# Sophos Sweeps 5 Gartner Awards as AI Agents — July 2026

> Sophos sweeps five Gartner Customers Choice awards while Bitdefender slashes GravityZone pricing by 50 percent to pressure European mid-market rivals.

*Endpoint Security & Cybersecurity · general · August 8, 2026*

Sophos achieved a rare sweep of five Gartner Customers’ Choice awards while launching a next-gen SIEM with 10-year data retention to target regulated industries. Simultaneously, Bitdefender intensified pricing pressure in Europe with 50% discounts on GravityZone, and CrowdStrike overhauled its core messaging to position as an 'Agentic Security Platform.'

## Key Findings

- Sophos secured the 2026 Gartner Peer Insights Customers’ Choice for Email Security, completing a sweep across five core security markets — establishing a dominant mid-market position.
- Bitdefender increased GravityZone discounts to 50% in DACH and Romania — signaling an aggressive push for new logos against US-based rivals.
- CrowdStrike launched 110 new advertising campaigns this period, maintaining a volume 3.7x higher than its historical average to fuel international expansion.
- Huntress expanded its EMEA reach through distribution deals with Giacom and MSP Nordics — providing 6,000+ MSPs with streamlined access to its MDR platform.
- SentinelOne research demonstrated an 86% token reduction in OpenAI compaction testing — validating the cost-efficiency of its agentic security workflows.

## Sophos vs CrowdStrike in 2026

Sophos is aggressively challenging enterprise incumbents by securing top-tier analyst validations and expanding its technical stack. The company was named a Leader in the 2026 IDC MarketScape for Worldwide Midmarket MDR and earned the Gartner Peer Insights Customers’ Choice for Email Security with a 4.8/5.0 rating. This award marks a rare sweep across five categories, including EPP, MDR, and Firewall. To further its enterprise appeal, Sophos shipped a next-gen SIEM featuring 10-year data retention and a per-user pricing model, a strategic departure from traditional volume-based ingestion costs that often lead to billing unpredictability.

CrowdStrike is countering this momentum by scaling its global reach and repositioning its platform around AI autonomy. The vendor detected 110 new ad campaigns this period, a volume 3.7x higher than its historical average, targeting markets in Canada and Spain. CrowdStrike also updated its homepage messaging to define itself as the "Agentic Security Platform," focusing on the transformation of the SOC through AI-powered agents. For a deeper look at how these narratives compare, see our analysis of [CrowdStrike vs Sophos](/compare/crowdstrike-vs-sophos). While CrowdStrike maintains a perfect 5.0 rating trajectory, internal feedback from 15 employee reviews highlights a "pressure cooker" environment and burnout risks that could impact long-term service delivery.

## How Bitdefender is using pricing and sovereignty to win

Bitdefender is utilizing a dual-track strategy of aggressive discounting and geopolitical positioning to displace US-based rivals in Europe. The company launched a Sovereign Acceleration Program specifically designed to help EU organizations transition to security stacks hosted entirely within the union, offering contract buyouts to lure customers away from CrowdStrike and Microsoft. This move is supported by search advertising revealing a 50% discount on GravityZone subscriptions in the DACH region, a significant increase from the 30% baseline observed in previous months. This aggressive pricing is a direct response to the [Bitdefender and Sophos AI claims](/reports/bitdefender-sophos-claims-52-ai-july-2026) currently circulating in the mid-market.

Despite this growth push, Bitdefender is also seeking to monetize its existing base through new paid services. The launch of "Setup & Go" ($224.99) and "Essential Tips" ($54.99) represents a shift toward charging for SMB onboarding and training. This move aims to reduce churn caused by configuration complexity while adding high-margin professional services revenue. However, Bitdefender must balance these costs against competitors like ESET, which currently maintains a 4.0 rating but is seeing a declining trajectory in user satisfaction due to licensing workflow friction.

## Why companies are switching from SentinelOne to Huntress

Review data from this period shows a distinct switching flow, with 4 verified instances of users moving from SentinelOne Singularity Endpoint to Huntress. This migration is driven by Huntress's focus on the MSP channel and its human-led SOC model. Huntress recently expanded its EMEA footprint through distribution agreements with Giacom, granting it access to over 6,000 MSPs. The company is also aggressively hiring for Identity and SOC Experience roles, with director-level salaries reaching $290,000, signaling a rapid roadmap execution for its Managed ISPM and ITDR capabilities. You can track these shifts in our [Huntress Signal Spotlight](/reports/signal-spotlight-huntress).

SentinelOne remains a formidable technical competitor, particularly in AI efficiency. Its SentinelLABS unit reported an 86% token reduction in OpenAI compaction testing, which significantly lowers the operational costs of running long-term AI security agents. Furthermore, SentinelOne is positioning for federal dominance by submitting a NIST proposal for AI workload security standards, targeting the $600 million US federal AI infrastructure budget. While SentinelOne maintains a stable 5.0 rating, Huntress is seeing an improving trajectory, bolstered by its reputation for "persistent foothold" detection that traditional antivirus tools often miss.

## Malwarebytes and ESET market activity

Malwarebytes is focusing on high-efficacy remediation and consumer-to-business cross-pollination. The company documented the GigaWiper Trojan this period, reinforcing its status as a threat intelligence specialist. It also executed a high-volume trial acquisition strategy by sponsoring a panel at San Diego Comic-Con, offering 1-year licenses to attendees. However, Malwarebytes is seeing a declining rating trajectory (4.68), with users citing false positives as a recurring pain point. ESET, meanwhile, is maintaining its stronghold in Central Europe with a 110-ad campaign in Czechia and a framework agreement with the Dutch Central Government, positioning itself as a European alternative for critical infrastructure.

Other competitors remained relatively quiet or focused on niche updates. WithSecure released Elements Agent for Mac 26.3 to fix application blocking bugs, while Webroot highlighted a £10,000 cloud cost recovery for an MSP partner to showcase the financial benefits of its CSP model. Cybereason and IndustryLens-6 showed limited data this period, with Cybereason maintaining a quiet profile following its parent company LevelBlue's partnership with SentinelOne.

## Key Facts

- Sophos Named 2026 Gartner Peer Insights Customers’ Choice for Email Security (2026-08-08) — [Source — Sophos](https://www.sophos.com/blog/sophos-gartner-email)
- Sophos Ships Next-Gen SIEM with 10-Year Data Retention and Rebuilt XDR Platform (2026-08-08) — [Source — Sophos](https://www.msspalert.com/news/sophos-fusion-brings-endpoint-siem-identity-and-mdr-into-one-security-system)
- Sophos Joins Anthropic's Project Glasswing to Automate Vulnerability Discovery (2026-08-08) — [Source — Sophos](https://www.sophos.com/en-us/blog/sophos-joins-anthropics-project-glasswing)
- ESET [Current State]: Framework Agreement Signed with Dutch Central Government (2026-08-08) — [Source — ESET](https://www.eset.com/us/about/newsroom/company/the-dutch-central-government-signs-a-framework-agreement-with-european-cybersecurity-provider-eset/)
- CrowdStrike [Current State]: Scaled Advertising Library with 110 New Campaigns Detected (2026-08-08) — [Source — CrowdStrike](https://adstransparency.google.com/advertiser/AR13642683652595777537?region=anywhere)
- CrowdStrike Leverages Salesforce Partnership to Highlight Critical SaaS Security Gaps (2026-08-08) — [Source — CrowdStrike](https://www.linkedin.com/posts/crowdstrike_your-organization-probably-relies-on-dozens-activity-7481421991636447232-Rppv)

## Frequently Asked Questions

### What were the major Sophos product updates and awards in July 2026?

Sophos launched a Next-Gen SIEM featuring 10-year data retention and a rebuilt XDR platform. During this period, the company was also named a 2026 Gartner Peer Insights Customers’ Choice for Email Security and a Leader in the IDC MarketScape for Worldwide Midmarket MDR.

### Why are companies switching to Bitdefender in the DACH region right now?

Bitdefender is exerting significant pricing pressure by offering a 50% discount on its GravityZone platform specifically for the DACH and Romania markets. This aggressive marketing campaign is designed to capture market share from premium-priced competitors during the current cycle.

### How are Sophos and SentinelOne implementing AI and automation in 2026?

Sophos has joined Anthropic's Project Glasswing to automate vulnerability discovery, while SentinelOne recently reported an 86% token reduction in OpenAI compaction testing. These developments indicate a dual focus on automated threat research and optimizing the cost-efficiency of LLM-driven security operations.

### What is the significance of the CrowdStrike and Cato Networks partnership?

CrowdStrike and Cato Networks have partnered to unify SASE (Secure Access Service Edge) and endpoint telemetry. This integration allows for a more cohesive security architecture by blending network-layer visibility with device-level data.

### What are the latest strategic hiring trends for Huntress in mid-2026?

Huntress is currently prioritizing strategic hiring for roles with specific expertise in Identity and Security Operations Center (SOC) experience. This shift suggests a product roadmap expansion toward identity-centric security and enhanced managed detection capabilities.

### Which cybersecurity vendors received industry recognition between July and August 2026?

Sophos, ESET, SentinelOne, and Malwarebytes all secured industry awards during this period. Sophos was particularly prominent, sweeping five Gartner and IDC accolades, including recognition for Email Security and Midmarket MDR.

---

Source: IndustryLens — automated competitive intelligence. Read online: https://industry-lens.com/reports/bitdefender-sophos-sweeps-5-gartner-august-2026

Competitors monitored: Bitdefender, CrowdStrike, Cybereason, ESET, Huntress, IndustryLens-6, Malwarebytes, SentinelOne, Sophos, Webroot, WithSecure.
