Presuming all your SharePoint mappings are defined properly, all you have to do is enable Basic authentication in IIS - leaving the existing NTLM authentication as enabled is fine.
Whether you do the login prefix/suffix on IIS or the Sophos authentication profile is up to you.
Also, on your virtual server pass the host header.