Security testing

backgroud-texture-bg-2

Penetration testing engagements

While we aim to identify and prevent security bugs in our software development pipeline, no system is perfect. That’s why we also run regular security assessments on our products. These assessments are typically performed in a white box scenario with access to architecture details and source code. Our approach results in more efficient and effective testing when compared to a black box scenario where little information about the product is provided.

For our recent assessments, we have started collecting and publishing letters of attestation. For the older assessments, we are happy to share details upon request. We aim to collect letters for subsequent/future tests as they are completed.

Assessment letters of attestation

SolutionProductDate of Last TestVendorLetter of Attestation
EndpointIntercept XOctober 2024MWR CyberSecLoA - MWR - Endpoint
 XDRFebruary 2024MDSecLoA - MDSec - MDR - XDR - SOC.OS
 Sophos Mobile ControlAugust 2024MWR CyberSecLoA-MWR-SMC
NetworkFirewallNovember 2024MWR CyberSecLoA – MWR – Firewall

LoA – MWR – Sophos Connect Client
 SG UTMJuly 2022NettitudeContact Us
 SD-RED Remote Ethernet DevicesNovember 2021MDSecContact Us
 ZTNAOctober 2023MWR CyberSecLoA - MWR - Firewall/ZTNA
 SwitchJanuary 2024Sophos Red TeamContact Us
 DNS ProtectionJanuary 2024MWR CyberSecLoA - MWR - DNS Protection
Security OperationsMDRFebruary 2025MDSecLoA - MDSec - MDR
 XDRFebruary 2024MDSecLoA - MDSec - MDR - XDR - SOC.OS
 RefactrFebruary 2022Sophos Red TeamContact Us
 SOC.OSFebruary 2024MDSecLoA - MDSec - MDR - XDR - SOC.OS
 FactoryFebruary 2024MDSecLoA - MDSec - Sophos Factory
MessagingCentral EmailAugust 2024Sophos Red TeamContact Us
CloudSophos CentralJanuary 2025MDSecLoA - MDSec - Central
 Cloud OptixJanuary 2024MDSecLoA - MDSec - Optix
 ZTNAFebruary 2025Pen Test PartnersLoA – PTP - ZTNA
 FirewallOctober 2023MWR CyberSecLoA - MWR - Firewall/ZTNA
Home SecuritySophos HomeAugust 2022Sophos Red TeamContact Us
OtherSophosLabs 
(including Intelix)
November 2024Sophos Red TeamContact Us

Tabletop exercises

At Sophos, we believe that it’s very important to test our capabilities regularly. We do this by developing tabletop scenarios with input from experts across the business and our risk management team.

The chart below details some of the recent tabletop scenarios we have run.

Recent tabletop scenarios

TeamScenarioDate
Finance TeamTargeted attack against finance from attacker posing as vendorQ4 2024
MDR TeamDeveloper and Analyst compromise leading to Customer Ransomware AttackQ3 2024
Global PurchasingMalicious Vendor onboarding and fake purchase requisitionQ2 2024
SophosLabsInsider threatQ1 2024
HRRansomware and employee PII leakageQ4 2023
SupportTargeted attack by someone posing as a customerQ3 2023
MarketingA compromised employee leading to the defacement of the company website 
and social media
Q2 2023
LegalMalicious bug bounty researcherQ1 2023
Sophos HomeCompromised engineer leading to large PII lossQ4 2022
SophosLabsCompromised analyst system, supply chain attackQ3 2022
EndpointCompromised Sophos binaries, supply chain attackQ2 2022
OptixPhished engineerQ1 2022
ITLarge-scale ransomware incidentQ4 2021
CentralZero-day vulnerability in application leading to compromise of customer dataQ4 2020

SecurityScorecard vendor risk management

IT vendor risk management (VRM) solutions support enterprises that assess, monitor, and manage risks associated with using third-party IT products, services, and vendors that can access their data. There are many IT VRM solutions available, all of which vary in their ability to accurately identify a vendor’s assets, and the potential risks associated with those assets.

Sophos engages with SecurityScorecard and its VRM platform to support customers who use IT VRM tools as part of their procurement process. To see our current rating, visit  https://securityscorecard.com/security-rating/sophos.com.

securityscorecard