-
Sophos Network Detection and Response NDR - 100-199 users - 1-year subscription
BUY$65.00MSRP: $69.00 -
Sophos Network Detection and Response NDR - 1-9 users and servers - 1 year subscription
BUY$110.00MSRP: $115.00 -
Sophos Network Detection and Response NDR - 1-9 users and servers - 3 year subscription
BUY$340.00MSRP: $345.60 -
-
Sophos Network Detection and Response NDR - 10-24 users and servers - 3 year subscription
BUY$280.00MSRP: $289.00 -
-
Sophos Network Detection and Response NDR - 25-49 users and servers - 3 year subscription
BUY$245.00MSRP: $249.00 -
-
Sophos Network Detection and Response NDR - 50-99 users and servers - 3 year subscription
BUY$218.00MSRP: $222.20
See the threats hiding in your network traffic.
Sophos NDR uses AI to spot attacker activity in network traffic that endpoints and firewalls miss, feeding Sophos MDR and XDR. Buy a licence below, or ask us to size it.
Search by product name, model, or part number, for example a model number or SKU. Or browse the options below.
Unmanaged & IoT devices
Legitimate devices with no protection agent, plus IoT and OT assets, that could be used as an entry point.
Rogue assets
Unauthorised, potentially malicious devices communicating across the network that shouldn't be there.
Command-and-control
Server C2 attempts and new or zero-day C2 traffic, spotted from patterns in the network sessions.
Lateral movement
The east-west traffic an attacker uses to spread through your network after the first foothold.
Insider threats
Unusual data movement and behaviour from inside the organisation, measured against what normal looks like.
Zero-day & novel attacks
Previously unseen attacks and unusual patterns deep in the network that signature-based tools would miss.
What does Sophos NDR do?+
It monitors your internal network traffic for suspicious and malicious patterns that endpoints and firewalls cannot see, such as rogue and unmanaged devices, command-and-control, lateral movement, insider threats, and zero-day attacks, and feeds those detections into Sophos MDR and XDR.
How is NDR different from EDR, a firewall, or SIEM?+
EDR watches activity on endpoints, firewalls control traffic at the perimeter, and SIEM correlates logs. NDR analyses the network traffic between devices to expose activity from unmanaged, IoT, and rogue devices that those tools often miss. It complements them rather than replacing them.
Does it decrypt my traffic?+
No. Sophos NDR uses a deep learning model to find patterns in traffic, including encrypted traffic, without decrypting payloads or exposing personal data.
How is it deployed?+
As a sensor that connects to your switch through a SPAN (mirror) port, available as a virtual appliance on VMware, Hyper-V, or AWS, or as a hardware appliance. It does not sit inline in your traffic path.
Do I need Sophos MDR or XDR to use NDR?+
Sophos NDR is available for both Sophos MDR and Sophos XDR, and its value comes from feeding those workflows. If you run either, NDR adds the network layer; we will confirm the right fit when we quote.




