Skip to main content Scroll Top

Sophos Synchronized Security, explained simply

Illustration for the article: How to choose a managed IT provider (and check the one you have)

Picture a Friday afternoon. Someone in your office opens an attachment that looks like a shipping notice. Within minutes, a program on their laptop starts doing things it should not. The question that decides how bad your weekend gets is simple: how long before something stops that laptop from reaching the rest of your network?

With security tools that work on their own, the answer is “whenever someone notices.” With Sophos Synchronized Security, Sophos says the answer is usually seconds, and nobody has to be sitting at a screen for it to happen. Here is how it works, without the jargon.

Think of your office as a building

A well-run building has several kinds of security. There is a front desk that checks who comes in. There are cameras in the hallways. There are locks on the doors of each office. In a lot of buildings, each of these is run by a different company, and they do not talk to each other. The camera might see someone breaking into an office, but the front desk has no idea and keeps letting the same person in and out.

Now imagine a building where the cameras, the front desk and every door lock are wired to one alarm. The moment a camera sees trouble in one office, that office door locks, the front desk stops that person at the exit, and the security company is called. Nobody has to run down the hall and pull a lever.

That is the idea behind Synchronized Security. In your network, the pieces are:

  • The front desk: Sophos Firewall. The box that sits between your office and the Internet and decides what traffic gets in and out.
  • The cameras and door locks: Sophos Endpoint. Protection software on every computer and server (an “endpoint” is any device on the network). It watches what programs are doing, not just what files look like.
  • The hallways: Sophos Wireless and Sophos Switch. The Wi-Fi access points and network switches that connect devices to each other.

The heartbeat: green, yellow, red

Every computer running Sophos Endpoint regularly reports its health to the other Sophos products. Sophos calls this the Security Heartbeat. The status is shown as a traffic light:

  • Green: the device is healthy.
  • Yellow: the device may be compromised. Something suspicious was seen and is being dealt with.
  • Red: the device is confirmed compromised.

The heartbeat is the wiring between the cameras and the alarm. It is what lets the firewall and Wi-Fi know, right away, that a particular laptop is in trouble.

What happens when a laptop goes red

According to Sophos, when Sophos Endpoint detects a threat it sets that device’s heartbeat to red, and the other Sophos products act on that status automatically:

  • The firewall, Wi-Fi access points and switches block the device’s network access, so it cannot reach your file server, your accounting system or the Internet.
  • Sophos Endpoint on the healthy computers stops them from connecting to the infected one, so the problem does not hop from desk to desk.
  • Once the threat is cleaned up, the device goes back to green and its connection is restored automatically.

Sophos says this containment happens in seconds. In building terms: the office door locks, the hallway closes, and the rest of the building keeps working. Your other staff can carry on while the one laptop is dealt with.

Why speed matters so much

Attackers rarely stop at the first computer they reach. They look around, collect passwords and try to spread to servers and backups. Sophos’s 2026 Active Adversary Report, based on 661 incident response and monitoring cases, found that 88% of ransomware payloads were deployed outside business hours. Attacks are timed for when nobody is watching.

That is exactly the gap automatic isolation is designed to close. It does not need an employee to notice a strange pop-up, or an IT person to wake up and log in. The response starts on its own, and people follow up.

To be clear about what it is and is not: no security product can promise that nothing will ever get through. Synchronized Security reduces how far an attack can spread and how long it goes unanswered. That is often the difference between one bad laptop and a whole office that cannot work.

What you, the owner, actually see

Very little, most days, and that is the point. The management side lives in Sophos’s cloud console, which Sophos now calls Sophos Fusion (it announced Fusion in July 2026 as the evolution of the console formerly known as Sophos Central). If you have seen “Intercept X” on an older invoice, that is the previous name for what is now Sophos Endpoint.

When something does happen, a typical owner’s experience looks like this:

  1. An employee’s laptop suddenly cannot reach the network. They call the help desk.
  2. By the time they call, the alert is already in front of our engineers, with the device name, what was detected and what was blocked.
  3. We clean up or rebuild the device, confirm it is healthy, and it reconnects.
  4. You get a plain-English summary: what happened, what was affected (ideally just that one laptop), and anything we recommend changing.

What it takes to make it work

Synchronized Security only works if the pieces are in place and set up correctly:

  • Sophos Endpoint on every computer and server, including the one in the back room that “nobody uses.”
  • A Sophos Firewall at each office, with the heartbeat connection turned on.
  • Sophos Wi-Fi and switches where you want isolation to reach the access layer, not just the Internet connection.
  • Someone watching the alerts. Automation handles the first seconds; people still have to investigate, clean up and learn from it.

How FTI helps

We chose Sophos for our clients largely because of this coordinated response. You can read the fuller story in why we chose Sophos. As part of our managed IT services, we install and configure the Sophos products, keep them updated, and watch the alerts. Our AI-assisted operations read Sophos alerts together with monitoring data, tickets and documentation, so our engineers see the whole picture quickly. The engineers decide what to do and do it, with a help desk that answers 24/7. More on our security services.

Talk to us about securing your network