Sophos Compromise Assessment

SKU:
SOPHOS-SVC-CA
Availability:
Scoped and quoted per engagement

Description

Sophos Compromise Assessment

Compromise Assessment answers one question: has someone already been in your environment? It is delivered by the Sophos incident response team and the four phases typically complete within seven days of the initial coordination call.

This is the service for a suspicion, not an active incident. If you are currently under attack, Emergency Incident Response is the one you want and you should call rather than order. Compromise Assessment is for the quieter and more common worry, that something got in months ago and nobody noticed.

How the engagement runs

  • Initial coordination call to exchange information on the suspected threat, identify contacts and agree deployment scope.
  • Deployment of investigation tools across the agreed endpoints, with a device health assessment.
  • Threat investigation and risk assessment, including an immediate active threat call if something live is found.
  • Summary call and written report, with technical documentation and a non-technical executive summary.

What it looks for

Lateral movement, anomalous or malicious files, credential theft, data exfiltration and unverified scripts. The investigation targets the full spectrum of attacker activity rather than scanning for known malware.

What you get at the end

A written report in two registers: technical detail your team can act on, and an executive summary a board or an insurer can read. If an active breach is confirmed, priority onboarding moves you straight into incident response rather than starting a new procurement conversation.

Frequently asked questions

What does a Compromise Assessment tell me?

Whether an attacker is currently operating in your environment or has been recently, the scope of any activity found, and what to do about it. It answers the question, have I been breached.

How long does it take?

All four phases typically complete within seven days of the initial coordination call.

What if you find an active attack?

Sophos raises an immediate active threat call, and priority onboarding lets you shift straight into incident response rather than waiting on a new engagement.

How is this different from MDR?

MDR is continuous monitoring by a security team. Compromise Assessment is a one-off targeted investigation to establish whether something already happened. Many organizations run the assessment first and move to MDR afterwards.

Arrange this through Nuformat

Nuformat is a Sophos partner serving Canada and the United States. Tell us your environment size and what prompted the enquiry, and we will scope the engagement and come back with a quote, usually in two to three business days.

Request a quote

Service scope and delivery as published by Sophos. Pricing confirmed by Nuformat at the time of quotation.