Sophos cuts threat investigation time by 96% with OpenAI Daybreak
Quick Answer
Sophos has reduced threat investigation time by 96% using OpenAI Daybreak, bringing average response time down from 38 minutes to 89 seconds.
Quick Take
This advancement enables Sophos to automate 52% of MDR cases, enhancing efficiency across its cybersecurity operations for over 625,000 organizations.
Key Points
- Average response time for cases using Daybreak agents is now 89 seconds.
- Sophos automates 52% of MDR cases, improving operational efficiency.
- The system integrates data from over 500 third-party products.
- Sophos employs a layered security approach to combat emerging vulnerabilities.
- Future enhancements will broaden agent capabilities and use cases.
DeepSignal Analysis
What happened
Sophos has significantly reduced its threat investigation time by integrating OpenAI Daybreak into its operations. The average response time has decreased from 38 minutes to 89 seconds, allowing the company to automate 52% of its Managed Detection and Response (MDR) cases. This advancement supports Sophos in protecting over 625,000 organizations.
Key evidence
- Sophos's average response time for cases has dropped from 38 minutes to 89 seconds after implementing OpenAI Daybreak.
- The integration of Daybreak has enabled Sophos to automate 52% of its MDR cases, enhancing operational efficiency.
- Sophos protects more than 625,000 organizations, utilizing its AI-native cyber defense system, Sophos Fusion.
Why it matters
The reduction in investigation time and the ability to automate a significant portion of cases allows Sophos to allocate resources more effectively. This efficiency is crucial in the cybersecurity landscape, where threats evolve rapidly. By leveraging AI, Sophos can maintain a competitive edge and provide faster, more consistent responses to its clients, ultimately improving overall security posture.
What to watch
📖 Reader Mode
~4 min readStaying ahead as the defender’s window narrows
Frontier AI is changing cybersecurity on both sides(opens in a new window). Advanced models can help defenders find and investigate threats faster. But those capabilities are also spreading to open-weight models, giving attackers new ways to discover vulnerabilities and accelerate exploitation.
Sophos(opens in a new window) is one of the companies standing in their way, protecting more than 625,000 organisations across sectors and regions. “We see a huge variety of different attacks,” says John Peterson, the company’s Chief Technology Officer. “We’ve cultivated vast expertise in combating them over four decades in the cybersecurity business.”
Through OpenAI Daybreak, Sophos is combining OpenAI models with its own threat intelligence, response playbooks and security expertise. The aim isn’t simply to give analysts another tool. It’s to increase the impact of Sophos’s expertise across every customer it protects.
“Sophos brings the domain expertise and the know-how to combat attacks at scale. Programmes like Daybreak, and companies like OpenAI, bring frontier intelligence that allows us to take that domain expertise and scale it to support all of our customers.”
—John Peterson, CTO, Sophos
Inside the rollout
At the centre of the work is Sophos Fusion, the Sophos AI-native cyber defense system that includes Sophos Managed Detection and Response (MDR). It brings together sensor data from more than 500 third-party integrations alongside Sophos’s own products. Together, those sensors generate trillions of events every day, which Sophos distills into roughly 1,000 to 2,000 cases for its nine security operations centres to investigate.
Agents built through Daybreak have changed how those cases are handled. An investigation agent gathers the customer context, detections, indicators of compromise (IoCs) and relevant threat intelligence for each case. A planning model then creates a plan–execute–review loop: building an investigation plan, completing the steps and producing a summary with recommended response actions for analysts to review. Other agents can carry out parts of the response.
Before Daybreak, investigating and responding to a case depended primarily on human expertise. Sophos’s existing process averaged around 38 minutes — performance Peterson says was better than 96% of professional security operations centres.
“Now, because of the agents we’ve been able to build through the Daybreak programme, the average response time for cases using those agents has fallen to about 89 seconds. About half of the cases we handle are now being automated by agents we developed using the Daybreak models.”
—John Peterson, CTO, Sophos
Keeping judgement at the centre
Sophos has built customer control into its MDR service through three operating modes:
Notify: Sophos investigates the case and recommends a response, but the customer acts.
Collaborate: Sophos and the customer work together before action is taken.
Authorise: Sophos can respond directly on the customer’s behalf.
The same boundaries apply whether work is completed by a person or an agent. Sophos uses automation to move quickly and make better use of analysts’ time, but potentially destructive actions still require the right level of human oversight.
“Anything we don’t feel comfortable with an agent handling gets passed off for human judgement,” Peterson confirms.
Results at a glance
Reduced the average response time for cases using agents from approximately 38 minutes to 89 seconds.
Enabled Sophos to resolve 52% of MDR cases end-to-end with AI, within boundaries calibrated by Sophos analysts.
Gives customers a faster and more consistent investigation experience.
Helps Sophos scale compute rather than relying on equivalent growth in scarce cybersecurity headcount.
Returns analysts’ attention to the threats, exceptions and decisions where their expertise matters most.
What’s next
Peterson says Sophos will keep expanding what its agents can do. “The response capabilities are going to continue to become more sophisticated, and we’re going to broaden the range of use cases we address with the agents we’ve built.”
“With programmes like Daybreak, we have an opportunity to stay a step ahead of the attacker community.”
—John Peterson, CTO, Sophos
His advice for other security leaders is simple: “The one thing security leaders should do tomorrow is really come back to focusing on the security fundamentals for their organization,” he says. “That of course includes patching. But patches are only ever going to include vulnerabilities that are known by the vendor.”
The answer is to maintain “a layered security approach” that includes endpoint protection, multifactor authentication (MFA), network segmentation and strong security operations. “Vulnerabilities are being discovered at an alarming rate and exploited at a scale that we’ve never seen. So I think doing the fundamentals well is more important today than it’s ever been.”
— Originally published at openai.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from OpenAI Blog
See more →Scientific computing in the age of agentic AI
AI agents are transforming scientific computing by streamlining software development, enabling researchers to focus on discovery. Projects using Codex and Claude Code report accelerated development and improved maintenance, though challenges in validating AI outputs remain. Long-term stewardship of research software is crucial to ensure reliability and reproducibility.