Sophos Gets IDC Recognition Thanks to Key Milestones
Cited for Key Protection Technologies and Proactive Defence Capabilities

Sophos, a global leader of innovative security solutions for defeating cyberattacks, has announced it has been named a Leader in the IDC MarketScape™: Worldwide Extended Detection and Response (XDR) Software 2025 Vendor Assessment (doc #US52997325, September 2025) report.
The IDC MarketScape for Extended Detection and Response cites Sophos’ protection capabilities as a strength, noting: “Sophos is viewed favourably in terms of the protections it offers. Key protection technologies included as standard features on the endpoint are host-based firewall and IDS/IPS, device control, DLP, antimalware scans, and encryption.”
The report also highlights Sophos’ proactive defence capabilities, with IDC stating: “Colloquially known as ‘Shields Up,’ Sophos’ Adaptive Attack Protection was introduced in 2023. Adaptive attack protection automatically enforces certain protections if there is evidence of a ‘hands-on-keyboard’ attack.”
“Sophos’ prevention-first strategy is designed to stop breaches before they happen, adapt defences in real time, and strengthen detection and response when it matters most,” said Kyle Falkenhagen, SVP, Product Management, at Sophos. “We believe being named a Leader in the IDC MarketScape for XDR is powerful recognition of our strategy to deliver intelligent, adaptive, and integrated cybersecurity. Sophos XDR empowers organisations to detect and respond to threats faster with Artificial Intelligence (AI)-driven workflows, an extensive massive ecosystem of integrations, and a unified platform that scales from SMBs to enterprises. As we continue integrating Secureworks Taegis into our Sophos Central platform, we’re accelerating innovation and expanding our ability to help customers stay ahead of evolving threats with resilient, scalable security operations.”
“While Sophos has been working on many of these technologies internally, the integration of the Taegis XDR platform adds heft to existing capabilities and jumpstarts engineering cycles to newer initiatives,” said Chris Kissel, IDC Research Vice President.
Empowering the Defence of Businesses Big and Small
When highlighting when to consider Sophos, the report notes: “Sophos has an international presence, and its ecosystem is designed to empower businesses of all sizes and all types. Cybersecurity novices, intermediate users, and experts will gain value from the Sophos XDR platform.”
Sophos Extended Detection and Response (XDR) provides organisations with powerful tools and intelligence to detect, investigate, and neutralise threats across the entire IT ecosystem. Delivered through an adaptive, AI-native, open platform,
Sophos XDR helps security teams stay ahead of attackers while reducing operational complexity.

Key capabilities of Sophos XDR include:
- Prevention-First Approach: Sophos Endpoint is included and natively integrated with Sophos XDD. Sophos Endpoint stops advanced threats before they escalate, enabling organisations to focus investigations on critical priorities.
- AI-Accelerated Security Operations: Embedded AI tools deliver real-time insights, contextualise threat data, and provide natural language recommendations. The AI Assistant, developed in partnership with Sophos MDR frontline analysts, streamlines investigations with proven workflows.
- Identity Protection: Sophos XDR includes turnkey integrations with a range of identity technologies and is tightly integrated with the new Sophos Identity Threat Detection and Response (ITDR) solution, providing comprehensive visibility of identity-based threats, misconfigurations, and suspicious user behaviou
- Automated and Adaptive Defences: Automated responses—from isolating endpoints to enforcing MFA and rolling back ransomware damage—activate during attacks to minimise impact and speed recovery.
- Ecosystem Flexibility: An extensive range of turnkey integrations enables Sophos XDR to fit seamlessly into diverse IT environments, enhancing existing investments without disruption.
- Open, Unified Platform: A single, extensible platform provides visibility across the entire attack surface, reduces noise from unactionable alerts, and unifies detection and response.

Following Sophos’ acquisition of Secureworks in February 2025, Sophos Endpoint is now natively integrated and automatically included with Taegis XDR and Taegis MDR subscriptions. This milestone delivers combined prevention, detection, and response in a single platform with lower licencing costs and simplified operations. This integration strengthens protection, accelerates threat mitigation, and ensures customers maximise ROI while maintaining flexibility.
Sophos Industry Validation
Sophos XDR is not just leading in innovation; it is earning awards and accolades. From analysts to end users, Sophos recognition includes:
- Sophos was named a Gartner “Customers’ Choice” for XDR in the inaugural version of the report, “Customers’ Choice” for EPP, for the fourth consecutive year, a “Customers’ Choice” for MDR for the second consecutive year.
- Sophos was named a G2 Leader in Endpoint Protection, XDR, EDR, MDR, and Firewall in its Fall 2025 Grid Reports.
- Sophos was named a Leader in the Gartner® Magic Quadrant™ for Endpoint Protection Platforms for the 16th consecutive report.
- Sophos was named a Leader in the 2025 Frost Radar™ for Managed Detection and Response.
- Sophos was the ONLY vendor named a “Customers’ Choice” in both EPP and XDR.
Read an excerpt of the IDC MarketScape™: Worldwide Extended Detection and Response (XDR) Software 2025. Learn more about Sophos XDR.



