Security Architecture, MSSP, EDR, MDR, SOC, Endpoint/Device Security, Identity

Sophos Fusion brings endpoint, SIEM, identity and MDR into one security system

Sophos has launched Sophos Fusion, a new platform that brings endpoint, network, identity, email, cloud, and security operations into one system. Fusion builds on Sophos Central and adds analytics from Secureworks Taegis, following Sophos’ acquisition of Secureworks in 2025. The platform pulls data from Sophos products and third-party tools into one shared system. That means a threat detected in one part of the environment can trigger a response somewhere else.

Sophos says Fusion can investigate and respond to some incidents automatically, within rules set by security teams. Human analysts step in when a case requires judgment, business context, or direct coordination with the customer.

Sophos builds on Secureworks Taegis

Sophos says its own managed security operation shows how the model works at scale. The company’s agentic security operations center supports more than 40,000 customers. According to Sophos, AI fully resolves 52% of cases, with an average of 89 seconds between an alert and an automated response.

Rob Harrison, senior vice president of product management at Sophos, told MSSP Alert, “The 52% figure reflects real-world cases in our MDR operation that were fully handled through agentic workflows without requiring analyst intervention. These are typically high-confidence situations where the system has sufficient context to detect, investigate, and execute an appropriate response within predefined operating boundaries.”

The automated cases tend to be incidents where Sophos has enough information to identify the activity, determine the appropriate response, and act without escalating the case to an analyst. More uncertain situations remain with the human security team.

“Where humans remain essential is in situations involving ambiguity, novel attacker behavior, business context, or decisions with broader organizational impact,” Harrison said. “For example, when an incident requires judgment about business risk, investigation of previously unseen techniques, or coordination with a customer on a complex response strategy, our analysts step in.”

New SIEM, AI security, and MDR features

Sophos plans to add several new Fusion capabilities between August and October 2026, with Sophos Next-Gen SIEM, MDR, and the rebuilt Sophos XDR platform scheduled for general availability on Aug. 15. The SIEM service will add long-term data retention, compliance reporting, and analytics, with pricing based on users and servers rather than data volume.

The MDR update will add continuous AI-enabled threat hunting and broader response across endpoint, firewall, cloud, email, and identity systems. Sophos XDR will use Secureworks Taegis analytics and add thousands of detectors, automated playbooks, and built-in security orchestration and response.

Sophos AI Defense will enter early access in August and become generally available in October. It is designed to help organizations identify approved and unauthorized AI tools, enforce usage policies, and control access to company data.

Sophos CISO Advantage is also expected in October. The service will combine control validation, compliance mapping, risk assessments, threat intelligence, and peer benchmarking with advisory support delivered through Sophos’ MSP network.

What Sophos Fusion means for MSPs and MSSPs

For Sophos partners, Fusion creates a more consolidated operating environment for managing customer security services. Many MSPs still manage several security products that generate separate alerts, require different workflows, and provide limited context about what is happening elsewhere in the customer environment. Fusion is designed to connect those controls so they can share intelligence and coordinate response actions.

“Sophos Fusion gives MSPs more than a unified platform; it delivers a coordinated cybersecurity defense system,” Harrison said. “While many MSPs today manage 5–7 security tools that operate in silos, Sophos Fusion enables security controls to share intelligence, coordinate response actions, and function as a single defense system across endpoint, network, cloud, email, and MDR.”

MSPs and MSSPs would be able to oversee endpoint, firewall, cloud, email, identity, and managed detection services through the same system. That could reduce the number of consoles and manual handoffs involved in investigating an incident and coordinating a response.

“Sophos Fusion is designed to reduce operational complexity by allowing partners to manage customers through one coordinated system where telemetry, detections, investigations, and response actions work together,” Harrison said. “That helps reduce operational overhead while creating opportunities to deliver additional high-value services.”

Sophos also sees Fusion as a way for partners to expand accounts over time. An MSP could begin with endpoint security or a firewall deployment, then add MDR, email security, identity protection, XDR, or advisory services as the customer’s requirements change.

“The MSP opportunity is both operational and commercial,” Harrison said. “Partners can start anywhere- endpoint, firewall, email, MDR/XDR - and seamlessly expand into adjacent services as customer needs evolve, creating flexible, expandable service offerings.”

CISO Advantage is a key part of that services strategy. It gives partners a framework for offering risk assessments, compliance guidance, control validation, and ongoing security leadership alongside technical services.

“On the revenue side, Fusion expands the opportunity beyond traditional product sales into recurring strategic service offerings (MDR, CISO Advantage, advisory services), allowing deeper customer relations for MSPs,” Harrison said. “We believe the combination of greater operational efficiency and broader service offerings creates a stronger economic model for partners.”

Sophos has not yet provided detailed partner data showing how Fusion affects margins, staffing requirements, or service delivery costs. Harrison said the company plans to work with partners to track those results as the system reaches the market.

“As Sophos Fusion enters the market, we'll continue working closely with partners to measure and demonstrate those operational and financial outcomes,” he said.


Suparna Chawla Bhasin

Suparna is the Senior Managing Editor for CyberRisk Alliance’s Channel Brands, including MSSP Alert and ChannelE2E. She manages content development, sharpens editorial workflows, and ensures storytelling is tightly aligned with audience needs. With a background in technology, media, and education, she combines strategic insight with creative execution.

You can skip this ad in 5 seconds