Protection against ransomware, advanced threats, and more across endpoints, cloud workloads, servers, mobile devices, networks, and email. Extend on premise security and build secure and scalable cloud transformations with a complete cybersecurity platform for all Sophos next-gen technologies.
Sophos provides powerful and effective cybersecurity, designed to be accessible and manageable for any organization - from schools, hospitals, local government, healthcare, and businesses of every shape and size.
Available through the Sophos Central platform, a single pane of glass, born in the cloud, natively synchronizing the management of an entire ecosystem of adaptive security defenses. Start with Sophos Firewall, and next-gen endpoint or workload protection and grow.
Sophos Endpoint: Security for endpoints, servers, and EC2. Combining malware protection, XDR, MDR, and more.
Firewall: Protect networks from advanced threats and maintain web-app availability. https://soph.so/xg-firewall-payg
Cloud Optix: Visualize cloud resources, monitor compliance, and analyze configurations to optimize security. https://soph.so/cloud-optix
Mobile: Secure UEM solution to protect and manage mobile devices.
Email: Stop spam, phishing, and data loss.
Phish Threat: Security awareness training with phishing simulations.
Encryption: Full disk encryption for Windows and macOS.
-- Managed Services --
Managed Detection & Response: 24/7 threat hunting, detection, and response. https://soph.so/MTR
Rapid Response: Incident response service during an attack. https://soph.so/rapid-response
Looking for custom pricing options? Contact us publiccloudsales@sophos.com
Highlights
Easy to deploy, manage, and highly effective at stopping cyberattacks. Sophos products and services provide cloud security best practices and compliance, threat detection and response, network security, host and endpoint security in a single console.
Block ransomware: Endpoint and Server anti-ransomware technology detects malicious encryption processes and shuts them down before they spread. Any files encrypted are rolled back to a safe state automatically.
Sophos synchronized security allows organizations to link endpoints, cloud workloads, and firewall to relay health status, immediately isolate compromised devices or workloads, and respond to threats on your network automatically.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy each option per unit under a contract, and you pick only the modules you need. Endpoint protection comes in three levels that build on each other: EDR, then XDR (adds extended detection tools), then MDR (adds managed detection with XDR). The same three levels repeat for server operating systems as separate dimensions. Other dimensions cover distinct needs and price independently: mobile device management, cloud native app protection, email security, phishing simulation and training (per user), and zero trust network access. You scale each dimension by the number of units you require.
Top-of-mind questions for buyers
What counts as one unit for the endpoint and server dimensions versus the per-user options?
Endpoint and server dimensions bill per protected device. Each laptop, desktop, or server operating system counts as one unit. Phish Threat bills per user account, as its description states. Cloud Optix Advanced covers cloud workloads and Kubernetes environments. You count the number of devices, users, or workloads you need to protect.
How do the endpoint dimensions differ from the matching server dimensions?
Endpoint dimensions protect user devices like laptops and desktops. Server dimensions protect server operating systems and add Server Lockdown and Cloud Optix standard, per their descriptions. Both come in three levels: EDR, XDR, and MDR. You buy endpoint units and server units separately, based on how many of each you run.
If I buy several modules, how do the charges combine on my bill?
Each dimension bills independently by its own unit count. Endpoint, server, mobile, cloud, email, phishing, and zero trust charges add together on one invoice. No dimension is required to buy another. You scale each line by the units you need, so your total reflects the modules you selected and their quantities.
www.sophos.com+1
Helpful?
Vendor refund policy
Please refer to the Sophos EULA for details on our refund policies.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Sophos support portal for licensed customers with an existing SophosID: https://support.sophos.com Toll Free: 1-888-SOPHOS-9 (1-888-767-4679)International: 1-781-494-5800
To contact Support, please log into your Sophos Central Dashboard, click on HELP in the upper right corner, then click on CREATE SUPPORT TICKET. Or, visit https://www.sophos.com/en-us/support.aspx to go to the Sophos Community to find information and resolutions on common questions and issues.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Single pane of glass management platform for coordinating security across endpoints, servers, cloud workloads, firewalls, mobile devices, email, and network infrastructure.
Ransomware Protection
Anti-ransomware technology that detects malicious encryption processes, terminates them before propagation, and automatically rolls back encrypted files to a safe state.
Synchronized Threat Response
Cross-platform security synchronization that links endpoints, cloud workloads, and firewalls to relay health status, automatically isolate compromised devices or workloads, and execute coordinated threat response.
Extended Detection and Response
XDR and MDR capabilities combined with malware protection for comprehensive threat detection, hunting, and response across the security ecosystem.
Multi-Layer Security Coverage
Integrated protection spanning endpoint security, server protection, EC2 workloads, network firewall, mobile device management, email security, and full disk encryption for Windows and macOS.
Application Layer Visibility and Control
Complete application layer-7 visibility and control of traffic with next-generation firewall capabilities in AWS environments
AI/ML-Powered Threat Detection
AI/ML-powered inspection engine with researcher-grade signatures for detection of zero-day threats, exploits, malware, spyware, and command and control attacks
Dynamic Policy Management
Policy definitions that dynamically apply to cloud assets based on AWS tags, Application IDs, User IDs, geographies, or zones without manual intervention
Cloud Infrastructure Integration
Seamless integration with Gateway Load Balancer, AWS Auto Scaling, and Transit VPC with AWS Transit Gateway for protection across dynamic and large-scale deployments
Advanced Threat Prevention Service
Cloud-delivered Advanced Threat Prevention security service with market-leading threat coverage against known and zero-day threats while maintaining performance
Next Generation Firewall Architecture
High-performance firewall solution with core firewall, VPN, NAT, and advanced L4-L7 security services including application security, IPS, and anti-virus capabilities.
Anti-Virus and Malware Protection
Cloud-based anti-virus protection that detects and blocks spyware, adware, viruses, keyloggers, and other malware over POP3, HTTP, SMTP, and FTP protocols.
Intrusion Detection and Prevention
Intrusion detection and prevention (IPS) system integrated with application visibility and control through AppSecure for threat detection and workload protection.
VPN and Secure Connectivity
IPsec and full mesh VPN termination services enabling secure connectivity from on-premises data centers, campuses, and branches to AWS cloud across geographically dispersed VPCs.
AWS Cloud Service Integration
Native integration with AWS services including Elastic Load Balancer, Auto-Scaling Groups, CloudWatch, Security Hub, Key Management Service, Elastic Network Adapter support, and Gateway Load Balancer with L3 gateway and L4 load balancer capabilities.
Effortless Endpoint Security Management with Real-Time Cloud Visibility
Reviewed on Aug 03, 2026
Review provided by G2
What do you like best about the product?
The unified cloud dashboard makes managing endpoint security across multiple devices effortless. Rolling out agents, pushing policies and viewing threat alerts happen in real-time without managing on-premise servers. The integration with intercept X provides solid anti-ransomware protection out of the box.
What do you dislike about the product?
The interface can occasionally feel sluggish during high traffic updates, and search query filters in the logs could be more intuitive, initial deployment on legacy OS machines can also require occasional manual troubleshooting.
What problems is the product solving and how is that benefiting you?
It gives us centralized visibility over our remote and on-premise endpoints. We have significantly reduced administrative overhead for malware remediation and simplified compliance reporting.
Prateek T.
Synchronized Security That Saves Time: Real-Time Endpoint-to-Firewall Protection
Reviewed on Jul 25, 2026
Review provided by G2
What do you like best about the product?
The Standout feature for me is Synchronized Security / security Heartbeat functionality across our endpoints and firewalls . Having Intercept X talking directly to the Sophos XGS firewall in real -time has saved out team multiple times . if users laptop pick something suspicious or triggers an alert, the firewall immediately isolates that host from the rest of the VLAN without requiring us to jump in manually out of hours .
from a management standpoint :
Centralized Policy Deployment : Pushing global polices or overriding settings for specific user groups (like developers vs general staff) is straightforward once you understand policy inheritance.
Live Discover(XDR): Being able to execute quick sql queries across our entire fleet to look for specific IOCs or missing KB updates saves us from running separate PowerShell scripts via RMM.
BitLocker Recovery: Helpdesk agents can grab BitLocker recovery keys in under 10 seconds straight from the users object page, which trimmed down our lock out ticket times significantly .
Threat Graphs : The root cause analysis visualization (Showing process parentage , modified files , and network connections) makes post-incident write-ups fast and easy to explain to non technical managers .
What do you dislike about the product?
While the core detection and cloud UI work well overall, there are definitely areas where it feels unpolished :
Local Resource Usage : On older machines or developer workstations, the deep learning files scanning and memory protection can lead to noticeable CPU/disk usage spikes. Developers compiling local code or running Docker containers frequently hit false positives or slowdowns until we set up granular folder exclusions .
Support Turnaround : Opening a ticket directly through the portal of technical glitch or false positive reviews can feel like a black hole. Standard tier support takes too long to escalate beyond initial "have you restart the agent" scripts.
Deep Navigation & Reporting Constraints : Basic dashboard are great, but custom scheduled reporting feels clunky . Finding specific nested setting like Tamper Protection overrides or specific web control sb categories often takes 3 to 4 clicks deeper than it should.
What problems is the product solving and how is that benefiting you?
Tool Consolidation : Prior to Sophos Central , we managed standalone endpoint protection, a separate web filter , and legacy BitLocker tools. Bringing endpoint , server security , device encryption ,and firewall monitoring into one dashboard reduced our daily administration overhead significantly.
Automated Containment : Because we operate with a small IT/Security team , automated Endpoint isolation gives us critical breathing room. If malware attempts to run on a remote worker's laptop on a Friday night, Central isolates the machine from local network resources while leaving management communication open .
Simplified Off-Network Security : Remote and hybrid workers receive policy updates and push telemetry back to the cloud console seamlessly without needing an active VPN connection back to our head office
Dheeraj S.
Unified Sophos Central Management with Top-Tier Intercept X and Security Heartbeat
Reviewed on Jul 22, 2026
Review provided by G2
What do you like best about the product?
Unified Management (Single Pane of glass) Managing endpoint protection server defense email filtering and firewall policies from one central console significantly cuts down on context switching pushing global policies setting up exclusions and pushing agent updates across device groups is straightforward once the tenant structure is established. Intercept X & Crypto guard feature are top tier in instances halts the process and automatically rolls back targeted files from local shadow copies before damage occurs. Synchronized security (Security Heartbeat) If you run Sophos Firewall alongside Sophos Central endpoint the security Heartbeat Features is an operational game changer If a device drops to a Red Helt status due to a threat the firewall automatically restricts its lateral network access until remediated.
What do you dislike about the product?
Minor Resource Impact on older Hardware
On legacy or budget-tier client machines (especially those with spinning HDDs) background deep scans can cause occasional CPU spikes modern machines with standard SSDs and 16 GB RAM run the agent without any noticeable lag.
Reporting Customization limits
The built-in Executive summaries and compliance reporting dashboards requires upgrading complex Highly customized reporting Dashboards requires upgrading to full XDR or Exporting logs to an external SIEM.
What problems is the product solving and how is that benefiting you?
Reduced Incident Response Time: Automated Network isolation and threat rollback mean minor malware alerts rarely require manual re-imaging or onsite intervention. Consistent policy Enforcement: Remote laptops stay protected and updated directly through the cloud regardless of whether end users are connected to the corporate VPN. Leverage the full Ecosystem: Sophos Central delivers the most value when you pair Intercept X on endpoints with Sophos firewalls to take advantage of Synchronized security.
Akinola Makinde
Centralized protection has secured global endpoints and simplifies daily threat response
Reviewed on Jun 21, 2026
Review provided by PeerSpot
What is our primary use case?
My main use case for Sophos Central is to help protect our endpoints, especially as we have different team members across different countries. We have team members in Africa, and we have team members in the UK. In Africa, we have team members in Lagos, Nigeria, Uganda, South Africa, and Kenya because these are where our markets are. This helps us protect our endpoints, especially as these team members have their work to do.
Regarding how I use Sophos Central day-to-day, it helps with malware detection. Each day, I can come to the dashboard and see threats and alerts. I can see the compromised level and the level of threats, whether they are high, medium, or low, and then I take the necessary action. Sophos has been especially helpful for malware on endpoints. I have not had any cause for concern, especially regarding malware attacks.
What is most valuable?
Sophos Central has been really helpful over time. A specific example of how it has helped me is that there have been cases where a particular team member tried to install software from a compromised site. Sophos immediately sends a high alert to my email, mentioning that this particular user with this particular device is trying to download software from a particular compromised website. The software will not allow the person to download it, and I can reach out to the person to inform them that I can see they are trying to download this and ask them to stop downloading it.
I think the best features Sophos Central offers are the parts where users cannot uninstall Sophos themselves unless they reach out to me as the IT administrator. I appreciate this because ordinarily a user could decide to do something, uninstall the software, do whatever they want to do, and come back and install the software again. However, that is not the case for Sophos Central. Before you can uninstall Sophos Central, you have to reach out to the IT administrator. This is a very good feature.
This aspect impacts my daily work positively because it has helped prevent issues with users trying to bypass security. It has helped in many ways, especially when a user wants to view inappropriate content on their work device. Sophos immediately sends a high alert and will not even allow the user to open the site. This is helpful because I do not know what could have come into the work device by visiting those sites. It is something I have enjoyed personally.
Another feature I appreciate is the email alerts. When Sophos sends an email alert to me, I can easily see that something is going on and needs my attention, and I can immediately take action. This helps with monitoring, especially regarding security. When anything is flagged, I immediately log on to Sophos Central and take action.
What needs improvement?
I have noticed pain points around installation. Whenever I want to install on devices that are Windows, it is usually a lot of hassle because it is very easy to install on a MacBook. However, when a user is using Windows, installing Sophos Central on Windows is usually a serious undertaking. I think they can improve on that. Additionally, the installation takes a really long time for Sophos Central. While that might be fine if it is doing its job, for Windows it is really quite a lot when you are installing for a particular person.
Regarding needed improvements, I would suggest something. Zoho has this ManageEngine feature where users can actually turn off a device from the administrator end. I think if Sophos Central could integrate that in their system, whereby when there is a high alert, I as an IT administrator can easily go there and click on something to turn off the user's work device, I think that would be something I would love to have. That is a feature I would appreciate.
I believe if Sophos Central could have something like remote desktop access, similar to Zoho ManageEngine, where when a particular device is attacked, you can toggle off the device from your end or maybe access the device remotely and render it non-functional, that is something I would appreciate seeing on Sophos Central in the future.
For how long have I used the solution?
I have been using Sophos Central for about a year.
What do I think about the stability of the solution?
Sophos Central is stable for us. Sophos Central has been stable for our organization.
What do I think about the scalability of the solution?
Regarding Sophos Central's scalability, I think it can handle our organization's growth and more users if needed. When the team starts increasing in number, you only need to procure more licenses. I know of bigger startups that are using Sophos Central today. Our team is less than fifty people, so I think it can definitely handle scalability.
How are customer service and support?
We have been contacting our third-party vendor's customer support, and they have been very responsive. Recently, they mentioned an upgrade plan for Sophos Central. We have not explored it yet, but it is something we might be willing to explore in the near future. Their customer support has been wonderful. I would give the customer support a ten out of ten. They have been excellent. In fact, there are times when they would visit us in the office to help with any technicalities. So they have been good.
Which solution did I use previously and why did I switch?
We have not been using a different solution before Sophos Central.
How was the initial setup?
My experience with pricing, setup cost, and licensing for Sophos Central shows that it is expensive. However, when you look at it holistically, I think it is still fair. We got licenses at first for fifteen team members, and that was about 1.8 million Naira. We then got additional licenses for ten more team members, which brought us to twenty-five team members, and that was about 1.3 million Naira as well. The pricing is not cheap, especially for a startup like ours. However, I think that for the cost-saving, especially around security, the value as against the cost is fair. I think the value outweighs the cost.
What about the implementation team?
We have been getting the license from a third party called Aricent Solution in Lagos State. For the solution itself and for the deployment, it is on a private cloud with the third-party vendor.
What was our ROI?
There is a return on investment with Sophos Central. I cannot say exactly how much time is saved, but time is definitely saved because you are assured that you do not have to worry about checking for security. We have been worried about cyber theft and cyber attacks. For fewer employees, in fact, we have not had cause to employ any cyber analyst. We did not even employ any cybersecurity analyst. That is actually saving us the overhead cost of having that additional employment.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for Sophos Central shows that it is expensive. However, when you look at it holistically, I think it is still fair. We got licenses at first for fifteen team members, and that was about 1.8 million Naira. We then got additional licenses for ten more team members, which brought us to twenty-five team members, and that was about 1.3 million Naira as well. The pricing is not cheap, especially for a startup like ours. However, I think that for the cost-saving, especially around security, the value as against the cost is fair. I think the value outweighs the cost.
Which other solutions did I evaluate?
Before choosing Sophos Central, we wanted to pursue ISO 27001 certification at that time, and that was when they told us that we needed to start using a security software.
What other advice do I have?
My advice for others looking into using Sophos Central is that if you are a startup and you do not have the cost to build a cybersecurity team, I think Sophos Central is your best option. Having a dashboard where you can actually see every possible attack, threat, attempt, or malware attempt on the devices of your team members basically solves your security issue. I would rate this review a nine out of ten.
Anup A.
Powerful security management with fantastic RCA, but watch out for system resource usage
Reviewed on Jun 13, 2026
Review provided by G2
What do you like best about the product?
Th biggest selling point for our team is heaving the firewall (XGS series)and our endpoint protection living in the exact same dashboard. The "Synchronized Security" Feature specifically the security heartbeat is incredibly useful If an endpoint gets infected or starts showing suspicious behavior, it automatically drops its heartbeat, and the Sophos firewall Isolates it from the rest of the VLAN instantly without me having to LOG in manually after hours to kill the switch port. From an Admin perspective managing global policies is straightforward. If i need to create a peripheral control policy to block rogue USB drives or add a global threat exclusion for a quirky legacy line-of-business app I can push it out to the entire tenant in a few clicks. tamper protection is also robust: they know IT can't easily kill the service or tamper with the registry to disable it.
What do you dislike about the product?
My main complaint is the resource footprint of the endpoint agent on our older endpoint if you have users running older laptops or developer machines doing heavy compiles, they will absolutely notice a slowdown during a full scheduled scan when or when Sophos is processing deep learning malware analysis on localized files. CPU spikes are a common helpdesk ticket item for us on those specific machines.
What problems is the product solving and how is that benefiting you?
We use it to centralize security operation across our corporate office and our fully remote workspace before migration to Sophos central we were managing a disjointed stack one vendor for antivirus another for the firewall and a separate tool for full disk encryption keys.
Sophos central allowed us to consolidate Everything now when a remote user loses their BitLocker PIN, they don't lock themselves out forever the helpdesk can grab the recovery key straight from the Central console in seconds it has significantly streamlined our incident response times and stopped us from wasting hours trying to correlate separate logs across three different security platforms during a suspected event.