What is our primary use case?
My main use case for Sophos Cloud Optix is for cloud security posture management, as it gives visibility across Azure or other clouds, detecting misconfigurations, automating compliance checks, and helping teams respond faster to threats. Recently, the team running workloads across AWS and Azure used Sophos Cloud Optix to spot over-privileged IAM roles that could be exposing sensitive data, and by visualizing relationships and applying recommendation policies, they reduced risk without slowing down DevOps.
What is most valuable?
Beyond visibility and compliance, I also use Sophos Cloud Optix for IAM analysis, which helps me spot over-privileged accounts and tighten access policies, while the smart alerts give context so my team can react quickly without digging through logs, making daily operations smoother.
The best feature of Sophos Cloud Optix is the multi-cloud visibility and the ability to automate compliance checks. These features have specifically helped my team by providing a single dashboard to see risks across different clouds, in my case, Azure or AWS, which cut investigation time by hours, while automated compliance checks save us days of manual work during audits by producing ready-to-share reports.
One more feature I have found useful in Sophos Cloud Optix is IAM analysis, as it highlights over-privileged accounts and suggests tighter policies, which has improved our governance, and the topology visualization also helps us see relationships between resources and IAM. Sophos Cloud Optix has positively impacted my organization by giving us clear visibility across different clouds, reducing investigation time during incidents, and cutting audit prep from days to hours with automated compliance checks, saving both time and effort, while IAM analysis has helped us tighten access policies and reduce risk.
Since adopting Sophos Cloud Optix, audit prep time has dropped from several days to just a few hours thanks to automated compliance checks, while multi-cloud visibility has cut incident investigation time by nearly fifty percent since we no longer have to jump between AWS and Azure consoles, and IAM analytics have reduced over-privileged accounts by about thirty percent, lowering risk.
What needs improvement?
While I find Sophos Cloud Optix strong, it could improve by reducing alert noise, as I sometimes get too many notifications without enough prioritization, and more customizable compliance reports would help tailor outputs to specific frameworks, and deeper integration with niche cloud services beyond AWS, Azure, and GCP would also add value.
For how long have I used the solution?
I have been using Sophos Cloud Optix for the last two years.
What do I think about the stability of the solution?
Sophos Cloud Optix is stable.
What do I think about the scalability of the solution?
Sophos Cloud Optix's scalability is good.
How are customer service and support?
My experience with customer support has been great, faster, and intelligent. I would rate the customer support an eight on a scale of one to ten.
Which solution did I use previously and why did I switch?
Before using Sophos Cloud Optix, we relied mostly on native AWS tools like GuardDuty or Config, which were useful but did not give us the same unified visibility across multiple clouds.
How was the initial setup?
I purchased Sophos Cloud Optix through the
AWS Marketplace.
What about the implementation team?
I work in IT West.
What was our ROI?
I have seen a return on investment regarding time saved and money saved.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing has been very great, as it is always clear for me.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Sophos Cloud Optix.
What other advice do I have?
I rate Sophos Cloud Optix a nine out of ten because it delivers strong multi-cloud visibility and automated compliance checks that save us significant time, and the IAM analytics and smart alerts have reduced risk and improved governance, while it is easy to deploy and agentless, which keeps our operations smooth.
Regarding Sophos Cloud Optix's AI capabilities, I think its governance and security are strong, as it automates compliance checks and reduces audit complexity while enhancing security through anomaly detection, IAM analytics, and contextual alerts, meaning faster remediation of risks and tighter control over multi-cloud environments. The AI capabilities of Sophos Cloud Optix are generally accurate and reliable, especially for governance and security tasks such as compliance checks.
My advice to others looking into using Sophos Cloud Optix is to start with a pilot across one cloud provider before rolling out multi-cloud, and to pay attention to IAM analytics and compliance automation since those features deliver the biggest value early. My overall rating for this review is a nine out of ten. Clouds mapped with a clear eye, compliance flows without strain, security holds firm.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)