Sophos launches MDR for Microsoft Defender

Issue 5 2023 Information Security, Security Services & Risk Management

Sophos has launched Sophos Managed Detection and Response (MDR) for Microsoft Defender, a fully managed offering that provides the industry’s most robust threat response capabilities for organisations using Microsoft Security. Sophos MDR for Microsoft Defender adds a critical layer of 24/7 protection across the Microsoft Security suite of endpoint, SIEM, identity, cloud, and other solutions to safeguard against data breaches, ransomware and other active adversary cyberattacks.

“Baseline security technology alone is not enough to defeat determined attackers who will find a way in, as evidenced by the cases our incident response team manages. Attackers are extremely persistent, and organisations need a human layer of security to conduct threat hunts, identify attacker behaviours attempting to evade security tools, and respond to stop attacks with speed and precision,” said Raja Patel, Senior Vice President of Products and Managed Services at Sophos.

“Rather than forcing them to rip and replace existing technologies, we support organisations with what they need, how and where they need it – regardless of what security solutions they already use. For channel partners delivering Microsoft Security offerings, there’s tremendous opportunity to ensure customers are fully protected and maximising value from their existing deployments.”

Sophos MDR for Microsoft Defender integrates telemetry from a broad range of Microsoft Security tools. Unlike other MDR offerings that limit support to Microsoft Defender for Endpoint or Microsoft Sentinel and provide minimal threat response capabilities, Sophos MDR fortifies the broader Microsoft Security suite, including:

• Microsoft Defender for Endpoint

• Microsoft Defender for Identity

• Microsoft Defender for Cloud

• Microsoft Defender for Cloud Apps

• Identity Protection (Azure Active Directory)

• Office 365 Security and Compliance Center

• Microsoft Sentinel

• Office 365 Management Activity

Telemetry from these sources is automatically consolidated, correlated and prioritised with insights from the Sophos Adaptive Cybersecurity Ecosystem and the Sophos X-Ops threat intelligence unit of more than 500 security analysts, threat hunters, responders, data scientists, and other specialists across Sophos worldwide. This enables the Sophos MDR operations team to identify and stop more threats than Microsoft Security tools – or any security technology – can on their own.

“Sixty-five percent of organisations have had a significant ransomware event in the last 12 months despite significant investments in cybersecurity tools, according to IDC research. It is often not a tool but a people problem. Most IT and security teams are generally overworked, understaffed and under resourced. They cannot triage and address the daily deluge of alerts and issues to get the desired protections promised from their current tool investments,” said Frank Dickson, group vice president for IDC’s Security and Trust research practice. “For organisations leveraging the Microsoft security stack, Sophos MDR assists those to realise the outcomes hoped for from their existing cybersecurity investments.”

“Our guiding principle is to deliver the best security outcomes possible for our customers. Advancements in technologies like extended detection and response (XDR) and generative AI are driving efficiencies in security operations, but the human element remains a critical component to stopping advanced threats,” said Kieron Newsham, Chief Technologist – Cybersecurity at Softcat. “We’re really pleased with how Sophos MDR is helping our customers overcome the increasing talent shortage and widening skills gap to deliver the best cybersecurity outcomes possible, independent of the customer’s size, structure or previous technology investments.”

Sophos MDR is the most widely used MDR offering, with more than 17 000 customers of all sizes and across all industries, and is the top-rated and most reviewed MDR solution on Gartner Peer Insights and G2. It is the only MDR service that can be delivered across end users’ existing third-party security deployments as well as Sophos offerings. In addition to Microsoft, organisations can also integrate telemetry sources from dozens of other vendors, including Amazon Web Services (AWS), Google, CrowdStrike, Palo Alto Networks, Fortinet, Check Point, Okta, Darktrace, and many others, through the Sophos Marketplace.

Sophos MDR for Microsoft Defender is available now to all Sophos MDR Essentials customers using security technologies included in Microsoft 365 E3 and E5 licenses. The customisable offering with different threat response options is available through Sophos’ global channel of reseller partners and Managed Service Providers (MSPs).

More information is available at www.sophos.com


Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Want effective Attack Surface Management? Think like an attacker.
Information Security
Effective ASM requires companies to think like attackers, anticipate risks, and act decisively to reduce exposure by knowing their environment, deploying a structured approach, leveraging capable tools, and addressing both internal and external risks.

Read more...
Your Wi-Fi router is about to start watching you
News & Events Surveillance Security Services & Risk Management
Advanced algorithms are able to analyse your Wi-Fi signals and create a representation of your movements, turning your home's Wi-Fi into a motion detection and personal identification system.

Read more...
The growing role of hybrid backup
Infrastructure Information Security
As Africa’s digital economy rapidly grows, businesses across the continent are facing the challenge of securing data in an environment characterised by evolving cyberthreats, unreliable connectivity and diverse regulatory frameworks.

Read more...
POPIA non-compliance puts municipalities at risk
Information Security Government and Parastatal (Industry)
Digital responsibility must go beyond POPIA compliance to recognising that privacy and service delivery are fundamentally linked. Despite this, only 51 out of 257 municipalities submitted their mandatory data protection and access to information reports in 2024.

Read more...
Choicejacking bypasses smartphone charging security
News & Events Information Security
Choicejacking is a new cyberthreat that bypasses smartphone charging security defences to confirm, without the victim’s input or consent, that the victim wishes to connect in data-transfer mode.

Read more...
Most wanted malware
News & Events Information Security
Check Point Software Technologies unveiled its Global Threat Index for June 2025, highlighting a surge in new and evolving threats. Eight African countries are among the most targeted as malware leaders AsyncRAT and FakeUpdates expand.

Read more...
Welcome to the new cyber battleground
Information Security
The Iran-Israel conflict is rapidly redefining modern warfare, pushing the boundaries of cyber capabilities and creating a new, borderless digital battlefield. Fortinet’s CISO, Dr Carl Windsor, offers a critical, in-depth analysis of the escalating tactics and global implications in his latest report.

Read more...
African industries may overestimate cyber defences
Information Security
] A significant perception gap exists in security awareness training: 68% of leaders believe training is tailored to roles, yet only a third of employees feel adequately trained. Many organisations only conduct annual or biannual generic training that may not effectively change behaviour.

Read more...
SMARTpod talks to Sophos and Phishield
SMART Security Solutions Technews Publishing Sophos Videos Information Security News & Events
SMARTpod recently spoke with Pieter Nel, Sales Director for SADC at Sophos, and Sarel Lamprecht, MD at Phishield, about ransomware and their new cyber insurance partnership.

Read more...
Cybersecurity and insurance partnership for sub-Saharan Africa
Sophos News & Events Information Security Security Services & Risk Management
Sophos and Phishield Announce first-of-its-kind cybersecurity and insurance partnership for sub-Saharan Africa. The SMARTpod podcast, discussing the deal and the state of ransomware in South Africa and globally, is now also available.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.