Across 20 companies in Content Asset, 16 in Partnership, 16 in Product Update, and 15 in Positioning, vendors are pushing research, alliances, product launches, and rebrands. SentinelOne, Sophos, and Barracuda lead with threat research, while ConnectWise, ESET, and CrowdStrike expand partnerships. Product updates from N-able, Kaspersky, Malwarebytes, CrowdStrike, and ESET target managed detection and AI security.
20
Content Asset moves (companies, 90d)
IndustryLens
16
Partnership moves (companies, 90d)
IndustryLens
16
Product Update moves (companies, 90d)
IndustryLens
15
Positioning moves (companies, 90d)
IndustryLens
Last reviewed · 20 tracked moves cited below, each linked to its source
This cross-category view examines how B2B software companies are acting right now across Content Asset, Partnership, Product Update, and Positioning, for cybersecurity buyers and IT security teams. The buckets cover 20, 16, 16, and 15 companies respectively, with named moves from SentinelOne, Sophos, Barracuda, N-able, Cynet, ConnectWise, ESET, CrowdStrike, Kaspersky, Malwarebytes, Webroot, WithSecure, and Bitdefender.
See the live vendor ranking
We rank the endpoint-security vendors we track on signal velocity, surface breadth and strategic threat density — refreshed as new reports publish, from 90 days of cited primary sources. See who’s moving fastest right now.
Content Asset: threat research and readiness reports
SentinelOne published technical research detailing $3.4B in Iranian IP theft and 500+ Medusa ransomware victims, giving defenders concrete adversary tradecraft to map against. Sophos released its Active Adversary Report 2026, identifying identity attacks as the primary breach vector, which shifts detection priorities toward credential abuse. Barracuda published research on AI exploitation and Microsoft Copilot vulnerabilities, highlighting how generative AI surfaces are being probed by attackers.
N-able released its 2026 State of the SOC Report based on 900,000 alerts, offering a volume-grounded view of analyst workload and triage patterns. Cynet issued its 1H 2026 Cyber Hostility and Global AI Security Readiness Reports, tying geopolitical hostility to AI readiness gaps. Together these assets give buyers external evidence for board conversations and control prioritisation.
- SentinelOne: SentinelOne Technical Research Details $3.4B Iranian IP Theft and 500+ Medusa Ransomware Victims
- Sophos: Sophos Active Adversary Report 2026 Identifies Identity Attacks as Primary Breach Vector
- Barracuda: Barracuda Publishes Research on AI Exploitation and Microsoft Copilot Vulnerabilities
- N-able: N-able Releases 2026 State of the SOC Report Based on 900,000 Alerts
- Cynet: Cynet Releases 1H 2026 Cyber Hostility and Global AI Security Readiness Reports
Partnership: Channel, Cloud, and AI alliances
ConnectWise partnered with Insight to expand its presence in US IT departments, targeting mid-market and enterprise IT teams through a larger services footprint. ESET launched PRIVATE Scanning Solutions on AWS Marketplace (August 19, 2026), making its scanning capabilities procurable through cloud committed spend. Sophos integrated the Nozomi Vantage OT Security Platform into its Sophos Fusion Architecture, extending visibility from IT into operational technology.
Sophos also partnered with OpenAI to deliver frontier AI models to its global MSP channel, embedding generative AI into managed service delivery. CrowdStrike holds founding membership in the Open Secure AI Alliance, positioning itself in cross-industry AI security governance. These moves show vendors using partnerships to reach new buyers and to co-develop AI and OT coverage.
- ConnectWise: ConnectWise Partners with Insight to Expand Presence in US IT Departments
- ESET: ESET Launches PRIVATE Scanning Solutions on AWS Marketplace (August 19, 2026)
- Sophos: Sophos Integrates Nozomi Vantage OT Security Platform into Sophos Fusion Architecture
- Sophos: Sophos Partners with OpenAI to Deliver Frontier AI Models to Global MSP Channel
- CrowdStrike: CrowdStrike [Current State]: Founding Membership in the Open Secure AI Alliance
Product Update: managed Detection, DRaaS, and AI security
N-able launched Cove DRaaS as a fully managed infrastructure offering, adding disaster recovery to its managed services stack. Kaspersky shipped an update for Managed Detection and Response (MDR) with leaked credential correlation, helping analysts connect credential exposure to active incidents. Malwarebytes released its full Malwarebytes for Windows suite on the Microsoft Store, simplifying deployment for Windows-centric organisations.
CrowdStrike launched Falcon AIDR for Copilot Studio and Claude Code, extending detection and response to AI coding assistants and copilots. ESET launched an AI Security Suite featuring conversation and agent protection, addressing risks in AI-mediated workflows. These updates concentrate on operationalising AI security and managed recovery for lean security teams.
- N-able: N-able Launches Cove DRaaS Fully Managed Infrastructure Offering
- Kaspersky: Kaspersky ships update for Managed Detection and Response (MDR) with leaked credential correlation
- Malwarebytes: Malwarebytes releases full Malwarebytes for Windows suite on Microsoft Store
- CrowdStrike: CrowdStrike [Current State]: Launch of Falcon AIDR for Copilot Studio and Claude Code
- ESET: ESET launches AI Security Suite Featuring Conversation and Agent Protection
Positioning: Identity, Platform, and paradigm shifts
ConnectWise redefined its corporate identity to focus on unified automation and predictive IT, signalling a move beyond traditional remote monitoring and management. Sophos rebranded its Sophos Central Management Console as the AI-native Sophos Fusion Platform, aligning its console narrative with AI-native operations. Webroot integrated its Business Security Portfolio under the OpenText Core brand, consolidating product identity under a parent portfolio.
WithSecure repositioned its Elements Platform to target machine-speed AI attack windows, framing defence around automation velocity. Bitdefender will challenge detection-first security paradigms at Black Hat USA 2026, staking out a thought-leadership position against incumbent detection models. These positioning moves aim to reframe buyer evaluation criteria around AI-native and platform-level outcomes.
- ConnectWise: ConnectWise Redefines Corporate Identity to Focus on Unified Automation and Predictive IT
- Sophos: Sophos Rebrands Sophos Central Management Console as AI-Native Sophos Fusion Platform
- Webroot: Webroot Business Security Portfolio Integrated Under OpenText Core Brand
- WithSecure: WithSecure Repositions Elements Platform to Target "Machine-Speed" AI Attack Windows
- Bitdefender: Bitdefender to Challenge "Detection-First" Security Paradigms at Black Hat USA 2026
Track every endpoint security vendor in one weekly briefing. £149/mo, published.
IndustryLens monitors pricing changes, product launches, ads, reviews, social and hiring signals across every vendor in this category, delivered weekly with every claim cited to its source. No demo gate.
Latest analysis
Recent IndustryLens reports in the endpoint security category.
- WithSecure: Elements AI Claims 60x — September 2026
WithSecure's WithSecure Elements AI is claimed by the company to deliver a 60x increase in security operations throughput, according to the signal. For CI and marketing leaders, this is a vendor…
- CrowdStrike Falcon Flex Launch — Aug 2026 — September 2026
CrowdStrike introduced Falcon Flex, an annual module swapping model for enterprise portfolios, and expanded its AI-driven security platform with NVIDIA Nemotron 3.5 Lightning integration, positioning…
- Sophos Sweeps 5 Gartner Awards as AI Agents — July 2026
Sophos achieved a rare sweep of five Gartner Customers’ Choice awards while launching a next-gen SIEM with 10-year data retention to target regulated industries. Simultaneously, Bitdefender launched a…
- CrowdStrike and Cerebras Partner to Optimize AI Threat Detection Performance — July 2026
CrowdStrike is experiencing a pattern of displacement for Symantec and SentinelOne according to recent reviews. By partnering with Cerebras and Cato Networks, CrowdStrike is simultaneously expanding…
- Malwarebytes Launches 50% Discount Across Tiers
Malwarebytes has launched a significant 50% discount across its entire product spectrum, targeting personal, family, and small business tiers simultaneously. This aggressive pricing move signals a…
- Sophos Sweeps G2, Gartner and IDC Validation While Embedding OpenAI Models
Sophos is pairing frontier-model AI integration with an unusually broad sweep of third-party validation. Logged signals show OpenAI models embedded directly into MDR and endpoint defence workflows,…
See how IndustryLens stacks up, free
IndustryLens is a competitive intelligence platform built for B2B SaaS, covering pricing pages, changelogs, ads, reviews, social, Reddit, hiring and news, in one weekly cited briefing. Published pricing. No demo gate.
Endpoint Security Software 2026: frequently asked questions
How should we evaluate threat research from SentinelOne, Sophos, and Barracuda?
Use the research as evidence for control gaps: SentinelOne's Iranian IP theft and Medusa ransomware findings, Sophos's identity attack focus, and Barracuda's AI exploitation and Copilot vulnerability research can inform detection engineering and identity hardening priorities. Cross-check vendor claims against your own telemetry before changing controls.
What do partnerships like ConnectWise with Insight, ESET on AWS Marketplace, and Sophos with OpenAI mean for procurement?
They can simplify procurement through existing cloud marketplaces and service providers, and they can expand coverage into OT and AI. Assess whether the partnership changes support, data handling, or integration depth, and confirm that the combined offering meets your compliance and operational requirements.
Are product updates such as N-able Cove DRaaS, Kaspersky MDR credential correlation, and CrowdStrike Falcon AIDR ready for production?
Treat them as candidates for piloting: test DRaaS recovery objectives, validate credential correlation against your identity sources, and evaluate AI detection and response for Copilot Studio and Claude Code in a controlled environment. Confirm licensing, data residency, and integration with your existing SIEM and SOAR before broad rollout.
