Where the decision point can sit
The decision point lives where you put it, so an air gapped site is a supported deployment rather than an exception you argue for, and the network layer under your endpoints is post-quantum by construction.
Sophos Central is a cloud-based console, and every Sophos product you turn on is managed from it. QS-WAN hands you that console instead: it runs on your own infrastructure, including air gapped, over a post-quantum network layer. Move if the thing deciding your policy has to sit inside your boundary. Stay if it doesn’t, because their catalogue is wider.
Sophos is an endpoint and network suite with a long detection history and a channel built around service providers.
What they’re good at isn’t small, and the catalogue covers ground we don’t touch.
You “deploy and manage every Sophos product (including endpoint, firewall, email, server, mobile, and cloud)” from Sophos Central.
Their endpoint side is a “single lightweight agent for Windows, macOS, and Linux” with exploit mitigation, deep learning malware prevention, CryptoGuard, web and application control and DLP.
Security Heartbeat is a genuinely good design: firewall and endpoints “exchange information about the endpoints’ security status”, so “endpoints with security incidents can be immediately isolated”.
Where does the thing that decides your policy live?
Theirs is “a cloud-native application”, “hosted on public cloud platforms, such as Amazon Web Services (AWS) and Microsoft Azure”. Security Heartbeat shows the shape: firewall and endpoint don’t couple directly, they “communicate through Sophos Central”. Your network layer and your endpoint layer are linked through a console you don’t host.
In QS-WAN the control tower is software you run, on premise, in a private cloud, or air gapped. Enrolment, certificate issuance, key exchange and policy signing happen inside your boundary. Patching and backups become yours, which Sophos does for you today.
The diagram compares two architectures. A dashed box marks your network boundary and holds a laptop, a server and an office LAN. In the first, the management console that decides their policy is cloud native and hosted on public cloud platforms, so it sits outside the boundary and the control channel from each machine crosses the line to reach it, with nothing there for you to host. Post-quantum appears in that model as an inspection point on the boundary, where the key exchange is identified and controlled. In the second, the control tower runs inside the boundary, so enrolment, certificate issuance and the signed company policy stay on your side of the line, and post-quantum runs on every tunnel inside it, with a hybrid key exchange of X25519 and ML-KEM-768 and ML-DSA-87 authentication. That model hands you a bill as well: patching, backups and availability of the tower become yours. The diagram compares where the management plane runs and where post-quantum sits. It says nothing about detection engines and nothing about how traffic is carried.
Is post-quantum something you inspect, or something that protects you?
Their release notes say the firewall “identifies and controls the use of post-quantum cryptography (PQC)”, with intrusion prevention that “can detect and block pure and hybrid PQC key exchange algorithms based on ML-KEM”. That decides which post-quantum traffic crosses the firewall.
QS-WAN sits on the other side of that sentence. Your tunnels run a hybrid key exchange, X25519 plus ML-KEM-768, with ML-DSA-87 authentication and AES-256-GCM, and the console tells you traffic captured today cannot be decrypted later by a quantum computer. Hybrid means the classical half has to break too. Eight key exchange options, eight certificate authorities and three ciphers switch per gateway or fleet wide, with certificates re-signed for you: crypto agility over a post-quantum layer.
Sophos Connect installs separately, and users import a configuration or provisioning file per authentication method. The QNova Client is one signed install and one button.
That install also carries endpoint protection with EDR, remote support, a password vault and encrypted file transfer. The test is whether it ends contracts.
Sixteen rules scoped per gateway, user or device, where a device override changes only the ids it sets. USB port blocking is one.
Nine frameworks scored in the console, CIS benchmarks running against real hosts, and reports carrying aggregates only.
The decision point lives where you put it, so an air gapped site is a supported deployment rather than an exception you argue for, and the network layer under your endpoints is post-quantum by construction.
Segments are objects you draw on a map of VLANs and edges, and the console runs in 15 languages.
We're not a security operations centre. Nobody of ours watches your traffic.
The specific cost of leaving a Sophos estate is that you stop being a tenant. Their console is hosted for you and their updates arrive without you scheduling them. So the first decision is who patches and backs up the tower, because that becomes yours.
If you use the link between their firewall and their endpoint agent, that link has no equivalent here because we do not sell a firewall. Accept that the signal goes away, and work out whether you were relying on it.
Then run both agents side by side until the new one has survived a patch cycle and a real incident. Two endpoint agents on one machine is a fortnight of care, not an afternoon.
Sophos Central is hosted for you, and Sophos MDR is “an outsourced cybersecurity service” with experts who “monitor, investigate, and respond to threats on an organization’s behalf”. We sell neither. If your gap is analyst hours at three in the morning, we’re the wrong answer.
Their console covers those from one place and ours doesn’t. Trading breadth for a control plane you didn’t need is a bad deal.
Health status feeding firewall rules is real work, and we put a gateway beside infrastructure you already have rather than replacing appliances.
Windows is the complete column, macOS ships with CIS benchmarks running, and Android is there. Linux has gaps and iOS is next, not now.
Consolidation only pays when it ends contracts, and no architecture argument fixes that arithmetic.
One where the management plane has no route to the internet. Sophos Central is cloud-native and hosted on public cloud platforms; the QS-WAN control tower runs on your own infrastructure, which makes air gapped networking a deployment rather than an exception.
No, and probably not on day one. The gateway sits beside the network you already have. Dropping their firewall does cost you Security Heartbeat, where firewall and endpoints exchange health status through Sophos Central.
Running. Hybrid key exchange, X25519 plus ML-KEM-768, ML-DSA-87 authentication and AES-256-GCM, aligned to FIPS 203, FIPS 204 and CNSA 2.0.
No. This is a product, not a managed service, and that's the clearest line between us and an MDR subscription.
For those two, yes: tunnel, endpoint protection, remote support, password vault and file transfer in one signed install. It doesn't replace email or cloud workload security.
We’ll show you where the tower would sit on the network you already run, free, with nothing to sign.