I consider the heuristics to be most valuable, the fact that the solution does not work solely on signatures.
eResearch Solution Architect at a educational organization with 1,001-5,000 employees
A good heuristics solution
Pros and Cons
- "I consider the heuristics to be most valuable, the fact that the solution does not work solely on signatures."
- "I consider the heuristics to be most valuable, the fact that the solution does not work solely on signatures."
- "We are considering switching from this solution as a result of the closer integration needed between the firewall systems and the EDR."
- "We are considering switching from this solution as a result of the closer integration needed between the firewall systems and the EDR."
What is most valuable?
What needs improvement?
We are considering switching from this solution as a result of the closer integration needed between the firewall systems and the EDR.
We are not talking about issues with the installation, documentation or interface, but with the existing combination between Sophos Intercept X and our firewalls. This is why we are considering other options.
Moreover, the solution does not offer support for a legacy SAN. However, as this is a legacy issue, it will likely resolve itself eventually.
For how long have I used the solution?
I have been using Sophos Intercept X for close to 15 years.
What do I think about the stability of the solution?
The stability is fine.
Buyer's Guide
Intercept X Endpoint
May 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
895,990 professionals have used our research since 2012.
How are customer service and support?
We have had no problems with technical support.
How was the initial setup?
The installation was fine.
What's my experience with pricing, setup cost, and licensing?
As I am not responsible for paying the bills I cannot comment on the pricing.
What other advice do I have?
I would never rate a solution as a ten out of ten, so I give Sophos Intercept X a rating of eight.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Manager at a financial services firm with 10,001+ employees
Good cost and easy to interact with, but needs threat hunting capabilities and better DLP module
Pros and Cons
- "It is easy to interact with, and its cost is also good."
- "It is easy to interact with, and its cost is also good."
- "The Data Loss Prevention module can be better. It should also have threat hunting capabilities."
- "The Data Loss Prevention module can be better. It should also have threat hunting capabilities."
What is most valuable?
It is easy to interact with, and its cost is also good.
What needs improvement?
The Data Loss Prevention module can be better. It should also have threat hunting capabilities.
For how long have I used the solution?
I am really new to it because I just joined a new organization. It has not even been two weeks.
What do I think about the stability of the solution?
Its stability is good so far.
What do I think about the scalability of the solution?
It is scalable.
What's my experience with pricing, setup cost, and licensing?
Its cost is good.
What other advice do I have?
I would recommend it for small and medium enterprises. I would rate Sophos Intercept X a six out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Intercept X Endpoint
May 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
895,990 professionals have used our research since 2012.
Administrator
Good app control and threat protection
Pros and Cons
- "We find the app control and its threat protection to be the best features."
- "We find the app control and its threat protection to be the best features."
- "The choices offered for the on-premises and cloud-based platforms are the reverse of each other."
- "The choices offered for the on-premises and cloud-based platforms are the reverse of each other, such as the one responsible for allowing or denying access."
What is most valuable?
We find the app control and its threat protection to be the best features.
What needs improvement?
The app control in respect of the user interface could be improved, The choices offered for the on-premises and cloud-based platforms are the reverse of each other, such as the one responsible for allowing or denying access. This can be confusing initially, even though I later discovered that it is possible to set it back.
What do I think about the stability of the solution?
We are happy with the solution's stability.
What do I think about the scalability of the solution?
The solution is scalable. We continue to add devices to the several sites we have on it without any problem.
How are customer service and technical support?
I haven't had much cause to deal with technical support, although we sometimes require this concerning the email component, particularly in respect of the relay to Office 365.
Which solution did I use previously and why did I switch?
In our ten years we have not worked with another solution before using Sophos Intercept X.
How was the initial setup?
The initial setup was easy.
What's my experience with pricing, setup cost, and licensing?
While I do not have much experience dealing with the price, we have been entitled to a substantial discount on the solution in our use of it as an educational tool.
What other advice do I have?
Our organization has 1,500 end-users making use of the solution.
We require four to five administrators.
The solution sufficiently satisfies one's standard needs, including those of antivirus and app control.
I rate Sophos Intercept X as an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Engineer at a tech services company with 10,001+ employees
Stable, easy to deploy, and has valuable firewall synchronization feature
Pros and Cons
- "Synchronization with the firewall is most valuable."
- "Synchronization with the firewall is most valuable."
- "When we load Intercept X, it puts a load on the device. When it is scanning, it slows down the device. A system with basic specifications completely slows down till the scan is complete. They should improve this part."
- "When we load Intercept X, it puts a load on the device. When it is scanning, it slows down the device."
What is most valuable?
Synchronization with the firewall is most valuable.
What needs improvement?
When we load Intercept X, it puts a load on the device. When it is scanning, it slows down the device. A system with basic specifications completely slows down till the scan is complete. They should improve this part.
For how long have I used the solution?
I have been using this solution for more than a year.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
We have roughly 500 to 550 users.
How are customer service and technical support?
For Intercept X, the support was good, but for the firewall part, we have to wait a lot for the support to be online.
How was the initial setup?
It is very easy.
What other advice do I have?
I would rate Sophos Intercept X an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Technical Manager at Digital World
Comparable pricing, stable and scalable, easy to install
Pros and Cons
- "This solution can be used with any device, mobiles, desktops, or any appliances."
- "The initial setup is straightforward, the installation is easy, and it's faster than SAP, with Sophos Intercept deployable in a couple of minutes, taking about one hour for a firewall and only 15 minutes for endpoint protection, needing just one engineer."
- "When I use a proxy, I can bypass Sophos, which is an area that needs improvement."
- "When I use a proxy, I can bypass Sophos, which is an area that needs improvement."
What is most valuable?
This solution can be used with any device including mobiles, desktops, or any appliances.
What needs improvement?
When I use a proxy, I can bypass Sophos, which is an area that needs improvement.
For how long have I used the solution?
We have been providing this solution for one year.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's scalable. We have 50 customers.
How are customer service and technical support?
Technical support should be faster.
How was the initial setup?
The initial setup is straightforward. The installation is easy, and it's faster than SAP.
Sophos Intercept can be deployed in a couple of minutes.
It will take one hour to deploy it for a firewall, and only 15 minutes for the endpoint protection.
We need one engineer to deploy this solution.
What's my experience with pricing, setup cost, and licensing?
The price is okay. It's comparable with other solutions.
You can purchase a license for one to three years.
What other advice do I have?
I would recommend this solution.
I have no issues with this solution, I would rate it a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
System Integrator, Sr Security Engineer at a tech services company with 51-200 employees
Good, reliable, and easy to deploy with zero-day protection and lesser price than other solutions
Pros and Cons
- "We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X. We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization."
- "We find all features valuable."
- "It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day. We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person."
- "We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person, which is very challenging."
What is most valuable?
We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X.
We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization.
What needs improvement?
It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day.
We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person.
For how long have I used the solution?
I have been using Intercept X with EDR for the last one year. We have its latest version. It is automatically updated through Sophos Central.
What do I think about the stability of the solution?
If an endpoint has at least 4GB RAM and the latest OS, the stability and performance are better. If RAM is too less, there is slowness.
What do I think about the scalability of the solution?
We have implemented it for so many customers. One of them has more than 1,500 users. In an on-prem solution, scalability could be challenging. For example, if you are using 1,000 endpoints and want to add 500 more, you need to expand the server memory or RAM. In a cloud solution, you don't need to do any such thing.
How are customer service and technical support?
They have a very less number of people in their technical team. When I call the Sophos team, it takes more than half an hour to connect to a technical person, which is very challenging. We should be able to get through to them quickly.
How was the initial setup?
Its initial setup is fine. If an end-user is using an old OS version, you need to download the latest patches and all other things. For Windows 10 and higher versions, only the client is downloaded from Sophos Central, and it will automatically sync with the cloud.
What about the implementation team?
I have implemented this solution for so many customers. I am pretty confident in the implementation of Intercept X.
What's my experience with pricing, setup cost, and licensing?
Its price depends on the scenario. It is very expensive, but it is not more expensive than other vendors. The price of Check Point and other vendors is much higher than Sophos.
What other advice do I have?
I would recommend Sophos Intercept X as well as Check Point.
I would rate Sophos Intercept X a ten out of ten. It is a good and reliable solution.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Service Delivery Engineer - Network Security Lead at a tech services company with 51-200 employees
Built-in AI, intelligent scanning, easy to use interface, and easy to manage from a single panel
Pros and Cons
- "This is really good because it's applicable to zero-day threats."
- "Overall, I am perfectly satisfied with the product."
- "The security is good but the feature set is limited."
- "The security is good but the feature set is limited."
What is our primary use case?
We use this solution for endpoints and a firewall.
What is most valuable?
The most valuable feature is the AI functionality.
It really does intelligent scanning to know if it really is a threat or not.
This is really good because it's applicable to zero-day threats.
The engine that is behind the Intercept X is really good because it has AI in-built.
The UI, the user interface it's really simple and straightforward.
The management is quite simple. it is backed up on the cloud. From the cloud, you can manage all of your devices through the firewall, including the endpoint solution and the email solutions. They are all managed in one panel.
It's a straightforward product. I don't see anything that they can change.
One of the best parts of Sophos is manageability. You will find in the organization you just have one portal where we just manage all of the devices in one place.
It's very simple. You just run an agent with the machine that communicates with the cloud portal. it is very simple to manage.
What needs improvement?
When comparing the security, I feel that Fortinet has more features as compared to Sophos Intercept X. As such, the feature set needs improvement. They should offer more with the firewall.
For example, Fortinet has a web application, it has application control, it has antivirus, and it has anti-malware. It offers many features.
Sophos is a bit behind when it comes to the features of the firewall itself.
The security is good but the feature set is limited.
They can up their marketing strategies. They need to increase their marketing efforts.
For how long have I used the solution?
I have been using Sophos Intercept X for one year.
We are using the latest version.
What do I think about the stability of the solution?
It's a very stable product.
What do I think about the scalability of the solution?
It's a scalable solution.
We have 100 users in our organization.
We have plans to continue using this solution.
How are customer service and technical support?
Technical support is very good.
Which solution did I use previously and why did I switch?
I was using Kaspersky for endpoints. I changed back because Kaspersky was using too many resources on my machine. Also, I changed because of the complexity.
How was the initial setup?
The installation was straightforward.
It took a day and a half.
The deployment for a medium enterprise can be done by one engineer unless they are deploying several appliances.
What about the implementation team?
I implemented this solution myself. We did not use an integrator or vendor.
What's my experience with pricing, setup cost, and licensing?
Licensing costs are not expensive.
What other advice do I have?
They have the hardware for different products, different appliances for different specifications.
Sophos bought Cyberoam. People who were Cyberoam customers needed to migrate to the Sophos platform. They could migrate to the Sophos platform while they were still on the Cyberoam product or the Cyberoam appliances.
You can see the kind of work that went back into backward compatibility of the Sophos platform to the Cyberoam platform.
People could actually migrate from that Cyberoam to Sophos, and their licenses as well.
Overall, I am perfectly satisfied with the product. I have no complaints.
I would definitely recommend Sophos Intercept X to others who are interested in using it.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Tanium Subject Matter Expert at a tech services company with 51-200 employees
Good web filtering with an excellent central console and the capability to scale
Pros and Cons
- "The package we use also comes with spam filtering features, which are quite useful."
- "So far, the solution has met all our expectations."
- "The initial setup can be a bit challenging."
- "The initial setup with the centralized console was a little bit challenging."
What is our primary use case?
We primarily brought on the solution to replace Symantec's product, as Symantec was purchased by Broadcom. The company in question has a lot of stuff, and 40 users, and is a pure Windows environment. They don't do anything on Mac or Linux, for example.
What is most valuable?
So far, the solution has been working quite well.
Sophos offers a manuscript response.
The product has three tiers that you can choose from when you buy. The highest is a Managed Threat Response. We chose the middle range, which offers Intercept X and is more than just Malware protection.
This solution is a kind of Next-Gen anti-virus.
The product has some web filtering, which blocks people from going to websites they shouldn't be going to.
It supports the Windows 10 server platform.
The solution offers a centralized view of the status of protection, via a central console for users to check the status or the health of the endpoints.
So far, the solution has met all our expectations. It's blocked malicious websites effectively and stopped people from going to places online that they shouldn't be going to. It's automatic. We simply took the default settings and we were finding people right away that were going to illicit sites, and we were able to see that easily in the console.
The package we use also comes with spam filtering features, which are quite useful.
What needs improvement?
We're still new to the solution. We haven't come across any weakness yet. There aren't features that are missing.
The initial setup can be a bit challenging.
For how long have I used the solution?
I just deployed the solution a few weeks ago. It's quite new at this point. We've had it now for a little over a month.
What do I think about the stability of the solution?
The solution is extremely stable. It doesn't crash or freeze. There aren't bugs and glitches. It's kept us safe. Nothing has gotten through. It's reliable.
What do I think about the scalability of the solution?
Currently, the company only has 40 users, and therefore there are no scalability issues so far. However, it's a cloud-based centralized console, so that will help with scaling in the future if the company decides to expand. It wouldn't be hard to do. It's completely achievable.
How are customer service and technical support?
Technical support is okay. I'd give them higher scores if I didn't have to contact them about the initial console setup. That said, they were helpful. Their service so far has been about average.
Which solution did I use previously and why did I switch?
We previously used Symantec.
We switched solutions for a few reasons. The first one is that Symantec was bought by Broadcom and there were some unknowns about what would happen with the product. Support typically gets worse when Broadcom buys a product, and we wanted to step away on the off-chance that could happen in the near future.
We were also looking to consolidate and to find a replacement but to also get something that had spam protection and something that was easily obtainable for a small business. Sophos ultimately could hit all those checkmarks.
How was the initial setup?
The initial setup with the centralized console was a little bit challenging. It wasn't complex per se, however, due to the fact that the instructions weren't clear, you can get stuck at certain points. I opened up a case for support, and at that point, I was able to get under the console. You could say the onboarding of additional administrators was a challenge. The centralized console was also a bit difficult.
After that, the implementation was pretty easy. You simply remove the old one, add the new one, and then, with the new one, you could send the user an email link, or you could send them a path to where the software is.
What's my experience with pricing, setup cost, and licensing?
I do not know the exact costs offhand, however, it's my understanding that their pricing is listed publicly on their site and would be easy to find. Sophos seemed surprised that their pricing was public. They were shocked that I could just Google it and it came up.
There are extra add-ons you can purchase over and above this product. The add-ons cost a bit more, however, they offer extra security advantages.
What other advice do I have?
We are a reseller.
We deployed the latest version of the solution. I don't have the version number on hand, however.
It's a good product to consider if a company is looking to also do spam filtering. What Sophos has as well as a firewall, and it'll give a company a little bit of tighter integration, and that's good. Having those additional security tools as add-ons is an excellent option. We personally haven't gotten their firewall yet, however, it is nice that that is an option.
I would rate the solution at an eight out of ten. Overall, in the short amount of time we've used it, we've had a positive experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
Fortinet FortiGate
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cortex XDR by Palo Alto Networks
Cloudflare One
SentinelOne Singularity Endpoint
IBM Security QRadar
Elastic Security
Huntress Managed EDR
HP Wolf Security
Trellix Endpoint Security Platform
WatchGuard Firebox
Microsoft Defender XDR
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?















