Try our new research platform with insights from 80,000+ expert users

Secureworks Taegis Managed XDR / MDR vs Sophos MDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Secureworks Taegis Managed ...
Ranking in Managed Detection and Response (MDR)
10th
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
13
Ranking in other categories
Managed Security Services Providers (MSSP) (2nd)
Sophos MDR
Ranking in Managed Detection and Response (MDR)
5th
Average Rating
8.6
Reviews Sentiment
7.2
Number of Reviews
30
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of April 2025, in the Managed Detection and Response (MDR) category, the mindshare of Secureworks Taegis Managed XDR / MDR is 4.3%, down from 6.2% compared to the previous year. The mindshare of Sophos MDR is 6.1%, down from 6.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Managed Detection and Response (MDR)
 

Featured Reviews

Tom Kar - PeerSpot reviewer
Has a user-friendly setup process, but its query language needs improvement
The product has valuable features for the EDR section. We can easily isolate affected machines in the network. It helps us prevent the spreading of malware or ransomware further Secureworks Taegis ManagedXDR's query language and stability need improvement. Additionally, its price could be better…
Shaun Gordon - PeerSpot reviewer
Extensive data lake, ease of use is great and you can really get started very quickly
Sophos MDR is a service. MDR is managed detection and response. It's a managed security service. So instead of having an anti-malware, which in Sophos' case would be Intercept X, with MDR, they add human-led threat hunting. It's a managed service. So it's not a product that you sell the client per se. You're selling them a service, which is almost like an SLA, and that includes Cloud MDR. MDR is not a product. It's a service. The reality is that when it comes to the likes of SentinelOne, McAfee, CrowdStrike, ESET, and all the other players out there, they're single-product security companies. CrowdStrike is an anti-malware. That's one thing. ESET, same thing. But if you look at the other vendors, within the appliances, you're looking at Fortinet, Palo Alto, and Checkpoint. They only sell firewalls. That's all they do. When you deal with Sophos, they are the entire product suite. They sell firewalls. They sell Intercept X, which is their anti-malware, Intercept X for Server with anti-malware, email protection with ties into Office 365, and Sophos Plus encryption. All of these security products pull telemetry. So every time somebody hits a firewall, it's called, for argument's sake, that goes into their central data lake. All the firewalls around the world add that information to a data lake. Now, when you're dealing with Sophos, because of their exposure, because they've got so many different products, their data lake is a lot more extensive than competing vendors because they're not relying on one threat factor. They're not relying on one area of expertise. They're a global company. So, I can't compare their telemetry, for instance, to the likes of CrowdStrike. If CrowdStrike has probably started doing appliances, then the users will get that benefit as well. Sophos is the only vendor that does do that. It's like hiring a security team. Sophos do things differently in that they've got more telemetry and more insight into a network because they offer a variety of products. The other part about it is Sophos MDR; the service, unlike other vendors like CrowdStrike, is not limited to their products. If you are running CrowdStrike in your company, for instance, you can get their integration packs, in which case Sophos will manage your CrowdStrike system for you. Whereas with CrowdStrike, it's only CrowdStrike. You are locked into that vendor. So Sophos offers that flexibility. It's a multi-vendor service as opposed to SentinelOne or CrowdStrike, which is a single-vendor service. For instance, if I'm running Sophos, I would like to go with CrowdStrike MDR. I would have to remove my entire security investment, in this case, Sophos, and reinstall CrowdStrike in order to use their service. Sophos doesn't have that problem. If you've got CrowdStrike and you've already invested in CrowdStrike, cool. You stay on CrowdStrike. They will still manage it for you.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution definitely made us way more aware of the possibilities out there."
"This solution gathers the information logs from all devices and correlates all the information. It notifies us of any critical events taking place across our networks which has been valuable."
"There are some patent pending detectors within the platform that provides a lot of value."
"Securworks' threat intel seems pretty decent, and they integrate with several solutions we have, such as Azure AD, so all our Microsoft 365 stuff is covered."
"The pricing is flexible."
"The most valuable feature is the fast alerting and response time."
"We don't have a full SOC, so it's helpful to have them sifting through our alerts and only bringing actionable items to us."
"The most valuable features are IDS and IPS."
"The product as a whole is truly outstanding and it excels in detecting and responding to various types of cyberattacks."
"The user doesn't need a technician; it offers 24/7 support to identify and manage your infrastructure and take complete care of any technological incidents."
"It is stable and scalable. It has good technical support."
"It is a scalable solution."
"There is a feature called XDR Central. With this, Sophos can connect to third-party security solutions."
"I like Sophos MDR's inbuilt feature for DLP (Data Loss Prevention)."
"The important mechanism is the dilation of the desktop. It quarantines and removes threats from the network. Sometimes, security devices similar to firewalls are used. It also creates dynamic rules to protect against attacks. The security cross-synchronization is very important."
"The product’s most valuable feature is ease of use."
 

Cons

"Secureworks Taegis ManagedXDR's query language and stability need improvement."
"We did a PoC of their next-gen antivirus product, but it wasn't ready yet. It was underdeveloped and caused a lot of issues. We'd like to move away from Carbon Black, but they said that it's probably still not to a point where we'd be happy with it. Carbon Black and RedCloak seem to work fine for us."
"The deployment could definitely be improved."
"The integration with the Carbon Black sensor could be better. ManagedXDR doesn't seem to know how to extract the forensic data from an endpoint that was quarantined by Carbon Black."
"Dell Secureworks could improve its integration with other third-party solutions."
"Tamper-proofing or tamper protection is still pending in Secureworks. Tamper protection will make it more secure. If I'm an admin of a device, I can uninstall an agent without the knowledge of the security or Secureworks admin. If someone gets hold of one endpoint with admin credentials, he can remove anything, and an organization will lose visibility. They need to work on providing more visibility across endpoints. A couple of times it has happened that the cloak agent is there, but it did not get activated, or there were some issues. The machine was restarted, but the cloak agent didn't run. In such cases, you have to troubleshoot. It is a big issue if a cyber attack is happening, and your machine is rebooted, but the events are not captured."
"Dell Secureworks is for higher-end customers and it's not quite as straightforward to implement or to get up and running as some of the other solutions."
"In the next release of this solution, I would like to see file integrity monitoring."
"Once in a great while, an update fails."
"One of the limitations that we have found is with communications and the languages in different countries."
"The integration with third-party solutions as an area for slight improvement"
"The solution's integration should be made easier because it is difficult."
"There could be improvement in features like more detailed reporting for the end customer."
"Maybe the reporting needs improvement."
"Sophos is not integrating the same console and umbrella with its product."
"The service could enhance its scope, particularly in managing firewalls."
 

Pricing and Cost Advice

"Initially, the cost was going to be something around $160 or $170. And eventually, I think they brought it down to $110 and they also threw in some endpoint protection platforms."
"It is expensive but there is no better product than this."
"The price is kind of on par. The licensing was comparable to other solutions. It's not particularly high or low."
"Secureworks Taegis ManagedXDR is very expensive and could be more cost-effective."
"The pricing of Dell Secureworks is very reasonable."
"The Red Cloak agent is free."
"The pricing for this solution is reasonable. One agent costs approximately 270 dirhams/70 USD for one year. There is a reduction in cost per licence as the number of licences used increases."
"I rate Sophos MDR’s pricing a seven or eight out of ten."
"Sophos MDR could be more affordable."
"Sophos MDR is less expensive than other products like Fortinet or Palo Alto."
"It is an expensive platform."
"The product is reasonably priced considering the cybersecurity features."
"Compared to other tools, Sophos has a pretty good price."
"The price falls somewhere in the middle range."
"The tool is too expensive for small companies."
report
Use our free recommendation engine to learn which Managed Detection and Response (MDR) solutions are best for your needs.
845,406 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
23%
Manufacturing Company
8%
Financial Services Firm
8%
Government
8%
Computer Software Company
20%
Manufacturing Company
7%
Educational Organization
6%
Government
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Secureworks Taegis ManagedXDR?
The most valuable feature is the support. The support chat. It's always connecting to people. And you open the chat, and it's not about that automated response. It's actually a human being that res...
What is your experience regarding pricing and costs for Secureworks Taegis ManagedXDR?
It is worth the money. It is expensive but there is no better product than this.
What needs improvement with Secureworks Taegis ManagedXDR?
The integration would look better with other products, with other EDRs, with other firewalls, with other older versions of firewalls, and the versions of software and hardware. Then, basically, it'...
What do you like most about Sophos MDR?
The user doesn't need a technician; it offers 24/7 support to identify and manage your infrastructure and take complete care of any technological incidents.
What needs improvement with Sophos MDR?
There could be improvement in features like more detailed reporting for the end customer. For example, reports should be in simple language that is easy to read and understand for management level ...
What advice do you have for others considering Sophos MDR?
I would absolutely recommend Sophos MDR to other organizations. It is rated ten out of ten overall, with a deduction of one point only due to the commercial cost. I'd rate the solution nine out of ...
 

Also Known As

Secureworks Red Cloak Managed Detection and Response, Dell Secureworks, SecureWorks Taegis Managed TDR
Sophos Managed Threat Response
 

Overview

 

Sample Customers

RICOH, Owens and Minor
Information Not Available
Find out what your peers are saying about Secureworks Taegis Managed XDR / MDR vs. Sophos MDR and other solutions. Updated: March 2025.
845,406 professionals have used our research since 2012.