When cybersecurity becomes a system, not a stack

Cybersecurity has long been sold as a growing stack of point products, each solving a narrow problem while leaving security teams to stitch together the bigger picture manually. Jason Clark, Senior Vice President, Global Sales Engineering (USA) at Sophos, argues that model is breaking down just as frontier AI hands attackers the ability to generate working exploits and chain attacks across systems in seconds rather than days. In this conversation with CISO Forum, Clark unpacks why Sophos frames its Fusion offering as a “cybersecurity defence system” rather than a platform, how a shared context lake changes the economics of detection and response, and what the Secureworks Taegis integration unlocks for XDR and next-gen SIEM. He also addresses a sobering statistic: fewer than 35,000 of the world’s 359 million businesses have a dedicated CISO and what that means for closing the security leadership gap at scale.

Jason Clark
Senior Vice President, Global Sales Engineering (USA)
Sophos

CISO Forum: Sophos calls Fusion a “cybersecurity defence system,” not a platform or suite. What’s the substantive difference, and why does that distinction matter to a CISO evaluating vendors right now?

Jason Clark: It should matter a lot to many CISOs and organisations. We’ll start with the platform. A platform is usually built by aggregating several siloed products. And if AI is in the mix, it’s typically bolted on top rather than natively integrated or built from the ground up. Response challenges are often manual because the systems or control points don’t talk to each other. So it’s either manual or playbook-driven. The biggest issue with platforms today is that intelligence is static and siloed per product, so threat intelligence context isn’t shared across those siloed technologies.

Now, Sophos Fusion, on the other hand, is a system that is built from the ground up as a single open architecture where all the control points, whether they’re Sophos or third-party, and data sources and the analysts operate as a cohesive team. So they share information and context. It’s not just a collection of products connecting through a shared console. So we’ve built our architecture around a few principles.

One is that single shared context lake. Second is synchronised security, which Sophos coined about 10 years ago. So detections trigger responses everywhere, across all of your control points in that cohesive system. And then if AI is in the mix, it’s autonomous.

Human accountability and governance on top of that, and then the intelligence compounds and is shared across all those control points in the system.

CISO Forum: You’ve said something shifted in late 2025 when frontier AI models crossed a threshold that lets adversaries generate working exploit code and chain attacks across product boundaries autonomously. What changed concretely in the attacks you’re seeing, and how has that reshaped Sophos’s own defence architecture?

Jason Clark: A lot has changed. The biggest one is probably the speed. So that’s the key shift. But then autonomy- the new agentic shift in the fact that many SaaS platforms, when a feature is released, that feature may be agentic AI in your environment.

Whether you govern it or not. And then lastly, is, you know, candidly, just the unknown in the world that we’re living in. And then the scope of the attacks, you know, activities that prior unfolded over, you know, days or hours or weeks, they can play out in seconds. And we’re seeing that in the news nearly every week.
And on top of that, we have these new concepts we’re calling frontier models. They have crossed the boundary where machines can identify vulnerabilities at scale. And you don’t have to be part of a frontier program to gain access. You can use some of these open-weight models if you have the compute power.

So attackers are getting their hands on those. So it’s an interesting time we’re in, and it’s very dangerous for several organisations because AI is enabling these attackers to generate, you know, working exploits in real time, improve their ability to social engineer their way in.

At scale, and then connect those attacks across several boundaries autonomously. So they’re very difficult to attack these days. Our response is a connected architecture, which we call the Sophos Fusion cyber defence system.

Where those control points share that context in real time. And our agentic AI can fight against the attacker’s agentic AI, improving response speed and investigation for our customers.

CISO Forum: Sophos cites 52% of agentic SOC cases resolved entirely by AI with an 89-second average alert-to-response time. What kinds of cases fall in that 52%, and what still requires a human analyst?

Jason Clark: The Fusion architecture is designed to really hand the reins over to AI and let AI handle the volume and the velocity of those routine operations across security operations, including detections, investigations,
and response actions. We let AI take on the repetitive, well-understood decisions. And that’s the key. It has to be well understood. You typically don’t want to let AI, not just in security, but in enterprise operations, make decisions on something that’s not well understood.

By the industry or the organisation. But by letting AI handle routine tasks, it frees experts for complex investigations. But we strongly believe that at Sophos, human oversight is paramount to making high-impact, business-critical decisions. So humans have to stay in the loop. We know that AI sometimes simply does what it thinks is the best decision, and that’s not always the right decision. These conversations should move away from AI versus humans, you know, to more of: Allowing AI to handle the scale and speed. In contrast, humans impart judgment and maintain accountability for the decisions being made.

CISO Forum: How does a shared “context lake” actually change the unit economics of detection and response for a security team, versus stitching together telemetry from separate point products?

Jason Clark: When we look at Fusion, and we touched on it earlier, it takes that telemetry. When you get away from siloed technologies and products, you own all of the control points. Or at least have connectivity in that context. It brings the telemetry from each of those points into one data layer.

All in real time, so you don’t have the delays of aggregating data or managing separate data lakes, and it removes the cost in dollars and time. That means all control points, whether they’re close or your own, can see the context. They can see each other’s context of what’s going on, whether it’s an attack or signals or detection. So that allows an attack that may move across multiple layers, like email or firewall or your network devices, to be collected and treated as a single
Incident with connected components instead of isolated alerts. And then we talk about the economics. Another component is that it offloads the manual work of maintaining those consoles, moving between them, and manually correlating the
the data and then manually managing those separate response actions.

And again, it’s not just limited to Sophos technologies that you have to invest in. Fusion supports over 500 3rd-party technologies and integrations that let you leverage your existing security investments, and they can certainly participate in the Fusion architecture. So it’s not an immediate replacement. And I’ll add one other: we’ve recently announced our next-gen SIEM technology, which is integrated into our system. That gives you more predictable economics.

The challenge with SIEM, or one of the challenges, is the cost and pricing model. It’s typically by volume and data. So sometimes organisations have to make the unfortunate decision not to collect certain types of data because of cost, depending on where they are in that product cycle. So it removes the cost barrier by offering simple user-based pricing with up to 10 years of storage, so you still meet your compliance requirements while also benefiting from a cohesive system that shares context.

CISO Forum: With Secureworks Taegis folded in, what does that acquisition unlock for XDR and next-gen SIEM that Sophos couldn’t do on its own, and how soon will customers see that integration land?

Jason Clark: To answer the last part, they started seeing those integrations land as early as 6 to 8 months ago. We’re effectively taking the best of both technologies.
And seamlessly rebuilding our platform into a cohesive system. We’ve effectively rebuilt it based on analytics and threat intelligence; we’re ingesting thousands of new detectors, which improves the overall security posture for all of our customers.

We’ve also added a new analyst experience in Sophos Fusion, with built-in automation and orchestration capabilities, plus playbooks that let you trigger actions based on detections or other events. So, our overall objective is to provide lightning-fast, high-fidelity responses with low manual effort, making teams more efficient and freeing them up to do other work. And the integration isn’t just about the roadmap; our XDR and MDR platform is powered by the back end of Securex Taegis, and the Sophos Next Gen SIM is the next evolution of that.

CISO Forum: Futurum projects security operations doubling from $18B to $37B by 2029. What’s driving that specific segment’s growth faster than the rest of cybersecurity spend?

Jason Clark:
By those numbers, security operations is the fastest-growing category in cybersecurity. Step back: it’s an industry problem. We have more attacks every year. They’re coming out faster, they’re more sophisticated. And traditionally, we add more tools, which is counterintuitive. It’s counterproductive because you’re spreading your analyst teams’ knowledge across many tools, so it’s harder to keep up. The underlying shift is away from simply adding more security products.

Moving more towards AI native capabilities where you can orchestrate and really adapt to new attacks using a single defence system. And as these new, sophisticated attacks include AI, they’re moving at not just machine speed, but
across several layers and tools across the enterprise. Organisations need a security operations platform or system that can correlate all the signals and respond much, much faster. Ultimately, it’s driving demand for AI-enabled detection, investigation, response, and orchestration. And the trend we’re going to see is more need for managed detection and managed security operations.

CISO Forum: Sophos’s own research finds fewer than 35,000 of the world’s roughly 359 million businesses have a CISO or security leader in place. How is CISO Advantage designed to actually close that gap rather than just paper over it with automation?

Jason Clark: CISOs today, just in the world we live in, have a very important job, which has always been the case, but they have a very challenging one now just due to the speed and scale at which things are occurring. And in many cases, they have limited staff in the CISO office.

CISO Advantage is designed to provide CISO-level guidance to organisations, whether they’ve detected or dedicated to CSO or not. And it combines. Continuous control validation. It maps controls to regulations and compliance frameworks like NIST, CIS, or local regulations. It brings together integrated technology, validation, compliance mapping, peer benchmarking, and risk assessment. For organisations with a CISO, it’s designed to extend your team and make risk management, control, validation, and even board communication more accurate and efficient. And then for organisations that don’t have a CSO on staff, which there are a lot of, it provides practical guidance and in-house security leadership that’s actually grounded in their systems and their environment instead of just automating security alerts.

CISO Forum: For Indian enterprises still consolidating point tools under new data protection obligations like the DPDP Act, what’s the realistic timeline and effort to migrate onto a unified system like Fusion?

Jason Clark: So, with Fusion, we look at it as a system. We don’t typically talk to customers about ripping out their current security tools and replacing everything. That sounds daunting to most people. It certainly sounds daunting to me.

So that’s why we’ve built our architecture open by design. That was one of the founding principles. That allows organisations to connect their existing 3rd-party tools. So they’re really investing in Fusion as a system.

You can start with your endpoint control or firewall, or you can start with our managed detection and response while continuing to use your existing endpoint protection, then migrate later. So the open architecture lets them consolidate on their own.

Timeline: As some of those contracts come up for renewal, they can save the cost of managing multiple vendors. Again, we support over 500 third-party tools and integrations across every security tool category. So you can start with the control points you have today, focus on the greatest need, and grow from there over time. And across all of that, Fusion provides unified context that you retain. Then it supports the compliance reporting and the necessary evidence if they have auditors- you mentioned DBT earlier- and then regulators and insurance as well.

CISO Forum: With MSPs and MSSPs central to Sophos’s go-to-market, how does Fusion change what a partner sells and operates, and what does that mean for mid-market Indian customers who rely on MSSPs rather than in-house SOCs?

Jason Clark: It’s a really interesting opportunity for our partners here in India. Yesterday, we sat down with about 120 of our leading partners in Bengaluru, and they also see it as an interesting opportunity. It does allow them to grow their business, but it’s an interesting

In this paradigm, we’re solving the problem of selling more and more tools to address the growing threat. Instead, we give our partners the ability to sell a single system in Sophos Fusion that operates as a system rather than just a collection of point products. So if you’re a system integrator partner and you have a team that has to understand several point products inside and out, it becomes very challenging to provide a high level of service to your customers.

This also lets MSPs and MSSPs go beyond managing multiple vendors from a vendor-management perspective and deliver a broader set of capabilities in a single system that drives recurring outcomes for them and their customers. Our CSO Advantage is designed for the managed service provider business model we know today. It enables them, particularly those that provide strategic value and are trusted advisors. It makes them a trusted advisor, not just an operator and deliverer of technology to their customers. And for small and mid-market companies, they don’t have the resources to build out their own internal SOC, especially with some of these front-frontier AI models, which require a lot of compute to really respond rapidly. MDR has a complete partner ecosystem that provides around-the-clock, 24/7, 365-day detection, protection, and response capabilities from a geographically dispersed group of top-tier analysts, compounded by AI as well. And the intelligence across all those components continues to compound not just within an MSP, but across all customers in the Sophos ecosystem. So we all benefit from that—that compounding intelligence.

CISO Forum: As AI Defence rolls out for shadow-AI visibility through Q4, what’s the first blind spot you expect security teams to discover about their own AI usage once they turn it on?

Jason Clark: Sophos AI Defence- this is something that we’re really proud of and very excited about. We’ve been running it internally for some time, and it’s already showing tremendous benefit. And when I talk to customers about shadow AI, I believe that every single organisation has adopted AI, whether they know it or not. Even if the policy is to block it broadly, you still have to, as you mentioned, worry about shadow AI. The first step in AI governance is visibility, and Close AI Defence is designed to give you that visibility.

Across your organisation, whether it’s a small business or an enterprise, it gives you visibility into the AI tools, the embedded agents, the type of activity across your AI workflows, whether shadow or governed across the entire organisation—and you know the immediate blind spot that most find is the gap between what you approve, what they use, and the tools they’re actually using. And most organisations will be pretty surprised once you drop in AI defence, because you’ll see immediate value and immediate visibility. It’ll surprise you what’s going on in your environment.

Beyond that, once you’ve established visibility into your AI usage and enterprise or your environment, Defence provides the control capability to apply policy and protect your data, your customers’ data, and sensitive data from the AI tools in your environment. So you’re limiting that access, reducing the blast radius. And it’s really designed to address the adoption of AI, not create roadblocks, but rather remove roadblocks for many of our customers. So we’re really removing the security issues.

With AI, we’re letting you govern it, giving you the visibility to apply data protection, rather than blocking AI altogether. And customers can look forward to the release date of October of this year, so we’re right around the corner, but it is in early access today. With the flip of a button in our Sophos defence system, customers can start taking a look today.

Author