No more typing reviews! Try our Samantha, our new voice AI agent.

Gophish vs Sophos Cybersecurity as a Service comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Gophish
Ranking in AWS Marketplace
2nd
Average Rating
8.6
Number of Reviews
22
Ranking in other categories
No ranking in other categories
Sophos Cybersecurity as a S...
Ranking in AWS Marketplace
5th
Average Rating
8.8
Number of Reviews
13
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the AWS Marketplace category, the mindshare of Gophish is 0.2%, up from 0.2% compared to the previous year. The mindshare of Sophos Cybersecurity as a Service is 0.2%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
AWS Marketplace Mindshare Distribution
ProductMindshare (%)
Gophish0.2%
Sophos Cybersecurity as a Service0.2%
Other99.6%
AWS Marketplace
 

Featured Reviews

JC
Administrador de sistemas informaticos en red at a consultancy with 201-500 employees
Phishing awareness campaigns have improved training impact but still need smarter automation
I think Gophish could be improved with more automation, for instance. It is great that you can create templates, schedule them, and do everything you want in Gophish, but it would be nice to have a small integrated AI model with which you could create email templates and phishing templates. It would be nice if Gophish implemented artificial intelligence. I wish Gophish could provide more support and be more advanced and that they continue developing it because it seems that Gophish does not get many updates, and I think they need to implement more features. It is great because it is free, but it needs more features. It would be cool if there was an artificial intelligence model that could create phishing campaigns or templates or email templates for you integrated within Gophish. I would rate it a seven. It is quite good and free software, but it needs more substance. It also depends on the number of clients a company has; it may be necessary to launch Gophish in a staggered way, which I also think is a drawback Gophish has. The issue is that if there are many people being targeted, for example, 5,000 employees in a company and you send 5,000, it may be that sending so many messages gets blocked by the security systems companies have. I think that Gophish could also improve the message sending flows. I gave it a seven because there are things to improve and it is not perfect. As I said before, it would be nice if templates could be created with AI, integrated into Gophish using an API with Gemini or ChatGPT or whichever, but the point is that it would be nice if the sending flows at large scale were better managed. When you send a phishing campaign to 5,000 people, you have to send it in sections in a staggered way, for example: to these 5,000 people it is going to be sent between eight in the morning and four in the afternoon. If you send them all at once, the phishing may get blocked and then the campaign has no effect. I would like it if Gophish implemented more improvements because they are needed, as it is kind of a bit stagnant. I hope that in the future they add more improvements including creating personalized templates with artificial intelligence and improving the message sending flows.
SR
Director at a outsourcing company with 1,001-5,000 employees
Integrated defenses have enabled rapid ransomware prevention and streamlined incident response
Sophos Cybersecurity as a Service is a mature platform with strong endpoint protection, MDR, and integrated security capabilities. However, areas exist where it can continue to evolve. I see opportunities around AI-driven automation, cloud-native security, identity protection, third-party integrations, executive reporting, and proactive risk management. Sophos already provides a strong integrated security platform with MDR, XDR, endpoint protection, and firewall integration. The next evolution is to become even more predictive and autonomous. I would like to see deeper AI-driven response automation, enhanced cloud and identity threat detection, broader third-party integrations, executive-focused risk dashboards, automated compliance mapping, and continuous external attack surface management. These enhancements would not only improve security outcomes but also help CISOs better demonstrate cyber risk reduction and business value. To make it a ten, I would like to see cloud-native workload protection and identity security deeper compared with some specialized competitors. Some enterprises with highly customized SOCs may prefer broader native integration and automation available from platforms such as Microsoft, Palo Alto Networks, or CrowdStrike. Further enhancement in executive reporting and exposure management capabilities is also needed.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Gophish has positively impacted my organization by helping my team reach our goals."
"Gophish has positively impacted my organization by increasing awareness among my employees."
"I think Gophish is a fantastic tool that, at least for my use case, worked perfectly."
"My advice to other professionals who are considering using Gophish is that it is a platform for people who are just starting out and do not have the resources and also do not have knowledge."
"Gophish is one of the easiest tools that I can see available online, and a significant advantage is that it is free of cost and open source."
"The best feature that Gophish offers is its customizability; it makes everything look very professional and makes tracking very easy."
"Gophish has had a positive impact on my organization, as I noticed that since I used Gophish for the benefit of several clients, the maturity level of my clients was increasing."
"Regarding my use of Gophish in this academic context, I found it extremely easy to use; you do not need to be a technical person with special skills to be able to handle it."
"Since using Sophos Cybersecurity as a Service, I have seen measurable improvements such as faster incident response, fewer successful attacks, and significant efficiency gains for IT teams, with independent evaluations showing near-perfect detection rates and response times under two minutes, translating directly into saved hours and reduced risk."
"Sophos Cybersecurity as a Service has positively impacted our organization by providing management with confidence, knowing we have one of the best MDR services overseeing our entire ecosystem."
"Sophos Cybersecurity as a Service offers very tight security and compliance; if anybody applies Sophos at their premises, the environment is completely secure and sound."
"Support comes not only on problems in terms of security, but also on other matters such as concerns, questions, or inquiries about the license and inquiries about the best way to deploy it."
"Enhanced Threat Hunting and Forensics help my organization address cyberattacks."
"I personally know hundreds of customers, and I can say they are very satisfied with Sophos Cybersecurity as a Service."
"Since the day we started using Sophos Cybersecurity as a Service MDR, there has not been a single incident."
"Sophos Cybersecurity as a Service has positively impacted our organization by being very beneficial for our business and serving as a valuable income source."
 

Cons

"I believe that Gophish can be improved by increasing the number of possible integrations."
"The customer support needs improvement."
"For Gophish, there is a lack of integration with MFA and cookie captures that are more advanced attack methods."
"The feature of actually taking the website's source code might be something which is not so ethical, because you're copying from the main website even though you're learning."
"When I send to more than 300 recipients, I am forced to split it into several sends because the tool doesn't behave effectively and freezes."
"The one improvement I would like to see in Gophish is the booting up of the images, as it sometimes takes a lot of time and could be improved."
"While I mentioned that one of the best features of Gophish is its reporting and analytics capabilities, I believe it requires more focus to become even better."
"I believe Gophish can be improved by adding new features based on attack types in the future, particularly for new zero-day attacks, and incorporating AI-based tools to enhance analyzing and automation."
"In terms of improvement, Sophos testing after implementation is quite difficult."
"There are a few areas where Sophos Cybersecurity as a Service could be improved."
"There are a lot of technical issues with the implementation of Sophos Cybersecurity as a Service, particularly because we are currently implementing the XG series, where Citrix is the endpoint, leading to a lot of confusion."
"Sophos Cybersecurity as a Service could be improved by adding features such as patch management and file encryption, as these are currently missing."
"The issue is that I am mentioning the need for more education because customers are using the solution, but I do not think they are maximizing the use or the functionalities of the solution."
"Sophos Cybersecurity as a Service is continuously consuming more resources, which leads to slower PC performance, so reducing resource consumption would be better for both Sophos products and our sales."
"The disadvantages of Sophos Cybersecurity as a Service include that the support, specifically after-sales support, needs to be improved."
"To make it a ten, I would like to see cloud-native workload protection and identity security deeper compared with some specialized competitors."
report
Use our free recommendation engine to learn which AWS Marketplace solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
26%
Manufacturing Company
10%
University
10%
Comms Service Provider
8%
Construction Company
37%
Comms Service Provider
10%
Outsourcing Company
9%
Security Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise6
Large Enterprise9
By reviewers
Company SizeCount
Small Business15
Large Enterprise3
 

Questions from the Community

What is your experience regarding pricing and costs for Gophish?
My experience with pricing, setup costs, and licensing shows that the setup cost is not very high; Gophish is completely free, as it is an open-source tool.
What needs improvement with Gophish?
I believe Gophish can be improved in a few areas. First, the user interface could be made more modern and beginner-friendly. The current setup is simple, but for a new user, campaign creation, land...
What is your primary use case for Gophish?
My main use case for Gophish is to run a phishing awareness campaign inside an organization in a safe and controlled way. For example, instead of waiting for a real attacker to send a fake email to...
What needs improvement with Sophos Cybersecurity as a Service?
The R&D team is very good in doing their task and continuously conducting research. I cannot comment on what could be added in future updates of Sophos Cybersecurity as a Service that they need...
What is your primary use case for Sophos Cybersecurity as a Service?
I want to discuss the experience with Sophos Cybersecurity as a Service products. I have familiarity with the service in general, but I do not have specific experience with Sophos. Sophos Cybersecu...
What advice do you have for others considering Sophos Cybersecurity as a Service?
Most of our customers are very cautious about the data that they are keeping, so they prefer buying Sophos Cybersecurity as a Service directly from Sophos or third-party vendors to building their i...
 

Overview

Find out what your peers are saying about Gophish vs. Sophos Cybersecurity as a Service and other solutions. Updated: June 2026.
909,725 professionals have used our research since 2012.