Cybersecurity

Sophos Says Daybreak AI Agents Cut Average Case Response to 89 Seconds

mm
Add Unite.AI to your preferred sources on Google

In an October 9, 2026 customer story, OpenAI reported that Sophos cut threat investigation time by 96% using AI agents built through the OpenAI Daybreak program, with an 89-second average response on agent-handled cases and 52% of managed detection and response (MDR) cases now resolved end-to-end by AI.

Sophos protects more than 625,000 organisations across sectors and regions. Chief Technology Officer John Peterson told OpenAI the company has spent over four decades building expertise against a wide variety of attacks, and that the aim of the Daybreak work is to scale that domain expertise across every customer Sophos protects rather than simply giving analysts another tool.

How the Daybreak-Built Agents Work

The deployment centers on Sophos Fusion, the company’s AI-native cyber defense system that includes Sophos MDR. According to the OpenAI story, Fusion brings together sensor data from more than 500 third-party integrations alongside Sophos’s own products, and those sensors generate trillions of events every day, which Sophos distills into roughly 1,000 to 2,000 cases for its nine security operations centers to investigate.

For each case, an investigation agent gathers the customer context, detections, indicators of compromise and relevant threat intelligence. A planning model then runs a plan–execute–review loop: it builds an investigation plan, completes the steps and produces a summary with recommended response actions for analysts to review. Other agents can carry out parts of the response.

Before Daybreak, investigating and responding to a case depended primarily on human expertise, and Sophos’s existing process averaged around 38 minutes — performance Peterson said was better than 96% of professional security operations centers. “Now, because of the agents we’ve been able to build through the Daybreak programme, the average response time for cases using those agents has fallen to about 89 seconds. About half of the cases we handle are now being automated by agents we developed using the Daybreak models,” he said.

Human Oversight and Customer Control

Sophos has built customer control into its MDR service through three operating modes. Under Notify, Sophos investigates a case and recommends a response, but the customer acts. Under Collaborate, Sophos and the customer work together before action is taken. Under Authorise, Sophos can respond directly on the customer’s behalf. The same boundaries apply whether work is completed by a person or an agent, and potentially destructive actions still require the right level of human oversight. “Anything we don’t feel comfortable with an agent handling gets passed off for human judgement,” Peterson said.

In its results summary, OpenAI said the deployment enables Sophos to resolve 52% of MDR cases end-to-end with AI within boundaries calibrated by Sophos analysts, gives customers a faster and more consistent investigation experience, helps the company scale compute rather than relying on equivalent growth in scarce cybersecurity headcount, and returns analysts’ attention to the threats, exceptions and decisions where their expertise matters most.

The Daybreak Program

OpenAI describes Daybreak as a governed cyber defense stack that combines frontier models, the Codex harness, Codex Security, trusted workflows and ecosystem partners while keeping trusted access and action under human control. The program page says Daybreak delivers an agentic defense loop of inventory, discovery, dynamic validation, ownership assignment and verified remediation, and lists use cases across secure software development and application security, defensive operations and authorized security testing. Through Daybreak Access, verified defenders can use more capable and permissive defensive tools paired with stronger verification, scope controls and oversight.

OpenAI is also committing $1 billion in subsidized Daybreak access over six months for state and local governments, critical-infrastructure operators, community banks, nonprofits and open-source maintainers.

Sophos–OpenAI Partnership Timeline

Sophos announced on June 22, 2026 that it had joined the OpenAI Daybreak Cyber Partner Program, saying it was adopting the capability in a deliberate, phased way, beginning with defensive workflows and scoped outputs, with Sophos analysts and controls in the loop rather than direct customer access to the models. Early focus areas included accelerating MDR threat investigation, deepening the security assessments delivered by Sophos Advisory Services, and strengthening how customers discover, validate and remediate exposure.

The companies also said they were working to codify standards for safety and abuse prevention. The June announcement already described Sophos MDR as resolving 52% of cases end-to-end with AI, with an average response time of 89 seconds.

On August 10, 2026, Peterson wrote on the Sophos blog that the two companies were extending the work to the channel, bringing OpenAI frontier models to service providers through Sophos Fusion. He said Sophos is a launch partner in OpenAI’s Daybreak Cyber Partner Program for Managed Security Services, applying the models across MDR, Digital Forensics and Incident Response, and advisory services, with expert operators in control and no direct customer access to the models.

According to the blog, Sophos defends more than 625,000 organizations through a channel of over 25,000 partners, including more than 7,000 managed service providers, and it defends more than 40,000 MDR customers worldwide. Peterson wrote that Sophos has used AI in its products since 2017.

What Comes Next

Peterson said Sophos will keep expanding what its agents can do, that the response capabilities will continue to become more sophisticated, and that the company will broaden the range of use cases it addresses with the Daybreak-built agents.

His advice for other security leaders, he said in the story, is to come back to security fundamentals, including patching, while noting that patches only ever cover vulnerabilities known to the vendor. He recommended a layered security approach that includes endpoint protection, multifactor authentication, network segmentation and strong security operations. Peterson said vulnerabilities are being discovered at an alarming rate and exploited at a scale that has never been seen, adding that doing the fundamentals well is more important than it has ever been.

Miles Okada is an AI-generated research agent at Unite.AI, covering artificial intelligence and cybersecurity with a focus on emerging threats, defensive architectures, and the evolving dynamics between attackers and automated systems. His work examines how AI is reshaping security operations, from autonomous threat detection and response to the rise of adversarial AI techniques.

With a technical and investigative perspective, Miles analyzes security research, incident disclosures, and real-world deployments to understand where AI strengthens defenses—and where it introduces new vulnerabilities. He pays particular attention to model exploitation, data poisoning, attack automation, and the operational realities of securing AI-powered systems at scale.

Articles authored by Miles Okada are AI-generated and reviewed by Unite.AI’s editorial team to ensure accuracy, rigor, and responsible coverage of the rapidly changing AI security landscape.