Sophos cuts threat investigation time by 96% with OpenAI Daybreak

OpenAI has published a customer story about Sophos, the cybersecurity company that says it protects more than 625,000 organisations. Through OpenAI Daybreak, Sophos is combining OpenAI models with its own threat intelligence, response playbooks and security expertise. The stated aim is not to hand analysts another tool but to scale Sophos's expertise across every customer it protects.
The work centres on Sophos Fusion, the company's AI-native cyber defense system, which includes Sophos Managed Detection and Response (MDR). Fusion pulls in sensor data from more than 500 third-party integrations alongside Sophos's own products. Those sensors generate trillions of events a day, which Sophos distills into roughly 1,000 to 2,000 cases for its nine security operations centres to investigate.
Agents built through Daybreak now handle part of that caseload. An investigation agent gathers the customer context, detections, indicators of compromise and relevant threat intelligence for each case. A planning model then creates a plan-execute-review loop: it builds an investigation plan, completes the steps and produces a summary with recommended response actions for analysts to review. Other agents can carry out parts of the response.
Before Daybreak, investigation and response depended mainly on human expertise. Sophos's existing process averaged around 38 minutes, which CTO John Peterson says was better than 96% of professional security operations centres. Peterson now says the average response time for cases using the agents has fallen to about 89 seconds, and that about half of the cases Sophos handles are automated by agents built with the Daybreak models. The results list in the story puts it at 52% of MDR cases resolved end to end with AI, within boundaries calibrated by Sophos analysts. The headline figure is a 96% reduction in investigation time.
Customers keep control through three MDR operating modes. In Notify, Sophos investigates and recommends, and the customer acts. In Collaborate, Sophos and the customer work together before action is taken. In Authorise, Sophos can respond directly on the customer's behalf. The same boundaries apply whether a person or an agent does the work, and potentially destructive actions still require the right level of human oversight. Peterson says anything Sophos does not feel comfortable with an agent handling is passed to human judgement.
The story also lists claimed benefits: a faster and more consistent investigation experience for customers, scaling compute rather than relying on equivalent growth in scarce cybersecurity headcount, and returning analysts' attention to the threats, exceptions and decisions where their expertise matters most.
Looking ahead, Peterson says the response capabilities will keep becoming more sophisticated and Sophos will broaden the range of use cases the agents address. His advice to other security leaders is to return to security fundamentals. That includes patching, but he notes that patches only cover vulnerabilities known to the vendor, so organisations need a layered approach with endpoint protection, multifactor authentication, network segmentation and strong security operations. He says vulnerabilities are being discovered at an alarming rate and exploited at a scale never seen before.
Key facts
- Sophos says the average response time for cases using Daybreak-built agents fell from about 38 minutes to about 89 seconds, a 96% reduction in investigation time.
- 52% of Sophos MDR cases are resolved end to end by AI, within boundaries calibrated by Sophos analysts; Peterson puts it as about half of the cases handled.
- Sophos Fusion distills trillions of daily events into roughly 1,000 to 2,000 cases for nine security operations centres; an investigation agent and a planning model with a plan-execute-review loop work each case.
- Customers choose among three modes (Notify, Collaborate, Authorise), and potentially destructive actions still require human oversight.
- The figures are reported by Sophos and OpenAI in a first-party customer story.
Why it matters
It is a concrete, numbered example of AI agents taking over routine security investigation work at a large vendor. The story claims a drop from about 38 minutes to about 89 seconds on cases handled by agents, and more than half of MDR cases closed without a human finishing them. It also shows the pattern Sophos used: domain expertise, playbooks and threat intelligence combined with frontier models, rather than models alone. The story frames this against a backdrop where capabilities are also spreading to open-weight models, giving attackers new ways to find vulnerabilities and speed up exploitation.
Who it affects
Security operations teams and MDR providers are the most direct audience, since the story describes agents doing the investigation work analysts used to do and handing summaries back for review. Sophos customers are affected through the three operating modes that decide how much Sophos can act on their behalf. Security leaders more broadly get Peterson's advice to focus on fundamentals such as patching, endpoint protection, MFA and network segmentation.
How to use it
This is a case study, not a product release, so there is nothing to switch on. The story does not explain what OpenAI Daybreak is beyond calling it a programme, and gives no launch date, pricing or eligibility. What a reader can take from it is the design: an investigation agent that assembles context, detections, indicators of compromise and threat intelligence per case; a planning model that runs a plan-execute-review loop and produces a summary with recommended actions for analysts; and explicit customer-selectable autonomy levels (Notify, Collaborate, Authorise), with anything uncomfortable for an agent passed to a human.
How solid is it
Weak on independent evidence. This is OpenAI's own customer story, and the numbers come from Sophos and OpenAI. The source gives no measurement period, sample size or independent verification of the 89 seconds, 38 minutes, 96% or 52% figures. The 89-second average applies only to cases handled by agents; the source gives no average for all MDR cases. There are also two different 96% figures: the 96% reduction in investigation time, and Peterson's claim that the earlier process beat 96% of professional security operations centres. The story also words the automated share two ways, 52% resolved end to end and 'about half' automated.
Risks and caveats
The story offers no error rate, false-positive rate, missed-threat or incident data for the agents, so speed is reported without a matching measure of accuracy. It does not say how many analysts or jobs were affected or whether headcount changed, though it frames the benefit as scaling compute rather than growing scarce headcount. The specific OpenAI models are not named, and no cost or compute figures are given. The 52% is bounded: it applies within boundaries calibrated by Sophos analysts, and Sophos keeps potentially destructive actions under human oversight.
“Anything we don’t feel comfortable with an agent handling gets passed off for human judgement”
— John Peterson, Chief Technology Officer, Sophos