Sophos Taegis
Taegis: enterprise-grade detection, now inside Sophos
Secureworks built its reputation on the Taegis extended detection and response platform and on the Counter Threat Unit, a research team that tracked well over a hundred and fifty threat groups. Sophos completed its acquisition of the company in February 2025, and both the platform and the research function now sit within the Sophos portfolio. This brief sets out what that capability does, what changed with the acquisition, and how to decide whether it fits.
Executive summary
Extended detection and response is the practice of gathering security telemetry from endpoints, network, cloud and identity systems into one place, correlating it, and acting on what the correlation reveals. Taegis is the platform Secureworks built to do that, and the Counter Threat Unit is the research function that told the platform what to look for.
Those two assets are why the company was bought. Sophos acquired Secureworks for 859 million dollars, completing in February 2025, and folded the Counter Threat Unit into Sophos X-Ops, its own research organisation. Sophos already served smaller organisations with its own managed detection service; Taegis brought the larger, more complex estates.
Takeaway: the capability described here is real and continuing, but it is now purchased as part of Sophos rather than from an independent vendor.
Why current controls miss what this catches
Most organisations own several security products that each see one slice of the estate. The endpoint agent watches processes. The firewall watches traffic. The identity provider watches logins. Each is competent within its own boundary and blind immediately outside it.
Serious intrusions are usually unremarkable within any single boundary. An administrator logging in is normal. A file archive being created is normal. Data leaving the network is normal. The three together, in that order, within ten minutes, at two in the morning, is an exfiltration, and no single product is positioned to notice.
Correlation across sources is what turns those separately ordinary events into one recognisable pattern. It requires collecting from every layer, resolving which records describe the same machine and the same person, and ordering everything onto one timeline.
That work is unglamorous and it is the entire basis of the category. A product that only aggregates alerts into a single console has not done it; it has merely moved the problem into one window.
Takeaway: the gap is not detection sensitivity, it is the absence of anything that looks across boundaries.
The approach
Taegis ingests telemetry across endpoint, network, cloud and identity, applies analytics to the combined stream, and presents investigations rather than raw alerts. Delivered as a managed service, the investigation is carried out by the provider's analysts, and the customer receives findings with recommended action.
The Counter Threat Unit supplied the intelligence behind those analytics. Its remit was tracking named threat groups, publishing research including an annual threat report, and issuing daily intelligence updates that informed detection logic. That function now operates within Sophos X-Ops.
Takeaway: the platform supplies the correlation, and the research function supplies the judgement about what matters.
Evidence and current status
| Item | Position as of this brief |
|---|---|
| Corporate status | Acquired by Sophos, completed February 2025 |
| Consideration | 859 million dollars |
| Taegis platform | Continues within the Sophos portfolio |
| Counter Threat Unit | Now part of Sophos X-Ops |
| Threat groups tracked by CTU | More than 150, per published material |
| Brand presence | Secureworks web presence now directs to Sophos |
Key findings
- The technical capability is intact and continuing under new ownership.
- Procurement, contracting and support now run through Sophos.
- Buyers evaluating Sophos endpoint products and this service are evaluating one vendor, not two, which affects both negotiation and concentration risk.
- Anyone holding an existing Secureworks contract should confirm renewal terms against the combined portfolio rather than assuming continuity.
Takeaway: treat this as a Sophos purchasing decision, because that is what it now is.
Recommendation
For estates with genuine complexity, multiple sites, mixed cloud platforms, a substantial identity footprint, the correlation capability is worth buying rather than building. Assembling it internally means a platform, a research function and a staffed operations centre, and the research function is the part nobody can hire quickly.
For a smaller, simpler estate, the enterprise-oriented platform may be more than the situation requires, and the lighter managed service in the same portfolio is likely the better starting point. That is a scoping conversation, not a product debate.
One point deserves weight in either case. Consolidating detection, response and endpoint protection with a single vendor simplifies operations and strengthens the commercial position, but it also concentrates dependency. That is a legitimate trade, and it should be made deliberately rather than by drift.
Takeaway: decide the scope of the estate first; the product tier follows from it.
Schedule the readout
A short session covering which telemetry sources exist today, which are correlated, and where the current portfolio leaves the estate exposed.
Schedule the readoutGet in touch with Your Company
Questions about this solution? Reach us directly.