Sophos Fusion Aims To Replace Security Tool Sprawl With One AI System

The average enterprise now runs more than 45 separate security products, according to a Gartner estimate Sophos cited when it introduced Sophos Fusion in July. That sprawl means more dashboards and manual correlation work for security teams already outnumbered by the threats they’re chasing.

Sophos’s answer is Fusion, what the company calls an AI-native cybersecurity defense system, built on Sophos Central and folded together with the Taegis analytics platform it picked up when it acquired Secureworks last year.

What Sophos Says Fusion Actually Does

Every signal from every control point, whether it’s a Sophos product or one of the more than 500 third-party tools Sophos says it integrates with, flows into a single shared data layer in real time. When something is detected at one control point, the system triggers a coordinated response across the others through Synchronized Security, without waiting for an analyst to stitch the alerts together by hand. The AI investigates and acts inside limits human analysts set and adjust, rather than operating unsupervised. Most vendors have bolted similar ideas onto existing product lines one piece at a time; Sophos says Fusion was rebuilt as one architecture from the ground up instead.

Sophos’s own State of Ransomware 2026 report, released in July, found that 79 percent of ransomware attacks now start with a compromised identity rather than an exploited vulnerability. Sophos CISO Ross McKerchar wrote that multi-factor authentication alone isn’t enough to stop those attacks, and that prevention, detection, and response need to work as one strategy instead of separate tools reacting on their own schedules.

Sophos says Fusion already runs its own security operations center, defending more than 40,000 customers. AI resolves 52 percent of those cases on its own, and the average time from alert to a fully automated response is 89 seconds.

New Pieces Rolling Out Through October

Sophos is adding several capabilities to Fusion between August and October. Next-Gen SIEM, priced by users and servers instead of data volume, goes generally available August 15, alongside an expanded managed detection and response offering and an XDR product rebuilt on the Taegis analytics engine. AI Defense, aimed at giving companies visibility into the AI tools employees already use, including the ones nobody approved, moves to early access in August and general availability in October.

Sophos’s own AI Security 2026 report, drawn from the same customer base, found the credential layer around enterprise AI services has become a harvesting target of its own, and that AI so far is mostly compressing familiar attack steps rather than inventing new ones.

CISO Advantage, which bundles continuous control validation, compliance mapping, and peer benchmarking, arrives in October for companies too small to have a dedicated security chief. I spoke with Sophos CEO Joe Levy at RSA Conference earlier this year, months before any of this had a name, and CISO Advantage was already what he wanted to talk about most. He called it “the fundamental solution to a 40-year-old model failure,” and said it was the single most important thing Sophos had to work on.

Whether “cybersecurity defense system” becomes an actual product category or just a new label for consolidation remains open, and Sophos is far from the only company arguing that agentic AI and unified data solve tool sprawl. The real test won’t be the launch announcement. It’ll be whether the 500-plus integrations hold up in practice, and whether the automation numbers translate to environments that look nothing like Sophos’s own SOC. Smaller organizations leaning on CISO Advantage need real leadership out of it, not just another dashboard with a new name on it.

Why Sophos Is Making This Argument Now

Gartner distinguished analyst Neil MacDonald has warned that simply layering more tools onto a security stack won’t produce the connected defense organizations need against AI-orchestrated attacks, and he pointed directly to the campaign Anthropic disclosed last November, when a Chinese state-sponsored group used Anthropic’s own Claude Code tool to automate most of an espionage operation against roughly 30 organizations with almost no human involvement. That incident has become a reference point for how fast an AI-assisted attack can move once it gets past the first layer of defense.

Futurum Group projects the broader security operations category will roughly double from $18 billion to $37 billion by 2029, faster growth than any other part of cybersecurity, according to Futurum vice president Fernando Montenegro. Levy made a related point when we talked at RSAC 2026. He argued every frontier AI lab is already fighting off attackers trying to abuse their own platforms, Anthropic included, and that no amount of guardrail engineering fully closes the gap between what a model is instructed to do and what it can be tricked into doing. “You can’t sanitize your way out of this problem,” he told me.

Tony Bradley: I have a passion for technology and gadgets and a desire to help others understand how technology can affect or improve their lives. I also love spending time with my wife, 7 kids, 3 dogs, 5 cats, a pot-bellied pig, and sulcata tortoise, and I like to think I enjoy reading and golf even though I never find time for either. You can contact me directly at tony@xpective.net. For more from me, you can follow me on Threads, Facebook, Instagram and LinkedIn.
Related Post