The solution is useful for protecting against ransomware and malwares.
Easy to install, but has slow performance and response time
Pros and Cons
- "The solution is easy to install."
- "The performance is very slow and should be faster."
What is our primary use case?
What needs improvement?
The performance is very slow and should be faster.
Data resources will be consumed, affecting the performance, when there is a concurrent login involving a server with multiple RDP users.
The installation of the solution will start the 17 services involved.
While the tech support is knowledgeable, it's response time should be faster, as it will only get back to us the day after raising a ticket.
For how long have I used the solution?
We have been using Sophos Intercept X for around two years.
How are customer service and support?
Technical support, while knowledgeable, is not adequately responsive, as it will take a day from when the ticket was raised to receive a response. This needs improving.
Buyer's Guide
Intercept X Endpoint
June 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
How was the initial setup?
The solution is easy to install. Downloading time takes only 15 minutes.
What about the implementation team?
Our technical team consists of a team leader, team manager and administrators.
What other advice do I have?
The solution has around 60 licenses.
It is cloud-based.
We have around 10 clients making use of the solution.
We would recommend the solution to others.
I rate Sophos Intercept X as a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Implementer

Sr Manager - Information Security & Researcher at a tech services company with 1,001-5,000 employees
Straightforward installation, secure, but could be more user-friendly
Pros and Cons
- "The most valuable feature of the solution is that it is less hash-based than competitors."
- "I would like the solution to have more functions and to be more user-friendly."
What is our primary use case?
The primary use of the solution is to block threats. It contains a quick queries engine that can help us figure out where all threats are coming from.
What is most valuable?
The most valuable feature of the solution is that it is less hash-based than competitors.
What needs improvement?
I would like the solution to have more functions and to be more user-friendly.
In the next release, the solution could have more use cases. For example, protection against ransomware.
For how long have I used the solution?
I have used the solution for approximately one month.
What do I think about the stability of the solution?
I find the solution to be stable and secure. However, there are some operational issues with the hashing algorithm.
What do I think about the scalability of the solution?
We have 7000 uses in our organization using the solution.
Which solution did I use previously and why did I switch?
I have used Falcon CrowdStrike and Kaspersky.
How was the initial setup?
The installation of the solution is straightforward and took approximately two days for tuning.
What about the implementation team?
The solution was deployed by the vendor team, using approximately three administrators.
What's my experience with pricing, setup cost, and licensing?
The solution requires an annual subscription.
What other advice do I have?
I rate Sophos Intercept X a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Intercept X Endpoint
June 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
A scalable, stable and easily installable solution
Pros and Cons
- "The solution is scalable."
- "Through Sophos Central I would like to see the ability to zero in and produce a report about the challenges being faced by a particular machine and user, to know if a virus is appearing only on that specific machine or also on others."
What is our primary use case?
I am not in the office at the moment and would have to check which version we are using.
What is most valuable?
We have a firewall, for which we will be adding support and integration capabilities.
What needs improvement?
Through Sophos Central I would like to see the ability to zero in and produce a report about the challenges being faced by a particular machine and user, to know if a virus is appearing only on that specific machine or also on others. This way I could know if a virus or issue is a result of an identifiable program that the user may have downloaded.
Also, while the tamper protection is a very good feature, it requires of me to first login to Sophos Central and then look for the Sophos protection password for the particular machine I wish to use. While this is definitely good, this could pose an issue when the internet connection is not working up to speed, something which is occasionally problematic for some of us here in Africa.
For how long have I used the solution?
I have been using Sophos Intercept X for three years.
What do I think about the stability of the solution?
From what I can observe, I would say that the solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and technical support?
You provide us with technical support through our partner relationship.
How was the initial setup?
The initial set up for me was not an issue. I found it to be simple and straightforward, although I cannot recall how long it took, as it has been a while.
What other advice do I have?
I would recommend the solution to others.
I rate Sophos Intercept X as a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Analyst at a educational organization with 1,001-5,000 employees
Plenty of features, effective ransomware protection, and good interface
Pros and Cons
- "The most valuable feature is the CryptoGuard in Sophos. In a case of a ransomware attack, this feature comes into action to protect us."
What is our primary use case?
We have deployed Sophos Intercept X in our environment, both on desktop as well as server environments. We have set up policies in Sophos. For example, there is a web console that can allow or block websites, and you choose what peripheral control you want your desktop environment to connect to.
We use threat protection and we configure the settings to what we want to enable or disable on a particular device. If a device had a threat on it we can disable the device.
The application control allows us to limit the application that users can install on their devices.
What is most valuable?
The most valuable feature is the CryptoGuard in Sophos. In a case of a ransomware attack, this feature comes into action to protect us. Additionally, the under interface, customization, and integration are very good.
For how long have I used the solution?
I have been using this solution within the past 12 months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
We have approximately 450 users in my organization.
How are customer service and technical support?
The technical support is good.
What's my experience with pricing, setup cost, and licensing?
You are able to purchase more licenses for the number of devices or servers that you require.
There are many other features available but our license does not include them, such as XDR, which is endpoint detection and response. We have not explored the new features as of yet but plan to in the coming future.
What other advice do I have?
I rate Sophos Intercept X a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Security Manager at a financial services firm with 10,001+ employees
Good cost and easy to interact with, but needs threat hunting capabilities and better DLP module
Pros and Cons
- "It is easy to interact with, and its cost is also good."
- "The Data Loss Prevention module can be better. It should also have threat hunting capabilities."
What is most valuable?
It is easy to interact with, and its cost is also good.
What needs improvement?
The Data Loss Prevention module can be better. It should also have threat hunting capabilities.
For how long have I used the solution?
I am really new to it because I just joined a new organization. It has not even been two weeks.
What do I think about the stability of the solution?
Its stability is good so far.
What do I think about the scalability of the solution?
It is scalable.
What's my experience with pricing, setup cost, and licensing?
Its cost is good.
What other advice do I have?
I would recommend it for small and medium enterprises. I would rate Sophos Intercept X a six out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CIO at a financial services firm with 11-50 employees
Protects our devices from viruses and other forms of malware
Pros and Cons
- "It does its job — it protects us from viruses. We don't really interact with it very much."
- "It has a performance hit on a local laptop. There's an agent installed and we are bothered a lot by it because it seems to be using a lot of computer resources."
What is our primary use case?
We use this solution to protect all of our computers against viruses — malware in general.
What is most valuable?
It does its job — it protects us from viruses. We don't really interact with it very much.
What needs improvement?
It has a performance hit on a local laptop. There's an agent installed and we are bothered a lot by it because it seems to be using a lot of computer resources.
We're interested in some behavioral analysis regarding activities on all of our networks so that we can anticipate intrusions and problems before they occur. My understanding is that Sophos doesn't provide such a facility. Darktrace seems to offer an artificial intelligence solution along these lines.
For how long have I used the solution?
I have been using Sophos Intercept X for roughly two to three years.
What do I think about the stability of the solution?
This solution seems very stable. We just installed it and forget about it.
How are customer service and technical support?
On the rare occasion that we've asked for help, the IT support company has delivered.
What about the implementation team?
We have a company that provides IT support for us. They recommended it and they set it up. All we had to do was install the agent on each laptop, which was a pretty easy thing to do.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is reasonable.
What other advice do I have?
Overall, on a scale from one to ten, I would give this solution a rating of eight.
I would recommend this solution; it does its job as far as I'm aware. I can't tell you if it's better or worse than other software packages for security. It's the one suggested by our IT services provider. It seems to do the job. We're a bit bothered about the performance hit on the laptops, but other than that, it seems fine.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Coordinator at a pharma/biotech company with 51-200 employees
Services perform well, minimal resources, and synchronizes well with other solution
Pros and Cons
- "The solution is overall quite good, the services are performing well. It is very good for those who are using standard PC configurations. It does not block their system up by taking up a lot of resources."
- "This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it."
What is our primary use case?
We are not only using Sophos Endpoint with this solution, we are also using Sophos Email Security and firewall. It is a completely synchronized security package.
What is most valuable?
The solution is overall quite good, the services are performing well. It is very good for those who are using standard PC configurations. It does not block their system up by taking up a lot of resources.
What needs improvement?
This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it. I do not think a lot of companies know about this solution, it could be a lack of marketing that is the reason why it is not at the top.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the scalability of the solution?
The solution is very good for small-sized businesses.
How are customer service and technical support?
The technical support sometimes is a bit delayed, but sometimes they are responding very fast. Overall they are good but could improve on the times they are having delays.
Which solution did I use previously and why did I switch?
Previously we used McAfee for our endpoint protection for our company. It was very problematic, it was using up a lot of resources and delaying the work of users. Users were not able to do multitasking in the system. It is blocking all access to our server at the time of scanning. We decided to move to some other good antivirus. After analyzing the market, we found Sophos. Sophos is best for the standard configuration PC.
Which other solutions did I evaluate?
Due to some circumstances, we are going to switch from this solution to Symantec. Additionally, we have evaluated Kaspersky before choosing Symantec as the replacement for this solution. Kaspersky has had a very good rating amongst review sites along with Symantec.
What other advice do I have?
I rate Sophos Intercept X a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CEO & MD at Gurjartech
A good solution with good stability and good price
Pros and Cons
- "It is stable and has a good price. I find it very good."
- "They need to focus on their SLA or technical support. They also need to focus on their UI. They should also improve their content filtering tool and update it so that correct categories are there. Sometimes, when I want to block an online gaming website, it is not shown under the correct category. It is shown under another category. They need to review their content filtering tool on a bi-weekly or monthly basis and update the sites and categories. This will be really helpful for them."
What is our primary use case?
My client is a BPO with three branches. One branch is in the US, and two branches are in India. We are using Sophos for the best connectivity. We are using Sophos for endpoint, DLP, and encryption. We are also using it for content filtering and managing security policies. Currently, we are using its latest version.
What is most valuable?
It is stable and has a good price. I find it very good.
What needs improvement?
They need to focus on their SLA or technical support. They also need to focus on their UI.
They should also improve their content filtering tool and update it so that correct categories are there. Sometimes, when I want to block an online gaming website, it is not shown under the correct category. It is shown under another category. They need to review their content filtering tool on a bi-weekly or monthly basis and update the sites and categories. This will be really helpful for them.
For how long have I used the solution?
I have been using this solution for two to three years.
What do I think about the stability of the solution?
I am happy with its stability.
What do I think about the scalability of the solution?
I have not scaled it. Currently, I have only one client who is using it.
How are customer service and technical support?
They need to work on their SLA or technical support. Their technical support is not as good as Cisco's support.
They get back in one or two hours, which is not good enough for a security or firewall solution. This is because an organization's security and all the outgoing and incoming traffic depends on the firewall. When they take one hour and two hours to provide the support, an organization is in danger during that whole duration. There are many threats on the internet, and they need only five minutes to hack.
Which solution did I use previously and why did I switch?
We also work with Fortinet, Palo Alto, and Check Point solutions. If a client has Check Point, we work with that. Similarly, if a client has Sophos, we work with Sophos. We have knowledge of different end products. As compared to Cisco ASA, Sophos is good. However, Palo Alto and Check Point are better than Sophos.
How was the initial setup?
If you have more than five years of experience in network security or network administration, it is easy, but if you are a fresher, it is very difficult.
In terms of duration, it takes two days for it to be completely functional in production. Just connecting it doesn't take more than three to four hours.
What's my experience with pricing, setup cost, and licensing?
Price-wise, it is good. Currently, we have a three-year plan.
What other advice do I have?
I would definitely recommend this solution. I find it very good. If you have an experienced engineer with more than five years of experience, you can easily maintain a Sophos solution. An experienced engineer would not require any support and will be capable of handling it. However, if you have someone with two or three years of experience, it will be difficult to handle all the features.
I would rate Sophos Intercept X an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
SentinelOne Singularity Complete
Microsoft Defender XDR
IBM Security QRadar
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
HP Wolf Security
Elastic Security
Trellix Endpoint Security Platform
Symantec Endpoint Security
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?