So the consensus seems to be that Firepower is the "enterprise" choice, while Sophos is more SMB-friendly. I'm inherently suspicious of that dichotomy, especially when the team managing it is a handful of generalist network engineers with no 24/7 SecOps rotation.
Let's frame the real question: which system fails more gracefully when you're not staring at its dashboards all day? I've seen too many shiny consoles that turn into a blizzard of uncorrelated alerts the moment you look away.
Firepower's integration with the rest of Cisco's ecosystem is often touted as a killer feature. But is that a benefit or a lock-in? If your team already lives in CLI for switches and routers, does the FMC's complexity become a net negative? The resource overhead, both in hardware and mental load, for the full suite (FMC, FTD) is non-trivial. You're not just managing a firewall; you're managing a management platform.
Sophos sells on simplicity and a unified agent. That's attractive for a small team. But I've dug into their published threat detection rates, and the methodology is... let's say, marketing-grade. Have you ever tried to get a straight answer on their false positive rate under real, messy network traffic? Exactly.
For a team of five covering everything from VLANs to VPNs to user support, the primary metric shouldn't be the Gartner quadrant. It should be: which one requires the least weekly babysitting to avoid either a) blocking legitimate business traffic, or b) silently turning into an expensive passthrough device after a bad update? I'm not convinced the usual review sites measure that.
Data skeptic, not a data cynic.
That "blizzard of uncorrelated alerts" is exactly the problem. The question of which fails more gracefully is the right one. In my experience with both, Sophos will often fail closed, blocking traffic that's ambiguous, while Firepower's complex policy layers can fail open in subtle, audit-log-only ways if not meticulously tuned.
You're right to question the lock-in aspect. The Cisco ecosystem integration becomes a cost multiplier: you need Smart Licensing, a stable FMC VM, and compatible Talos feeds just to keep the baseline. For a team living in CLI, the FMC isn't just another GUI; it's a separate appliance with its own failure domain and upgrade cadence that dictates your security posture.
On threat detection rates, most vendor benchmarks are useless. The real metric for a small team is time-to-diagnosis. Can your engineers, after being paged at 3am, trace an alert from the firewall log to a specific user or host within five minutes using tools they already have? Sophos often wins there by being a single pane, even if that pane is sometimes overly optimistic.
Instrument everything.