TrustRadius: an HG Insights company

Sophos Central Device Encryption

Score8.4 out of 10

38 Reviews and Ratings

What is Sophos Central Device Encryption?

Sophos Central Device Encryption (formerly SafeGuard) is a full disk encryption solution, based on the technology acquired with Utimaco by Sophos in 2008. It provides full disk encryption for Windows and macOS, and enables users to confidentially share sensitive files. A password protected HTML wrapper ensures only recipients with the correct password can access a document.

Categories & Use Cases

Sophos is great and works exactly how you need it to.

Use Cases and Deployment Scope

We use Sophos to manager our bitlocker encryption on our endpoints. We use it on around 400 - 500 endpoints. It's very easy to deploy and quick to configure. It's important as it ensure that our drives are secure and keeps information within them safe. It's a simple software but very effective

Pros

  • It's very easy to set up
  • It's simple to use
  • Works very quickly in applying policy

Cons

  • Sometimes It can be difficult removing Sophos from endpoints, especially in circumstances where it'd been accidently deleted off the main portal some time ago.
  • It can be a little unpredicable at times when it comes to forcing bitlocker encryption.

Return on Investment

  • It's had a positive impact as it's allowed us to effectively secure hard drives with bitlocker encryption
  • A larger part of our work force works from home, and Sophos can be deployed remotely and will start encryption almost straight away on any computer that isn't already encrypted.

Usability

Other Software Used

Heimdal Threat-hunting & Action Center, Heimdal Remote Desktop, Heimdal Next-Gen Endpoint Antivirus

Sophos Central Device Encryption makes life easier

Use Cases and Deployment Scope

A easy way to central manage Bitlocker throughout a clients network. Force new endpoints to start encrypting the hard drive As well as centrally keep a copy of Bitlocker recovery keys.

Pros

  • Centrally enforce device encryption
  • Easy 3 button policy is sweet and simple to setup and rollout
  • Uses the same Sophos Endpoint client already installed on the machine

Cons

  • None so far, It does exactly what it is supposed to

Return on Investment

  • Easy to remotely and centrally manage
  • Easy to remotely enforce

Usability

Alternatives Considered

BitLocker Drive Encryption

Other Software Used

BitLocker Drive Encryption, SentinelOne Singularity, DataSet by SentinelOne

Security with Sophos.

Use Cases and Deployment Scope

Because our clients have top-secret products and processes, we must work on a highly secure network. We also need to protect our data from hackers, so we need complete control over network security. To allow certain websites and block others, Sophos Central makes it easy to granularly control each device on the network, as well as overall internet security rules.

Pros

  • Blocks unwanted website access.
  • Allows access to websites that a blanket blocking would prevent us from using.
  • Isolates user/machines individually to check/watch for errors and issues.

Cons

  • The blocking of specific websites could be explained and executed more easily. It should be a separate option to block unwanted website access more easily.

Return on Investment

  • We can rest assured our network is monitored and secure, and peace of mind is priceless.
  • We have been able to increase productivity by easily blocking websites that employees may want to access outside of their scope of work (ie, cause distractions).

Usability

Alternatives Considered

McAfee Total Protection (discontinued)

Other Software Used

Net2Phone, Evernote, JumpCloud, Robly

Sophos Central

Use Cases and Deployment Scope

We have rolled out Sophos Central Device Encryption at multiple organizations. As administrators, we now have more control and oversight over the security of our endpoints. Through the real-time dashboard, I can see which systems are fully encrypted with BitLocker and where further action is needed. The rollout went smoothly: BitLocker was automatically activated without any user issues. Thanks to the self-service recovery portal, support requests have dropped significantly. Management is now more streamlined, and we can better meet compliance requirements.

Pros

  • Centralized management of BitLocker and FileVault.
  • Self-service recovery portal for end users.
  • Real-time reporting and compliance monitoring.

Cons

  • Expansion to File and Folder Encryption.
  • Compatibility with Dynamic Disks.
  • Knowledge needed to set it up.

Return on Investment

  • Less supportickets, Cost Savings on Helpdesk Support.
  • More efficient management that saves time, and therefore money.
  • Less security tickets.

Usability

Alternatives Considered

Sophos Central Device Encryption and Sophos XG Firewall

Other Software Used

Google Chrome, Microsoft Edge, KeePass

Sophos Central Device Encryption is an excellent solution to manage your endpoint encryption.

Use Cases and Deployment Scope

My organization uses Sophos Central Device Encryption to protect corporate endpoints with encryption and BitLocker management from its web-based Sophos Cloud solution. It addressed the need for encryption on mobile devices and provided a necessary solution while allowing us to manage the encryption, passwords, access, and removal of the keys in case the device is lost.

Pros

  • Sophos Central Device Encryption provides the ability to easily encrypt endpoints.
  • Sophos Central Device Encryption provides the ability to force and change passwords easily.
  • Sophos Central Device Encryption provides the ability to easily manage access to the device.

Cons

  • The Sophos Central Device Encryption policies could be more enhanced and detailed.
  • The Sophos Central Device Encryption audit logs could be better.
  • The Sophos Central Device Encryption real-time monitoring can be improved.

Return on Investment

  • Positive impact from a regulatory and security perspective.
  • Positive impact from an administrative perspective.
  • Negative impact as users typically dont like another credential to enter.

Usability

Alternatives Considered

Microsoft Intune, FortiClient and DataSet by SentinelOne

Other Software Used

Mimecast Advanced Email Security, Arctic Wolf Managed Detection and Response, Cisco Duo