-
Sophos Central Managed Risk - 1-9 users - 1-year subscription
BUY$109.00MSRP: $115.00 -
Sophos Central Managed Risk - 10-24 users - 1-year subscription
BUY$91.00MSRP: $96.00 -
Sophos Central Managed Risk - 25-49 users - 1-year subscription
BUY$79.00MSRP: $83.00 -
Sophos Central Managed Risk - 1-9 users - 3-year subscription
BUY$328.00MSRP: $346.00 -
Sophos Central Managed Risk - 50-99 users - 1-year subscription
BUY$70.00MSRP: $74.00 -
Sophos Central Managed Risk - 10-24 users - 3-year subscription
BUY$274.00MSRP: $288.00 -
Sophos Central Managed Risk - 25-49 users - 3-year subscription
BUY$236.00MSRP: $249.00 -
Sophos Central Managed Risk - 50-99 users - 3-year subscription
BUY$211.00MSRP: $222.00
Find and fix your weak spots before an attacker does.
Sophos Managed Risk is a managed vulnerability and attack surface service powered by Tenable, with EASM, IASM, and expert remediation guidance. Buy a licence below, or ask us to size it.
Looking for a specific model or SKU? Use the search bar at the top of the page. Or browse the options below.
| Capability | What it does |
|---|---|
| External attack surface (EASM) | Finds and classifies the internet-facing assets you may not know you own, including web and email servers, web apps, and public API endpoints. |
| Internal attack surface (IASM) | Uses Tenable Nessus scanners to find vulnerabilities inside your network and rate their severity, closing the internal blind spot. |
| Risk-based prioritisation | Intelligently ranks which vulnerabilities pose the highest risk, so you know what to patch first and why, instead of drowning in a flat list. |
| Continuous scanning | Regular automated scans keep pace with your changing attack surface, plus extra scans when a new exploit appears or a vulnerability's risk level changes. |
| Proactive notification | When a severe exposure appears, Sophos checks your assets for the chance of an exploit and tells you, rather than leaving you to find out later. |
| Expert remediation guidance | A dedicated team of Tenable-certified analysts explains each exposure and gives tailored guidance on how to close it. |
What is Sophos Managed Risk?+
A fully managed vulnerability and attack surface management service, powered by Tenable and delivered by a dedicated Sophos team. It finds your internal and external exposures, prioritises them by risk, scans continuously, and gives you remediation guidance.
What is the difference between EASM and IASM?+
External Attack Surface Management (EASM) finds internet-facing assets that could be attacked from outside, such as web and email servers and public APIs. Internal Attack Surface Management (IASM) uses Tenable Nessus scanners to find vulnerabilities inside your network. Sophos Managed Risk includes both.
Is this a product I run, or a service?+
It is a fully managed service. A dedicated team of Tenable-certified Sophos analysts runs the scanning and prioritisation and hands you findings and guidance. You configure and view it in Sophos Fusion.
How often does it scan?+
Regular automated scans run on a schedule, with additional scans when a new exploit is discovered or when the risk level of a known vulnerability changes.
Do I need Sophos MDR to use it?+
No, but the two work together. The Managed Risk team shares vulnerability and exposure information with Sophos MDR, so if you run both, an at-risk environment gets investigated faster.




