JR
Jennifer R.
"24/7 Monitoring and Proactive Threat Detection"
5/5
What do you like best about Sophos MDR?

I love how Sophos MDR provides 24/7 threat detection and response which our internal team couldn't fully cover. It fills gaps in identifying sophisticated threats, reduces drill time, and provides expert analysis. I appreciate the proactive threat hunting and clear incident reports, which help detect threats early. The seamless integration with existing security tools and prioritized alerts simplify and enhance our response efficiency. Additionally, the combination of automated detection with human analysis offers significant risk reduction and response time, making it a vital extension of our security team and ensuring peace of mind. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

I would like to improve the customization of alert thresholds and notifications because the default settings sometimes generate noise that can be distracting. Having more granular control would help tailor these settings better to our environment and priorities. Review collected by and hosted on G2.com.

Brian D.
BD
Brian D.
Free
Small-Business (50 or fewer emp.)
"Once setup we are extremely satisfied with our experience"
5/5
What do you like best about Sophos MDR?

It removes the onus from our small team, namely myself, of detecting and evaluating and if needed responding to any malicious content. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

Only real thing is the plethora of settings needed to get the system configured initially. This then makes it harder later on to remember why a setting was made if something strange occurs. This is usually due to an OS update or changes in the operations of a third party product or service. Review collected by and hosted on G2.com.

Javier G.
JG
Javier G.
Cybersecurity analyst
Small-Business (50 or fewer emp.)
"Sophos, a practical and economical tool"
4/5
What do you like best about Sophos MDR?

Sophos is very convenient and easy to run and manage. It is simple to use and client installation is very quick. It also has many built-in features and add-ons at a very affordable price. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

One of its main disadvantages is that despite having many ways to customize its operation, it still lacks in terms of complete customization. There are certain options that cannot be altered or can only be added by the manufacturer itself. In addition, it lacks some ways to more efficiently manage registered devices. Review collected by and hosted on G2.com.

Bear R.
BR
Bear R.
VP of Technology
Small-Business (50 or fewer emp.)
"Effortless 24/7 Cybersecurity Monitoring for Our Clients"
5/5
What do you like best about Sophos MDR?

It helps us keep eyes on our clients' cybersecurity 24/7 without actually having to use internal staff to do so. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

No real downsides that I've noticed. There's a little extra setup involved but nothing major. Review collected by and hosted on G2.com.

SS
Stephen S.
IT Manager
Mid-Market (51-1000 emp.)
"Sophos MDR Complete brings peace of mind to cyber security."
5/5
What do you like best about Sophos MDR?

Since implementing Sophos MDR, we have experienced a significant improvement in our security posture. Sophos MDR actively monitors our network and login activity, and they have alerted us to suspicious behavior on our Entra account within just one to two hours of compromise. Moreover, they provide clear, step-by-step remediation guidance, which has been invaluable. For our on-premises infrastructure, we’ve configured the system to allow Sophos to autonomously address any issues they detect. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

The endpoint agent can take a lot of system resources, especially when doing a scan Review collected by and hosted on G2.com.

Verified User in Government Administration
AG
Verified User in Government Administration
Mid-Market (51-1000 emp.)
"Centralized Management Praised Despite Compatibility Issues With Outdated Linux Kernel"
3.5/5
What do you like best about Sophos MDR?

Central management with a single pane of glass and the live human response to our MDR incidents. Not having to check emails or alerts and just knowing that someone will look after the issue is really helpful and less stressful than having to keep an eye on email/teams all the time. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

I haven't run into many downsides yet. The service has caught everything that it has detected since installation. Other than the software is using an outdated version of linux OS, I'm happy. Review collected by and hosted on G2.com.

Verified User in Hospitality
AH
Verified User in Hospitality
Mid-Market (51-1000 emp.)
"Sophos MDR – Strong Security Backbone for Our Organization"
4/5
What do you like best about Sophos MDR?

What I like best about Sophos MDR is its 24/7 expert threat monitoring and rapid incident response, which gives us peace of mind knowing our systems are being actively protected by professionals. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

While Sophos MDR provides excellent threat detection and response, the pricing can be a bit high for smaller organizations, and some advanced configurations may require support assistance, which slightly limits flexibility for in-house teams. Review collected by and hosted on G2.com.

Rafael L.
RL
Rafael L.
Cybersecurity Analyst
Computer & Network Security
Small-Business (50 or fewer emp.)
Business partner of the seller or seller's competitor, not included in G2 scores.
"my opinion about MDR Sophos"
5/5
What do you like best about Sophos MDR?

The proactive threat hunting and rapid incident response are truly what set Sophos MDR apart. Knowing that a team of experts is constantly monitoring our environment gives me unparalleled peace of mind Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

There is nothing to dislike about this solution. It has consistently met and exceeded our expectations, delivering exactly what was promised. Review collected by and hosted on G2.com.

Prashant S.
PS
Prashant S.
Manager SMB Sales
Computer & Network Security
Small-Business (50 or fewer emp.)
"Sophos MDR"
5/5
What do you like best about Sophos MDR?

MDR helps organizations “stop breaches faster, free up time, and sleep better at night” by offloading the burden of threat detection and response.

Top features of Sophos MDR:

1. 24/7 Human-Led Threat Response

2. Proactive Threat Hunting

3.Rapid Incident Response - minimizes breach impact through fast, AI-powered response actions, backed by a global incident response team.

4. Integration with Microsoft Defender - can monitor and respond to Microsoft Security alerts more comprehensively than Microsoft itself, making it a strong co-pilot for hybrid security setups

5. Cyber Insurance Benefits - can lower cyber insurance premiums

6.Unified XDR Platform - enabling visibility across endpoints, servers, firewalls, identity solutions, and cloud tools. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

Common Dislikes and Limitations of Sophos MDR:

1. High Pricing Compared to Competitors is more expensive.

2. Limited Third-Party Integration.

3. Communication and Language Support. Review collected by and hosted on G2.com.

Verified User in Translation and Localization
AT
Verified User in Translation and Localization
Enterprise (> 1000 emp.)
"Solid security operations, but containment needs work"
4/5
What do you like best about Sophos MDR?

What we like best about Sophos MDR is the 24/7 expert threat monitoring and rapid response.

The MDR team acts as an extension of our internal security operations, providing actionable alerts and guided response support, which gives us confidence and peace of mind, especially outside business hours. Their expertise in investigating complex threats and reducing false positives has been a key advantage. Review collected by and hosted on G2.com.

What do you dislike about Sophos MDR?

What we dislike about Sophos MDR is the limited containment in specific threat scenarios.

In a recent case involving the Horabot trojan, MDR did not fully contain the threat — email propagation was not blocked in time, and containment actions required manual follow-up. This revealed a gap in automated response and containment capabilities for advanced or evasive threats. Review collected by and hosted on G2.com.