No more typing reviews! Try our Samantha, our new voice AI agent.

Sophos UTM vs Trellix Network Detection and Response comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.7
Sophos UTM offers quick returns, efficient network management, and cost savings, benefiting managed service providers and ensuring data protection.
Sentiment score
6.9
Trellix NDR boosts security confidence, offers up to 200% ROI, reduces costs, and enhances threat detection and response efficiency.
I have seen a return on investment with Sophos UTM, and I can share that the price is around thirty percent better, especially if you count in the employee time.
System Engineer SDDC / VCF at a tech services company with 51-200 employees
The time was reduced because of the automated detections.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
It has saved us money and time, and the overall investment has been profitable.
Network & Security Lead at Net-International
 

Customer Service

Sentiment score
6.7
Sophos UTM's customer service receives mixed reviews for response times but is praised for expertise and community resources.
Sentiment score
7.2
Trellix Network Detection and Response support is well-rated but can face delays, with room for improvement on complex issues.
The technical support by Sophos is amazing, especially when I pay for the enhanced support.
Associate Director - Management Support Services at CIHP
I would rate the technical support by Sophos a 10.
Network and Infrastructure Manager at Sonysugar
I would rate the technical support with Sophos a seven because sometimes the time of the first resolution is not ideal.
IT Manager at a consultancy with 51-200 employees
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
Information Security Engineer at Nhq Distribution Ltd
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
They help and support us promptly, allowing us to resolve issues immediately.
Network & Security Lead at Net-International
 

Scalability Issues

Sentiment score
6.0
Sophos UTM is highly scalable, supporting growth via licenses, hardware, and clustering, adaptable to varying deployment sizes.
Sentiment score
7.3
Trellix Network Detection and Response offers scalable cloud solutions, smooth transitions, and efficient support for diverse enterprise environments.
You can have high availability clusters, so very, very scalable in my opinion.
System Engineer SDDC / VCF at a tech services company with 51-200 employees
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response is scalable.
Network & Security Lead at Net-International
Trellix Network Detection and Response is designed to scale based on our workloads, and it performs well when we scale.
Cyber Security Engineer II (Vulnerability & Threat Management) at FICO
 

Stability Issues

Sentiment score
7.5
Sophos UTM is praised for stability and reliability, with few issues occurring mainly during updates or resource demands.
Sentiment score
7.7
Trellix Network Detection and Response is stable and reliable with minor performance issues, requiring experts for deeper maintenance.
Trellix Network Detection and Response is somewhat stable but there is a bit of downtime sometimes during the off-hours.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Room For Improvement

Sophos UTM needs enhancements in reporting, UI, threat protection, VPN, technical support, scalability, pricing, and configuration simplicity.
Trellix users desire better firewall integration, AI, reporting, UI, customization, threat intelligence, onboarding, documentation, support, and automation.
If you want to really implement some rules that are a little bit more difficult, Sophos always recommends getting the dedicated WAF, or web application firewall, but I would prefer to have more features on the web application firewall in the firewall itself because it would make more sense.
System Engineer SDDC / VCF at a tech services company with 51-200 employees
I would prefer to see additional features in the next release of Sophos UTM because cyber crime increases every day, so we also need to improve our game to prevent any chances for intrusion.
Network and Infrastructure Manager at Sonysugar
It would make my work much simpler because it makes decision-making much easier.
IT Manager at Vegol
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
Information Security Engineer at Nhq Distribution Ltd
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Network & Security Lead at Net-International
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
Presales Manager
 

Setup Cost

Sophos UTM offers flexible pricing with incentives, praised for its features and value despite some regional variances.
Trellix NDR is seen as pricey yet valued for quality, with customers desiring more cost-effective options despite reliability.
Pricing has become expensive recently due to the dollar hike and naira value changes in Nigeria.
Associate Director - Management Support Services at CIHP
The value between what I receive and what I pay is the best in the industry.
System Administrator at a training & coaching company with 11-50 employees
The pricing would be more economical if sold directly to the user compared to going through a partner, as they need to take their percentage.
Network and Infrastructure Manager at Sonysugar
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
Network & Security Lead at Net-International
The price for Trellix Network Detection and Response is reasonable.
IT Manager at Gigabit Technologies Pvt Ltd
I am sure the ROI was definitely fine for this because we were using this tool for three years.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
 

Valuable Features

Sophos UTM excels in configuration ease, real-time reporting, cost-effectiveness, and flexible security features, benefiting efficient management.
Trellix Network Detection excels in threat detection, malware analysis, and integrates seamlessly with existing security tools for real-time response.
The zero-day protection and firewall rules are some of the most effective features for threat management.
Associate Director - Management Support Services at CIHP
It helps us quite a lot, especially because since we use Sophos UTM, malware intrusions are not rampant.
Network and Infrastructure Manager at Sonysugar
Sophos UTM's valuable features include the cost, which is very competitive when compared with other vendors, balanced with the features that it delivers.
IT Manager at a consultancy with 51-200 employees
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Associate Cybersecurity Analyst at a tech vendor with 10,001+ employees
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Network & Security Lead at Net-International
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
Presales Manager
 

Categories and Ranking

Sophos UTM
Average Rating
8.6
Reviews Sentiment
6.7
Number of Reviews
119
Ranking in other categories
Unified Threat Management (UTM) (5th)
Trellix Network Detection a...
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
45
Ranking in other categories
Advanced Threat Protection (ATP) (17th), Network Detection and Response (NDR) (13th)
 

Mindshare comparison

While both are Network Security Systems solutions, they serve different purposes. Sophos UTM is designed for Unified Threat Management (UTM) and holds a mindshare of 9.4%, up 7.1% compared to last year.
Trellix Network Detection and Response, on the other hand, focuses on Advanced Threat Protection (ATP), holds 4.1% mindshare, up 3.9% since last year.
Unified Threat Management (UTM) Mindshare Distribution
ProductMindshare (%)
Sophos UTM9.4%
Fortinet FortiGate26.6%
Check Point Quantum Force (NGFW)8.5%
Other55.5%
Unified Threat Management (UTM)
Advanced Threat Protection (ATP) Mindshare Distribution
ProductMindshare (%)
Trellix Network Detection and Response4.1%
Palo Alto Networks WildFire7.4%
Microsoft Defender for Office 3656.7%
Other81.8%
Advanced Threat Protection (ATP)
 

Featured Reviews

Bashir Bashir - PeerSpot reviewer
IT Manager at Vegol
Firewall management has become simpler and now provides real-time visibility and bandwidth control
The features I have found most valuable in Sophos UTM are that it is much easier to configure, I appreciate the reporting side of it, and the rules are very straightforward to work with. Sophos UTM's real-time insights into network health help my organization because I get real-time reports on what is happening on my network, what is trying to access me, the destination, and all that. I can then be reactive or proactive, and for zero-day, I think it is beneficial because it can learn what my network does. If anything goes outside what it expects, it sends a report on Sophos Central, so I find zero-day makes my work a bit easier. The use of Sophos UTM's intuitive management console has impacted my security policy enforcement in that it is much easier to configure; I configure with information rather than with presumptions.
Hassan Sheikh - PeerSpot reviewer
Network & Security Lead at Net-International
Integrated sensors have improved traffic inspection and now provide resilient east-west threat control
I believe Trellix Network Detection and Response can be improved by integrating machine learning into its detection response capabilities. Additionally, incorporating failover kits integrated into the sensors could be beneficial. It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features. While Trellix Network Detection and Response sensors are highly capable, I think it would be advantageous to include features such as Layer 7 profiles, application profile filters, web filters, IDx, IP feature sets, signature detection features, and routing and switching capabilities all in one device. While the user interface of Trellix Network Detection and Response is very good, I suggest implementing a customizable dashboard. Additionally, there should be report generation for critical attacks and high alert severities, displayed graphically on the dashboard, and providing options to extract files in Excel format for better visibility.
report
Use our free recommendation engine to learn which Unified Threat Management (UTM) solutions are best for your needs.
896,467 professionals have used our research since 2012.
 

Comparison Review

it_user216600 - PeerSpot reviewer
Senior Technical Consultant with 51-200 employees
Jan 3, 2016
Sophos UTM vs. Fortinet FortiGate
I have used both Sophos and Fortinet products in production and I have found the Sophos UTM appliances (hardware and virtual) to be a better fit most of the time -- with a few caveats which I will touch on below. In both instances, the transition from TMG will be mostly straightforward. The main…
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Construction Company
9%
Manufacturing Company
9%
Financial Services Firm
6%
Financial Services Firm
14%
Comms Service Provider
12%
Manufacturing Company
11%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business75
Midsize Enterprise28
Large Enterprise27
By reviewers
Company SizeCount
Small Business22
Midsize Enterprise8
Large Enterprise21
 

Questions from the Community

What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
As a solution, Sophos UTM offers a lot of functionality, it scales well, and the stability and performance are quite good. The most valuable features for me are their web and email filtering. I wou...
What is your experience regarding pricing and costs for Sophos UTM?
The pricing for Sophos UTM is reasonable; I do not have an issue with it, though I was considering RED because I have different sites I wanted to connect, and instead of doing site-to-site, the RED...
What needs improvement with Sophos UTM?
I would like to improve Sophos UTM in that there is software I use that goes deeper in the reporting on usage. There is software called Fastvue that breaks down everything in the firewall and whate...
What is your experience regarding pricing and costs for FireEye Network Security?
The price for Trellix Network Detection and Response is reasonable. The pricing is reasonable, and I do not need to bargain with Trellix or customers.
What needs improvement with FireEye Network Security?
The negative aspect is support. When I need urgent support from Trellix, there is a response after four hours or three hours, which is my main concern regarding the negative point of Trellix Networ...
What is your primary use case for FireEye Network Security?
I am working with Trellix Network Detection and Response as part of my overall experience with these products today. Trellix Network Detection and Response is used for threat and response use cases...
 

Also Known As

Astaro
FireEye Network Security, FireEye
 

Overview

 

Sample Customers

One Housing Group
FFRDC, Finansbank, Japan Advanced Institute of Science and Technology, Investis, Kelsey-Seybold Clinic, Bank of Thailand, City of Miramar, Citizens National Bank, D-Wave Systems
Find out what your peers are saying about Fortinet, Check Point Software Technologies, WatchGuard and others in Unified Threat Management (UTM). Updated: May 2026.
896,467 professionals have used our research since 2012.