Sophos has announced the launch of Sophos Fusion, the industry’s most comprehensive AI-native cybersecurity defense system, designed to deliver a coordinated response to threats in the age of AI.

A cybersecurity defense system is an emerging category in the industry: a single, open architecture in which each control point, each service, each data source, and each analyst operate as a whole, regardless of whether the control point is native or third-party. Each new source improves the system, accelerating results while reducing costs.

The AI ​​era has changed the demands of modern defense. Attacks can now move across an organization’s entire environment as a single coordinated operation, further reducing the time from first access to impact from days to hours.

Most security and IT managers are trying to cope with that speed with an increasing number of disjointed tools. A typical company uses more than 45 different security products, generating more expense, more control panels and more manual work, while attackers move at machine speed.

A cybersecurity defense system responds to this market challenge, being defined by four key characteristics:

A shared ‘context lake’, where all signals from all control points flow into a single real-time data layer.

Synchronized Security™, where a detection at one control point triggers a coordinated action at the rest of the points at the same time.

Agent autonomy with human supervision, in which the system investigates and responds within limits established and continually calibrated by analysts.

Cumulative intelligence, in which each detected threat reinforces the defense of all clients.

Sophos Fusion is the evolution of Sophos Central, the system trusted every day by 625,000 organizations around the world, now redesigned on an open architecture that incorporates Secureworks Taegis analytics following the company’s acquisition in 2025.

This system leverages agentic AI to connect and synchronize all control points throughout the environment. And Sophos demonstrates its effectiveness and scalability in its own operation, managing the world’s largest agent-based SOC with more than 40,000 customers: 52% of cases are resolved entirely through AI, and the average time from alert to a fully automated response is 89 seconds. Additionally, Sophos Endpoint is designed to stop entire categories of behavior-based attacks, such as memory abuse, encryption and data exfiltration, as well as other attack techniques used by human or AI attackers.

“As AI increases the speed, scale and complexity of attacks, organizations need a modern, connected, intelligent and adaptive defense,” said Joe Levy, CEO of Sophos. “Sophos Fusion is designed as a defense system optimized for workflows where people and AI collaborate. We bring the most complete solution to a new category, a timely advance that the AI ​​era demands.”

Sophos Fusion offers endpoint protection, endpoint detection and response (EDR), extended detection and response (XDR), next-generation SIEM, identity threat detection and response (ITDR), managed detection and response (MDR), network security, email, cloud and advisory services, all integrated into a single defense system.

It is an open and native system: Sophos develops the core control points natively, and more than 500 third-party integrations feed the same shared data layer, so the endpoint, firewall or identity tools an organization already has work as part of the system alongside Sophos defense and protection.

Expanding the Sophos Fusion defense system

Sophos is expanding Fusion with the following capabilities, due for general availability between August and October 2026:

  • Sophos Next-Gen SIEM provides long-term data retention, compliance reporting, and analytics on the same unified data, with pricing based on the number of users and servers rather than data volume, so organizations can include all of their telemetry without unpredictable billing or gaps in data retention. Generally available starting August 15, 2026.
  • Sophos AI Defense protects AI that organizations are adopting, giving them visibility into the AI ​​tools in use – including ‘shadow AI’ -, control to enforce policies and protection of the data those tools can access, all based on capabilities that are already built into the system. Early access in August 2026; general availability in October 2026.
  • Sophos CISO Advantage offers all organizations access to CISO-level guidance, with continuous validation of controls, compliance mapping, benchmarking and risk assessment, regardless of whether they have a CISO or not. It combines integrated technology, agent-based AI and active threat intelligence in Sophos Fusion with the trusted human expertise provided by Sophos’ extensive global network of managed service providers (MSPs). For organizations with a CISO, it offers a more efficient and integrated way to manage risk, validate controls, and communicate progress to the board. For those who don’t have it, it provides practical security leadership based on their real-world environment. Available from October 2026.
  • Sophos MDR It is extended with continuous AI-based threat hunting – powered by the Sophos Generally available starting August 15, 2026.
  • Sophos XDR powered by Secureworks is redesigned based on Secureworks Taegis analytics, incorporating thousands of detectors, a new analyst experience in Sophos Fusion, and integrated SOAR automation with response scripts, giving teams faster, more accurate detection and response with less manual work. Generally available starting August 15, 2026.

Sophos operates through one of the largest global ecosystems of MSPs, managed security service providers (MSSPs), resellers, distributors and technology partners. Sophos Fusion offers partners a single system they can sell and manage, rather than a set of standalone products, generating new avenues for recurring revenue through Sophos CISO Advantage – designed specifically for the MSP model – and turning partners into strategic security advisors. Because intelligence is aggregated across all protected environments, each customer managed by a partner benefits from all Sophos threat detections elsewhere, reinforcing the results that partners deliver.