Sophos Managed Risk - Staying Ahead of Cyber Threats
In an increasingly complex digital world, where attack surfaces continue to grow and threats become ever more sophisticated, it is crucial for companies to understand and actively monitor their security posture. Sophos Managed Risk offers a comprehensive solution for identifying, assessing, and prioritizing risks through external attack surface management and vulnerability management. This service is powered by Tenable’s leading technology and delivered by Sophos experts.
What makes this solution interesting is that Sophos is taking a new path. Instead of simply acquiring a company and integrating the product into Central, Sophos is now working directly with the market leader Tenable. A fresh and promising partnership.
For current setup and operational guidance, continue with our Sophos Managed Risk knowledge base, which covers setup, scans, reports, and cases.
What is Sophos Managed Risk?
Sophos Managed Risk is a comprehensive service for vulnerability and attack surface management, powered by Tenable’s leading technologies. This service is delivered by experienced Sophos experts who identify high-priority cybersecurity vulnerabilities and potential attack vectors. This enables actions to be taken to prevent attacks before they disrupt business operations.
Key Features and Benefits
Transparency across attack surfaces
Attack surface management is crucial because a company’s digital attack surface continues to grow through cloud usage, IoT devices, and remote work. Without reliable visibility into external assets and the internal assets deliberately brought into scope, potential entry points can easily be missed.
You can only address vulnerabilities effectively once you know they exist. Sophos Managed Risk reports external, internet-facing assets associated with the domains you provide and scans specified external targets for vulnerabilities. In 2025, Sophos expanded the service with Internal Attack Surface Management. Specified internal assets can now be scanned too, but this requires a virtual scanning appliance in your network.
Continuous risk management
The threat landscape is constantly evolving, and new vulnerabilities are continuously discovered. One-off security checks are therefore not enough. To stay current and respond quickly to new threats, continuous risk management is essential.
Sophos Managed Risk combines ongoing discovery of the external attack surface with scheduled vulnerability scans of specified external and internal assets. Sophos experts assess and prioritize the findings, so customers receive both identified vulnerabilities and remediation recommendations.
Regular reports keep IT and security teams informed about identified risks. Thirty days after onboarding, the Sophos Managed Risk team contacts the customer to schedule a baseline meeting; subsequent review meetings take place every three months to discuss findings, emerging risks, and recommendations.
This recurring assessment and expert support help security teams focus limited remediation resources on the findings that matter most. Customers remain responsible for patching and carrying out the recommended actions.
In a time when cyberattacks are becoming more frequent and sophisticated, Sophos Managed Risk offers the necessary security and flexibility to continuously improve a company’s security posture and be prepared for new challenges.
Risk-based prioritization of vulnerabilities
In a complex IT environment, hundreds or even thousands of vulnerabilities can exist. However, not all vulnerabilities are equally dangerous or have the same potential to cause damage. Therefore, it is crucial to identify the vulnerabilities that pose the greatest risk to the company. This is where risk-based prioritization comes into play.
Sophos Managed Risk uses Tenable’s leading technology to comprehensively analyze vulnerabilities across a company’s IT landscape. It considers not only the technical details of a vulnerability, but also factors such as the current threat landscape, known exploits, and the potential business impact. This risk-based analysis helps create a clear picture of which vulnerabilities need to be remediated first to minimize the risk of a successful attack.
Another advantage of this prioritization strategy is the efficient use of resources. IT and security teams are often under enormous time and resource pressure. With risk-based prioritization, they can focus on the truly critical vulnerabilities and remediate them in a targeted manner, rather than spreading limited resources across less significant security gaps. This not only improves security but also makes day-to-day work more effective.
Furthermore, prioritization enables a quick response to new threats. For example, if a new, particularly critical vulnerability is discovered, companies can immediately determine whether they are affected thanks to risk-based prioritization and initiate appropriate measures. This can prevent potential damage at an early stage.
The combination of comprehensive vulnerability detection and risk-based prioritization offers companies a customized security strategy that can respond flexibly and efficiently to new challenges. Sophos Managed Risk ensures that companies always know which vulnerabilities have the highest priority and what actions need to be taken to continuously improve the security posture.
Rapid identification of new risks
In the constantly changing threat landscape, cybercriminals are always looking for new vulnerabilities they can exploit. They often exploit newly discovered security gaps long before companies can recognize them or take steps to defend against them. This time lag between the discovery of a vulnerability and its remediation can have catastrophic consequences. This is where Sophos Managed Risk comes in.
Sophos Managed Risk observes a company’s internet-exposed assets and performs vulnerability scans. When the team finds a critical external vulnerability or considers a vulnerability high-risk, it notifies the customer through a Managed Risk case and provides remediation guidance.
How quickly a newly published vulnerability can be identified depends on factors including the target system, scan type, reachable services, and the availability of a suitable Tenable plugin. The service therefore does not replace patch management or the customer’s responsibility to carry out recommended actions.
Notifications and investigations from the Managed Risk team appear as a distinct case type in Sophos Central. The shared interface is useful, but it does not make Managed Risk and MDR the same service.
Timely, risk-based findings help teams decide what to investigate and remediate first without turning Managed Risk into an incident-response service.
How Managed Risk differs from Sophos MDR
You must have a Sophos MDR or Sophos MDR Plus license before subscribing to Managed Risk. The services nevertheless have separate responsibilities: Managed Risk identifies and prioritizes vulnerabilities, reports risk, and recommends remediation. MDR monitors for active threats and responds to security incidents.
Both services use Sophos Central, and XDR, MDR, and Managed Risk cases can appear in the same case list. This does not establish automatic correlation with MDR detections, automatic detection-rule creation, or joint remediation. For a Managed Risk query, customers create a Managed Risk service request; only Sophos teams process MDR and Managed Risk cases.
Licensing and Pricing
Managed Risk requires an existing Sophos MDR or Sophos MDR Plus license. As a typical starting point, Sophos adds the customer’s MDR user and server licenses. Internal scans can cover assets equal to 120% of the Managed Risk license count; additional licenses are needed to scan more internal assets.
When internal attack-surface management launched in 2025, Sophos announced it at no additional cost for new and existing Managed Risk customers. That dated launch statement is not a current pricing or contractual commitment. Request a current quote through our contact page.
Onboarding Process
Getting started with Sophos Managed Risk begins in Sophos Central. External scanning requires authorized contacts, domains or IP ranges, and a scan schedule. Internal scanning additionally requires a virtual scanning appliance in your network. At a high level, setup includes these steps:
- Provide authorized contacts: You provide the relevant contact details that will be used for managing the service.
- Enter domain details: The domains to be monitored are specified.
- Schedule automated scans: You define when the regular vulnerability scans should be performed.
After 30 days, the Managed Risk team contacts the customer to schedule a baseline meeting. Subsequent review meetings take place every three months to discuss findings, emerging risks, and recommendations.
Why choose Sophos Managed Risk?
Sophos Managed Risk offers numerous advantages for IT administrators and Managed Service Providers (MSPs):
- A clear complement to MDR: Managed Risk adds vulnerability and attack-surface management to MDR’s active-threat detection and response, while remaining a distinct service.
- Efficient resource utilization: Risk-based prioritization helps to optimize the use of limited resources.
- Trusted partnership: Collaboration with Tenable, a leading provider in the field of exposure management, strengthens the credibility and trust in the security solutions offered.
- Scalability: Licensing based on the number of users and servers enables easy scaling according to company size.
FAQ
Which license does Sophos Managed Risk require?
How is Sophos Managed Risk licensed?
What does "Powered by Tenable" mean?
How does Managed Risk differ from MDR?
What types of assets are detected and scanned?
Avanet downloads
For readers who want supporting material for an internal evaluation, Avanet provides these two downloads:
- Sophos Managed Risk - Solution Brochure — This brochure provides a comprehensive introduction to the features and benefits of Sophos Managed Risk. It contains details on attack surface management, continuous risk assessment, and risk-based prioritization of vulnerabilities. It is ideal for gaining a comprehensive overview of the service and considering it for your own IT security strategy.
- Sophos Managed Risk - Solution Description — This document goes deeper into technical details and use cases and adds further information about the service.
These documents expand on the overview in this article and can support an internal assessment of the service.
