Sophos GSE · Partner enablement

Partner Future-State Journey

v2 · working draft

Work through the partner discovery one stage at a time — capture what you learn, model the money, and produce a tailored takeaway. One vendor. One platform. One journey.

⚠ Indicative model for field conversations. The pricing fields are editable assumptions, not official Sophos or partner pricing — set each to the partner's real economics before sharing. Framework mapping is indicative, not a formal audit.
1Partner profile
2Current state
3Future state
4Revenue levers
5Outcome & takeaway
1 · The partner
Who you're working with, and the size of their book of business today.
Notes Discovery / interview notes
What are they doing today? What did they tell you in the meeting? These flow into the final takeaway.
2 · Where they are now
Place the partner's customers on the maturity journey today. Source: Sophos "Meet customers where they are."
Notes Current-state observations
Gaps, tooling, what's working / not, where their customers get stuck.
3 · Where we take them
The target maturity stage you're aligning them toward.
Notes Future-state / agreed direction
The plan you discussed — what good looks like for them, sequencing, any commitments.
4 · Revenue levers
Toggle what to model and set attach %, sell and cost to the partner's real economics. Currency: AUD.
24x7 SOC via Sophos MDRper endpoint / mo
NG-SIEM (retention + compliance)per endpoint / mo
Penetration testingper customer / yr
Security retainer (vCISO / DFIR)per customer / mo
Notes Commercial assumptions
Partner's real pricing/margins, why these attach rates, anything to revisit.
5 · The outcome
The journey, in dollars and in maturity. Review it, add a closing note, then export the takeaway.

The opportunity, in dollars

New monthly recurring revenue
across the modelled levers
New annual revenue
recurring × 12 + annual services
New annual gross margin
sell − cost, partner-kept
LeverBasisUnitsMonthly revenueMonthly margin

Maturity journey

Where the partner's customers sit today, and the target.

Framework coverage

What the modelled Sophos stack contributes against common frameworks (indicative, not a formal audit).
CapabilityEssential EightCIS ControlsISO 27001NIST CSF
Sophos MDR
24x7 detect & respond
Supports monitoring & ML8 detection/response maturity 8 Audit log mgmt · 13 Network monitoring · 17 Incident response A.5.7 Threat intel · A.5.24–.28 Incident mgmt · A.8.15–.16 Logging & monitoring DETECT · RESPOND · RECOVER
NG-SIEM
retention + correlation
Centralised event logging & retention 8 Audit log mgmt (collection & retention) · 13 Monitoring A.8.15 Logging · A.8.16 Monitoring activities DETECT (continuous monitoring) · IDENTIFY (asset/log visibility)
MDR + NG-SIEM
combined
Strong across the monitoring/response controls; pairs with E8 patching/backup controls the partner still owns Materially advances Controls 8, 13, 17 Covers the detect/respond/logging clauses; supports certification roadmap Lifts DETECT + RESPOND + RECOVER toward Optimized

Why it lands — for both sides

For the partner: recurring revenue and margin uplift (above), stickier customers, a clear up-sell path instead of fixed packs that stall, and a vendor-backed story to lead with.

For the customer: 24x7 cover they can't staff alone, faster containment (measurable MTTD/MTTR), compliance and audit evidence, and a single-vendor, single-platform journey rather than a tool sprawl.

Notes Closing summary / next steps
The wrap-up you want on the takeaway — agreed actions, owners, timing.
Sophos Confidential · Partner Future-State Journey v2 · indicative figures, set to the partner's real economics before use. Your inputs are saved locally in this browser.