trueNetLab logo
EN
Sophos Fusion: Real Progress or Just Another New Name?

Sophos Fusion: Real Progress or Just Another New Name?

At first glance, Sophos Fusion looks like a new product. The name is big, the videos are dark blue, data streams glow everywhere, and of course the term AI-native cannot be missing in 2026. In the short introductory video, Fusion sees everything, connects everything, and responds as one.

After 66 seconds, you still know hardly any more than before.

Do I have to buy Sophos Fusion? Does it replace Sophos Central? Do I need a new license? Does it make my firewall better? Is this the next generation of XDR and MDR, or merely a new label on products that were already there?

The short answer is: Sophos Fusion is not a new license or a single product. It is the new name and the new architectural story around Sophos Central. There are real technical changes behind it, especially in XDR and MDR. At the same time, Fusion is a very cleverly constructed sales logic for additional products and paid add-ons.

Both can be true at the same time.

Sophos Fusion is not a new product. But it is a very effective new sales product.

What Sophos Fusion Actually Is

Sophos describes Fusion as an AI-Native Cybersecurity Defense System. That initially sounds like a new product category, but it becomes easier to understand when the marketing term is broken down.

Fusion is intended to connect Sophos Endpoint, Firewall, Email, Cloud, Network, Identity, Workspace Protection, XDR, and MDR with data from third-party products in a shared architecture. Telemetry lands in a common context store. Detections should not remain trapped in individual products but should be able to trigger automated responses at other control points. AI is supposed to investigate large volumes of alerts and respond within approved boundaries, while humans retain the high-risk decisions.

Sophos identifies five components:

  • Control Points: Sophos products and connected third-party tools provide data and can execute responses.
  • Unified Context Lake: Telemetry from these sources is stored and evaluated with shared context.
  • Synchronized Security: A detection in one place can trigger a response elsewhere.
  • Agentic Autonomy: AI may investigate and respond within defined boundaries.
  • Compounding Intelligence: Insights from the customer base protected by Sophos are intended to improve protection for all customers.

That is not insignificant. A compromised endpoint, a suspicious user, a malicious email, and an unusual network connection often belong to the same incident. If these signals are considered separately, a person has to piece the connections together with considerable effort. If they are brought together technically, detection and response can become faster and more precise.

The underlying idea is not new, however. Synchronized Security has connected Sophos Endpoint and Sophos Firewall for years. Sophos Central was already the shared management layer. XDR collects data from multiple sources, MDR investigates it as a service, and a data lake is not a concept invented with Fusion.

Fusion is therefore less the birth of a completely new platform than the consolidation, extension, and renaming of an existing strategy. The Secureworks acquisition supplies important technology, detectors, and security operations experience. The new name supplies the story with which Sophos can sell all of this as one major leap.

Is Fusion a New Product or a New License?

No. At least not directly.

Sophos explicitly says that Fusion is not a separate product, not a bundle, and not its own SKU. Existing customers do not need to order anything to become part of Fusion. Sophos Central will gradually adopt the Fusion name over the coming months while existing workflows are expected to continue.

That is the reassuring half of the answer.

The other half is that very real purchasable components are emerging around Fusion. These include Sophos Next-Gen SIEM, Sophos AI Defense, and Sophos CISO Advantage. The more powerful XDR and MDR capabilities remain tied to the relevant licenses. Anyone who owns only Endpoint Protection or a firewall does not suddenly receive the capabilities of a SOC because of the new umbrella brand.

This creates a familiar platform logic:

  • Does Fusion need to be purchased separately? No, Fusion itself does not have its own SKU.
  • Is Sophos Central being replaced? The service is being developed further and gradually renamed Fusion.
  • Will all AI features be free? No. Some are included in existing products, while others arrive as add-ons or higher-tier licenses.
  • Does an individual firewall automatically become better? No. The value only emerges through telemetry, integrations, suitable licenses, and enabled response actions.
  • Is Fusion only marketing? No. But the marketing promises considerably more unity than a mixed customer tenant automatically delivers today.

Fusion is therefore not a new license. It is, however, the architecture on which Sophos can explain and sell many additional licenses in the future.

The Real Progress Is in XDR and MDR

Customers using Sophos XDR or Sophos MDR receive the largest tangible part of the Fusion strategy. The new capabilities are scheduled to roll out gradually to conventional customers from August 2026, with MSP environments following later.

In Sophos XDR, a new Security Operations interface replaces the previous Threat Analysis Center. Secureworks technology contributes additional detectors and detection logic. There are also custom rules, more integrations, bidirectional responses, and SOAR capabilities. An analyst should therefore not only be able to see data from Microsoft 365, Okta, or other sources, but—depending on the integration and permissions—also trigger actions back into those systems.

That is real progress. An integration that only imports logs is useful. An integration that locks a user, isolates a device, or controls another control point is considerably more valuable in operations.

In Sophos MDR, the same architecture is combined with the 24/7 service. AI is intended to take over a larger portion of triage, investigation, and response. Sophos cites its own operational figures, saying that 52 percent of cases are handled entirely by AI and that the average time between an alert and an automated response is 89 seconds.

Those figures sound impressive, but they need context. The 89 seconds apply to cases in which an automated response is authorized and possible in the first place. They do not mean that every attack is resolved after 89 seconds. The 52 percent also does not mean that the hardest 52 percent require no humans. Sophos itself emphasizes that the remaining cases need human judgment.

That is the right way to understand it: AI is not a digital magic SOC that understands every attack. It is an accelerator for recurring work that can be bounded clearly enough. That can be highly valuable because seconds matter during an active compromise. But it replaces neither clean data nor qualified analysts nor sensible approval boundaries.

The MDR names are moving again as well. MDR Essentials becomes MDR, while MDR Complete becomes MDR Plus. Sophos can describe that as simplification. Customers and partners are still entitled to be annoyed when service tiers once again have to be compared, documented, and explained at the next renewal.

What Changes for Endpoint and Central Customers?

For a customer with Sophos Endpoint, little changes at first because of the Fusion name. The agent remains installed, policies remain in central management, and protection features do not disappear overnight. The endpoint is, however, presented more strongly as a control point within the overall system.

It becomes technically interesting when endpoint signals are correlated with identity, email, network, and third-party telemetry. A single malware alert can then become a connected case: the user signed in unusually shortly beforehand, opened a suspicious message, and then established a connection to a new destination. Ideally, XDR or MDR sees one attack path rather than four isolated events.

But the same rule applies here: a new name does not create data. Anyone who owns only an endpoint license, connects no additional data sources, and authorizes no response actions does not get the same effect as a fully integrated XDR or MDR environment.

The phrase “all Sophos customers are already part of Fusion” is therefore formally correct but practically misleading. Everyone is running on the same strategic platform. That does not mean they all own the same capabilities.

What Changes for Sophos Firewall?

For firewall administrators, the most important answer is pleasantly uneventful: Fusion does not replace SFOS and does not introduce a new firewall license. A firewall remains a firewall, local rules remain local rules, and the new brand name makes an existing XGS appliance neither faster nor more stable.

Fusion becomes relevant where the firewall is integrated as a sensor and response point in a broader chain. Endpoint detections can restrict network access through Synchronized Security and Active Threat Response. Firewall telemetry can complement XDR and MDR investigations. New APIs create additional options for central management and AI Defense, including web policies, URL groups, and rules.

That makes sense. A firewall sees connections that may be incomplete or entirely invisible on the endpoint. Conversely, the endpoint understands processes and user context that the firewall lacks. When both perspectives are combined properly, the result is more than the sum of the individual logs.

Even so, nobody should buy a firewall simply because Fusion now appears on the website. The decisive questions remain the same:

  • What data does the firewall actually provide to XDR or MDR?
  • Which responses can be triggered automatically?
  • Which licenses are required?
  • What happens if Central or the internet connection is unavailable?
  • Which capabilities remain local, and which depend on the cloud service?

The new hardware-as-a-service approach for MSPs also fits this strategy. Monthly hardware, licensing, and service relationships can simplify procurement. But they also tie customers more closely to Sophos and to the managing partner. That is not automatically bad. It simply should not be sold as a technical necessity when it is also a commercial operating model.

Switch, Wireless, Workspace, ZTNA, Email, and ITDR

The many Sophos announcements around the Fusion launch create the impression that every product is becoming part of one major new system at the same time. Some of that is justified.

Sophos Switch and AP6 Access Points provide additional connection data to the Data Lake through Live Discover. Workspace Protection can make Protected Browser data visible and queryable through XDR. ITDR calculates an identity risk score from configuration, behavior, and detected issues. Email cases and notifications are being drawn more closely into the central Security Operations interface.

These are building blocks from which a more connected picture can emerge. Network and identity signals are particularly valuable because modern attacks rarely remain on a single endpoint.

Other announcements from the same month are simply normal product maintenance. Multi-domain support in ZTNA, macOS beta compatibility, Config Studio 2.6, or new notification settings do not automatically become Fusion innovations merely because they appear at the same time. Sophos is continuing to develop its products. That is good, but it does not prove that every product already responds to every other product in real time.

A simple distinction is useful here:

  • Telemetry available: A product provides data.
  • Context available: The data is correctly assigned to a shared case.
  • Response available: Another product can execute a useful action.
  • Automation available: That response is allowed to run without a manual handoff or approval.

Only when all four layers work does an integration become a genuine defense system. The number of logos on an integrations page says remarkably little about that.

350 or 500 Integrations Is Not the Most Important Question

The first public FAQ referred to more than 350 third-party integrations. The current Fusion page cites more than 500 Sophos and third-party integrations. Such figures can change because of new connectors, a different counting method, or the inclusion of Sophos products.

They also demonstrate why pure marketing numbers should be read cautiously.

An integration can be a complete bidirectional connector. It can also merely ingest events, provide a query, or rely on an API that the customer has to configure. Five hundred integrations do not mean five hundred equally capable response options.

For a customer, five well-supported integrations into the actual environment are worth more than five hundred logos of which 490 will never be used. Before making a decision, the following should therefore be clarified for every important source:

  • Which data is ingested?
  • How quickly does it become available?
  • Which fields and retention periods apply?
  • Is the integration included in the existing product?
  • Can Fusion only see, or can it also respond?
  • Who carries the risk of an incorrect automated response?

The term open architecture sounds like low vendor dependency. In reality, a platform can be open to data sources while still being highly binding operationally. The more detection logic, retention, workflows, and response actions reside in Fusion, the harder a later move becomes.

Open on import does not automatically mean open on exit.

What Is Really Behind the AI?

Sophos has used AI for years for malware detection, classification, prioritization, and threat hunting. Fusion adds agentic workflows to these methods: the system is intended to gather information, form hypotheses, run additional queries, and respond within defined boundaries.

That is far more interesting than a chat window with attractive summaries. A system that enriches an alert with identity and network data, discards known benign patterns, and isolates an endpoint when confidence is sufficiently high can genuinely relieve analysts.

But “AI-native” does not answer the most important security questions:

  • Which models or methods make which decisions?
  • How are incorrect decisions detected?
  • Which actions require human approval?
  • How are prompt injection and manipulated telemetry handled?
  • Which customer data flows into training or ongoing improvement?
  • What evidence remains available for audit and forensics?

The Sophos AI Security 2026 Report is more interesting at this point than the Fusion advertising. Sophos’ own research does not describe AI as a new magical class of attack. AI compresses timelines, scales existing methods, and makes defense harder through speed and volume. At the same time, proving concrete AI use in many attacks remains difficult.

The same sober view should apply to defense. AI can accelerate investigation and response. It does not turn poor telemetry into good telemetry, replace an identity strategy, or patch an unpatched vulnerability. Anyone allowing agents to perform actions needs particularly clean permissions, logging, and boundaries.

The best description of Fusion is not “AI protects everything,” but this: good telemetry, shared context, and bounded automation should work together faster.

The Pricing Question Sophos Has Not Answered

There is currently no announced Fusion fee. Existing customers are not being forced onto a new license solely because of the new name. That should be stated clearly.

But another point is equally clear: Sophos is building Fusion as a growth engine. Public partner information discusses additional solutions, recurring revenue, expansion within existing customers, and new services. Next-Gen SIEM is an add-on. AI Defense will be an add-on for customers with EDR, XDR, or MDR. CISO Advantage is intended to be sold as a structured, recurring MSP service.

That is a legitimate business model. Sophos is not a charity. If SIEM stores more data, AI Defense makes generative AI visible and controllable within a company, or a CISO service performs real work, it is reasonable for that to cost money.

It becomes problematic when AI capabilities are first integrated into existing products and later used to justify higher base prices—even for customers who neither asked for those capabilities nor can use them sensibly.

Microsoft shows that this concern is not imaginary. In 2025, Microsoft integrated Copilot into Microsoft 365 Personal and Family while simultaneously raising the price in the United States by three dollars per month. Options existed to move to plans without Copilot, but the direction was clear: AI became part of an existing subscription and part of the justification for a higher price.

Similar steps are being discussed around Apple, iCloud+, and additional AI usage. What has been confirmed so far is only that higher AI limits are tied to certain iCloud+ plans. A general iCloud price increase because of AI is not a fact at the time of this article and should not be presented as one.

For Sophos customers, the decisive question is therefore not whether Fusion is a new license today. The decisive question is what happens at the next renewal:

  • Will existing XDR and MDR capabilities remain at the current price?
  • Which Fusion capabilities will move into paid add-ons?
  • Will old packages continue to be offered or be migrated into new tiers?
  • Can AI capabilities be deselected if they provide no value?
  • How will data volume, retention, and automation be priced in the future?

I would not claim an unannounced price increase. But for multi-year agreements, I would obtain pricing limits, exact service descriptions, and a termination and export plan in writing. Anyone relying only on the promise that Fusion is “not a new product” is answering the wrong question.

The Real Risk Is Growing Dependency

Fusion becomes more valuable as more data sources and response points are connected. That is precisely how dependency also grows.

An organization buying Endpoint, Firewall, Email, Identity, Switch, Wireless, XDR, MDR, and SIEM from Sophos can genuinely benefit from tight correlation and automated response. At the same time, operational knowledge, detection rules, historical data, processes, and contracts move to a single vendor.

That is the classic platform trade: less integration work today in exchange for higher switching costs tomorrow.

Sophos advertises that existing third-party products can continue to be used and connected through open integrations. That is positive. Nevertheless, nobody should confuse “open” with “interchangeable.” A connector makes data import easier. It does not guarantee that cases, context, queries, automations, and years of telemetry can be exported losslessly to another platform.

Skepticism is understandable, particularly with Sophos, because product names, packages, and strategic priorities have repeatedly shifted. Sophos Cloud became Sophos Central. MTR became MDR. The MDR tiers are being renamed again. The long-running Intercept X story became the MDR story, and now Fusion is intended to be the term under which everything comes together.

The exaggerated claim that Sophos never keeps a product name for more than three years is not actually true. Sophos Central had already turned ten in 2023, and Intercept X has also been in the market for many years. The problem is not that every name disappears immediately. The problem is that customers regularly have to reassess new package logic, names, add-ons, and strategic priorities.

For partners, that means a new presentation every time. For customers, it means asking every time whether their existing license still contains the product they originally bought.

What Customers and Administrators Should Check Now

Fusion is not a reason for a rushed product change. It is, however, a good occasion to inventory the existing Sophos architecture soberly.

First, determine which products and licenses are actually present. Not which Fusion slide theoretically covers them, but which data sources are active in the tenant, which retention periods apply, and which responses work today.

Then test a realistic attack scenario. Is an endpoint isolated? Does the firewall block access? Do identity and email signals appear in the same case? Does the analyst still have to move between several interfaces? How well is the automated decision explained?

For XDR and MDR customers, the transition to the new Security Operations interface is also relevant. Certain response integrations, including Microsoft 365 and Okta, may require reauthorization. Existing reports and workflows should also be checked because Sophos is retiring some MDR reports while new self-service reporting will only arrive later.

Before the next renewal, the commercial boundaries should be placed on the table: the current price, the expected renewal price, included Fusion capabilities, costs for SIEM storage and retention, AI Defense, the MDR tier, and export options.

Finally, an exit plan is necessary. Not because Sophos will disappear tomorrow, but because every good architecture should survive a vendor change. Which logs can be exported? Which firewall and endpoint capabilities continue to operate without a cloud connection? How much history is lost? Which integrations would have to be rebuilt?

Anyone who can answer these questions uses Fusion deliberately. Anyone who cannot is being used by Fusion.

My Conclusion

Sophos Fusion is more than a new logo, but less than the revolution the marketing makes it out to be.

The real value lies in tighter connections between telemetry, context, and response. XDR and MDR customers in particular can benefit from Secureworks detectors, more integrations, SOAR, bidirectional actions, and faster automated investigation. Additional network, workspace, and identity signals can also turn individual alerts into a better overall picture.

For a customer with a single Sophos Firewall or a basic endpoint license, however, the term Fusion changes little. Products do not automatically become more intelligent simply because they are now described as part of a “Defense System.” Without suitable licenses, data sources, configuration, and authorized responses, Fusion remains primarily a new heading above Sophos Central.

My larger concern is therefore not the technology. Much of the technology makes sense.

My concern is the combination of an umbrella brand, add-ons, subscription models, and growing vendor dependency. Sophos can position almost any future extension as a missing component of the Fusion system. The more a customer buys, the better the coordinated defense may work—and the more expensive and difficult the exit becomes.

Fusion should therefore not be judged with the question: “Does it contain AI?”

The better questions are: Which specific detection improves? Which response becomes faster? Which work disappears for my team? Which capability costs extra? Which data can I take back out? And what happens to the price at the next renewal?

If Sophos answers these questions cleanly and the technical promises hold up in everyday operations, Fusion can be a strong evolution of Central.

If not, Fusion is primarily the next big word with which a vendor wraps familiar products, new add-ons, and old dependencies in more modern packaging.

Until next time,
Joe

FAQ

What is Sophos Fusion?
Sophos Fusion is not a single product or a separate license. It is the evolution and gradual renaming of Sophos Central into a shared architecture for Sophos products, third-party integrations, XDR, MDR, and automated responses.
Do existing Sophos customers have to buy Fusion?
No. Fusion itself has no separate SKU. The actual capabilities still depend on the existing Endpoint, XDR, MDR, Firewall, and add-on licenses. Next-Gen SIEM, AI Defense, and CISO Advantage are additional offerings.
What does Fusion add for Sophos Firewall?
Fusion does not automatically change SFOS or the firewall license. The value appears when firewall telemetry is combined with endpoint, identity, email, or XDR data and the firewall serves as a response point for Synchronized Security or Active Threat Response.
Which customers benefit the most?
Sophos XDR and Sophos MDR customers receive the largest direct benefit. They get the new Security Operations interface, additional Secureworks detectors, more integrations, SOAR capabilities, and expanded automated responses.
Will Sophos prices increase because of Fusion?
Sophos has not announced a general Fusion price increase. Higher total costs remain a risk because some new capabilities are sold as add-ons and Sophos explicitly uses Fusion to expand existing customer relationships. A future price increase should therefore be treated as a risk, not as a confirmed fact.
Is Sophos Fusion only marketing?
No. The XDR and MDR enhancements, additional telemetry, shared context data, and automated responses are technically relevant. It becomes marketing when integration counts or the term AI-native are used to imply that every customer already has a fully connected system.
Sources