Sophos Central Device Encryption (formerly SafeGuard) is a full disk encryption solution, based on the technology acquired with Utimaco by Sophos in 2008. It provides full disk encryption for Windows and macOS, and enables users to confidentially share sensitive files. A password protected HTML wrapper ensures only recipients with the correct password can access a document.
N/A
Sophos Cloud Web Gateway (discontinued)
Score 7.0 out of 10
N/A
Sophos Cloud Web Gateway has been discontinued since 30 June 2020.
It is mid-level when it comes to running it by a non-IT person. I have no technical/IT training and can figure out on my own (or with a little web search) how to do most tasks. It may not be best for the very tech-challenged operator.
Sophos Secure Web Gateway is great for almost any business that needs an easily-manageable proxy server. We're a medium-sized enterprise, but the product would work great for much larger companies as well. The only real limitations would be hardware resources, but it isn't that intensive. The administration of it is very intuitive, and it was quick to set up. Where it might not make sense is across multiple sites, unless all internet traffic is funneled through one place. It would be a bit complicated to maintain multiple setups.
Administrator Permissions: There's not enough granularity on the administrative side. We ran into an issue where we wanted to restrict junior admins from being able to see traffic per user. But in doing so, it also prevented them from adusting some other settings they had to have access to, like setting exceptions for sites.
CA Database: I occasionally run into issues where the list of certificate authorities in the appliance is not up to date, and I have to manually add a CA. These aren't rare, never-heard-of authorities, either, but they are usually subsidiaries of one of the major ones.
Feedback: Sometimes it takes some good detective skills to track down why a legitimate site isn't working. It's often because of content hosted elsewhere (images, for example), but the reports aren't always clear as to what actually gets blocked. It takes some trial and error sometimes to unblock something that should be okay for our business.
I am pretty satisfied with Sophos Central Device Encryption's overall capabilities. It is easy to implement and ultimately brings more peace of mind because fewer tickets are generated. As a result, security within the organization is also improved. Another significant advantage is that you can quickly see the statuses in real time on the dashboards. This gives you a better overview and reduces the chance of missing minor security settings.
At that time, we chose Sophos based on the reputation and our partnership with our partner. And in general Sophos could give us more benefit than other competitors with the similar solution. However we do not feel comfortable to disclose information about comparison with other solutions. Despite that, we think Sophos could deliver our requirements very well with the cost that were reasonable for us.
Sophos Secure Web Gateway has flexible pricing and deployment options. It offers a huge range of categorization options and they also pull web categorization info from other services
It's had a positive impact as it's allowed us to effectively secure hard drives with bitlocker encryption
A larger part of our work force works from home, and Sophos can be deployed remotely and will start encryption almost straight away on any computer that isn't already encrypted.
We have not had a single instance of malware since installing Web Gateway. We have other ways to prevent infections and attacks, of course, so this is just one tool in the box, but we had a handful before this from people visiting sites they should not have. Web Gateway has prevented those, at least.
There was some pushback initially as users had to deal with some business sites not working (usually due to CA problems). After the initial growing pains, however, we've seen very few other problems.
The appliance updates itself, in the middle of the night, so that reduces some overhead and planned downtime.