Centralized firewall oversight has streamlined multi-branch security management and saved time
What is our primary use case?
My main use case for Sophos Central is to manage multiple firewall devices. We have multiple branches and each branch has a Sophos firewall, which I can manage centrally through Sophos Central. It helps us to create a rule and send it to all the firewalls at once.
Currently, I am using Sophos Central for monitoring purposes. I can monitor all firewalls in a single dashboard, which is the greatest thing in Sophos Central.
What is most valuable?
The best feature Sophos Central offers is the ability to manage multiple firewalls from a single dashboard.
Besides the single dashboard, I find it invaluable that I can create and apply policies through Sophos Central easily to all firewalls, which would not be possible if I had to connect each firewall one by one.
I can manage more than 50 devices from a single dashboard, which is the best feature currently.
Sophos Central has improved my organization because previously we had to manually monitor all firewalls and check logs one by one. Now I see everything in a single dashboard, which is very beneficial.
Using Sophos Central saves me so much time because checking logs for all firewalls one by one is very difficult. Here I check all logs on a single dashboard, which is very useful.
What needs improvement?
Currently, based on my knowledge and experience, Sophos Central is perfect. It might need updates if technology increases in the future.
Currently I do not want to suggest anything small or minor that could make my experience even smoother. If possible, a mobile app would be perfect; if it is available, I currently do not know about it.
I did not use or know about a mobile app currently, and if it is available, then it would be a ten out of ten for me. If anything happens, I can easily access it on mobile, which would be available at all times.
For how long have I used the solution?
In my current organization, I have been working for eight months.
What do I think about the stability of the solution?
We have not experienced any downtime or issues with Sophos Central; it has been stable for us.
What do I think about the scalability of the solution?
Currently, Sophos Central is a very perfect application as per my needs, and it solves a lot of our time issues.
How are customer service and support?
I reached out to customer support for Sophos Central and I had a very good support experience. I received instant support and remote assistance, and the Sophos team is very cooperative and helped me a lot.
Which solution did I use previously and why did I switch?
I did not use a different solution before Sophos Central; we were manually checking all firewalls without any other solution. Now we are using Sophos Central after receiving updates about it and implementing it.
How was the initial setup?
We did not evaluate other solutions.
What about the implementation team?
We are a partner or reseller with the vendor, suggesting to customers that if they have requirements about network security, they should consider using Sophos Central and Sophos firewalls for their multiple branches.
What was our ROI?
We see a return on investment with Sophos Central because it saves manpower and time. Previously we needed one employee for log management, but currently we manage everything on a single platform, making it very easy for us.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing for Sophos Central are not handled by me; that is handled by another team. Currently I do not know about that.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Sophos Central because all the firewalls we have are Sophos. We only evaluated Sophos Central.
What other advice do I have?
I advise those with multiple firewalls to use Sophos Central, as it is the best solution to manage all firewalls from a single dashboard, allowing you to check all logs easily.
Currently I am managing Sophos Central after receiving updates about it and implementing it. I would rate this solution an 8 out of 10.
Single Pane of Glass for Firewall and Antivirus Management
What do you like best about the product?
It gives us a single pane of glass for managing our firewalls and antivirus.
What do you dislike about the product?
Doing a deeper analysis of the firewall requires logging in directly to the firewall.
What problems is the product solving and how is that benefiting you?
It enables us to isolate threats before they become bigger issues.
Sophos Central Review
What do you like best about the product?
Sophos Central’s best strengths are its single, cloud‑native management console and tightly integrated AI‑driven protection (Intercept X, XDR, and MDR), which together deliver fast detection, coordinated response, and simple multi‑site administration—especially useful for distributed teams in Ahmedabad and India where centralized visibility and cloud hosting region choice matter.
What do you dislike about the product?
Cluttered navigation,Policy and alert workflows,Mitigation,Reporting and Visibility,Sometimes Sophos Central works slow, Sometime not able to download setup file from Sophos Central
What problems is the product solving and how is that benefiting you?
Sophos Central provides centralized management with coordinated detection and response, while also simplifying endpoint and firewall policy enforcement. As a result, it helps us detect incidents faster, reduce administrative overhead, and manage multiple sites more easily for teams in Ahmedabad and across India. Also their Support team available by 24x7
Clean, Single-Pane Control and Reporting for the Sophos Ecosystem
What do you like best about the product?
Enables a very clean oversight and configuration and control of the entire Sophos hardware and Software ecosystem. Also provides an easy reporting interface that helps with creating a report from"C" level reports to detailed technician styles reports.
What do you dislike about the product?
Only downside is the fact that in order to perform some admin level tasks requires a complex set of steps to get down far enough to perform those actions. Not always intuitive on how to get to where you need to be. If the interface could be customized in some fashion to make it any unneeded menus this would be an almost perfect single pane of glass interface.
What problems is the product solving and how is that benefiting you?
Full cybersecurity protection from end to end. Very easy hardware control as well. Everything from endpoints to access points and firewalls to MFP and ZTNA functions.
Easy-to-Use Portal, Reliable Endpoint Protection, and Responsive Support
What do you like best about the product?
The portal is easy to use, and each module is explained with clear, specific details. Integration with the endpoints is straightforward and accessible whenever needed.
Sophos installed on each endpoint receives updates at regular intervals, and the same status is visible in the admin console as well. Overall, the performance has been consistently reliable and never disappoints.
The pricing has gone down, which is a positive change, and it now meets all the expectations we had.
The vendor NetNxt, which we collaborate with for Sophos, has been helpful and responsive, and they answer whenever we need support.
I haven’t used the AI feature in the console yet, so I don’t have much to say about it.
The protection it gives for the endpoints is magnificent along with the tune able policies as per our needs.
What do you dislike about the product?
Few time there is a lag between the policy which are pushed to the endpoints and have to wait a long time to get it reflected.
IF this could be Improved that would be a great help.
What problems is the product solving and how is that benefiting you?
In our organization, it protects around 250+ endpoints from all kinds of malware and other threats and keeps the org data safe.
Unified, Cloud-Based Security Management with Real-Time Visibility
What do you like best about the product?
What I like most about Sophos Central is its unified management platform, which gives me full visibility and control across all security layers from a single console. It streamlines day-to-day operations by bringing firewall, endpoint, MDR, and email protection together in one place. The real-time alerts, synchronized security, and detailed reporting also make a noticeable difference in incident response and threat detection. On top of that, the cloud-based management makes it easy to deploy, manage policies, and troubleshoot remotely, which saves time and improves overall efficiency.
What do you dislike about the product?
Some advanced configurations require switching to the local firewall, and reporting/customization options could be improved. There can also be occasional sync delays between devices and Sophos Central.
What problems is the product solving and how is that benefiting you?
Sophos Central helps cut through the complexity of managing multiple security solutions by offering a single, unified platform for visibility and control. Rather than juggling separate tools for the firewall, endpoints, email, and threat detection, everything is centralized in one place, which reduces operational overhead and makes day-to-day management simpler. For me, this translates into faster incident response, better threat correlation through synchronized security, and quicker deployment of policies across the organization. Overall, it strengthens our security posture while saving time on routine operations and troubleshooting.
Centralized Dashboard with Real-Time Visibility and Effortless Policy Management
What do you like best about the product?
One of the best aspects is the single dashboard view, where I can monitor firewall, endpoint, and user security status in real time. I frequently use the Alerts & Events section to quickly identify critical threats and take immediate action.
The Device Management panel is very helpful for checking endpoint health, applying policies, and isolating compromised systems remotely. I also rely on the Threat Analysis Center to investigate malware detections and review root cause analysis.
The policy management feature allows me to modify web control, application control, and threat protection policies easily without logging into multiple systems. Additionally, the reporting section helps me generate scheduled reports for management and customers.
Overall, the centralized control, real-time visibility, easy policy deployment, and detailed reporting are the features I use the most, and they significantly reduce administrative workload.
What do you dislike about the product?
All good, full fill my all requirements.
What problems is the product solving and how is that benefiting you?
1. Unified Dashboard
2. Faster Threat Detection & Response
3. Better Reporting & Compliance
Centralized security management has simplified real-time protection and unified policy control
What is our primary use case?
As I am from a service-based company, my main use case for Sophos Central is that I am taking care of all of our security needs.
I use Sophos Central to block any website or application. For example, if I want to block WhatsApp, I simply call that specific application through Sophos Central.
I can manage Sophos firewall from Sophos Central, along with managing ZTNA, encryption, mobile MDM, and Sophos MDM.
What is most valuable?
The best feature of Sophos Central is that I can use all of the solutions from Sophos in a single pane of glass, which means I can manage all the services of Sophos from one console.
Having everything in one console makes my work easier because if I want to make a change on the firewall, I can simply go to the firewall management and make the changes. If I want to change anything related to Sophos wireless, I can directly change it from Sophos firewall without needing to access multiple consoles.
Sophos Central has positively impacted my organization because it allows us to utilize Sophos products in a single pane of glass, and with its synchronized security, it helps to protect our environment more effectively by isolating infected devices from the internet.
What needs improvement?
I think Sophos Central could be improved by offering an on-premises option because some users prefer to keep their data locally rather than in the cloud.
I think if there were a new licensing model for Linux endpoints, it would be very helpful for us.
For how long have I used the solution?
I have been working in my current field for the last two years.
What do I think about the stability of the solution?
Sophos Central is stable.
What do I think about the scalability of the solution?
Sophos Central's scalability is excellent because I can add any licenses at any time without needing to create a new console. For example, if I have 100 endpoints and need 20 more licenses, I can simply purchase them and continue to use them within the same console.
How are customer service and support?
The customer support for Sophos Central is very good. If I call support at any time, they will assign a new engineer according to SLA immediately or within one to three hours.
Which solution did I use previously and why did I switch?
I previously used Trend Micro before switching to Sophos Central because Trend Micro did not integrate with the console like Sophos Central does.
How was the initial setup?
The experience with pricing, setup cost, and licensing for Sophos Central has been very good. Additionally, there is no license required for Linux EDR machines, and if Sophos were to add Linux EDR licensing, it would be very helpful for my organization and others.
What about the implementation team?
The data is already stored in Sophos cloud, specifically in Sophos database.
What was our ROI?
I have not seen a return on investment yet.
Which other solutions did I evaluate?
I evaluated CrowdStrike as well, but I found that CrowdStrike does not provide the same level of protection with site management and application control as Sophos Central does.
What other advice do I have?
I would advise others to use Sophos Central because of its performance and customer support. It works in real-time, making it beneficial for many organizations. I can add that we can manage Sophos firewall from Sophos Central, along with managing ZTNA, encryption, mobile MDM, and Sophos MDM. My review rating for Sophos Central is 10.
All-in-One Monitoring with Robust Notifications and Easy Usability
What do you like best about the product?
- Ease of use
- All-in-one view for most tasks and monitoring
- Robust notification services.
- Good coverage and very good triage performance.
- Ease of integration.
What do you dislike about the product?
- Many FP findings.
- A bit difficult to complete some trivial tasks.
- Performance issues with development devices.
What problems is the product solving and how is that benefiting you?
Sophos is an excellent XDR and cloud security solution, especially suited for organizations seeking an all-in-one platform with a minimal learning curve.
Centralized threat blocking has reduced manual monitoring but still needs better exclusions and logs
What is our primary use case?
My main use case for Sophos Central involves utilizing it as an endpoint, EDR, and email gateway.
In my day-to-day work, I use Sophos Central by installing the agent on our clients. We have around 40 to 50 clients that are using Sophos as their EDR. We have created the alerting system in our ServiceNow, which is integrated with Sophos Central, so we get tickets in ServiceNow whenever something is triggered. I log into Sophos to investigate the alert, reviewing the alerts on that device from Sophos, and if required, I manually log into the device to check the alert and take actions accordingly.
Regarding my main use case or how I use Sophos Central day to day, the most useful feature is that Sophos blocks threats. As a senior engineer, my main work involving Sophos is handling situations when it blocks something that is legitimate, such as a ServiceNow MID Server. Every time this happens, Sophos blocks it as a malicious file, so we dive into Sophos and create exclusions, especially path exclusions, and if necessary, we also create hash exclusions to ensure that the legitimate file can be accessed and run by the user without any issues.
What is most valuable?
The best features Sophos Central offers, in my opinion, involve its excellent ability to block threats in endpoint protection. While it is not as effective in handling exclusion cases, it excels at successfully blocking almost all files that seem suspicious, which is really good and provides strong security.
What I appreciate most about the blocking features in Sophos Central is its real-time detection and the variety of threat types it can catch. Many other endpoints miss files that don't have a bad reputation, but Sophos finds a way to catch those malicious files, and if there's even a small suspicion, it blocks them. The real-time detection is really great in Sophos Central.
Sophos Central has positively impacted our organization by being a desired EDR solution for our many clients. As an MSSP, we have a significant number of clients utilizing Sophos Central, and it provides excellent service as an EDR. Even when we use it as an email gateway, it continues to perform well, making it beneficial for our organization with a wide client base.
What needs improvement?
One way Sophos Central can be improved is in its exclusion capabilities. When we try to exclude legitimate files, we find that it requires a lot of effort, as we cannot simply exclude one file from every detection. Due to the layered approach, it takes time to exclude even one file, indicating that the exclusion process could definitely be enhanced.
I would add that the logs in Sophos Central should be more detailed. Sometimes, when we're checking the logs, they simply state that a file is blocked, but we can't find out why that is the case. More detailed logs could significantly improve the log collecting aspect.
Areas for improvement in Sophos Central are log collection, exclusion processes, and customer support. Aside from these points, I believe the overall product is great.
For how long have I used the solution?
I have been using Sophos Central for the last six years.
What do I think about the stability of the solution?
Sophos Central is stable, which is a positive attribute.
What do I think about the scalability of the solution?
I believe Sophos Central's scalability is good compared to other EDR solutions that we have.
How are customer service and support?
Customer support for Sophos Central is a bit slow. When I create a support ticket, it takes a while for them to respond. In my recent experience with a support ticket, the engineer was not very effective and took longer than I expected. When we reach out to the support team, we anticipate quick answers, especially since the client is waiting for a resolution. The vendor seems to take time contacting other teams, so I feel the support team could improve their response times.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
Before using Sophos Central, we had utilized CrowdStrike; however, due to an outbreak, some clients wanted to switch away from CrowdStrike. We provided clients with options, including Sophos Central and SentinelOne, with SentinelOne being fairly costly. Ultimately, most clients preferred Sophos Central, leading us to switch a few clients from CrowdStrike to Sophos Central.
What was our ROI?
I have seen a return on investment with Sophos Central in terms of needing fewer employees because Sophos Central is handling many tasks itself. Previously, we had to monitor other endpoints and faced issues integrating with ServiceNow, requiring separate monitoring. After adopting Sophos Central, we can easily integrate with ServiceNow, which means fewer employees, and that translates to money saved.
Which other solutions did I evaluate?
Before choosing Sophos Central, we evaluated other options such as SentinelOne and Microsoft Defender.
What other advice do I have?
My advice to others looking into using Sophos Central is that it is beneficial in terms of cost efficiency and time efficiency. I recommend using Sophos Central and digging into the logs more thoroughly, and if possible, incorporating syslogs or other kinds of logs. I would rate this product a 7 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?