We use the solution to prevent ransomeware attacks and those from unknown sources.
Engineering Manager at a manufacturing company with 51-200 employees
A scalable, stable and easily installable solution offering comprehensive protection
Pros and Cons
- "Sophos Intercept X is a complete endpoint solution."
- "It should offer better security updates."
What is our primary use case?
What is most valuable?
Sophos Intercept X is a complete endpoint solution. It represents the combination of two products in one, offering the same configuration and management.
What needs improvement?
While the solution does not seem to lack any features, it should offer better security updates. It could be more secure, something which holds true for any solution.
Also, the support could be faster.
For how long have I used the solution?
We have been using Sophos Intercept X over the course of the past year. While it is very new in my current company, we made use of it for four years in my previous one.
Buyer's Guide
Intercept X Endpoint
June 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
Technical support could be faster.
Which solution did I use previously and why did I switch?
We used Trend Micro and Symantec in the past.
How was the initial setup?
The solution was installed together with Endpoint, as a single agent, meaning the licensing covers two products. Similar to Endpoint, the installation was very easy.
What's my experience with pricing, setup cost, and licensing?
We have an annual subscription.
What other advice do I have?
We have 300 users making use of the solution.
I would definitely recommend its use to others.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Stable and easy to use, and integrates with their on-premises firewall
Pros and Cons
- "It's a good antivirus software and has a lot of features. It now integrates with their on-premises firewall, which is perfect."
- "The main real-time scanning takes most of the processing power of my notebook."
What is most valuable?
Their support is located in Egypt, so we like this aspect.
It's a good antivirus software and has a lot of features. It now integrates with their on-premises firewall, which is perfect.
It is stable and easy to use as well.
What needs improvement?
The main real-time scanning is taking most of the processing power of my notebook. This is a big problem.
It would be nice if Sophos Intercept X could provide some of their other features for free. For example, when I wanted to add another feature, like zero-day attack, I was told that I would need to add the license.
Also, it would be good to have a lot more resources.
For how long have I used the solution?
I've been using it for about four or five years.
It's a cloud-based solution.
How are customer service and technical support?
The technical support staff are excellent.
Which solution did I use previously and why did I switch?
I used Symantec antivirus, but when they ended the corporate product of Symantec, I was not able to contact them. It was very difficult to reach them and get support or purchase the antivirus, so I switched.
How was the initial setup?
The installation is straightforward.
What about the implementation team?
I deployed it myself with some technical support. They were able to provide what I needed.
What other advice do I have?
If I were to rate Sophos Intercept X on a scale from one to ten, I would rate it at eight. I would recommend this solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Intercept X Endpoint
June 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
857,028 professionals have used our research since 2012.
eResearch Solution Architect at a educational organization with 1,001-5,000 employees
A good heuristics solution
Pros and Cons
- "I consider the heuristics to be most valuable, the fact that the solution does not work solely on signatures."
- "We are considering switching from this solution as a result of the closer integration needed between the firewall systems and the EDR."
What is most valuable?
I consider the heuristics to be most valuable, the fact that the solution does not work solely on signatures.
What needs improvement?
We are considering switching from this solution as a result of the closer integration needed between the firewall systems and the EDR.
We are not talking about issues with the installation, documentation or interface, but with the existing combination between Sophos Intercept X and our firewalls. This is why we are considering other options.
Moreover, the solution does not offer support for a legacy SAN. However, as this is a legacy issue, it will likely resolve itself eventually.
For how long have I used the solution?
I have been using Sophos Intercept X for close to 15 years.
What do I think about the stability of the solution?
The stability is fine.
How are customer service and technical support?
We have had no problems with technical support.
How was the initial setup?
The installation was fine.
What's my experience with pricing, setup cost, and licensing?
As I am not responsible for paying the bills I cannot comment on the pricing.
What other advice do I have?
I would never rate a solution as a ten out of ten, so I give Sophos Intercept X a rating of eight.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Administrator
Good app control and threat protection
Pros and Cons
- "We find the app control and its threat protection to be the best features."
- "The choices offered for the on-premises and cloud-based platforms are the reverse of each other."
What is most valuable?
We find the app control and its threat protection to be the best features.
What needs improvement?
The app control in respect of the user interface could be improved, The choices offered for the on-premises and cloud-based platforms are the reverse of each other, such as the one responsible for allowing or denying access. This can be confusing initially, even though I later discovered that it is possible to set it back.
What do I think about the stability of the solution?
We are happy with the solution's stability.
What do I think about the scalability of the solution?
The solution is scalable. We continue to add devices to the several sites we have on it without any problem.
How are customer service and technical support?
I haven't had much cause to deal with technical support, although we sometimes require this concerning the email component, particularly in respect of the relay to Office 365.
Which solution did I use previously and why did I switch?
In our ten years we have not worked with another solution before using Sophos Intercept X.
How was the initial setup?
The initial setup was easy.
What's my experience with pricing, setup cost, and licensing?
While I do not have much experience dealing with the price, we have been entitled to a substantial discount on the solution in our use of it as an educational tool.
What other advice do I have?
Our organization has 1,500 end-users making use of the solution.
We require four to five administrators.
The solution sufficiently satisfies one's standard needs, including those of antivirus and app control.
I rate Sophos Intercept X as an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at a tech services company with 501-1,000 employees
Provides us anti-malware capabilities with additional features
Pros and Cons
- "Sophos Intercept X has a host of valuable features, including its anti-malware feature, which we considered key."
- "Features that should be improved in the upgrade involve the excessive consumption of the the solution's processor, RAM and resources."
What is our primary use case?
The solution is deployed concerning all our users, of which there are between 500 and 600. We utilize it for whoever is making use of our company assets.
What is most valuable?
Sophos Intercept X has a host of valuable features, which is why we selected it. These include the prevention of lost data, device and web control, and the application level controls with the anti-malware feature. The anti-malware feature was key for us and we benefit from all these other attendant ones.
What needs improvement?
Features that should be improved in the upgrade involve the excessive consumption of the the solution's processor, RAM and resources.
We have often encountered pain points, such as field users having insufficient resources at their disposal. Their system may offer, say, i3 processor or four GB of RAM, and become slow, owing to the large number of features. While it is okay that this results in the system slowing down, it remains a challenge for us, as our users and employees are complaining that it is becoming progressively slower.
In the next release it would be great to also see VPN integrated or in-built in the solution.
For how long have I used the solution?
We have been deploying Sophos Intercept X for nearly two years.
What do I think about the scalability of the solution?
We have not expanded the solution. As nearly two-and-a-half years have elapsed, the number of users have already been added. We have not increased the number of users in the past year. There is no increase in increment planned for now but, perhaps, there will be in six months' time.
How are customer service and technical support?
As mentioned, we consider the solution's technical support to be good.
How was the initial setup?
The initial setup was straightforward and easy.
Since prior to using Sophos Intercept X we were using the on-premises solution of Sophos Central, our use has exceeded two years.
The deployment took from five to ten days.
What's my experience with pricing, setup cost, and licensing?
The licensing is annual, which means that we have already procured licenses for three years.
We are happy with the pricing across all Sophos products. Comparatively, the cost is very low.
Which other solutions did I evaluate?
Prior to going with Sophos Intercept X, we evaluated McAfee, Trend Micro, Seqrite and Symantec.
What other advice do I have?
Sophos Intercept X does not have any specific version. It started out on-premises but is now cloud-based. As such, we are using it on the cloud, meaning, Sophos Intercept X Advanced.
We use EDR for both solutions.
There are currently around 550 to 600 users making use of the solution across our company.
For someone contemplating implementing the solution who is looking for a single product containing many features, Sophos Intercept X is the best available. It has features like web, application, and device control, as well as DLP. For someone solely interested in an anti-malware solution, but without DLP, Sophos Intercept X would be so-so.
I would rate Sophos Intercept X as an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Director at a comms service provider with 201-500 employees
Very stable although after-sales technical support is lacking
Pros and Cons
- "Very stable solution."
- "The after sales service and support could be improved."
What is our primary use case?
We're currently implementing this solution in our company, but we generally implement it for our clients. I'm a director and we are resellers of Sophos Intercept X.
What is most valuable?
The product is very stable which is great.
What needs improvement?
The after sales service and support could be improved, particularly on the technical side. The solution has room for additional features.
For how long have I used the solution?
I've been using this solution for two years.
What do I think about the stability of the solution?
The product is stable, although one of my clients suffered a bit from downtime. The clients are happy with it.
What do I think about the scalability of the solution?
We purchase different boxes according to the needs of the client, because every single box has a limitation on number of users. The lowest one, which is 110, supports up to 20 users, 10 to 20 users. 125 supports around 30 users and so on. Most of our clients are medium and enterprise size companies.
What's my experience with pricing, setup cost, and licensing?
I'd like to see the price lowered.
What other advice do I have?
Although this is quite an expensive solution when you compare it to products like Automate or Cisco, Sophos does better on pricing.
I rate this solution a seven out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
Technical Manager at Digital World
Comparable pricing, stable and scalable, easy to install
Pros and Cons
- "This solution can be used with any device, mobiles, desktops, or any appliances."
- "When I use a proxy, I can bypass Sophos, which is an area that needs improvement."
What is most valuable?
This solution can be used with any device including mobiles, desktops, or any appliances.
What needs improvement?
When I use a proxy, I can bypass Sophos, which is an area that needs improvement.
For how long have I used the solution?
We have been providing this solution for one year.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's scalable. We have 50 customers.
How are customer service and technical support?
Technical support should be faster.
How was the initial setup?
The initial setup is straightforward. The installation is easy, and it's faster than SAP.
Sophos Intercept can be deployed in a couple of minutes.
It will take one hour to deploy it for a firewall, and only 15 minutes for the endpoint protection.
We need one engineer to deploy this solution.
What's my experience with pricing, setup cost, and licensing?
The price is okay. It's comparable with other solutions.
You can purchase a license for one to three years.
What other advice do I have?
I would recommend this solution.
I have no issues with this solution, I would rate it a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
System Integrator, Sr Security Engineer at a tech services company with 51-200 employees
Good, reliable, and easy to deploy with zero-day protection and lesser price than other solutions
Pros and Cons
- "We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X. We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization."
- "It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day. We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person."
What is most valuable?
We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X.
We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization.
What needs improvement?
It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day.
We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person.
For how long have I used the solution?
I have been using Intercept X with EDR for the last one year. We have its latest version. It is automatically updated through Sophos Central.
What do I think about the stability of the solution?
If an endpoint has at least 4GB RAM and the latest OS, the stability and performance are better. If RAM is too less, there is slowness.
What do I think about the scalability of the solution?
We have implemented it for so many customers. One of them has more than 1,500 users. In an on-prem solution, scalability could be challenging. For example, if you are using 1,000 endpoints and want to add 500 more, you need to expand the server memory or RAM. In a cloud solution, you don't need to do any such thing.
How are customer service and technical support?
They have a very less number of people in their technical team. When I call the Sophos team, it takes more than half an hour to connect to a technical person, which is very challenging. We should be able to get through to them quickly.
How was the initial setup?
Its initial setup is fine. If an end-user is using an old OS version, you need to download the latest patches and all other things. For Windows 10 and higher versions, only the client is downloaded from Sophos Central, and it will automatically sync with the cloud.
What about the implementation team?
I have implemented this solution for so many customers. I am pretty confident in the implementation of Intercept X.
What's my experience with pricing, setup cost, and licensing?
Its price depends on the scenario. It is very expensive, but it is not more expensive than other vendors. The price of Check Point and other vendors is much higher than Sophos.
What other advice do I have?
I would recommend Sophos Intercept X as well as Check Point.
I would rate Sophos Intercept X a ten out of ten. It is a good and reliable solution.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Fortinet FortiClient
Elastic Security
HP Wolf Security
Symantec Endpoint Security
Trellix Endpoint Security Platform
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?