Sophos UTM provides security for our network here and access through a VPN connection for our remote users. It also offers the flexibility to create different tools for accessibility.
Chief Information Technology Officer at a engineering company with 1,001-5,000 employees
It's a good value and priced better than many competing solutions, but it should integrate more advanced threat detection
Pros and Cons
- "Sophos UTM provides security for our network here and access through a VPN connection for our remote users. It also offers the flexibility to create different tools for accessibility."
- "I would like to see Sophos UTM add support for all the new threat-detection technologies and the ability to respond to novel security threats that come along every day."
What is most valuable?
What needs improvement?
I would like to see Sophos UTM add support for all the new threat-detection technologies and the ability to respond to novel security threats that come along every day.
I'm in the process of switching every UTM device in all branches to Sophos, so I need visibility into each branch to see the activity. I need alerts for any threat that enters the network. If there is unauthorized access or some specific action that can threaten my network, I want to be notified.
For how long have I used the solution?
We've been using Sophos UTM for the last three years.
What do I think about the stability of the solution?
Sophos UTM is stable so far.
Buyer's Guide
Sophos UTM
February 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I haven't had the need to scale up Sophos UTM so far, but I believe it's scalable.
How are customer service and support?
We have excellent technical support. The company that supports us is highly experienced with Sophos.
Which solution did I use previously and why did I switch?
We previously had Cyberoam. After Sophos acquired Cyberoam, we purchased new Sophos hardware devices.
What's my experience with pricing, setup cost, and licensing?
Sophos UTM is priced in the middle range. Okay. It's a good value and a far better price than many competing solutions.
What other advice do I have?
I rate Sophos UTM seven out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Security Specialist at Tetracom S.A.L
It blocks malware and other unauthorized apps
Pros and Cons
- "Installing Sophos UTM is straightforward. The deployment itself doesn't take long, but you have to spend some time planning and waiting for the hardware to be delivered."
- "Sophos customer support could use some improvement."
What is our primary use case?
We use Sophos UTM for multi-site VPN, quarantine, sandboxing, and IPF. It blocks malware and other unauthorized apps.
For how long have I used the solution?
I've been using Sophos UTM for more than four years.
What do I think about the stability of the solution?
Sophos UTM is stable and ready for customization.
What do I think about the scalability of the solution?
Sophos UTM is scalable. We have around 100 users, including engineers, managers, and computer scientists. We plan to increase our usage in the future.
How are customer service and support?
Sophos customer support could use some improvement.
Which solution did I use previously and why did I switch?
We were using something else, but we switched to Sophos because it's politically neutral.
How was the initial setup?
Installing Sophos UTM is straightforward. The deployment itself doesn't take long, but you have to spend some time planning and waiting for the hardware to be delivered.
What's my experience with pricing, setup cost, and licensing?
Sophos UTM should be more open-source and reduce its license cost.
What other advice do I have?
I rate Sophos UTM 10 out of 10. If you're considering Sophos UTM, I would say go for it.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos UTM
February 2026
Learn what your peers think about Sophos UTM. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
General manager at DotCom, Lda.
It's a complete firewall covering all layers of protection
Pros and Cons
- "The three most important features for us are web protection, web server protection, and network protection."
- "Sophos UTM sometimes falls short in high-availability environments. They used to launch firmware that didn't work very well in a high-availability environment."
What is our primary use case?
Sophos UTM is a complete firewall we use to protect from internet threats and check traffic from our network to the internet. It's a firewall covering all layers of protection.
Sophos has some plugins that run on the cloud, but it's transparent to the end-user. For example, there is something to identify threats on an email system called SenseStorm, which is connected to the Sophos Cloud and identifies new threats then spreads the same pattern to all Sophos installations in real-time. I can say that almost 100 percent of our customer companies who have a file solution use Sophos.
What is most valuable?
The three most important features for us are web protection, web server protection, and network protection.
What needs improvement?
Sophos UTM sometimes falls short in high-availability environments. They used to launch firmware that didn't work very well in a high-availability environment.
For how long have I used the solution?
I've been using Sophos UTM for the last five years, but we started using Astaro Security Gateway, the predecessor to Sophos UTM, in 2002.
What do I think about the stability of the solution?
Sophos UTM is a strong solution. I give it a 10 out of 10 for stability.
What do I think about the scalability of the solution?
Sophos UTM is scalable.
How was the initial setup?
The initial setup is somewhat tricky. You need to understand networking concepts well, and the company must have good policies for internet access. However, it's not that complicated. I would say it's an intermediate difficulty, but I also have a lot of experience with this solution. It might be challenging for a new technician. We do all the deployment in-house, and it takes about three business days. Our team consists of two technicians and me, the manager.
What's my experience with pricing, setup cost, and licensing?
Sophos UTM isn't cheap. It's in the middle, so not the cheapest, but not the most expensive. It's average. If you buy the full suite, you don't need to pay for add-ons, but if you buy some partial products, you have to pay to deploy more features.
What other advice do I have?
I rate Sophos UTM 10 out of 10. It's the most reliable solution in the firewall market. Considering the price and quality of the product, Sophos UTM is the best solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Software Sales Manager at a tech services company with 51-200 employees
Stable and scalable user-friendly software which offers good integration with other solutions
Pros and Cons
- "Sophos UTM is very user-friendly and has good integration with other solutions."
- "Flexibility in pricing could be improved. It's more rigid in its pricing compared to its competitor: Kaspersky."
What is our primary use case?
Mostly when we see that the client has no security product, we offer both of the products: firewall and endpoint security. We offer endpoint security solutions: EDR and XDR.
Most of the time, we offer Sophos UTM and firewall products, but when we see that the customer has a firewall already deployed, we pitch endpoint security. If they're already using a different product, we cross-sell a product. For example, if someone has an environment with just endpoint security and doesn't have XDR or EDR, we'll suggest upgrading to XDR or we'll upsell XDR.
What is most valuable?
The overall visibility of the console is what I find most valuable, plus it's very user-friendly. It can be integrated with other solutions such as SOAR, SIEM, etc., even when you have an existing firewall. I really like that the console can be integrated. You'll see everything on the same window, and the single window feature of the machine is so good. These are the features I really like.
What needs improvement?
I have no suggestions for improvement for Sophos UTM. It's been a decade and it has been a very good product throughout the Pakistan market.
Pricing could be improved. After-sales service is much better. Once you have a sales team and a technical team for any product, it definitely becomes very easy to pitch or get the revenues out of that product. Flexibility in pricing matters a lot.
For how long have I used the solution?
This is the fourth year we've been implementing this solution.
What do I think about the stability of the solution?
Sophos UTM is stable which is why I like it.
What do I think about the scalability of the solution?
I find Sophos UTM scalable and it is one of the reasons I like it.
How are customer service and support?
For Sophos support: the distributor is responsible for providing maintenance, support, and after-sales service. Most of the time, we try to have an agreement between the customer and affiliates which is binding for two or three years.
The support team here is from the distributor. The first layer of support is really fine when compared to the support provided by other products, e.g. McAfee or Kaspersky. This means it doesn't go to the principal for resolution because the distributor or the partner experts try to fix it on their own before logging in to further complaints. We are good with this kind of solution for our customers, and we prefer those distributors who have their support team.
This is why I really like Softech, although everyone does this, Sophos relies on the Softech technical team. They fix the issues most of the time, so it's very rare for us to go to the principal solution. This is the first line of support we have here in Pakistan.
The principal response time is so quick. It took them only two or three hours maximum. I had the experience of addressing an issue to the principal and they were able to answer me in two or three hours maximum. They have a good TA team.
What's my experience with pricing, setup cost, and licensing?
Although Sophos UTM is a good product, other products have more flexibility with their pricing. It is a very fine product, but when someone wants more relaxed pricing or more leverage in pricing, Sophos is more rigid.
For example, Kaspersky is successful in Fintechs because of its services, plus they offer flexible pricing to their end users. It's a comparative advantage here in Pakistan because Pakistan is a very price-conscious market. This is the reason why every time we pitch, we have to pitch more than one product here in Pakistan. They spend their money on SIEM and other kinds of security firewall, but for endpoint solutions, they say any low-budget product could easily be implemented. Most of the customers here in Pakistan like it this way.
Which other solutions did I evaluate?
We also implemented Kaspersky and McAfee.
What other advice do I have?
We are a partner for all these products. We market these products to the end customers or the end users. We are both selling and implementing these products. We're partners with Sophos. There's a distributor in Pakistan called Softech Microsystems, and we have a silver-level partnership with them.
We've been working with Sophos since 2019.
In the financial market, however, Kaspersky is being used more than Sophos because of its credibility, integration, and extra features offered by Kaspersky. We always try to recommend Sophos as it's what we want, but sometimes, because we also carry a Kaspersky partnership, when a customer demands for Kaspersky, we have to let the customer test it and we have to give them a quote for Kaspersky. We also carry another product, e.g. McAfee, aside from Kaspersky and Sophos. Sophos UTM is a product I want to go further. I try to pitch Sophos UTM rather than Kaspersky or McAfee.
I'm giving this solution a nine out of ten.
Whenever we go for the public tenders, because there's no price flexibility, most of the time I find other products win. Although we have completed our POCs and all that, convincing customers to go with our product, but when it goes to the tenders: in the tenders they mention specification rather than mentioning a particular product, so we'll have to qualify. We qualify technically, but when it comes to the commercial opening or the financial opening, we fail.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director at a consultancy with 11-50 employees
Secure and stable with an easy initial setup
Pros and Cons
- "With Sophos, we have not had any incidents this year. The security provided has been good. It has proven to be okay for our needs."
- "The solution needs to do better at covering mobile devices, although they may have an integrated solution for that purpose."
What is most valuable?
During the pandemic, telework grew, however, so did attacks. There was a higher degree of ransomware and so on. With Sophos, we have not had any incidents this year. The security provided has been good. It has proven to be okay for our needs.
The initial setup is very simple.
The solution is stable.
the scalability is good.
What needs improvement?
The solution needs to do better at covering mobile devices, although they may have an integrated solution for that purpose.
I don't really know how it behaves when it comes to web server protection. We have no web servers of our own. I don't know how it behaves if we open our servers to the outside. My sense is that the degree of protection must be higher.
For how long have I used the solution?
We haven't used the solution for very long. We've been using it for less than a year at this point.
What do I think about the stability of the solution?
The stability has been good. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The scalability on offer is quite good. If a company needs to expand, it can do so.
We are not a big company. We have about 70 or so people.
How are customer service and support?
Technical support is okay. It is provided by a local company, not Sophos directly.
Which solution did I use previously and why did I switch?
Previously we did not have any integrated solutions. We had an antivirus of one kind, and a firewall of another. It was a good step for us to integrate all these features into one solution.
How was the initial setup?
The initial setup was simple and straightforward. The deployment was fast. It only took about a week or so, maybe less.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable. Of course, the customer would always like it to be lower, however, the quality to price ratio is positive.
Which other solutions did I evaluate?
I'm also aware of Fortinet options, however, they are more expensive if you look at Fortinet vs Sophos.
What other advice do I have?
We are customers and end-users. We came into the pandemic situation needing a VPN and the one offered by the Sophos behaves quite well. From the point of view of our users, it has been a positive experience.
I don't quite know by heart the version of the solution, however, it's quite recent. It's not the newest one. I saw that the brand new one which came out this year and we don't have that.
I'd rate the solution at an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a consultancy with 51-200 employees
Stable with good documentation and fair pricing
Pros and Cons
- "The cost of the solution is very reasonable."
- "The initial setup may be difficult for those not familiar with the product."
What is our primary use case?
We primarily used the solution to replace Cyberoam. For a client recently, we replaced their old SD device with the latest version, XG 210.
What is most valuable?
At the moment we have deployed the web filtering application as they have their own web servers and their email protection. The web filtering is great. At the moment, we haven't heard any negative feedback from the client.
There is plenty of documentation that can help you check scenarios or different situations that might you have.
The stability is great.
The cost of the solution is very reasonable.
What needs improvement?
I can't recall dealing with any missing features.
Lately, I've dealt more with Fortinet, and haven't focused too much on Sophos.
The initial setup may be difficult for those not familiar with the product.
For how long have I used the solution?
If I recall correctly, I've been dealing with the solution for about five or so years. It's been a while at this point.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
We are actually in the process of discussing scaling with a client. We're working on the business planning aspect right now. We're looking at opportunities on how to protect their network, besides just the webserver and the email servers.
How are customer service and technical support?
I haven't made any request for technical support previously. That is due to the fact that even the local authorized distributor here in the Philippines is very helpful in deploying and configuring the product. Therefore, we have no need to contact Sophos directly.
There's also lots of documentation to reference.
Which solution did I use previously and why did I switch?
Recently, I've used a lot of Fortinet products.
How was the initial setup?
Although I hadn't done a setup in a while, I quickly recalled the steps taken. If you've handled a setup before, you're likely to find the implementation process rather straightforward. I found I was able to adapt quickly and figure out the necessary configurations.
What's my experience with pricing, setup cost, and licensing?
In terms of licensing, here in the Philippines, we just pay on a yearly basis. The renewal is up for this year in Q3. We are talking now with the distributor where we purchased the hardware for a possible renewal with the client.
Overall, they provide very reasonable pricing.
What other advice do I have?
My company is a reseller of Sophos.
I haven't deployed one of their latest solutions yet. We just had a recent project for a basic firewall, and they were actually 210. That's the last project I had with Sophos.
We are in the process of taking up certification exams for Sophos.
I definitely recommend Sophos. It's one of our top products in the company.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer.
Science Technician at a government with 201-500 employees
Simple to use, good technical support, but not scalable
Pros and Cons
- "What I like about the solution is the ease of use."
- "The solution is not scalable."
What is our primary use case?
The primary use of the solution is to create a firewall, web filters, and load balance. We also use it as an IPS.
What is most valuable?
What I like about the solution is the ease of use.
What needs improvement?
In the next release, the solution should contain an administration security user to access the interface.
For how long have I used the solution?
I have used the solution for one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is not scalable. In my organization, we have approximately 500 employees using it.
How are customer service and technical support?
The technical support of the solution is good.
How was the initial setup?
The installation of the solution is easy. It can be finalized in approximately five hours.
What about the implementation team?
The deployment of the solution was completed by a consultant. We have three technicians and two administrators that oversee the solution.
What's my experience with pricing, setup cost, and licensing?
It is necessary to pay for a licence to use the solution, but it is not very expensive.
What other advice do I have?
I will continue to use and recommend the solution.
I rate Sophos UTM a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator at a manufacturing company with 51-200 employees
Great web and email filtering with reasonable pricing
Pros and Cons
- "We've found the technical support to be helpful."
- "The ease of use could be a bit better."
What is our primary use case?
We primarily use the solution for a number of use cases, including the firewall, web filtering, email filtering, and email encryption. UTM does it all. The only thing that we don't use it for is web application and protection. We don't really have any web servers in-house.
What is most valuable?
The web and email filtering are the two biggest and most valuable aspects of the solution for us.
The solution overall has just been a good, cost-effective solution for us.
The solution offers a lot of functionality.
The solution scales well.
We've found the technical support to be helpful.
The stability and performance are quite good.
What needs improvement?
The ease of use could be a bit better. It's something they could work on.
The ease of configuration could be improved. It's not as simple as it could be just yet. However, it's kind of the nature of it.
They're kind of difficult to get set up sometimes.
Some of the detail in the web filter and the email filtering could be better outlined in the reporting. It is not as good as the two separate standalone solutions we used previously. However, it does also gives us a lot of other stuff that those two solutions didn't. It's a trade-off.
For how long have I used the solution?
I've been using the solution for the last five years at this point.
What do I think about the stability of the solution?
The stability and performance are good. The solution is reliable. There are no bugs or glitches. It doesn't crash or freeze. It's good.
What do I think about the scalability of the solution?
We've been using the same hardware for five years and it's always had a very good performance. I would say it scales pretty well. We have around 80 users on the solution currently. We've had double that. Actually, until COVID hit, we did have double that, as of a year ago.
How are customer service and technical support?
We've been very happy with Sophos, despite the fact that most of their support is based out of Europe. When you get them on the phone, they're actually very good. Their support is very good. We've been happy with them, and have no concerns about renewing the maintenance.
Which solution did I use previously and why did I switch?
We currently use a few Cusco solutions. We had a SurfControl web filter previously - a standalone server for that. We also had an email filtering package, that was on a separate server by itself. We found that the Sophos UTM did both of those things, and it gave us a firewall, and it saved us money. That's largely why we switched. The downside to Sophos is the reporting wasn't as good, however, everything else was better.
There was nothing wrong with the other solutions that we had other than it would cost us twice as much money to get a lot fewer capabilities. We don't really have the manpower to fully utilize those other solutions in great detail, which is why a simple web filter and email filter that was built into the Sophos solution worked for us. Plus, it does a lot more than that. We could run everything through it. We could - and we may do this - move away from using the Cisco solutions altogether, and just use the two Sophos firewalls. Once we get the XG up and running, we can upgrade the UTM to XG also and have the two XG firewalls in our two locations, and use it for the LAN connection between the locations. I don't know that we'll do that, however, it's definitely something that we can do. It's just a lot of additional capability and flexibility.
How was the initial setup?
While the configuration can sometimes be tricky, it was pretty much straightforward to initially set everything up. It helped that we had paid support through Sophos, so their technicians helped us get it up and running.
The deployment took a couple of weeks in total. It wasn't too big of a deal.
We don't really have any staff dedicated to deployment and maintenance. I tend to handle those aspects myself.
I've watched a few webinars, even on implementation, and it's just that a lot of the stuff is really different. You need to work on it a bit to get the hang of everything.
What about the implementation team?
We had Sophos directly assist us. They were great at helping us implement everything. We physically got it in place, and then got it up and running, and then finished it off with some assistance from Sophos.
What's my experience with pricing, setup cost, and licensing?
We've found the solution to be cost-effective overall.
Normally we do a three-year license with maintenance on a firewall.
Beyond the standard maintenance fee, the solution doesn't require any other licensing costs.
What other advice do I have?
We are a manufacturing company. We're not a technology company. We don't need to have the very latest state-of-the-art technology, however, we want to try to be close to it. For us, Sophos is perfect.
We also plan to use Sophos XG, however, we haven't implemented it yet. We're hoping it might be easier to configure and set up than UTM.
Our antivirus, actually, was the antivirus that was managed by the UTM. Now they've since retired that capability, and they've gone to endpoint security software being managed in the cloud. Sophos Central can manage all of the Sophos security products, including all the firewalls, the endpoint security. Basically, you end up with one web interface for all of your security stuff. That's actually going to be a big feature, especially moving forward with XG, due to the fact that, if XG detects anything fishy going on, you can shut down individual client networks, and not allow any traffic to go through.
Our Exchange ActiveSync is actually behind a Cisco firewall. We have a Cisco ASA also.
We use the latest version of the solution.
I'd rate the solution at an eight out of ten. We've largely been satisfied with the product.
As a company, you're looking to get the best solution out there. Once you have something in place, and it's worked well for you, and it hasn't cost you any excess money, you don't need to have too much contact with anyone. I rarely contact Sophos. That's a good indication of how good the product is working for us. If I was looking for something new, or if when maintenance comes up, and we've had hardware that's been in operation for a while, maybe we just need something new. Then you look and see if there's something out there that works better for you. That's basically it. We're not looking for anything new. We've actually been very happy with Sophos. I liked the way that there's a lot of good stuff there.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Unified Threat Management (UTM)Popular Comparisons
Fortinet FortiGate
WatchGuard Firebox
Check Point Quantum Force (NGFW)
Cisco Meraki MX
Check Point CloudGuard Network Security
Juniper SRX Series Firewall
KerioControl
Untangle NG Firewall
Stormshield Network Security
Zyxel Unified Security Gateway
Huawei NGFW
Juniper vSRX
Sophos Cyberoam UTM
LANCOM R&S Unified Firewalls
Seqrite UTM
Buyer's Guide
Download our free Sophos UTM Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which would you recommend to your boss, Fortinet FortiGate or Sophos UTM?
- What Is The Biggest Difference Between Sophos UTM and Sophos XG?
- What are the biggest technical differences between Sophos UTM and Fortinet FortiGate?
- What Is The Biggest Difference Between Sophos and pfSense?
- Who provides a better antivirus solution: Bitdefender or Sophos?
- What are the biggest differences between Meraki and Sophos? Which one is good for security and SD-WAN?
- What is the biggest difference between Fortinet FortiGate and Sophos UTM?
- When evaluating Unified Threat Management (UTM), what aspect do you think is the most important to look for?
- What UTM solution do you recommend?
- Why is a UTM solution important?
















