Try our new research platform with insights from 80,000+ expert users

Cortex XDR by Palo Alto Networks vs Sophos Central comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Ranking in AI-Powered Cybersecurity Platforms
4th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
91
Ranking in other categories
Endpoint Protection Platform (EPP) (5th), Extended Detection and Response (XDR) (7th), Ransomware Protection (2nd)
Sophos Central
Ranking in AI-Powered Cybersecurity Platforms
9th
Average Rating
8.4
Reviews Sentiment
8.5
Number of Reviews
39
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2025, in the AI-Powered Cybersecurity Platforms category, the mindshare of Cortex XDR by Palo Alto Networks is 10.9%, down from 12.3% compared to the previous year. The mindshare of Sophos Central is 0.0%. It is calculated based on PeerSpot user engagement data.
AI-Powered Cybersecurity Platforms
 

Featured Reviews

NiteshSharma - PeerSpot reviewer
Automated threat response and behavioral control improve security measures
I recommend adding a data loss prevention (DLP) solution to Cortex XDR by Palo Alto Networks. The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products. Additionally, multi-tenancy and multi-cloud features are not available and should be considered for inclusion.
Sandeepraj Gatla - PeerSpot reviewer
Cost-effective security management with a user-friendly interface, efficient resource utilization, and rapid response capabilities
While Sophos Central has demonstrated commendable functionality, there is room for improvement in the realm of automation. Specifically, addressing ransomware attacks often requires leveraging external tools, deploying virtual machines, and utilizing supplementary tools like Caliper Analytics for operations and security communication. The integration of these essential functionalities directly into the software would represent a significant enhancement, streamlining the incident response process and bolstering the platform's comprehensive threat mitigation capabilities. Furthermore, a valuable addition to future releases could involve augmenting the new screen component with advanced capabilities such as XML utilization and rule integration. This enhancement, especially pertinent to tools involved in sandboxing and virtual machines within the investigation process, would greatly streamline the analysis of logs and reports. This would prove particularly beneficial in the context of email analysis, spam attack detection, and other critical security aspects. By incorporating these features, Sophos Central could further elevate its utility in facilitating in-depth security analyses and response strategies.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution's most valuable feature is the user interface."
"Cortex covers everything I need. It's a perfect solution. Cortex provides a different level of visibility because it's an extended EDR, allowing you to grab logs from the network and firewalls. Palo Alto invented the concept of the extended EDR or XDR."
"The stability of the solution is very good. We have about 100 users on it right now, and we use it twice a week."
"It blocks malicious files. It prevents attacks. It doesn't require many updates, it's a very light application."
"The user interface of the solution is sophisticated and straightforward."
"Stability is one of the features we like the most."
"One of the main benefits of the solution is its intelligence to correlate the events into an incident."
"We have a complete overview of all our PCs and it's very easy to handle and to use the interface. It has a lot of benefits for us."
"The standout feature is its focus on indexing, primarily designed for managing reports and logs from 500 to 1,000 endpoints, including Windows 10 hosts within the network."
"The interface, especially when using the software center, is quite user-friendly and easy to navigate."
"What I find most valuable in Sophos Central is its clear and detailed threat visibility on the dashboard."
"The product is easy to use."
"One of the significant advantages of Sophos is its affordability compared to other technologies like Check Point and Fortinet."
"The most valuable feature is that it protects my IT infrastructure from attacks."
"The best thing about Sophos Central is how it brings all its security solutions together in one place."
"The product's initial setup phase was easy."
 

Cons

"Cortex XDR is trickier to configure than other Palo Alto products. This is one area where we are not so satisfied."
"There are some false positives. What our guys would have liked is that it would have been easier to manipulate as soon as they found a false positive that they knew was a false positive. How to do so was not obvious. Some people complained about it. The interface, the ESM, is not user-friendly."
"The solution can never really be an on-premises solution based simply on the way it is set up. It needs metadata to run and improve. Having an on-premises solution would cut it off from making improvements."
"It would be good to have a better way to search for a file within the UI."
"There are a large number of false positives."
"Cortex XDR could improve its sales support team, including better commission structures and referral programs."
"The playbooks could be improved to include more functionalities or actions."
"In the next release, I would like to see more UI improvements. Their UI is a bit basic. When we are speaking about Palo Alto Networks they are the big company, so they can improve the UI a little bit. The UI, the reports, the log system can all be improved."
"The product's firewall servers and dashboard need improvement."
"The tool is slow in the Middle East region. It should also integrate custom reporting."
"Having and option for endpoint security on mobile devices, it would be advantageous."
"Pushing global rules and policies to all devices from Central isn't easy. You can do it for all endpoints, which is fine. But you can't do the same with firewalls. Firewall management with Central is very limited. You can connect one firewall to another and tell it, "I want one policy for all my customer's firewalls," but that's not possible. For a customer with multiple firewalls, you can't say, "This works for France, Great Britain, Canada," and push it. It's not possible."
"Improving the response time of the customer support team would be beneficial."
"I would like to see improvements in the password recovery process within the Sophos Central solution."
"The product does not have a dedicated MFA."
"With the current hybrid work environment and travel requirements, having a mobile solution would greatly improve our ability to access and navigate Sophos Central on the go, enhancing the overall user experience and making it a more portable solution."
 

Pricing and Cost Advice

"Cortex XDR's pricing is ok."
"It has reasonable pricing for the use cases it provides to the company."
"The pricing is a little high. It is per user per year."
"The price of the solution is high for the license and in general."
"Traps pays for itself within the first 16 months of a three-year subscription. This is attributed to OPEX savings, as security teams spent less time trying to identify and isolate malware for analysis as a result of a reduction in malware incidents, false positives, and breach avoidance."
"Very costly product."
"It's about $55 per license on a yearly basis."
"I don't recall what the cost was, but it wasn't really that expensive."
"The pricing is very competitive. When compared to other vendors like Fortinet, Sophos stands out, especially in terms of firewall and endpoint pricing."
"Sophos Central is an affordable solution that any mid-level customer can buy."
"The pricing of Sophos is quite reasonable and generally cheaper compared to competitors like Fortinet and Check Point."
"It is rather expensive."
"The cost is quite affordable."
"The product's pricing was somewhat high. We paid Rs. 1500 INR per license, approximately equivalent to 20 USD."
"It's not considered a cheap solution and falls more in the moderate pricing category."
"It is an expensive tool."
report
Use our free recommendation engine to learn which AI-Powered Cybersecurity Platforms solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
9%
Manufacturing Company
8%
Government
7%
Manufacturing Company
18%
Comms Service Provider
13%
Financial Services Firm
10%
University
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
What do you like most about Sophos Central?
One of the significant advantages of Sophos is its affordability compared to other technologies like Check Point and Fortinet.
What is your experience regarding pricing and costs for Sophos Central?
As we get more people, we just add another item or Sophos appliances, and then we are good to go.
What needs improvement with Sophos Central?
As a user, I suggest improving Sophos Central by addressing some error messages we occasionally encounter that we just do not know what they relate to, even when it says it has resolved them. To im...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Find out what your peers are saying about Cortex XDR by Palo Alto Networks vs. Sophos Central and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.