Sophos uses OpenAI Daybreak to speed MDR investigations

Sophos reports 89-second AI-assisted case response
Sophos says it has reduced the average response time for Managed Detection and Response cases handled with AI agents from about 38 minutes to 89 seconds. The cybersecurity company attributes the change to agents built through OpenAI Daybreak, which combine OpenAI models with Sophos threat intelligence, response playbooks and security expertise.
The company describes the result as a 96% reduction in investigation time for cases using OpenAI models. Sophos also says 52% of its MDR cases are now resolved end to end by AI, within operating boundaries set by its analysts. Sophos protects more than 625,000 organisations across sectors and regions.
Agents assemble evidence and prepare response plans
The work is centred on Sophos Fusion, the company’s AI-native cyber defence system, which includes Sophos MDR. Fusion combines Sophos telemetry with sensor data from more than 500 third-party integrations. Those sources generate trillions of events each day, which Sophos narrows to roughly 1,000 to 2,000 cases for investigation across its nine security operations centres.
An investigation agent gathers customer context, detections, indicators of compromise and relevant threat intelligence for an individual case. A planning model then runs a plan-execute-review loop: it forms an investigation plan, completes the required steps and produces a summary with recommended response actions for analysts to assess. Other agents can perform elements of the response.
The deployment builds on the automation focus in OpenAI Daybreak patching and protection tools, where OpenAI Daybreak tools are applied to patching and software protection, while this implementation addresses MDR investigations and selected response tasks at operational scale.
Customer controls remain in place
Sophos retains three MDR operating modes: Notify, where Sophos recommends an action for the customer to take; Collaborate, where both parties decide before action; and Authorise, where Sophos can act for the customer. The same controls apply whether a person or an agent performs the work.
John Peterson, Sophos’s Chief Technology Officer, said work that the company does not consider appropriate for an agent is passed to human judgement. Potentially destructive actions therefore remain subject to the relevant level of oversight rather than being automated solely for speed.
What the figures mean for security operations
Sophos says the agents help it scale compute instead of requiring equivalent growth in scarce cybersecurity headcount, while returning analyst attention to threats, exceptions and decisions that need expertise. Peterson also said the company intends to broaden the use cases and sophistication of agent response capabilities.
For security leaders, the practical implication is to apply automation inside defined response boundaries while maintaining the fundamentals Peterson identified: patching, endpoint protection, multifactor authentication, network segmentation and strong security operations.

