
Sophos Fusion
Sophos Consolidates Security on an AI-Based Platform



Sophos is rebranding its security portfolio as Sophos Fusion. For businesses, this is more than just a name change: With new components for SIEM, MDR, XDR, AI risks, and security governance, a unified security architecture is taking center stage. Anyone currently planning projects related to managed security, compliance, data retention, or SOC operations should assess these changes early on.
Sophos is gradually transitioning its existing management platform, Sophos Central, to Sophos Fusion. The vendor describes the platform as an AI-Native Cybersecurity Defense System that consolidates data from endpoints, firewalls, identity, networks, email, the cloud, and security operations.
The goal is to create a unified data foundation where detection, response, and policy enforcement work more closely together. According to Sophos, 625,000 organizations already rely on the platform. In Sophos’s own SOC, 52 percent of cases are handled entirely with AI support, and the time from alert to automated response averages 89 seconds.
For existing customers, the name change does not initially require any immediate action. The new name will gradually appear in the console, and existing processes are expected to continue unchanged for the time being.
With Sophos Next-Gen SIEM, Sophos is expanding its offering to include features for extended log retention, compliance reporting, policy monitoring, and additional data sources. Billing will be based on users and servers rather than data volume.
This is particularly relevant for companies with audit requirements, regulatory obligations, or extended retention periods. Previously, many organizations had to deploy an additional SIEM platform for this purpose. Going forward, an option from the Sophos portfolio—closely integrated with XDR and MDR—will be available for this purpose.
Several changes are also coming to Sophos MDR and Sophos XDR:
Particularly notable is the expansion of data sources. According to the announced changes, the number of pre-built integrations is growing significantly. In addition, more than 500 integrations are available system-wide, supplemented by custom parsers and custom data sources. For businesses, this means greater visibility into events without having to invest significant resources to connect each source individually.
With Sophos AI Defense and Sophos CISO Advantage, Sophos is expanding the platform in two directions.
Sophos AI Defense is designed to provide visibility into which AI tools are being used within the organization, including shadow AI. It also includes policy guidelines and protection for the data accessed by these tools. The launch is initially planned as an Early Access release.
Sophos CISO Advantage is aimed at executive management, security officers, and IT leadership. The offering is designed to provide a clearer understanding of cyber risks, compliance requirements, and pending actions. Features planned include continuous monitoring, risk assessment, benchmarking, and support for reporting to executive management.
The announcement is particularly important for companies currently making decisions about MDR, XDR, SIEM, data retention, or compliance. The rebranding itself is not yet a reason to launch a project. The bigger picture lies in the architecture: Sophos is bringing endpoint, network, email, identity, and security operations closer together.
For midsize companies, this can reduce costs and coordination efforts by minimizing the number of standalone solutions running in parallel. For regulated organizations, the new SIEM offering will be of particular interest. And those who already use AI tools in their day-to-day operations should add AI Defense to their list early on.
Sophos is shifting its focus away from individual products toward an end-to-end security architecture. For decision-makers, this is particularly relevant if security data is still spread across multiple tools today and analysis, response, or evidence collection require an unnecessarily high level of effort.
Our recommendation: