We use Sophos Intercept X on all of our end-user PCs and servers.
Network Administrator at a manufacturing company with 51-200 employees
Useful central management, fantastic technical support, and priced well
Pros and Cons
- "The most valuable feature of Sophos Intercept X is cloud management."
- "Sophos Intercept X could improve on its setup process. They could make it easier to have a baseline set up for the system, or at least provide more understanding of what the baseline is when you first install it. This could be a matter of lack of training on my part, but it's difficult to receive training on solutions that are not Cisco. Cisco is the only vendor with classes or courses."
What is our primary use case?
What is most valuable?
The most valuable feature of Sophos Intercept X is cloud management.
Sophos Intercept X used to be managed through the Sophos UTM, and they moved it. They moved the endpoint security strictly to the cloud, and it is a lot better that way it is more functional. Before all it did was download the software. Now that we have full management of the clients, you can easily update them remotely. There's a lot of additional policy functionality that was not there before. However, sometimes a little too much, but not as much as a solution, such as Cisco.
For how long have I used the solution?
I have been using Sophos Intercept X for approximately six years.
How are customer service and support?
Sophos technical support has always been fantastic. I've never had an issue, they have been great, and they are tremendously helpful. They are very hands-on, and they dive in to help to fix your problem if you need them to.
Buyer's Guide
Intercept X Endpoint
March 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
846,617 professionals have used our research since 2012.
Which solution did I use previously and why did I switch?
I have used many other solutions, such as Cisco.
When comparing Cisco to Sophos Intercept X, Cisco solutions are more difficult.
How was the initial setup?
Sophos Intercept X could improve on its setup process. They could make it easier to have a baseline set up for the system, or at least provide more understanding of what the baseline is when you first install it. This could be a matter of lack of training on my part, but it's difficult to receive training on solutions that are not Cisco. Cisco is the only vendor with classes or courses.
When we set it up, we made very few changes from the baseline setup, and mainly that's to allow other software to operate. Sometimes the endpoint security software interferes with your software that needs to be running in addition to the bad software. You have to set up and configure the software and the policies to allow for the software you want to operate.
What about the implementation team?
We typically have one person that does the implementation and maintenance of Sophos Intercept X.
What's my experience with pricing, setup cost, and licensing?
The cost of Sophos Intercept X is reasonable.
I would rate the price of Sophos Intercept X an eight out of ten.
What other advice do I have?
I would recommend others to try the solution, we have had a very good experience with it.
I rate Sophos Intercept X a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Network Administrator at Sechelt Indian Band
Is easy to install and manage, and has anti-exploit protection
Pros and Cons
- "One reason why I have stuck with Sophos is because it grabs it and deals with it, and if it's known malware, it can quarantine it or delete it."
- "As for improvement, more notifications or emails about what to watch out for globally would be nice. For instance, information about the spread of a current phishing campaign or ransomware would be very helpful. I find that I have to dig in the back to find out what is happening on the global scene for things to be aware of."
What is our primary use case?
Sophos Intercept X is the antivirus protection of my choice and my client's choice because it does not only malware, antivirus, and Trojan protection but also anti-exploit protection. It has a quarantine process as well. It does all of the usual antivirus plus the anti-exploit and anti-ransomware processes.
What is most valuable?
One reason why I have stuck with Sophos is because it grabs it and deals with it, and if it's known malware, it can quarantine it or delete it.
I look at all my network workstations and laptops, and if any one of them has some issues with updates or receives a notification, then the server console in the cloud will send me an email as well.
I like it's user interface, cloud integration, and the GUI. It's easy to work with it with clients.
I also like Sophos Intercept X because I can install it on a computer, and if it's set for tamper proof, then nobody can uninstall the program.
What needs improvement?
As for improvement, more notifications or emails about what to watch out for globally would be nice. For instance, information about the spread of a current phishing campaign or ransomware would be very helpful. I find that I have to dig in the back to find out what is happening on the global scene for things to be aware of.
For how long have I used the solution?
I've been working with Sophos Intercept X ever since it was released three years ago.
It is a cloud solution. The installation is local on the device, but it communicates to the cloud where the cloud server manages the reports, notifications, and licensing.
What do I think about the stability of the solution?
My impressions of the stability of Intercept X is that it's excellent.
What do I think about the scalability of the solution?
The scalability is not a problem at all.
How are customer service and support?
I've received really good technical support. They're amazing.
Which solution did I use previously and why did I switch?
I've had experience with other antivirus programs such as Trend, Norton, and McAfee, and they just flag it and indicate that you are infected. However, Sophos has always taken care of things. This way, if my users don't know what to do with a popup, at least I know that Sophos will just grab it, quarantine it, and protect the user.
Sophos is easy to install and easy to manage, and I have had no issues with it. I've had better protection and quarantining features with Sophos Intercept X.
How was the initial setup?
On a scale from one to five, where one is complex and five is easy, I'd rate the initial setup at four. This is because sometimes you'll get a popup asking you to reboot, but actually, if you've installed it a few times, you know that you have to reboot it after the installation. So, there are a couple of popups that don't make it seamless.
If I've got 10 new workstations with a new client and I've sold them 10 licenses and one server, I will have that set up in the cloud as soon as I get the license. It will probably take half an hour to set that up. I can then start adding computers instantly. To install 10 computers, it would take about five hours.
What about the implementation team?
My team and I implement it. We also, sometimes, walk a client through the process remotely.
What other advice do I have?
Sophos Intercept X is a good protection service package for small businesses and large corporations. You can have two computers, five computers, or 5,000 computers, and it'll be just as easy to manage.
I haven't had any issues with ransomware since I began using anti-exploit. I trust Sophos Intercept X and rate it at ten on a scale from one to ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:
Buyer's Guide
Intercept X Endpoint
March 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
846,617 professionals have used our research since 2012.
Chief Executive Officer at Infoview Limited
Beneficial policy management, automatic endpoint updates, simple installation
Pros and Cons
- "Sophos Intercept X is a very effective solution and its being cloud-based is a benefit. Wherever my users are, I can apply policies to them. In the era of mobility, when users are out of the office or they're in different locations, it doesn't matter."
- "From the management side, we receive detailed information. Sophos has many features, such as Threat Hunting but that comes with the XDR version of the solution. There's Sophos Intercept X and then there's Sophos Intercept X with XDR technology. We bought the XDR and then now the MTR, Managed Threat Response version available too. They have different packages for clients which gives them different options to pick from. If Sophos could combine more features into one package it would be beneficial."
What is our primary use case?
We are using Sophos Intercept X for endpoint protection.
What is most valuable?
Sophos Intercept X is a very effective solution and its being cloud-based is a benefit. Wherever my users are, I can apply policies to them. In the era of mobility, when users are out of the office or they're in different locations, it doesn't matter.
Whenever a user gets infected, as an admin, we get notified. We have many options to pick from, the ability to send policies to the endpoints is a very good feature that they have.
Whenever there is an update all the agents on the end-users systems automatically update.
We have the option of caching updates on the network, which allows us to save on bandwidth. For example, if we have 100 people in the office, we can deploy an internal caching server or a message link server, so not all computers need a connection to Sophos onto the cloud.
Sophos Intercept X integrates with their other solution very well, such as the XG Firewall. The feature is called Synchronized Security.
What needs improvement?
From the management side, we receive detailed information. Sophos has many features, such as Threat Hunting but that comes with the XDR version of the solution. There's Sophos Intercept X and then there's Sophos Intercept X with XDR technology. We bought the XDR and then now the MTR, Managed Threat Response version available too. They have different packages for clients which gives them different options to pick from. If Sophos could combine more features into one package it would be beneficial.
For how long have I used the solution?
I have been using Sophos Intercept X for approximately five years.
What do I think about the stability of the solution?
Sophos Intercept X is highly stable.
What do I think about the scalability of the solution?
I have found Sophos Intercept X to be scalable.
We have approximately 40 clients using this solution.
How are customer service and support?
I'm a Sophos certified architect to myself, and as a partner, from the vendor, we have excellent support. We have not had a problem with the technical support, they are always available for communication, such as online chat or on-call.
Which solution did I use previously and why did I switch?
We have used Kaspersky, ESET, Bitdefender, and Symantec solutions.
How was the initial setup?
The installation is very easy. If someone is not on the network, you can send them an invite by email and they would only need to install the agent, and everything will work perfectly.
The time the installation takes depends on the internet connection. Sometimes it takes only five minutes and other times it can take up to 10 minutes. It all depends on the connection because it has to download the installer.
What about the implementation team?
The end-user can install the solution themself. It is very easy. It is only a two to three-step process it is complete.
Many people are using this solution and some customers don't even have IT managers, we provide them manage services I this case.
What was our ROI?
The solution has great protection against anti-ransomware and all of the zero-day threats. The ROI is very good.
What's my experience with pricing, setup cost, and licensing?
There is a license required to use this solution.
If it's a managed services provider contract that we have with the customer, then they pay monthly. Depends on the customer, what the requirements are. They can pay either monthly or annually to us, but we have to pay annually to the vendor.
Which other solutions did I evaluate?
Before choosing Sophos Intercept X we evaluated Kaspersky, ESET, Bitdefender, and Symantec. For some of our clients who are using the other products, now they've shifted to Sophos Intercept X.
What other advice do I have?
I would recommend this solution to others.
I rate Sophos Intercept X a ten out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Technology at Speed enterprises
Stops data leaks, highly stable and scalable solution
Pros and Cons
- "It is quite scalable. You can always add more users. I would rate the scalability a nine out of ten."
- "It's a bit heavy on the computers. So once you install it, the computer slows down. It is a resource-intensive solution."
What is our primary use case?
It is an endpoint. So it's antivirus and DLP, and all those integrated in one.
What is most valuable?
It is like an antivirus. So it stops viruses. DLP stops data leaks in the organization.
What needs improvement?
It's a bit heavy on the computers. So once you install it, the computer slows down. It is a resource-intensive solution.
For how long have I used the solution?
I have been using this solution for two to three years now. We use the latest version.
What do I think about the stability of the solution?
It is a stable solution. I would rate the stability a nine out of ten.
What do I think about the scalability of the solution?
It is quite scalable. You can always add more users. I would rate the scalability a nine out of ten.
How was the initial setup?
The initial setup is easy. The server, the main server, is online. And then the agent is on the premises.
After online configuration, the agent installation takes only ten minutes. It is a very quick installation.
The configuration takes around two hours.
What about the implementation team?
I do maintenance for this solution. A team of four engineers handles the maintenance and deployment.
What's my experience with pricing, setup cost, and licensing?
The pricing is quite expensive compared to the rest. I would rate the pricing a four out of ten; one is expensive, and ten is cheap.
What other advice do I have?
It's a good product. So, link it with the security policies because you can link it with the firewall. The endpoint can communicate with the hardware firewall. So that's one of its strong points.
Overall, I would rate the solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer:
Managing Director at Behold IT
Very good endpoint protection capabilities with useful AI and effective threat management
Pros and Cons
- "The security on offer is pretty good. We are happy with it."
- "The solution can be expensive, although we do see the value in it."
What is our primary use case?
We primarily use the solution for endpoint protection.
What is most valuable?
The endpoint protection capabilities are great.
The security on offer is pretty good. We are happy with it.
I love the threat management on offer.
Their AI is quite good.
We haven't had any issues with stability so far.
Sophos has a central management dashboard, which I'm happy about.
The installation process is very straightforward.
What needs improvement?
I'm mostly quite happy with the solution. I haven't had any issues with it.
From the firewall side, from the Intercept X to endpoint protection, everything is there, so there's nothing much that I can complain about.
The solution can be expensive, although we do see the value in it.
For how long have I used the solution?
I've used the solution for over a year now.
What do I think about the stability of the solution?
The stability has been good. There are no bugs or glitches. it doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We have over 200 employees on the solution currently. I haven't had any issues with scaling.
How are customer service and support?
I'm quite happy with the level of support on offer.
Which solution did I use previously and why did I switch?
We've used also AVG. We've used it in quite a few different places for different systems.
How was the initial setup?
I found the implementation process sot be easy. It wasn't a problem at all. I did not find it to be overly complex or difficult.
We have administrators and managers that can handle any technical stuff.
What about the implementation team?
We were able to handle the setup ourselves, in-house. We didn't need any integrator or consultant assistance.
What's my experience with pricing, setup cost, and licensing?
We have paid for three years of licensing.
It is expensive, however, for what you getting out of it, from the firewall side and to endpoint protection, everything seems to be worth it.
What other advice do I have?
I'd recommend the solution to other users and organizations. I'd rate it at a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Director at Geekz Information Technology
Effective EDR, reliable, and scalable
Pros and Cons
- "I have found the most valuable feature to be the EDR."
- "The solution is heavy in the usage of resources, you can notice the performance decrease. This should prove in the future."
What is most valuable?
I have found the most valuable feature to be the EDR.
What needs improvement?
The solution is heavy in the usage of resources, you can notice the performance decrease. This should prove in the future.
For how long have I used the solution?
I have been using this solution for approximately five years.
What do I think about the stability of the solution?
I have found the solution to be stable.
What do I think about the scalability of the solution?
The solution is scalable. We have multiple clients and have approximately 1,000 users using the solution.
How are customer service and technical support?
We have not had a good experience with technical support. The quality of support we received was not what someone would expect from a leading solution provider.
Which solution did I use previously and why did I switch?
We have used McAfee and Trend Micro previously. The customer's environment would determine what is the best option that we would recommend. For example, if the customer has a Sophos firewall and other Sophos products, then it would be better to go with Sophos Intercept X.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is a little high compared to competitors because they do not have a proper pricing structure.
What other advice do I have?
I rate Sophos Intercept X an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
IT Manager at a tech services company with 201-500 employees
Integrated anti-malware, next-generation firewalls, and IPS for network security solutions
Pros and Cons
- "We use Sophos Intercept X for Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) in our organization."
- "They should work on the logs and events. Sophos Intercept X needs to increase the interface test so that it can export to a live event."
What is our primary use case?
Our primary use case is the interception solution in Sophos Intercept X.
How has it helped my organization?
We use Sophos Intercept X for Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) in our organization.
What is most valuable?
The future's about anti-malware, next-generation firewalls, and IPS. We value the IDS features of Sophos Intercept X the most. This is the best solution that we use and need.
What needs improvement?
Sophos Intercept X has room for improvement in the user management of live events.
They should work on the logs and events. Sophos Intercept X needs to increase the interface test so that it can export to a live event.
For how long have I used the solution?
I have been using this solution less than a year.
What do I think about the stability of the solution?
The stability of this solution was great. Sophos is a very powerful tool for all of our needs.
What do I think about the scalability of the solution?
We have an enterprise company. There are branches all over the world. Support for 50 schools over the internet is what we're supposed to intercept. It is scalable.
We have about 500 end users. For deployment and maintenance, we require just a few people. It is done by me and one of my colleagues.
How are customer service and technical support?
The technical support is not good because we are in Iran. We don't have any solidarity support from the company. We have some sanctions on. We just handle everything by ourselves.
Which solution did I use previously and why did I switch?
Before Sophos, we had older hardware that was not able to handle this software. We decided to change the solution to the Sophos device.
How was the initial setup?
The setup of Sophos Intercept X was straightforward. Our deployment took about two days, each day six to seven hours of work.
What about the implementation team?
We have used both consultants and a reseller.
What's my experience with pricing, setup cost, and licensing?
We renew the license for one year at $10,000.
What other advice do I have?
Sophos Intercept X is easy to deploy. It has all the features for a small, medium, or large scale business. On a scale from 1 to 10, I would rate this product an eight.
The security of other devices on Cisco is more reliable and stable, but the user control in Sophos is a feature that Cisco doesn't have.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sr Manager - Information Security & Researcher at a tech services company with 1,001-5,000 employees
Straightforward installation, secure, but could be more user-friendly
Pros and Cons
- "The most valuable feature of the solution is that it is less hash-based than competitors."
- "I would like the solution to have more functions and to be more user-friendly."
What is our primary use case?
The primary use of the solution is to block threats. It contains a quick queries engine that can help us figure out where all threats are coming from.
What is most valuable?
The most valuable feature of the solution is that it is less hash-based than competitors.
What needs improvement?
I would like the solution to have more functions and to be more user-friendly.
In the next release, the solution could have more use cases. For example, protection against ransomware.
For how long have I used the solution?
I have used the solution for approximately one month.
What do I think about the stability of the solution?
I find the solution to be stable and secure. However, there are some operational issues with the hashing algorithm.
What do I think about the scalability of the solution?
We have 7000 uses in our organization using the solution.
Which solution did I use previously and why did I switch?
I have used Falcon CrowdStrike and Kaspersky.
How was the initial setup?
The installation of the solution is straightforward and took approximately two days for tuning.
What about the implementation team?
The solution was deployed by the vendor team, using approximately three administrators.
What's my experience with pricing, setup cost, and licensing?
The solution requires an annual subscription.
What other advice do I have?
I rate Sophos Intercept X a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
Cisco Secure Endpoint
Fortinet FortiClient
Symantec Endpoint Security
HP Wolf Security
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?