Sophos cuts threat investigation time by 96% with OpenAI Daybreak

Published · AI Daily — AI-assisted deep research, methodology & disclosure

OpenAI says Sophos pairs frontier models with its own threat intelligence via Daybreak. Reported: 89-second response, 96% less investigation time, 52% of MDR cases resolved by AI. Vendor figures, unverified.

On 9 October 2026, OpenAI published a customer story about Sophos, the cybersecurity company. Using OpenAI Daybreak, Sophos combines frontier models with its own threat intelligence, response playbooks and four decades of security expertise. The headline claim is a 96% cut in threat investigation time. Three figures carry the story. Cases handled with AI agents have an average response time of 89 seconds. Investigation time fell 96% with OpenAI models. And 52% of Managed Detection and Response (MDR) cases are resolved end to end by AI. One caveat comes first. These numbers come from a vendor-authored case study. Their definitions and sample are not independently verified. Treat them as a strong signal, not an industry benchmark. Even with that discount, the message is clear: agents have moved from being a helper at the analyst's elbow to handling live production cases.

The story sits inside a narrowing window for defenders. OpenAI notes that frontier AI changes cybersecurity on both sides. Advanced models help defenders find and investigate threats faster. The same capabilities are also spreading to open-weight models, which gives attackers new ways to discover vulnerabilities and speed up exploitation. Attack cost falls, while defender headcount does not grow at the same pace. Sophos stands on that front line. It protects more than 625,000 organisations across sectors and regions. Its Chief Technology Officer, John Peterson, puts it plainly. The company sees a huge variety of attacks and has built expertise against them over four decades. Programmes like Daybreak, and companies like OpenAI, bring frontier intelligence that lets Sophos scale that domain expertise to all of its customers. The key word is scale. The word is not replace.

Now consider the system itself. The centre of the rollout is Sophos Fusion, the company's AI-native cyber defense system, which includes Sophos Managed Detection and Response. Fusion brings together sensor data from more than 500 third-party integrations and from Sophos's own products. Those sensors generate trillions of events every day. Sophos distills them into roughly 1,000 to 2,000 cases for its nine security operations centres to investigate. The shape of this funnel matters. Raw events exceed any human capacity by orders of magnitude. The real bottleneck sits at the case layer. At that layer, a machine has already done the first triage, but someone must still check context, link evidence and decide whether to act. Agents built through Daybreak changed how those cases are handled. The source text we hold is cut off at this point. It does not say how the agents orchestrate tools, which data they read, or when they hand a case to a person. This article does not guess.

The numbers need careful reading. An 89-second average response means the waiting time between a case entering the queue and a usable investigative conclusion has nearly vanished for these cases. A 96% reduction in investigation time suggests that most of the forensic lookups, queries and correlation work once done by hand is now done by the model. The 52% end-to-end resolution rate also tells us something honest: close to half of MDR cases still involve people. Sophos does not claim that humans have left the loop. The division of labour is being rearranged. Machines take the repetitive, formalisable work. Analysts keep their time for ambiguous, high-risk judgments where someone must be accountable. Several questions that vendor case studies rarely answer remain open. What are the false-positive and false-negative rates? Are cases closed by AI sampled and audited? Who is responsible when the agent is wrong? Can a customer inspect each step the agent took? Those answers, not the headline percentages, will show how much the figures are worth.

For the industry, the most important signal is that the moat is moving. Frontier model capability is becoming a widely available input, and part of it is diffusing to open-weight models. What is hard to copy is the long-built stock of threat intelligence, response playbooks, analyst experience and trillions of real events. Sophos is pairing those assets with general intelligence. It is not handing the whole investigation process to a black box. The lesson for other security vendors and in-house teams is plain. Structure your own playbooks and workflows first, then deploy agents, because a model amplifies expertise that already exists. It does not create it from nothing. Three things deserve watching next. Can independent parties reproduce these metrics? How will the remaining cases, those not resolved by AI, be handled as the systems mature? And will defenders keep their lead in response speed once attackers use agents too? When the defender's window is closing, speed is itself a form of defense. This case shows one possible answer to that problem, and it is one that the rest of the market will now be pushed to match or to challenge with better evidence.

Sources

FAQ

What are the headline figures in the Sophos case?

OpenAI reports an average response time of 89 seconds for cases handled by AI agents, a 96% reduction in investigation time using OpenAI models, and 52% of MDR cases resolved end to end by AI. The figures are vendor-reported and not independently verified.

How does Sophos Fusion turn huge event volumes into manageable cases?

Fusion combines sensor data from more than 500 third-party integrations with Sophos's own products. Those sensors generate trillions of events daily. Sophos distills them into roughly 1,000 to 2,000 cases for its nine security operations centres, and agents built through Daybreak changed how those cases are handled.

Does 52% end-to-end resolution mean humans are out of the loop?

No. It means close to half of MDR cases still involve people. The division of labour is shifting: machines take repetitive, formalisable work, while analysts keep ambiguous, high-risk judgments where someone must be accountable.