Skip to main content Scroll Top

Why we chose Sophos, and how we use it for our clients

FTI Insights: Managed IT

Most small businesses end up with security that grew by accident: antivirus from one company, a firewall from another, whatever spam filter came with the email service. Each piece does its own job, but none of them talk to each other. When something gets past one layer, the others have no idea.

That is the problem we set out to solve when we chose a security partner for our managed IT clients. We chose Sophos because its products are designed to work together, and because they can be managed centrally by us rather than on each device.

What we were looking for

Our requirements were practical, based on years of looking after networks for organizations of every size:

  • Coverage of the everyday risks. The network edge, each computer, email and Wi-Fi.
  • Tools that share information. A threat spotted in one place should trigger a response everywhere.
  • One place to manage it all. So we can see every client’s status and act quickly, from anywhere. That matters in Alaska, where a site visit can mean a flight.
  • Automatic responses. Attacks do not wait for business hours, so the first response should not either.

What has changed at Sophos since 2024

Sophos has changed a good deal in the last two years, so here is a short update, based on Sophos’s own announcements, as of September 2026:

  • Secureworks joined Sophos. Sophos completed its acquisition of Secureworks on February 3, 2025, bringing in the Taegis detection platform and Secureworks’ threat research team.
  • Intercept X is now Sophos Endpoint. In late 2025 Sophos dropped the Intercept X name. Sophos describes the change as simplifying its product names; if you see “Intercept X” on an older invoice, it is the same family of protection.
  • Sophos Central became Sophos Fusion. In July 2026 Sophos announced Sophos Fusion, which it describes as the evolution of Sophos Central, rebuilt on one architecture, with features rolling out from August through October 2026.

None of this changes why we chose Sophos. If anything, the direction is the one we wanted: more of the security layers sharing information and responding together.

The pieces, in plain English

Sophos Firewall: the front door

A firewall sits between your office network and the Internet and decides what gets in and out. Sophos Firewall is a “next-generation” firewall, meaning it looks at the content of traffic, not just where it is coming from, including encrypted web traffic. According to Sophos, it shares information with other Sophos products and can automatically block a device that has been compromised.

Sophos Endpoint: protection on every computer

An “endpoint” is any computer or server on your network. Sophos Endpoint goes well beyond traditional antivirus. Sophos says it uses multiple AI models to identify new malware, including AI-generated variants, blocks the techniques attackers use to exploit software flaws, and switches to a more aggressive protection mode when it detects an active attacker.

Its anti-ransomware feature, CryptoGuard, watches for files being encrypted by a malicious program, stops that program, and, according to Sophos, returns affected files to their original state. Ransomware, software that locks your files and demands payment, is one of the most damaging threats small businesses face. We cover how those gangs operate in how ransomware gangs pressure victims.

Sophos Email: filtering what reaches the inbox

Most attacks still start with an email. Sophos Email scans attachments, including opening suspicious ones in an isolated test area (a “sandbox”) to see what they do. It rewrites links so they are checked again when someone clicks, not just when the message arrives. Sophos says it analyzes the wording and structure of messages to spot impersonation, such as a fake invoice “from” your boss. It works alongside Microsoft 365 and Google Workspace.

Sophos Wireless: Wi-Fi that is part of the defense

Wi-Fi is often the easiest way onto a network. Sophos access points are managed from the same console as everything else, so guest networks, staff networks and security rules are set up consistently. More importantly, they take part in the coordinated response described next.

Synchronized Security: why the pieces matter together

This is the main reason we chose Sophos. Sophos calls it Synchronized Security. Each computer running Sophos Endpoint reports its health, which Sophos calls a “Security Heartbeat”: green for healthy, yellow for possibly compromised, red for compromised.

When a computer turns red, the other Sophos products act on it. According to Sophos, the firewall, Wi-Fi access points and switches block that computer’s network access, and containment happens automatically in seconds rather than after someone notices. That limits how far an attacker can spread, including at 2 a.m. on a Sunday.

No security product can promise that nothing will ever get through. What coordinated tools do is shorten the time between detection and response, which is often the difference between one infected laptop and a company-wide outage.

One console, managed by us

Sophos products are managed from one cloud console, now part of Sophos Fusion. Sophos states that Fusion is not a separate product and there is nothing extra to license to turn it on.

For our clients, the console is our job, not theirs. We deploy and configure the products, set policies that fit each organization, watch the alerts and act on them. Sophos works alongside Kaseya, our management platform for monitoring, patching and backup, and our AI-assisted operations read Sophos alerts together with monitoring data, tickets and documentation. That gives our engineers the full picture quickly; they decide what to do. We also use Sophos’s web application firewall to protect sites on our secure web hosting.

What you can do now

  1. List your current security tools. Do they come from different vendors, and does anyone watch their alerts?
  2. Ask what happens today if one computer is infected overnight. Who finds out, and when?
  3. Check that email filtering covers links and attachments, not just spam.
  4. Make sure your Wi-Fi separates guests from staff.

How FTI helps

Sophos security is part of our managed IT services. We install it, tune it and manage it, with a 24/7 help desk and senior engineers on call. You can read more about our security approach, or see how managed IT compares to in-house IT.

Talk to us about securing your network