PRODUCTS

Cyber Security Elements by NSS

News

29

Sep

Every few weeks, the AI conversation seems to reset around a new warning.

A model demonstrates an unexpected capability. An autonomous agent behaves in a way its designers did not anticipate. A new forecast describes how quickly AI could transform work, security or society. The details change, but the pattern is familiar: a new development emerges, the debate swings between extraordinary promise and existential danger, and organizations are left wondering whether their strategy must change again.

There is a legitimate case for stronger testing, greater transparency, independent evaluation, and guardrails that keep capability advances from moving too far ahead of our ability to secure them. Innovation without accountability is not a sustainable strategy.

But neither is waiting for the AI debate to be resolved.

For security leaders, the central question is not whether every forecast about AI will prove correct. It is whether their organizations can adapt safely as the technology, the threat landscape and the way people work continue to change.

That has always been the job.

The stakes are also not shared evenly. The cybersecurity poverty line existed well before AI but, since it significantly raises the cost of both attack and defense, the organizations most exposed are often the ones that were already under-resourced.

Adaptability is not the same as overreaction

Security leaders need to resist two equally dangerous impulses:

  • The first is complacency: assuming today’s controls will remain sufficient simply because the fundamental principles have not changed
  • The second is overreaction: allowing every new AI development to trigger a wholesale reinvention of strategy.

Neither approach builds resilience.

Instead, the focus should be on adaptability; that is, preserving a stable security foundation while changing how that foundation is applied. This is especially important because the AI news cycle is unlikely to slow down. There will be more incidents, more capability demonstrations and more disagreement about what they mean. Security leaders cannot operate effectively if their attention and investments move in lockstep with every headline.

They need a durable way to decide what matters.

A useful starting point is to focus less on whether an AI tool appears novel and more on what it can access, what it is authorized to do, and what the consequences would be if it behaved unexpectedly.

This is where risk-based governance becomes essential. Organizations should be able to experiment, but the strength of the control should rise with the autonomy, access, and potential impact of the use case.

That principle allows innovation to continue without pretending every application of AI carries the same risk.

We need guardrails that strengthen innovation

Calls for caution are sometimes interpreted as calls to stop. Calls for innovation are sometimes interpreted as opposition to oversight. That is a false choice, largely because AI is dual use. The same advances that can help defenders analyze activity, investigate threats, and respond more quickly can also help adversaries operate at greater speed.

The question is not whether guardrails are needed; they are.

The better questions are whether those guardrails are proportionate, verifiable, and focused on measurable risk. Regulation should establish accountability, improve transparency, and make it harder for dangerous capabilities to be developed or deployed without appropriate scrutiny.

However, regulation should not freeze responsible innovation or make advanced defensive capabilities accessible only to the organizations with the greatest resources.

Rules that unintentionally slow defenders, restrict responsible research or raise the cost of protection could widen the gap between organizations that can defend themselves and those that cannot.

Instead, the goal should be to create a race to stronger security, which requires close collaboration. Frontier AI developers understand their models. Cybersecurity experts understand how systems are attacked, where operational controls fail and how risk appears in real environments. Policymakers can establish accountability and defend the public interest.

None of those groups can solve the problem alone.

The security work in front of us already exists

Much of the public debate is focused on what the next generation of AI might be able to do. Security leaders do not have the luxury of concentrating only on a future model.

The technology available today is already changing how people create, communicate, analyze information and make decisions. AI tools and agents are already entering organizations, sometimes through approved programs and sometimes without the knowledge of IT or security teams.

Even if frontier AI development stopped today, that work would remain.

Organizations would still need to discover unsanctioned AI use. They would still need to understand which information is being shared with external services. They would still need to assess integrations, permissions and identities. They would still need to monitor for abuse and prepare for mistakes. They would still need to help employees use AI productively without creating unacceptable risk.

That is why a slowdown cannot be the security strategy.

The strategy must be to build organizations that can adopt technology safely, respond to change, and maintain control even when the direction of innovation remains uncertain

The fundamentals should not change every time the narrative does

Cybersecurity has never operated in a stable environment. Threat actors evolve, technology architectures shift, geopolitical events alter risk, and new applications appear inside organizations before security teams have had time to assess them. That’s just part of the day-to-day.

AI raises the speed and scale of that change, but it does not eliminate the foundations of sound security. Organizations still need to know what is in their environment, understand who and what has access to sensitive systems and data, and controls that limit exposure, detect malicious activity, and support an effective response when a threat is identified.

In other words, priorities may move, but the fundamentals must hold.

We saw a similar dynamic during the transition to the cloud. Nobody secured the cloud by treating every new application as a separate strategic crisis. We adapted our security models by developing new forms of visibility, establishing new controls, and learning how to manage a technology environment that would continue to evolve.

AI requires the same discipline, but with an important difference. Unlike previous technology evolutions, AI adoption does not arrive through a centrally managed transformation program. It can enter an organization one employee, one browser tab, one application integration, or one autonomous agent at a time.

That makes adaptability inseparable from visibility. Security teams cannot assess risk, apply appropriate controls, or govern AI usage if they do not know where and how AI is being used across the business.

Making secure AI adoption accessible

At Sophos, our mission has long been to help close the cybersecurity poverty line. That mission matters even more in the AI era.

Our role is to help customers safely adopt the tools they choose while bringing the strongest available security technology within practical reach. That means giving organizations visibility across their environments, helping them identify risk, and applying protection in ways that match their operational reality.

It also means working closely with the organizations building frontier AI systems. AI developers can accelerate safely when they build alongside cybersecurity specialists who see how threat actors behave in the field and how technology is used in real organizations.

This is not an argument for moving fast and ignoring the consequences. Rather, it is an argument for making security part of innovation from the beginning.

The fundamentals are available to us now: know what is operating in your environment, understand what it can access, apply controls according to risk, monitor what it does, and prepare for failure. Above all, adapt as the evidence changes.

AI may move faster than any technology transition that came before it. That does not mean security strategy must move with every headline. It simply means the strategy must be built to adapt.

Source: Sophos

25

Sep

Security information and event management (SIEM) has come a long way since its inception over 20 years ago. Adoption was originally driven by The Payment Card Industry Data Security Standard (PCI DSS) but has since enjoyed widespread use due to its joined-up approach to identifying and combatting security threats.

Just monitoring one system in isolation isn’t suitable for modern-day security. According to the Global Incident Response Report by Palo Alto Networks, 87% of intrusions involve activity across multiple attack surfaces, including endpoints, networks, cloud, SaaS and identity.

So, it’s no surprise that SIEM has caught the eye of legislators, with the NIS2 directive (which covers many companies in the EU, and indirectly their supply chains) giving guidance that specifically recommends SIEM to aid compliance.

Here are five ways Kaseya SIEM helps organisations with NIS2 compliance.

1.SIEM helps identify security incidents faster

One of NIS2’s central requirements is the ability to detect, monitor and respond to cybersecurity incidents effectively. This is all about bringing together the data from across your organisation to detect potential threats and respond to them.

Guidance states that the ability to correlate information between systems is important for compliance. It also suggests SIEM as an evidence point for the monitoring and logging portion of incident handling.

Without this orchestration ability, you are looking at individual signals in isolation. SIEM is what brings them together to provide a unified picture of threats to your organisation.

2.SIEM provides the context needed for incident response

Detecting an incident is only the first step.

Organisations must also determine the severity of the threat, understand its potential impact and decide how to respond.

Is it a small security issue that can be fixed quickly and without further intervention?  Or is the incident severe enough to trigger other parts of your security planning?

You can’t decide it in the moment. That pathway must be laid out clearly in advance. NIS2 guidance suggests ensuring you have clear criteria on what can be classed as an incident, how the severity is categorised and how you then handle it as a result.

But the SIEM data — and understanding the severity of the incident — is what provides that foundation of information that allows you to trigger the appropriate response.

3.Automation accelerates response times

Responding to an incident quickly could be the difference between nipping an issue in the bud versus that issue grinding your business to a halt. According to the CrowdStrike Global Threat Report 2025, it takes just 48 minutes on average for attackers to move laterally from initial compromise.

As part of incident response, NIS2 guidance suggests the use of automated solutions. Automation across cloud, email and endpoint can trigger an immediate response before an engineer even receives the notification.

Kaseya SIEM’s automated response rules stop threats without manual intervention. In fact, you can use automated response rules out of the box, or fine tune and create your own.

4.Tailored security helps you focus your efforts

Acknowledging the sheer wealth of data that could overwhelm a team, NIS2 guidance suggests utilising automation to triage incoming alerts and prioritise them based on severity.

NIS2 recognizes the importance of focusing resources on genuine risks and minimizing false positives wherever possible.

Kaseya SIEM allows you to define your own custom indicators of compromise and adjust alert severity. When combined with automated response, it allows you to tailor responses to fit your environment and ensure that your teams respond to what matters most.

5.Logs give the evidence you need after an incident

There is no set way an investigation may unfold, or indeed what may trigger one. But, if auditors do carry out an investigation after a security breach, having the right data on hand is vital.

Auditors will likely want to see how you handled the incident, the data used to inform your resolution and the steps you took. They may also want to see what data you were collecting and how you were interpreting and acting upon that data before the event.

With a 400-day log retention, Kaseya SIEM has that covered. And when you consider it takes an average of 241 days to identify and contain a breach, that length of log retention becomes even more important.

There’s SIEM -and then there’s Kaseya SIEM

Kaseya has taken SIEM and adapted it for modern threats. While SIEM has always been a powerful tool for aggregating data, Kaseya SIEM combines AI automation along with a high level of customisation so you can tailor and speed up your response to an incident.

The cost of not having a SIEM solution could also have wider ramifications. Many cyber insurers now require SIEM or SOC coverage as a condition of policy renewal. Kaseya SIEM offers both.

In addition to the automated responses and tailored alerting, Kaseya SIEM is also backed by a 24/7 SOC that scans for issues at all times.

NIS2 calls for the right tools with the right people and the right training — and by combining SIEM with SOC, Kaseya SIEM helps organisations tackle both parts of the requirement.

Find out more about Kaseya SIEM.

Source: Kaseya

22

Sep

For years, the cybersecurity industry has blurred the lines between XDR and SIEM. As capabilities converged, organizations were left trying to connect separate security operations and compliance solutions, often moving the same data between different tools, workflows, and teams.

Security teams have been asked to do more than ever: detect and investigate threats faster, automate response actions, and retain growing volumes of data. This is in addition to reconstructing activity across different systems, manually correlating events, and bridging gaps between operational and compliance requirements.

Pricing tied directly to data ingestion created another challenge. As data volumes grew, organizations were forced to choose between greater visibility, retention, and cost, even when historical context could prove critical during an investigation, audit, or incident review.

At Sophos, we think the conversation has focused on the wrong thing.

The question is not whether an organization needs XDR or SIEM. The question is whether security operations and compliance should require separate solutions, separate workflows, and separate data foundations in the first place.

We don’t think so. The work is different. The data does not have to be.

Designed around outcomes, built on shared context

When Sophos acquired Secureworks in 2025, we brought together two of the most influential lineages in cybersecurity. This gave us an opportunity to rethink how security operations and compliance should work together.

Rather than forcing organizations to treat XDR and SIEM as separate data foundations, Sophos Fusion brings them together through shared context while keeping security outcomes at the center.

Within Sophos Fusion, the industry’s most complete cyber defense system, telemetry from Sophos and third-party  control points flows into a unified context lake. Security operations capabilities use that context to detect threats, investigate activity, automate workflows, and accelerate response. Compliance capabilities draw from the same foundation to support long-term data retention, reporting, and evidentiary needs.

Distinct outcomes. Shared context. One cyber defense system.

Security remains the focus

Organizations should not have to add a separate SIEM to access the capabilities required for effective security operations.

Sophos XDR Powered by Secureworks delivers the capabilities analysts need to detect, investigate, and respond. AI-assisted detection analysis and natural-language search help teams understand activity faster. Context-rich cases bring together related evidence and threat intelligence. Built-in automation, SOAR workflows, response actions, and over 500+ third-party integrations help analysts move from detection to containment without manually assembling response across disconnected tools.

These capabilities belong in XDR because they directly contribute to security outcomes. Compliance builds on that security foundation rather than competing with it.

Sophos Next-Gen SIEM helps organizations retain, report, and prove. Flexible data ingestion and AI-assisted parsers bring in telemetry unique, legacy, regional, and internally developed sources. Retained data remains structured and searchable, supporting compliance reporting while adding historical context to the security operations already taking place in Sophos XDR or Sophos MDR.

Pricing based on users and servers rather than data volume helps organizations retain the data they need without turning every increase in visibility into an increase in cost. This means fewer trade-offs between security, compliance, and budget, with historical context available when analysts, auditors, or incident responders need it.

A clearer path forward

The cybersecurity industry spent years blurring the lines between XDR and SIEM. Organizations were left trying to determine whether they needed one solution, the other, or both.

Sophos is taking a different approach.

Within Sophos Fusion, Sophos XDR and Sophos Next-Gen SIEM are designed around the outcomes organizations need, not the boundaries between product categories. Security teams can detect, investigate, and respond. Compliance teams can retain, report, and prove. Both work from the same foundation of data and context, within a single cyber defense system.

Sophos XDR Powered by Secureworks and Sophos Next-Gen SIEM are now generally available as part of Sophos Fusion. Existing Sophos XDR and Sophos MDR customers can add Sophos Next-Gen SIEM to their environment. New customers can adopt Sophos XDR with Next-Gen SIEM, or pair Next-Gen SIEM with Sophos MDR for fully managed, 24/7 detection and response supported by extended historical context.

Whether you’re looking to strengthen security operations, simplify compliance, or bring both together through shared context, visit Sophos.com/NG-SIEM or contact your Sophos representative to learn more.

Source: Sophos

18

Sep

GigaOm has recognized Keeper Security in the Enduring Innovators quadrant of its 2026 Radar Report for Enterprise Password Management. This marks the fifth consecutive year that Keeper has been named a Leader in GigaOm’s evaluation of the enterprise password management market.

The report recognizes Keeper’s continued innovation, architectural depth and ability to help organizations secure more than just passwords. With Keeper, enterprises can protect credentials, secrets, machines, non-human identities and AI agents from a single, unified platform. Request a demo today to see firsthand why we are ranked so highly.

Report overview and key highlights

GigaOm’s 2026 Radar Report examines 23 leading enterprise password management solutions. It evaluates each provider against a range of capabilities, including table-stakes, key and emerging features, as well as broader business criteria.

The Enduring Innovators quadrant recognizes platforms that continue to build on their market position through ongoing innovation and strong underlying architecture. Keeper was recognized as advancing faster than the majority of the field, with particular strengths in secrets management, its official Model Context Protocol (MCP) server and governance for agentic and non-human identities.

This is the fifth year that GigaOm has evaluated the enterprise password management market  and the fifth consecutive year that Keeper has earned a Leader designation.

How Keeper stands out 

Unlike fragmented tools or limited vault-only solutions, Keeper provides a zero-trust, zero-knowledge security architecture for protecting credentials and access across the enterprise. Key strengths include:

  • Compliance-ready security: FedRAMP High Certified and GovRAMP High Authorized, FIPS 140-3 validated, with longstanding SOC 2 and ISO certifications.
  • One platform for every identity: Govern human, machine, non-human and AI agent identities from a single control plane.
  • Built-in secrets management: Protect credentials used by developers, applications, services and infrastructure.
  • Secure access anywhere: Use Keeper across desktops, mobile devices and browsers.
  • Fine-grained controls: Apply least-privilege principles with time-limited access, one-time sharing and self-destructing records.
  • Broad integrations: Connect with SSO, MFA, SIEM, CI/CD tools and passwordless authentication.
  • Fast deployment: Deploy in minutes alongside existing tools, no disruptive rip-and-replace required.

Innovation since the last GigaOm report

The identity security landscape is changing quickly, with AI agents, machine identities and non-human accounts becoming part of everyday business operations. Keeper has responded by continuously expanding its platform to help organizations manage these identities alongside their workforce.

The latest capabilities include AI agent governance, an official MCP server, real-time threat detection through KeeperAI, improved risk visibility and stronger session protection. Keeper has also expanded passkey and passwordless authentication, while KeeperPAM brings password management, secrets management, privileged access management and endpoint privilege management together in one unified identity security platform.

Together, these updates give security teams greater visibility and control as identity environments become more complex. To see the full Keeper platform beyond just password management, request a demo of KeeperPAM.

Why enterprise password management matters

Weak, reused or exposed credentials can leave organizations vulnerable. Enterprise password management helps security teams protect passwords, secrets and machine credentials while enforcing access policies, supporting passwordless authentication and maintaining clear audit trails.

Password management is about more than just storing passwords. It provides centralized control and visibility across users, devices, applications and identities.

Try Keeper for free

Protect your organization’s passwords, credentials and secrets with zero-trust and zero-knowledge security. Sign up for a free 14-day trial or reach out to our team to learn more.

Looking to secure your organization beyond password management? Learn more about KeeperPAM®

Strengthen your organization’s security posture by investing in a privileged access management solution that supports a zero-trust strategy. KeeperPAM is both zero trust and zero knowledge, which helps prevent unauthorized access and ensures that only the right users have the appropriate level of access. With features like endpoint privilege management, role-based access control, Just-in-Time (JIT) access and detailed auditing, monitoring and session recording, KeeperPAM helps your organization secure critical data and maintain tight controls over all infrastructure.

To learn more about how KeeperPAM can secure your organization with its zero-trust strategy, request a demo today.

Source: Keeper

15

Sep

A question every business should be asking is: How quickly can we get back to business if something goes wrong?

Downtime is expensive, and in extreme cases, can even affect the wider economy — with the Jaguar Land Rover cyberattack estimated to have wiped out 0.1% of the UK’s GDP.

That’s why legislation such as the EU NIS2 Directive places a strong emphasis on recovery capability, not just prevention, for companies deemed “critical” or “important.” Even organizations that are not directly subject to NIS2 may still need to demonstrate appropriate safeguards if they want to do business with customers, partners or suppliers that are.

But every company should be asking this question, whether they are affected by the legislation or not. Backup is no longer simply about having another copy of your data. It’s a key part of any disaster response and how quickly you can move from recovery to normal business operations.

That’s why backup and recovery discussions are moving beyond IT departments and becoming board-level priorities.

How a good backup strategy supports NIS2

For many years, the widely accepted backup framework was:

  • 3 copies of data (to protect against data loss)
  • 2 different formats (stored on at least two media types)
  • 1 off-site copy (to protect against physical disasters)

However, it’s now recommended to add two more measures for true backup efficacy:

  • 1 immutable copy (ensuring ransomware-proof backups)
  • 0 doubt you can recover (regular testing guarantees reliability)

This evolving approach has a key part to play in NIS2 compliance.

What does NIS2 say about backup strategy?

At NIS2’s core is a focus on recovery and business continuity. It’s about ensuring disruption is kept to a minimum in the event of an incident. As such, most sections of NIS2 legislation are supported by a good backup strategy.

Three areas are particularly relevant.

One of the pillars of NIS2 is “policies to assess effectiveness.” Put simply, this isn’t just about the belief you have effective backup in place — it’s the ability to prove you do.

A backup is useless if you can’t use it. The “0 doubt you can recover” principle should form part of any recovery strategy,  supported by documented recovery procedures and regular testing. Organizations need confidence that when recovery is required, it will work as expected.

Meanwhile, the immutable copy addresses the legislation’s need for “business continuity measures” and basic “computer hygiene.” It’s vital to have a copy of data that cannot be altered or deleted and can act as a known and reliable restore point if needed. This is necessary for general disaster recovery and offers a reliable version of data in the event of a cyberattack or ransomware incident.

Avoid cloud complacency

One of the biggest misconceptions in modern IT is the assumption that cloud services automatically provide complete protection, and that providers will handle backup and recovery. The problem is exacerbated by SaaS, where the promise of instant access to a solution is enticing and often achieved without IT involvement.

Even well-established services like Microsoft 365 can have backup blind spots if organizations do not have an independent protection strategy in place

The term “cloud blindness” has been coined for this and other areas of cloud complacency.

While cloud services may bake in a certain amount of resiliency, businesses cannot take a hands-off approach to critical areas such as backup and recovery.

Businesses need to employ a zero-trust policy when it comes to their data integrity. Regardless of who has stored the data or where, and regardless of the promises given in terms of reliability, the backup strategy must remain consistent across the board.

Backups are about getting back to business

In a world where ransomware attacks are increasingly common and SaaS outages are frequently making headlines, backups need to be a key part of any compliance posture.

Every moment of downtime is potentially lost revenue. The legislation’s approach to making IT part of boardroom governance is good for IT teams, and Datto has long been making the case for backups to be an important part of this discussion.

Read Datto’s The ultimate guide to BCDR: Why backup and disaster recovery matter.

Source: Kaseya

12

Sep

Privileged accounts are standing invitations for attackers, with credentials to steal and permissions to misuse. When administrative rights are persistently active, whether or not they’re being used, privileged accounts significantly expand the attack surface. Zero Standing Privilege (ZSP) shrinks that risk by ensuring no user holds permanent elevated access. Instead, privileges are requested for a specific task, granted for a limited time, approved through a defined workflow and automatically revoked when the approved window expires. ZSP reflects a broader shift in modern security, replacing standing access with temporary access to reduce what an attacker can exploit. Keeper helps enforce ZSP by granting Just-in-Time (JIT) access and automatically revoking it when the approved window expires, moving users from zero privilege to exactly the access they need, then back to zero automatically.

Continue reading to learn the importance of ZSP, how it works in Keeper and where Keeper enforces it across environments.

Why standing privileges are a security risk

A privileged account that stays active indefinitely gives attackers a long-lasting target: the credentials don’t expire, the access is constantly available and there’s no given moment when those rights are taken away. If attackers steal or compromise one of these accounts, they inherit standing privileges in their entirety.

The bigger problem is blast radius since a compromised account with standing access rarely stops at the system for which it was intended. Attackers use standing privileges to move laterally across environments, reaching additional servers, databases and cloud resources in their paths. What may begin as a single compromised credential can quickly turn into a foothold across your entire infrastructure if the user has standing access. When privileges are permanent, access isn’t tied to a specific request, task or timeframe, leaving no clear record of why someone could reach a system at a certain moment. That ambiguity makes investigating security incidents involving standing privileges and proving compliance much more challenging.

How zero standing privilege works in Keeper

Keeper helps enforce ZSP through Keeper Privileged Cloud, which extends KeeperPAM’s JIT access framework to your identity providers and federated applications. Instead of provisioning permanent admin rights, Keeper Privileged Cloud grants elevated access only when it’s requested, only for an approved time window and only under the workflow controls you define. Users default to no privilege and elevate through a controlled, auditable process, then return to zero when the task is done. Below is how ZSP works in practice for Keeper.

Configure access policies

On a PAM Cloud record, admins define the rules of engagement using JIT and Workflow settings. This includes whether a request needs approval, who can approve it, how long access lasts once granted and which role the user is elevated into. These settings help determine exactly how privileged access is requested, approved and time-boxed, ensuring no elevation happens beyond the boundaries you set.

Share records with authorized users

Once a policy is in place, the PAM Cloud record is shared with the users who should be able to request access. Because elevation happens through your identity provider, each user needs an account in both your identity provider and Keeper tenant. With the record shared, those users can request elevated access when a task calls for it, without holding any standing privilege in the meantime.

Review and approve requests

When a user needs access, they can request it directly from their Keeper Vault or the Keeper Commander CLI. Designated approvers receive real-time notifications from tools like Slack, Teams, Jira and ServiceNow and can either approve or deny a request from any Keeper client, so requests aren’t stuck waiting for someone to be at their desk. Depending on the policy, approvers can also require a justification and a ticket number before granting access, linking every elevation to a documented reason.

Grant and revoke access automatically

After a request is approved, the Keeper Gateway performs the elevation on the identity provider or target resource, granting the user the configured group membership, role or entitlement so they gain the access the policy allows. When the approved duration expires, the Keeper Gateway automatically revokes that access, removing the temporary membership or assignment and returning the user to ZSP. It also records every elevation that requested access, who approved it, and when it started and ended so security and compliance teams have a clear, per-request account of how privileged access was granted and used.

Where Keeper enforces zero standing privilege

Keeper doesn’t confine ZSP to a single system or account type. The same JIT framework applies wherever privileged access exists in your environment, from the identity providers your users authenticate against to the cloud resources, databases and machines behind them.

Across your identity providers

Keeper Privileged Cloud extends JIT access across existing identity providers, including AWS IAM, Microsoft Entra ID, Google Cloud via Google Identity, Okta and Active Directory. Keeper grants and revokes privileges directly within your existing infrastructure, so elevation happens where your accounts already live with no disruption to how users authenticate. The identity provider remains your source of truth, while Keeper simply controls when a user is elevated into a privileged group and when they’re removed from it.

That reach is not only for the platforms themselves but also includes applications that federate access and authorization through these identity providers. Federated applications can also use Keeper for access control, allowing users to apply the same JIT model to the downstream apps that teams sign into every day.

Across cloud, databases and machines

Since ZSP isn’t just a cloud-console issue, KeeperPAM applies the same privilege-elevation framework beyond your identity providers. Using PAM Cloud, PAM Database and PAM Machine records, you can extend time-limited access to cloud resources, databases and individual machines, bringing the same lifecycle to the infrastructure behind your identity layer.

Beyond elevation, the Keeper Gateway also rotates privileged credentials so they don’t linger as static targets, and for databases and machines it can provision ephemeral accounts, injecting credentials server-side so the user never handles them. All of it sits within Keeper’s zero-knowledge architecture, meaning credentials and secrets remain end-to-end encrypted and are never exposed to Keeper or anyone else. Together, automated rotation and zero knowledge ensure that even the credentials that enable privileged access don’t persist as materials an attacker could steal and exploit.

Minimize your attack surface with Keeper

Zero standing privilege only works if it’s enforced consistently, which is where Keeper Privileged Cloud thrives. With Keeper, security teams have an auditable way to grant privileged access on demand and revoke it automatically, working through the identity providers and infrastructure you already run. Administrators get provable control over who can access what and when; users get the access they need without waiting for manual provisioning or holding on to rights they don’t.

Request a demo of KeeperPAM to see JIT access and automatic revocation in your environment.

Πηγή: Keeper

7

Sep

This year’s State of Ransomware survey showed promising signs that education providers are building resilience against ransomware attacks. But the costs and recovery timelines after attacks are still climbing. Recovery costs rose across lower education (students up to age 18) and higher education providers (over 18) this year, with higher education’s average recovery bill growing by more than $1 million. And one education sector now ranks among the slowest to recover when compared to the complete list of sectors surveyed.

The sixth annual Sophos State of Ransomware in Education report is now available with detailed findings filtered by survey respondents from higher and lower education providers: 131 from lower education and 95 from higher education whose organizations were hit by ransomware in the last 12 months. The survey was administered from January to March 2026.

Click here to access the full report now.

Attack vectors concentrated on identity

Identity-based vectors, including malicious email, phishing, compromised credentials, and brute force attacks, initiated 85% of attacks across education, above the 79% overall survey rate.

Malicious email was the single most common technical root cause in both lower education (31%) and higher education (29%).

However, the identity theme runs deeper than the entry point for ransomware attacks. 73% of education victims confirmed their ransomware attack was also their most significant identity attack in the past year. That was six percentage points above the 67% overall survey rate. Higher education had the most overlap at 77%, while lower education’s rate was 71%. The 67% overall survey finding was also featured in our State of Identity Security 2026 report earlier in the year.

Education was worse off operationally than the overall survey sample

When asked which operational shortcomings contributed to the ransomware attack, education providers cited each factor at a higher rate than the overall survey, aside from security gaps.  Here’s what that looked like:

Splitting education reveals different weaknesses:

  • In higher education, the defining gap was expertise: 53% said they lacked the skills to detect and stop the attack in time, compared with 35% for the overall survey.
  • In lower education, the problems clustered around capacity and tooling, led by human error (52%) and lack of protection (47%).

These operational root causes are described in more detail in the report.

Encryption climbed sharply in lower education

Last year’s report showed lower education stopping more attacks before encryption than any other sector. This year, that progress reversed. The share of attacks against lower education that succeeded in encrypting data more than doubled, from 29% in the 2025 report to 61% in 2026, above the 56% overall survey rate.

Across all of education, 58% of attacks ended in encrypted data.

However, the usage of backups to recover data increased in this year’s report: 77% of lower education and 69% of higher education providers restored data from backups, both above the 66% overall survey rate, and both a rebound from 2025.

Education recovered slower than almost everyone

Education not only paid more to recover, it also took longer. Education providers were nearly twice as likely as the overall survey to face a recovery lasting a month or more.

Education sectors sat near the top of the list when ranking sectors that had the longest average recovery times, and lower education was at the top of the list for another long-recovery time category. You can find the full details in the report.

The economics moved in different directions

Ransom demands sent to education providers fell to a multi-year low, with the median demand dropping to $775,200 and continuing a downward trend that has held for two years running.

Ransom payments moved the other way, edging up slightly to a median of $515,000. Even so, that amount stayed below the $769,000 overall survey median. It’s a positive step that education kept paying less than the overall survey despite facing steeper demands.

The report breaks down which education sector is driving demands and payments down.

Defenses that log the signal but don’t act on it

A common thread runs through all sectors in this year’s findings. Almost all victims of credential-based attacks had MFA enabled (98% education, 97% overall survey), yet most still had their data encrypted.

Another question revealed that firewalls flagged 65% of attacks for education providers before the ransomware detonated. But even in those early-detection cases, education victims were still encrypted 51% of the time.

Controls are collecting the right signals. They aren’t connecting deeply enough with each other to stop the attack in time. One of the recommendations in the report is to start moving cybersecurity toward a defense system posture, where identity, email, endpoint, and network controls share signals and respond as one.

This report also explores how the pressure of ransomware lands on people. 53% of higher education teams reported increased pressure from senior leaders after an attack, and around four in ten education teams reported staff absence due to stress or mental-health issues, well above the overall survey rates.

Read the report

For a sector where recovery is already slower and costlier, connecting existing defenses is the highest-leverage place to invest, both to protect data and to relieve the teams defending it.

Download the report for the full findings, lower and higher education breakdowns, sector comparisons, and recommendations.

Source: Sophos

2

Sep

The MSP 501 is widely regarded as one of the most comprehensive rankings in the managed IT services industry. Making the list is no small feat, requiring real operational discipline, consistent client delivery and a business built for sustainable growth.

The organizations on the 2026 MSP 501 list generated aggregate revenue of more than $32 billion, with average growth of 10.1%. Accounts grew 13.4% and staffing increased by 7%.

At Kaseya, we are thrilled that so many of our partners made the list, as we’ve seen firsthand all the hard work, innovation and strategic client focus that went into earning this recognition.

“Congratulations to all of this year’s MSP 501 honorees, especially the more than 300 Kaseya partners — including 10 of the top 20,” said Dan Tomaszewski, EVP, Channel, Kaseya. “This recognition is very well deserved.”

What separates the MSPs that make this list from those that don’t? To find out, we talked with Christopher Miller, CRO of ATB Technologies, which has made the list six years in a row. Here’s what he and other top-ranked MSPs are doing differently.

The best MSPs aren’t chasing the rankings,” said Miller. “They chase client success, and the recognition becomes a byproduct of that focus.” 

1. They treat AI and cybersecurity as growth engines

Three quarters of the 2026 MSP 501 listed managed security as a top revenue producer. Security and AI were the top two expected growth areas heading into 2026. The MSPs that made the list have moved well beyond talking about these trends. They’re building services around them.

According to PartnerOptimizer’s DNA of MSP Growth report, MSP 501 winners emphasized AI 3.8 times more than the broader MSP sector. This focus reflects the depth of their AI capabilities and how deliberately they’re integrating AI into client services.

But Miller is quick to draw a line between selling AI tools and delivering AI outcomes. “The reality is that software itself isn’t going to make AI work in an organization,” he said. “It’s a tool. It’s about how we provide outcomes. That takes knowledge-based workers, thought leadership and taking a tool and making it create an outcome.”

That distinction between deploying technology and driving outcomes is one of the clearest markers of the MSPs that consistently rank at the top.

2. They’ve evolved from IT support into strategic business advisors

The MSP industry has undergone a fundamental shift over the past two decades, from remote monitoring and cloud to AI. MSP 501 winners have been on the forefront of those seismic shifts.

Miller, who has been in the industry for 20 years, describes the transformation.

“We’ve evolved from providing IT support to really becoming more of a strategic business advisor,” he said. “Today, our clients expect guidance around cybersecurity, compliance, cloud transformation and AI adoption.”

Rather than leading with technology, Miller and his team approach every client AI conversation by leading with the question: “What outcome are you trying to achieve?” Then they determine whether AI is the right path to get there. It’s a simple reframe, but it’s the difference between being a vendor and being a trusted advisor.

“Technology has become a boardroom conversation,” said Miller. “MSPs that can connect technology decisions to business outcomes are really going to define the next decade of the MSP space.”

3. They practice what they preach by testing AI internally

Top MSPs don’t just recommend AI to clients; they use it in their own businesses. ATB uses AI across ticket intake, new user onboarding, recruiting, HR and marketing.

“We test emerging technologies internally because we believe we need to try it and test it before we bring it to our clients,” said Miller. “It gives us real scenarios and real solutions.”

The ROI case is direct. Miller puts it simply: A well-crafted prompt can produce 90% of what you need in minutes, leaving an hour of refinement instead of a full day of work. Across a team, that kind of efficiency compounds quickly and frees people up for higher-value work.

4. They invest in their people and use AI to help them, not replace them

The MSPs who make the 501 list consistently cite an investment in people as a core differentiator. But in 2026, that conversation is inseparable from AI.

Miller offers a concrete example from his client base: engineering firms that can’t hire qualified staff fast enough, leaving teams running at 125% capacity. ATB’s approach is to use AI to absorb that 25–35% overload — the repetitive, low-judgment tasks people don’t want to do — so staff can focus on the work that drives business value.

“If you truly care about your people, it’s not about putting them out of work,” said Miller. “It’s about helping them enjoy work more.”

It’s a people-first philosophy that runs through the best MSPs on the list, and it resonates with their clients who are wrestling with the same workforce pressures.

5. They chase client success, not rankings

Perhaps the most consistent theme across MSP 501 honorees is one that’s easy to overlook. The best-performing MSPs obsess over client outcomes first, and the recognition follows.

“The best MSPs aren’t chasing the rankings,” said Miller. “They chase client success, and the recognition becomes a byproduct of that focus.”

ATB’s success, by Miller’s account, comes down to three things: staying obsessed with client outcomes, investing in people and embracing innovation without losing sight of the business value it needs to deliver.

How Kaseya helped ATB and other MSPs

For many of the 300+ Kaseya partners who made this year’s list, Kaseya has been essential to their growth. Miller has worked within the Kaseya ecosystem across multiple platforms, from Autotask and Datto to Kaseya today.

“Kaseya has really helped us scale efficiently,” said Miller. “They provide the tools, the automation, the security and the monitoring — the overall operational consistency we need as an MSP.”

Just as important, Miller says, Kaseya has been a strong partner to ATB.

“Kaseya provides us with industry insights and access to a community of other successful MSPs,” he said. “That combination of technology and partnership is really what helps us deliver a more consistent, secure and ultimately strategic experience for our clients.”

At Kaseya, we’re committed to helping our partners scale and succeed.

“We want to be the partner that’s genuinely invested in your success,” said Tomaszewski. “The best partnerships are built on shared ambition, and this community has it in abundance.”

The future belongs to MSPs that lead with relationships

The MSPs at the top are building businesses with genuine depth: in their security practices, their AI capabilities, their operational discipline and their client relationships.

“The future really belongs to MSPs that can combine automation, cybersecurity and AI with what technology can’t replace, and that’s trusted relationships,” said Miller.

Congratulations again to all 2026 MSP 501 honorees and to the Kaseya partners who earned their place on the list. The work you’re doing for your clients, your teams and the broader industry is what makes this community exceptional.

Source: Kaseya

28

Aug

G2 has released its Fall 2026 Reports, and customers once again ranked Sophos among the industry’s top cybersecurity vendors.

Sophos was named the #1 Overall solution across Endpoint Protection Platforms (EPP), Managed Detection and Response (MDR), Extended Detection and Response (XDR), and Firewall Software. In addition, Sophos was recognized as a Leader for the 17th consecutive reporting period across the G2 Overall Grid® for Endpoint Protection Platforms, Endpoint Detection and Response (EDR), XDR, Firewall Software, and MDR.

We believe these #1 Overall rankings across Endpoint Protection, XDR, MDR, and Firewall along with Leader recognition across Endpoint Protection, EDR, XDR, MDR, and Firewall reflect Sophos’ commitment to delivering powerful, unified cybersecurity protection without adding operational complexity. Based on customer feedback, organizations continue to recognize Sophos for strong security outcomes, Synchronized Security (coordinated cross-product response), easy deployment, and day-to-day usability.

Additionally, Sophos is the only vendor recognized as a Leader across all five of these core cybersecurity markets, a distinction we believe underscores the strength of Sophos Fusion, the industry’s most complete AI-Native Cybersecurity Defense System, which protects more than 625,000 organizations worldwide.

G2 Fall 2026 Sophos results at a glance

Across the G2 Fall 2026 reporting period, Sophos achieved:

  • 73 #1 rankings across global G2 reports
  • Four #1 Overall rankings across Endpoint Protection, XDR, MDR, and Firewall
  • 15 Consecutive #1 Overall rankings for Sophos Firewall in the G2 Grid® Report for Firewall
  • Leader distinctions for 17 consecutive reporting periods across the named G2 Overall Grids
  • Five consecutive seasonal reports where Sophos Firewall was ranked #1 by Enterprise, Mid-Market, and Small Business customers
  • Nine consecutive seasonal reports with Sophos MDR ranked #1 Overall

How Sophos MDR ranked in the G2 Fall 2026 Reports

Sophos MDR was ranked the #1 Overall MDR solution for the ninth consecutive G2 seasonal report. Sophos MDR was also recognized as a Leader across all customer segments and earned Best Results and Best Usability distinctions among Enterprise and Mid-Market customers.

We believe this continued recognition of Sophos MDR reflects customer confidence in its ability to deliver 24/7 threat monitoring and response through an easy-to-use service model, helping IT and security teams strengthen their security posture while reducing operational burden.

How Sophos Endpoint and XDR ranked in the G2 Fall 2026 Reports

Sophos Endpoint maintained its #1 Overall position for both Endpoint Protection Platforms and XDR for the third consecutive seasonal report. Across the Endpoint Protection and XDR categories, Sophos received #1 rankings in 30 reports.

Sophos Endpoint also received the following distinctions:

  • Best Results and Best Usability across Endpoint Protection Platforms category among Enterprise, Mid-Market, and Small Business customer segments
  • Best Usability in Endpoint Detection and Response among Enterprise and Mid-Market customers
  • Best Overall Results and Best Usability in Extended Detection and Response

How Sophos Firewall ranked in the G2 Fall 2026 Reports

Sophos Firewall earned its 15th consecutive #1 Overall ranking in the G2 Grid® Report for Firewall. It was also named the #1 Firewall solution by Enterprise, Mid-Market, and Small Business customers for the fifth consecutive seasonal report.

Sophos Firewall also earned the following G2 distinctions across Overall, Enterprise, Mid-Market, and Small Business segments:

  • Best Results
  • Best Usability
  • Best Relationship
  • Most Implementable

Why organizations continue to trust Sophos

The G2 Fall 2026 rankings reflect customer recognition across several areas of the Sophos portfolio, Customers awarded Sophos distinctions including Overall Best Results, Best Usability, and Best Relationship across Firewall, EPP, and XDR categories.

These distinctions reinforce the importance customers place on security effectiveness, usability, and the vendor relationship when evaluating cybersecurity solutions.

What the G2 Fall 2026 rankings mean for security teams

Organizations continue to balance the need for effective cybersecurity with the operational demands placed on IT and security teams. Sophos’s recognition across Endpoint, XDR, MDR, and Firewall shows the breadth of customer feedback represented across its security portfolio.

Sophos brings together these capabilities to help organizations:

  • Protect endpoints and networks across their environments
  • Detect, investigate, and respond to threats
  • Simplify security administration and day-to-day workflows
  • Reduce the operational burden placed on internal IT and security teams
  • Strengthen security through integrated products, services, and threat intelligence

What Sophos customers are saying

Don’t just take our word for it. Sophos customers describe the value of Endpoint, Firewall, and MDR in terms of strong threat protection, greater visibility, easier management, synchronized security, continuous monitoring, and reduced pressure on internal IT teams. Their feedback shows how Sophos helps organizations strengthen security while simplifying day-to-day operations.

Sophos MDR

“Sophos MDR is the 24/7 threat monitoring and rapid response capabilities provided by the security team. It significantly reduces the workload on our internal IT team while improving our overall security posture.” Source: Validated Director of IT in the Mid-Market segment.

Sophos Endpoint

“[Sophos Endpoint] excels at blocking ransomware, exploits, zero-day attacks and other advanced threats by combining deep learning and AI with behavioral analysis and real-time intelligence.” Source:Validated user in the Mid-Market segment.

Sophos Firewall

“The best thing about [Sophos Firewall] is the synchronized security through Security Heartbeat. It’s really great that the firewall can communicate with devices on the network and immediately stop any device from causing further problems.” Source: Validated Security Analyst in the Small Business segment.

Learn more about Sophos security solutions

Explore how Sophos helps organizations protect endpoints and networks, detect and respond to threats, and simplify security operations:

Source: Sophos

25

Aug

The main difference between AI governance and AI compliance is that AI governance is the internal framework an organization develops to manage AI responsibly, while AI compliance is how organizations demonstrate to external regulators that they’re adhering to applicable laws and regulations. These two terms get used interchangeably, but they solve different problems. With compliance alone, an organization can satisfy regulators without meaningfully controlling how its AI behaves. With governance alone, it has controls in place but no proof they meet regulatory standards.

Continue reading to learn more about AI governance and AI compliance, how they differ and why your organization needs both.

What is AI governance?

AI governance is the set of policies, roles and processes that determine how an organization builds, deploys and manages AI throughout its lifecycle. It’s internal and proactive, shaped by the organization’s own values, and it sets guardrails before a system reaches production.

In practice, AI governance covers everyday decisions that hold AI accountable, including classifying use cases by risk, assigning an owner to each system and setting approval thresholds. It also covers ongoing work, such as monitoring model behavior, logging decisions and running bias checks, so the organization can explain how any given system reaches outputs.

What is AI compliance?

AI compliance involves meeting the external requirements – laws, regulations, industry standards and contractual obligations – that govern how AI is used. Unlike governance, it isn’t shaped by an organization’s own values. Instead, it answers the question of whether or not an organization is following the rules that apply to it. Regulations like the EU AI Act impose risk classifications, transparency obligations and human oversight for high-risk systems. Organizations also increasingly adopt voluntary frameworks like the NIST AI Risk Management Framework to show a credible, structured approach even where the law hasn’t caught up yet.

The main differences between AI governance and AI compliance

AI governance is internal and proactive, originating within an organization and reflecting the standards it holds itself to. AI compliance is external and evidence-based, validating that the organization meets rules set by others, and it depends on the documentation the organization can produce. Governance asks whether an organization is managing AI responsibly and builds the controls to do it. Compliance asks whether the organization is meeting the rules and can produce evidence to prove it. Below are the key distinctions between AI governance and AI compliance.

AI governance AI compliance
Driven by Internal values, risk tolerance and objectives External laws, regulators and standards
Posture Prevents problems before they happen Validates rules already in place
Main output Controls, ownership and accountability Documentation, disclosures and audit evidence
Examples Review boards, approval workflows and monitoring EU AI Act conformity, ISO/IEC 42001 and GDPR

How AI governance and AI compliance work together

Despite their differences, AI governance and AI compliance depend on each other. Once an organization has classified its use cases, assigned owners and built monitoring into how AI runs, meeting an external requirement becomes largely a matter of pointing to controls that already exist. Compliance without governance is documentation with nothing behind it: the paperwork satisfies a checklist while the rules go unenforced in practice. Real AI compliance is only sustainable when AI governance is doing the work behind the scenes.

AI needs both governance and compliance

Skipping either AI governance or AI compliance has significant consequences. Fall short on compliance, and you expose the organization to regulatory penalties and lasting reputational damage. Fall short on governance, and you face unsafe AI adoption and a higher risk of shadow AI. Both risks grow as AI agents gain more privileged access across your environment, making it essential to govern and secure those agents to protect sensitive data.

Secure your AI agents and privileged access with Keeper® to enforce least-privilege access, maintain a detailed audit trail and control both human and machine identities.

Source: Keeper

21

Aug

The Sophos AI Security 2026 report, released last month, just showed us the current state of AI-enhanced cyberattacks: Timelines are accelerating from weeks into days. Defending against that speed requires more than access to advanced models. Organizations also need a system to operationalize those models into working defenses, and the reach to deliver that capability at scale.

Today, Sophos and OpenAI are announcing a partnership to bring OpenAI frontier models to the channel and service providers through Sophos Fusion, the industry’s most complete AI-native cybersecurity defense system. By combining OpenAI’s model capabilities with deep knowledge across our customers’ environments, we intend to give partners a new way to deliver frontier AI security as one connected defense system, and to build recurring services on top of it.

Sophos has also been invited to join a new program that extends OpenAI’s Daybreak Cyber Partner Program for managed security services.

The three ways AI meets cybersecurity

Futurum Group’s Fernando Montenegro frames the relationship between AI and cybersecurity in three parts, and Sophos will have a focus on each of them with OpenAI:

  1. Security from AI: AI is accelerating the development of malicious tradecraft, vulnerability exploitation, and enabling threat actors to launch more attacks against more targets. Stopping these AI-enabled attacks is a core pillar of the Sophos defense system. For example:
    • Sophos Endpoint blocks the techniques used to exploit vulnerabilities, so a novel, AI-discovered weakness meets the same wall as a known one.
    • Our agentic SOC compresses detection, investigation, and response to match the speed AI hands attackers, with 52% of incidents resolved end-to-end by AI in an average of 89 seconds.
    • Our researchers track adversarial AI use continuously, and what they find feeds directly back into both.
  2. AI for security: Fight fire with fire. We’ve been using AI in our solutions since 2017 and AI capabilities are embedded right across the Sophos portfolio. Plus, every threat the system encounters informs and improves the system as a whole. The OpenAI partnership has a goal of adding frontier model capability on top of a foundation that is already AI-native rather than bolting AI onto it.
  3. Security for AI: Organizations are standing up AI across their lines of business and need security guardrails along with it. This is where Sophos AI Defense fits, giving organizations visibility into AI and shadow AI use, enforcing policy, and helping govern how sensitive data is used across AI models and tools.

One connected defense system for the channel

Sophos Fusion is built on a single, open architecture where every control point operates as one, whether native to Sophos or a third-party integration. The partnership will extend that openness by bringing OpenAI frontier models into our defense system, which already connects endpoint, network, email, cloud, identity, and security operations while continuously compounding intelligence from every threat it encounters.

Many managed service providers (MSPs) and managed security service providers (MSSPs) are uniquely positioned to turn frontier cyber capabilities into practical security outcomes because they understand their customers’ environments and already operate the workflows organizations rely on. Sophos Fusion supports that work by connecting endpoint, network, email, cloud, identity, and security operations in one coordinated defense system. By pairing that foundation with OpenAI’s frontier capabilities, Sophos plans to help approved partners enhance detection, investigation, and response, while also helping MSPs develop and scale new AI security services for their customers. Sophos intends to expand this protection with OpenAI, securing the AI workloads, data, and usage as part of one connected defense system.

Reach that spans SMB to enterprise

Sophos defends more than 625,000 organizations worldwide, from small businesses to global enterprises, delivered through a channel of over 25,000 partners, including more than 7,000 MSPs. That breadth is how frontier AI can reach the organizations that need it most, including those unable to deploy these models on their own.

Frontier AI across our managed services

Sophos is also extending its partnership within OpenAI’s Daybreak Cyber Partner Program. In June, Sophos gained access to OpenAI’s cyber models to strengthen our products and threat intelligence.

Now we’re extending that work into Sophos MDR, Digital Forensics and Incident Response (DFIR), and advisory services as a launch partner in OpenAI’s new Daybreak Cyber Partner Program for Managed Security Services.

This program brings frontier cyber models to organizations delivering managed security. As a launch partner, Sophos applies the latest cyber-capable models across three pillars of our managed services, with expert operators in control and no direct customer access to the models:

  • MDR: The models help analysts correlate signals across endpoint, network, identity, email, and cloud, separating real threats from noise in seconds. Analysts validate each finding and direct the response.
  • DFIR: The models help responders rebuild the attack timeline and assess what an intruder accessed, moved, or took. This will support containment, disclosure obligations, and recovery.
  • Advisory services, including offensive security and penetration testing: The models help consultants map likely attack paths and validate exploitable weaknesses, giving customers a prioritized, evidence-backed view of their exposure.

The benefit for customers is frontier-grade defense that would be extremely difficult to build in-house. Most organizations can’t hire the rare talent needed or take on the capacity or financial obligations associated with running frontier AI in their own security operations, and they shouldn’t have to. Customers can rely on Sophos experts to operate the latest models, govern them, and stay accountable for the outcome.

Sophos is uniquely positioned to deliver these capabilities, operating the world’s largest agentic security operations center and defending more than 40,000 MDR customers worldwide, with human analysts maintaining oversight throughout and keeping hands-on-keyboard in every engagement.

Sophos will continue to develop the safety, abuse-prevention, and monitoring standards for responsible use of these capabilities.

Source: Sophos

18

Aug

We’re excited to announce another update to Sophos DNS Protection, helping you monitor and control use of Generative AI sites and services within your network.

A new Generative AI category has been added to the already-extensive list of categories used in web and domain policies across our product range. With this update, the category is available for use in DNS Protection policies.

For those of you who are already using Sophos DNS Protection, the new category is available right away. Because most of the sites covered by the new category were previously in the Information Technology category, your policies will be updated so that the action for the new Generative AI category is the same as that for Information Technology. But you can go straight in there and change it if you want!

You’ll also see the Generative AI category start to appear in DNS Protection reports and in the traffic logs that XDR and MDR customers can access via LiveDiscover queries. So you’ll be able to quickly see whether Generative AI tools are in use on your networks.

Customers with Workspace Protection who have deployed the Endpoint DNS Protection feature will also be able to pinpoint the users and devices where Generative AI domains are in use.

Learn more about Sophos DNS Protection and how you can add it easily to your Sophos Firewall with the Xstream Protection Bundle or devices with Sophos Workspace Protection.

Source: Sophos

14

Aug

Nozomi Networks, the leader in operational technology (OT), Internet of Things (IoT) and cyber physical systems (CPS) security and Sophos, a global cybersecurity leader, today announced a partnership to integrate Nozomi Networks Vantage, Nozomi’s cloud-native, AI-enabled OT security platform, with Sophos Fusion, Sophos’ AI-native cybersecurity defense system to enhance visibility and threat detection between IT and OT environments.

The announcement represents one of the first major third-party technology integrations following the launch of Sophos Fusion, demonstrating Sophos’ commitment to an open ecosystem that brings best-of-breed security technologies into a unified defense system.

Critical infrastructure is facing an aggressive threat landscape as both nation states and cybercriminals increasingly target OT and industrial environments, and many OT outages begin with a compromise of the IT environment. As organizations connect more industrial assets and adopt remote management capabilities, complete visibility across both IT and OT environments becomes increasingly important.

“The intersection of IT and OT environments has long been misunderstood by the cybersecurity industry, leading to inefficiencies and potential danger for critical infrastructure,” said Matt Cowell, Vice President of Strategic Alliances at Nozomi Networks. “This partnership helps solve these problems by seamlessly integrating OT intelligence into IT security investigations so teams have the full picture when assessing their increasingly expanding attack surface.”

This integration brings Nozomi’s OT telemetry, asset intelligence, and threat data directly into Sophos Fusion, where it can be correlated with security data from across the customer’s IT environment without needing to switch contexts, putting OT intelligence directly where investigations happen to help security teams work faster and make better decisions.

Key benefits of the partnership include:

  • Security data correlation across OT, endpoint, network, cloud, and identity sources
  • Improved investigation quality through richer context and correlation
  • Greater SOC efficiency through fewer manual processes and less console switching
  • Automated enrichment and response through Security Orchestration, Automation, and Response (SOAR) workflows

“Defenders need every resource they can to combat sophisticated threat actors. This partnership helps security teams easily assess OT and IT vulnerabilities in one place, allowing them to take action much faster,” said Chris Bell, SVP of Global Channel and Alliances at Sophos. “Following the launch of Sophos Fusion, this is a testament to our commitment to bring best-of-breed security technologies into a single defense system for superior threat detection, investigation, and response.”

To learn more about Nozomi Networks Vantage, click here. To learn more about Sophos Fusion, click here.

Source: Sophos

10

Aug

With evolving AI threats, traditional defences are no longer enough.

Email has long been a point of vulnerability for businesses, but the scale and sophistication of attacks are evolving, posing a greater threat than ever before.

Adding to the challenge is AI, which is helping bad actors iterate and improve their attacks at an unprecedented pace. This is no longer a theory — it’s happening right now.  According to Infosecurity Magazine, phishing attacks doubled in just one year.

While AI may be fuelling an increase in malicious activity, the good news is that, in the right hands, it’s also helping organisations combat phishing threats.

In today’s email security “arms race,” having the right tools to counter evolving threats is vital.

Email security is a priority for SMBs 

In Kaseya’s 2026 Cybersecurity Outlook, two of the top three areas of concern for SMBs were related to email —  and many respondents had already experienced email-based attacks firsthand.

56% said they had been impacted by phishing attacks, while 40% reported being victims of business email compromise (BEC).

Looking ahead, businesses continue to view email as a risk. Human error and social engineering ranked as the top concern for 29% of businesses, while 27% identified email itself as a primary threat. But with email being frequently exploited for social engineering attacks, the two are intrinsically linked.

MSPs surveyed broadly agreed with these concerns but took an even more stark view of future risks. 76% of MSPs believe companies will succumb to a successful phishing attack and 66% to BEC.

The positive among these concerning stats is that companies see email protection as one of the best applications for AI — with 49% saying email protection is AI’s biggest strength.

How strong email security supports NIS2 compliance

Threat prevention forms a core part of NIS2 legislation, moving email security from an IT discussion to a broader boardroom responsibility for security and resiliency. While NIS2 doesn’t directly address email, its principles apply to this and other systems.

Several areas of NIS2 are supported by effective email security:

  • Risk analysis & information system security  | Email is at the centre of many threats, including phishing, BEC and malware. It’s vital that risk analysis covers both the email systems themselves as well as the potential ramifications of successful attacks that use email as the method of entry.
  • Basic computer hygiene and training  | Even with the best tools, emails will slip past automated checks. That’s why it’s vital that employees get regular training on what to look out for and on security best practices. This should be backed up with useful, contextual reminders, such as anti-phishing banners to coach users on each email risks.
  • Business continuity measures  | If email goes down, what happens next? There are many elements to this, including backup emergency communications (itself a part of NIS2 guidance) as well as secure email backups, so your business can confidently recover from an incident.
  • Use of multifactor authentication | This is explicitly flagged in NIS2 and is a vital part of email security. With email offering the ability for bad actors to find their way into other systems, as well as sending malicious communications, MFA provides a sensible core security measure as a first line of defence for email security.  

Companies need to review their security posture to remain compliant with NIS2, and for MSPs, it’s an opportunity to help guide customers on that journey.

MSPs are concerned about the growing sophistication of attacks

At a recent Kaseya Connect Local event, two MSP leaders took to the stage to discuss how email threats are evolving.

“I think the biggest difference is the quality and variation,” said Phil Callowat, Director of Ark ICT Solutions. He admitted the pace of change is “really scary, if I have to be honest.” Explaining how emails in the past were largely limited to adding some branding and pretending to be from a trusted organisation such as a bank, he said “I think the difference now is it’s just so much more imaginative than it ever used to be. It’s getting much more clever at adapting to what you’re likely to fall for.”

Echoing the concerns around social engineering in combination with phishing attempts, Marvin Miller, Director of 1101, said bad actors were putting the time into doing their homework. “It’s getting smarter and smarter and also more targeted as well. They tend to target your top board members, your directors, your managers — but then also new employees as well. They’re constantly scoping LinkedIn to work out who’s joined a company.”

Attacks “are coming in thicker and faster” thanks to AI, Miller added, but also said it would help in defending against them. “Leveraging AI, that’s going to help us to keep abreast of it,” he said.

The right tools are vital to combat modern threats

While AI may be a threat, with the right tools, it also strengthens the first line of defence.

  • AI can help protect email in ways that tools previously couldn’t. Features such as conversation analysis can read not just the content but also understand intent.
  • With computer vision, emails can be “seen” to understand brand impersonation attempts and scan items like QR codes to understand where the destination URL is going and if it’s safe.
  • AI can combat tricks used by scammers, such as zero-font manipulation, while machine-based learning based on content helps find and identify likely spam or phishing content.

Source: Kaseya

7

Aug

Phishing has topped the list of initial attack vectors for the fourth year running, according to the latest edition of IBM’s annual Cost of Data Breach report.

According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence.

Voice and SMS phishing has led to the highest average breach costs of any attack vector studied this year, according to IBM’s research, reaching at US $5.29 million per incident.

Social engineering attacks – which include help desk impersonation and MFA fatigue tactics – were not far behind at an average cost of US $5.23 million.

To put those figures in context, the global average cost of a data breach across all types of attack came to US $4.99 million. In short, phishing and social engineering attacks cause above an average financial cost for victim organizations.

But, of course, that doesn’t tell the whole story. A successful phishing attack will often lead to a valid business account being accessed and abused – at an average cost, according to the report, of $5.07 million per breach.

It’s easy to see just how quickly a single convincing email or phone call can set off a chain of events that could cost an organization millions of dollars.

It’s impossible in 2026 not to recognize the difference that artificial intelligence is making to cybersecurity, and how criminals have adopted AI to their benefit.

Generative AI has dramatically lowered the cost, time, and expertise required to launch convincing phishing campaigns. Poorly worded emails with suspicious links are increasingly a thing of the past, as AI can easily generate highly-targeted, convincing communications at a scale that unheard of in the past.

The report found that AI-generated phishing and other communications accounted for some 17% of the malicious AI attacks studied. Meanwhile, the highest volume of AI-driven attacks overall involves deepfake impersonation. 45% of AI-driven attacks saw deepfake techniques used to make convincing voice and video messages, designed to trip up unsuspecting users.

All of this use of AI means that the barrier to launching sophisticated phishing campaigns has effectively collapsed. Where once cybercriminals would have required skilled cohorts and significant resources, they now can use AI to automate, personalize and deploy attacks at scale.

What is particularly disappointing is that despite breaches which start with a phishing attack being one of the most well-understood types of threat, they still take an average of 251 days to identify and contain. according to the research.

251 days is an awfully long time for a cybercriminal to explore a hacked network, escalate their privileges, and steal sensitive data.

Part of the problem is that criminals are abusing legitimate credentials and established channels to access information. Once an attacker is operating through a valid account, businesses may find it difficult to distinguish a normal user’s behavior from that of a hacker – unless the right visibility tools are put in place.

It is clear that awareness training on its own is not enough. If it were, then phishing would have been removed from the top of the attack charts long ago.

That’s not to say that awareness training has no value – it remains a valuable layer of defense – but it should not be your company’s primary way of dealing with the problem.

Businesses should deploy layered technical defenses which can pick up what humans miss. Incoming messages – via email and other routes – should be filtered and analyzed for suspicious content before they reach a user’s desktop or smartphone. Anomalous behavior should be highlighted after an account has been compromised. Controls should be put in place to limit the blast radius of a breach after a user clicks on the wrong link.

Without stronger controls, phishing is likely to keep on being a winning tactic for cybercriminals, especially when augmented with AI.

Source: Fortra

4

Aug

Cybersecurity investment is increasing. So are incidents, compliance pressures, and demands for accountability. Organizations have more security data than ever before, yet many still struggle to answer fundamental questions: are we secure, are we improving, where should we invest next, and can we prove it?

For some, the problem is a lack of strategic security leadership. For others, it’s the challenge of stitching together data from across a fragmented security program. For MSPs as well, there is the challenge of delivering cybersecurity leadership and compliance guidance in a way that is standardized, scalable, and commercially viable.

That’s why we’re excited to introduce Sophos CISO Advantage, a new approach to Cyber Program Management that helps organizations and MSPs measure, manage, improve, and communicate cybersecurity outcomes.

Introducing Sophos CISO Advantage

Sophos CISO Advantage is an assessment-led entry point into Cyber Program Management, enabling you to take control of security outcomes by offering visibility and insight into your or your customers’ environments.

It helps organizations understand risk, prioritize what matters most, and show measurable improvements in their security posture. Assumptions can be replaced with validated, framework-mapped evidence of whether controls are working, and evidence that is defensible to boards, auditors, and insurers. By translating complex assessment data into business language, Sophos CISO Advantage ultimately bridges the gap between IT and the boardroom, enabling leadership to make informed cybersecurity investment decisions.Sophos CISO Advantage is delivered through Sophos Fusion, our AI-Native Cybersecurity Defense System. This gives organizations all the benefits of a cyber defense system that sees everything, connects everything, and enables your defenses to respond as one.

How Sophos CISO Advantage works

For CISOs and security leaders

We developed Sophos CISO Advantage with a challenge in mind that we’ve repeatedly heard from security leaders: despite having more tools, data, and reporting than ever before, it remains difficult to demonstrate whether your security program is delivering value. Boardroom trust is harder to capture, adding tensions.

Sophos CISO Advantage helps you consolidate information from across your cybersecurity program into a single framework for measuring and improving performance. It removes the need to spend hours gathering evidence, preparing reports, and translating technical findings into business outcomes. You gain a structured way to assess your environment, identify gaps, prioritize investments, and demonstrate measurable progress over time.

The result is greater visibility into the effectiveness of your security program and a clearer way to communicate risk, priorities, and outcomes to executive stakeholders.

For MSPs and service providers

MSPs are more than a beneficiary of Sophos CISO Advantage. They are one of the primary reasons we built it. Many are already delivering the core elements of Cyber Program Management: answering customer questions about risk, supporting compliance initiatives, providing strategic guidance, and helping justify security investments. The problem is that much of this work is delivered informally, making it difficult to scale and monetize.

As customers increasingly look to their provider for strategic security leadership, MSPs face a unique opportunity to evolve. Now, they can move beyond administering security tools and operations towards delivering a complete Cyber Program Management program. Sophos CISO Advantage provides the framework to make that possible in a repeatable, scalable, and commercially successful way. It transforms advisory work that is often delivered as added value into a structured, AI-powered service that creates measurable outcomes for customers and recurring revenue for their own business.

Key features available in Sophos CISO Advantage v1

The initial release of Sophos CISO Advantage is scheduled for October 2026 and focuses on helping organizations and MSPs establish a scalable approach to Cyber Program Management.

Key capabilities include:

  • Framework-aligned assessments to establish a cybersecurity baseline and measure maturity
  • AI-powered scoring and guidance to accelerate analysis and highlight high-priority issues
  • Gap analysis and prioritized recommendations that turn findings into actionable plans
  • AI-generated action prioritization to help focus resources on the areas of greatest risk reduction
  • Multi-audience reporting for technical teams, executives, and boards
  • AI-generated report narratives that convert technical findings into business-focused insights
  • Industry benchmarking to provide context for performance and maturity
  • Evidence storage and framework mapping to support compliance, audit, and cyber insurance requirements

Together, these capabilities help organizations move from asking “Where are we?” to confidently answering “What should we do next?”

Looking ahead: Sophos CISO Advantage Plus

Sophos CISO Advantage v1 establishes the foundation for Cyber Program Management. In December, Sophos plans to introduce additional capabilities through Sophos CISO Advantage Plus, helping organizations evolve from periodic assessment and planning toward a more continuous model of cyber leadership. Future enhancements will focus on ongoing control effectiveness, continuous monitoring, governance workflows, and deeper strategic engagement.

What to do next

For CISOs and security leaders

For more information on how to adopt Sophos CISO Advantage, please speak to your account manager or contact us here. You can also find out more through the Sophos website here.

We’ll be sharing more information and helping you understand the problems Sophos CISO Advantage solves through upcoming webinars later this year. Stay tuned for more.

For MSPs and Partners

Visit the Partner Portal to access launch resources, positioning guidance, and enablement materials designed to help you introduce Sophos CISO Advantage to customers and build new Cyber Program Management service offerings.

The cybersecurity conversation has shifted from controls to outcomes, from activity to performance, and from security operations to cyber leadership. Sophos CISO Advantage is designed to help both CISOs and MSPs lead that shift.

Source: Sophos

 

30

Jul

The AI era is here. Now comes the hard part: how do you see, control, and secure its usage?

Employees are using AI tools faster than anyone can track them. Source code, customer records, and financial data flow into apps no one approved. Agents and embedded AI features act without oversight. Security teams frequently cannot see what AI is in use, let alone control how it behaves or protect the data moving through it.

The numbers make the gap clear:

  • 75% of employees use AI tools not sanctioned by IT.
  • 82% of organizations discovered at least one AI agent or workflow they did not previously know about.
  • 90% of IT leaders are concerned about shadow AI from a privacy and security standpoint.

This is not a future problem. It is happening right now, in every kind of organization, whether they have a full security operations center or no dedicated security staff at all.

Introducing Sophos AI Defense

Sophos AI Defense brings AI out of the shadows, allowing you to see, control, and secure how AI is used across your environment. It discovers AI activity, including shadow AI, assesses which activity introduces real risk, enforces policy at the moments that matter, and feeds AI-related signals into the security workflows your team already trusts.

Powered by Sophos Fusion, Sophos AI Defense delivers practical AI security you can adopt today, without new platforms, added tooling, or a dedicated AI security team.

Built for how organizations really use AI

Most AI security tools are built to secure models, pipelines, or future-state platforms. Sophos AI Defense focuses on the risk you face right now: unmanaged usage, blind spots, and sensitive data leaving through everyday AI tools.

Sophos AI Defense enables you to discover AI activity across your environment, assess what introduces real risk, enforce AI use at scale, and respond to threats before impact escalates.

  • Discover. Reveal every AI agent, tool, and activity across your environment, including shadow AI and autonomous agents, so nothing runs beyond your view.
  • Assess. Understand which activity actually introduces risk by weighing identity, permissions, geography, data access, and behavior in context, not in isolation.
  • Enforce. Apply scalable guardrails that keep AI use aligned with policy and regulation, including controls on prompts and agent behavior, without slowing people down.
  • Respond. Feed AI activity into your detection and response workflows as a first-class security signal, using the same playbooks, tools, and escalation paths you rely on today.

Powered by Sophos Fusion

Sophos AI Defense is part of Sophos Fusion, the AI-Native Cybersecurity Defense System that unifies Sophos technology into a coordinated, adaptive defense. Rather than adding another standalone product, Sophos AI Defense extends the protection you already have across endpoint, network, identity, and browser, and applies it to the fast-emerging risk of unmanaged AI use.

It is available as an add-on for Sophos EDR, Sophos XDR, and Sophos MDR customers on Sophos Fusion.

Bring AI out of the shadows

AI is already part of how your organization works. Sophos AI Defense helps you adopt and use it with confidence, turning AI from an unmanaged liability into a visible, controllable, and secure part of your environment.

Speak to an expert today or visit sophos.com/ai-defense to learn more.

Source: Sophos

28

Jul

Security teams have a lot coming at them right now. Attacks are moving faster, environments are getting more complex, and many teams are being asked to do more with less.

That’s why we’re excited to share that Sophos has been named a Leader in the IDC MarketScape for Worldwide Managed Detection and Response Services for Midmarket 2026 Vendor Assessment (#US52992326, July 2026).

The IDC MarketScape evaluates MDR providers based on both current capabilities and future strategy, looking at how well vendors help organizations detect, investigate, and respond to threats across increasingly complex environments. For midmarket organizations in particular, we believe the report offers a helpful view into which providers can deliver strong security outcomes without adding unnecessary operational burden.

We believe this recognition reflects the work we’re doing to help organizations strengthen their defenses with intelligence-led security operations, flexible service models, and open security architectures that work with the tools they already have.

According to the IDC MarketScape:

“Organizations of any size seeking a managed detection and response service with deep proprietary threat intelligence, flexible co-management engagement models, and a vendor-agnostic platform that accommodates existing security investments should evaluate Sophos’s MDR offering.”

Security operations built for today’s threat landscape

Sophos MDR protects more than 40,000 customers worldwide through a globally distributed security operations model backed by Sophos X-Ops, which brings together threat intelligence, threat hunting, detection engineering, and managed service delivery.

Our approach is simple: the best security outcomes come from combining AI with human expertise. Sophos MDR uses agentic AI to automate investigations and operational workflows, so analysts can stay focused on high-stakes decisions, novel threats, threat hunting, and customer guidance.

That gives customers security operations that can move quickly and scale, while still keeping the human oversight and expertise they expect from a managed service. Today, 52% of MDR cases are closed end-to-end by AI, and authorized fully automated responses can occur in as little as 89 seconds.

Open, flexible, and designed to work with your environment

Every organization’s environment is different. Sophos MDR is built to support both Sophos and third-party telemetry sources across endpoints, networks, cloud, email, and identity environments. Our vendor-agnostic architecture helps organizations get more value from the security investments they already have, rather than forcing them to start over.

Customers can choose the level of engagement that works best for them, from notification-only support to collaborative investigations and full response authorization. Modular capabilities including exposure management, next-gen SIEM, and identity threat detection and response also make it easier to expand coverage as needs change.

Intelligence that gets stronger with every threat observed

Threat intelligence powers the detections, threat hunts, and response actions that help Sophos MDR protect customers around the world. The Sophos X-Ops Counter Threat Unit (CTU) tracks ransomware operators, initial access brokers, and nation-state actors, generating intelligence that feeds directly into detection engineering, threat hunting, and response playbooks.

Combined with visibility across a large global customer base of over 625,000 defended organizations, that intelligence helps us quickly turn emerging threats into protections, detections, and response actions for customers around the world. All in real-time, all without fine-tuning.

MDR as part of a broader defense system

This IDC MarketScape recognition also comes at an exciting time for Sophos.

With the launch of Sophos Fusion, our AI-native cybersecurity defense system, we’re bringing together endpoint, network, email, cloud, identity, security operations, and advisory services within a single connected architecture.

Built for a threat landscape reshaped by AI, Sophos Fusion combines shared context, synchronized security operations, agentic AI, and intelligence that compounds across the environments it protects. As Sophos Fusion evolves, customers will get deeper integration across MDR, exposure management, identity protection, next-gen SIEM, executive guidance, and proactive risk reduction.

Learn more

Click here to read the report excerpt. For organizations looking for a managed detection and response service that combines deep threat intelligence, flexible engagement models, and an open platform approach, we believe this latest IDC MarketScape recognition reinforces the strength of Sophos MDR.

Source: Sophos

 

23

Jul

This year’s data has a few eyebrow-raising departures from the patterns of past State of Ransomware reports. Exploited vulnerabilities lost their three-year grip on the top root-cause spot. Median ransom demands and payments both dropped, yet the average recovery bill still climbed. And small organizations (100-250 employees) are falling further behind their larger peers on the one metric that matters most: stopping the attack before data gets encrypted.

The seventh annual Sophos State of Ransomware report is based on a vendor-agnostic survey of 2,158 IT and security leaders whose organizations were hit by ransomware in the last 12 months.

Click here to access the full report now.

Email is the new number one root cause

For the first time in four years, exploited vulnerabilities are not the top way attackers get in. The rankings this year:

  • Malicious email (26%) and phishing (24%) together account for half of all incidents.
  • Compromised credentials (23%) held steady in third.
  • Exploited vulnerabilities (18%) fell 14 percentage points year over year.
  • Brute-force attacks (6%) were flat.

The takeaway for defenders is direct: patching alone will not close the gap. Advanced email protection, DMARC, DKIM, and SPF, and user awareness training belong at the top of the 2026 investment list.

Identity-based attacks now drive most ransomware incidents

79% of ransomware attacks started with an identity-based approach, and 67% of victims confirmed that their ransomware incident was the same event as their most significant identity attack. This finding was also featured in our State of Identity Security 2026 report earlier in the year.

The 2026 Sophos Active Adversary Report, which is based on analysis of real-world incidents remediated by Sophos defenders, arrives at the same finding. 67% of root causes across 661 incident response (IR) and managed detection and response (MDR) cases were identity-related, and multi-factor authentication (MFA) was missing where it mattered in 59% of cases.

MFA is deployed, but not everywhere

97% of victims where compromised credentials were the root cause had MFA enabled in some form at the time of the attack. Coverage gaps are where the damage happens. The Active Adversary Report saw the same pattern: SaaS accounts often had MFA, but VPNs, firewall admin consoles, and legacy apps did not.

Where ransomware attacks start

For the first time, this year’s report maps where respondents say their initial compromises happened inside their IT environments. Across attacks that started with an exploited vulnerability, compromised credentials, or brute force, these were the locations where victims reported that the attacks started:

  • Exposed applications and systems: 38%
  • User devices: 30%
  • Firewalls: 21%
  • VPNs: 8%
  • IoT devices: 3%

Firewall compromises carry outsized financial impact because the firewall sits in a privileged position across the organization’s infrastructure. When attackers successfully exploit a vulnerability on the firewall, they often gain extensive access across the business, and the resulting ransom demands reflect that leverage.

When ransomware attacks start with the exploitation of a vulnerability in the firewall, 59% of those demands are for $1 million or more. That’s more than the baseline 48% $1-million-plus demands across all attacks.

Things are getting better, but ransomware is still devastating

Some economics moved in defenders’ favor this year, but the picture is mixed. Having data encrypted in a ransomware attack reamins a serious event.

The good news:

  • Median ransom demand: $698,000, down 65% over two years.
  • Median ransom payment: $769,000, down from $1 million last year.
  • 51% of paying organizations negotiated a lower amount than the demand.
  • Only 32% of retail organizations paid, the lowest of any sector.
  • Backup-based recovery jumped to 66% of encrypted-data cases, up 12 percentage points from 2025.

The bad news:

  • Average recovery cost: $1.7 million per incident, up 11% year over year.
  • 56% of attacks still succeeded in encrypting data, up from 50% last year.
  • 48% of encrypted victims paid the ransom, in line with the four-year average of roughly 50%.
  • 72% of local and state government organizations paid, the highest of any sector.
  • The UK saw the highest median ransom demand recorded for any country at $2.5 million.

The organization-size gap is stark: only 34% of small organizations (100–250 employees) stopped attacks before encryption or extortion, well behind the 46% success rate at 3,001–5,000 employee organizations. Scale is buying real defensive outcomes, and small businesses are carrying a disproportionate share of the damage.

Read the report

The 2026 data points to a consistent theme across sections: outcomes improve when identity, email, endpoint, and network defenses operate as one system rather than in isolation. Closing the gap on AI-era attacks will depend less on adding tools and more on connecting the ones already in place.

Download the report to get the full findings, industry breakdowns, and recommendations.

Source: Sophos

20

Jul

When frontier AI models crossed a new capability threshold towards the end of last year – developing the kind of ability that lets nearly any adversary generate working exploit code, craft convincing social engineering at scale, and chain attacks that cross security product boundaries autonomously – the threat landscape didn’t just evolve. It accelerated into a different category entirely.

The speed, scale, and scope of attacks all shifted in the adversary’s favor simultaneously. Intrusions that used to unfold over days and hours now play out in minutes and seconds. The multi-stage campaigns that once required nation-state resources are now accessible to almost anyone. And every AI agent, every automated workflow an organization adopts to become more productive, quietly gifted adversaries a new attack surface at the same time.

I’ve been watching this unfold and thinking hard about how to respond to it. And I keep arriving at the same conclusion: the defense most organizations rely on today was built for a different threat. Not just an older one. A structurally different one.

When attacks move at machine speed, the organizations that thrive aren’t the ones with the most products. They’re the ones whose defense gets smarter every time it encounters a threat, and passes that intelligence to every other customer in the system.

The stack problem

For 40 years, the cybersecurity industry had a reliable playbook: every new threat category became a new product. New threat, new tool. New gap, new vendor. The result? The average enterprise today manages more than 45 separate security products.1

The problem with that number isn’t the cost and complexity, though that’s real too. It’s what happens to intelligence when it’s fragmented across 45 silos. The endpoint doesn’t know what the firewall saw. The email gateway doesn’t tell the identity layer what it caught. Every tool learns alone. Nothing builds on what came before.

When attacks move at machine speed and execute across endpoint, cloud, identity, network and email in one coordinated push, a defense that correlates those signals manually – if it correlates them at all – isn’t a defense. It’s a very expensive post-mortem.

The stack model assumes a human analyst can connect the dots across those 45 tools fast enough to matter. In the old world, built on a slower and structurally different threat, that approach was serviceable. It isn’t tenable anymore.

SIEM and XDR were the right instincts

Give the industry credit. It didn’t just name the fragmentation problem; it built two technologies to solve it: SIEM and XDR. SIEM set out to pull every log into one place. The first wave of XDR set out to correlate detections across tools.

Both were the right instinct. Both are real capabilities. In fact, both are essential components of a defense system, and Sophos delivers them today. But here is what a decade of deployment made clear: neither one alone, nor both together, reaches the capability set the moment now demands.

SIEM aggregates data after the fact. It collects logs from products that are still strangers to each other, then asks an analyst to make sense of the pile. Early XDR correlated alerts, but only across the tools a single vendor happened to own, and only after each tool had already decided, alone, what mattered. Aggregation is not architecture. Pulling data into a shared window does not make the sources aware of each other, and it does not let them act as one.

A defense system is different in kind, not degree. SIEM and XDR live inside it as capabilities, not as the ceiling of what the system can do. The control points share one data layer from the moment a signal is born, not after it lands in a warehouse. They inform each other’s decisions in real time, not in a report an analyst reads later. That is the line between collecting intelligence and operating on it. SIEM and XDR collect and correlate. The defense system acts.

The real capability gap

With ~359 million businesses in the world, fewer than 35,000 have a CISO or security leader in place. 35,000 have a CISO. That ratio — one CISO for every 10,000 organizations — is at the heart of why the industry has failed to keep pace with the threat.

The cybersecurity poverty line is what happens when organizations can’t convert their security technology into functional defense. It’s not defined by size or budget alone. I’ve seen well-funded organizations sitting well below it, and 200-person regional companies running well above it.

It’s defined by strategic capability: the ability to set up controls correctly, monitor them continuously, measure whether they’re working, and improve over time.

AI made that gap both more dangerous and, for the first time, genuinely closable. More dangerous because attackers adopted it instantly, an immediate, free upgrade. Closable because the same AI capabilities that accelerate attacks can also accelerate defense if it’s built as part of the architecture and not bolted on as a feature.

Introducing Sophos Fusion

Today, we’re announcing Sophos Fusion, the industry’s most complete AI-native cybersecurity defense system.

Sophos Fusion is the evolution of what in the industry we’ve called Platforms. It’s a single, open architecture where every control point — endpoint, firewall, email, cloud, network, identity, and security operations, and more — shares the same data, the same intelligence, and responds as one.

What makes that different from the platforms our competitors sell is the architecture underneath:

  • A unified context lake, where every signal from every control point flows into one shared data layer in real time. No aggregation delay. No silo. The entire system sees what any individual part sees.
  • Synchronized Security™ is the connective tissue that transforms shared insights into coordinated response. A detection at the endpoint triggers a coordinated response at the firewall, a compromised identity locks down access across the environment, and a suspicious email raises the scrutiny level everywhere else. Detection anywhere, response everywhere.
  • Agentic autonomy with human judgment. The system can detect, investigate, and respond without waiting for a human, operating inside boundaries that our MDR analysts set and continuously calibrate. This isn’t automation replacing human ownership. It’s AI reasoning about novel situations, with humans governing the trust boundary.
  • Compounding intelligence. Every threat seen across more than 625,000 defended organizations by Sophos feeds back into the system. A new customer doesn’t start from zero; they inherit the benefit of every threat the system has ever seen.
  • We’re also clear about what it isn’t: a closed system. More than 500 third-party integrations feed the same shared data layer. Threat telemetry from a customer’s existing endpoint, firewall, or identity tools from a vast number of vendors flows into the same context lake as the insights from their Sophos solutions, the same correlation engine, and the same MDR team. Native where it matters. Open where the customer needs it to be.

The evolution of Sophos Central

Sophos Fusion is the evolution of Sophos Central, rearchitected for the AI era. All Sophos customers are already part of Sophos Fusion and already benefit from unmatched protection from threats that move at machine speed. Over the coming months, users will see Sophos Central evolve to Sophos Fusion in the interface as we roll out the naming, with no action required of customers or partners.

Proof in our own operation

Sophos runs the world’s largest agentic SOC on Sophos Fusion. 52% of cases are handled entirely by AI, with no human required. The average time from alert to a fully automated response is 89 seconds. We’re not measuring MDR response time in minutes anymore. We’re measuring it in seconds.

The market is validating what we’ve built as well. In the G2 Summer 2026 reports — based entirely on verified customer reviews — Sophos ranked number one across endpoint, EDR, XDR, MDR, and firewall in a single season. No other vendor has done that across all five categories simultaneously.

Sophos is also the only vendor recognized as a Gartner® Peer Insights™ Customers’ Choice across Email Security, Endpoint Protection Platforms, Managed Detection and Response, Extended Detection and Response, and Network Firewalls. These recognitions reflect what matters most: customers consistently choosing Sophos to protect, detect, and respond across their entire cybersecurity environment.

What’s coming

Sophos Fusion is available now, and we’re expanding the system significantly over the coming months.

From mid-August we’ll release major enhancements to the Sophos MDR service, significant expansion of Sophos XDR powered by Secureworks Taegis analytics, and a new Next-Gen SIEM offering.

Sophos Next-Gen SIEM deserves particular attention: it’s priced by users and servers rather than data volume, which eliminates the perverse incentive that leads security teams to limit the telemetry they ingest and deliberately leave blind spots in their coverage or face runaway costs.

In October, two more capabilities arrive. Sophos AI Defense gives organizations visibility, control, and protection over every AI tool in their environment, including shadow AI, built on capabilities already inside the system. And Sophos CISO Advantage scales CISO-level guidance to every organization, with or without a CISO, delivering continuous control validation, compliance mapping, peer benchmarking, and executive-ready risk assessment. For the organizations below the poverty line that have never had access to that kind of strategic capability, it transforms what’s possible.

A defense that compounds

For decades, the industry told customers that more tools meant better security. The AI era exposed the lie of that assumption completely. The advantage belongs to organizations with a coordinated defense that sees every signal, learns from every threat, and responds as one.

That requires a fundamentally different architecture, one that the majority of leading cybersecurity providers have failed to construct in full.

Sophos Fusion is the architecture we spent years building toward. The AI era made it necessary. The work we’ve done, from our award-winning product capabilities to the Secureworks acquisition and the agentic SOC we run today, made it possible.

The stack had a good run. What comes next is a system.

Source: Sophos