Sophos bets against the market on Fusion, the AI-native defence system built to stop short of full autonomy
Sophos has launched Sophos Fusion, an AI-native cybersecurity defence system that unifies security operations, endpoint, network security, identity, email, and cloud into one architecture, and the argument holding it together is not that AI does more but that AI is not trusted to do everything.
Unveiled on Wednesday, Fusion is the evolution of Sophos Central, the console 625,000 organisations worldwide already use every day, now rebuilt on one open architecture incorporating Secureworks Taegis analytics following the $859 million acquisition Sophos completed in February 2025. In a market where the prevailing direction of travel is toward security that acts on its own, Sophos has chosen to make the limits of autonomy its selling point.
Joe Levy, Chief Executive Officer at Sophos, set the problem in terms of a market that spends heavily and defends poorly. “There have never been more tools or more vendors, more dashboards, and yet breaches keep rising in frequency and in cost,” he said, describing a condition he called an “AI-enhanced market for lemons, where the information gap between vendors and buyers only widens as the technology gets more complex.”
The world spends about $240 billion a year on cybersecurity, close to a quarter of a trillion dollars, and Gartner research, Levy cited, puts the average enterprise at more than 45 discrete security tools, most of which do not integrate well with one another. More money spent in his account has not reliably bought better outcomes.
Where a human stays accountable
The discipline that separates Sophos’s system from the market’s drift toward autonomy is where a human stays responsible, and Rob Harrison, SVP Product Management at Sophos, made it the centre of the case. “We believe the future of cybersecurity is not fully autonomous AI,” he said. “It is systems where AI provides speed and scale while humans remain accountable for outcomes.” The proof point is the split in Sophos’s own security operations centre, which the company says is the world’s largest agentic SOC, serving over 40,000 customers: 52% of cases are resolved end to end by AI and the remaining 48% are closed by a person, a ratio offered not as a way station on the road to full automation but as the intended shape of the system.
Harrison’s more distinctive claim was that the accountability boundary is not a fixed setting but a moving one, calibrated to the risk an AI agent is carrying at any moment. “Managing agent access/privilege is becoming the defining challenge of the agentic AI era,” he said, with an approach “grounded in the principle that AI should operate within clearly defined boundaries and that accountability remains with humans.” Sophos designs systems, he said, “so AI can act independently where the task is well understood and the risk is manageable, while human experts remain responsible for governance, calibration, oversight, and exception handling.” The risk profile shifts through a session.
“An agent session is at higher risk for data loss after it loads privileged data,” he said. “An agent that has processed untrusted input, reading an email or browsing a website, is more likely to have been subverted by prompt injection,” and those signals “can be used to dynamically adjust and monitor agent sessions throughout their lifecycle.” It is a description of autonomy that tightens automatically as an agent becomes more dangerous, a materially different proposition from a system that grants a fixed level of trust and leaves it there. That openness runs through the architecture as well, he added, with the system “designed to integrate with hundreds of third-party technologies,” more than 500 of them already feeding one shared data layer.
What the boundary looks like when an attack is running
Raja Patel, who took the audience through the expanded portfolio, put the practical test of a system in a single question, and it is a question about coordinated machine response rather than autonomy for its own sake. “Does a detection at one control point automatically trigger a response at the identity layer, the firewall, and the endpoint in real time, without anyone configuring it?” he said. “If the answer is no, they have a stack. We just watched a system.” The system he referred to was a scripted demonstration in which an attacker opened with an AI-assisted phishing lure on a legitimate host, walked past the email filters, and stole not just a password but the live session token to bypass multifactor authentication, before creating “a quiet inbox rule that hides one’s supplier’s emails,” the setup for wire fraud.
Six control points fed the demonstration, three of them Sophos and three third-party, including Microsoft Entra and Microsoft Graph, all feeding one shared data lake. “No single alert tells the story,” the walkthrough ran. “The attack is only visible when you see all of it in one place, at one time.” The agentic SOC blocked the sign-in, revoked the session, isolated the endpoint, and blocked the malicious addresses at the Sophos firewall, in 89 seconds. Then the boundary appeared. Automation stopped the access, and a person closed the case, with the analyst confirming that the inbox rule named a specific supplier. “That is intent. That is proof. This is the other 48%. A.I. handles the volume. Humans own the judgment.” Patel said the machine-speed half of that equation is what most of the market cannot match, since in his account no rival offers the full native span of “email, firewall, cloud, identity, endpoint, XDR, MDR,” feeding a single context in real time.
Completing Secureworks, and the channel play built on the same principle
Fusion also closes out the Secureworks integration, which Levy said was never about shelf space. “We didn’t acquire secure works to add another product to the shelf,” he said. “We acquired them to bring two leaders and leading architectures together,” fusing “the depth of Secure Works tagious, with the reach of Sepho Central, into a unified system. Not two products bolted together.” The company is expanding Fusion with capabilities reaching general availability between August and October 2026: Sophos XDR, powered by Secureworks, rebuilt on Taegis analytics with thousands of additional detectors and built-in SOAR automation; a next-generation SIEM on the same data lake, priced by users and servers rather than data volume to avoid runaway costs; Sophos AI Defense, securing the AI customers are themselves adopting including shadow AI; and an expanded Sophos MDR with continuous AI-enabled threat hunting fed by the X-Ops research team.
The capability that carries the accountability argument furthest into the business is Sophos CISO Advantage, which takes senior security judgment and, delivered through managed service providers, scales it to organisations that may have no CISO at all. Asked which services partners would be most able to monetise over the next 12 to 18 months, Patel named them without hesitation.
“I believe that CSO advantage will be the biggest opportunity for our partner ecosystem,” he said, because it “takes our partner ecosystem and puts them as the strategic partners for those businesses, where they may or may not have a CSO today.” The effect, he said, is to move the conversation “from reactive to proactive,” letting a partner “walk into a customer environment, show them how they’re complying with a particular regulatory standard, show them where the gaps are, show them how they look relative to peer groups.” The scarcity is real: Sophos research put the number of organisations worldwide at roughly 359 million against fewer than 35,000 chief security officers, a ratio Levy said “works out to about one in 10,000” and one he described as a broader strategic capability gap. Senior human judgment is what the market cannot buy more of, and the system exists to extend its reach rather than replace it.
The threat data that makes the argument urgent
Rafe Pilling, who leads threat intelligence production at Sophos, supplied the evidence, previewing the annual State of Ransomware report drawn from 2,158 organisations across 17 countries that had each suffered a ransomware attack. Its central finding reshapes where defence has to start. “For the last three years, exploited vulnerabilities were consistently the number one entry point, Pilling said, “but this year, we can see, they’ve dropped 18%.” Malicious email now leads at 26% of attacks, phishing accounts for another 24%, and compromised credentials follow at 23%.
“Four out of five ransomware attacks, 79%, now begin with identity in one form or another,” he said, adding that 67% of victims told Sophos the ransomware incident was the same as their most significant identity attack, so identity “is no longer just part of the ransomware story. It is increasingly how ransom operators are gaining access in the first place.”
That data argues directly for coordinated defence. Pilling said the firewall detected signs of attack before the payload launched in 61% of cases, and that early identification roughly halved the rate of encryption, but “when the firewall saw nothing, that figure rose to 71%.” Firewall telemetry alone has value, he said, but “when it’s combined with endpoint, email, and identity signals through an XDR platform or managed service, organisations are significantly better positioned to stop attacks before encryption occurs.” Recovery costs averaged around $1.7 million, and 56% of attacks still ended in encryption, yet compared to two years ago, ransom demands were down 65% and payments down 62%, which Pilling read as organisations with stronger, more connected operations responding from a better position.
Sophos’s first dedicated study of AI cyberattacks, due Wednesday, concludes that AI is accelerating attacks more than inventing new ones. Pilling described a campaign tracked as STAC 6994 in which a threat actor ran what amounted to a software development operation against a victim, using around a dozen AI agents coordinated through a commercial coding assistant to test nearly 80 malware modules.
“The significance isn’t necessarily what they built. It’s the speed at which they built it,” he said, with weeks of work compressed into days. He set that intensification against Levy’s own reading of the threat landscape: that Sophos is not seeing new categories of attack from AI but “an increase in the scope, scale, and velocity of the same category of threats,” with prompt injection “fundamentally just a new manifestation of an insider threat, where the AI itself becomes the insider.” Whether the defence system endures as a category will owe something to validation Sophos does not control, with Gartner standing up a Magic Quadrant for integrated SOC systems expected in November, in which Sophos says it will feature.
Adoption is running well ahead of control, Pilling said, with AI itself now a target: hundreds of thousands of ChatGPT credentials are offered for sale in criminal marketplaces, while one industry study found 71% of large enterprises already running AI agents against core business systems and only 16% with governance controls in place. The market, on those numbers, is handing autonomy to AI far faster than it is deciding who remains accountable for what it does, which is the gap Sophos has built Fusion to occupy.