Sophos Fusion Automates 52% of Ransomware Response as Identity Attacks Hit 79%

Sophos Fusion Automates 52% of Ransomware Response as Identity Attacks Hit 79%

BackerLeader 43 231 384
calendar_todayschedule3 min read

Sophos is launching a new security architecture built around a problem its own data just confirmed: identity, not software vulnerabilities, is now the primary way ransomware gets in.

The company's 2026 State of Ransomware report, released today alongside the launch of Sophos Fusion, found that 79% of ransomware attacks now start with compromised identities. Two-thirds of victims said the ransomware incident was also their most serious identity attack of the year. Multi-factor authentication was in place for 97% of the incidents where stolen credentials were the root cause, which says a lot about how far MFA alone can carry an organization at this point. For the first time in four years, exploited software vulnerabilities aren't even the top root cause anymore. Malicious email (26%) and phishing (24%) have taken over that spot. Encryption success also rebounded to 56% of attacks, reversing a two-year decline, and the average recovery cost per incident has climbed to $1.7 million.

Sophos Fusion is the company's answer to that shift. It's built on Sophos Central, which already protects 625,000 organizations, and now incorporates Secureworks Taegis analytics following Sophos's 2025 acquisition of Secureworks. The pitch is straightforward: instead of stitching products together after the fact, Fusion runs on one shared data layer, so a detection at any control point, whether that's endpoint, firewall, identity, email, or cloud, triggers a coordinated response across all the others in real time.

CEO Joe Levy frames it as a shift from platform thinking to system thinking. "Sophos Fusion is built as a defense system optimized for Human-AI workflows," Levy said. "We bring the most complete solution to a new category, a timely advancement demanded by the AI era."

The architecture rests on four ideas. One shared context lake, where every signal from every control point lands in the same place in real time. Synchronized response, where a detection at one layer triggers action at the others simultaneously rather than in sequence. Agentic autonomy inside boundaries that human analysts set and adjust. And compounding intelligence, where a threat caught at one customer strengthens the defense at every other customer almost immediately.

Sophos already runs this model internally, and the numbers are the part worth sitting with if you build or evaluate security tooling. Across more than 40,000 managed detection and response customers, the company says 52% of cases are resolved entirely by AI, with an average of 89 seconds between alert and automated response. That figure matters because 89 seconds is roughly the window an attacker needs to go from a stolen session token to lateral movement across a network. A defense system has to move on the same clock, or the response arrives after the damage is already done.

There's a distinction in how Sophos describes the human role here, and it's relevant to anyone architecting agentic systems of their own. Levy called the setup "human-on-the-loop" rather than "human-in-the-loop." Agents act on their own for high-volume, well-understood tasks: isolating an endpoint, revoking a session, blocking a malicious IP. A person stays accountable for the calls that require judgment, like confirming whether a suspicious inbox rule change is an accident or the setup for wire fraud. Put a human in the loop for every single action, and the system loses the speed advantage that justified building it agentic in the first place.

Fusion keeps expanding through the rest of the year. Sophos Next-Gen SIEM and a rebuilt Sophos XDR, powered by Secureworks Taegis analytics with added detectors and built-in SOAR automation, both reach general availability August 15. Sophos AI Defense, which gives visibility into AI tools already running inside a company, shadow AI included, gets early access in August and general availability in October. Sophos CISO Advantage, aimed at organizations without a dedicated security leader, starts rolling out in October.

That last piece connects to a stat Levy raised at Sophos's press briefing earlier this month: there are roughly 359 million organizations worldwide and fewer than 35,000 full-time CISOs to lead them, or about one for every 10,000 organizations. Fusion's underlying bet is that agentic AI can close part of that gap by putting CISO-level judgment into a system that runs continuously, instead of depending on headcount that mostly doesn't exist.

More than 500 third-party integrations feed into the same data layer, so existing tools from other vendors aren't replaced, they're folded in. For security teams already running a stack of 45-plus disconnected tools, a figure Sophos and Gartner both cite, that's arguably the more useful claim than "AI-native" on its own. The value isn't the AI by itself. It's what happens once everything already in place starts sharing context in real time.

Whether "cybersecurity defense system" becomes a real category, Gartner is reportedly building a new Magic Quadrant for it, expected in November, or just turns out to be Sophos's name for consolidation done well, is worth watching over the next couple of quarters. The ransomware numbers aren't really in dispute, though. Identity is the front door now, and a lot of the tooling built for perimeter and vulnerability defense wasn't built for that.

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

Sophos Traces a Ransomware Operation Back to 12 AI Agents Running Inside a Coding Assistant

Tom Smithverified - Jul 22

The Audit Trail of Things: Using Hashgraph as a Digital Caliper for Provenance

Ken W. Algerverified - Apr 28

Local-First: The Browser as the Vault

Pocket Portfolio - Apr 20

Cyera: Non-Human Identities Grew 480% in Six Months. Most Companies Have No Idea What They're Doing.

Tom Smithverified - Aug 3

From Prompts to Goals: The Rise of Outcome-Driven Development

Tom Smithverified - Apr 11
chevron_left
15.6k Points658 Badges
194Posts
119Comments
81Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

2 comments
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!