Sophos has acquired Capsule8, a pioneer of runtime visibility, detection and response for Linux production servers and containers covering on-premise and cloud workloads.

Founded in 2016, Capsule8 is privately held and headquartered in New York.

“Sophos already protects more than two million servers for over 85,000 customers worldwide, and the Sophos server security business is growing at more than 20% per year,” says Dan Schiappa, chief product officer of Sophos. “Comprehensive server protection is a crucial component of any effective cybersecurity strategy that organizations of all sizes are increasingly focused on, especially as more workloads move to the cloud. With Capsule8, Sophos is delivering advanced, differentiated solutions to protect server environments, and expanding its position as a leading global cybersecurity provider.”

Capsule8 is dedicated to the development of Linux security and has established itself as a technology and thought leader in the market, with marquis customer wins and billings growth of 77% in the year to March 31, 2021. Driven by the dramatic growth in cloud platforms, Linux has become the dominant operating system for server workloads. Capsule8’s high-performance, low-impact design is ideal for Linux servers, especially those used for high-scale workloads, production infrastructure and storing critical business data.

“The main idea behind Capsule8 is that providing enterprise-grade security for Linux systems requires deploying components that are designed specifically for that environment. These components are more adept at making the trade-offs between security and performance when needed, to achieve the desired levels of resilience and protection,” says Fernando Montenegro, principal research analyst with 451 Research, part of S&P Global Market Intelligence, in reference to Capsule8’s solutions.

“As organizations move to embrace concepts such as cloud-based delivery and DevOps, the underlying compute environments shift noticeably toward Linux as a frequent execution environment. For security teams, often more familiar with Windows-centric concepts, this represents a potential challenge – there are different demands, concepts and practices for Linux. This is the space that Capsule8 aims to address with its endpoint security offering, combining an architecture optimized for Linux with more features aimed at enterprise security and IT operations teams.”

Sophos is integrating Capsule8 technology into its recently launched Adaptive Cybersecurity Ecosystem (ACE), providing powerful and lightweight Linux server and cloud container security within this open platform. Sophos will also feature Capsule8 technology in its Extended Detection and Response (XDR) solutions, Intercept X server protection products, and Sophos Managed Threat Response (MTR) and Rapid Response services. This will further expand and enhance Sophos’ data lake and deliver continuous, fresh intelligence for advanced threat hunting, security operations and customer protection practices.