Cybersecurity as a Service for AWS logo

    Cybersecurity as a Service for AWS

    Sold by
    Sophos Cybersecurity as a Service combines world class products, tools, services, and expertise into one holistic solution.

    Ratings and reviews

    4.7
    507 ratings
    86%
    12%
    1%
    1%
    0%
    2 AWS reviews
    |
    505 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (507)
    Mansukh Bhesania

    Centralized threat response has strengthened remote protection for complex on‑premise environments

    Reviewed on Jul 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Sophos Cybersecurity as a Service is an on-premise solution. This is the first implementation of Sophos Cybersecurity as a Service with Citrix, and otherwise we are going with the Sophos XDR solution instead of a third party, as we are currently using Trend Micro, which is not working properly with Sophos.

    The thin client is not compatible with the Sophos firewall, and we found the fault in the Sophos solution. They have now released a light version of the XDR, and that type of activity is what we are coordinating in the backend.

    What is most valuable?

    The best feature of Sophos Cybersecurity as a Service is the XDR, along with remote management, which is particularly beneficial for small and medium environments.

    We and our customers use the automated threat response feature, which is included but requires a license. For example, one of the banks using XDR provided by Sophos is very happy, and we conduct remote sessions with XDR, ensuring our involvement is minimal, leading to customer satisfaction.

    I assess the value of deep visibility into network activities provided by Sophos Cybersecurity as a Service as good enough, especially regarding firewall and wireless aspects, with new switching features introduced that are acceptable.

    What needs improvement?

    There are a lot of technical issues with the implementation of Sophos Cybersecurity as a Service, particularly because we are currently implementing the XG series, where Citrix is the endpoint, leading to a lot of confusion. The XDR client is not working, so we are taking time for research and development, and they are providing us with whatever solutions from the company, even a lighter version of the XDR for this particular Citrix thin client.

    Product-wise, improvements need to be made in Sophos Cybersecurity as a Service, particularly because they do not have a testing lab for the implemented customer environments. We have implemented a large environment where a number of problems occur, and they are unable to provide on-the-spot solutions, often taking five to ten days to set up a lab at the customer's premises to identify solutions.

    For how long have I used the solution?

    I have been working with Sophos Cybersecurity as a Service since 1994, almost 30 years, starting with Astaro, which is the original security company that Sophos has taken over, and nowadays Sophos is the product.

    What do I think about the stability of the solution?

    I do not face many challenges, but we did encounter ransomware attacks at two to three locations, and Sophos Cybersecurity as a Service protected us immediately, within three to four seconds, providing alerts about ransomware threats, leading to automatic disconnections when necessary.

    What do I think about the scalability of the solution?

    Cloud-based operation is nowadays required for centralized management since all servers and resources are being kept in the cloud, and future developments must trend towards cloud solutions.

    However, we are not promoting cloud solutions to our customers, as our business remains focused on on-premise setups.

    How are customer service and support?

    I rate the technical support of Sophos Cybersecurity as a Service an eight compared to Juniper, also an eight, but primarily due to timing issues. They are technically strong, but their resources are problematic, and timing is also an issue as nowadays people require solutions on-demand.

    What about the implementation team?

    I am also a partner with Juniper, Cisco, and everything, because I am a system integrator, so I have to maintain relationships with all OEMs.

    What was our ROI?

    There is definitely a return on investment when using Sophos products; it all comes down to how deployment is managed, as policy is crucial. Initiating a deny everything approach before gradually allowing access is the best way to ensure security.

    What's my experience with pricing, setup cost, and licensing?

    The pricing of Sophos Cybersecurity as a Service is approximately 60 percent that of Cisco, as Cisco requires a greater number of licenses to meet its requirements, while Sophos and Juniper, along with Fortinet, offer lower prices. In negotiations, Fortinet and Sophos have almost equal prices, allowing for competitiveness in order acquisition at the negotiation table, leading to price reductions.

    What other advice do I have?

    This is the first implementation of Sophos Cybersecurity as a Service with Citrix, and otherwise we are going with the Sophos XDR solution instead of a third party, as we are currently using Trend Micro, which is not working properly with Sophos. The thin client is not compatible with the Sophos firewall, and we found the fault in the Sophos solution. They have now released a light version of the XDR, and that type of activity is what we are coordinating in the backend.

    I do not fully understand the metric used to measure the effectiveness of Sophos threat intelligence capabilities. However, we do have one scheme, which involves dedicating manpower for customer support. For larger customers, we assign dedicated personnel who understand the ins and outs of their needs, which helps streamline processes without needing repeated explanations.

    Rizwan Ikram

    Security has blocked all unauthorized uploads and email sharing in our developer environments

    Reviewed on Jul 17, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We work with Sophos XG Firewall including Sophos Agent for Servers. Most of my customers are maintaining developer environments and want to secure their developer environments by preventing uploading and use of phishing websites and outbound emails to public email services like Hotmail and Gmail. They want to secure their environment to block users from sending emails to public email addresses and prevent uploads with this security measure.

    What is most valuable?

    Sophos Cybersecurity as a Service offers very tight security and compliance. If anybody applies Sophos at their premises, the environment is completely secure and sound.

    The biggest advantage I achieved with Sophos Cybersecurity as a Service is the upload block. I never achieved it with other products, and Sophos completely delivered on this. We completely block uploads from any website and anywhere in the environment. No one can upload without our permission.

    There are many reasons why Sophos is better in comparison with other solutions, but our focus was blocking uploads. The most important thing in our environment is blocking uploads, and we achieved this target with Sophos. Sophos Cybersecurity as a Service also protects against malicious websites and performs antivirus scanning and blocks all threats that any XG firewall is supposed to achieve.

    The automated response is excellent because the portal handles almost everything on a single dashboard, and we can manage and control everything automatically. This is really systematic and automated. It is absolutely highly scalable.

    What needs improvement?

    I don't think there is anything to improve in my experience because I found Sophos already maintains regular updates and provides support portals in proper order. I don't find anything to recommend for improvement.

    For how long have I used the solution?

    I have been working with Sophos Cybersecurity as a Service for around five years.

    What do I think about the stability of the solution?

    It is 99% stable.

    How are customer service and support?

    The support I experienced is extremely good. I always found the support persons very friendly and helpful, and they always try to fix the service at any cost and are available anytime.

    Which solution did I use previously and why did I switch?

    Before using Sophos Cybersecurity as a Service, we tried Cisco and other firewalls, but when we experienced Sophos, it really did what we wanted to achieve.

    Previously we were using AWS, but recently we have moved to a hosting service. Both are compatible with using Sophos Cybersecurity as a Service.

    How was the initial setup?

    I found the installation is very simple. I just need to run the installer and it completes in one go by itself. There is no complex installation required.

    What about the implementation team?

    Our service provider in Canada is the company NE Format. The representative is Saif Khan. He provides all Sophos Cybersecurity as a Service-related services to us. He controls many things on his end, including the portal management of Sophos Cybersecurity as a Service, and I just look after the user environment. The provider manages it at their end, and Mr. Saif Khan from NE Format in Canada handles the implementation.

    What's my experience with pricing, setup cost, and licensing?

    For the Pakistan region, this is very expensive. Not anyone can afford it. It is expensive, but it is worthwhile for paying the investment. However, it is not affordable for everyone. Only very high and large enterprises can afford it.

    Which other solutions did I evaluate?

    I never bought any service of Sophos Cybersecurity as a Service from anywhere else because we bought it from a reseller located in Canada who handles everything for us.

    What other advice do I have?

    Users never prefer to be blocked from performing activities. If you block users from doing activities, they do not prefer it. That is a security requirement, but as a technical provider, I understand this is important to do. We are using a product that offers EDR as well. I rate this review as a 10 out of 10.

    Vishal Khedekar

    Deep threat visibility has transformed how my team detects attacks and manages endpoint security

    Reviewed on Jul 14, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I spent a couple of hours deploying Sophos Cybersecurity as a Service. Since we were already working on several firewall technologies and the platform is user friendly, I managed to complete the implementation quickly. I took part in the deployment with my team, as I was performing implementation work in earlier days.

    What is most valuable?

    The best features in Sophos Cybersecurity as a Service for me personally are the MDR service they are offering nowadays, which is also very helpful. Managed Detection and Response for endpoints helps customers manage their threats on several endpoints, so that was beneficial.

    I assess the value of deep visibility into my network activities provided by Sophos Cybersecurity as a Service as quite good. Deep visibility on endpoints through EDR means we get good insight from the EDR dashboard regarding where the threats are, what changes are happening, and how it is preventing attacks. The visibility shows how the attacker is trying to target files if they want to exploit them, so that was valuable.

    Enhanced Threat Hunting and Forensics help my organization address cyberattacks. I found several scripts that were running and which were blocked by the EDR services and the rules we had set. This helped us find out and reach the root cause or try to find the infected part, which helped us significantly because of the visibility aspect, allowing us to track it when otherwise it would have been impossible to do so in an antivirus scenario.

    What needs improvement?

    The disadvantages of Sophos Cybersecurity as a Service include that the support, specifically after-sales support, needs to be improved. Sometimes when I log a call in support, it takes time to get the engineer for critical issues. For L1 and L2 support, we can manage, but for critical issues, we need immediate support. They could add some SKUs for critical support so that for any production downtime, an L3 resource should be available within a fifteen-minute to half-hour time range.

    For how long have I used the solution?

    I have been familiar with Sophos Cybersecurity as a Service since it was Cyberoam, and I have been working with it for almost ten years or more.

    How was the initial setup?

    There are no difficulties or challenges with the implementation of Sophos Cybersecurity as a Service. It is very easy, and the GUI is also very user friendly.

    What about the implementation team?

    In the implementation of Sophos Cybersecurity as a Service on my side, I have a team of twelve people, consisting only of support engineers and administrators.

    What's my experience with pricing, setup cost, and licensing?

    Regarding the licensing cost of Sophos Cybersecurity as a Service, I find it reasonable, as even SMB customers can also afford it.

    What other advice do I have?

    To measure the effectiveness of Sophos threat intelligence capabilities, I rate it a nine. My overall review rating for Sophos Cybersecurity as a Service is nine.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Saad Qaiser

    Sophisticated monitoring has protected critical services and supports ransomware resilience

    Reviewed on Jul 02, 2026
    Review from a verified AWS customer

    What is our primary use case?

    We are working with Trend Micro as a competitor, and it is also a great experience. I am using Trend AI Vision One. I know the Secureworks product for XDR and EDR; I know they acquired Secureworks. We do not have any customers of Secureworks yet, but we are trying to pitch it and develop some business with Secureworks as well. We are working with Sophos Cybersecurity as a Service.

    What is most valuable?

    We started working with Sophos Cybersecurity as a Service last year and we have some customers for Sophos in the resolution which is Cybersecurity as a Service. Sophos teams work with these customers to secure them and integrate them in case of any issues, and they are really satisfied with the product; it is a good one.

    Customers basically use Sophos Cybersecurity as a Service against ransomware attacks, especially when they are not in their operational hours such as during the night, on weekends, or holidays when their team is not directly available in the premises to secure something. In that case, they need these services so that someone reliable is watching their network to avoid any ransomware attacks.

    There are multiple benefits of Sophos Cybersecurity as a Service. The biggest one is that it will save any stoppage of services; for example, if there is a hospital environment that faces any ransomware attack, it may stop their operations. This solution helps them to maintain their uptime and ensure business continuity 100%, which is a very good thing. Secondly, it helps avoid financial losses; once the data of the company is encrypted due to a ransomware attack, they obviously face financial losses and may be asked for bigger ransom amounts. Sometimes a company has to pay them; to avoid these issues, there is no surety of getting data back even after paying the ransom. Additionally, there are various kinds of attacks nowadays, such as CNC attacks, where someone may be using their resources for bad purposes; these services stop any unethical behavior, ultimately helping the customer to increase their productivity and financial growth.

    The automated threat response feature of Sophos Cybersecurity as a Service is definitely very helpful.

    Most of the companies do not have cybersecurity experts, particularly mid-level or small enterprises; they cannot afford cybersecurity experts or SOC teams. With this product, they do not need to go through extensive learning in cybersecurity; the automatic mitigation helps them to focus on their work and avoid problematic behaviors. There are some IT staff who do not have any security background, which means they do not need to get involved when reliable products are handling this.

    Network visibility with Sophos Cybersecurity as a Service is positive and brings benefits; they are connected with your network, providing a larger view and a dedicated team who understands all the ins and outs. For instance, some equipment such as PBX systems or CCTV cameras in the network typically are not viewed as potential threats, but these services help monitor even those, ensuring protection.

    Features such as threat hunting and forensics are definitely effective for cybersecurity; for example, we might not know if our management team addresses, such as our CFO or CEO email addresses, are being misused on the dark web for phishing attacks. These solutions help us to see any misuse of our resources, effectively preventing such issues.

    What needs improvement?

    I would suggest improvements such as integrating a third-party platform or making the products mature enough for customers who do not use Sophos switches or similar hardware, allowing security integration. If a firewall or another security solution could learn logs from attacks originating from switches or CCTV systems, it should be accessible enough for a regular network engineer or security engineer to understand and handle.

    What do I think about the stability of the solution?

    Sophos Cybersecurity as a Service does not have any glitches; it is very stable.

    What do I think about the scalability of the solution?

    It is very scalable without any limitations.

    How are customer service and support?

    The customer support from Sophos is great; they are very supportive and available 24/7. It depends upon the region, but they are accessible whenever we approach them, and they engage their development team and a global escalation team when needed, providing an exceptionally strong support system.

    Which solution did I use previously and why did I switch?

    We work with other products as well, but we are the Platinum Partner of Sophos in Pakistan.

    How was the initial setup?

    It is very easy to install, and I give full marks for the easiness of the solution.

    What was our ROI?

    I believe it is more than 30% ROI. While it is hard to quantify exactly, when you consider data theft and customers protecting billion-dollar data assets, the price of the solution is only about $4,000 to $5,000 per year. The ROI provided by these solutions is more than 100%, making it a very economical choice, thus worth buying.

    What's my experience with pricing, setup cost, and licensing?

    The price for Sophos is somewhere in the middle; it is a good price. They offer good discounts for customers and have competitive pricing when compared to their competition such as Trend Micro and other high-end products. It is very aggressive pricing.

    Which other solutions did I evaluate?

    Sophos Cybersecurity as a Service utilizes its own cloud, which may have integrations with other services, but they provide their cloud for customer console access.

    What other advice do I have?

    Centralized management is very important for cloud-based operations because most companies have multiple branches and offices in different cities. It really helps us manage, especially if a customer has 300 firewalls and 2000 endpoints spread across various offices; it becomes much easier to manage everything centrally. If they need to push a policy for internet validation, all their endpoints or users can be managed from a single interface, which is very effective.

    It is not exactly a disadvantage, but it does impact the company financially. These are services that the company must purchase, whether from Sophos or other providers, which impacts their finances. Thirty or forty years ago, without internet or network connectivity, companies did not have to worry about data theft and could focus on operations. Now, no solution can guarantee 100% security. Unless a company invests in a firewall for network security, endpoint protection, network detection and response, MDR, security-as-services, and patch management, their finances are heavily drained due to these cybersecurity solutions, and this burden will only increase over time. Other than that, I do not find any disadvantages; the products are very good and competitive.

    I give this solution a rating of 9 out of 10. It is worth buying and definitely provides ROI.

    SudarsanRajamani

    Integrated defenses have enabled rapid ransomware prevention and streamlined incident response

    Reviewed on Jul 01, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Sophos Cybersecurity as a Service is to stop ransomware attacks. I work for a manufacturing company with a total of 2,500 employees across 15 locations, Microsoft 365, VMware servers, Windows laptops, OT environments, and a hybrid workspace. An employee received a phishing email with the subject around invoice payment pending, and the attachment contained malicious macros. The user enabled the macro, and PowerShell downloaded ransomware. Sophos' email security helped beyond what is expected, as it checks the SPF, DKIM, DMARC, sandboxing, reputation, and AI detection. Suppose this is a zero-day attack; the email bypasses the filtering. Overall, Sophos XDR automatically correlates all the logs from the endpoint, the firewall, the identity email, and the cloud, allowing analysts to immediately see patient zero, the download file, PowerShell command, network connections, registry changes, and lateral movement attempts. Everything appears on a single investigation timeline.

    A little more on the use case: Intercept X detects the malicious behavior, and CryptoGuard stops the encryption and restores the modified files. XDR correlates telemetry, MDR validates the threat, and performs 24/7 response, while the firewall blocks the attacker's communication.

    What is most valuable?

    The best features Sophos Cybersecurity as a Service offers is that instead of treating endpoint, firewall, email, and mobile security as separate products, Sophos enables them to communicate automatically through Security Heartbeat. An example would be when an endpoint becomes infected; Sophos Intercept X causes the firewall to isolate the device, block the malicious IP address, and prevent lateral movement automatically, reducing response time from minutes to seconds.

    Automatic communication between Sophos products helps my team day-to-day by significantly reducing manual effort and speeding up incident response. Instead of analysts having to investigate alerts across multiple consoles, Sophos shares threat intelligence automatically between endpoints, firewalls, email security, and the management platform. This means that when one product detects a threat, the others immediately take coordinated action.

    Sophos Cybersecurity as a Service has positively impacted my organization by simplifying cybersecurity operations while improving our ability to detect and respond to threats. Its integrated platform reduces the need to manage multiple disconnected tools, allowing our security teams to work more efficiently. Features such as automated threat correlation, endpoint isolation, and managed detections and response help reduce incident response time and minimize the impact of cyberattacks. For organizations with limited cybersecurity resources, Sophos also provides enterprise-wide protection through its MDR services without requiring a large in-house SOC.

    What needs improvement?

    Sophos Cybersecurity as a Service is a mature platform with strong endpoint protection, MDR, and integrated security capabilities. However, areas exist where it can continue to evolve. I see opportunities around AI-driven automation, cloud-native security, identity protection, third-party integrations, executive reporting, and proactive risk management.

    Sophos already provides a strong integrated security platform with MDR, XDR, endpoint protection, and firewall integration. The next evolution is to become even more predictive and autonomous. I would like to see deeper AI-driven response automation, enhanced cloud and identity threat detection, broader third-party integrations, executive-focused risk dashboards, automated compliance mapping, and continuous external attack surface management. These enhancements would not only improve security outcomes but also help CISOs better demonstrate cyber risk reduction and business value.

    To make it a ten, I would like to see cloud-native workload protection and identity security deeper compared with some specialized competitors. Some enterprises with highly customized SOCs may prefer broader native integration and automation available from platforms such as Microsoft, Palo Alto Networks, or CrowdStrike. Further enhancement in executive reporting and exposure management capabilities is also needed.

    For how long have I used the solution?

    I have been working in my current field for 20 years.

    What do I think about the stability of the solution?

    Sophos Cybersecurity as a Service is stable.

    What do I think about the scalability of the solution?

    I would rate Sophos Cybersecurity as a Service scalability at 9 out of 10. It's designed to scale from small businesses to large enterprises without requiring significant changes to the underlying platform.

    How are customer service and support?

    Customer support is really good. I would rate the customer support a 10 out of 10.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution.

    How was the initial setup?

    Overall, my experience with pricing, setup cost, and licensing has been positive. I would rate the pricing setup to be 8 out of 10. Sophos offers competitive pricing, especially for organizations looking for an integrated security platform rather than purchasing multiple standalone products. The licensing model is generally straightforward, with flexible subscription options based on the organization's requirements. The initial setup costs are reasonable, particularly for cloud-managed deployments through Sophos Central. Overall total cost of ownership can be lowered because endpoint, firewall, email security, and MDR services are managed through a unified platform.

    What was our ROI?

    I have seen a positive return on investment, primarily through improved operational efficiency and faster incident response rather than reducing headcount. Sophos centralized management, automation, and MDR capabilities allow my security team to spend less time on repetitive tasks and more time on higher-value security activities. One example was a phishing incident that resulted in malware execution on a user laptop. Sophos detected the suspicious behavior, isolated the endpoint automatically, and prevented lateral movement. Because the investigation data was already correlated in Sophos Central, the analyst completed the investigation in 20 minutes, whereas previously, it could have taken close to an hour by manually reviewing multiple security tools. The incident was contained to a single endpoint, and the user experienced minimal disruption.

    Which other solutions did I evaluate?

    Before choosing Sophos Cybersecurity as a Service, I evaluated other options, including Microsoft Sentinel.

    What other advice do I have?

    My advice to others looking into using Sophos Cybersecurity as a Service would be to first understand their organization's security maturity, business requirements, and existing technology stack. Sophos Cybersecurity as a Service delivers the most value when you leverage it as an integrated platform rather than deploying individual products in isolation. If you're looking for centralized management, strong ransomware protection, 24/7 managed detection and response, and reduced operational complexity, it's a compelling choice. I would also recommend planning the deployment carefully, defining security policies upfront, and investing time in tuning the alerts during the initial rollout to maximize effectiveness and minimize unnecessary noise. I would rate this solution an 8 out of 10.

    Nicholas Da Costa

    AI-driven monitoring has freed our team to focus on core work and has strengthened breach response

    Reviewed on Jun 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Sophos Cybersecurity as a Service serves as our main solution to maintain a 24/7/365 security operations center that oversees our networks, computers, and servers, ensuring that if a breach occurs, the team will remedy it and eradicate the intruder.

    A specific example of how Sophos Cybersecurity as a Service helped my team occurred three weeks ago when one of our employees clicked on a phishing link. Sophos was able to stop the employee, halt the attack, reset the user password, block all activity, and effectively counteract the situation due to their integration with M365.

    What is most valuable?

    Sophos Cybersecurity as a Service offers several valuable features, including weekly and monthly reports, direct communication about incidents, swift responses typically within two minutes for cases or questions, security assessments of our environment, and security posturing of our environment.

    Among these features, my team relies on the reports most significantly because they provide important insights into what is happening on the machines and the network on a weekly basis.

    Sophos Cybersecurity as a Service has positively impacted our organization by providing management with confidence, knowing we have one of the best MDR services overseeing our entire ecosystem. We also benefit from a breach protection warranty that can provide up to one million US dollars.

    This service has allowed my team to work more efficiently on other tasks rather than constantly monitoring every single notification, report, or incident that comes in, as the Sophos team investigates these on our behalf.

    What needs improvement?

    Currently there are not any major upgrades necessary, but the ease of use of reports could probably be enhanced. I would suggest making the reports easier to understand.

    For how long have I used the solution?

    I have been using Sophos Cybersecurity as a Service for four years.

    What do I think about the stability of the solution?

    Sophos Cybersecurity as a Service is very stable, and as of today, we have had no issues.

    What do I think about the scalability of the solution?

    Its scalability is remarkable, allowing for very easy scaling up or down without any complexity. It is one of the easiest solutions we have encountered.

    How are customer service and support?

    Customer support is fantastic, and we have never had any issues. When we create a ticket in the Sophos portal, they respond quickly based on the tier of urgency.

    Which solution did I use previously and why did I switch?

    We previously used Fortinet before switching to Sophos Cybersecurity as a Service. The reasons for the switch include Fortinet's increase in costs and the complexity involved in licensing and additional storage required for features that Sophos offers.

    How was the initial setup?

    Pricing for Sophos Cybersecurity as a Service was excellent, and the setup was extremely easy.

    What was our ROI?

    I have seen a return on investment primarily through time saved. My team can focus on core functions rather than monitoring reports or alerts that come into the Sophos Central portal daily.

    Which other solutions did I evaluate?

    Before choosing Sophos Cybersecurity as a Service, we did not evaluate other options. We went with Sophos because we heard positive feedback from others and conducted our own due diligence.

    What other advice do I have?

    Sophos Cybersecurity as a Service's AI capabilities are impressive, as I believe its governance and security are very strong. The AI is highly intuitive, providing a lot of insights into case details and threats, breaking down complex information into layman's terms for our management to understand easily.

    So far, the accuracy and reliability of the AI output have been spot on, and we have seen no real issues with it to date.

    My advice to others considering Sophos Cybersecurity as a Service is to conduct a proof of concept to see what it offers. Once you try it, you will realize how easy it is to manage, how intuitive it is, and the wealth of information available from it.

    In conclusion, I believe Sophos Cybersecurity as a Service is an excellent solution that simplifies cybersecurity tasks, allowing my team to focus on essential areas. I rate this solution a nine out of ten.

    Evren Kürşat .

    Sophos MDR Delivers 24/7 Monitoring and Rapid Response with Actionable Alerts

    Reviewed on Jun 24, 2026
    Review provided by G2
    What do you like best about the product?
    Sophos MDR is the 24/7 threat monitoring and rapid response capabilities provided by the security team. It significantly reduces the workload on our internal IT team while improving our overall security posture. The visibility and actionable alerts help us respond to incidents more quickly and effectively.
    What do you dislike about the product?
    Sophos MDR is that it does not offer Turkish language support, which can make management and communication less convenient for our team.
    What problems is the product solving and how is that benefiting you?
    Sophos MDR helps us by providing 24/7 monitoring, threat detection, and incident response, which significantly reduces the workload on our internal IT security team. It improves our ability to detect and respond to threats quickly, even outside business hours. As a result, we gain stronger security coverage, faster incident handling, and better overall risk reduction.
    D Alvarado

    Automated threat response has reduced breaches and frees our team to focus on strategic work

    Reviewed on Jun 20, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Sophos Cybersecurity as a Service protects our cloud workloads and endpoints from ransomware and phishing. The managed service constantly monitors for threats so we don't need a large in-house security team. It is especially useful during off-hours, since alerts and response are handled automatically, keeping our environment secure without gaps.

    What is most valuable?

    The best feature about Sophos Cybersecurity as a Service is threat response automation because suspicious activities are contained quickly without waiting for manual intervention, which reduces damage.

    Threat response automation in Sophos Cybersecurity as a Service fits into our daily operation by cutting down reaction time. When suspicious activity is detected, the system automatically isolates affected endpoints, blocks malicious traffic, and alerts the managed team. For us, that means incidents are contained before they escalate, and we don't lose hours manually chasing threats.

    It has impacted our organization very positively. The biggest improvement has been efficiency. The managed team handles alerts and incidents so our IT staff can focus on projects instead of constant monitoring. We have also seen cost savings by not needing to expand our in-house security team. Most importantly, resilience has improved. Ransomware attempts were contained quickly, giving us confidence that threats will not disrupt operations.

    I have very concrete outcomes with Sophos Cybersecurity as a Service. For example, automated threat response saved our team an estimated ten to fifteen hours per month that they used to spend chasing alerts manually. By relying on the managed service instead of expanding our in-house staff, we avoided hiring at least one additional security analyst, resulting in cost savings. During the phishing incidents, containment was complete in under an hour, compared to the full day it used to take us before Sophos Cybersecurity as a Service.

    What needs improvement?

    There are a few areas where Sophos Cybersecurity as a Service could be improved. One area is dashboard usability, another is alert tuning, and another is reporting customization.

    Alert tuning would help us focus on critical issues faster, reducing wasted time on minor notifications. More flexible report customizations would let us align outputs directly with compliance frameworks, making audits smoother.

    For how long have I used the solution?

    I rate my use of Sophos Cybersecurity as a Service as a nine.

    Which solution did I use previously and why did I switch?

    I used Check Point Security Infinity Portal in the past. However, that solution is very high cost, and I needed to switch to Sophos Cybersecurity as a Service because it is better for me.

    What other advice do I have?

    We had a phishing attack attempt where several employees clicked a suspicious link. Sophos Cybersecurity as a Service immediately flagged the activity, isolated the affected endpoints, and blocked further spread. The managed team notified us quickly, and within the same day, everything was contained and cleaned, saving us from what could have been a major breach.

    Sophos Cybersecurity as a Service really helps with day-to-day peace of mind. During patch cycles when vulnerabilities are at their highest, the managed service keeps monitoring and blocking exploit attempts automatically.

    One small feature I would add is the centralized dashboard. Having all alerts, reports, and threat actions in one place makes daily monitoring much easier. I also appreciated the scalability. For example, new users or workloads inherit policies instantly.

    Sophos Cybersecurity as a Service uses AI with strong governance and security controls, combining deep learning models with human oversight to ensure threats are detected, contained, and reported in a transparent, auditable way. This balance of automation and accountability makes its AI outputs trustworthy for compliance-driven organizations.

    It delivers highly accurate and reliable AI outputs by combining deep learning models with human review, minimizing false positives while ensuring rapid detection of real threats. Overall, I find Sophos Cybersecurity as a Service to be very great and very fast. I rate the overall product experience as a nine.

    Leo Diaz

    Centralized monitoring has transformed incident response and now protects endpoints in real time

    Reviewed on Jun 19, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for Sophos Cybersecurity as a Service is endpoint and network protection, ensuring that laptops, servers, and other devices and cloud workloads are monitored with Sophos Cybersecurity as a Service. I centralized threat detections and response, which is similar to a SOC.

    A quick example of how I use Sophos Cybersecurity as a Service for endpoint and network protection in my day-to-day work occurred last week when Sophos Cybersecurity as a Service flagged unusual outbound traffic from one endpoint, and the automatic response isolated the device from the network so the suspicious activity did not spread. Peers often mention this kind of real-time containment as a daily benefit of using the service.

    What is most valuable?

    The best features that Sophos Cybersecurity as a Service offers include centralized threat monitoring and automatic response, which cut down manual efforts, along with strong endpoint protection and phishing detection that peers consistently highlight.

    Centralized monitoring and automatic response have made things much easier for me and my team compared to what we used before. Previously, my team had to manually sift through logs and chase alerts across different tools, which was time-consuming and often delayed our reaction. Now with Sophos Cybersecurity as a Service, it consolidates everything in one dashboard and automatically isolates suspicious endpoints.

    Sophos Cybersecurity as a Service has impacted my organization positively by streamlining how we handle threats and reducing downtime. Before, my teams spent a lot of time chasing alerts across different systems. Now, with the centralized monitoring and automatic response, incidents are contained quickly and consistently.

    What needs improvement?

    For improvement, I suggest dashboard flexibility, more customizable views, and reporting for different teams, along with alert precision for finer tuning to reduce false positives and noise.

    For how long have I used the solution?

    I have been using Sophos Cybersecurity as a Service for around two years.

    What do I think about the stability of the solution?

    Sophos Cybersecurity as a Service is very stable.

    What do I think about the scalability of the solution?

    Scalability of Sophos Cybersecurity as a Service is very good, with no problems because the cybersecurity is in the cloud.

    How are customer service and support?

    For me, customer support has been very great.

    Which solution did I use previously and why did I switch?

    Previously, I used Check Point as a different solution.

    What was our ROI?

    I think the return on investment with Sophos Cybersecurity as a Service is primarily about the time saved for my team.

    Since using Sophos Cybersecurity as a Service, I have seen measurable improvements such as faster incident response, fewer successful attacks, and significant efficiency gains for IT teams, with independent evaluations showing near-perfect detection rates and response times under two minutes, translating directly into saved hours and reduced risk.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing has been great, though I do not understand the licensing very well.

    Which other solutions did I evaluate?

    Before choosing Sophos Cybersecurity as a Service, I did not evaluate other options.

    What other advice do I have?

    I would add that Sophos Cybersecurity as a Service has become part of my daily routine by simplifying endpoint checks and network monitoring, with alerts that are clear and actionable so I do not waste time chasing noise.

    Regarding Sophos Cybersecurity as a Service's AI capabilities, I find it combines advanced AI with strict governance and layered security controls, ensuring both reliable detection and response and responsible use of automation.

    Accuracy and reliability of Sophos Cybersecurity as a Service AI output is generally impressive, with independent evaluations showing high detection rates with threats identified quickly and consistently, which reduces the number of incidents that reach IT teams.

    My advice for others looking into using Sophos Cybersecurity as a Service would be to evaluate automation, plan integration, and customize alerts. I rate this product an 8 overall.

    Tonmoy Roy

    Advanced threat detection has strengthened our incident response and protected client operations

    Reviewed on Jun 06, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Sophos Cybersecurity as a Service is our main solution to ensure secure operations as we build and connect more clients successfully, while also addressing our specific requirements. We have been using Sophos Cybersecurity as a Service, which provides many functionalities, including a taskbar that shows resource consumption from PCs, leading to good customer feedback. When Sophos resources are low, customers purchase more, recognizing it as a useful product.

    We use mobile device management (MDM) services, and customer feedback indicates that it works very well for their custom work apps, benefiting both us and them.

    Sophos Cybersecurity as a Service is deployed in our organization for cloud security purposes. Currently, we are not utilizing any specific cloud provider; instead, we are using Sophos endpoint security.

    What is most valuable?

    The best feature that Sophos Cybersecurity as a Service offers is Sophos XDR.

    Sophos XDR stands out as the best feature for us and our clients because of its ability to investigate issues like a MITRE attack, conduct live discovery, and perform root cause analysis to understand how attackers attempt to access PCs.

    Sophos Cybersecurity as a Service has positively impacted our organization by being very beneficial for our business and serving as a valuable income source.

    The AI capabilities within Sophos Cybersecurity as a Service are very good, as it effectively detects incidents and tracks how issues occurred, providing a high level of security for banking and other sectors.

    Sophos AI proves to be very capable for us in terms of input and output; when it detects any anomaly or file path, we are able to investigate it utilizing Sophos AI, which is very useful for us.

    What needs improvement?

    Sophos Cybersecurity as a Service is continuously consuming more resources, which leads to slower PC performance, so reducing resource consumption would be better for both Sophos products and our sales.

    Improving the resource consumption aspect would enhance Sophos Cybersecurity as a Service market presence.

    If Sophos antivirus could reduce its resource consumption during scheduled scans, it would help address the PC slowness issue.

    For how long have I used the solution?

    We have been using Sophos Cybersecurity as a Service for at least 10 years since our company was established in 2016, and we are still using it currently.

    What do I think about the stability of the solution?

    Sophos Cybersecurity as a Service is stable.

    What do I think about the scalability of the solution?

    The scalability of Sophos Cybersecurity as a Service is really great.

    How are customer service and support?

    Our customer support is excellent, with 24/7 availability, handling at least 15 calls per week to solve client issues.

    Which solution did I use previously and why did I switch?

    We did not use a different solution before opting for Sophos Cybersecurity as a Service; we have always focused on Sophos along with options like Palo Alto, Cortex XDR, and CrowdStrike.

    What was our ROI?

    We experience a return on investment from using Sophos Cybersecurity as a Service; for example, when we pre-configure it during installations for devices, it proves to be working well and saves time. I cannot provide specific monetary metrics since this is handled by our product team.

    Which other solutions did I evaluate?

    We did not evaluate any other options before choosing Sophos Cybersecurity as a Service; our team has consistently used Sophos Cybersecurity engineering and has not switched to other services such as XDR or CrowdStrike.

    What other advice do I have?

    When advising others about using Sophos Cybersecurity as a Service, I emphasize that the main reason to choose Sophos Cybersecurity as a Service is its effective incident management; unlike other providers such as CrowdStrike, which have faced issues with server hacks and resource consumption, Sophos Cybersecurity as a Service has maintained a good reputation and is our best solution. I would rate this product a 9 overall.