Skip to content
Avanet
Sophos Fusion Cybersecurity Defense System

Sophos Fusion explained: Product, licence or platform?

Sophos Fusion sees everything, connects everything and makes your defences respond as one. That is the message in the 66-second introductory video. It is accompanied by terms such as AI-native, Agentic AI, Unified Context Lake, Compounding Intelligence and Synchronized Security. It sounds impressive, but it does not answer the obvious questions: Is Sophos Fusion a new product? Does it require a new licence? Is Sophos Central being replaced? And what happens to Endpoint, XDR, MDR, Firewall and the other Central products?

Sophos Fusion: Securing the AI Era – the 66-second introductory video from Sophos.

The short answer is: Sophos Fusion is neither a single product nor a licence of its own. The AI-Native Cybersecurity Defense System refers to the underlying architecture. Sophos Fusion is the evolution of Sophos Central and the management environment in which customers connect their control points and manage their security on this architecture. The existing Central console is not being replaced by a second portal. Instead, existing accounts will be upgraded to Fusion automatically and gradually, with the interface rebranded accordingly; customers do not need to take any action. At the same time, Fusion is more than a new logo: the Secureworks integration significantly expands XDR and MDR technically, Next-Gen SIEM arrives as a new add-on, and further offerings such as AI Defense and CISO Advantage are being introduced under this umbrella.

Fusion is therefore best understood as a combination of three things: a technical platform strategy, a new portfolio model and a new brand message. Anyone who only operates a Sophos Firewall will not suddenly gain an autonomous security operations centre. Anyone who uses multiple control points, XDR or MDR and configures the integrations properly, however, can genuinely benefit from more context and faster responses.

The key answers at a glance

Is Sophos Fusion a new product or a new licence?

No. Sophos does not sell standalone Fusion software or a Fusion licence. Existing products and services retain their own licences.

Is Sophos Fusion a new strategic direction?

Yes. Sophos is positioning its portfolio as an interconnected Cyber Defense System rather than merely a collection of individual products.

Is Sophos Central being replaced or renamed?

The platform is not being replaced: existing accounts, configurations and workflows remain intact. The management environment is evolving from Central to Fusion through an automatic, phased upgrade. Customers do not need to take any action.

Does an existing Sophos Firewall need to be migrated?

No. Neither a new appliance nor a Fusion licence or special SFOS upgrade is required solely because of Fusion.

What is actually changing?

The main developments are in XDR, MDR, SIEM, integrations, automation and the shared use of telemetry.

Will Sophos Fusion create additional costs?

Fusion itself costs nothing. Next-Gen SIEM, AI Defense and other services, however, are additional offerings or add-ons.

This distinction matters. Sophos itself states explicitly that Fusion is not a SKU, not a bundle and not something that can be purchased separately. At the same time, the vendor is naturally using the launch to position new products and enhancements. “No Fusion licence” therefore does not mean “all Fusion features are included in every existing licence”.

What Sophos means by a Cyber Defense System

Traditional security portfolios consist of many tools: Endpoint Protection, Firewall, email security, identity security, NDR, XDR, SIEM, ZTNA, switches, access points and cloud security. Each product sees a different part of an attack. The problem is rarely a lack of data. The problem is that this data ends up in different consoles, formats and areas of responsibility.

Sophos Fusion is intended to connect these parts into a single system. The architecture can be reduced to five building blocks:

  1. Control points: Sophos Endpoint, Firewall, Email, Identity, NDR, Workspace Protection, Switches, Wireless and cloud products provide telemetry or can implement protective measures. According to the current product page, there are also more than 500 third-party integrations.
  2. Shared context: A Unified Context Lake is intended to bring together events, devices, users, identities and indicators of attack. Technically, this builds on the existing Sophos Data Lake and Secureworks Taegis technology.
  3. Coordinated response: Synchronized Security and other bidirectional integrations are intended to translate findings from one control point into actions elsewhere.
  4. AI, automation and human oversight: Agentic AI is intended to structure investigations, enrich context, prepare decisions and trigger responses within defined boundaries. Sophos X-Ops, MDR analysts and defined trust boundaries remain part of the system.
  5. Compounding Intelligence: Insights from real attacks should not remain within a single customer tenant, but improve detectors, AI models and response logic for all customers.

The unwieldy term Compounding Intelligence therefore describes a central learning cycle. Sophos says its data foundation includes more than 625'000 protected organisations and over 380'000 MDR investigations per year. This does not mean that customers can access one another’s raw data. Instead, insights from attack patterns and investigations are intended to feed back into updated detections, models and response logic. From the outside, however, it is virtually impossible to verify how quickly and for which products this cycle actually takes effect.

The objective makes sense. A compromised account, a suspicious process on an endpoint and an unusual connection through the firewall may not be conclusive on their own. Together, they may reveal an attack. Fusion is intended to recognise these relationships more quickly and coordinate an appropriate response.

The crucial point, however, is this: An architecture diagram is not the same as an enabled integration. For data to come together in practice, the relevant products must be licensed, registered in Central, configured correctly and enabled for logging or Data Lake uploads. Automated responses additionally require supported Response Actions, permissions and a defined incident process.

Is Sophos Central now becoming Sophos Fusion after all?

Sophos itself apparently had not quite settled on the message. Just two months ago, Paul Murray, Senior Product Marketing Director at Sophos, stated in the Community that Central would be neither renamed nor replaced. Apparently, even a Senior Product Marketing Director did not yet have all the news at that point.

Sophos FAQ on the relationship between the Fusion Defense System and Sophos Central
Two months ago, Sophos was still saying that Sophos Central would be neither renamed nor replaced. That statement has since been superseded. Quelle: Sophos Community: How does the Defense System relate to Sophos Central?

The position is now clear: Sophos Central is becoming Sophos Fusion. The existing management environment will be renamed and expanded automatically and in phases; customers do not need to initiate anything. There will be neither a second tenant nor a new console. In short: the platform remains, the name changes. For straightforward Endpoint, Email or Firewall administration, little is likely to change initially in day-to-day work. The transition will be more noticeable where XDR, MDR, integrations and the Threat Analysis Center are already in use.

The real product changes behind the Fusion launch

The term Fusion covers the entire portfolio. At launch, however, the most concrete changes concern Sophos XDR, Sophos MDR and Next-Gen SIEM. These enhancements are based heavily on Secureworks and its Taegis technology following the acquisition completed in 2025.

Sophos introduced Fusion on 15 July 2026 and announced the new XDR, MDR and SIEM capabilities for 15 August 2026. The rollout for existing XDR and MDR tenants is expected to begin in August and proceed in phases over several months. No agent redeployment is required, and Sophos expects neither an interruption nor any change to the existing XDR or MDR licence solely as a result of the platform upgrade.

Sophos XDR is being significantly expanded

Sophos XDR retains its name but gains a new security operations interface that replaces the existing Threat Analysis Center, along with considerably more capabilities from the Secureworks world:

  • thousands of additional detectors from Taegis,
  • custom Detection Rules,
  • AI-assisted Detection Analysis,
  • more telemetry and threat intelligence from Sophos X-Ops,
  • SOAR playbooks and additional Connectors,
  • more bidirectional integrations with Response Actions,
  • an integrated Email Monitoring System, and
  • the option to add Next-Gen SIEM as an add-on.

Some upgrade materials temporarily use the name Sophos XDR Powered by Secureworks. This is not a separate XDR product, but a description of the technically enhanced platform.

For analysts, this makes AI more tangible in the day-to-day interface for the first time. Related activities are grouped into cases, complex security data is presented more clearly, and investigations can be searched using natural language. Sophos explicitly advertises this as “no SQL required”. This lowers the barrier to entry, but it does not replace verification of the results or an understanding of the underlying telemetry.

For existing XDR teams, this is probably the most important Fusion change. The existing query and investigation platform is developing into more of a complete SOC working environment. However, the additional technology does not eliminate operational work. Detection Rules, data sources, playbooks, permissions and escalation paths still need to be maintained.

After the upgrade, integrations for Microsoft 365 and Okta must be reauthorised if Response Actions are configured there. Details like these show why a platform upgrade should not simply be ignored, despite the promise of “no downtime”.

According to Sophos, the integrated Email Monitoring System (EMS) is included in XDR and MDR and does not require an additional Fusion licence. It replaces neither Sophos Email, Microsoft Defender for Office 365 nor any other email gateway. EMS uses journalling rules in Microsoft 365 or Google Workspace and operates in monitoring mode alongside the existing email security. The original email flow and delivery remain unchanged. EMS provides a second layer of detection and investigation; with Microsoft 365, malicious messages that have already been delivered can also be removed retrospectively.

My assessment: So many new XDR features without a separate new licence and without an announced price increase at launch almost seem unusually generous. Microsoft has just shown what can happen next: alongside additional AI, security and management capabilities, the prices of selected Microsoft 365 plans were increased effective 1 July 2026. At Sophos, we last reported in 2022 on a price increase of 7 to 9 per cent for Intercept X Advanced with XDR. I would therefore not be surprised to see another XDR price increase within the next twelve months. Nothing has currently been announced — this is explicitly a personal prediction.

Sophos MDR gains more automation and yet more new names

Sophos is turning the naming wheel again for MDR: MDR Essentials becomes MDR, while MDR Complete becomes MDR Plus. That is hardly surprising. Sophos Central product and licence names change so regularly that I can barely think of an offering that kept the same name for four years. I would therefore not regard the renaming itself as a major Fusion innovation. The technical changes behind it are what matter.

Sophos speaks of continuous, AI-assisted threat hunting, more integrations and additional response capabilities. The Email Monitoring System is also being integrated.

Sophos cites two figures to demonstrate the automation: according to the vendor, 52 per cent of MDR cases are handled by AI from start to finish within boundaries defined by analysts. However, the public wording around the 89 seconds is not consistent. The Fusion announcement and the MDR product page measure from alert to automated response. An earlier Agentic SOC announcement, however, starts the clock only when a case is created and applies to cases that the AI is authorised to handle completely. An alert and case creation are not the same thing. The figure should therefore be read as a Sophos operational metric, not an independently verified end-to-end response time or a guarantee for every incident.

One concrete change is likely to be noticed in day-to-day work sooner than the new name: the existing weekly and monthly MDR reports will be discontinued with the upgrade. New self-service reporting is not planned until later in 2026. Until then, the MDR Dashboard remains available with freely selectable date ranges, customisable views and PDF export. Anyone who uses the regular reports for customers, audits or internal controls should therefore replace the existing distribution with a new process before the upgrade.

For existing MDR customers, the key priorities are therefore to monitor the announced upgrade date, review integrations, and plan for changes to reports or workflows. Anyone already using MDR with third-party telemetry can find the foundations of this development in our article Sophos MDR integrates telemetry data from third parties.

Next-Gen SIEM is new and costs extra

Next-Gen SIEM is not a free gift for every Central account. It is offered as an optional add-on for XDR and MDR. Its main benefits are longer data retention, additional compliance capabilities and custom integrations. According to the public Sophos FAQ, one year of retention is standard, with options for three, five, seven or ten years planned.

The licensing model is notable: Sophos intends to price Next-Gen SIEM according to the number of protected users and servers rather than the volume of data ingested. This could reduce the otherwise difficult-to-predict log-volume costs associated with SIEM products. This alone does not indicate whether the offering is cheaper; users, servers, retention and required integrations all need to be considered together.

Custom data sources are to be connected through Custom Integrations. In the public upgrade FAQ, however, Sophos still describes the announced AI-assisted parsers for these integrations as coming soon. They should therefore not be treated as an already available feature in an implementation project.

For organisations already operating Splunk, Microsoft Sentinel, Google Security Operations, Elastic, QRadar or another SIEM platform, this is not an automatic reason to switch. The offering becomes interesting where XDR or MDR is already the central security operations process and a separate SIEM platform would be too complex or expensive. Before switching, organisations should compare data sources, retention, search capabilities, export, compliance, cost and exit strategy.

Data residency also belongs on the checklist for Swiss and European organisations. Sophos Central provides data regions including Frankfurt, Germany, and Dublin, Ireland; a Swiss Central region is not currently listed. The region is selected when an account is created. Customer data remains tied to that region and cannot be transferred between regions. A later change of region is therefore not a simple account option.

The current XDR privacy data sheet confirms this regional binding for Sophos Central and the existing Data Lake. The Secureworks documentation identifies separate Taegis locations in the US and in the EU or Germany. What is not clearly explained publicly, however, is how an existing Central tenant will be mapped to these Taegis regions during the Fusion upgrade and whether all new Context Lake, SIEM and third-party data flows will remain unchanged in the existing region. This is precisely what should be confirmed in writing before an implementation.

Sophos lists ISO 27001, ISO 27017, ISO 27018, SOC 2 and C5 Germany, among others, in its business certifications. C5 is the criteria catalogue of Germany’s Federal Office for Information Security for cloud services. This list is helpful, but it does not replace checking the exact scope. A compliance project must establish whether the required Fusion component, region and data processing are actually covered by the relevant certificate or report.

AI Defense and CISO Advantage are additional offerings

With Fusion, Sophos is not only introducing an architecture, but also expanding its portfolio:

  • Sophos AI Defense is intended to make the use of generative AI and Shadow AI visible, assess risks and control access. The offering is planned as an add-on for qualifying EDR, XDR and MDR solutions and requires a Fusion-enabled account. An Early Access programme is announced for August, with general availability in October 2026.
  • Sophos CISO Advantage is not a technical agent for Endpoint or Firewall, but a security programme. It is intended to include continuous Control Validation, compliance mapping, risk assessments, comparisons with similar organisations, and reporting that is understandable to executive management or the board. Launch is planned from October 2026.

For AI Defense, Sophos describes four steps: identify AI tools and autonomous agents in use; assess risks based on identity, permissions, location, data access and behaviour; enforce guardrails for prompts and agents; and feed suspicious AI activity into existing detection and response workflows. This is more concrete than simply adding another AI label. How granularly these controls work in practice and which applications are fully supported will only become clear during Early Access and general availability.

This reveals the commercial side of Fusion. The system itself has no licence, but it creates the framework in which additional products and services can be sold. That is not automatically a bad thing. It should simply be kept distinct from the technical architecture.

What is changing for Sophos Firewall?

For existing Sophos Firewall installations, the initial position is clear: Fusion replaces neither the firewall nor SFOS or Firewall licensing. An XGS Firewall continues to operate locally, enforce rules, inspect traffic and retain its Network, Web, Zero-Day or Xstream Protection capabilities. Central Firewall Management also remains Central Firewall Management.

The firewall is a control point in the Fusion architecture. It can provide network data and respond to findings from other products. Depending on the licence and configuration, this includes:

  • Synchronized Security and Security Heartbeat,
  • Central Firewall Management and Central Reporting,
  • Firewall telemetry in the Data Lake,
  • XDR and MDR integrations,
  • Active Threat Response,
  • NDR Essentials and NDR Active Threat Intelligence, and
  • APIs for management and automation tasks.

A realistic example: a suspicious process is detected on an endpoint. Identity data shows that the affected account logged in unusually shortly beforehand. At the same time, the firewall sees a connection to suspicious infrastructure. XDR or MDR correlates these signals, isolates the endpoint and can restrict network access through a supported integration. This is exactly the chain Sophos means by “respond as one”.

Anyone who operates only a firewall with local rules, sends no telemetry to Central and uses neither XDR nor MDR will gain practically no new protection from the word Fusion. Anyone who deliberately connects the firewall with NDR Active Threat Intelligence, the Data Lake and Active Threat Response, however, can incorporate network decisions into a faster incident process.

The other Central products also illustrate this direction. Sophos has announced Live Discover queries for Switches and AP6 Access Points. Data from Workspace Protection can feed into XDR queries. ZTNA supports multiple domain controllers, while Protected Browser and the browser extension provide additional visibility into web and AI applications. These are not features that appeared overnight because of Fusion. They do, however, illustrate how more control points are being integrated into the same investigation and response layer.

What is really behind “AI-native”?

The term deserves a sober assessment. Sophos has used machine learning and deep learning in endpoint, email and network protection for years. Fusion is not AI-native because a model is suddenly classifying malware for the first time. What is new is the ambition to use AI across the entire security operations process:

  • prioritise and summarise alerts,
  • correlate events from different sources,
  • explain detection decisions,
  • plan investigation steps,
  • perform threat hunting continuously,
  • prepare or trigger suitable Response Actions, and
  • feed findings from many incidents back into detectors and models.

By Agentic AI, Sophos means systems that do not merely answer a single question, but independently carry out several steps within a defined assignment. In a SOC, this could mean that an agent examines an alert, gathers context about the user and device, searches for related events, creates a risk assessment and, if the situation is sufficiently clear, initiates a previously authorised containment measure.

The important qualifier is within defined trust boundaries. Which actions are allowed automatically, which require approval and when a human analyst takes over matters more than the AI-native label. An AI that decides quickly but is confronted with incomplete telemetry, incorrect permissions or poorly defined playbooks may, in the worst case, automate the wrong response.

In its own AI Security 2026 Report, Sophos also makes a far more nuanced argument than in the short Fusion videos: AI compresses attack sequences and improves social engineering, reconnaissance and automation. It has not, however, suddenly invented entirely new categories of attack. Sophos describes the reality between exaggerated hype and the equally mistaken assumption that AI plays no role for attackers.

This is also the most sensible interpretation of Fusion: AI makes a good security system faster and more scalable, but it does not replace data quality, a permissions structure or an incident process.

Where the marketing claims fall short

“Sees everything” and “responds as one” are bold promises. In practice, several limitations apply:

An emerging category is not yet a market standard

Sophos describes Cybersecurity Defense Systems as a new, emerging category and Fusion as its first and most complete system. As evidence, the Fusion press release refers to the Gartner report “Tech FutureSight: Protect the Global Attack Surface with an Autonomous Cyber Defense System” dated 12 December 2025. This is neither a Magic Quadrant nor a Market Guide or a product evaluation of Sophos Fusion. The report describes the broader direction of autonomous defence systems.

Nor does the market forecast cited in the press release come from Gartner. The Futurum Group expects the security operations market to grow from USD 18 billion to USD 37 billion by 2029. This does not make the technical idea behind Fusion wrong. It does show, however, that “Cybersecurity Defense System” is currently as much a category narrative actively promoted by Sophos as it is a generally established market standard. For a product comparison, the data sources, Response Actions and operational processes actually available are therefore more meaningful than the category label.

Not every integration can respond

The figure of more than 500 integrations is a system-wide number for the open Fusion architecture. It does not say how many are available as ready-made XDR connections or support a bidirectional response. Some integrations only deliver logs, others support queries, while others allow specific Response Actions. Before planning, organisations therefore need to establish for each product which telemetry is ingested and which actions are actually supported.

More Sophos increases the integration benefit

Fusion explicitly supports third-party providers too. As expected, however, the greatest automation benefit emerges where many Sophos control points are already present. This is technically plausible and, at the same time, a clear portfolio and cross-selling strategy. Mixed environments remain possible, but need to be assessed against the specific integrations.

“Part of Fusion” does not mean “everything is included”

Sophos describes every product as part of the system. This does not mean that every feature is available under every licence. Firewall protection bundles, Endpoint licences, XDR, MDR, Next-Gen SIEM, AI Defense and consulting services retain different prerequisites and prices.

Automation requires operational responsibility

Automatic isolation can save crucial minutes during an incident. It can also disconnect a production-critical server from the network. This is why approvals, exceptions, roles, emergency contacts and regularly tested runbooks are required. The Network Security Best Practices for Sophos Firewall remain relevant in a Fusion architecture too.

What to do now

For most existing customers, there is no need for a rushed migration project. A phased approach makes sense.

If you only use Endpoint, Email or Firewall

  • Continue operating existing licences and protection capabilities as normal.
  • Review Central registration, roles, MFA, logging and data transmission.
  • Do not assume that Fusion automatically unlocks new XDR, MDR or SIEM entitlements.
  • Decide whether additional telemetry will actually be evaluated in your own incident process.

If you already use XDR or MDR

  • Monitor the upgrade notification in Sophos Central. A notification is expected to appear approximately one week before the upgrade.
  • Reauthorise Microsoft 365 and Okta integrations after the upgrade if Response Actions are in use.
  • Document or export saved queries, Detection Rules, dashboards, workflows and integrations, then test them after the upgrade. Sophos has not publicly described how each of these objects will be migrated.
  • Replace the automatic distribution of weekly or monthly MDR reports and check whether the dashboard and PDF export meet internal reporting and audit requirements.
  • Determine which new detectors, SOAR capabilities and Response Actions should be enabled.
  • Update documentation, quotations and internal processes to reflect the renaming of MDR Essentials to MDR and MDR Complete to MDR Plus.

If you have SIEM, SOC or compliance requirements

  • Compare Next-Gen SIEM with the existing SIEM rather than assessing it only by its proximity to other Sophos products.
  • Record data sources, retention, search syntax, export, data residency, roles, costs and exit strategy.
  • Test whether third-party integrations only provide events or also support Response Actions.

If you are interested in AI Defense

  • Check whether a qualifying EDR, XDR or MDR licence is in place and whether the account has already been enabled for Fusion.
  • First take an inventory of which AI services are already being used and what data is sent to them.
  • Consider Shadow AI, browser usage, API access and existing web, DNS, Endpoint or SSE controls together.
  • Do not confuse Early Access with production readiness. Test policies and blocking actions with a limited group first.

My assessment of Sophos Fusion

Sophos Fusion is not a new licence or a single product, but it certainly is a new direction. Following the Secureworks acquisition, the vendor no longer wants to sell merely Endpoint, Firewall and individual Central products, but a shared Cyber Defense System. Technically, this is a logical step: attacks span identities, endpoints, email, browsers, cloud services and networks. A defence system that brings these signals together and responds more quickly makes more sense than five isolated consoles.

The launch nevertheless contains plenty of marketing. The short video sticks to claims such as “see everything” and “respond as one” without explaining the necessary licences, integrations and operational processes. The term AI-native alone also says little. What matters are the specific innovations: Secureworks detectors in XDR and MDR, shared context, more Response Actions, SOAR, Next-Gen SIEM and a clear expansion of the control points.

For existing Sophos customers, the conclusion is therefore:

  • No forced migration and no Fusion licence.
  • The Central management environment is evolving automatically into Fusion; no customer action is required.
  • Firewall, Endpoint, Email, Switch, Wireless and ZTNA remain standalone products.
  • XDR and MDR receive the most significant immediate changes.
  • New capabilities may require additional licences or add-ons.
  • The practical benefit depends on enabled telemetry, supported integrations and good incident processes.

Fusion is therefore neither an empty rebranding exercise nor the fully automated security promise portrayed in the video. It is a serious platform strategy whose value still has to be proven in operation.

FAQ

What is Sophos Fusion?

The AI-Native Cybersecurity Defense System is the shared architecture in which control points, integrations, context, automation, AI and human security expertise work together. Sophos Fusion is the evolution of Sophos Central and the management environment through which customers use this architecture.

What is changing for Sophos XDR?

Sophos XDR gains a new security operations interface, additional Taegis detectors, custom Detection Rules, AI-assisted analysis, more integrations and Response Actions, SOAR playbooks, and the Email Monitoring System. Next-Gen SIEM can be added as an add-on.

What is changing for Sophos MDR?

MDR gains more AI-assisted threat hunting, additional detectors, integrations and response capabilities. MDR Essentials becomes MDR and MDR Complete becomes MDR Plus. Existing customers will be migrated to the new platform in phases; the existing weekly and monthly MDR reports will initially be discontinued as part of this process.

Is Next-Gen SIEM included free of charge with Sophos Fusion?

No. Next-Gen SIEM is an optional add-on for XDR and MDR. Among other capabilities, it adds data retention, custom integrations and compliance features.

Does Sophos Fusion work only with Sophos products?

No. Sophos cites more than 500 third-party integrations. Their capabilities vary, however: some integrations provide only telemetry, while others allow queries or specific Response Actions.

What does AI-native mean in Sophos Fusion?

AI is intended not merely to classify individual files, but to support multi-step security operations tasks such as prioritisation, correlation, investigation and response. Automated actions remain subject to defined permissions and trust boundaries.

Further information

Patrizio