Sophos has expanded its Managed Risk service with the launch of Internal Attack Surface Management (IASM), leveraging technology from Tenable to strengthen cyber defence against hidden vulnerabilities.
The enhancement provides organisations with comprehensive visibility into both internal and external weaknesses, addressing blind spots that have led to ransomware breaches. According to the Sophos State of Ransomware 2025 report, 40% of affected organisations were hit due to unidentified exposures.
“With Sophos Managed Risk, organisations gain an attacker’s-eye view to identify and prioritise remediation of risks before adversaries can exploit them,” said Rob Harrison, Senior Vice President of Product Management at Sophos.
Key features of IASM include:
- Unauthenticated internal scanning to mimic external attacker behaviour
- AI-powered prioritisation of vulnerabilities
- Automated vulnerability scanning using Tenable Nessus
- A unified service combining both external and internal assessments
The IASM update is available immediately for all existing and new Sophos Managed Risk customers at no additional cost, with scans deployed via the Sophos Central console.
Sophos says its integrated approach, powered by Tenable and backed by its Managed Detection and Response (MDR) team, enables rapid identification and mitigation of high-risk vulnerabilities, including open ports, misconfigurations and exposed services.




