Sophos has launched Sophos Fusion, which has been designed to deliver a coordinated response to AI-era threats.
The AI era has changed what modern defense requires. Attacks can now move across an organisation’s environment as a single coordinated operation, further compressing the time from first access to impact from days to hours. Most security and IT leaders are trying to meet that speed with a growing pile of disconnected tools. The typical enterprise runs more than 45 separate security products, which leaves teams with more spending, more dashboards, and more manual work while attackers move at machine speed.
A cybersecurity defense system is an emerging category in the industry: a single, open architecture where every control point, every service, every data source, and every analyst operates as one, whether the control point is native or third-party. Every new source enhances the system, accelerating outcomes while reducing overhead.
Introducing Sophos Fusion
Sophos Fusion is the evolution of Sophos Central, now rebuilt on one open architecture incorporating Secureworks Taegis analytics.
It leverages agentic AI to connect and synchronise every control point across the whole environment. Sophos proves the system’s efficacy and scalability in its own operation, running the world’s largest agentic SOC with over 40,000 customers worldwide: 52% of cases are resolved entirely by AI, and the average time from alert to a fully automated response is 89 seconds.
Additionally, Sophos Endpoint is designed to stop entire classes of attacks based on behaviors, such as memory abuses, data encryption and exfiltration, or other human or AI attacker tradecraft.
“As AI increases the speed, scale, and complexity of attacks, organizations need a modern connected, intelligent, and adaptive defense,” said Joe Levy, chief executive officer, Sophos. “Sophos Fusion is built as a defense system optimized for Human-AI workflows. We bring the most complete solution to a new category, a timely advancement demanded by the AI era.”
Sophos Fusion offers:
- endpoint protection
- endpoint detection and response
- extended detection and response
- next-gen SIEM
- identity threat detection and response
- managed detection and response
- network security, email, cloud, and advisory services,
all as one defense system.
It is open as well as native: Sophos builds the core control points natively, and more than 500 third-party integrations feed the same shared data layer, so an organisation’s existing endpoint, firewall, or identity tools operate as part of the system alongside Sophos defense and protection.
According to Gartner®’s analyst Neil MacDonald:
“Simply adding more tools onto the stack won’t provide the intelligent cyber defense fabric that organizations need to mitigate AI-orchestrated attacks like the one Anthropic recently identified. Organizations need an intelligent overlay that connects the different elements of their cybersecurity toolset to proactively and reactively respond to risks and threats at machine speeds.”
Expanding the Sophos Fusion Defense System
Sophos is expanding Fusion with the following capabilities, reaching general availability from August through October 2026:
• Sophos Next-Gen SIEM
provides long-term data retention, compliance reporting, and analytics on the same unified data, priced by users and servers rather than by data volume, so organizations can feed in all of their telemetry without unpredictable billing or the gaps that come from holding data back.
Generally available 15 August 2026.
• Sophos AI Defense
secures the AI that organisations are adopting, giving them visibility into AI tools in use including shadow AI, control to enforce policy, and protection for the data those tools can reach, built on capabilities already inside the system.
Early access in August 2026, generally available October 2026.
• Sophos CISO Advantage
gives organisations access to CISO-level guidance, with continuous control validation, compliance mapping, peer benchmarking, and risk assessment. It combines integrated technology, agentic AI, and active threat intelligence in Sophos Fusion with trusted human expertise delivered through Sophos’ extensive global network of managed service providers (MSPs). For organisations with a CISO, it delivers a more efficient, integrated way to manage risk, validate controls, and communicate progress to the board. For those without one, it provides practical security leadership grounded in their own environment.
Availability beginning October 2026.
• Sophos MDR
is expanding with continuous, AI-enabled threat hunting fed by the Sophos X-Ops research team and broader two-way response across endpoint, firewall, cloud, email, and identity, so threats are neutralised before they disrupt business and without the customer building a Security Operations Centre.
Generally available 15 August 2026.
• Sophos XDR
powered by Secureworks, is rebuilt on Secureworks Taegis analytics, adding thousands of detectors, a new analyst experience in Sophos Fusion, and built-in SOAR automation with playbooks, giving teams faster, higher-fidelity detection and response with less manual work.
Generally available 15 August 2026.
Related Post: New TD SYNNEX Sophos Software Store for easy Licence Renewals













