<p>Sophos is strengthening its firewall platform around a principle that network security vendors have historically struggled to deliver: customers should be able to verify that protective controls are working, not simply trust that they exist.</p><p>In a new Secure by Design update, the company described changes made after reviewing attacks against internet-facing edge devices. One important lesson concerned accounts that had never completed multifactor authentication enrollment. If an attacker guessed the password for an unused account, the attacker could potentially become the first person to register an authentication factor.</p><h2>Closing the first-use authentication gap</h2><p>Sophos redesigned that process so enrollment information is delivered through email instead of being displayed directly in the user portal. The codes expire after 24 hours, requiring someone to demonstrate control of the associated mailbox before completing enrollment. Dynamic login lockouts and MFA protection for SSH access are also under development.</p><p>The company has expanded behavioral detection across its XGS firewall appliances through the Sophos Linux Sensor. This capability looks for post-exploitation activity such as interactive shells, reverse shells and command-and-control traffic. Detection rules can be updated independently of full firmware releases, allowing protections to change more quickly when new attacker behavior is identified.</p><h2>Making patch status visible</h2><p>Sophos says more than 99 percent of customer firewalls receive its automatic hotfixes, but administrators previously had limited ways to confirm that a specific fix was present. Hotfix status is now visible through the firewall interface, logs, email notifications and centralized reporting. Scheduled firmware updates managed through Sophos Central are expected to become available in August 2026.</p><p>The company is also using an internal agentic vulnerability-hunting platform to test firewall source code and physical appliances inside an isolated laboratory. Engineers and red-team specialists supervise the models, while every action is recorded for review.</p><h3>What administrators should do</h3><ul><li>Confirm that management and user portals are not unnecessarily exposed to the internet.</li><li>Review dormant and synchronized directory accounts.</li><li>Verify hotfix and firmware status across every deployed appliance.</li><li>Forward firewall logs to protected external storage.</li><li>Prepare procedures for collecting forensic evidence after a suspected compromise.</li></ul><p>In my view, the most significant development is not any single control. It is the move toward measurable security. Firewalls are critical trust boundaries, and vendors should provide customers with patch evidence, useful telemetry and practical forensic capabilities. That level of transparency should become an expected purchasing requirement across the network security market.</p>