Short answer
Yes. Sophos MDR is a separate service that attaches to Sophos Firewall as a Service on the same monthly bill. With Sophos endpoints, Synchronized Security can also isolate compromised devices automatically.
In detail
What adding MDR gives you:
- Sophos analysts monitoring, hunting and alerting 24/7
- FirstNet's Incident Response team acting on Sophos alerts with you, under a runbook agreed during onboarding
- Longer log retention through the Sophos MDR data lake, beyond the firewall's own seven-day or 30-day retention
- With Xstream Protection, a connector that feeds firewall telemetry into MDR and XDR
MDR is not part of Firewall as a Service by default, so it is scoped and contracted separately. Incident response on your endpoints is only in scope once Sophos MDR is contracted.
Standard MDR onboarding typically takes two to four weeks and covers discovery, a deployment plan, telemetry validation, MDR onboarding and the incident response runbook.
Everything is managed from Sophos Central, the same console FirstNet uses to run your firewall, which keeps policy and visibility in one place.
Source: FirstNet Managed Cybersecurity Services service page →
Didn’t answer your question?
