×

Sophos says Daybreak AI agents reduced average case response to 89 seconds – Unite.AI

Sophos says Daybreak AI agents reduced average case response to 89 seconds – Unite.AI

In an October 9, 2026 customer story, OpenAI reported that Sophos reduced threat investigation times by 96% using AI agents created through the OpenAI Daybreak program, with an average response of 89 seconds on agent-handled cases and 52% of managed detection and response (MDR) cases now resolved end-to-end by AI.

Sophos protects more than 625,000 organizations across industries and regions. Chief Technology Officer John Peterson told OpenAI that the company has spent more than four decades developing expertise against a wide variety of attacks, and that the aim of Daybreak’s work is to broaden that domain expertise to every customer protected by Sophos rather than simply providing analysts with another tool.

How the agents created by Daybreak work

The deployment is centered around Sophos Fusion, the company’s native AI cyber defense system that includes Sophos MDR. According to OpenAI’s story, Fusion brings together sensor data from more than 500 third-party integrations alongside Sophos’ own products, and those sensors generate trillions of events every day, which Sophos distills into about 1,000 to 2,000 cases for its nine security operations centers to investigate.

For each case, an investigative agent gathers relevant customer context, detections, indicators of compromise, and threat intelligence. A planning model then runs a plan-execute-review cycle: it creates an investigation plan, completes the steps, and produces a summary with recommended response actions that analysts can review. Other agents can execute parts of the response.

Before Daybreak, investigating and responding to a case depended primarily on human expertise, and Sophos’ existing process averaged about 38 minutes – performance, according to Peterson, was better than 96% of professional security operations centers. “Now, thanks to the agents we were able to create through the Daybreak program, the average response time for cases using those agents has dropped to about 89 seconds. About half of the cases we handle are now automated by agents we developed using Daybreak models,” he said.

Human supervision and customer control

Sophos has integrated customer control into its MDR service through three operational modes. In Notify, Sophos investigates a case and recommends a response, but the customer takes action. In Collaboration, Sophos and the customer collaborate before an action is taken. Under Authorize, Sophos can respond directly on the customer’s behalf. The same limits apply whether the work is completed by a person or an agent, and potentially destructive actions still require the right level of human supervision. “Anything that makes us feel uncomfortable with an officer’s handling is passed off as human judgment,” Peterson said.

In its findings summary, OpenAI said the implementation allows Sophos to resolve 52% of end-to-end MDR cases with AI within limits calibrated by Sophos analysts, gives customers a faster and more consistent investigation experience, helps the company scale processing rather than relying on equivalent growth of scarce cybersecurity staff, and brings analysts’ attention back to threats, exceptions and decisions where their expertise matters most.

The dawn program

OpenAI describes Daybreak as a governed cyber defense stack that combines frontier models, Codex harness, Codex security, trusted workflows and ecosystem partners, while maintaining reliable access and action under human control. The program page states that Daybreak provides a defense agent cycle of inventory, discovery, dynamic validation, ownership assignment, and verified remediation, and lists use cases in secure software development and application security, defensive operations, and authorized security testing. Through Daybreak Access, verified defenders can utilize more capable and permissive defensive tools paired with more rigorous verification, scope controls, and oversight.

OpenAI is also committing $1 billion in subsidized access to Daybreak for six months for state and local governments, critical infrastructure operators, community banks, nonprofits and open source maintainers.

Sophos-OpenAI partnership timeline

Sophos announced on June 22, 2026 that it had joined the OpenAI Daybreak Cyber ​​Partner program, saying it was adopting the functionality in a deliberate and phased manner, starting with defensive workflows and targeted outputs, with Sophos analysts and controls in the loop rather than direct customer access to models. Early areas of focus included accelerating MDR threat investigations, deepening security assessments provided by Sophos Advisory Services, and strengthening how customers discover, validate and remediate exposure.

The companies also said they are working to codify standards for security and abuse prevention. The June announcement already described Sophos MDR as capable of resolving 52% of cases end-to-end with artificial intelligence, with an average response time of 89 seconds.

On August 10, 2026, Peterson wrote on the Sophos blog that the two companies were extending work to the channel, bringing OpenAI’s frontier models to service providers through Sophos Fusion. He said Sophos is a launch partner of OpenAI’s Daybreak Cyber ​​Partner program for managed security services, which applies models across MDR, Digital Forensics and Incident Response, and consulting services, with operators experienced in auditing and without direct customer access to the models.

According to the blog, Sophos defends more than 625,000 organizations across a channel of more than 25,000 partners, including more than 7,000 managed service providers, and defends more than 40,000 MDR customers worldwide. Peterson wrote that Sophos has been using artificial intelligence in its products since 2017.

What comes next

Peterson said Sophos will continue to expand what its agents can do, that response capabilities will continue to become more sophisticated, and that the company will broaden the range of use cases it addresses with the agents created by Daybreak.

His advice to other security leaders, he said in the article, is to go back to the fundamentals of security, including patches, while stressing that patches only cover vulnerabilities known to the vendor. He recommended a layered security approach that includes endpoint protection, multi-factor authentication, network segmentation and robust security operations. Peterson said vulnerabilities are being discovered at an alarming rate and exploited at an unprecedented scale, adding that managing fundamentals well is more important than it has ever been.

Post Comment