Use Sophos Managed Risk cases and service requests
Under Threat Analysis Center > Cases, Sophos lists XDR, MDR, and Managed Risk cases together. For Managed Risk, there are two tasks here: review a case opened by Sophos or create a Managed Risk service request yourself.
Managed Risk is a separate vulnerability management service. It requires Sophos MDR or Sophos MDR Plus as well as a Managed Risk license. The Managed Risk branch becomes available when creating a case only with this license.
A Managed Risk service request is intended only for matters relating to the Managed Risk service. It is neither a technical Product Support ticket nor the route for an active MDR security incident or a self-managed XDR investigation.
Find and review a Managed Risk case
Sophos uses Managed Risk cases to notify you of a critical external vulnerability or another vulnerability classified as high risk. The team records progress and provides remediation guidance in the case. Cases are also used to arrange appointments and coordinate other service-related matters.
To find the correct case:
- In Sophos Fusion (formerly Sophos Central), open Threat Analysis Center > Cases.
- In the Case type column, look for Managed Risk. The list also contains XDR and MDR cases, so the case type is the deciding attribute.
- Select the Case ID of the required case.
- On the Case details page, review the details for the specific case and the documented investigation progress.
- Record the Case ID internally with the corresponding remediation activity. This keeps the technical change, questions, and answers linked.
Only Sophos teams work on MDR and Managed Risk cases. Managed Risk scans the agreed assets, reports risks, and recommends remediations. However, this does not mean that Sophos makes changes to the affected customer systems. Nor should custom status rules from the XDR workflow be inferred for the documented progress. Internally, a clearly designated responsible person is required. That person approves and implements the recommended remediation, verifies its effect, and coordinates questions in the existing case.
Create a Managed Risk service request
A service request is appropriate when scan settings need to be changed, a scan result or report is unclear, a meeting with the Managed Risk team is needed, or a controlled change in the service lifecycle must be coordinated.
- Open Threat Analysis Center > Cases.
- At the top right, select Create case.
- Under Create a case, select Managed Risk service request.
- Under Create a Managed Risk service request, enter a meaningful case name and a precise description.
- Submit with Create.
- Verify that the Case details page appears, and save the new Case ID for further communication.
If Managed Risk service request is not offered, do not create a Self-managed XDR Case or an MDR Service Request instead. Check that you are working in the correct Sophos Fusion account and that the account has a Managed Risk license.
Prepare the description and supporting information securely
The creation dialog requires a case name and description. A good description helps the Managed Risk team understand the request without multiple follow-up questions. The following information is generally useful:
- a short, specific question or requested change;
- the affected tenant or account, without credentials;
- the name of the scan, report, or existing Managed Risk case and the associated Case ID;
- affected assets or target areas, limited to what is necessary;
- the time and time zone of the observed result;
- expected and actual behavior;
- the exact visible error text and a text description of the relevant details visible in the screenshot;
- the latest relevant change and any safe checks already performed;
- the desired outcome, responsible contact, and suitable time windows if a meeting is needed.
These service requests have additional information requirements and limits:
- External scan scope or root domains: Request changes to external scan assets and/or monitored root domains by case; such changes are limited to once per month. In the description, give the current and exact desired scope, every root domain or external asset to add or remove, and the requested effective date. Attach only a sanitized export or screenshot limited to those targets and, if needed, evidence that scanning is authorized; do not include credentials or secrets.
- On-demand scan: Request it in advance, up to five per month, with at least one business day of lead time. State the scan name and type (internal or external), exact targets, requested date, start time and time zone, approved window, and responsible contact; attach sanitized approval or authorization evidence if required for the scope. The requested time is not confirmed until the Managed Risk team responds.
After receiving a response, check in Managed Risk that the agreed scope is visible or that the requested scan runs as agreed.
Choose the correct escalation route
- Managed Risk Service Request: Questions about Managed Risk scans or reports, changes to scan settings, appointment scheduling, and service handovers that must be coordinated with the team.
- Sophos Product Support: The Central feature or Managed Risk appliance does not technically work as documented, shows a reproducible error, or remains nonfunctional after safe basic checks. The process is described in Open a Sophos support ticket with Support Assistant.
- MDR process for active incidents: Signs of an ongoing attack, compromise, or an immediate need for investigation and containment follow the agreed MDR escalation route. A Managed Risk service request is not a substitute for MDR incident response.
- Self-managed XDR Case: Your own investigations based on XDR Detections belong in the XDR branch. Operate Sophos XDR cases and detection rules describes selecting Detections, assignment, Severity, Status, Suppression, and closure.
This separation is particularly important because all three case types use the same Cases interface. For Managed Risk, no XDR Detections are selected or added, and no XDR rules for assignment, status, closure, removal, or suppression are adopted. Case type: Managed Risk is decisive; when creating a case, Managed Risk service request must be selected explicitly.