Remote in Canada; must be legally authorized to work in Canada without sponsorship.
Sophos provides cybersecurity solutions for businesses, covering endpoint, network, and mobile security, with a cloud-based management console called Sophos Central. Its products protect devices, networks, and mobile endpoints, and include Managed Detection and Response (MDR) where experts monitor and respond to threats. The company differentiates itself by offering an integrated, single-vendor security stack—covering endpoint, network, and mobile protection—managed from one platform. Its goal is to help organizations prevent digital threats while simplifying security operations.
Company Size
5,001-10,000
Company Stage
Acquired
Total Funding
$208.6M
Headquarters
Abingdon, United Kingdom
Founded
1985
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Disability Insurance
Remote Work Options
Wellness Program
Mental Health Support
Thoma Bravo offers lenders more protections in Sophos refinancing. * September 11, 2026 * - 10:07 am Thoma Bravo is offering lenders a fresh package of protections as it seeks to refinance cybersecurity company Sophos, highlighting the growing pressure on PE sponsors to reassure creditors as artificial intelligence reshapes the software sector, according to a report by Bloomberg. The report cites unnamed people familiar with the matter as saying that the proposed refinancing includes several provisions designed to strengthen the position of existing lenders. Among them is an "omniblocker", which broadly restricts a company from giving preferential terms to selected creditors in ways that could disadvantage others. Sophos has also agreed to measures intended to prevent existing debt holders from being subordinated and to restrict the movement of assets, including intellectual property, away from lenders, the people said. The concessions come as Thoma Bravo works to refinance a $2.1bn loan due in March 2027. The sponsor has faced a cautious lending market amid concerns that AI could disrupt established software businesses, although recent signs suggest some of those concerns may be easing. The Sophos situation is being closely watched because Thoma Bravo has almost $9bn of software-related debt maturities coming due over the next two years, more than any of its private equity peers. The firm recently agreed to roughly 40 lender-friendly amendments as part of a refinancing for another cybersecurity investment, Proofpoint. The proposed Sophos financing comprises a roughly $1.67bn loan priced at 5 to 5.25 percentage points over benchmark rates and offered at 97 cents on the dollar, alongside a €350m loan. A further $300m privately placed junior payment-in-kind instrument, together with $98m of cash on Sophos' balance sheet, is intended to reduce the company's overall leverage. Thoma Bravo is also seeking to move ahead with refinancing its portfolio companies before other private equity sponsors begin addressing their own approaching debt maturities, according to one of the people. Sophos has added several provisions that reflect the increasingly familiar language of the leveraged credit market. A so-called Serta blocker is designed to prevent non-pro-rata debt exchanges that could move certain lenders down the repayment hierarchy, while a Pluralsight blocker seeks to prevent the transfer of assets such as intellectual property to facilitate new borrowing outside the existing lender group. The provisions take their names from high-profile debt restructurings involving Serta Simmons Bedding and Pluralsight, respectively, and are part of a broader set of protections that lenders have increasingly sought as liability-management transactions have become more common. Thoma Bravo has not undertaken a liability-management exercise, according to people familiar with the matter.
The numbers behind CISO burnout and turnover. This week in cybersecurity from the editors at Cybercrime Magazine. Sausalito, Calif. - Sep. 8, 2026 The 2026 CISO Report from Cybercrime Magazine in partnership with Sophos looks at how security Chiefs are faring in one of the most stressful tech jobs. "For a while now, the industry data has told us that the average tenure for a CISO is less than any other [C-suite] member," according to Joe Levy, CEO at Sophos. CSO names frustration, stress, and increased liability as a few of the off-putting realities giving CISOs cold feet. More CISOs are dissatisfied with the role today than ever before, with studies indicating that 75 percent of security chiefs are interested in a job change. Surveys show that 99 percent of CISOs work extra hours every week, and 1 in 5 work an extra 25 hours per week, according to Help Net Security. ComputerWeekly reports that almost one-third of CISOs say stress is adversely affecting their performance. Dark Reading reports that average CISO tenure now hovers between 18 months and 26 months, according to multiple industry estimates, and the result is not just executive churn, but instability that ripples through security programs, teams, and risk posture. It doesn't help that in several incidents over the past couple of years, CISOs have been held legally and personally responsible for the handling and reporting of breaches. A survey by Heidrick & Struggles found that nearly half of surveyed CISOs did not have an adequate internal successor in place. Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest: * SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally. * NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy and security stories. * HACK. Another organization gets hacked every day. We tell you who, what, where, when, and why. * VC. Cybersecurity venture capital deal flow with the latest investment activity from various sources around the world. * M&A. Cybersecurity mergers and acquisitions including big tech, pure cyber, product vendors and professional services. * BLOG. What's happening at Cybercrime Magazine. Plus the stories that don't make headlines (but maybe they should). * PRESS. Cybersecurity industry news and press releases in real time from the editors at Business Wire. * PODCAST. New episodes daily on the Cybercrime Magazine Podcast feature victims, law enforcement, vendors, and cybersecurity experts. * RADIO. Tune into WCYB Digital Radio at Cybercrime.Radio, the first and only round-the-clock internet radio station devoted to cybersecurity. Contact us to send story tips, feedback and suggestions, and for sponsorship opportunities and custom media productions.
Sophos to showcase ai-native cybersecurity defense at GISEC 2026. Posted on September 8, 2026 Company to spotlight Sophos Fusion and its expanding portfolio of AI-powered security, XDR, SIEM and MDR capabilities Dubai, United Arab Emirates, September 8, 2026, ZEX PR WIRE - Sophos, a global cybersecurity leader, has announced its participation at GISEC Global 2026 (16-18 September) at Dubai Exhibition Centre, Expo City. The company will showcase how organizations can strengthen cyber resilience in an AI-enabled threat landscape where attacks are becoming faster, more coordinated, and difficult to manage with disconnected security tools. The focus will be on Sophos Fusion, its AI-native cybersecurity defense system designed to move businesses beyond fragmented security stacks. Attackers are now using AI and automation to move faster, scale campaigns, and operate across multiple parts of an organization's environment. Disconnected tools cannot keep pace with threats that move this way. Sophos' 2026 State of Ransomware report found that 79% of ransomware attacks globally involve an identity-based initial access vector, with malicious email and phishing accounting for 26% of attacks, followed by exploited vulnerabilities at 24% and compromised credentials at 23%. In the UAE, organizations that suffered ransomware attacks reported an average recovery cost of US$665,000. These findings reinforce the need for a system that can see the whole picture and respond as one. Sophos Fusion, a modern cybersecurity defense system, is designed to close that gap by preventing, detecting, investigating, and responding at AI speed, while keeping human expertise and accountability at the center of security operations. This shift is particularly relevant in the Middle East, where rapid digital transformation and AI adoption are creating new opportunities as well as new security challenges. "As AI agents gain greater access to sensitive systems and data, enterprises need security and governance to keep pace with innovation. This demands a coordinated, AI-native defense system that can respond at the speed and scale of today's threats," said Harish Chib, Vice President for Emerging Markets, Middle East & Africa at Sophos. "GISEC is an important platform for us to bring these conversations together, engage with customers, partners, policymakers and security leaders, and reinforce our commitment to helping organizations build the resilience they need for the AI era." At GISEC 2026, Sophos will also highlight how it is applying agentic AI to strengthen security operations. Within Sophos MDR, agentic workflows can resolve a significant proportion of cases end-to-end using AI, while human analysts remain responsible for business judgment, context and complex investigations. This enables high-confidence tasks to be handled at machine speed while maintaining human oversight and reducing the operational burden on security teams. Building on this approach, Sophos is advancing the defensive use of frontier AI through the OpenAI Daybreak Cyber Partner Program and Anthropic's Project Glasswing. These collaborations enable Sophos to integrate advanced AI capabilities into trusted security workflows, with analysts and controls in the loop, to accelerate threat investigation, strengthen detections and support faster vulnerability remediation. Through Project Glasswing, Sophos has access to Claude Mythos 5, an advanced frontier model that is not publicly available, helping identify and remediate software vulnerabilities before they can be exploited by AI-driven attackers. Visitors can meet the Sophos team and explore its latest AI-native cybersecurity capabilities at Hall 4, Booth D100 during GISEC Global 2026. About Sophos Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Company-submitted announcement. Visit their site for details.
Sophos to bring OpenAI GPT cyber models into Managed Risk offering, helping defenders validate exploit paths. Sep. 3, 2026, 05:02 PM OXFORD, United Kingdom, Sept. 03, 2026 (GLOBE NEWSWIRE) - Sophos, a global cybersecurity leader, today announced Exploit Path Verification (EPV), a new capability that will be built into Sophos Managed Risk to help security teams better prioritize and manage exploitable vulnerabilities in their environment. The capability will be built with OpenAI's GPT cyber models through the Daybreak Defense Network, to return verified, evidence-backed verdicts that give defenders the clarity they need to fix the exposures that matter first. Availability will be announced at a later date. Security teams face a widening gap between the vulnerabilities they can find and the ones they can fix. Scanners surface thousands of exposures and severity scores and rank them, but a severity score cannot tell whether a critical flaw sits behind a control that blocks it, or whether two low-severity findings chain into the path that leads to a breach. As a result, security teams often patch by generic score, rather than by whether an attacker could reach and use a flaw in their specific environment. Sophos is designing EPV to close that gap. It is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, and returns a clear evidence-backed exploitability verdict: * Confirmed Exploitable * Blocked by a Control * Not Reachable * Insufficient Evidence EPV will also be designed to identify chained paths where multiple lower-severity findings combine into one exploitable route, assess whether a control blocks a technique class or only a common public proof of concept, and draft remediation text ready for a ticket. The capability will be advisory and additive by design. Every verdict is labeled as AI-generated with its evidence visible, and Sophos analysts review the results. "One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk," said John Peterson, chief technology officer, Sophos. "Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first." EPV extends Sophos' work with OpenAI. Through the OpenAI Daybreak Defense Network (formerly OpenAI Daybreak Cyber Partner Program), which Sophos joined in June 2026, the company brought frontier cyber models into MDR investigation, advisory assessments, and workflows that help customers discover, validate, and remediate exposure. EPV will build on that work inside a product customers already run. OpenAI's GPT cyber models provide frontier reasoning to help assess exploitability. Sophos supplies the environment-specific evidence and product controls, and its analysts review the results delivered to customers. "Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely," said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. "Sophos has been a thoughtful partner since joining the program, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands." Sophos defends more than 625,000 organizations worldwide, including 40,000 managed detection and response (MDR) customers across enterprise, mid-market, and commercial segments, delivered through one of the industry's largest partner ecosystems. That reach is central to EPV's purpose. Verified exploitability should not be a capability reserved for the largest security teams with the deepest budgets. EPV is in development for enterprise and mid-market business customers of Sophos Managed Risk. Sophos will announce availability, including early access and general availability timing, at a later date. ABOUT SOPHOS Sophos, a global cybersecurity leader, defends more than 625,000 organizations worldwide with Sophos Fusion, the industry's first and most complete AI-native cybersecurity defense system: a single, connected architecture where every control point operates as one. Powered by agentic AI and elite human expertise, Sophos detects, investigates, and neutralizes threats before they become business-disrupting events. Working alongside a global ecosystem of managed service providers, resellers, and technology partners, Sophos compounds intelligence from every threat encountered and every environment defended to make every customer's defense stronger than the last. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. Markets Insider and Business Insider Editorial Teams were not involved in the creation of this post. Sponsored Financial Content
The next chapter of Sophos Fusion starts now. Sophos XDR Powered by Secureworks, enhanced Sophos MDR, and Sophos Next-Gen SIEM are now available, giving you more ways to grow customer relationships and strengthen security outcomes. August 31, 2026 Last month, Sophos Group introduced Sophos Fusion and shared its vision for the future of cyber defense. Today, Sophos Group is excited to announce the next significant milestone in that journey: Sophos XDR Powered by Secureworks, Sophos Next-Gen SIEM, and an expanded Sophos MDR service, are now generally available. Powered by Sophos Fusion, these new and enhanced offerings create fresh opportunities to help customers strengthen security operations, defend against AI-driven threats, meet compliance requirements, and reduce complexity. What's available now. The following are now generally available for new term (non-MSP) customers: * Sophos XDR Powered by Secureworks Delivering stronger detections, embedded threat intelligence, expanded integrations, automation playbooks (SOAR), Sophos Email Monitoring System (EMS), a significantly enhanced analyst experience, and more. * Sophos MDR Now expanded with broader integrations, embedded threat intelligence, Sophos EMS, a redesigned analyst workspace, continuous agentic threat hunting through the world's largest Agentic SOC, and more. * Sophos Next-Gen SIEM A new compliance-focused add-on that extends Sophos XDR and Sophos MDR with long-term data retention, compliance reporting, and support for custom integrations. Existing customer upgrades are underway. Sophos Group has also started a phased upgrade program for existing Sophos EDR, Sophos XDR, and Sophos MDR customers. Customers will receive in-product notifications before their upgrade takes place. As customers are upgraded to the enhanced solutions, they'll gain access to new capabilities included as part of their existing subscription. This creates a valuable opportunity to reconnect with customers, demonstrate the additional value they're receiving, and explore ways to further strengthen their security operations. Sophos AI Defense EAP is now open. Sophos AI Defense helps organizations gain visibility and control over AI use across their environments, creating new opportunities to engage customers on AI governance, AI risk management, and secure AI adoption. Learn more about Sophos AI Defense Customers running the enhanced Sophos EDR, Sophos XDR, or Sophos MDR solutions can now join the Sophos AI Defense Early Access Program (EAP) ahead of general availability coming soon. Identify customers interested in securing AI usage and encourage them to join the EAP. The partner opportunity. The latest offerings, enabled by Sophos Fusion, create opportunities across both new and existing customer relationships. Partners can position enhanced Sophos XDR and Sophos MDR capabilities, helping organizations strengthen security operations with broader visibility, deeper integrations, and enhanced threat detection and response. Sophos Next-Gen SIEM also creates new opportunities to address customer requirements for compliance, long-term data retention, and custom integrations, while increasing the value of Sophos XDR and Sophos MDR deployments. And Sophos AI Defense gives you a timely way to extend customer conversations into securing AI adoption across the business. Potential customer conversations include: * Moving from Sophos Endpoint or Sophos EDR to Sophos XDR for broader visibility and response. * Upgrading Sophos Endpoint, Sophos EDR, or Sophos XDR to Sophos MDR for 24/7 protection through the world's largest Agentic SOC. * Extending Sophos XDR or Sophos MDR with Sophos Next-Gen SIEM to address compliance reporting and long-term data-retention requirements. * Introducing customers to the new Sophos AI Defense solution, built to help them see, control, and secure AI across their environment. What partners need to know. This GA release is for term (non-MSP) customers only. MSP availability is planned for next quarter, with dedicated communications to follow. * New term customers and new trials will now be provisioned on the enhanced Sophos EDR, Sophos XDR, and Sophos MDR solutions, on the new Sophos Fusion architecture. * Continue to sell existing Sophos EDR, Sophos XDR, and Sophos MDR SKUs. * Sophos MDR service tiers have been renamed. Sophos MDR Essentials is now Sophos MDR, and Sophos MDR Complete is now Sophos MDR Plus. SKU codes remain unchanged. * The Sophos Next-Gen SIEM add-on is now available for customers on the enhanced Sophos XDR and Sophos MDR solutions. Partner resources. Ready to start the conversation with customers? Visit the Sophos Partner Portal to access the latest Sophos Fusion resources, along with updated sales, marketing, and enablement materials for the new and enhanced solutions. Sophos Fusion is moving from vision to customer value. The new and enhanced solutions are available now, the customer upgrade journey is underway, and partners have more ways to grow relationships, increase value, and help customers strengthen security operations. Together, let's go win with Sophos Fusion.