We use this solution to protect all of our computers against viruses — malware in general.
CIO at a financial services firm with 11-50 employees
Protects our devices from viruses and other forms of malware
Pros and Cons
- "It does its job — it protects us from viruses. We don't really interact with it very much."
- "It has a performance hit on a local laptop. There's an agent installed and we are bothered a lot by it because it seems to be using a lot of computer resources."
What is our primary use case?
What is most valuable?
It does its job — it protects us from viruses. We don't really interact with it very much.
What needs improvement?
It has a performance hit on a local laptop. There's an agent installed and we are bothered a lot by it because it seems to be using a lot of computer resources.
We're interested in some behavioral analysis regarding activities on all of our networks so that we can anticipate intrusions and problems before they occur. My understanding is that Sophos doesn't provide such a facility. Darktrace seems to offer an artificial intelligence solution along these lines.
For how long have I used the solution?
I have been using Sophos Intercept X for roughly two to three years.
Buyer's Guide
Intercept X Endpoint
March 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
842,388 professionals have used our research since 2012.
What do I think about the stability of the solution?
This solution seems very stable. We just installed it and forget about it.
How are customer service and support?
On the rare occasion that we've asked for help, the IT support company has delivered.
What about the implementation team?
We have a company that provides IT support for us. They recommended it and they set it up. All we had to do was install the agent on each laptop, which was a pretty easy thing to do.
What's my experience with pricing, setup cost, and licensing?
The price of this solution is reasonable.
What other advice do I have?
Overall, on a scale from one to ten, I would give this solution a rating of eight.
I would recommend this solution; it does its job as far as I'm aware. I can't tell you if it's better or worse than other software packages for security. It's the one suggested by our IT services provider. It seems to do the job. We're a bit bothered about the performance hit on the laptops, but other than that, it seems fine.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.

System Integrator, Sr Security Engineer at a tech services company with 51-200 employees
Good, reliable, and easy to deploy with zero-day protection and lesser price than other solutions
Pros and Cons
- "We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X. We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization."
- "It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day. We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person."
What is most valuable?
We find all features valuable. It has zero-day protection, which is the most valuable feature of Intercept X.
We have Intercept X with EDR. EDR is a very important feature. It gives an idea about the source of a particular attack. An administrator gets to know everything, which helps in understanding the things that need to be done or protected in the organization. Based on this information, an administrator can decide what needs to open or allowed in the network. Without EDR, Intercept X is like an antivirus, and the administrator won't get to know the things going on at the organizational level. I recommend purchasing an EDR solution for every organization.
What needs improvement?
It would be better if it can automatically generate a report for each and every user so that the users get to know the things that shouldn't be accessed from their PCs. It can have information about malicious and non-malicious sites so users are aware of them, and they don't access malicious websites. Such reports can be generated at the end of the day.
We should also be able to get through to their support team quickly. Currently, it takes more than half an hour to get through to a technical person.
For how long have I used the solution?
I have been using Intercept X with EDR for the last one year. We have its latest version. It is automatically updated through Sophos Central.
What do I think about the stability of the solution?
If an endpoint has at least 4GB RAM and the latest OS, the stability and performance are better. If RAM is too less, there is slowness.
What do I think about the scalability of the solution?
We have implemented it for so many customers. One of them has more than 1,500 users. In an on-prem solution, scalability could be challenging. For example, if you are using 1,000 endpoints and want to add 500 more, you need to expand the server memory or RAM. In a cloud solution, you don't need to do any such thing.
How are customer service and technical support?
They have a very less number of people in their technical team. When I call the Sophos team, it takes more than half an hour to connect to a technical person, which is very challenging. We should be able to get through to them quickly.
How was the initial setup?
Its initial setup is fine. If an end-user is using an old OS version, you need to download the latest patches and all other things. For Windows 10 and higher versions, only the client is downloaded from Sophos Central, and it will automatically sync with the cloud.
What about the implementation team?
I have implemented this solution for so many customers. I am pretty confident in the implementation of Intercept X.
What's my experience with pricing, setup cost, and licensing?
Its price depends on the scenario. It is very expensive, but it is not more expensive than other vendors. The price of Check Point and other vendors is much higher than Sophos.
What other advice do I have?
I would recommend Sophos Intercept X as well as Check Point.
I would rate Sophos Intercept X a ten out of ten. It is a good and reliable solution.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Intercept X Endpoint
March 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
842,388 professionals have used our research since 2012.
Managed Services Mng at a computer software company with 1,001-5,000 employees
A solid solution that has a good common dashboard feature
Pros and Cons
- "I am impressed with the tool's common dashboard feature. The solution is also easy to deploy and manage. Reporting is also easy with the software."
- "The tool should be made compatible with Linux and Microsoft operating systems."
What is our primary use case?
We use the tool for complete surface deployment. My company uses it not only to manage endpoints but for mobile management as well.
What is most valuable?
I am impressed with the tool's common dashboard feature. The solution is also easy to deploy and manage. Reporting is also easy with the software.
What needs improvement?
The tool should be made compatible with Linux and Microsoft operating systems.
For how long have I used the solution?
I have been working with the tool for five years.
What do I think about the stability of the solution?
The product's stability is really good. It is a solid solution. I would rate the solution's stability a nine out of ten.
What do I think about the scalability of the solution?
The tool is scalable. I would rate its scalability a nine out of ten.
How are customer service and support?
The product's tech support is good.
How was the initial setup?
The product's deployment is easy and straightforward. The tool's deployment is quick and gets completed in an hour.
What's my experience with pricing, setup cost, and licensing?
The solution offers both a three-year license and an annual license. I would rate the product's pricing a one out of ten.
What other advice do I have?
I would rate the solution a nine out of ten. The tool is a really good product. If you are looking to use the solution, give it a try. You will not be disappointed with its use. Most of the tool's competitors have either difficulty in management or installation. We have used all of them.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Technical Support at a tech services company with 11-50 employees
Smart protection and machine learning capabilities are good
Pros and Cons
- "Intercept X's smart prevention it's very good as so are its machine learning capabilities for troubleshooting channels and files."
- "Intercept X needs more reporting and device management features, so I can get messages from PCs that let me know if I need to do something with them."
What is our primary use case?
We currently have about 13 staff using Intercept X. We use it to secure and protect our devices as well as monitor projects and do some product reviews. You can also use it to block devices as needed, like if you just want to block a work point category.
What is most valuable?
Intercept X's smart prevention it's very good as so are its machine learning capabilities for troubleshooting channels and files.
What needs improvement?
Intercept X needs more reporting and device management features, so I can get messages from PCs that let me know if I need to do something with them. For example, they could add a report that shows me the versions of the devices on the infrastructure server, so I can make sure all the devices are updated.
For how long have I used the solution?
I've used Intercept X for three years.
What do I think about the stability of the solution?
Intercept X is good in terms of both performance and stability. It's not constantly updating the device or using up too many resources.
What do I think about the scalability of the solution?
I would say that Intercept X is easy to scale.
How are customer service and support?
Sophos support is very good. I don't talk to them that much, though. I can usually handle everything because it's not complicated. However, in the past, I have contacted support because there were some features I didn't know how to use or configure.
How was the initial setup?
The setup was simple. I deployed this by myself. Though my team and I got some help from the vendor for new features that I didn't know about.
What other advice do I have?
I would rate Intercept X eight out of 10
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
A scalable, stable and easily installable solution
Pros and Cons
- "The solution is scalable."
- "Through Sophos Central I would like to see the ability to zero in and produce a report about the challenges being faced by a particular machine and user, to know if a virus is appearing only on that specific machine or also on others."
What is our primary use case?
I am not in the office at the moment and would have to check which version we are using.
What is most valuable?
We have a firewall, for which we will be adding support and integration capabilities.
What needs improvement?
Through Sophos Central I would like to see the ability to zero in and produce a report about the challenges being faced by a particular machine and user, to know if a virus is appearing only on that specific machine or also on others. This way I could know if a virus or issue is a result of an identifiable program that the user may have downloaded.
Also, while the tamper protection is a very good feature, it requires of me to first login to Sophos Central and then look for the Sophos protection password for the particular machine I wish to use. While this is definitely good, this could pose an issue when the internet connection is not working up to speed, something which is occasionally problematic for some of us here in Africa.
For how long have I used the solution?
I have been using Sophos Intercept X for three years.
What do I think about the stability of the solution?
From what I can observe, I would say that the solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and technical support?
You provide us with technical support through our partner relationship.
How was the initial setup?
The initial set up for me was not an issue. I found it to be simple and straightforward, although I cannot recall how long it took, as it has been a while.
What other advice do I have?
I would recommend the solution to others.
I rate Sophos Intercept X as a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Technical Manager at Digital World
Comparable pricing, stable and scalable, easy to install
Pros and Cons
- "This solution can be used with any device, mobiles, desktops, or any appliances."
- "When I use a proxy, I can bypass Sophos, which is an area that needs improvement."
What is most valuable?
This solution can be used with any device including mobiles, desktops, or any appliances.
What needs improvement?
When I use a proxy, I can bypass Sophos, which is an area that needs improvement.
For how long have I used the solution?
We have been providing this solution for one year.
What do I think about the stability of the solution?
It's a stable product.
What do I think about the scalability of the solution?
It's scalable. We have 50 customers.
How are customer service and technical support?
Technical support should be faster.
How was the initial setup?
The initial setup is straightforward. The installation is easy, and it's faster than SAP.
Sophos Intercept can be deployed in a couple of minutes.
It will take one hour to deploy it for a firewall, and only 15 minutes for the endpoint protection.
We need one engineer to deploy this solution.
What's my experience with pricing, setup cost, and licensing?
The price is okay. It's comparable with other solutions.
You can purchase a license for one to three years.
What other advice do I have?
I would recommend this solution.
I have no issues with this solution, I would rate it a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
System Integrator IT Manager at Tecnimex S.r.l.
It is very stable and I like the monitoring I get over my clients
Pros and Cons
- "A valuable feature offered by Sophos is called Naked Security, and it entails the control managed by the firewall on the site regarding the desktop client interfacing with our cloud client."
- "The initial setup was not very user-friendly."
What is our primary use case?
Our primary use case for this solution is to offer a complete and monitored solution regarding ransomware protection to all my clients & servers.
How has it helped my organization?
Sophos improved our organization allowing us to setup a very efficient solution, cloud managed, introducing a new modern concept: Syncronized Security (between Firewall and end-point)
What is most valuable?
A valuable feature offered by Sophos is called Naked Security and it entails the control managed by the firewall on the site regarding the desktop client interfacing with our cloud client. So we have a central management console where we can observe and act and manage all our customers. It's like a proper perfect solution.
What needs improvement?
Something that could be improved is to better integrate all different platform available at the moment (not only allow pcs, servers but also other o.s. platforms, Android & IOS and so on too). It should be more user-friendly, automated and able to manage and analyze the logging of the operation, provided that Intercept X is one part of a more complete security solution (Syncronized Security - between firewall, endpoint, mobile devs). Logging & reporting is very important for us, especially in Italy.
For how long have I used the solution?
We've been using Sophos Intercept X ( /products/sophos-intercept-x-reviews ) for two to three years now on public cloud.
What do I think about the stability of the solution?
I am satisfied with the program's stability. There were some maintenance problems, but very rarely. We generally receive an alert from Sophos when there will be maintenance operations, so we can plan accordingly.
What do I think about the scalability of the solution?
The program is very scalable. We have about 300 computers, servers, work stations and mobile devices in our company. We have one staff member who is responsible for maintenance. We are all system integrators in our office and we plan to increase our usage soon.
How are customer service and technical support?
The support wasn't very good initially, but they became better. Compared to other brands' support, I'm quite satisfied about the support we get now.
Which solution did I use previously and why did I switch?
We used a few different products to achieve one objective, but now, with Sophos Intercept, we've solved our problem, reducing dramatically manual monitoring activities.
How was the initial setup?
The initial setup was not very user-friendly, but it improved during the evolution. It was rather difficult at first. Our deployment took half a day. Especially if we consider the Intercept X inside the final solution. We had to plan the setup. It all depends on the number of clients, of course. We did everything by ourselves because we are certified partners; we don't need external consultants.
What's my experience with pricing, setup cost, and licensing?
We pay an annual license fee.
What other advice do I have?
My advice to others would be to get certification over time because without certification, it's not so easy to setup and use. Users should familiarize themselves with all the features of the program. On a scale of one to ten, my rating is nine, because of the few missing features that I think should be added in a close future.
Disclosure: My company has a business relationship with this vendor other than being a customer: Silver Solution Partner
Business Development Manager at Computer Learning centre
Stable and scalable solution that provides endpoint detection and response, email protection, and data loss prevention
Pros and Cons
- "Solution for endpoint detection and response, with good stability and scalability. Users also benefit from email protection and data loss prevention."
- "Installing Sophos Intercept X was not as straightforward, as we had to ask support and had to work with an integrator, though the process didn't take much time, e.g. it was completed within one hour."
What is our primary use case?
We use a normal EDR solution in the office: Sophos Intercept X, for endpoint detection and response, email protection, and data loss prevention.
For how long have I used the solution?
I've been using Sophos Intercept X for a long time, and I'm currently in my second year of using the solution.
What do I think about the stability of the solution?
Sophos Intercept X is a very stable solution.
What do I think about the scalability of the solution?
My impression of Sophos Intercept X is that it's a scalable solution.
How was the initial setup?
For the installation of Sophos Intercept X, we had to ask support from their sales staff. The installation process didn't take much time, as it was completed within an hour.
What about the implementation team?
We implemented the solution through an integrator.
What's my experience with pricing, setup cost, and licensing?
We pay for the Sophos Intercept X license annually.
Which other solutions did I evaluate?
We were initially using ESET.
What other advice do I have?
I'm not yet satisfied with Sophos Intercept X, but I know how to use it. It's good for now, so I can't think of what I'd like to change in the solution.
We have up to 25 users of Sophos Intercept X, and one person in charge of the deployment and maintenance of the solution. For the installation, that person works with an external consultant.
I'm recommending this solution to others who may want to start using it.
I'm rating Sophos Intercept X an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cisco Secure Endpoint
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
Symantec Endpoint Security
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?