Try our new research platform with insights from 80,000+ expert users
reviewer1439172 - PeerSpot reviewer
Project Manager at a tech services company with 11-50 employees
Real User
Easy to use, straightforward to set up, and it's effective against critical problems including ransomware
Pros and Cons
  • "The most valuable features are ease of use and the GUI."
  • "We would like to deploy across a variety of machines simultaneously through the network."

What is our primary use case?

This security solution covers most of the critical problems such as ransomware.

What is most valuable?

The most valuable features are ease of use and the GUI. The interface is very subjective. Personally, I am fine with it. However, some people don't like it. Generally speaking, I would say that it is easy to use.

They have a free version that is installed on mobile phones, which is very good.

The integration with my AP works well.

What needs improvement?

The price of this product should be reduced because it is a little high.

We would like to deploy across a variety of machines simultaneously through the network.

For how long have I used the solution?

We have been using Sophos Intercept X for the past month.

Buyer's Guide
Intercept X Endpoint
September 2025
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.

What do I think about the stability of the solution?

So far, I haven't seen any bugs in this product, so the stability is good.

What do I think about the scalability of the solution?

Scalability-wise, Sophos Intercept X is good. We have close to 100 users, who are mostly salespeople.

How are customer service and support?

We have not engaged with technical support.

How was the initial setup?

The initial setup is straightforward and not complicated. Deployment-wise, this solution is okay. It is easy to get the agents up.

One problem is that we want to know if there is a way to deploy the agent without going to every machine if I am upgrading from another product. Locally, I have to go machine by machine to complete the installation.

What about the implementation team?

We deployed by ourselves.

What other advice do I have?

My advice for anybody who is considering this product is that if you want ease of use for a good price, and something that addresses most of the endpoint protection needs, then this is the best solution to implement.

Generally, I like this product compared to other endpoint solutions and I don't have many complaints. The vendor just has to keep it up or continue to improve. That said, it cannot stop every virus so it is not perfect.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1418319 - PeerSpot reviewer
IT Infrastracture Consultant at a healthcare company with 201-500 employees
Consultant
Behavioral-based protection that is user-friendly and easy to deploy
Pros and Cons
  • "The most valuable feature is the behavioral, non-signature-based threat detection."
  • "When there is an event generated by either the firewall or Intercept X, and the originating IP address is the same, these should be merged into a single event rather than two."

What is our primary use case?

We were recently the target of a ransomware attack and we used this product to clean it from our environment. Our in-place endpoint protection is just signature-based and it was not able to identify which device had passed the malware.

I am in charge of monitoring at this time.

How has it helped my organization?

Once we installed Intercept X, it was able to detect and remove malware that could not be found by the simple endpoint security solution.

What is most valuable?

The most valuable feature is the behavioral, non-signature-based threat detection.

We like Sophos Central, where you have access to a security console. It provides you with information such as recommendations on what to do next. Using this, we were able to trace the affected devices, which were then cleaned. If new alerts are given then we know which devices are still affected and we can take the appropriate action.

Sophos Central also shows us which alerts have not yet been attended to, which is nice.

What needs improvement?

Sophos Central does not provide all of the information that is available, so it requires us to take the additional step of retrieving details from the firewall. It would be more productive if the information between Sophos products were automatically correlated and updated in Sophos Central.

When there is an event generated by either the firewall or Intercept X, and the originating IP address is the same, these should be merged into a single event rather than two. Automatically correlating these events would save us time.

For how long have I used the solution?

We began using Sophos Intercept X a few days ago.

What do I think about the stability of the solution?

We use Intercept X on a daily basis and it is quite stable.

What do I think about the scalability of the solution?

My impression is that this product is scalable.

We have only deployed Intercept X at one hospital, which has about 300 people that it protects. We have approximately six hospitals for which we are recommending its use.

How are customer service and technical support?

We have only dealt with the sales team in the Philippines. Our concerns were commercial in nature, for the most part, rather than technical.

Which solution did I use previously and why did I switch?

Prior to Intercept X, we were using the signature-based endpoint protection by Sophos. Our license was just recently up for renewal and we are in the process of upgrading to Intercept X.

In my previous company, we were using Cisco AMP. The beauty of Sophos Intercept X is that it does both signature-based on behavioral threat protection in one agent. With some other solutions, you have to install a different product for each approach.

How was the initial setup?

The initial setup is very simple. We were able to install it in a few minutes and then it automatically begins detection. Completing the initial scan involves rebooting the computer a couple of times, so it takes a little while to complete and clean out the malware if it is there.

What about the implementation team?

The interface is very user-friendly and we were able to deploy and operate it ourselves.

Our company does not have 24/7 monitoring, so we are now looking at a managed SOC that we can subscribe to. Ideally, this type of service will give recommendations, above simply alerting us to problems.

What's my experience with pricing, setup cost, and licensing?

We were able to eliminate the ransomware using the one-month, full-featured trial license. Our intention now is to upgrade our systems to the full product. We were given a corporate rate.

Our licensing includes local support for each of our offices, nationwide. This something that we like.

What other advice do I have?

Overall, this is a good product that seems to address our concerns and I can recommend it.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Intercept X Endpoint
September 2025
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
868,787 professionals have used our research since 2012.
reviewer1416969 - PeerSpot reviewer
Network Engineer at a tech services company with 201-500 employees
Real User
If improving existing security measures is a goal, this product fits your model
Pros and Cons
  • "Sophos Intercept X is easy to install and has a lower price than similar solutions."
  • "Integration with firewall solutions could be better."

What is our primary use case?

Our primary use case is to enhance existing security.  

What is most valuable?

The most valuable part of this solution is just the general capability of making security more robust.  

What needs improvement?

There are a lot of things that can be added based on the user's need for the solution.  

Where this solution has room for improvement generally is in the integration with Sophos Central and firewalls.  

For how long have I used the solution?

We have been using Sophos Intercept for the last two years.  

What do I think about the stability of the solution?

Right now I am in the midst of trying to solve a bug, but I think it is generally a stable product. When there is a bug, the solution usually comes down to updating the firmware or endpoint.  

What do I think about the scalability of the solution?

Intercept X is a scalable solution.  

How are customer service and technical support?

We have worked with technical support due to some issues we experienced. We had some problems with firewall or endpoint issues that we could not solve immediately. While Sophos is helpful technically, their tech support is not so good. Their tech response could be better. They need to do more to deliver support that is as good or than their competition.  

How was the initial setup?

Intercept is easy to install. There is not a lot to do in the setup for a cloud product of this type.  

What other advice do I have?

My advice to people looking at Sophos Intercept X is that it is easy to install and has a lower price than similar solutions. I recommend it.  

On the scale from one to ten (where one is the worst and ten is the best), I would rate Sophos Intercept X as an eight-out-of-ten.  

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1238874 - PeerSpot reviewer
Network Administrator at a tech services company with 51-200 employees
Reseller
Not just another simple virus-scanning product, but it does not handle removable USB drives well
Pros and Cons
  • "It is not just a simple virus scanning product. It handles more advanced needs."
  • "This product does not handle USB drives well."

What is our primary use case?

We use Intercept X Advanced along with Sophos EDR (Enhanced Data Detection and Response).  

We use it for our servers and clients as advanced protection. It is not just a simple virus scanning product.  

We use it to work with clients and it is installed on five servers. At this time we have only installed it at one customer site. But we plan to continue to expand.  

What is most valuable?

The most valuable part of the solution in our use case is client isolation. It is a good feature.  

What needs improvement?

What I think Sophos can improve is with the data-loss feature, especially when it comes to using USB sticks and USB hard disks. The feature blocks access to these USB sticks and disks and there seems to be no immediate workaround for that. Our customer was not satisfied with the feature. We actually ended up having to deactivate this feature because it is too aggressive and could not meet the client's needs.  

For how long have I used the solution?

We started using Sophos Intercept X in December of 2019.  

What do I think about the stability of the solution?

We have not had a problem at all with the stability.  

What do I think about the scalability of the solution?

It is easy to scale this product. As far as the typical organization size that it fits, I would say it is suited for smaller and medium-sized companies. We have not yet installed it at a large customer site, so I cannot answer about large or enterprise companies specifically.  

How are customer service and technical support?

To this point, I have not had a need to use Sophos support for Intercept X specifically.  

I have used Sophos support for other products that we use. Sophos support for XG is okay if it is just regarding questions about the product. I did not have any problems with them in getting a good answer to questions about the product or installations. But when it comes to device defects, then it can take four to six weeks to get a solution. In that case, the support is really not satisfactory. It does not satisfy me and it is really unacceptable.  

Which solution did I use previously and why did I switch?

We did use other solutions in the past, including Trend Micro, Symantec, and Kaspersky. The main difference between Sophos Intercept X and the other products is the client reservation feature. I believe that is a standalone point for Sophos as it is the only product that has it. It allows particular hosts to always use the same IP address which is sometimes desirable.  

The administration of Trend Micro is one thing which I like about that product. It is very easy to use. I would say that Trend Micro is better than Sophos on that point.  

We switched to Sophos because we are selling Sophos firewalls already. The Sophos Intercept X product works better with these firewall solutions than other virus scanning products from different vendors. We decided to keep to the same vendor for a more unified solution.  

We started to work with Sophos Endpoint Protection originally and we are on Bonfire XG as well. It is convenient to expand out working with the brand as a partner.  

How was the initial setup?

The initial setup for the product is not simple. It is medium to complex to install and setup.  

After deploying it takes only me and the customer team for maintenance. Really one person can do it. So there is just one person at my company and I have communication with one colleague at the customer site.  

What about the implementation team?

We did not need outside help from a vendor to handle the deployment. I did it myself and we are a partner with Sophos.  

What other advice do I have?

Advice that I would have for people considering using virus scanning is that I, personally, would not use Sophos Endpoints. That is the simplest edition of the Sophos virus protection product line. I would use Intercept X Advanced as the entry-level product as the other, simpler product, is not robust enough to provide acceptable protection for businesses in my estimation.  

On a scale from one to ten where one is the worst and ten is the best, I would rate Sophos Intercept X as a seven. First, I never give a ten because every product can be improved. Second, I subtract two points because of my experience with the data loss feature and how it behaves with USB drives.  

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1362132 - PeerSpot reviewer
CTO & CISO at a tech vendor with 51-200 employees
Real User
A very complete solution with good functionalities and the capability to scale
Pros and Cons
  • "There are products that are technically stronger. However, this product has everything in one solution, which makes it a strong endpoint option."
  • "The ADR functionalities feel like they aren't mature enough. It hasn't been a long time since Sophos has offered reproduction. Due to the fact that it's so young, it has fewer functionalities than other and more mature ADR solutions."

What is our primary use case?

We primarily use the solution to protect our company from ransomware and malware attacks.

What is most valuable?

The product is very complete.

There are products that are technically stronger. However, this product has everything in one solution, which makes it a strong endpoint option. 

There are good functionalities for advanced incorporation and good ADI functionalities that work well specifically against dangerous strains of malware and ransomware.

Since 2015, Sophos is trying to integrate its products with synchronized security. The communication from UTM to the agent goes both ways. It allows the platform to gain a very high amount of data about the Endpoint's telemetry and to give the administrators a lot of visibility. A lot of other platforms cannot synchronize with other security ICT solutions and cannot guarantee the same visibility at all. 

What needs improvement?

The ADR functionalities feel like they aren't mature enough. It hasn't been a long time since Sophos has offered reproduction. Due to the fact that it's so young, it has fewer functionalities than other and more mature ADR solutions. 

Sophos would benefit from a cloud server implementation on top of the cloud provider (whether it's Google, Amazon, Azure, etc.). The solution is great, however, it's still intended for traditional off-cloud usage. It's focused on endpoint protection of the end-user. It's less targeted on servers, especially Linux or newer implementations that have microservices contained within the environment.

For how long have I used the solution?

I've been using the solution for about five years now.

What do I think about the stability of the solution?

The stability is good. We haven't seen any issues that would make us believe it is unreliable. We haven't had crashes. I don't really recall bugs or glitches.

What do I think about the scalability of the solution?

The solution really targets medium-sized enterprises. Therefore, it's not a problem to scale until it reaches 5,000 users. Most of the Italian market would fit into this category, and therefore, it works pretty well for most organizations here.

How are customer service and technical support?

I can say that I'm happy with the level of technical support we've received so far. In my experience, they are quick. There also isn't a language barrier. There is an Italian support team, which means we can speak with them in Italian. It's always easier than trying to explain difficult problems in other languages. They are quite efficient so I'm quite satisfied.

What other advice do I have?

I am a customer, however, I also have a partnership relationship with Sophos due to the fact that we are a security system integrator and post-security system integrator. That means we not only use Sophos, but we also propose it to our clients. 

I'd rate the solution nine out of ten.

I would recommend Sophos as one of the platforms to take into account when looking for a solution that would work for a mid-sized company. Whether it's the ideal solution or not depends on what objectives and goals the organization has. Those need to be taken into account when evaluating a potential solution.  

That said, generally speaking, I would recommend Sophos. If you compare the environment, the scope, objectives, and goals of the organization, you'll be able to decide if Sophos would be right for you.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
PeerSpot user
PeerSpot user
Senior Security Consultant - Checkpoint Technologies at a tech services company with 11-50 employees
Consultant
Top 20
A solution that offers good forensics, good ransomware mitigation, and good stability
Pros and Cons
  • "The forensics within the solution are quite good. The ransomware mitigation is also impressive."

    What is most valuable?

    The forensics within the solution are quite good. The ransomware mitigation is also impressive.

    What needs improvement?

    We haven't had any issues with the solution, so I can't speak to any improvements that can be made at this time.

    What do I think about the stability of the solution?

    The solution is stable.

    What do I think about the scalability of the solution?

    The solution is scalable.

    How are customer service and technical support?

    The technical support of the solution is satisfactory. We've never had any problems or issues dealing with them.

    What other advice do I have?

    We're a reseller for Sophos.

    The newest release has got the EDR, so I think they're moving in the right direction in terms of the development. 

    I'd rate the solution ten out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Consultant at a tech services company with 5,001-10,000 employees
    Consultant
    Range and restriction features make this a good choice for customers who want endpoint protection
    Pros and Cons
    • "The most valuable features are the range and restriction."
    • "To be a perfect product, the price would have to be a bit better."

    What is our primary use case?

    The primary use case is for protection. We sell this solution to our customers.

    What is most valuable?

    The most valuable features are the range and restriction. This is why our users choose Intercept X.

    What needs improvement?

    To be a perfect product, the price would have to be a bit better.

    For how long have I used the solution?

    I have been using this solution for two years.

    What do I think about the stability of the solution?

    This solution is stable.

    We haven't had any issues with Sophos Intercept X and we haven't had any complaints from our customers.

    What do I think about the scalability of the solution?

    This solution is scalable.

    We have one customer who is scaling quickly, increasing by ten to twenty users each month. We sell them new licenses, put them in their client central, and all they have to do is pull it out to their new devices. 

    How are customer service and technical support?

    We have contacted Sophos technical support in the past, but not Intercept X.

    How was the initial setup?

    For our customers, the deployment of Sophos Intercept X is easy and it's easy to manage.

    What's my experience with pricing, setup cost, and licensing?

    The price is pretty good.

    Which other solutions did I evaluate?

    For my customers who do not want the range and restriction features, I instead recommend using Windows Defender.

    What other advice do I have?

    I would recommend this solution if they want endpoint protection.

    Always check the Sophos Central to make sure that the device is activated with the current updates and scanning.

    Customers should log onto the portal to see if the scan has been updated.

    I would rate this solution an eight out of ten.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    it_user1156602 - PeerSpot reviewer
    Technology Solutions Specialist at a tech services company with 501-1,000 employees
    Reseller
    An excellent protection against ransomware that’s stable and easily scalable
    Pros and Cons
    • "After that, the client switched to Sophos to get the protection they lacked. It either works or it doesn’t and Sophos works."
    • "They might want to offer an MSP model for licensing, to offer the solution as a software as a service."

    What is our primary use case?

    Clients primarily use the solution for ransomware.

    What is most valuable?

    There isn’t a specific feature; the solution itself secures your infrastructure. We had a partner whose client was using a different solution that was hit by ransomware recently. It was an inferior product and it didn’t protect them. They didn’t buy a license to protect them for ransomware. After that, the client switched to Sophos to get the protection they lacked. It either works or it doesn’t and Sophos works.

    What needs improvement?

    We’ve only been using the solution for two months, so we don’t have a grasp of the full system to comment too much.

    They might want to offer an MSP model for licensing, to offer the solution as a software as a service.

    For how long have I used the solution?

    We’ve been a distributor of the solution for two months.

    What do I think about the stability of the solution?

    The solution is pretty stable.

    What do I think about the scalability of the solution?

    The solution is easily scalable to thousands of users. It’s very capable.

    How are customer service and technical support?

    So far, we haven’t had to deal with technical support at all.

    How was the initial setup?

    The initial setup is easy.

    What other advice do I have?

    We are distributors of Sophos.

    I’d rate the solution ten out of ten. I think Sophos is at the top of their game and offering a good protection solution.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Intercept X Endpoint Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2025
    Buyer's Guide
    Download our free Intercept X Endpoint Report and get advice and tips from experienced pros sharing their opinions.