コンテンツに移動

Turning Network Data into Action with Network Map and Live Discover Queries

Network Map and Live Discover queries give your customers clearer network visibility, searchable device context, and a faster path from investigation to response.

Barbara Hudson

Sophos Fusion, the Sophos AI-Native Cybersecurity Defense System, elevates defenses by connecting control points so they can share insights and work together. Network Map and Live Discover queries bring that story to life, giving you a practical example for customer conversations and a strong cross-sell opportunity.

When topology, device, and connection data sit in different views, it can be difficult to see what’s connected to the network and quickly investigate anything unexpected. Network Map and the new Live Discover queries for Sophos Switch and Sophos Wireless bring that information together, giving your customers a clearer picture of their wired and wireless environment and a faster path from investigation to response.

The Network Map shows how Sophos switches, AP6 Series access points, Sophos firewalls, and connected devices fit together across the network. Live Discover queries take that visibility a step further, helping administrators investigate network activity using data already available in the unified context lake.

These capabilities clearly demonstrate the value of having multiple network control points within Sophos Fusion. Built on the Sophos AI-Native Cybersecurity Defense System architecture, Sophos Fusion connects products, services, data sources, and analysts so defenses can share context and respond as one.

From network management to cybersecurity insight

Network Map gives administrators a live visual view of managed network infrastructure in Sophos Fusion, the evolution of Sophos Central. Instead of piecing together device lists, port information, or manually maintained diagrams, administrators can see switch-to-switch, switch-to-access-point, and switch-to-firewall connections in one place. They can search for devices, drill into switch ports, view connected endpoints where available, and understand topology across an individual network or the wider account.

 

turning-network-data-into-action-image01.png


Note: In this initial release, Network Map focuses on Sophos Switch and Sophos Wireless environments in Sophos Fusion. Further firewall topology visualization is planned for a later release.

Live Discover queries go beyond a snapshot of the current device state by providing on-demand access to connection-event data in the Sophos Fusion unified context lake. Ready-made queries can be run as-is, edited, or used as starting points for custom queries.

 

turning-network-data-into-action-image02.png


For AP6 Series access points, administrators can review all Wi-Fi clients, find a client by MAC address, and explore connection history, including first-seen dates, associated users, access point details, SSID, band, and signal strength. For Sophos Switch, queries can list reachable clients, return the latest session details, and map a device to a specific switch and port, with timestamps, connection status, and estimated session duration. Together, these capabilities help uncover common access-layer blind spots, such as new or unauthorized devices, clients using an unexpected SSID, or devices connected to the wrong switch port.

Active Threat Response, a Synchronized Security™ capability, uses API-triggered responses to automatically isolate compromised or unauthorized devices. Using context from Live Discover, administrators can block a device at the wired or wireless access layer, helping prevent threats from moving laterally across the network or unauthorized users from gaining further access.

How this helps to strengthen defenses

  • See the network clearly: Network Map helps customers understand how firewalls, switches, access points, and connected devices fit together, making infrastructure easier to manage and troubleshoot.
  • Connect network context to investigation: Live Discover queries for AP6 and Sophos Switch help administrators ask targeted questions of wireless and wired network data.
  • Respond with better context: Query-driven visibility can help identify new or unexpected devices, unusual connection patterns, clients appearing where they shouldn’t, or wired devices that may need investigation.
  • Act from the network edge: Active Threat Response turns investigation into action by enabling AP6 access points and Sophos switches to block potentially compromised devices at the access layer, helping prevent lateral movement across wired and wireless networks.

Together, these capabilities turn APs and switches into network control points within Sophos Fusion. Live Discover surfaces device details, context, and connection history, while Active Threat Response enforces the response at the access layer. This helps the Defense System see what’s connected, add network context to an investigation, and respond when a device should no longer be trusted.

A stronger story for Sophos partners

The “why Sophos” story is simple: customers are not just buying a switch or an access point. They’re extending the Sophos Defense System to the wired and wireless edge.

In firewall-led opportunities, Network Map and Live Discover show how Sophos Switch and AP6 add visibility, investigation, and response value within Sophos Fusion. In wireless- or switch-led opportunities, the same capabilities help position Sophos Firewall and the broader portfolio as logical next steps by connecting network insight to response and helping isolate compromised devices before threats can move laterally.

Your talk track

Sophos-managed network infrastructure gives customers more than centralized configuration. It shows what’s connected, provides queryable data for investigation, and adds network control points that can support automated response. With query packs for both AP6 and Sophos Switch, customers can move from asking “Which device connected, where, and when?” to blocking a potentially compromised device through Active Threat Response.

That makes Sophos AP6 access points and Sophos switches easier to position in security-led conversations. They help close visibility gaps at the network edge and strengthen the customer’s defenses, while keeping management, investigation, and response aligned in Sophos Fusion.

For you, this opens the door to broader customer conversations by positioning AP6 access points and Sophos switches as ways to extend visibility, operational context, and network control across the customer’s Defense System.

Summary

The Network Map and Live Discover queries connect three capabilities that are often separated: network topology visibility, investigation data, and access-layer response. For your customers, that can simplify operations and shorten the path from identifying an unexpected device to blocking a potentially compromised device with Active Threat Response. 

It provides you with a broader value story: Sophos AP6 access points and Sophos switches can serve as network control points within Sophos Fusion, the AI-Native Cybersecurity Defense System.

Release notes on the Sophos Community