Sophos - Experts & Thought Leaders

Latest Sophos news & announcements

Sophos launches CISO advantage for AI-driven security

Sophos, a global cybersecurity pioneer, launches Sophos CISO Advantage, an agentic AI-enabled solution that connects security operations to security strategy. The solution gives organizations a clear picture of their cyber risk, a prioritised plan to reduce it, and measurable proof of progress, in plain language that business leaders can understand, fund, and act on. Delivered through Sophos Fusion, the Sophos AI-Native Cybersecurity Defense System, Sophos CISO Advantage begins rolling out today across North America, the UK, and the rest of Europe. Strong cybersecurity strategy Sophos CISO Advantage defines a new category in the market, turning security data into strategy and measurable improvement, driven by agentic AI. The offering assesses an organisation’s environment, maps it against industry frameworks, and turns the result into a prioritised plan at a speed and scale that human experts alone cannot reach. For most organisations, creating and executing against a strong cybersecurity strategy is both the greatest opportunity and the greatest challenge in strengthening their resilience. The cybersecurity industry has invested heavily in tools that prevent, detect, and respond, with global spending on information security expected to reach $240 billion in 2026. However, despite significant investment in cybersecurity tools, the market remains fragmented. Organisations often rely on disconnected assessments, spreadsheets, and point solutions to understand and manage cyber risk, making it difficult to measure progress, prioritise investments, and demonstrate the impact of cybersecurity programs. Impact of cybersecurity programs The gap, in large part, is due to a scarcity in security leadership and talent. According to the 2026 CISO Report, an estimated 35,000 CISOs serve 359 million businesses worldwide, a ratio of roughly 10,000 to one. Hiring alone cannot close the gap. In fact, our 2026 MSP Perspectives Report found that on average, 46% of customers look to their MSP to act as their CISO now; with 84% of MSPs expecting the demand for CISO services to increase over the next year. Organisations without a CISO lack the skillset and resources to assess risk and build a strategy. Organisations with a CISO are increasingly asked to prove control effectiveness and demonstrate progress to boards, regulators, and insurers, even as the role strains under pressure, as average tenure of a CISO runs 18 to 26 months2 and 75% are considering a job change. Prove control effectiveness Sophos CISO Advantage closes that gap. It builds a security assessment unique to each organisation's environment and threat profile, maps controls against frameworks including NIST CSF, CIS v8, Cyber Essentials Plus, and NCSC CAF, and turns the results into a prioritised, budget-aligned roadmap of what to fix first, what it costs, and why it matters to the business. Because it is part of Sophos Fusion, every assessment is informed by live threat intelligence and the collective insight from 625,000+ Sophos-defended organisations, rather than generic benchmarks. “Good security strategy has always required expertise that's too scarce to scale, so it's stayed a luxury only the largest enterprises could afford.” said Rob Harrison, senior vice president, product management, Sophos. “Sophos CISO Advantage changes that. We built it around the question every board is now asking its security team: are we safer than we were last quarter, and can you prove it? Putting a credible answer within reach of any organisation, not just the ones that can staff a large security team, is how the industry starts to close the resilience gap.” Dedicated security team Every organisation's path to strengthening their security strategy with Sophos CISO Advantage is different. Some want to own and run the program themselves, with their internal team driving strategy and using Sophos CISO Advantage as their system of record. Others may start with an MSP partner to stand up the program, build confidence, and then transition to running it in-house. Many will start with a baseline assessment of their program, and move into a continuous managed service delivered entirely through a trusted partner. Sophos CISO Advantage is designed to support all three.  For the growing number of MSPs already acting as the de facto security leader for their customers4, it turns that role into a structured, scalable, and billable service. For organisations that want to own their program directly, it provides the system, the framework, and the AI-powered workflows to do it without a dedicated security team. Whichever path fits the business, Sophos CISO Advantage delivers the same outcome: a clear program, measurable improvement, and reporting that leadership can act on. Showing meaningful progress “CISOs are being asked to move faster, manage more risk, and show meaningful progress to boards, regulators, and insurers. There are too many tools out there that track activity without any insight. What security leaders need now is a solution that helps them understand where they stand, take action, and clearly show how their security posture is improving. The vendors that can bring that together in one AI-native system, from assessment through remediation, will be the ones that shape where this market goes next,” said Phil Haris, research director, governance, risk and compliance solutions, IDC. "CISO Advantage gives us a structured way to deliver something we were already doing informally. We can now walk into any customer conversation with a clear program, a prioritised plan, and reporting that leadership can buy into. It has elevated how we position ourselves," said David Peck, President, Trebron Security, Lancaster, Pennsylvania.    Sophos CISO Advantage is available beginning October 2026 across North America, the UK, and the rest of Europe, as an annual term license or as a monthly subscription through MSP Flex. Global availability is expected by the end of calendar year 2026. Sophos CISO Advantage Plus, which adds convergence, risk, and governance capabilities for enterprise organisations, is targeted for mid-2027.

SE Labs leads UK cybersecurity testing shift

A wave of cybersecurity firms have abandoned the Department of Defense-backed MITRE test as major companies join independent cyber testing programme PIVOT, run by British company SE Labs.  Participants in MITRE Engenuity ATT&CK Evaluations plummeted from 30 to just 11 last year. Meanwhile, CrowdStrike, Palo Alto Networks and Broadcom are among the participants confirmed for PIVOT, a 6-month testing programme by SE Labs evaluating how effectively vendors can defend against the world’s most dangerous hacking groups and attack techniques. Testing critical cyber solutions  “It’s a landmark moment for British cyber security, as the world’s biggest and best organisations choose to test their critical cyber solutions in the UK rather than in the US,” said Simon Edwards, CEO of SE Labs. “There are now very few tier-one vendors that aren’t testing within PIVOT.” “The requirements for cyber security have completely changed. There are autonomous AI agent attacks, such as those that affected Hugging Face, while the sheer economic scale of the JLR incident influenced the UK economy. Businesses need to know which solutions actually protect them against nation-state attacks, major ransomware campaigns and machine-speed threats, and that demands rigorous testing of defences.” PIVOT testing The PIVOT testing will see teams of trained ethical hackers from SE Labs impersonate nation-state cyber groups and other hacking circles responsible for the most disruptive cyber breaches in recent years, replicating attack types across ransomware, malware, phishing and beyond to stress test vendor solutions on their ability to detect threats from known attack groups and protect against them. Authority insights Adam Bromwich, Vice President of Engineering and CTO, Enterprise Security Group at Broadcom, said: "CISOs today need clarity and proof, not just promises. PIVOT emphasises full transparency and inclusion of major analyst firms to set a new standard for trust. For us isn't just about a score; it's about demonstrating Symantec and Carbon Blacks' real-world efficacy in an open, verifiable way that empowers customers to make confident security investments." Simon Reed, Chief Research and Scientific Officer (CRSO) at Sophos, said: “SE Labs’ PIVOT brings clarity to endpoint testing. It highlights who’s genuinely preventing and detecting threats, not just tuning for test conditions. As cybersecurity focuses increasingly on prevention and resilience for real-world protection, this independent assessment is critical to retain trust.”  Independent scrutiny on test results The data from testing is shared with analyst firms for independent scrutiny ahead of publication to help vendors identify gaps in their security solutions and support product development against ongoing threat groups and attack types. The test portion of the programme runs from July to October, with the final report released in January 2027. It comes amid the development of the Cyber Security & Resilience Bill, which will mandate designated essential services and digital service providers to report incidents within 24 hours to the regulator and NCSC and a full report within 72 hours, widen regulatory scope, and promote cross-border information sharing with EU authorities under NIS2.

Espria's Optimise IT event returns: Join the cybersecurity talk

Digital workplace solutions and managed services pioneer Espria returns in December with another Optimise IT exhibition, pioneering the discussion on how IT solutions can best work together to provide the ultimate support for businesses and end-user experience.  Post-COVID, Espria hosted a series of Optimise IT webinar discussions, covering themes such as business peace of mind, business readiness and AI integrations for workplace teams. These discussions have featured key spokespeople from some of their pioneering IT solutions partners and provided industry pioneers with a platform to network directly with key decision-makers who are looking for increasingly efficient ways to deliver their IT strategy. Event feature representatives This year’s in-person event will feature representatives from premier vendor partners Gamma, Microsoft (hardware and software), Sophos and Omada by TP-Link, with more vendors to be confirmed. Marketing and Business Strategist, Bryony Thomas, will be giving a keynote speech during the lunch, sharing lessons in preparation, prioritisation and attention to detail and how missing these can be catastrophic. The event will be held from 9 am to 2 pm on 3rd December at the Down Hall Hotel, Matching Lane, Hatfield Heath, Bishop’s Stortford. Attendance is free but subject to prior registration on the Espria website. Cybersecurity alliance partnerships Stephen Cook, Sales Director at Espria, commented, “Turning to 2026, cybersecurity has entered a transformative phase, with the cyberthreat landscape accelerating in complexity and scale. Businesses that adopt intelligent monitoring and integrated, adaptive defence strategies will be best positioned to navigate 2026 with confidence.” “Similarly, customer trust is entirely defined by uncompromising data security in today’s environment. Where AI has been rapidly adopted into operations, it has simultaneously amplified the quantity and quality of cyberattacks, creating this paradox for security." "Espria has always prioritised our cybersecurity alliance partnerships as a critical solution for today’s security landscape, especially with the proliferation of AI-boosted attacks, which is why bringing experts such as Micrsoft and Sophos to the table is a key part of building a lasting strategy for SMEs from our previous Optimise events.” Commitment to cyber hygiene and defence practices Cook added: “Peace of mind with data security has always been a part of this and requires a continuous commitment to cyber hygiene and defence practices from experts and clients alike. It’s not just about the most high-technology solutions, but the ones that work best within businesses and align with existing operations seamlessly." "Our mission is to lead the conversation for enterprises of all sizes to navigate their modern technology needs, and that ensures any technology introduced, particularly AI tools, provides a strategic boost without hindering operations or opening up wider attack surfaces."  Comprehensive security strategies Cook concludes, “Educating our customer businesses who may be neglecting their endpoint security is an essential way to show security support. We’ve seen that customers, particularly smaller businesses with limited cyber skills or expert access, need that guidance when it comes to network security." "Thankfully, we can provide those skills and in this instance the forum for expert minds to collaborate, providing those all-comprehensive security strategies needed to tackle the cyber threats of today and tomorrow.”