Try our new research platform with insights from 80,000+ expert users

Cortex XDR by Palo Alto Networks vs Sophos EPP Suite comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.7
Cortex XDR secures data, reduces malware, lowers costs, and replaces systems, enhancing user satisfaction and operational efficiency.
Sentiment score
7.7
Sophos EPP Suite boosts ROI in 12-16 months, enhancing productivity, protection, and compliance while ensuring customer satisfaction.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
 

Customer Service

Sentiment score
6.6
Cortex XDR support is praised for responsiveness but criticized for delayed responses and knowledge gaps in certain regions.
Sentiment score
7.7
User reviews of Sophos EPP Suite support highlight responsiveness and expertise, though some experience delays and ineffective resolutions.
Their support is efficient and responsive whenever I raise a ticket through my portal.
Every vendor has similar support; it depends on how the case is handled and raised.
They have introduced a dedicated role called Technical Account Manager (TAM) for every partner.
The Sophos people here in South Africa are very helpful.
 

Scalability Issues

Sentiment score
7.6
Cortex XDR offers scalable, efficient data handling across Linux, Mac, and Windows, praised for simplifying large enterprise management.
Sentiment score
8.5
Sophos EPP Suite offers scalable solutions for diverse organizations, accommodating growth and simplifying cloud deployments, despite third-party integration limits.
 

Stability Issues

Sentiment score
8.1
Cortex XDR is praised for its stability and reliability, with minor issues noted but generally offering seamless protection.
Sentiment score
9.0
Sophos EPP Suite is generally stable but has minor glitches; some users seek other solutions for better stability.
Cortex XDR is stable, offering high quality and reliable performance.
 

Room For Improvement

Cortex XDR struggles with integration, high memory, false positives, limited features, complex setup, and lacks enhanced support and customization.
Sophos EPP Suite needs improvements in migration, resource usage, integration, support, and user interface for better performance and compatibility.
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
Cortex XDR could improve its sales support team, including better commission structures and referral programs.
The enterprise integration is very poor, requiring a lot of manual work.
Users have noted that daily upload limits per device, overall data lake storage capacity tied to licenses, and daily API query limits can be restrictive.
 

Setup Cost

Enterprise buyers view Cortex XDR as expensive yet flexible, offering scalable licensing with varying costs based on features and users.
Sophos EPP Suite offers competitive, often affordable pricing, with discounts for longer licenses, despite varying costs by features and users.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
Compared to competitors such as CrowdStrike and Sophos, the pricing of Cortex XDR by Palo Alto Networks is similar to CrowdStrike but more expensive than Sophos.
The cost is reasonable and cheaper than other alternatives.
 

Valuable Features

Cortex XDR excels in cybersecurity with advanced detection, ease of use, and integration, offering scalable, efficient threat management.
Sophos EPP Suite offers seamless integration, advanced threat detection, centralized management, and user-friendly features for comprehensive security solutions.
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
Key features for comprehensive detection and prevention include advanced threat prevention, ransomware protections, exploit prevention, and AI-powered detections.
With the reseller management, I can manage multiple clients without having to log in to each client.
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
90
Ranking in other categories
Extended Detection and Response (XDR) (7th), Ransomware Protection (1st), AI-Powered Cybersecurity Platforms (4th)
Sophos EPP Suite
Ranking in Endpoint Protection Platform (EPP)
24th
Average Rating
8.2
Reviews Sentiment
7.6
Number of Reviews
59
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of June 2025, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, down from 5.0% compared to the previous year. The mindshare of Sophos EPP Suite is 0.8%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP)
 

Featured Reviews

NiteshSharma - PeerSpot reviewer
Automated threat response and behavioral control improve security measures
I recommend adding a data loss prevention (DLP ( /categories/data-loss-prevention-dlp )) solution to Cortex XDR ( /categories/extended-detection-and-response-xdr ) by Palo Alto Networks. The inclusion of this feature would allow the application of DLP ( /categories/data-loss-prevention-dlp ) policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products. Additionally, multi-tenancy and multi-cloud features are not available and should be considered for inclusion.
Sabbir Ahmed - PeerSpot reviewer
Experience significant threat prevention advancements with user-friendly deployment
The feature is called relay server, and some people refer to it as a cache server. The Sophos EPP Suite is scalable. Some customers in banks typically have 5,000 to 7,000 users. One customer started with 1,000 users and has now extended to 4,000 users. Some customers are using up to 8,000 users without any issues. Regarding AI elements in the Sophos EPP Suite, firewalls have already introduced AI features. They have integrated AI models similar to ChatGPT in firewalls. These AI features should be introduced in endpoint XDR as well. Key features for comprehensive detection and prevention include advanced threat prevention, ransomware protections, exploit prevention, and AI-powered detections. Extended visibility and data analysis include cross-product data correlations. They have a data lake, live discover, and threat graphs. They also offer AI case summary and AI common analysis, accessible from Sophos Central, which is the management portal for Sophos XDR. Sophos Central serves as one central management portal for managing firewalls, endpoint, Sophos encryption, and mobile device management solutions. This centralized management is particularly appealing to customers.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
9%
Manufacturing Company
8%
Government
7%
Computer Software Company
18%
Financial Services Firm
10%
Manufacturing Company
8%
Educational Organization
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
What do you like most about Sophos EPP Suite?
Sophos EPP Suite is a powerful antivirus.
What is your experience regarding pricing and costs for Sophos EPP Suite?
For Bangladesh, the price of the Sophos EPP Suite is reasonable. We recently won a deal when compared with CrowdStrike, SentinelOne, Palo Alto, and Checkpoint. The deal was won based purely on comm...
What needs improvement with Sophos EPP Suite?
The Sophos EPP Suite should work on key areas, especially in data management, specifically the data retention part. The data lake storage has certain limits. Users have noted that daily upload limi...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
EPP Suite
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
EK Services
Find out what your peers are saying about Cortex XDR by Palo Alto Networks vs. Sophos EPP Suite and other solutions. Updated: June 2025.
856,873 professionals have used our research since 2012.