AI Briefing
KOSign in

Sophos cuts threat investigation time by 96% with OpenAI Daybreak

·2026.10.09 16:00

Key point

Sophos reduced average case response time from 38 minutes to 89 seconds and resolved 52% of MDR cases end-to-end using AI agents built with OpenAI Daybreak.

Details

Sophos has integrated OpenAI Daybreak with its Sophos Fusion cyber defense system to accelerate threat investigations for over 625,000 organizations. By combining OpenAI’s frontier models with Sophos’s proprietary threat intelligence and response playbooks, the company has significantly reduced the time required to handle security cases.

Accelerated Investigation Workflow

The system processes trillions of daily events from more than 500 third-party integrations, distilling them into 1,000 to 2,000 cases for investigation. AI agents built through Daybreak now handle these cases through a plan–execute–review loop:

  • An investigation agent gathers customer context, detections, and indicators of compromise (IoCs).
  • A planning model creates an investigation plan and executes steps.
  • The system produces a summary with recommended response actions for analyst review.

This approach has reduced the average response time for agent-handled cases from approximately 38 minutes to 89 seconds. Currently, 52% of Managed Detection and Response (MDR) cases are resolved end-to-end by AI.

Human Oversight and Control

Sophos maintains strict human oversight through three operating modes that apply to both human and AI actions:

  • Notify: Sophos investigates and recommends, but the customer acts.
  • Collaborate: Sophos and the customer work together before action.
  • Authorise: Sophos responds directly on the customer’s behalf.

Potentially destructive actions still require human judgment, ensuring that automation enhances rather than replaces critical decision-making. John Peterson, Sophos CTO, emphasized that this allows the company to scale compute resources instead of relying on scarce cybersecurity headcount, freeing analysts to focus on complex threats and exceptions.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.