Sophos says AI cuts security response time from 38 minutes to 89 seconds
Agents built through OpenAI Daybreak gather evidence, plan investigations and handle parts of the response. Potentially destructive actions still require human oversight.
Listen to this story
The audio brief
Story brief
3 key pointsSophos has embedded OpenAI-built agents in its Fusion cyber-defense service to investigate and respond to managed detection and response cases, with automation bounded by customer permissions and human review for potentially destructive actions. Sophos reports agents resolve 52% of cases end to end, while agent-assisted cases average 89 seconds to respond versus about 38 minutes previously. These are company-reported results in an OpenAI customer story, not an independent evaluation; Sophos frames the operational payoff as adding computing capacity without matching growth in scarce security staff.
- 01
Sophos Fusion combines its own product data with more than 500 third-party integrations, narrowing trillions of daily events to roughly 1,000–2,000 cases for nine security operations centers.
- 02
An investigation agent gathers customer context, detections, threat intelligence and attack indicators; a planning model then uses a plan–execute–review loop to recommend responses.
- 03
Customers choose Notify, Collaborate or Authorise permissions, and those boundaries apply to both human- and agent-performed work.
Sophos says AI agents now resolve 52% of cases in its managed detection and response service, which investigates threats for customers. In an October 9 case study published by OpenAI, the cybersecurity company says average response time for cases using agents fell from about 38 minutes to 89 seconds, while potentially destructive actions retain human oversight.
The results describe agents already working inside Sophos's security service, rather than a proposed capability. Built through OpenAI Daybreak, they combine OpenAI models with Sophos's threat intelligence, response playbooks and security expertise. The timing and automation figures are company-reported results presented in an OpenAI customer story, not findings from an independent evaluation.
From sensor signals to an investigation plan
The work sits inside Sophos Fusion, the company's cyber defense system, which includes its managed detection and response service, or MDR. It combines data from Sophos products with more than 500 third-party integrations. Sophos says those sensors generate trillions of events daily, narrowed to roughly 1,000–2,000 cases for its nine security operations centers to investigate.
An investigation agent assembles the material needed to examine each case: customer context, detections, relevant threat intelligence and indicators of compromise—clues that a system may have been attacked. That puts the evidence-gathering work at the start of the agent's job, before a planning model decides which investigation steps to take.
The planning model runs a plan–execute–review loop. It creates an investigation plan, completes the steps and produces a summary with recommended response actions for analysts to review. Other agents can carry out parts of the response. The workflow therefore extends beyond summarizing an alert: it includes investigative work and some action on the resulting findings.
Before Daybreak, investigating and responding to a case depended primarily on human expertise, according to Sophos. The company presents two different measures of the change: a shorter average response time for cases using agents, and the share of MDR cases resolved end-to-end by AI. The first measures speed in agent-assisted work; the second describes how much casework is automated.
Sophos says the end-to-end automation operates within boundaries calibrated by its analysts. Its stated operational benefit is to scale computing capacity rather than depend on equivalent growth in scarce cybersecurity staff. It also says automation returns analysts' attention to threats, exceptions and decisions where their expertise matters most.
Customers choose who can act
Automation does not give every agent the same authority over a customer's systems. Sophos offers three operating modes that determine who takes action after an investigation. Those customer-selected boundaries apply whether a person or an agent completes the work, so the permission to respond comes from the service arrangement, not simply from using AI.
- Notify: Sophos investigates and recommends a response, but the customer carries out the action.
- Collaborate: Sophos and the customer work together before action is taken, rather than Sophos responding on its own.
- Authorise: Sophos can respond directly on the customer's behalf. The same operating boundaries apply to work performed by people and agents.
Potentially destructive actions still require the appropriate level of human oversight. John Peterson, Sophos's chief technology officer, says work the company is not comfortable assigning to an agent gets passed to a human for judgment. That leaves a separate safety boundary alongside the customer's choice about who may respond.
Peterson says Sophos intends to make the agents' response capabilities more sophisticated and broaden the range of use cases they address. That is the next direction he describes, rather than a newly released feature in this disclosure. The current results concern how agents are handling investigations and responses inside the existing MDR service.
Sources
- openai.comSophos cuts threat investigation time by 96% with OpenAI Daybreak
Reader comments
Newest comments first. Replies stay oldest first.