Back to main siteBack Contact us
Solution Brief

Sophos Taegis

Managed Detection and Response

Taegis: enterprise-grade detection, now inside Sophos

Secureworks built its reputation on the Taegis extended detection and response platform and on the Counter Threat Unit, a research team that tracked well over a hundred and fifty threat groups. Sophos completed its acquisition of the company in February 2025, and both the platform and the research function now sit within the Sophos portfolio. This brief sets out what that capability does, what changed with the acquisition, and how to decide whether it fits.

VendorSophos Taegis, formerly Secureworks
CategoryManaged detection and response
Reading timeAbout four minutes
I

Executive summary

Extended detection and response is the practice of gathering security telemetry from endpoints, network, cloud and identity systems into one place, correlating it, and acting on what the correlation reveals. Taegis is the platform Secureworks built to do that, and the Counter Threat Unit is the research function that told the platform what to look for.

Those two assets are why the company was bought. Sophos acquired Secureworks for 859 million dollars, completing in February 2025, and folded the Counter Threat Unit into Sophos X-Ops, its own research organisation. Sophos already served smaller organisations with its own managed detection service; Taegis brought the larger, more complex estates.

Takeaway: the capability described here is real and continuing, but it is now purchased as part of Sophos rather than from an independent vendor.

II

Why current controls miss what this catches

Most organisations own several security products that each see one slice of the estate. The endpoint agent watches processes. The firewall watches traffic. The identity provider watches logins. Each is competent within its own boundary and blind immediately outside it.

Serious intrusions are usually unremarkable within any single boundary. An administrator logging in is normal. A file archive being created is normal. Data leaving the network is normal. The three together, in that order, within ten minutes, at two in the morning, is an exfiltration, and no single product is positioned to notice.

Correlation across sources is what turns those separately ordinary events into one recognisable pattern. It requires collecting from every layer, resolving which records describe the same machine and the same person, and ordering everything onto one timeline.

That work is unglamorous and it is the entire basis of the category. A product that only aggregates alerts into a single console has not done it; it has merely moved the problem into one window.

Takeaway: the gap is not detection sensitivity, it is the absence of anything that looks across boundaries.

III

The approach

Taegis ingests telemetry across endpoint, network, cloud and identity, applies analytics to the combined stream, and presents investigations rather than raw alerts. Delivered as a managed service, the investigation is carried out by the provider's analysts, and the customer receives findings with recommended action.

The Counter Threat Unit supplied the intelligence behind those analytics. Its remit was tracking named threat groups, publishing research including an annual threat report, and issuing daily intelligence updates that informed detection logic. That function now operates within Sophos X-Ops.

IDENTITY ENDPOINT NETWORK login 02:11 archive 02:14 transfer 02:19 ONE INCIDENT, NOT THREE
Exhibit A. Three events, each unremarkable in its own system, resolved onto a single timeline.

Takeaway: the platform supplies the correlation, and the research function supplies the judgement about what matters.

IV

Evidence and current status

ItemPosition as of this brief
Corporate statusAcquired by Sophos, completed February 2025
Consideration859 million dollars
Taegis platformContinues within the Sophos portfolio
Counter Threat UnitNow part of Sophos X-Ops
Threat groups tracked by CTUMore than 150, per published material
Brand presenceSecureworks web presence now directs to Sophos

Key findings

  • The technical capability is intact and continuing under new ownership.
  • Procurement, contracting and support now run through Sophos.
  • Buyers evaluating Sophos endpoint products and this service are evaluating one vendor, not two, which affects both negotiation and concentration risk.
  • Anyone holding an existing Secureworks contract should confirm renewal terms against the combined portfolio rather than assuming continuity.

Takeaway: treat this as a Sophos purchasing decision, because that is what it now is.

V

Recommendation

For estates with genuine complexity, multiple sites, mixed cloud platforms, a substantial identity footprint, the correlation capability is worth buying rather than building. Assembling it internally means a platform, a research function and a staffed operations centre, and the research function is the part nobody can hire quickly.

For a smaller, simpler estate, the enterprise-oriented platform may be more than the situation requires, and the lighter managed service in the same portfolio is likely the better starting point. That is a scoping conversation, not a product debate.

One point deserves weight in either case. Consolidating detection, response and endpoint protection with a single vendor simplifies operations and strengthens the commercial position, but it also concentrates dependency. That is a legitimate trade, and it should be made deliberately rather than by drift.

Takeaway: decide the scope of the estate first; the product tier follows from it.

Next steps

Schedule the readout

A short session covering which telemetry sources exist today, which are correlated, and where the current portfolio leaves the estate exposed.

Schedule the readout

Get in touch with Your Company

Questions about this solution? Reach us directly.