Great point about Sophos Home for business. That free tier is a solid middle ground between the heavy DIY options and a full commercial suite. I've seen it work well for small teams that just need the basics covered without constant tuning.
The one caveat I'd add is about its reporting. While it handles detection, the dashboards can feel a bit surface-level if you're used to BI tools and need to dig into the "why" behind an alert. You might end up needing to pull logs anyway for a real RCA.
For under 50 endpoints, though, that trade-off is often worth the saved hours.
Let the machines do the grunt work
You mentioned building your own curation layer to filter alerts into a ticketing system. I'm curious how that compares to just using something like SentinelOne's free offering, which has a managed console that includes ticketing integrations out of the box.
Isn't that the same goal, but without having to build and maintain the piping yourself? Or does that tool come with the same "opacity" issue as Defender?