This solution can be used with any device including mobiles, desktops, or any appliances.
Technical Manager at a tech services company with 1-10 employees
Comparable pricing, stable and scalable, easy to install
Pros and Cons
- "This solution can be used with any device, mobiles, desktops, or any appliances."
- "When I use a proxy, I can bypass Sophos, which is an area that needs improvement."
What is most valuable?
What needs improvement?
When I use a proxy, I can bypass Sophos, which is an area that needs improvement.
For how long have I used the solution?
We have been providing this solution for one year.
What do I think about the stability of the solution?
It's a stable product.
Buyer's Guide
Intercept X Endpoint
January 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
What do I think about the scalability of the solution?
It's scalable. We have 50 customers.
How are customer service and support?
Technical support should be faster.
How was the initial setup?
The initial setup is straightforward. The installation is easy, and it's faster than SAP.
Sophos Intercept can be deployed in a couple of minutes.
It will take one hour to deploy it for a firewall, and only 15 minutes for the endpoint protection.
We need one engineer to deploy this solution.
What's my experience with pricing, setup cost, and licensing?
The price is okay. It's comparable with other solutions.
You can purchase a license for one to three years.
What other advice do I have?
I would recommend this solution.
I have no issues with this solution, I would rate it a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
System Integrator, Sr Security Engineer at a tech services company with 51-200 employees
Good, reliable, and easy to deploy with zero-day protection and lesser price than other solutions
Pros and Cons
- "We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X. We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization."
- "It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day. We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person."
What is most valuable?
We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X.
We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization.
What needs improvement?
It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day.
We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person.
For how long have I used the solution?
I have been using Intercept X with EDR for the last one year. We have its latest version. It is automatically updated through Sophos Central.
What do I think about the stability of the solution?
If an endpoint has at least 4GB RAM and the latest OS, the stability and performance are better. If RAM is too less, there is slowness.
What do I think about the scalability of the solution?
We have implemented it for so many customers. One of them has more than 1,500 users. In an on-prem solution, scalability could be challenging. For example, if you are using 1,000 endpoints and want to add 500 more, you need to expand the server memory or RAM. In a cloud solution, you don't need to do any such thing.
How are customer service and technical support?
They have a very less number of people in their technical team. When I call the Sophos team, it takes more than half an hour to connect to a technical person, which is very challenging. We should be able to get through to them quickly.
How was the initial setup?
Its initial setup is fine. If an end-user is using an old OS version, you need to download the latest patches and all other things. For Windows 10 and higher versions, only the client is downloaded from Sophos Central, and it will automatically sync with the cloud.
What about the implementation team?
I have implemented this solution for so many customers. I am pretty confident in the implementation of Intercept X.
What's my experience with pricing, setup cost, and licensing?
Its price depends on the scenario. It is very expensive, but it is not more expensive than other vendors. The price of Check Point and other vendors is much higher than Sophos.
What other advice do I have?
I would recommend Sophos Intercept X as well as Check Point.
I would rate Sophos Intercept X a ten out of ten. It is a good and reliable solution.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Intercept X Endpoint
January 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,757 professionals have used our research since 2012.
Service Delivery Engineer - Network Security Lead at a tech services company with 51-200 employees
Built-in AI, intelligent scanning, easy to use interface, and easy to manage from a single panel
Pros and Cons
- "This is really good because it's applicable to zero-day threats."
- "The security is good but the feature set is limited."
What is our primary use case?
We use this solution for endpoints and a firewall.
What is most valuable?
The most valuable feature is the AI functionality.
It really does intelligent scanning to know if it really is a threat or not.
This is really good because it's applicable to zero-day threats.
The engine that is behind the Intercept X is really good because it has AI in-built.
The UI, the user interface it's really simple and straightforward.
The management is quite simple. it is backed up on the cloud. From the cloud, you can manage all of your devices through the firewall, including the endpoint solution and the email solutions. They are all managed in one panel.
It's a straightforward product. I don't see anything that they can change.
One of the best parts of Sophos is manageability. You will find in the organization you just have one portal where we just manage all of the devices in one place.
It's very simple. You just run an agent with the machine that communicates with the cloud portal. it is very simple to manage.
What needs improvement?
When comparing the security, I feel that Fortinet has more features as compared to Sophos Intercept X. As such, the feature set needs improvement. They should offer more with the firewall.
For example, Fortinet has a web application, it has application control, it has antivirus, and it has anti-malware. It offers many features.
Sophos is a bit behind when it comes to the features of the firewall itself.
The security is good but the feature set is limited.
They can up their marketing strategies. They need to increase their marketing efforts.
For how long have I used the solution?
I have been using Sophos Intercept X for one year.
We are using the latest version.
What do I think about the stability of the solution?
It's a very stable product.
What do I think about the scalability of the solution?
It's a scalable solution.
We have 100 users in our organization.
We have plans to continue using this solution.
How are customer service and technical support?
Technical support is very good.
Which solution did I use previously and why did I switch?
I was using Kaspersky for endpoints. I changed back because Kaspersky was using too many resources on my machine. Also, I changed because of the complexity.
How was the initial setup?
The installation was straightforward.
It took a day and a half.
The deployment for a medium enterprise can be done by one engineer unless they are deploying several appliances.
What about the implementation team?
I implemented this solution myself. We did not use an integrator or vendor.
What's my experience with pricing, setup cost, and licensing?
Licensing costs are not expensive.
What other advice do I have?
They have the hardware for different products, different appliances for different specifications.
Sophos bought Cyberoam. People who were Cyberoam customers needed to migrate to the Sophos platform. They could migrate to the Sophos platform while they were still on the Cyberoam product or the Cyberoam appliances.
You can see the kind of work that went back into backward compatibility of the Sophos platform to the Cyberoam platform.
People could actually migrate from that Cyberoam to Sophos, and their licenses as well.
Overall, I am perfectly satisfied with the product. I have no complaints.
I would definitely recommend Sophos Intercept X to others who are interested in using it.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Tanium Subject Matter Expert at a tech services company with 51-200 employees
Good web filtering with an excellent central console and the capability to scale
Pros and Cons
- "The package we use also comes with spam filtering features, which are quite useful."
- "The initial setup can be a bit challenging."
What is our primary use case?
We primarily brought on the solution to replace Symantec's product, as Symantec was purchased by Broadcom. The company in question has a lot of stuff, and 40 users, and is a pure Windows environment. They don't do anything on Mac or Linux, for example.
What is most valuable?
So far, the solution has been working quite well.
Sophos offers a manuscript response.
The product has three tiers that you can choose from when you buy. The highest is a Managed Threat Response. We chose the middle range, which offers Intercept X and is more than just Malware protection.
This solution is a kind of Next-Gen anti-virus.
The product has some web filtering, which blocks people from going to websites they shouldn't be going to.
It supports the Windows 10 server platform.
The solution offers a centralized view of the status of protection, via a central console for users to check the status or the health of the endpoints.
So far, the solution has met all our expectations. It's blocked malicious websites effectively and stopped people from going to places online that they shouldn't be going to. It's automatic. We simply took the default settings and we were finding people right away that were going to illicit sites, and we were able to see that easily in the console.
The package we use also comes with spam filtering features, which are quite useful.
What needs improvement?
We're still new to the solution. We haven't come across any weakness yet. There aren't features that are missing.
The initial setup can be a bit challenging.
For how long have I used the solution?
I just deployed the solution a few weeks ago. It's quite new at this point. We've had it now for a little over a month.
What do I think about the stability of the solution?
The solution is extremely stable. It doesn't crash or freeze. There aren't bugs and glitches. It's kept us safe. Nothing has gotten through. It's reliable.
What do I think about the scalability of the solution?
Currently, the company only has 40 users, and therefore there are no scalability issues so far. However, it's a cloud-based centralized console, so that will help with scaling in the future if the company decides to expand. It wouldn't be hard to do. It's completely achievable.
How are customer service and technical support?
Technical support is okay. I'd give them higher scores if I didn't have to contact them about the initial console setup. That said, they were helpful. Their service so far has been about average.
Which solution did I use previously and why did I switch?
We previously used Symantec.
We switched solutions for a few reasons. The first one is that Symantec was bought by Broadcom and there were some unknowns about what would happen with the product. Support typically gets worse when Broadcom buys a product, and we wanted to step away on the off-chance that could happen in the near future.
We were also looking to consolidate and to find a replacement but to also get something that had spam protection and something that was easily obtainable for a small business. Sophos ultimately could hit all those checkmarks.
How was the initial setup?
The initial setup with the centralized console was a little bit challenging. It wasn't complex per se, however, due to the fact that the instructions weren't clear, you can get stuck at certain points. I opened up a case for support, and at that point, I was able to get under the console. You could say the onboarding of additional administrators was a challenge. The centralized console was also a bit difficult.
After that, the implementation was pretty easy. You simply remove the old one, add the new one, and then, with the new one, you could send the user an email link, or you could send them a path to where the software is.
What's my experience with pricing, setup cost, and licensing?
I do not know the exact costs offhand, however, it's my understanding that their pricing is listed publicly on their site and would be easy to find. Sophos seemed surprised that their pricing was public. They were shocked that I could just Google it and it came up.
There are extra add-ons you can purchase over and above this product. The add-ons cost a bit more, however, they offer extra security advantages.
What other advice do I have?
We are a reseller.
We deployed the latest version of the solution. I don't have the version number on hand, however.
It's a good product to consider if a company is looking to also do spam filtering. What Sophos has as well as a firewall, and it'll give a company a little bit of tighter integration, and that's good. Having those additional security tools as add-ons is an excellent option. We personally haven't gotten their firewall yet, however, it is nice that that is an option.
I would rate the solution at an eight out of ten. Overall, in the short amount of time we've used it, we've had a positive experience.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Vice President at a tech services company with 1,001-5,000 employees
Good detection recommendations, good patching and pretty decent protection capabilities
Pros and Cons
- "The patches on offer are very helpful."
- "We've had difficulty with uninstalling the solution. When we try to uninstall an old version of the basic Sophos Antivirus, it doesn't seem to uninstall completely."
How has it helped my organization?
We upgraded the EDR and so far it's doing good. It patches the things that we weren't able to patch in previous antivirus hardships.
What is most valuable?
The solution has very useful response modules where we can get the recommendation on what needs to be done every day around detection.
The patches on offer are very helpful.
It's pretty good at protecting us as an anti-virus.
What needs improvement?
We've had difficulty with uninstalling the solution. When we try to uninstall an old version of the basic Sophos Antivirus, it doesn't seem to uninstall completely. Due to this issue, when we installed Intercept X, we had installation conflicts. The company needs to figure out a way to make installing their old products easier and more complete.
For how long have I used the solution?
We bought this solution in the middle of last year. It hasn't been an extremely long amount of time.
How was the initial setup?
The only issue we had with Sophos during installation was a problem around removing old versions of Sophos products from machines so that we could properly install Intercept X. There seemed to be some residual aspects of the older version, and that affected our ability to install the newer version. It was quite a headache for us.
Which other solutions did I evaluate?
We've been looking at Symantec and have been looking for information to compare it to Sophos. We're trying to decide which of these we'd use as the standard solution.
What other advice do I have?
We're just a customer and end-user. We don't have a special business relationship with Sophos.
Overall, I would rate the solution at a nine out of ten. We've had a very positive experience so far.
Aside from issues with overwriting old Sophos versions, it's been a pretty solid product.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder and General Manager at a tech services company with 11-50 employees
Stable with good pricing and rather simple to use
Pros and Cons
- "The pricing is fair. It's not too costly for our small organization."
- "It could be a bit easier to implement."
What is our primary use case?
We use the solution and we are also reseller of it. We offer it to our clients as well.
We primarily use the solution for security in order to protect our users and our endpoints.
What is most valuable?
The simplicity of the product is very good. I'm not a very technical person, therefore, the ease of use is very much appreciated.
Integrations are pretty easy to handle. That's very helpful to us.
The pricing is fair. It's not too costly for our small organization.
What needs improvement?
I can't think of any features that are lacking.
The solution needs to ensure it is keeping up with the latest malware defenses and security advancements.
It could be a bit easier to implement.
For how long have I used the solution?
I've been using the solution for a couple of years at this point. It's been a while.
What do I think about the stability of the solution?
The stability of the solution of pretty good. We've never had issues with instability. It's reliable. There aren't bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution can scale. If a company needs to expand it out, it can do so with ease.
We are a relatively small organization. Therefore, we don't have too many people using the solution. There are 20 of us, give or take.
How are customer service and technical support?
I've never used technical support. I can't speak to their level of knowledge or how quickly they respond.
How was the initial setup?
The initial setup has a moderate amount of difficulty. It's not too hard or too easy.
I'm not sure how long deployment generally takes, however.
What's my experience with pricing, setup cost, and licensing?
The solution isn't too expensive. We're pretty happy with the pricing.
What other advice do I have?
We are a small company and we don't use enterprise-class solutions. Our customers are mainly mid-size companies. I am a reseller. However, I do use this solution within our organization.
We're using the latest version of the solution. I'm not sure of the exact version number at this time.
I'd recommend the solution to other organizations. We've been happy with it so far.
Overall, I would rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Senior IT Analyst at a insurance company with 51-200 employees
Good ransomware security with an easy initial setup and good scalability potential
Pros and Cons
- "The initial setup is simple."
- "It's a challenge to do system maintenance work on a notebook. You always have to disable Sophos first."
What is our primary use case?
We primarily use the solution as endpoint protection as well as for endpoint detection and response. It's like an EDR. It's basically used to prevent ransomware.
How has it helped my organization?
I would say that it's difficult to really say how it's improved our organization. We had never actually been hit by a ransomware attack prior to installing Sophos and never had Sophos tell us that we're experiencing one. That said, it's very important to be protected. Getting attacked would be a disaster.
What is most valuable?
We were looking for something that could sense ransomware attempts, to encrypt files, and cut off and reverse attacks as well as alert us to issues. That's what the Intercept X is designed to do. It's very good at security and protection. It offers very good reports.
The initial setup is simple.
The biggest feature that's on the server version that we're using, the EDR, is the ability to push data on threats that it's seeing over to another management platform, like a managed detection response service. It's nice that it's possible to do this and we don't have to pay so much attention to the alerts. They can for us.
What needs improvement?
It's a challenge to do system maintenance work on a notebook. You always have to disable Sophos first. Otherwise, it thinks you're a virus. It would be ideal if there was some sort of setting where you could warn the system it's just you in there doing routine maintenance.
For how long have I used the solution?
I've used the solution over the last couple of years. However, I haven't used the product too heavily.
What do I think about the stability of the solution?
The stability is relatively good. We've had a few false alarms, however, there's nothing major that's happened so far. It seems free of bugs and glitches. It doesn't crash or freeze. It's good.
What do I think about the scalability of the solution?
I haven't personally tried to scale anything. It's probably pretty scalable because you don't have an appliance. Appliances have limitations as they have a set size or capacity. It is a cloud-based console, therefore it can probably scale pretty well.
We have 80 people in our organization and everybody uses the product.
How are customer service and technical support?
I'd rate technical support pretty high. I'd give them an eight out of ten. They're helpful. They are knowledgeable and responsive. We've been satisfied with the level of attention we get when we need them.
Which solution did I use previously and why did I switch?
We didn't have anything previously for anti-ransomware. We just had the Kaspersky antivirus. However, it wasn't able to detect ransomware specifically. Therefore, we put Sophos Intercept X on to do that.
How was the initial setup?
We've found the initial setup is pretty straightforward. It's not overly complex. We didn't have trouble setting everything up.
What other advice do I have?
We're using the latest version of the solution.
We've got Sophos Intercept X on the notebook computers along with Kaspersky and then on the servers it's only Sophos EDR, which has both antivirus and Intercept X. All are bundled together.
The console's on the cloud and that's just installed on the clients, however, they all communicate with a self-hosted JIRA cloud console.
I'd advise those considering the solution to probably just go with the antivirus portion as well. That way, you've got it all under one console. We're juggling two consoles, Kaspersky and Sophos. It would be easier if everything was under one.
ON a scale from one to ten, I'd rate this product at a nine. We've been very happy with it.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Country Manager at a tech services company with 1-10 employees
Good usability with helpful technical support and reliable stability
Pros and Cons
- "The solution has very good usability."
- "The initial setup can be difficult if you don't come in with at least some knowledge about the product."
What is our primary use case?
We primarily use the solution in order to check the correct flow of the workstations.
What is most valuable?
We have the complete solution. We try to see if we have any malware, ransomware, in our workstations, and detect and respond. It's very good at detection.
The solution has very good usability.
So far, it's working quite well for us and we've been very happy with it.
We don't often need support, however, when we do, they've been quite helpful.
If you have good hardware and a good memory, you won't have a problem with this solution's performance at all.
What needs improvement?
The solution is pretty complete and works well for our organization. I can't recall not having any specific feature on hand.
The initial setup can be difficult if you don't come in with at least some knowledge about the product.
The solution can run slower on older computers. When you do a scan, you need to configure the scan to run in the time not when your traffic is high. The performance can be affected if the traffic is high and you are trying to scan. This isn't really the solution's fault. It may be an issue with the robustness of the machine
For how long have I used the solution?
I've been using the solution for around two years now. It hasn't been too long.
What do I think about the stability of the solution?
The stability is very good. We have no complaints in this area. It doesn't crash or freeze. It's not buggy. It's reliable.
What do I think about the scalability of the solution?
Personally, I have not tried to scale the solution, and therefore can't speak to the scalability itself. For our organization and its size, it works well. We have approximately 100 people in the company.
How are customer service and technical support?
We've used technical support in the past. I've found them to be very good. We're quite happy with their level of service, even if we very rarely need to call on them. I'd give them very high marks - maybe 9.5 out of ten for the level of support they provide.
How was the initial setup?
The initial setup can be challenging for those that come in blind with no prior knowledge of the solution. That said, we're pretty knowledgable, so we went in knowing the product and therefore we didn't really have trouble in that sense.
You need to make the deployment, and you need to put the agent in the workstation. That is the most difficult part of the solution. If the company is not centralized, the deployment of the solution is hard. That can be true for any product, actually. However, if you have some solution, for example, to make the deployment of different software for you, you can make the deployment easier. That way, you can centralize the configuration, and set the configuration for the complex platform.
For us, it took two weeks to a month to deploy the solution with the assistance of a software platform. However, that can vary according to the company and its size and environment.
What other advice do I have?
We're partners with Sophos.
I'm not sure which version of the solution I'm using.
When implementing Sophos Intercept, other organizations need to know that the deployment can be a bit difficult. It's a good solution with a challenging implementation. YOu really need to centralize your deployment. If you have a solution that can help ease the deployment process, it's worth it.
Overall, we are very happy with it. I'd rate it at a ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
Fortinet FortiGate
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Fortinet FortiEDR
IBM Security QRadar
HP Wolf Security
Cortex XDR by Palo Alto Networks
Huntress Managed EDR
Elastic Security
Microsoft Defender XDR
WatchGuard Firebox
Trellix Endpoint Security Platform
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?














