Sophos launches AI-native cybersecurity defence system

July 2026 News & Events, Information Security, Security Services & Risk Management

Sophos has launched Sophos Fusion, an AI-native cybersecurity defence system, built to deliver a coordinated response to AI-era threats.

A cybersecurity defence system is an emerging category in the industry: a single, open architecture where every control point, every service, every data source, and every analyst operates as one, whether the control point is native or third-party. Every new source enhances the system, accelerating outcomes while reducing overhead.

The AI era has changed what modern defence requires. Attacks can now move across an organisation’s environment as a single coordinated operation, further compressing the time from first access to impact from days to hours. The majority of IT and security leaders are attempting to keep up with that pace while juggling an increasing number of disparate tools. The typical enterprise runs more than 45 separate security products [1], which leaves teams with more spending, more dashboards, and more manual work while attackers move at machine speed.

A cybersecurity defence system addresses this market failure, defined by the following four characteristics:

One shared context lake, where every signal from every control point flows into a single data layer in real time.

Synchronised security, where a detection on one control point triggers coordinated action across the others at the same moment.

Agentic autonomy with human governance, where the system investigates and responds inside boundaries analysts set and continuously calibrate.

Compounding intelligence, where every threat seen across the defended base makes every customer’s defence stronger.

Sophos Fusion is the evolution of Sophos Central, the system that 625 000 organisations worldwide trust every day, now rebuilt on one open architecture incorporating Secureworks Taegis analytics, following the acquisition of the company in 2025. It leverages agentic AI to connect and synchronise every control point across the whole environment.

With the largest agentic SOC in the world, serving over 40 000 customers, Sophos demonstrates the system's effectiveness and scalability in its own operations. On average, 89 seconds pass between an alert and a fully automated response, and 52% of cases are handled entirely by AI. Additionally, Sophos Endpoint is designed to stop entire classes of attacks based on behaviours, such as memory abuse, data encryption and exfiltration, or other human or AI attacker tradecraft.

“As AI increases the speed, scale, and complexity of attacks, organisations need a modern, connected, intelligent, and adaptive defence,” said Joe Levy, chief executive officer, Sophos. “Sophos Fusion is built as a defence system optimised for human-AI workflows. We bring the most complete solution to a new category, a timely advancement demanded by the AI era.”

Sophos Fusion offers endpoint protection, endpoint detection and response (EDR), extended detection and response (XDR), next-gen SIEM, identity threat detection and response (ITDR), managed detection and response (MDR), network security, email, cloud, and advisory services as one defence system.

It is open as well as native: Sophos builds the core control points natively, and more than 500 third-party integrations feed the same shared data layer, so an organisation’s existing endpoint, firewall, or identity tools operate as part of the system alongside Sophos defence and protection.

“Futurum Group's market forecast projects that security operations, the segment where AI-native orchestration and adaptive defence systems compete, will double from $18B to $37B by 2029, growing faster than any other cybersecurity category,” said Fernando Montenegro, vice president and practice lead, cybersecurity and resilience, The Futurum Group. “This is where the next generation of cyber defence will be won.”

According to Gartner distinguished analyst Neil MacDonald, “Simply adding more tools onto the stack won’t provide the intelligent cyber defence fabric that organisations need to mitigate AI-orchestrated attacks like the one Anthropic recently identified. Organisations need an intelligent overlay that connects the different elements of their cybersecurity toolset to proactively and reactively respond to risks and threats at machine speeds.”

Expanding the Sophos Fusion Defence System

Sophos is expanding Fusion with the following capabilities, reaching general availability from August through October 2026:

Sophos Next-Gen SIEM provides long-term data retention, compliance reporting, and analytics on the same unified data, priced by users and servers rather than by data volume. Organisations can feed in all their telemetry without unpredictable billing or the gaps that come from holding data back. Generally available 15 August 2026.

Sophos AI Defence secures the AI that organisations are adopting, giving them visibility into AI tools in use, including shadow AI, control to enforce policy, and protection for the data those tools can reach, built on capabilities already inside the system. Early access in August 2026; generally available October 2026.

Sophos CISO Advantage gives every organisation access to CISO-level guidance, with continuous control validation, compliance mapping, peer benchmarking, and risk assessment, whether they have a CISO or not. It combines integrated technology, agentic AI, and active threat intelligence in Sophos Fusion with trusted human expertise delivered through Sophos' extensive global network of managed service providers (MSPs).

For organisations with a CISO, it delivers a more efficient, integrated way to manage risk, validate controls, and communicate progress to the board. For those without one, it provides practical security leadership grounded in their real environment. Availability beginning October 2026.

Sophos MDR is expanding with continuous, AI-enabled threat hunting fed by the Sophos X-Ops research team and broader two-way response across endpoint, firewall, cloud, email, and identity. This ensures threats are neutralised before they disrupt business and without the customer having to build a SOC. Generally available 15 August 2026.

Sophos XDR, powered by Secureworks, is rebuilt on Secureworks Taegis analytics, adding thousands of detectors, a new analysis experience in Sophos Fusion, and built-in SOAR automation with playbooks, giving teams faster, higher-fidelity detection and response with less manual work. Generally available 15 August 2026.

Sophos delivers through one of the largest global ecosystems of MSPs, managed security service providers (MSSPs), resellers, distributors, and technology partners. Sophos Fusion gives partners a single system to sell and operate rather than a set of point products, opening new recurring-revenue opportunities, with Sophos CISO Advantage designed specifically for the MSP model and turning partners into strategic security advisers. Because intelligence compounds across every environment defended, each customer a partner manages benefits from every threat Sophos sees elsewhere, strengthening retention and the outcomes partners deliver.

To learn more about Sophos Fusion, visit www.sophos.com

Resources

[1] Gartner, “Tech FutureSight: Protect the Global Attack Surface with an Autonomous Cyber Defense System,” Neil MacDonald, Dec. 12, 2025




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Fire safety in South Africa
Technoswitch Fire Detection & Suppression Technews Publishing SMART Security Solutions Fire & Safety Security Services & Risk Management Editor's Choice
Fire safety is sometimes ignored, sometimes relegated to whatever is cheapest, and sometimes treated with the seriousness it deserves, given that it focuses on protecting life and assets. SMART Security Solutions asked Brett Birch, MD of Technoswitch, for some insights into the realities of fire safety in South Africa.

Read more...
From the editor's desk: The high price of cheap
Technews Publishing News & Events
Bringing fire and safety, along with intrusion and perimeter protection, into the same publication is an interesting exercise. At their core, all these systems exist for one reason: to warn people ...

Read more...
A risk-based approach to fire safety
Fire & Safety Security Services & Risk Management Industrial (Industry) Agriculture (Industry)
A report by fire engineering consultancy ASP Fire is challenging blanket assumptions around combustible-core sandwich panels, arguing instead for a rational, risk-based approach that balances fire safety requirements with commercial realities in sectors such as agriculture, manufacturing and industrial processing.

Read more...
Preventing and suppressing lithium fires
SMART Security Solutions Technews Publishing Editor's Choice Fire & Safety Security Services & Risk Management Smart Home Automation
SMART Security Solutions asked Clyde Becker, director of Pyro Brand, for some insight into the mechanics of lithium-ion battery fire risks, especially thermal runaway, and to define a comprehensive, layered approach to fire detection and suppression.

Read more...
Southern Africa’s security leaders honoured at the 2026 OSPAs
News & Events
The winners of the 2026 Southern Africa Outstanding Security Performance Awards (OSPAs) were announced at a virtual ceremony on 23 June 2026. The winners in seven categories will progress to the third Global OSPAs in 2027.

Read more...
MPT unveils R50m customer experience centre
News & Events Power Management
Master Power Technologies has unveiled its new Customer Experience Centre, also home to its new regional headquarters in Midrand, Gauteng. The facility spans 6 000 m2 and houses approximately 200 employees.

Read more...
Duxbury Cybersecurity sharpens reseller offering
Duxbury Networking Information Security News & Events
Duxbury Networking has strengthened its Duxbury Cybersecurity business unit by adding WatchGuard and Cynet, giving South African resellers broader, more integrated coverage for the security risks customers are now asking them to address.

Read more...
Disconnect between confidence in identity security and operational reality
Access Control & Identity Management News & Events
New FIDO Alliance and HID study reveals gap between identity security confidence and reality; 94% of enterprises claim they can revoke employee access within 24 hours, yet 35% experienced delays or failures in the past two years.

Read more...
Paxton Solo training available to security installers
Paxton Access Control & Identity Management News & Events
Following the launch of Solo, Paxton’s brand-new access control system, the security manufacturer is rolling out dedicated Solo training sessions across South Africa to support security installers working with the system.

Read more...
Echoes of 2018? Follow-up on Woolworths explosions
Technews Publishing News & Events Security Services & Risk Management Retail (Industry) Facilities & Building Management
SMART Security Solutions follows up with Jimmy Roodt to find out more about an old connection to the Woolworths bombings from 2018. The investigation remains ongoing.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.