Sophos - Experts & Thought Leaders

Latest Sophos news & announcements

SE Labs' PIVOT Testing: A New Era In Cybersecurity

A wave of cybersecurity firms have abandoned the Department of Defense-backed MITRE test as major companies join independent cyber testing program PIVOT, run by British company SE Labs.  Participants in MITRE Engenuity ATT&CK Evaluations plummeted from 30 to just 11 last year. Meanwhile, CrowdStrike, Palo Alto Networks and Broadcom are among the participants confirmed for PIVOT, a 6-month testing program by SE Labs evaluating how effectively vendors can defend against the world’s most dangerous hacking groups and attack techniques. Testing critical cyber solutions  “It’s a landmark moment for British cyber security, as the world’s biggest and best organizations choose to test their critical cyber solutions in the UK rather than in the US,” said Simon Edwards, CEO of SE Labs. “There are now very few tier-one vendors that aren’t testing within PIVOT.” “The requirements for cyber security have completely changed. There are autonomous AI agent attacks, such as those that affected Hugging Face, while the sheer economic scale of the JLR incident influenced the UK economy. Businesses need to know which solutions actually protect them against nation-state attacks, major ransomware campaigns and machine-speed threats, and that demands rigorous testing of defences.” PIVOT testing The PIVOT testing will see teams of trained ethical hackers from SE Labs impersonate nation-state cyber groups and other hacking circles responsible for the most disruptive cyber breaches in recent years, replicating attack types across ransomware, malware, phishing and beyond to stress test vendor solutions on their ability to detect threats from known attack groups and protect against them. Authority insights Adam Bromwich, Vice President of Engineering and CTO, Enterprise Security Group at Broadcom, said: "CISOs today need clarity and proof, not just promises. PIVOT emphasises full transparency and inclusion of major analyst firms to set a new standard for trust. For us isn't just about a score; it's about demonstrating Symantec and Carbon Blacks' real-world efficacy in an open, verifiable way that empowers customers to make confident security investments." Simon Reed, Chief Research and Scientific Officer (CRSO) at Sophos, said: “SE Labs’ PIVOT brings clarity to endpoint testing. It highlights who’s genuinely preventing and detecting threats, not just tuning for test conditions. As cybersecurity focuses increasingly on prevention and resilience for real-world protection, this independent assessment is critical to retain trust.”  Independent scrutiny on test results The data from testing is shared with analyst firms for independent scrutiny ahead of publication to help vendors identify gaps in their security solutions and support product development against ongoing threat groups and attack types. The test portion of the program runs from July to October, with the final report released in January 2027. It comes amid the development of the Cyber Security & Resilience Bill, which will mandate designated essential services and digital service providers to report incidents within 24 hours to the regulator and NCSC and a full report within 72 hours, widen regulatory scope, and promote cross-border information sharing with EU authorities under NIS2.

Espria Optimise IT: Boosting Business With IT Solutions

Digital workplace solutions and managed services pioneer Espria returns in December with another Optimise IT exhibition, pioneering the discussion on how IT solutions can best work together to provide the ultimate support for businesses and end-user experience.  Post-COVID, Espria hosted a series of Optimise IT webinar discussions, covering themes such as business peace of mind, business readiness and AI integrations for workplace teams. These discussions have featured key spokespeople from some of their pioneering IT solutions partners and provided industry pioneers with a platform to network directly with key decision-makers who are looking for increasingly efficient ways to deliver their IT strategy. Event feature representatives This year’s in-person event will feature representatives from premier vendor partners Gamma, Microsoft (hardware and software), Sophos and Omada by TP-Link, with more vendors to be confirmed. Marketing and Business Strategist, Bryony Thomas, will be giving a keynote speech during the lunch, sharing lessons in preparation, prioritization and attention to detail and how missing these can be catastrophic. The event will be held from 9 am to 2 pm on 3rd December at the Down Hall Hotel, Matching Lane, Hatfield Heath, Bishop’s Stortford. Attendance is free but subject to prior registration on the Espria website. Cybersecurity alliance partnerships Stephen Cook, Sales Director at Espria, commented, “Turning to 2026, cybersecurity has entered a transformative phase, with the cyberthreat landscape accelerating in complexity and scale. Businesses that adopt intelligent monitoring and integrated, adaptive defense strategies will be best positioned to navigate 2026 with confidence.” “Similarly, customer trust is entirely defined by uncompromising data security in today’s environment. Where AI has been rapidly adopted into operations, it has simultaneously amplified the quantity and quality of cyberattacks, creating this paradox for security." "Espria has always prioritized our cybersecurity alliance partnerships as a critical solution for today’s security landscape, especially with the proliferation of AI-boosted attacks, which is why bringing experts such as Micrsoft and Sophos to the table is a key part of building a lasting strategy for SMEs from our previous Optimise events.” Commitment to cyber hygiene and defense practices Cook added: “Peace of mind with data security has always been a part of this and requires a continuous commitment to cyber hygiene and defense practices from experts and clients alike. It’s not just about the most high-technology solutions, but the ones that work best within businesses and align with existing operations seamlessly." "Our mission is to lead the conversation for enterprises of all sizes to navigate their modern technology needs, and that ensures any technology introduced, particularly AI tools, provides a strategic boost without hindering operations or opening up wider attack surfaces."  Comprehensive security strategies Cook concludes, “Educating our customer businesses who may be neglecting their endpoint security is an essential way to show security support. We’ve seen that customers, particularly smaller businesses with limited cyber skills or expert access, need that guidance when it comes to network security." "Thankfully, we can provide those skills and in this instance the forum for expert minds to collaborate, providing those all-comprehensive security strategies needed to tackle the cyber threats of today and tomorrow.”

Prevent Cyberattacks With Sophos Security Services

Sophos, a pioneer of innovative security solutions for defeating cyberattacks, announces the launch of Sophos Advisory Services, a suite of security testing services designed to identify gaps in organizations’ security programs. These offerings – External Penetration Testing, Internal Penetration Testing, Wireless Network Penetration Testing, and Web Application Security Assessment – help fortify an organization’s defenses against cyberattacks and optimize their current security investments. Demonstrating regulatory compliance Regardless of an organization’s size or security maturity, assessing cybersecurity posture is critical to staying ahead of threat actors, demonstrating regulatory compliance, and building trust with customers, partners, and stakeholders. The Sophos State of Ransomware 2025 report highlights that the number one root cause for ransomware attacks is exploited vulnerabilities, and 65% of organizations reported a known or unknown security gap as a reason for being exposed to a ransomware attack. “Adversaries are increasingly skilled at exploiting the smallest cracks in an organization’s security program. With Sophos Advisory Services, we give customers a proactive advantage - helping them find and fix weaknesses before attackers can exploit them. Backed by real-time insights from Sophos X-Ops threat intelligence, our experts enable organizations to strengthen resilience, meet compliance requirements, and build lasting trust with stakeholders,” Jake Dorval, Senior Director, Sophos Advisory Services. Incident response engagements The following services — informed with leading threat intelligence research and insights from Sophos X-Ops, along with findings from threat hunting and incident response engagements — are now available: External Penetration Testing: Simulates an attacker trying to breach the perimeter from the outside. Internal Penetration Testing: Simulates an insider threat or an attacker who has already breached the perimeter, focusing on systems, applications, and data within the internal network. Wireless Network Penetration Testing: Assesses the security of an organization's Wi-Fi networks and infrastructure and evaluates their compliance with appropriate mandates. Web Application Security Assessment: Tests an organization’s web applications for security vulnerabilities and design weaknesses. Neutralisation of active threats Sophos Emergency Incident Response provides rapid identification and neutralisation of active threats Sophos Advisory Services are delivered by dedicated testers with vast cross-discipline security expertise spanning security research, threat intelligence, law enforcement, military and other backgrounds who joined Sophos through the recent acquisition of Secureworks.  The team holds hundreds of security certifications, has earned top finishes in capture the flag competitions, and is supported by Sophos X-Ops security analysts, threat intelligence and research specialists. Sophos will release additional Advisory Services in the coming months. Sophos Advisory Services are the latest addition to Sophos’ fast-growing security services portfolio that also includes Sophos Emergency Incident Response. Converging incident response expertise from Sophos and Secureworks in a single, hourly-billing offering, Sophos Emergency Incident Response provides rapid identification and neutralisation of active threats and is available to any organization experiencing a live incident.