten as they are good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have worked with other products. For instance, Symantec from Broadcom was a nightmare because having to install a separate server module for the management of workstations is not centrally accessible. If something happens, I have to either use TeamViewer to connect to the server to see what is going on or use VPN or another method. The biggest advantage for me is that I can log in from anywhere and see what is going on on the central dashboard with my customer's networks.
How was the initial setup?
I find the installation of Sophos Central easy.
What about the implementation team?
My clients have it on-cloud.
What was our ROI?
The biggest return on investment is securing my customer's networks.
Which other solutions did I evaluate?
I have not come across something that is better when I compare Sophos Central with other products.
What other advice do I have?
I have so many workstations and, as a reseller, I am not only working on one Sophos Central. I probably have about 35 to 40 different customers that are on Sophos Central. Each one is set up differently according to customer needs.
I would say Sophos Central is a good solution for all customers, from small to enterprise.
I have not integrated Sophos Central with any third-party applications, so I do not have experience with that functionality.
The machine learning features are enabled. We have picked up a false positive now and again, but then I report it to Sophos and they rectify the issue in upcoming release builds.
The biggest benefit in Sophos Central is the central functionality where I can have my Intercept X integrate the workstations, the servers, and the firewalls I import into Sophos Central. I always enable the RED functionality so that if a machine picks up an issue, it notifies the firewall immediately, and then the two combined rectify the issue if there are any threats or something picked up.
I would say Sophos Central is an affordable product.
They are using Sophos cloud instead of cloud providers like AWS , Azure , or GCP.
I buy the product directly from Sophos.
I am a Senior IT Consultant here in the company. My overall review rating for this product is ten.
Unified Dashboard Makes Managing Sophos Products Easy
Very resource intensive