Skip to content

MDR policies

Find out more about the policies that govern how Sophos MDR handles customer-initiated penetration testing and which response actions the MDR team can take on your behalf.

  • MDR PenTest Policy


    See our expectations for how Sophos MDR handles customer-initiated penetration testing, including notification, frequency, and collaboration requirements.

    MDR PenTest Policy

  • MDR Response Action Policy


    See the response actions Sophos MDR can take across endpoint, network, identity, and email to investigate, contain, and disrupt threats.

    MDR Response Action Policy