Controlled offboarding of Sophos Managed Risk
When offboarding Sophos Managed Risk, separate the documented controls in Sophos Fusion from service termination, for which the available documentation gives no procedure. Administrators can preserve available reports and record Managed Risk cases. Stopping either external or internal scans requires a Managed Risk service request and an order of operations confirmed for your environment; do not assume an undocumented self-service disable control exists.
⚠️ Mandatory stopping point: This checklist neither cancels a contract nor proves data erasure. Do not delete, reset, or disconnect the appliance or VM “to be safe”. Do not remove firewall rules or DNS, proxy, hypervisor, or service settings until the Managed Risk team has confirmed service and appliance dependencies and the sequence of work.
Controlled quick procedure
- Inventory the tenant, scanners, scans, schedules, targets, exclusions, credentials, contacts, and open Managed Risk cases.
- Download every required report currently offered under My Products > Managed Risk > Report History, and record relevant cases before access to the Managed Risk interface ends.
- Open a Managed Risk service request under Threat Analysis Center > Cases, request that both external and internal scans be halted or disabled, and have the supported sequence confirmed in writing.
- Validate the response against the inventoried scan scopes and scheduled windows; do not change the appliance, VM, network, or scan configuration while confirmation is missing or ambiguous.
- Only after the service confirms in writing that all scans have stopped and that no scan still depends on the specific credential, delete each approved credential that is no longer needed.
- Leave the appliance, VM, and related infrastructure unchanged until Sophos confirms the next steps for this environment in writing.
- Record the case ID, approvals, timestamps, and checks in the change record.
1. Record the initial state and approval
Before any change, create a timestamped inventory including the time zone. It must contain at least:
- the Sophos Fusion tenant and responsible people;
- authorized primary, secondary, and tertiary contacts, where present;
- every internal scanner, with name, description, virtual platform, management IP, and visible status;
- every discovery and vulnerability scan, with type, scanner, schedule, time zone, targets, and exclusions;
- credentials assigned to authenticated scans;
- saved external domains, IP addresses or CIDR ranges, and the weekly scan time;
- open Managed Risk cases, with case ID, purpose, and owner;
- the approved target state: scan pause only, technical handover, or planned service termination.
Do not copy passwords, private keys, hashes, or complete secrets into screenshots, tickets, or handover records. The inventory documents dependencies and evidence; it is not an export of the Managed Risk configuration or a promise of future availability.
Before continuing, the service owner, Security Operations, and network and platform owners must know the scope. For planned cancellation, include the responsible commercial team. Their approval alone has no documented technical or contractual effect.
2. Preserve currently available reports
Under My Products > Managed Risk > Report History, check External, Internal, and Account separately. Download only reports and formats currently shown there:
- Vulnerability Reports: CSV, PDF, or HTML;
- Attack Surface Management reports: CSV;
- Discovery Reports: CSV.
For each file, record report name, tab, download time, format, and owner. Store it under your access and retention rules and spot-check readability. For HTML reports, also check that active and resolved vulnerabilities and filters for risk level, device type, and IP address are visible.
Important: Report History is the documented download route, not a guarantee of completeness. Do not claim that all historical scans, cases, or raw data were exported. If a report or format is missing, do not substitute another Central report. Add the gap, report name, scan, expected period, and screenshot to the Managed Risk service request.
3. Plan for data and access boundaries
The current Privacy Data Sheet documents these boundaries for Managed Risk:
- Data is processed in the Sophos Fusion (formerly Sophos Central) region where the customer account is provisioned. That region is selected during onboarding to Sophos Fusion.
- Data is hosted in AWS data centers in the region or regions the customer selected when creating the Sophos Fusion account. For more information about subprocessors engaged by Sophos, see Sophos’s current subprocessor list; do not infer a different region or a contractual commitment from that list.
- Reporting and case data is retained for two years.
- After termination of the Managed Risk service, access to the Managed Risk interface in Sophos Fusion is disabled after a 30-day grace period.
The two-year retention period does not mean administrators retain interface access for two years. Download all currently required and visible reports, and record relevant open or closed cases in your own change or ticketing system before interface access ends. Record at least the Case ID, purpose, current status, agreed next steps, owner, and timestamps, while excluding secrets. This record is not a complete case export and does not guarantee that every case detail exists locally.
These statements define processing, hosting, retention, and interface access. They do not explain how to initiate cancellation or when particular data is finally erased. Nor do they establish any effect of service termination on scans, the appliance, VM, or network. Those points still require a confirmed, environment-specific sequence.
4. Open a service case before infrastructure changes
The available documentation establishes no self-service control for stopping scans. Request that the Managed Risk team halt or disable both external and internal scans. Do this before removing credentials, firewall rules, or changing any appliance, VM, network, or scan configuration.
- Open Threat Analysis Center > Cases.
- Select Create case.
- Select Managed Risk service request as the type.
- Enter a clear name and description.
- Select Create and record the resulting Case ID in the change record.
Describe the tenant, desired target state and date, external and internal scan scopes, scanner names, outstanding reports, and approved changes. Ask for explicit confirmation of:
- when external and internal scans will no longer be triggered;
- any remaining service-side scan or scanner dependencies;
- the permitted order for credentials, appliance, VM, firewall rules, and other infrastructure;
- the acceptance Sophos expects after each phase;
- who can give binding answers on the cancellation route, contractual effects, specific data erasure, and any differing contractual privacy requirements.
Never put passwords, private keys, or other secrets in the case. Until the supported sequence is provided, keep the infrastructure operational and unchanged.
5. Have scan cessation confirmed and validate it safely
Use the Managed Risk service request to request a halt or disablement for every inventoried external and internal scan, including both discovery and vulnerability scopes. Identify each scan by name, type, scanner, targets, schedule, and time zone; scanner name alone is insufficient.
Require written confirmation of the scans covered, the effective time, any final or in-flight run, remaining service-side dependencies, and the validation Sophos expects. Compare that response with the inventory and record any omitted, ambiguous, or mismatched scan in the same case.
After each previously scheduled window, check available status and reports for unexpected activity and add the evidence to the case. A missing report alone does not prove cessation. If confirmation is missing, scope is incomplete, or status, reports, and runtime behavior conflict, stop: do not shut down the VM, block traffic, improvise target changes, delete credentials, or alter/remove infrastructure. Keep everything operational and unchanged until the Managed Risk team resolves the discrepancy in writing.
6. Remove credentials for authenticated scans
Deleting a Managed Risk credential is permanent and removes it from all scan configurations that used it. Never delete one based on its name alone.
Before each deletion:
- Identify the credential name and type unambiguously.
- Check every discovery and vulnerability scan using it.
- Obtain written service confirmation that scanning has stopped and that no external or internal scan still depends on it.
- Involve the owners of the credential and target systems.
- Record approval, affected scans, and expected effect in the change record.
Then locate it under Managed Risk > Settings > Credentials, open the three-dot menu in Actions, select Delete, and permanently delete it with Confirm. Refresh the list and verify that exactly the approved entry is gone. Recheck affected scan configurations because deletion removes it from every assigned configuration.
This deletes the entry stored in Fusion for authenticated scans. It neither disables an underlying Windows, Linux, macOS, SNMP, or VMware account nor removes other secret copies. Handle those accounts only through the approved process of the target system.
The one-time administrative appliance credentials shown when a Scanning Appliance is created are separate. Available Managed Risk documentation defines no revocation or deletion process for them. Have their treatment confirmed in the service case; do not infer it from deletion of a scan credential.
7. Hand over infrastructure unchanged
After preserving reports, obtaining written scan-cessation confirmation, and completing approved credential cleanup, the self-service portion ends. Until an environment-specific answer arrives in the Managed Risk case:
- do not delete, shut down, reset, or redeploy the scanner appliance or VM;
- do not remove virtual disks, images, or hypervisor objects;
- do not change management IP, DHCP reservation, DNS, proxy, or routing;
- do not remove firewall rules or outbound connections;
- do not run shell commands, service restarts, or manual file/data cleanup;
- do not treat one-time appliance credentials as revoked by another deletion.
Service confirmation that scans have stopped and deletion of a scan credential do not prove that a subscription has been cancelled or stored data has been erased.
8. Completion and firm stopping points
The controlled handover state is reached when:
- inventory and approved target state are documented;
- all currently required and available reports are preserved and readable;
- relevant cases were recorded in your own system with case ID, status, and next steps before interface access ends;
- cessation of both external and internal scans is confirmed in writing under a Managed Risk case ID and checked after their next scheduled windows;
- any scan discrepancy and the subsequent order are resolved in that case or remain explicitly documented as open with no further changes made;
- only approved authenticated-scan credentials were deleted and their scan dependencies rechecked;
- appliance, VM, and network infrastructure remained unchanged pending Sophos confirmation;
- approvals, exceptions, screenshots, and timestamps are in the change record.
Stop here: The Privacy Data Sheet confirms regional processing and AWS hosting, points to Sophos’s subprocessor list, specifies two-year retention for reporting and case data, and gives a 30-day grace period before interface access is disabled. It does not define a cancellation procedure or contractual consequences, specific erasure or secure destruction, or how to remove the appliance or VM. Do not infer effects on scans or infrastructure from the documented periods. The responsible Managed Risk, contract, or privacy function must answer outstanding questions for the specific tenant in writing before further changes.