Set up Sophos Managed Risk and start external scans
This guide covers the prerequisites, Authorized Contacts, the external scan scope, the allowlist, the weekly schedule, and the first review of …
Sophos Managed Risk is a distinct vulnerability management service for the external and internal attack surface. These guides cover prerequisites and onboarding, scans, Critical Assets, reports, cases, troubleshooting, and controlled offboarding.
First clarify licensing prerequisites, responsibilities, and Authorized Contacts, then configure the external scan scope. Next deploy the internal Scanning Appliance and credentials where required, prioritize Critical Assets, and work with reports and Managed Risk Cases. Troubleshooting and offboarding follow deliberately bounded, documented paths.
Check the MDR or MDR Plus prerequisite, administrator access, and Authorized Contacts. Then configure owned external domains, IP addresses or CIDR ranges, scanner allowlisting, and the weekly schedule in a controlled manner.
This guide covers the prerequisites, Authorized Contacts, the external scan scope, the allowlist, the weekly schedule, and the first review of …
Deploy the virtual Managed Risk Scanning Appliance for internal discovery and vulnerability scans, assign authenticated scan credentials securely, and prioritize up to 25 previously discovered Critical Assets with business context.
The Managed Risk virtual appliance requires supported virtualization, 4 CPUs, 16 GB RAM, 160 GB of storage, and outbound access. Once its status is …
This guide covers preparing Windows, macOS, and Linux targets, completing every credential field in Sophos Fusion, assigning credentials to scans, and …
Critical Assets provide the Managed Risk team with business context for prioritization. You can mark up to 25 previously scanned assets, one at a …
Evaluate reports under My Products > Managed Risk > Report History, route safe remediation to the responsible system owners, and use Managed Risk Cases or service requests under Threat Analysis Center > Cases for the appropriate purpose.
This workflow covers weekly report review, technical assessment, safe remediation, validation, and escalation.
Managed Risk shares the Cases view with XDR and MDR. This guide focuses on the Managed Risk branch and explains which request belongs with which …
Isolate faults by external scan, scope, appliance, network path, or credential and escalate them to the correct team. During offboarding, preserve evidence and do not infer undocumented deletion or cancellation steps.
This runbook guides you from blocked or incomplete Sophos Managed Risk scans through safe checks to the correct escalation path—without undocumented …
This checklist reduces scan access, preserves currently available evidence, and defines firm limits for cancellation, data deletion, and appliance …
Sophos Managed Risk can only be subscribed to with an existing Sophos MDR or Sophos MDR Plus license. That prerequisite does not make the services the same: Managed Risk assesses the agreed attack surface for vulnerabilities, prioritizes risks, and recommends remediation. Changes to affected systems remain controlled tasks for the organization’s system owners.
Adjacent products have different responsibilities:
This hub therefore provides orientation only for the Managed Risk lifecycle. Exact UI procedures, safe checks, and stop boundaries remain in the relevant guide so that procedures are not duplicated inconsistently.