AIToday
AI Business & IndustryOpenAI BlogPublished: Oct 9, 2026, 19:00 JST

Sophos cuts threat response to 89 seconds with OpenAI Daybreak

Sophos cuts threat response to 89 seconds with OpenAI Daybreak

3 Key Points

  1. What happened

    Sophos CTO John Peterson says agents built through OpenAI's Daybreak cut average MDR case response time from about 38 minutes to roughly 89 seconds, and 52% of cases now run end-to-end on AI.

  2. Why it matters

    Sophos says the agents let it scale compute instead of hiring scarce security staff, while destructive actions still pass to human judgement.

WHO IT HITSSecurity operations centre (SOC) managers and MDR analysts at firms using Sophos gain faster, more consistent case triage, while vendors selling managed detection and response face a benchmark where AI agents handle half of cases.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

Peterson frames the Daybreak rollout against a widening gap: frontier AI helps defenders, but similar capabilities are spreading to open-weight models, giving attackers new ways to find and exploit vulnerabilities. Sophos protects more than 625,000 organisations, so the pressure is on scaling expertise rather than headcount.

At the centre of the work is Sophos Fusion, the company's AI-native cyber defense system that includes Sophos MDR. It pulls sensor data from over 500 third-party integrations and distills trillions of daily events into roughly 1,000 to 2,000 cases for nine security operations centres. Agents built through Daybreak now gather context, detections, indicators of compromise and threat intelligence for each case, then run a plan-execute-review loop that produces a summary and recommended actions for analysts.

Peterson says Sophos will keep expanding what the agents do. His advice to other security leaders is to focus on fundamentals: patching, endpoint protection, multifactor authentication, network segmentation and strong security operations, noting vulnerabilities are being discovered at an alarming rate and exploited at a scale not seen before.

FAQ
How much faster is Sophos' threat investigation with OpenAI Daybreak?
Sophos says the average response time for cases using the Daybreak-built agents fell from approximately 38 minutes to about 89 seconds.
Does Sophos let the AI act on its own?
Sophos uses three modes: Notify (customer acts), Collaborate (joint action), and Authorise (Sophos acts on the customer's behalf). Potentially destructive actions still require human oversight.
What are the agents built with Daybreak doing?
An investigation agent gathers customer context, detections, indicators of compromise and threat intelligence, while a planning model builds an investigation plan, runs it, and produces a summary with recommended responses.

AI news that matters for your work, delivered every morning.

Pick your industry and the AI tools you use, and get news related to your work every day.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleInnodisk, Apacer post September 2026 revenue growth