Cybersecurity for Small Business with Sophos XGS
Posted by Saif Khan on 2021 Jun 11th
Most firewall failures are configuration mistakes, not product flaws. A rule added for a project three years ago and never removed. A policy applied at head office but not at the branch. An exception that was meant to be temporary.
Running different firewall brands across your sites multiplies the chances of that happening, because each one has its own interface, its own policy model, and its own way of being wrong.
1. One policy model instead of three
With mixed vendors, a rule written at head office has to be translated by hand for the branch. Translation is where mistakes enter.
With one platform, a policy is written once and applied everywhere. Your team learns one interface rather than three, which matters most when the person who knew the other two has left.
2. Threats are visible across sites, not just within one
Attacks move laterally. Something that starts on a laptop at a branch office ends up reaching a server at head office.
If those two sites sit behind different firewalls with separate consoles, nobody sees the connection. One platform gives you a single view of activity across every location, so lateral movement shows up as one incident rather than two unrelated alerts nobody correlates.
3. Fewer contracts, fewer renewal dates, less training
Multiple vendors means multiple support contracts, multiple renewal dates, multiple portals and multiple sets of training. The cost is partly licensing and mostly the administrative drag nobody budgets for.
Standardizing also makes deployment faster. Adding a branch or onboarding a remote team becomes a repeat of something you have already done rather than a new project.
What "everywhere" actually covers
Sophos Firewall runs the same software across every deployment type, so the policy model does not change as you move between them.
| Location | What you deploy |
|---|---|
| Head office and branches | XGS hardware appliances, sized per site |
| Remote and home workers | Sophos ZTNA, which works with the same firewall |
| Public cloud | Sophos Firewall in AWS and Microsoft Azure |
| Virtual and private cloud | Virtual appliances for VMware, Hyper-V and KVM |
All of it is managed from Sophos Fusion, alongside your endpoint, switches and access points if you run those too.
The honest counter-argument
Standardizing has a real downside worth naming: you concentrate risk in one vendor. If that vendor has a serious vulnerability, every site is exposed at once rather than some of them.
Security teams at large organizations sometimes run different vendors at the perimeter and the core deliberately for this reason. For a business under a few hundred people, though, the maths usually goes the other way. The risk of a misconfiguration across three poorly understood platforms is higher and far more likely than the risk of a simultaneous vendor-wide flaw.
Worth deciding deliberately rather than by accident, which is how most mixed estates come about.
How to standardize without replacing everything at once
- Start with what is closest to end of life. Replace the appliance that is already due, rather than scrapping working hardware.
- Do head office first if that is where the most complex policy lives, so the branches inherit a rule set that has already been reviewed.
- Review rules at migration, not after. Most firewalls accumulate rules nobody remembers adding. Carrying them forward carries the problem forward.
- Standardize the license term. Aligning renewal dates across sites removes a recurring administrative job.
Frequently asked questions
Why standardize on one firewall vendor?
One policy model means rules are written once and applied everywhere rather than translated by hand per site, which is where configuration mistakes enter. It also gives a single view of activity across locations, so lateral movement between sites appears as one incident. Practically, it reduces support contracts, renewal dates and training to one set.
What is the risk of using a single firewall vendor?
You concentrate risk. A serious vulnerability in that vendor exposes every site at once rather than some of them. Large organizations sometimes run different vendors at the perimeter and core for this reason. For most businesses the misconfiguration risk across multiple platforms is higher and more likely than a simultaneous vendor-wide flaw.
Can one firewall platform cover cloud and remote workers?
Yes. Sophos Firewall runs as hardware appliances at physical sites, as virtual appliances on VMware, Hyper-V and KVM, and in AWS and Microsoft Azure. Remote workers are covered by Sophos ZTNA, which works with the same firewall. The policy model stays the same across all of them.
Do I have to replace all my firewalls at once?
No. Start with whichever appliance is closest to end of life rather than scrapping working hardware. Doing head office first usually makes sense, because branches then inherit a rule set that has already been reviewed.
Does standardizing actually save money?
Some of the saving is licensing, but most is administrative: one support contract instead of several, one renewal cycle, one set of training. Deployment is also faster, because adding a site repeats something your team has already done.
Standardize across your sites
Nuformat is a Sophos partner serving Canada and the United States. Tell us how many sites you have, what is running at each, and which appliances are closest to renewal. We will map a migration order and price it site by site. Request a quote.
Sophos XGS firewalls · Virtual firewalls · Compare XGS models · Managed firewall services
Deployment options as published by Sophos. Pricing and availability confirmed by Nuformat at the time of quotation.

