No more typing reviews! Try our Samantha, our new voice AI agent.

Morphisec vs Sophos Endpoint comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 19, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Morphisec
Ranking in Endpoint Protection Platform (EPP)
44th
Average Rating
9.2
Reviews Sentiment
7.4
Number of Reviews
21
Ranking in other categories
Vulnerability Management (56th), Advanced Threat Protection (ATP) (29th), Endpoint Detection and Response (EDR) (60th), Cloud Workload Protection Platforms (CWPP) (34th), Threat Deception Platforms (13th)
Sophos Endpoint
Ranking in Endpoint Protection Platform (EPP)
25th
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
64
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, up from 3.7% compared to the previous year. The mindshare of Morphisec is 1.1%, up from 0.5% compared to the previous year. The mindshare of Sophos Endpoint is 1.4%, up from 1.0% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
Cortex XDR by Palo Alto Networks3.8%
Sophos Endpoint1.4%
Morphisec1.1%
Other93.7%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Rick Schibler - PeerSpot reviewer
VP of Information Technology at Kentucky Trailer
Offers in-memory protection at a lower price than competitors
Morphisec's in-memory protection is probably the most valuable feature because it stops malicious activity from occurring. If something tries to install or act as a sleeper agent, Morphisec will detect and stop it. Morphisec's Moving Target Defense is critical to hardening our attack surface. If it detects something, it indicates whether it's valid. That means you've got a breach requiring investigation. It detects anomalies but doesn't necessarily point to what caused them. You still need to do that work. The solution is reasonably easy to administer. They made some changes last year, adding a cloud-based monitoring solution that makes deploying and monitoring our endpoints easy.
Ashutosh Jha - PeerSpot reviewer
Project engineer at IT Solution india private limited
Endpoint protection has strengthened malware defense and simplifies web and peripheral control
I would give Sophos Endpoint a rating of nine out of ten because it is working very well. I have cut one point because it has no solution for on-premises. Additionally, it has no solution for any Linux-based system endpoints. I have to install the server protection on Linux machines, which is why I am cutting one point for Sophos Endpoint. Sophos Endpoint should include the Linux endpoint agent and should provide a solution for Linux endpoints as well, because the server license is costly and nobody wants to use the server license on an endpoint machine. Sophos Endpoint should have a Linux endpoint independent agent as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature is that you can select remote access of any machine for sandboxing."
"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"The solution doesn't need a high level of technical training."
"The tool is designed to scale for large enterprises and handle large volumes of data."
"Cortex XDR is stable, offering high quality and reliable performance."
"It can automatically correlate events and logs, which is very helpful for an IT administrator. It can correlate different kinds of malware activities over a network, agent, or host system. You do not need to do it manually. It is a good feature. It is also a user-friendly solution. We have deployed it on the cloud because our space does not provide any flexibility for on-premises deployment, but Palo Alto has added some flexibility to install it on-premises. It must be like the same Cortex XDR agent for all the VPN services, web filtering services, and everything else."
"Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices."
"Has great threat detection capabilities."
"Since using Morphisec we have seen a downturn in attacks because Morphisec protects us versus Defenders and whatnot that are signature-based. I know we have not had any issues with ransomware or other zero-day attacks that we've seen with machines that, all of a sudden, have become before we instituted the product. Now the machine had to be re-imaged and there was a loss of data because something was on the machine. You couldn't really determine what was on the machine because nothing was picking it up. The products we were using weren't picking it up."
"The ability to stop attacks without having to detect or have a signature for the attack is the most valuable feature."
"Morphisec provides full visibility into security events from Microsoft Defender and Morphisec in one dashboard. Defender and Morphisec are integrated. It's important because it lowers the total cost of maintenance on the engineer's time, more or less. So the administrative time is dramatically reduced in maintaining the product. This saves an engineer around four to five hours a week."
"Morphisec has absolutely helped save money on our security stack. The ransomware at the end of the day can cost organizations millions upon millions of dollars. Investing in tools like Morphisec is a great reduction in that cost. If I can spend $10,000 in a year to protect assets that could be ransomed for $20,000,000, that's definitely a bet that one should pursue. Morphisec absolutely it's worth the investment."
"All the alerts are on the dashboard, which is quite simple and useful for us. You can easily check all the alerts that are being blocked or allowed, or whatever the action is. You can easily see that and you can take the necessary actions. You can add a PowerShell extension or any activities for blocking at your network level or for endpoints."
"Before we got Morphisec we evaluated solutions that claim to do similar things, and we have done additional evaluations since we started using it, but I don't think anything can truly touch what Morphisec does and the way it does it."
"Morphisec has enabled us to become a lot less paranoid when it comes to staff clicking on things or accessing things that they shouldn't that could infect the whole system. Our original ransomware attack that happened came from someone's Google drive and then just filtered on through that. It has put our minds at ease a lot more in running it. It's also another layer of security that has been proven to be effective for us."
"It's simple, it's easy, and it works."
"With Sophos, the scanning of viruses and scanning of the disk is done silently in the background."
"Endpoint protection is stable, easy to use, and scalable from deployment, management, and reporting perspectives."
"It's easy to deploy."
"Stability-wise, I rate the solution a ten out of ten...Scalability-wise, I rate the solution a ten out of ten."
"The web control and the application control are two good features."
"Really I could give it a nine because I can recommend the product as an excellent solution."
"With the reseller management, I can manage multiple clients without having to log in to each client."
"The product gives you a full picture of what's happening on your endpoint, on your PC, or your server."
 

Cons

"The solution lags to the real-time scenarios here and there."
"The solution should add unwanted malicious hash values to a block list so that whenever the action is triggered, it will automatically prevent the malicious content."
"In some cases, there are too many options for me, and it is a bit too hard to find some settings which I really need to implement."
"There are some limitations on the Traps agents."
"The solution should enhance the ADR and reporting."
"It takes time to scan the servers and devices."
"I would like to see some additional features related to email protection included."
"I would like to see improvement in the tool's user interface, particularly in the area of managing alerts and providing more reporting capabilities."
"I haven't been able to get the cloud deployment to work. When there's an update, I'm supposed to be able to roll it out for the cloud solution, but right now I'm continuing to use our SCCM solution to update it."
"We sometimes have to depend on the support team to know what action we should take. If the solution for an alert can be built into the report that we are getting, it will save time, and the interaction with support would be less. At times, corrective action is required, but at times, we don't need to take any action. It would be good if we get to know in the report that a particular infection doesn't require any action. It will save us time and effort."
"We started in the Linux platform and we deployed to Linux. The licensing of that has been kind of confusing between Linux licensing and Windows licensing. The overall simplicity of licensing or offering an enterprise license to just cover everything and then we don't have to count needs improvement."
"Having to have an on-prem server required a lot of administration."
"I haven't seen ROI because I haven't seen a threat that it has protected against, exactly."
"Some of the filters for the console need improvement. There are alerts that show up and just being able to acknowledge that we've seen those and not turn them off, but dismiss them, would be a huge benefit."
"If anything, tech support might be their weakest link."
"We sometimes have to depend on the support team to know what action we should take."
"If you are not an IT expert, the solution is difficult to use."
"I would like to see more integration with different platforms."
"There could be enhancements made to the DLP."
"From our enrollment perspective, I would say maybe it could be a little lighter in terms of agent usage so that there is less computer utilization."
"The product should improve support and provide more scalable clustering."
"I would like to have the capability to support legacy operating systems because the majority now don't support Windows XP, and Windows 2000."
"The weakest point from Sophos is that in many cases, it is not very well known."
"Technical support could be improved - quicker and better. Support is the bad side of Sophos."
 

Pricing and Cost Advice

"Our license will require renewal in August, after which the maintenance will continue as usual."
"The price was fine."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
"The pricing seems fair, and I do like the licensing model. You use wherever they are, and it is elastic."
"It's way too expensive, but security is expensive. You pay for your licensing, and then you pay for someone to monitor the stuff."
"The cost depends on your chosen license type, like Pro or other licenses."
"The pricing is okay, although direct support can be expensive."
"Cortex XDR's pricing is ok."
"Morphisec is reasonably priced because our parent company's other subsidiaries use different products like CrowdStrike. CrowdStrike is four or five times more expensive than Morphisec. The competitive pricing saves us money in our overall security stack."
"It is priced correctly for what it does. They end up doing a good deal of discounting, but I think it is priced appropriately."
"The pricing is definitely fair for what it does."
"Compared to their competitors, the price of Morphisec is not that high. You can easily deploy it on a large-scale or small-scale network."
"It is a little bit more expensive than other security products that we use, but it does provide us good protection. So, it is a trade-off."
"We are still using a separate tool. I know for our 600 or I think we're actually licensed for up to 700 users, it runs me 23 or $24,000 a year. When you're talking to that many users plus servers being protected, that's well worth the investment for that dollar amount."
"It is an annual subscription basis per device. For the devices that we have in scope right now, it is about $25,000 a year."
"Price-wise, it's on the higher side. A traditional antivirus solution is cheaper, but in terms of security and manageability, its ROI is better than a traditional antivirus. I would recommend it to anybody evaluating or considering an antivirus solution. If your system gets compromised, the cost of ransom would be a lot more. This way, it saves a lot of cost."
"I would rate the price seven out of ten, for its cost-effectiveness."
"The pricing for this solution is ok."
"The solution's cost is reasonable."
"Sophos EPP Suite is cost-effective. We bought it because it costs less than other solutions we like—for example, Trend Micro and Panda Antivirus."
"Sophos EPP Suite is a competitive and affordable solution."
"The pricing is reasonable."
"When compared to Fortinet, the renewal and subscription is quite expensive."
"If you compare this to other solutions from a pricing perspective, the enterprise version of Sophos turns out to be cost-effective."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Outsourcing Company
15%
Manufacturing Company
13%
Construction Company
13%
Comms Service Provider
10%
Outsourcing Company
14%
Manufacturing Company
10%
Financial Services Firm
9%
Comms Service Provider
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise8
Large Enterprise8
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise8
Large Enterprise14
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
What is your experience regarding pricing and costs for Sophos EPP Suite?
The setup cost is good and licensing is good. The pricing is slightly increased, but it is good because Sophos Endpoi...
What needs improvement with Sophos EPP Suite?
For endpoint protection, I do not see many weaknesses. The weakest point from Sophos is that in many cases, it is not...
What is your primary use case for Sophos EPP Suite?
I am conducting an information search to understand what other firewall solutions are doing rather than looking for a...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Morphisec, Morphisec Moving Target Defense
EPP Suite
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Lenovo/Motorola, TruGreen, Covenant Health, Citizens Medical Center
EK Services
Find out what your peers are saying about Morphisec vs. Sophos Endpoint and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.