Alle leveranciers

Vendor lineage

Sophos

Started in Oxford the year before the first PC virus spread, and is still here under its own name.

Jan Hruska and Peter Lammer founded Sophos at Oxford in September 1985, writing virus detection for the IBM PC before most people had encountered a virus. The name is the Greek for wisdom, chosen to signal a research-led posture rather than a product one.

The early business was deliberately narrow: corporate and educational customers in Britain and Europe, largely self-funded, at a time when antivirus was a cottage industry of individual researchers trading samples. By the early 1990s it was protecting thousands of enterprise endpoints.

It expanded into encryption, then into unified threat management, and became one of the few security vendors whose product line spans endpoint and network without either half having been bought in late.

Sophos listed on the London Stock Exchange in 2015 and was taken private by Thoma Bravo in 2020 - the same firm that appears elsewhere on this timeline holding LANDESK before Ivanti, and Ping Identity before ForgeRock. It has since acquired Secureworks.

What makes it notable here is longevity of a specific kind. Almost every company on this page that started in the 1980s has ended inside another one. Sophos is forty years old, privately held, and still trading under the name its founders chose.

Founding stories

1985

Sophos

Oxford, England · Founders: Jan Hruska, Peter Lammer

Founded in September, writing virus detection for the IBM PC before most people had met a virus - the first PC virus spread the following year. The name is Greek for wisdom. Forty years later the company is still headquartered in the same city, which almost none of its contemporaries can say.

The timeline

  1. Founded in Oxford

    Two founders, largely self-funded, selling to corporate and educational customers in Britain and Europe.

  2. Apax takes a majority stake

    The first outside control after twenty-five years of independence.

  3. London Stock Exchange listing

    Listed in London rather than New York, which is itself unusual for a security company of that size.

  4. Taken private by Thoma Bravo

    After five years as a public company.

  5. Secureworks

    Completed 3 February, all cash at approximately $859M, taking Secureworks off NASDAQ. It brought the Taegis platform and the Counter Threat Unit, a research team tracking more than 150 threat groups, and made Sophos the largest pure-play provider of managed detection and response.

  6. Sixteen consecutive leader placements

    Named a Gartner Magic Quadrant Leader for endpoint protection for the sixteenth evaluation running - a span covering the entire transition from signature scanning to behavioural detection to managed response.

Flagship products and solutions

  • Sophos Endpoint and Intercept XThe core protection product, with the anti-ransomware and exploit prevention work that became its distinguishing capability.
  • Sophos MDRManaged detection and response, now the largest part of the proposition and the reason the Secureworks purchase made sense.
  • TaegisThe Secureworks platform, retained rather than absorbed - and since September 2025 shipping with Sophos Endpoint included at no extra cost, which is an unusually direct way to demonstrate that an acquisition benefits existing customers.
  • Sophos Firewall, Switch, Email and ZTNANetwork and access products managed from the same console. The breadth is aimed squarely at organisations with one person doing all of security.
  • Sophos X-OpsThe combined research organisation - threat intelligence, malware analysis and offensive research published openly, now joined by the Counter Threat Unit.

Key innovations

  • Serving the organisation without a security teamThe mid-market has always been the harder problem: the same threats as an enterprise, none of the staff. A single console covering endpoint, firewall, email and access is a product decision derived from that constraint rather than from a feature matrix.
  • Ransomware behaviour rather than ransomware signaturesDetecting the act of mass file encryption and rolling it back addresses the one failure mode where detection after the fact is worthless. It is a good illustration of behaviour-based defence solving something signatures structurally cannot.
  • Managed response as the product, not the upsellSelling the analysts rather than only the software follows from the same customer: an alert that nobody is awake to read is not a defence. Buying the largest independent provider of that service made it the centre of the business.
  • Keeping the acquired platformTaegis was kept and extended rather than shut down, with the acquirer's endpoint product added to it free. Acquisitions in this industry more often end with the smaller platform quietly retired.

Main markets

More than 600,000 customers, weighted toward small and mid-sized organisations and served largely through partners and managed service providers rather than direct - a distribution model that suits the customer size and is hard to build late.

It competes with the endpoint platform vendors above it and the operating-system-bundled products below it, and increasingly on managed services, where the competition is as much other providers' analysts as other vendors' software.

Analyst standing

  • Sixteen consecutive Gartner Magic Quadrant Leader placements in endpoint protection, which is among the longest unbroken runs in the category and the clearest evidence for the longevity the entry above describes.
  • Its independent detection results are consistently strong, and its distinguishing assessment is usually not raw detection but the combination of protection and managed response sold at a price the mid-market can carry.