No more typing reviews! Try our Samantha, our new voice AI agent.
Victor Bayedo - PeerSpot reviewer
Cloud Solution Architect at a tech services company with 201-500 employees
Real User
Top 5
Jan 25, 2022
Allows us to achieve synchronized security, whereby we are able to see an automatic isolation of infected devices or compromised devices on the network
Pros and Cons
  • "The most valuable feature is the anti-ransomware capability, which has been helpful because we have been seeing a lot of information around what the ransomware hit and Sophos was able to prevent it from ruining the environment."
  • "The detection and the AI capabilities should be improved upon."
  • "It's a big issue that there isn't a way to do remote deployment. It's actually difficult because you have to depend on a third party to make sure it actually works."

What is our primary use case?

We use the solution for endpoint protection and particularly against ransomware. There is CryptoGuard capability within Intercept X. They're also competitive, so people actually leverage it to test the environment against ransomware. It also has the capability to send a warning in any attack. Say they want to assist in the environment so that we are able to run a case incident. I know what has happened, what's happening right now, and then probably what we need to be concerned about.

We have used the solution on-premise previously, but we currently use it on cloud.

I'm aware the on-premise is fading out, so I'm migrating other clients that are running companies to the cloud.

What is most valuable?

The most valuable feature is the anti-ransomware capability. It's been helpful because we have been seeing a lot of information around what the ransomware hit. It would have actually hit the environment before it was protected and Sophos was able to prevent it from ruining the environment. Sophos does this with the firewall to be able to achieve synchronized security, whereby we are able to see an automatic isolation of infected devices or compromised devices on the network.

What needs improvement?

The detection and the AI capabilities should be improved upon. I also find it narrow of an attack. Even though we have Sophos running on the network, we still have the system being hit. That was probably because Sophos is not running our data. 

Improvement should actually be made on remote capabilities. I would like to see additional features that provide capabilities that show a lot of sources that the attackers are actually making.

For how long have I used the solution?

I have been using this solution since it was released. We are working with the latest update.

Buyer's Guide
Intercept X Endpoint
August 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.

What do I think about the stability of the solution?

The solution is stable and reliable.

What do I think about the scalability of the solution?

It is easy to scale.

How are customer service and support?

Technical support is good.

Which solution did I use previously and why did I switch?

Previously, I worked with McAfee. I also have experience using Kaspersky.

McAfee has a component for exploit prevention which works similarly to Intercept X. I've actually seen Intercept X working better than that, especially because in Intercept X you're also leveraging from machine learning.

How was the initial setup?

It's a big issue that there isn't a way to do remote deployment. It's actually difficult because you have to depend on a third party to make sure it actually works. I'm inexperienced on third party use, and it becomes very tedious and almost unmanageable. We have to start helping customers fix their issues at no cost.

The solution requires maintenance, but it is automated.

What's my experience with pricing, setup cost, and licensing?

It's not bad, but compared to competitors, it's a little bit on the high side. The price could be more competitive.

What other advice do I have?

I would rate this solution 9 out of 10. I would recommend Intercept X to other users.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Muzamil Yakub - PeerSpot reviewer
Chief Executive Officer at Infoview Limited
Reseller
Top 5
Jan 9, 2022
Beneficial policy management, automatic endpoint updates, simple installation
Pros and Cons
  • "Sophos Intercept X is a very effective solution and its being cloud-based is a benefit. Wherever my users are, I can apply policies to them. In the era of mobility, when users are out of the office or they're in different locations, it doesn't matter."
  • "The solution has great protection against anti-ransomware and all of the zero-day threats."
  • "From the management side, we receive detailed information. Sophos has many features, such as Threat Hunting but that comes with the XDR version of the solution. There's Sophos Intercept X and then there's Sophos Intercept X with XDR technology. We bought the XDR and then now the MTR, Managed Threat Response version available too. They have different packages for clients which gives them different options to pick from. If Sophos could combine more features into one package it would be beneficial."

What is our primary use case?

We are using Sophos Intercept X for endpoint protection.

What is most valuable?

Sophos Intercept X is a very effective solution and its being cloud-based is a benefit. Wherever my users are, I can apply policies to them. In the era of mobility, when users are out of the office or they're in different locations, it doesn't matter. 

Whenever a user gets infected, as an admin, we get notified. We have many options to pick from, the ability to send policies to the endpoints is a very good feature that they have.

Whenever there is an update all the agents on the end-users systems automatically update.

We have the option of caching updates on the network, which allows us to save on bandwidth. For example, if we have 100 people in the office, we can deploy an internal caching server or a message link server, so not all computers need a connection to Sophos onto the cloud.

Sophos Intercept X integrates with their other solution very well, such as the XG Firewall. The feature is called Synchronized Security.

What needs improvement?

From the management side, we receive detailed information. Sophos has many features, such as Threat Hunting but that comes with the XDR version of the solution. There's Sophos Intercept X and then there's Sophos Intercept X with XDR technology. We bought the XDR and then now the MTR, Managed Threat Response version available too. They have different packages for clients which gives them different options to pick from. If Sophos could combine more features into one package it would be beneficial.

For how long have I used the solution?

I have been using Sophos Intercept X for approximately five years.

What do I think about the stability of the solution?

Sophos Intercept X is highly stable.

What do I think about the scalability of the solution?

I have found Sophos Intercept X to be scalable.

We have approximately 40 clients using this solution.

How are customer service and support?

I'm a Sophos certified architect to myself, and as a partner, from the vendor, we have excellent support. We have not had a problem with the technical support, they are always available for communication, such as online chat or on-call.

Which solution did I use previously and why did I switch?

We have used Kaspersky, ESET, Bitdefender, and Symantec solutions.

How was the initial setup?

The installation is very easy. If someone is not on the network, you can send them an invite by email and they would only need to install the agent, and everything will work perfectly.

The time the installation takes depends on the internet connection. Sometimes it takes only five minutes and other times it can take up to 10 minutes. It all depends on the connection because it has to download the installer.

What about the implementation team?

The end-user can install the solution themself. It is very easy. It is only a two to three-step process it is complete. 

Many people are using this solution and some customers don't even have IT managers, we provide them manage services I this case.

What was our ROI?

The solution has great protection against anti-ransomware and all of the zero-day threats. The ROI is very good.

What's my experience with pricing, setup cost, and licensing?

There is a license required to use this solution.

If it's a managed services provider contract that we have with the customer, then they pay monthly. Depends on the customer, what the requirements are. They can pay either monthly or annually to us, but we have to pay annually to the vendor.

Which other solutions did I evaluate?

Before choosing Sophos Intercept X we evaluated Kaspersky, ESET, Bitdefender, and Symantec. For some of our clients who are using the other products, now they've shifted to Sophos Intercept X.

What other advice do I have?

I would recommend this solution to others.

I rate Sophos Intercept X a ten out of ten.

Which deployment model are you using for this solution?

Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Intercept X Endpoint
August 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
reviewer1581882 - PeerSpot reviewer
Sr Manager - Information Security & Researcher at a tech services company with 1,001-5,000 employees
Real User
Sep 3, 2021
Straightforward installation, secure, but could be more user-friendly
Pros and Cons
  • "The most valuable feature of the solution is that it is less hash-based than competitors."
  • "The primary use of the solution is to block threats, and it contains a quick queries engine that can help us figure out where all threats are coming from."
  • "I would like the solution to have more functions and to be more user-friendly."

What is our primary use case?

The primary use of the solution is to block threats. It contains a quick queries engine that can help us figure out where all threats are coming from.

What is most valuable?

The most valuable feature of the solution is that it is less hash-based than competitors.

What needs improvement?

I would like the solution to have more functions and to be more user-friendly. 

In the next release, the solution could have more use cases. For example, protection against ransomware.

For how long have I used the solution?

I have used the solution for approximately one month. 

What do I think about the stability of the solution?

I find the solution to be stable and secure. However, there are some operational issues with the hashing algorithm.

What do I think about the scalability of the solution?

We have 7000 uses in our organization using the solution. 

Which solution did I use previously and why did I switch?

I have used Falcon CrowdStrike and Kaspersky.

How was the initial setup?

The installation of the solution is straightforward and took approximately two days for tuning. 

What about the implementation team?

The solution was deployed by the vendor team, using approximately three administrators.

What's my experience with pricing, setup cost, and licensing?

The solution requires an annual subscription. 

What other advice do I have?

I rate Sophos Intercept X a seven out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
PeerSpot user
Head Of Information Security at a manufacturing company with 1,001-5,000 employees
Real User
Sep 2, 2021
Easy to set up and stable but lacks responsive technical support
Pros and Cons
  • "The initial setup is pretty straightforward."
  • "The solution is stable; from what I have witnessed, it doesn't crash or freeze and there are no bugs or glitches, and historically, the performance has been good and I have found it to be reliable."
  • "They don't have the full stack of offerings as compared to the other competitive products that we see."
  • "The support on offer isn't ideal. In terms of the support on offer, for example, if there was a zero-day kind of attack or something, the turnaround time that Sophos offers is not acceptable."

What is our primary use case?

We are using Sophos as an endpoint protection solution.

What is most valuable?

It's too early for me to really evaluate the solution at this company, as I've only been at the organization for a month. That said, I have used Sophos before.

So far, the protection aspect seems to be good. 

I have used Sophos in my previous job and it has been a stable product. 

The product scales well. 

The initial setup is pretty straightforward. 

What needs improvement?

The challenge with Sophos is whenever there's an escalation to a level 3 or level 4 or a certain kind of important issue, or if you want to reach out to the leadership, it's difficult to do so.

They don't have the full stack of offerings as compared to the other competitive products that we see.

For how long have I used the solution?

While I've only been at the organization for about one month, it's my understanding that the company has been using the solution for about a year.

What do I think about the stability of the solution?

The solution is stable. From what I have witnessed, it doesn't crash or freeze and there are no bugs or glitches. Historically, the performance has been good and I've found it to be reliable. 

What do I think about the scalability of the solution?

The solution is very scalable. If a company needs to expand it, it can do so. It's not a problem.

We have about 5,000 users on the solution currently.

How are customer service and technical support?

The support on offer isn't ideal. In terms of the support on offer, for example, if there was a zero-day kind of attack or something, the turnaround time that Sophos offers is not acceptable. They should improve their responsiveness. We are not 100% satisfied. 

I've only been at this company for one month and have yet to contact technical support on behalf of this company.

How was the initial setup?

The installation process is very simple and straightforward. It's not overly complex or difficult. A company should have any issues handling deployments. 

Which other solutions did I evaluate?

Currently, we are considering other solutions and may move away from this product.

What other advice do I have?

We're just customers and end-users. The company does not have a business relationship with Sophos. 

I cannot speak to the exact version of the solution we're using. My understanding is that we are on whatever the latest version is. 

I'd rate the solution at a seven out of ten.

I wouldn't recommend the solution at this time as we are considering going to another solution. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
it_user1551411 - PeerSpot reviewer
Technology Infrastructure Manager at a non-profit with 201-500 employees
Real User
Aug 12, 2021
Not resource-intensive and does a good job of stopping and preventing different threats from being triggered
Pros and Cons
  • "It is very easy to set up and easy to use. It is also not resource-intensive."
  • "It is very easy to set up and easy to use, it is also not resource-intensive, has been very stable, and has done a good job of stopping and preventing different threats from being triggered."
  • "Sophos has a lot of different features. Some of them are tied to different clients, which may mean that different prices or licenses have to be added on. It can be a little bit confusing if you're not familiar with the logic of how they work. They can make it a little bit clearer."

What is our primary use case?

We are using it for endpoint antivirus, hardening, and some DLP policies. Its version is the current one.

What is most valuable?

It is very easy to set up and easy to use. It is also not resource-intensive.

It has been very stable. It has done a good job of stopping and preventing different threats from being triggered.

What needs improvement?

Sophos has a lot of different features. Some of them are tied to different clients, which may mean that different prices or licenses have to be added on. It can be a little bit confusing if you're not familiar with the logic of how they work. They can make it a little bit clearer.

For how long have I used the solution?

I have been using this solution for about a year and a half. 

What do I think about the stability of the solution?

Systems have been stable during deployment. It is not resource-intensive, and it has been working well.

What do I think about the scalability of the solution?

It has been easy to add additional Sophos components. They all are using the same console. We have about 400 users who are using this solution.

Which solution did I use previously and why did I switch?

We were using Symantec. We switched because we just needed something that was a little bit more aggressive and next-generation from an antivirus perspective.

How was the initial setup?

It is very easy to set up.

What about the implementation team?

We had a third party that helped us set it up.

What's my experience with pricing, setup cost, and licensing?

It was fairly and reasonably priced.

What other advice do I have?

I would advise others to thoroughly vet out because Sophos has a lot of different features. It can be a little bit confusing in terms of licensing.

I would rate Sophos Intercept X a solid eight out of 10.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT Coordinator at a pharma/biotech company with 51-200 employees
Real User
May 19, 2021
Services perform well, minimal resources, and synchronizes well with other solution
Pros and Cons
  • "The solution is overall quite good, the services are performing well, and it is very good for those who are using standard PC configurations because it does not block their system by taking up a lot of resources."
  • "This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it."

What is our primary use case?

We are not only using Sophos Endpoint with this solution, we are also using Sophos Email Security and firewall. It is a completely synchronized security package.

What is most valuable?

The solution is overall quite good, the services are performing well. It is very good for those who are using standard PC configurations. It does not block their system up by taking up a lot of resources. 

What needs improvement?

This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it. I do not think a lot of companies know about this solution, it could be a lack of marketing that is the reason why it is not at the top.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the scalability of the solution?

The solution is very good for small-sized businesses.

How are customer service and technical support?

The technical support sometimes is a bit delayed, but sometimes they are responding very fast. Overall they are good but could improve on the times they are having delays.

Which solution did I use previously and why did I switch?

Previously we used McAfee for our endpoint protection for our company. It was very problematic, it was using up a lot of resources and delaying the work of users. Users were not able to do multitasking in the system. It is blocking all access to our server at the time of scanning. We decided to move to some other good antivirus. After analyzing the market, we found Sophos. Sophos is best for the standard configuration PC.

Which other solutions did I evaluate?

Due to some circumstances, we are going to switch from this solution to Symantec. Additionally, we have evaluated Kaspersky before choosing Symantec as the replacement for this solution. Kaspersky has had a very good rating amongst review sites along with Symantec.

What other advice do I have?

I rate Sophos Intercept X a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
CEO & MD at Gurjartech
Real User
May 15, 2021
A good solution with good stability and good price
Pros and Cons
  • "It is stable and has a good price. I find it very good."
  • "I would definitely recommend this solution."
  • "They need to focus on their SLA or technical support. They also need to focus on their UI. They should also improve their content filtering tool and update it so that correct categories are there. Sometimes, when I want to block an online gaming website, it is not shown under the correct category. It is shown under another category. They need to review their content filtering tool on a bi-weekly or monthly basis and update the sites and categories. This will be really helpful for them."
  • "They need to work on their SLA or technical support. Their technical support is not as good as Cisco's support."

What is our primary use case?

My client is a BPO with three branches. One branch is in the US, and two branches are in India. We are using Sophos for the best connectivity. We are using Sophos for endpoint, DLP, and encryption. We are also using it for content filtering and managing security policies. Currently, we are using its latest version.

What is most valuable?

It is stable and has a good price. I find it very good.

What needs improvement?

They need to focus on their SLA or technical support. They also need to focus on their UI.

They should also improve their content filtering tool and update it so that correct categories are there. Sometimes, when I want to block an online gaming website, it is not shown under the correct category. It is shown under another category. They need to review their content filtering tool on a bi-weekly or monthly basis and update the sites and categories. This will be really helpful for them.

For how long have I used the solution?

I have been using this solution for two to three years.

What do I think about the stability of the solution?

I am happy with its stability.

What do I think about the scalability of the solution?

I have not scaled it. Currently, I have only one client who is using it.

How are customer service and technical support?

They need to work on their SLA or technical support. Their technical support is not as good as Cisco's support. 

They get back in one or two hours, which is not good enough for a security or firewall solution. This is because an organization's security and all the outgoing and incoming traffic depends on the firewall. When they take one hour and two hours to provide the support, an organization is in danger during that whole duration. There are many threats on the internet, and they need only five minutes to hack.

Which solution did I use previously and why did I switch?

We also work with Fortinet, Palo Alto, and Check Point solutions. If a client has Check Point, we work with that. Similarly, if a client has Sophos, we work with Sophos. We have knowledge of different end products. As compared to Cisco ASA, Sophos is good. However, Palo Alto and Check Point are better than Sophos.

How was the initial setup?

If you have more than five years of experience in network security or network administration, it is easy, but if you are a fresher, it is very difficult.

In terms of duration, it takes two days for it to be completely functional in production. Just connecting it doesn't take more than three to four hours.

What's my experience with pricing, setup cost, and licensing?

Price-wise, it is good. Currently, we have a three-year plan.

What other advice do I have?

I would definitely recommend this solution. I find it very good. If you have an experienced engineer with more than five years of experience, you can easily maintain a Sophos solution. An experienced engineer would not require any support and will be capable of handling it. However, if you have someone with two or three years of experience, it will be difficult to handle all the features.

I would rate Sophos Intercept X an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1500162 - PeerSpot reviewer
Chief Information Officer/Senior Vice President at a tech services company with 51-200 employees
Real User
Feb 24, 2021
A scalable and secure solution with additional security features and proxy rules and settings
Pros and Cons
  • "There are additional security features in Sophos Intercept X as well as proxy rules and settings that help us in minimizing the sites that our agents can go to, even after their work hours."
  • "We have been a client of Sophos for close to nine or ten years, and we have not been compromised with ransomware or anything like that during this period."
  • "We had some initial problems with our deployment, and they were more around uninstalling Sophos Basic and installing Sophos Intercept X. We had some challenges with some of the uninstallation scripts. They can improve the deployment of Sophos Intercept X when there is already an existing Sophos version. They can also provide more information in the form of best practices and lessons learned from previous findings. A knowledge base with this type of information would be helpful."
  • "We had some initial problems with our deployment, and they were more around uninstalling Sophos Basic and installing Sophos Intercept X."

What is our primary use case?

We have split our operations into work at home and on-premise. We have over 2,000 or 3,000 work-at-home agents. Some of them do not connect to us via a virtual private network. They connect directly to our CRM clients. In order for us to ensure that we have visibility and to be able to protect our PCs, we are using Sophos Intercept X via the cloud.

How has it helped my organization?

We have been a client of Sophos for close to nine or ten years, and we have not been compromised with ransomware or anything like that during this period. The whole Sophos solution set has been very useful.

What is most valuable?

There are additional security features in Sophos Intercept X as well as proxy rules and settings that help us in minimizing the sites that our agents can go to, even after their work hours. 

What needs improvement?

We had some initial problems with our deployment, and they were more around uninstalling Sophos Basic and installing Sophos Intercept X. We had some challenges with some of the uninstallation scripts. They can improve the deployment of Sophos Intercept X when there is already an existing Sophos version. They can also provide more information in the form of best practices and lessons learned from previous findings. A knowledge base with this type of information would be helpful.

For how long have I used the solution?

We've been a Sophos client for close to nine or ten years. We started using Sophos Intercept X last year.

What do I think about the stability of the solution?

After everything is deployed, I've not heard anything negative from my team. It seems stable. 

What do I think about the scalability of the solution?

Given that it is a cloud implementation, Intercept X is very scalable.

We have about 6,000 or 7,000 users. The majority of them are customer service agents. We are using both Sophos Basic and Intercept X, and our plan is to migrate the rest of the nodes to Sophos Intercept X. However, our migration plan might change because we are getting a requirement for Cynet from our clients who use Cynet. They are about 4,000 in number. 

How are customer service and technical support?

We are rather satisfied. It has not gone to that level where I have to escalate to Sophos Philippines for support. The only pain point that we had was related to the installation and deployment, given that we had to deploy outside of our network.

How was the initial setup?

We had some initial problems with our deployment, and it was more around uninstalling Sophos Basic and installing Sophos Intercept X. 

Its setup was rather complex because we support different clients, and the configuration of the PCs of each client is different. If every PC is the same, the initial setup might be straightforward, but we support over 30 different campaigns, which makes it challenging. We were able to deploy it for 2,000 or 3,000 agents, but it was not as seamless as we wanted it to be. It ended up taking four or five months.

What about the implementation team?

We had Sophos Philippines and a local partner of theirs to assist us in this whole process. Overall, the experience was positive, but it could have been better. We could have received some more assistance from Sophos, either Sophos Philippines or Sophos headquarters, in terms of script development. Some of the issues were resolved by my own engineers by tweaking some scripts.

What's my experience with pricing, setup cost, and licensing?

I am not sure about the cost. I would guess it to be between $50 to $60 per license. This would be the cost of the overall subscription. There is no additional fee.

What other advice do I have?

At this point, we are kind of positive about Sophos Intercept X. Our overall experience, after the deployment challenges, has been rather good.

I would rate Sophos Intercept X an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1265688 - PeerSpot reviewer
Manager of Information Security at a healthcare company with 1,001-5,000 employees
Real User
Jan 24, 2021
Reliable, user-friendly, good price, and useful for malware protection and application blocking
Pros and Cons
  • "Malware protection and application blocking are absolutely great. The DLP and malware features are very helpful. It is also very user-friendly, reliable, and scalable. It is easy to set up. We are also happy with its price and support."
  • "Malware protection and application blocking are absolutely great."
  • "Mobile device management is a challenging area, and it can be improved. Some areas in the DLP solution can also be improved. It has the DLP capability, but it is not an all-out DLP program. I would like to see them improve the DLP solution in terms of reporting and possibly network monitoring. Currently, they only do the reporting parts of it."
  • "Mobile device management is a challenging area, and it can be improved."

What is our primary use case?

We use it for all of its features, with the exception of mobile device management. We use it for DLP, malware protection, some forms of asset tracking, application blocking, and so forth.

It is deployed on-premises and on the cloud. We are using its latest version.

What is most valuable?

Malware protection and application blocking are absolutely great. The DLP and malware features are very helpful.

It is also very user-friendly, reliable, and scalable. It is easy to set up. We are also happy with its price and support.

What needs improvement?

Mobile device management is a challenging area, and it can be improved. Some areas in the DLP solution can also be improved. It has the DLP capability, but it is not an all-out DLP program. I would like to see them improve the DLP solution in terms of reporting and possibly network monitoring. Currently, they only do the reporting parts of it.

For how long have I used the solution?

I have been using this solution for close to two years.

What do I think about the stability of the solution?

It is a very reliable solution.

What do I think about the scalability of the solution?

It is very easily scalable. We have scaled it, and we had very minor problems in expanding it across the organizations and new acquisitions.

How are customer service and technical support?

They provide a great response. They are available through email and phone calls. After you create a ticket, they will respond within 24 hours.

Which solution did I use previously and why did I switch?

We've only used Symantec. Symantec is nowhere near this solution.

How was the initial setup?

The initial setup was straightforward.

What about the implementation team?

Our team did the deployment. We got the training from them, and we did the deployment ourselves.

What's my experience with pricing, setup cost, and licensing?

Compared to other solutions, such as CrowdStrike, we are most certainly happy with its pricing. We did a three year-business deal.

What other advice do I have?

I most certainly would recommend this solution. One of the recommendations would be to make sure that you have a plan and a dedicated team to be able to manage all of the functions that are in the Sophos solution.

I would rate Sophos Intercept X an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1364232 - PeerSpot reviewer
IT Manager at a construction company with 201-500 employees
Real User
Dec 24, 2020
Excellent at capturing malicious threats together with an aggressive next generation firewall
Pros and Cons
  • "Anti-virus captures malicious threats and an aggressive next generation firewall."
  • "To date, we haven't had any incidents related to viruses or any types of attacks and we barely get any false positives."
  • "Deployment on cloud needs to be carried out manually."
  • "If you start with the standard solution, move to Intercept X, and then go to the EDR version, it's almost double the price in comparison to other vendors."

What is our primary use case?

The main use cases of this solution are for protection from ransomware and malware. Although we don't have EDR because of its high cost, we do have the capability to filter the website. Our use case is more about capturing crypto and the like that can encrypt files. I'm a system administrator and we are customers of Sophos. 

What is most valuable?

I've found that the most valuable feature is the anti-virus that captures malicious threats and the next generation firewall which is more aggressive in terms of not only looking for viruses, but also for SaaS and the movement of equipment. If something strange comes up we're automatically notified and it's either blocked or quarantined. It enables you to prevent future viruses and enables us to inform the user of malicious websites they have visited.

To date, we haven't had any incidents related to viruses or any types of attacks and we barely get any false positives. It's good to know that any malicious anti-virus detected is automatically blocked, although it makes things more difficult for our IT department.

What needs improvement?

There is an issue when deploying on cloud because it needs to be done manually. For an enterprise company that can have 10,000 or even 50,000 end users, it's a lot to deploy manually. An additional feature they might include would be the ability to control the lockdown on hardware; to control all the entry points such as a USB, a camera or any external storage. 

For how long have I used the solution?

I've been using this solution for three years. 

What do I think about the stability of the solution?

I think this solution is stable. It doesn't allow you to do anything that may cause a problem. If you try to download something that is prone to hacking, the solution won't allow it. It's important to use the admin lock to prevent malicious programs being downloaded. It's good at preventing remote users from downloading malware. 

What do I think about the scalability of the solution?

The solution is very scalable because they don't generally deal with small size office deployments of 10 or 15 users. The solution can scale to 100,000 or even up to 200,000 users.  

How are customer service and technical support?

Initially we didn't have phone support, but now it's part of the enterprise portfolio which we have. We only use the support if we have an issue with the server. It's the benefit of the cloud, there are no concerns about the server whereas on-premise you need to synchronize your server or upgrade the new version to get those features.

Which solution did I use previously and why did I switch?

We migrated from Symantec enterprise to Sophos and SentinelOne. The approach is the same for all of them. 

How was the initial setup?

Initial setup for the cloud is very straightforward because it's managed by the company. It's just a matter of downloading the agent and installing to your end point. The on-premise implementation is more difficult, particularly if you're not familiar with it but the support is very helpful. I believe there's a way to roll out without the need to visit individual users. I believe they integrate with an active directory, and then post from there. Deployment time depends on availability of the user's desktop or and/or laptop. If it's on premise, you can push that one, it would take less than 15 minutes. To deploy in a company would take less than a month. 

What's my experience with pricing, setup cost, and licensing?

If you start with the standard solution, move to Intercept X, and then go to the EDR version, it's almost double the price in comparison to other vendors. It's a choice for any company. Check Point's SandBlast, for example, has two payables but the additional payable includes encrypting your hard drive - not everyone needs that feature. 

What other advice do I have?

This is a good product but it comes at a high price. As a result, I would rate this solution an eight out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros sharing their opinions.