We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Sophos Home consumer troubleshooting · Windows and macOS support, current known issues and release notes checked August 5, 2026

Sophos Home Not Working or Using High CPU: Safe Fixes

A scan using the processor for ten minutes, a Mac permission failure and a stopped Windows service are three different problems. This guide helps you identify which one you have, preserve protection and apply the narrowest current fix before reinstalling anything.

Sophos Home onlyNo magic CPU numberOne layer, one testReinstall last

Quick answer: save open work and note the process, time, active scan or update, protection state and exact trigger. Let a visible job finish when the machine remains responsive; restart once if an update requests it, then compare five to ten minutes of settled idle with the same safe action. Persistent idle load, `Service Failure`, a Mac update arrow or one repeatable application conflict each has a different branch below. Do not kill services, add broad exclusions or switch every protection off to make the fan quiet.

First confirm that you are troubleshooting Sophos Home

Sophos search results use similar names for products that do not share the same services or console. This page covers the Sophos Home consumer application installed from a Home account on Windows or Mac. It does not cover Sophos Firewall Home Edition, Sophos Central, business Endpoint, Server Protection or managed Intercept X. A command copied from an enterprise forum can target a service that does not exist in Home or is controlled by an administrator policy you do not have.

Open the local application and the browser dashboard reached from your own Home account. Record the product name, operating system, device name and version shown in About. The main Sophos Home review explains what the consumer product includes; this guide owns operational faults. If the device is a phone, use our Intercept X for Mobile review, because that free mobile app is not a seat in the Home dashboard and has different capabilities.

Check whether one device is broken or a Sophos service is unavailable

When several household computers lose dashboard access at the same time, check the current Sophos service-status page before repairing every endpoint. It lists Sophos Home, the Home Dashboard and the Home Support Portal as separate components. Save the incident time and region if an outage is shown, then avoid reinstalling a healthy local engine merely because a cloud surface is temporarily unavailable.

A green status page is not proof that your installation is healthy, and a dashboard message is not always live telemetry. During a Windows scan request, Sophos says the `offline` wording is static; if the endpoint is online, the job should start after a few seconds. Compare another device, ordinary internet access, the local shield and the dashboard's last activity. One computer with a service error while the other Home devices work belongs in the local branches below.

Measure the problem before changing protection

Save work, let startup settle and watch the same computer for five to ten minutes. On Windows, sort Task Manager by CPU and Disk; on Mac, sort Activity Monitor by % CPU and CPU Time. Record the process name, the local time, whether a scan or update is visible, the affected application and how quickly activity falls after that task ends. A screenshot without the clock and trigger is much less useful than one sentence such as “load begins when OneDrive opens this SharePoint folder and falls two minutes after I quit it.”

Repeat only one safe trigger. Do not run a full scan, a game, a large sync and an operating-system update at once, because the result cannot identify an owner. Check free disk space and temperature or thermal throttling when the whole machine is slow. Sophos's current system requirements warn that minimum-spec computers can show CPU or memory spikes during multi-file scans and automatic updates. Both platforms list 4 GB RAM as the minimum; Windows on ARM is unsupported, an SSD is strongly recommended, and Sophos recommends 8 GB RAM on Mac.

Choose the symptom before choosing the fix

“Sophos is not working” can mean six things, and each needs different evidence. Use the first row that matches what you can reproduce, not the most alarming result you saw in a forum. If two rows match, start with protection status and complete any pending update or restart before measuring performance again.

What you seeWhat to recordFirst safe branch
CPU/fan rises only during a visible scan or updateJob, duration, file/disk progress, recoveryLet bounded work finish; compare settled idle
High CPU while idle or during one app actionProcess, trigger, OS/app version, recoveryMatch the process and current known issue
`Service Failure` on WindowsExact message, updates, restart, other antivirusUse the official eight-service check
Scan stays at 0% or does not beginFast/Full scan, version, dashboard stateWait briefly, restart, update, check release notes
Mac shield shows arrow/vulnerable/action requiredmacOS, permissions, extensions, updater stateRepair the named permission or update gate
Browser, network save or one program becomes slowExact action, protection layer, repeatabilityUse the documented issue or one-layer A/B test
Five-step Sophos Home troubleshooting map from measurement to support logs
Our troubleshooting order keeps protection changes narrow: measure, match the component, isolate one layer, repair, then escalate with evidence.

The table deliberately puts reinstall outside the first action. A reinstall can repair incomplete components, but it also erases the state and timing that explain why the fault occurred. Finish the matching branch, recheck the original trigger and stop as soon as protection and ordinary use are healthy.

A visible scan or update can be busy without being broken

A full scan reads the entire selected file set and can spend longer on archives, developer trees, mail stores, backups or attached drives. Sophos's current Windows scan guide says a full scan can take time and suggests disconnecting external drives for the main run, then scanning them separately. Our Sophos scan and quarantine guide owns scan modes and exclusion mechanics; use it when the issue is file scope rather than an idle service.

There is no trustworthy universal “normal Sophos CPU” number. A current Cloudwards review observed its test PC move from roughly 10% to 35–40% during a scan, while older Tom's Guide and Comparitech reviews reported different impacts on different hardware and builds. Those figures demonstrate variability, not a threshold. Progress, duration, responsiveness and return to baseline matter more than comparing your laptop with somebody else's percentage.

Call it abnormal when load remains high after the visible job and startup activity end, the same safe action triggers it every time, protection changes state, or the machine cannot stay responsive. Record whether CPU, disk or memory is actually the constrained resource. A fast CPU paired with a nearly full hard drive may feel worse than a higher CPU percentage on an SSD, and changing antivirus settings will not repair failing storage.

Fix Windows “Service Failure” without leaving Tamper Protection off

Sophos's current Service Failure procedure says the message usually means one or more services stopped or did not install correctly. Common prerequisites are another resident security program, missing Windows updates, a pending restart after an upgrade or an incomplete installation. Finish supported Windows updates, restart once and remove another antivirus through that vendor's uninstaller before touching Sophos services.

The official Premium flow opens Sophos Home, then Help → Troubleshooting → advanced, and temporarily turns off Tamper Protection. In an administrator Services window, check these eight entries: HitmanPro.Alert service, Sophos Endpoint Defense, Sophos File Scanner, Sophos Health, Sophos MCS Agent, Sophos MCS Client, Sophos Network Threat Protection and Sophos System Protection. Start a listed service only when Sophos's procedure says it is stopped; do not change startup types, delete entries or import a business Endpoint service list.

Re-enable Tamper Protection immediately after the check and verify the local status. If a service will not start, record its exact Windows error and time rather than cycling it repeatedly. Sophos's next steps are removing another antivirus, using an administrator account and reinstalling through the current Home account. Persistent failure after a clean installation is a support case with logs, not an invitation to disable protection permanently.

Use the CertPolEng.dll exception only for the current network-save freeze

The live Sophos Home Known Issues page documents a narrow Windows symptom: the first save after boot to a remote or network location can make the computer unresponsive for several minutes, while later saves work until the next reboot. That pattern matters. It is not the same as a generally slow NAS, a full disk, bad Wi-Fi or a program that freezes on every local save.

For that exact pattern, Sophos currently gives the scan exception `C:\Windows\System32\CertPolEng.dll` and says a future update is planned. Treat the exception as a vendor workaround with a date, not a permanent tuning tip. Save the original state, add only the exact path through the supported exclusion interface, reproduce the first network save after a restart and remove the exception if it does not change that precise symptom.

Do not broaden the exception to System32, the network share or the whole project tree. Those locations contain far more than the component involved in Sophos's note. Re-check the live known-issues entry after endpoint updates, because a workaround can become unnecessary when the defect is fixed. If the freeze affects local saves or every network action, return to measurement instead of forcing this match.

A slow browser speed test may not mean slow browsing or downloads

Sophos's current known-issues note says HTTPS scanning can make browser-based speed-test results appear slow, while normal browsing and download performance should not be affected. Test the thing you actually care about: a known large download from a trustworthy source, the Windows Store Speed Test application, a video call or the work transfer that feels slow. One synthetic browser number is not enough evidence for disabling Web Protection.

If real daily activity is affected, run one brief controlled comparison with only Web Protection changed and the same server, connection and file. Re-enable it immediately and confirm the dashboard returns to protected. The Sophos Home Web Protection guide owns HTTPS filtering, Private Relay and website exceptions. Do not add a broad website allow list or turn off every protection layer because one speed-test site reports less throughput.

When Fast Scan stays at 0%, confirm version and actual reachability

A scan request can display static `offline` wording even when the computer is online; Sophos says an online endpoint should begin after a few seconds. Check the local shield, ordinary internet access and recent dashboard activity before deciding the device is unreachable. If the scan still does not start, note whether it is Fast Scan or Full Scan, save the time and restart once if an endpoint update is pending.

Sophos fixed a specific Fast Scan-stuck-at-0% issue in Windows Endpoint 2024.3.3, released in late 2025, and required a restart. That historical fix does not prove that every current 0% display has the same cause. Compare About with the live Sophos Home endpoint release notes, allow the current update to finish and preserve the exact version if the symptom repeats.

If Full Scan progresses but Fast Scan does not, include that contrast in the case. If neither begins and protection also says vulnerable or Service Failure, fix status first. Reinstall belongs after restart, current version, service/permission checks and evidence. Running the scan button dozens of times only creates duplicate requests and makes timing harder to read.

“Exploit mitigation is experiencing problems” is its own Windows fault

This Premium/Trial Windows message refers to the exploit component, not a generic CPU alert. Sophos's current exploit-mitigation recovery page lists an incomplete installation, an outdated operating system, System Restore removing components, an old Sophos build and conflicts with HitmanPro or another antivirus. Finish Windows Update, restart and let Sophos update before changing application rules.

Do not install a second copy of HitmanPro.Alert on top of Sophos Home or disable exploit protection indefinitely just to clear the banner. Record the exact message and whether another security tool is present. Our Sophos privacy and exploit guide explains what the Windows control protects and how narrow application exclusions differ from turning the component off for everything.

Stop ordinary troubleshooting when Windows blue-screens on boot

The current known-issues page documents `UNEXPECTED_KERNEL_MODE_TRAP (0x7F)` with some Nvidia drivers and names Nvidia version 582.11 as Sophos's current fix. Treat that version as a dated vendor note, verify the live Sophos entry and use Nvidia's official driver route. Do not download a driver from an error-code site or repeatedly force the same boot failure merely to see whether the stop code changes.

Preserve the stop code, current Windows build, Sophos version, GPU and driver version. If normal boot is unreliable, prioritize a recoverable system and data over collecting more performance samples. Driver rollback or update should follow the hardware vendor and Windows recovery guidance. A BSOD is not a case for adding scan exclusions, disabling random Sophos services or experimenting with registry cleaners.

Mac TCCD or TrustD above 60% has a current, narrow context

Sophos currently documents noticeable delays on Sonoma and Tahoe when affected users work with OneDrive/SharePoint or Olive Tree Bible Study; `TCCD` or `TrustD` can rise above 60% CPU. Sophos says backend changes are required and provides no timeline. This is one of the few cases where a percentage, process pair and application context come directly from the current vendor note rather than an old review benchmark.

Match all parts before using the note: supported macOS, affected application/action, the named process and repeatable delay. Update macOS and the affected application, record a short Activity Monitor sample and compare the same task without stacking a full scan. Do not kill TCCD or TrustD; they are macOS privacy/trust services, and stopping them does not fix the underlying interaction. The Sophos Home for Mac review explains the wider permission and compatibility tradeoff.

If Sophos's known issue matches and the workflow is business-critical, the honest choices are monitoring the live note, changing that workflow or choosing a different security product after a controlled comparison. Reinstalling Sophos repeatedly is unlikely to fix a backend dependency the vendor still lists. If the load occurs at idle or with another application, capture that different trigger instead of labelling it the same defect.

Fix a Mac shield stuck in the update-arrow state

Sophos's July 17, 2026 macOS update-failure advisory covers Home on Sonoma 14 and Sequoia 15. A missing Full Disk Access grant for `SophosUpdater` can make updates fail while the shield remains in an arrow/download animation. Update macOS first, because Sophos's supported state assumes current OS patches.

Open Privacy & Security → Full Disk Access, enable or add SophosUpdater from `/Library/Sophos Anti-Virus`, restart the Mac and use Check for updates. Then open About and compare the installed version with the live release notes. The animation is a symptom; the version comparison is the verification. Do not grant broad access to a similarly named file from Downloads or another folder.

The advisory includes an exact Terminal log predicate for identifying one rename error, but most readers do not need to paste a diagnostic command before completing the permission and restart steps. If the documented fix fails, use the linked official article or Sophos support so the command and interpretation stay tied to the current build. Avoid deleting updater folders or downloading a replacement package from a mirror.

Repair Mac “Action Required,” vulnerable and red-shield states by message

A successful installer message does not mean every macOS protection component loaded. Sophos's current Mac installation and upgrade guide requires four gates: System or Login Extensions, notifications, Full Disk Access and a reboot. After an install or macOS update, restart, allow about fifteen minutes and check every dashboard protection layer before deciding the product is damaged.

The separate Action Required guide routes specific messages to Network Filters, System/Login Extensions or Full Disk Access. On Sequoia, verify SophosScanD and the Sophos Network Extension under Login Items & Extensions. If the screen says “Almost done… Create account,” the endpoint may not be linked to the intended account; reinstall from that existing account rather than creating duplicates.

A red shield after the Mac starts offline should correct after reconnection, according to the current known-issues page. Give it time to communicate and compare the local state with the dashboard. If it stays red, preserve the exact message and use the matching permission or update branch. Do not use an old generic “delete the extensions” post; Sophos's advanced reload procedure deliberately moves components to Trash and puts them back, and it belongs under the official article or support guidance.

A stuck empty-folder scan animation does not mean protection is frozen

Sophos documents a Mac interface issue where right-click scanning an empty folder can leave the scan animation running indefinitely. The vendor workaround is to force-quit the Sophos Home UI from Activity Monitor. That instruction applies to the local interface for this exact empty-folder trigger, not the background protection services or every long-running scan.

Confirm that the selected folder is empty and that this is a right-click scan, then close only the documented UI process. Reopen the application and verify the protected state. If a non-empty scan stops making progress, preserve its path and use the scanning guide rather than assuming the same animation defect. A frozen picture and a frozen engine are different diagnoses.

Browser and application conflicts need the smallest current workaround

The known-issues page lists several current interactions: Chrome TLS 1.3 Early Data can cause access trouble, localhost-based apps such as AusweisApp2, Enpass and Sonos may need exact `127.0.0.1` exceptions, and some installers or business applications need narrowly documented exploit settings. These are examples of component conflicts, not a shopping list of settings every Home user should change.

Match the application, error and official workaround before editing protection. Use the live Sophos link because browser flags and application paths change. For website filtering or Private Relay, follow our dedicated web-protection guide. For an installation blocked by prerequisites, use the Sophos Home setup guide. Keeping ownership separate prevents a troubleshooting page from becoming a stale collection of copied exceptions.

When no current issue matches, reproduce one safe action and note which protection layer could plausibly observe it: file scan, web, exploit, ransomware or a Mac extension/permission. Then perform the controlled one-layer test below. Do not disable multiple layers simultaneously; if performance improves, you still will not know which layer mattered.

Use one protection layer for one short A/B test

Sophos's temporary-disable article is a troubleshooting tool, not a performance preset. Do not use it when infection is suspected. Open the dashboard, choose the computer and change only the layer relevant to the reproducible safe action. Keep the test short, avoid new downloads and record the start and end time.

Run the same action once under the same conditions, then turn the layer back on immediately. Confirm its slider is blue and the local/dashboard status is protected. If the symptom does not change, that layer is useful negative evidence; leave it enabled. If the symptom disappears, repeat once only if needed to rule out coincidence, then restore protection and use the component's current exception or support route.

A clean result does not justify working with protection off. It narrows the case: the browser issue follows Web Protection, the application issue follows Exploit Mitigation, or the file operation follows scanning. Send that relationship, version and timestamp to support. A precise A/B result is far more actionable than “Sophos makes everything slow.”

Exclusions should be narrow, trusted, tested and removable

An exclusion removes inspection from a path or application and can create a durable blind spot. Use one only when the file is trusted, the trigger is repeatable, the correct protection component is known and the live vendor guidance or support case justifies it. Record the exact path, publisher/version, reason and date. Retest the original action, and remove the exclusion when it does not solve the problem.

Never exclude a whole drive, home folder, Downloads, AppData, temporary folders, backup root or Sophos directories to lower CPU. Those locations receive new and changing files and are precisely where inspection matters. On Mac, scan exceptions do not behave identically across every scan type; our scan, quarantine and exclusions guide explains those boundaries and false-positive handling.

CandidateDecisionReason
Exact `CertPolEng.dll` path for the documented first network-save freezeTemporary vendor workaroundMatches the current named symptom; re-check after updates
One signed application path after a reproducible exploit conflictOnly with current Sophos guidanceNarrow component and version can be documented
Downloads, user profile or whole diskDo not excludeHigh-risk changing content and excessive scope
Sophos folders or protection processesDo not excludeCan weaken or destabilize the product
Unknown file that merely “uses CPU”Do not excludeTrust and causality have not been established

Update, repair and reinstall in an order that preserves evidence

The practical order is: capture the symptom, check service status, finish supported OS and application updates, restart once, match the current known-issues page, repair the named service or permission, run one-layer isolation, collect logs, then reinstall if components remain damaged. Verify after every stage and stop when the original trigger no longer fails. This keeps reversible steps first and avoids turning a current vendor defect into hours of local cleanup.

StageActionStop or continue?
1. PreserveRecord process, version, time, status and triggerContinue with evidence intact
2. PrerequisitesFinish supported OS/app updates and one requested restartStop if protected and trigger is gone
3. MatchUse the current named issue, service or permission fixStop after verified recovery
4. IsolateTest one protection layer once, then restore itEscalate the proven component
5. ReinstallUse the signed-in Home account and clean defaultsStop repeating if the clean fault returns

Before reinstalling, save the Home account email, device name, subscription state, installed version, useful exclusions and timestamps. Remove another resident antivirus first. Download Sophos only from the signed-in Home dashboard and use the same account so the endpoint links correctly. Our installation guide covers Windows installer errors, macOS permissions and correct removal; the dashboard and device guide explains why removing a dashboard seat is not the same as uninstalling locally.

Test a clean default install before restoring old exceptions. If the same idle load or update failure returns immediately, stop repeating the cycle. A recurrence on the supported OS, current build and default settings is strong support evidence. If the workflow is still unusable, compare the best Windows 11 antivirus options or current Mac alternatives after protection and data are stable.

Build a short support packet with SDU logs, not a folder dump

Write the case in a reproducible order: Sophos Home version, OS edition/build, device hardware, local time and timezone, process, CPU/disk pattern, protection state, active scan/update, exact trigger, recent change and each test with its result. Add the exact Service Failure, Action Required or update message and one or two screenshots with the clock visible. State whether another Home device works and whether the status page showed an incident.

Sophos's SDU instructions use Sophos Diagnostic Utility on Windows and the tool under `/Library/Sophos Anti-Virus/Tools` on Mac. The resulting archive contains system and application details that may be sensitive. Send it only through the official support ticket/SendSafely route with the requested submission identifier; do not attach it to a public Reddit or forum post.

Premium support offers the current web form/chat and documented weekday support route, while Free users mainly rely on the knowledge base and account routes. Use the current Sophos Home contact page rather than a phone number copied from a search result. Never grant remote access, install a “support tool” or share passwords because an unsolicited pop-up claims Sophos found a problem.

Verify the repair without using live malware

A quiet fan is not enough. Confirm the local shield and Home dashboard show the expected protected state, the installed version matches current release notes, updates finish and the original safe trigger no longer reproduces the fault. Check one normal restart and one wake/reconnect cycle. Remove temporary exclusions or test settings, then repeat the ordinary action with all required protection enabled.

Sophos provides an official harmless protection-test workflow, including EICAR and dashboard/history checks. Use that controlled route exactly as documented. Do not download live malware, visit a known malicious site or turn off several layers to “prove” the antivirus can find something. A failed harmless test after complete setup belongs in repair or reinstall, not riskier testing.

Independent reports explain variability, not your exact cause

Current third-party testing can show that a scan has visible cost, but one review machine cannot define normal for every PC. Cloudwards' 2026 review saw CPU move from around 10% to 35–40% during its scan. Tom's Guide and Comparitech published different numbers on older builds and hardware. Use those results to reject magical thresholds, not to diagnose your service, SSD or Mac permissions remotely.

Community evidence is even narrower. An old Sophos Community Home thread reported `SophosSXLD` near 99% on Mojave with Home 2.2.5, and an old `/r/sophos` post described download/speed-test frustration. They show that users have experienced these categories, but neither establishes prevalence or a 2026 defect. Current social searches were dominated by Sophos Firewall and business Endpoint cases, so this guide does not transfer those complaints to consumer Home.

The strongest current evidence is the combination of your reproducible local measurement and Sophos's live named issue or support route. Date-sensitive pages can change after an endpoint rollout. Keep the source link in the case, note when you checked it and remove temporary workarounds when the vendor closes the defect.

Sophos Home high CPU and troubleshooting FAQ

Why is Sophos Home using so much CPU?

A visible scan, automatic update or a large batch of changed files can produce a temporary spike, especially on a minimum-spec computer. Measure the same machine after startup settles and note whether load falls when that job ends. Sustained idle use or a repeatable one-app trigger needs component-specific diagnosis rather than a universal CPU threshold.

Is 60% CPU normal for Sophos Home?

No single percentage is a reliable normal limit because the processor, storage, file set and concurrent work change the result. Sophos currently documents one Mac issue where TCCD or TrustD can exceed 60% during affected OneDrive, SharePoint or Olive Tree activity; that is a named defect, not a general benchmark. Judge duration, trigger, process and recovery together.

Can I end a Sophos process in Task Manager or Activity Monitor?

Do not kill protection services simply because they are busy. Save the process name, activity, time and active job, then use the matching official recovery path. The only current UI-specific workaround covered here is force-quitting the Sophos Home interface when an empty-folder right-click scan leaves its animation stuck; that is not permission to stop protection services.

How do I fix Sophos Home Service Failure on Windows?

Install pending Windows updates, restart if requested and remove another resident antivirus through its supported uninstaller. Sophos then documents a controlled check of eight Premium services while Tamper Protection is temporarily off. Turn Tamper Protection back on immediately, and reinstall only if the services cannot start after the prerequisites are correct.

Why does Sophos Home Fast Scan stay at 0%?

First wait a few seconds because the scan prompt's offline wording is static and does not prove that the endpoint is unreachable. Sophos fixed a specific Fast Scan-at-0% defect in Windows Endpoint 2024.3.3 and required a restart, but a current installation may have a different cause. Restart, update, compare About with the live release notes and preserve the exact state if it repeats.

Why is Sophos Home stuck updating on Mac?

On current Sonoma and Sequoia systems, Sophos documents an updater problem that can leave the shield in an arrow animation when SophosUpdater lacks Full Disk Access. Update macOS, grant access to SophosUpdater from the official Sophos folder, restart and run Check for updates. Confirm the installed version against the live release notes instead of trusting the animation alone.

Should I disable Sophos Home to test a slowdown?

Only use a brief one-layer A/B test when there is no sign the computer is infected. Reproduce the same safe action once, re-enable that layer immediately and confirm the dashboard returns to protected. Turning off every layer for a workday creates exposure and does not identify the component.

Should I add exclusions to reduce Sophos CPU use?

Use an exclusion only for a verified, trusted and repeatable path, and make it as narrow as possible. The current CertPolEng.dll exception is a vendor workaround for one specific first-save-to-network freeze after boot, not a generic speed setting. Never exclude a drive, user profile, Downloads, temporary folders or Sophos directories to make a scan finish.

Will reinstalling Sophos Home fix high CPU?

Reinstallation can repair incomplete or damaged components, but it should follow evidence capture, supported OS and Sophos updates, one restart, known-issue matching and a narrow conflict test. Save the account, device, version and useful timestamps first. If the same fault returns on a clean default installation, stop repeating reinstall and send Sophos a reproducible support packet.

How can I test Sophos Home after a repair?

Confirm the local shield and web dashboard report a protected state, then use Sophos's official harmless protection-test workflow, which includes EICAR. Do not download live malware or disable several protections to make a test pass. Recheck the original safe trigger, one restart and one wake cycle before declaring the repair complete.

Final decision: keep, reinstall or replace Sophos Home

Keep Sophos when load is bounded to scans or updates, protection returns to normal and a current narrow workaround resolves the only conflict. Reinstall when official prerequisites are correct but services or Mac components remain incomplete. Escalate when the clean default installation reproduces the same fault, the shield cannot stay protected, updates never complete or a BSOD/overheating/boot problem makes further testing unsafe.

Replace the product when a documented no-timeline conflict blocks an essential workflow, the supported system repeatedly fails after a clean install, or the household no longer benefits from Sophos Home's web dashboard and multi-device model. Make the change deliberately: keep one resident antivirus, verify the new provider and remove the old product through its official uninstaller. The goal is a stable protected computer, not winning an argument with one CPU graph.

The useful habit carries across every security suite: measure, match, isolate, repair and escalate with evidence. It preserves protection and shortens support cases. Random service killing, broad exclusions and endless reinstalls do the opposite.