Sophos

Sophos

Subscription-based cybersecurity for endpoints, networks, MDR

Overview

Sophos provides cybersecurity solutions for businesses, covering endpoint, network, and mobile security, with a cloud-based management console called Sophos Central. Its products protect devices, networks, and mobile endpoints, and include Managed Detection and Response (MDR) where experts monitor and respond to threats. The company differentiates itself by offering an integrated, single-vendor security stack—covering endpoint, network, and mobile protection—managed from one platform. Its goal is to help organizations prevent digital threats while simplifying security operations.

Significant Headcount Growth

About Sophos

Simplify's Rating
Why Sophos is rated
B-
Rated B on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Enterprise Software

Cybersecurity

Company Size

5,001-10,000

Company Stage

Acquired

Total Funding

$208.6M

Headquarters

Abingdon, United Kingdom

Founded

1985

Get referred to Sophos

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Sophos and OpenAI announced Fusion partnership on August 6, 2026, expanding channel pull.
  • Sophos AI Defense enters early access in August 2026, targeting shadow AI governance.
  • Sophos Next-Gen SIEM and MDR GA August 15, 2026 deepen recurring platform revenue.

What critics are saying

  • Sophos cut up to 10% of staff in January 2026, signaling post-merger strain.
  • Secureworks integration creates overlapping products, channels, and teams through 2026, slowing execution.
  • CrowdStrike, Microsoft, and Palo Alto Networks bundle AI security faster, squeezing Sophos' standalone demand.

What makes Sophos unique

  • Sophos Fusion unifies endpoint, email, cloud, identity, and SOC workflows across 500 integrations.
  • Secureworks Taegis analytics deepens Sophos XDR after the February 3, 2025 acquisition.
  • Sophos serves 625,000 organizations through 25,000 partners, including 7,000 MSPs.

Help us improve and share your feedback! Did you find this helpful?

Funding

Total Funding

$208.6M

Above

Industry Average

Funded Over

6 Rounds

Acquisition funding comparison data is currently unavailable. We're working to provide this information soon!
Acquisition Funding Comparison
Coming Soon

Benefits

Health Insurance

Disability Insurance

Remote Work Options

Wellness Program

Mental Health Support

Growth & Insights and Company News

Headcount

6 month growth

14%

1 year growth

14%

2 year growth

14%
Associated Press
Aug 6th, 2026
Sophos partners with OpenAI to deliver frontier AI security through 25,000+ channel partners

Sophos has partnered with OpenAI to integrate frontier AI models into its Sophos Fusion cybersecurity platform for managed service providers (MSPs). The partnership aims to deliver AI-powered security through Fusion's unified architecture, which connects endpoint, network, email, cloud, identity, and security operations. Sophos will launch AI Defense in August 2026, providing organisations with visibility into AI usage across their environments and policy enforcement capabilities. The collaboration builds on Sophos' existing relationship with OpenAI through the Daybreak Cyber Partner Program. The integration will give Sophos' network of over 25,000 partners, including more than 7,000 MSPs, access to OpenAI's capabilities within their existing defence systems. Sophos defends more than 625,000 organisations worldwide and is headquartered in Oxford, UK.

GlobeNewswire
Aug 6th, 2026
Sophos announces partnership with OpenAI to bring frontier AI to the channel.

Sophos announces partnership with OpenAI to bring frontier AI to the channel. A dedicated channel partnership brings frontier AI to the channel and service providers through Sophos Fusion, powering new security services partners can build on. August 06, 2026 11:00 ET | Source: Sophos Inc. LAS VEGAS, Aug. 06, 2026 (GLOBE NEWSWIRE) - BLACK HAT USA - Sophos, a global cybersecurity leader, today announced a partnership with OpenAI to bring OpenAI frontier models to managed service providers (MSPs) through Sophos Fusion, the industry's most complete AI-native Cybersecurity Defense System. Through this partnership, Sophos intends to give partners a new way to deliver frontier AI security as one connected defense system, and to build recurring services on top of it. Sophos Fusion is built on a single, open architecture where every control point operates as one, whether native to Sophos or a third-party integration. The partnership will extend that open model, with a focus on bringing OpenAI frontier models into a cyber defense system that already connects endpoint, network, email, cloud, identity, and security operations, and compounds intelligence from every threat it encounters. For MSPs, that means frontier AI arrives inside the defense system they already run, not as another tool to wire in themselves. In addition to applying frontier AI to strengthen defense, Sophos is also defending the AI that organizations increasingly adopt. Through Sophos AI Defense, available for early access in August 2026, Sophos gives organizations visibility into how AI and shadow AI is used across their environment, enforces policy on that usage, and helps govern how sensitive data is used across AI models and tools. Sophos intends to expand this protection with OpenAI, securing the AI workloads, data, and usage that organizations increasingly depend on as part of one connected defense system. The partnership builds on an established relationship between Sophos and OpenAI through the OpenAI Daybreak Cyber Partner Program. Through Daybreak, OpenAI works with leading cybersecurity companies to develop practical, governed solutions for defenders, building new workflows, integrating frontier capabilities, and helping security teams identify, validate and remediate threats faster. This partnership deepens that work with a dedicated focus on the MSPs that deliver security to organizations worldwide, and reflects Sophos' commitment to an open architecture that brings best-of-breed technologies into one defense system. "Frontier AI only protects organizations at scale when you have the architecture to operationalize it and the reach to deliver it," said John Peterson, chief technology officer, Sophos. "Sophos Fusion will give OpenAI models a defense system to work inside: connected control points, shared context, and human accountability. Our channel gives them reach through a global network of more than 25,000 partners, including over 7,000 MSPs. For those partners, it opens a new class of AI security services to build a business on. That is how frontier AI reaches the organizations that need it most." MSPs are uniquely positioned to turn frontier cyber capabilities into practical security outcomes because they understand their customers' environments and already operate the workflows organizations rely on. Sophos Fusion supports that work by connecting endpoint, network, email, cloud, identity and security operations in one coordinated defense system. By pairing that foundation with OpenAI's frontier capabilities, Sophos plans to help approved partners enhance detection, investigation, and response and develop new services tailored to their customers' needs. "Many of our clients are adopting AI at rapid speed, and they're asking us how to stay secure while they do it," said Alex Ryals, CISO & SVP at MicroAge, a Sophos partner based in Phoenix, AZ, USA. "Seeing a leader in security and a leader in AI commit to working together on exactly that challenge means we can offer a strong answer for our clients, and new services to grow on." Sophos will share more information about their partnership with OpenAI and potential offerings in the coming months. To learn more about the t partnership, visit Sophos.com If attending Black Hat USA, visit Sophos at booth #3239. Forward-Looking Statements This announcement contains forward-looking statements regarding anticipated products, services, collaborations, and future capabilities. Any unreleased services or features referenced are subject to change and may not become generally available. Customers should make purchasing decisions based solely on currently available products and services. About Sophos Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

ARN
Aug 5th, 2026
Sophos promotes Marina Brook as A/NZ channel director.

Sophos promotes Marina Brook as A/NZ channel director. 5 Aug 2026 2 mins Brook brings more than 30 years of IT channel experience to the role. Sophos has promoted Marina Brook to director of channel and commercial sales for Australia and New Zealand (ANZ), replacing Robert Mottram in the role. The cybersecurity vendor said the appointment reinforces its commitment to accelerating partner growth and expanding its channel ecosystem across the region. In her new position, Brook will lead Sophos' A/NZ channel and commercial sales strategy, working closely with partners, distributors and internal teams to drive growth, strengthen engagement and improve cybersecurity outcomes for customers. Brook brings more than 30 years of IT channel experience to the role, with expertise spanning partner-led growth, go-to-market execution and channel ecosystem development. Prior to her promotion, Brook led Sophos' commercial channel division, where she was responsible for advancing the company's partner strategy and driving channel-focused business outcomes. According to Sophos, the appointment highlights its continued investment in the A/NZ market as it works with partners to expand services-led opportunities and help customers improve cyber resilience. "Marina's appointment comes at an important time for our A/NZ channel business," Sophos APJ senior director of channel sales Chad Cleevely said. "She has a proven ability to unite partners, distributors and sales teams around a clear strategy that delivers real business outcomes. Her leadership, deep channel expertise and focus on helping partners grow through services and innovation make her the ideal choice to lead Sophos' next phase of channel growth." Brook said her focus would be on strengthening partner engagement and helping the channel capitalise on emerging growth opportunities. "My priority is to deepen our partner relationships and help partners unlock new growth opportunities in an increasingly complex threat landscape," she said. "We are focused on driving greater adoption of managed security services, expanding go-to-market collaboration, and equipping partners with the tools, programs and AI-driven cybersecurity capabilities they need to better protect customers from continuously evolving threats." Don't miss a thing From its editors straight to your inbox. Get started by entering your email address below. Editor ARN | Reseller News With years of experience covering the latest technology trends and business news across the IT channel, Julia Talevski has been keeping the IT industry connected in Australia and New Zealand. She is currently the editor for ARN and Reseller News, responsible for keeping the community engaged at every touch point through its newsletters, websites and main events such as EDGE, WIICTA and Innovation Awards.

InfoSec Today
Aug 1st, 2026
Three-headed dogs and long tails: Sophos at BSides LV.

Three-headed dogs and long tails: Sophos at BSides LV. In addition to Sophos' presence at Black Hat USA this year, data scientists from the Sophos AI team will present two talks on novel AI security research at the BSides Las Vegas conference. A three-headed dog. On Monday August 3, Adarsh Kyadige presents 'CerBERTus,' a three-headed BERT-based model for prompt security. LLM jailbreak detection is often framed as a binary task: is a prompt harmful or benign? However, this framing is brittle. Harmful requests can be concealed inside roleplay, fiction, urgency, or 'academic' pretexts, while legitimate prompts can be topically close to unsafe content without malicious intent. As a result, single-label detectors overfit to surface patterns, yielding both false negatives (adversarial rewrites) and false positives (adjacent-benign prompts). CerBERTus addresses this issue because it does not treat jailbreak detection as a flat binary classifier; instead, it models the attacker's degrees of freedom by disentangling what is being asked (goal) from how it is being asked (frame). The method involves a single shared encoder that feeds three classification heads: * Harmfulness (primary) * Goal category (what the user is trying to do) * Framing style (how the request is presented). To train and stress-test this separation, Adarsh and team built a structured factorial prompt corpus that systematically crosses goals with frames: * Goals include harmful, adjacent-benign, and generic-benign requests spanning categories such as cyberattacks, fraud/social engineering, explosives, chemical/biological weapons, conventional weapons, drug synthesis, privacy/doxxing, human trafficking, extremist propaganda, and racism/nativism. * Frames include adversarial jailbreak styles (e.g., roleplay/persona, screenplay/fiction, urgency/crisis, academic pretext, obfuscation, injection-like prefixes) as well as benign and null/plain framing. The team will demonstrate that the model generalizes to both novel attack goals and novel presentation styles it had not encountered during training. In the talk, they'll cover the threat model, dataset construction, training objective, and evaluation strategy, and discuss when multi-task supervision improves robustness and interpretability. Anomalies and long tails. On Wednesday, August 5, following on from research presented at Black Hat USA 2025, Sophos data scientists Ben Gelman, Tamas Nyiri, and Tibor Kristóf Lányi will share details of their new anomaly detection research. Supervised classifiers in cybersecurity are often trained on data that doesn't capture the most unusual examples. Benign training sets are dominated by simple, common patterns, while malicious sets reflect known attacks from past investigations. The long tail of unusual files on both sides goes unlabeled. When these files appear in production, classifiers are more likely to misclassify them, generating false positives that overwhelm SOCs and false negatives that let threats through. Traditional approaches don't scale: manual labeling is expensive, rule-based collection is too narrow, and anomaly detection alone has historically produced unacceptable false positive rates. But anomaly detection combined with LLMs is excellent at something else: finding and labeling the unusual data that is missing from cybersecurity training sets. In their talk, Ben and team present an automated pipeline that combines anomaly detection and LLMs to augment training data for a suite of cybersecurity models. To surface distinctly unusual data, they used complementary anomaly detection methods that each operate on different feature representations. Then, an LLM classifies each anomaly with format-specific prompts calibrated per data type. Critically, the team used separate prompts that erred toward malicious and benign respectively, achieving high precision on both label types. This method was evaluated across three structurally different data types with monthly ingestion scales spanning separate orders of magnitude. Ben and colleagues will explain the architecture, walk through LLM reasoning on real anomalous files, show real world 'before' and 'after' results, and give attendees everything they need to build this for their own detection systems. More to come. InfoSec Today'll publish more in-depth articles on both projects after the conference. Andy Curtis is an award-winning security consultant, researcher and public speaker. He has been working in the computer security industry since the early 1990s, having been employed by state and federal government, leading healthcare and banking providers across three continents. He has given talks about computer security for some of the world's largest companies, worked with law enforcement agencies on investigations into hacking groups, and is a regular voice on TV and radio explaining IT security threats. What do you feel about this?

Sophos
Jul 22nd, 2026
Sophos named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026.

Sophos named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026. Recognition highlights Sophos' intelligence-led MDR capabilities, flexible co-management model and vendor agnostic architecture July 22, 2026 OXFORD, U.K Sophos, a global cybersecurity leader, today announced it has been named a Leader in the IDC MarketScape: Worldwide Managed Detection and Response Services for Midmarket 2026 Vendor Assessment. IDC MarketScape evaluates managed detection and response (MDR) providers based on their capabilities and strategies for helping organizations identify, investigate and respond to cybersecurity threats. Sophos MDR delivers threat detection, investigation and response through a globally distributed security operations model twenty-four hours a day, seven days a week, 365 days a year. Backed by Sophos X-Ops threat intelligence and advanced AI capabilities, the service helps organizations strengthen cyber defenses while maximizing existing security investments. "We believe this recognition reflects our continued focus on helping organizations achieve stronger cybersecurity outcomes through intelligence-led security operations, flexible service delivery and an open security ecosystem," said Rob Harrison, senior vice president of product management at Sophos. "Organizations today face increasingly sophisticated threats alongside growing operational complexity. Sophos MDR combines AI-powered security operations with human expertise to help customers detect and respond to threats quickly and effectively. As cyberattacks become faster and more coordinated, Sophos Fusion extends these capabilities through a connected, AI-native cybersecurity defense system that enables organizations to benefit from shared intelligence, synchronized security operations and agentic AI." According to the IDC MarketScape: "Organizations of any size seeking a managed detection and response service with deep proprietary threat intelligence, flexible co-management engagement models, and a vendor-agnostic platform that accommodates existing security investments should evaluate Sophos's MDR offering." As the world's largest agentic security operations center (SOC), Sophos MDR secures more than 40,000 customers worldwide and is built to support both Sophos and third-party telemetry sources across endpoints, networks, cloud, email and identity environments. Customers can choose the level of engagement that best fits their needs, ranging from notification-only support to collaborative investigations and full response authorization. Modular capabilities, including Exposure Management, Next-Gen SIEM and Identity Threat Detection and Response, enable organizations to expand security operations as requirements evolve. Sophos MDR is powered by Sophos X-Ops, which brings together threat intelligence, threat hunting, detection engineering and managed service delivery. The Sophos X-Ops Counter Threat Unit (CTU) tracks ransomware groups, initial access brokers and nation-state adversaries, generating intelligence that feeds directly into detections, threat hunts and response playbooks. Combined with visibility across more than 625,000 defended organizations worldwide, this intelligence helps Sophos rapidly transform emerging threat insights into protections and response actions. Sophos Group believe the recognition comes as Sophos continues to advance its AI-native cybersecurity strategy through Sophos Fusion, the company's AI-native Cybersecurity Defense System. Sophos Fusion brings together endpoint, network security, email, cloud, identity, security operations (XDR, MDR, Next-Gen SIEM) and advisory services within a single connected architecture designed to strengthen cyber resilience through shared intelligence, synchronized operations and agentic AI. About IDC MarketScape. IDC MarketScape vendor assessment model is designed to provide an overview of the competitive fitness of technology and service suppliers in a given market. The research utilizes a rigorous scoring methodology based on both qualitative and quantitative criteria that results in a single graphical illustration of each supplier's position within a given market. IDC MarketScape provides a clear framework in which the product and service offerings, capabilities and strategies, and current and future market success factors of technology suppliers can be meaningfully compared. The framework also provides technology buyers with a 360-degree assessment of the strengths and weaknesses of current and prospective suppliers. IDC MarketScape: Worldwide Managed Detection and Response Services for Midmarket 2026 Vendor Assessment, # US52992326, July 2026. About Sophos. Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

Recently Posted Jobs

Sign up to get curated job recommendations

Sophos is Hiring for 66 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →