Cybersecurity firm Sophos lays off 10% of its global workforce and sources say ~450 employees were let go; Thoma Bravo acquired Sophos for $3.9B in March 2020
Context & Ripple Effects
Sophos' path to this cut runs through its ownership changes: a $125M UK IPO in 2015 valued it at $1.6B, and then Thoma Bravo took it fully private for $3.9B via the acquisition that closed in March 2020. Under private equity ownership there are no public shareholders to answer to, so headcount decisions like this one land without earnings-call theater.
The move also lands mid-wave across the sector: cybersecurity firms had already shed roughly 1,400 jobs since May 2022, including OneTrust's ~950 and Lacework's 200, while Cybereason had cut 17% of staff after pausing IPO plans. Sophos is the first large, PE-owned incumbent in this coverage to join the list rather than a venture-backed startup defending a burn rate.
First-order effects
- About 450 employees across Sophos' global offices lose their jobs as of this week, with no product or market named in the reporting as spared.
- Thoma Bravo now owns a leaner cost base on the $3.9B asset it bought in 2020 — the lever it controls directly as sole owner, unlike when Sophos answered to public-market investors after its 2015 listing.
Second-order effects
- Rival security vendors get cover to make their own cuts under the same macro framing — the pattern already normalized by OneTrust, Lacework, and Cybereason — while affected engineers and sales staff flood a market where multiple security firms are laying off simultaneously.
- A cheaper operating base gives Thoma Bravo more room for M&A rather than less; Sophos' subsequent ~$859M agreement to buy Secureworks out of Dell's ~79% stake shows the consolidation direction the cost cuts free up capital for.
Third-order effects
- If PE-owned security incumbents keep pairing workforce reductions with bolt-on acquisitions, the industry consolidates into fewer, larger platforms — with startups' exit path narrowing to being acquired by these roll-ups rather than independent listings, a squeeze Cybereason's shelved IPO already foreshadowed.
- For employees, the lesson structuring career risk is that going private removes disclosure obligations: Sophos confirmed only a percentage and sourced headcount figure, so PE-held companies can resize with far less visibility than listed peers.
The trend: Cybersecurity is consolidating under private equity, where cost discipline and serial acquisitions by owners like Thoma Bravo are replacing the growth-at-all-costs posture of the 2021-22 cohort.