Security Teams Can See the Attack. They Still Cannot Close It the Same Way Twice

An attack that used to take a shift now lands inside the same hour, and the security team is still reading it across endpoint, firewall, identity, email and cloud tools that do not share a case. The detection exists. The repeatable response does not. That is the operational pressure on the floor at it-sa Expo & Congress in Nuremberg, 27-29 October 2026. The expo is the setting, not the event. Sophos is one of the companies on the floor. Illumio is another, in Hall 7, booth 7-710. A full list of seven named exhibitors is not in the material provided.
The Stack Is Fragmented. The Attack Is Not
Sven Janssen, vice president of sales for DACH at Sophos, said in comments provided to Security Guys News that visitors will be asked to discuss an AI-enabled threat landscape: faster attacks, more coordinated campaigns, rising pressure on security teams, and complexity from fragmented tools. The booth focus is Sophos Fusion, which he described as an open, AI-native defense system bringing security operations, controls, strategic risk, endpoint, network, identity, email, cloud, managed detection and response, and third-party tools into one architecture. It uses Sophos X-Ops intelligence, shared context, automation, agentic AI and human expertise so an organization can respond faster without replacing the technologies it already has.
He also pointed to Sophos AI Defense, for sanctioned and unsanctioned AI tools and the risk of exposed data, and to CISO Advantage, which maps controls against NIST CSF, CIS v8, Cyber Essentials Plus and NCSC CAF and turns that into a budget-aligned plan. Next-Gen SIEM, XDR powered by Secureworks, and MDR, with agentic AI in the hunt and Sophos analysts still accountable for investigation and response, are on the same stand. So is Firewall v23 early access, an AI firewall assistant, secure DNS, NDR and Workspace Protection.
A Detection Is Not an Operation
Janssen said operators move past fragmented alerts by turning detections, telemetry, intelligence and response into one cycle. Fusion pulls context from endpoint, firewall, identity, email, network, cloud, MDR, SIEM, XDR and third parties so the team acts from a shared view of risk. The cycle he described starts with X-Ops and cross-domain telemetry, moves to prioritization in Next-Gen SIEM and XDR, then to MDR for the hunt and the response, then to CISO Advantage, which converts the evidence into a roadmap a board, a regulator or an insurer can read. Human accountability stays. Existing tools stay.
The same limit is already on the record. In Security Guys News coverage of perimeter response, Jamie Mortensen, spokesperson at Spotter Global, said in written comments to Security Guys News: "Rapid automated threat response depends on two things: early detection and sufficient integration to enable automated mitigation." Detection without that integration is an alert. It is not a closed action.

HANSA-FLEX Closed the Night Shift. It Did Not Publish a Number
Before the project, Janssen said, HANSA-FLEX AG had a high level of shadow IT, no consistent 24/7 monitoring, and a fragmented set of Microsoft and third-party tools. Incidents were detected late and took time to handle. The company moved to Sophos MDR Complete, network detection and response, email advanced and firewall, managed through Fusion. Janssen said it now monitors endpoints and events on one dashboard, has 24/7 protection with escalation paths, and uses automation in incident response, which reduced the burden on internal teams. Reporting is simpler. Implementation did not disrupt operations. He said response improved and administrators were freed for strategic work. He did not give a detection-time cut, an incident count, or a headcount change.
A shared dashboard does not, by itself, make the cycle repeatable. The HANSA-FLEX account shows a night shift that was missing and a stack that was split. It does not show how many alerts still reach a person, or how often the MDR analyst overrides the agent. Until that ratio is on the record, a faster attack is still landing on a team that can see more and has not proved it can close the same case the same way twice.





