AI news ·
Sophos cuts threat investigation time by 96% with OpenAI Daybreak
Sophos cut threat investigation times from 38 minutes to 89 seconds, a 96% drop, with AI agents now resolving half of all cases end-to-end.

Sophos has cut threat investigation times from 38 minutes to 89 seconds using OpenAI Daybreak models, the cybersecurity company reported on October 9, 2026. The 96% reduction means half of all Managed Detection and Response cases are now resolved end-to-end by AI agents, freeing analysts for work that requires human judgment.
The performance gain comes as Sophos protects more than 625,000 organizations globally. Its security operations centers process trillions of sensor events daily, distilling them into roughly 1,000 to 2,000 cases for investigation. Before Daybreak, Sophos's 38-minute average investigation time already outperformed 96% of professional security operations centers, according to Chief Technology Officer John Peterson.
How the AI agents work
The agents operate within Sophos Fusion, the company's AI-native defense system that pulls data from over 500 third-party integrations alongside Sophos's own products. An investigation agent gathers customer context, detections, indicators of compromise, and relevant threat intelligence for each case. A planning model then creates a plan-execute-review loop: it builds an investigation plan, completes the steps, and produces a summary with recommended response actions.
"Now, because of the agents we've been able to build through the Daybreak programme, the average response time for cases using those agents has fallen to about 89 seconds," Peterson said. "About half of the cases we handle are now being automated by agents we developed using the Daybreak models." Other agents handle parts of the response, though Sophos keeps human oversight for potentially destructive actions.
Customer control built into automation
Sophos structures its MDR service around three operating modes that apply whether a person or an agent handles the work. In Notify mode, Sophos investigates and recommends a response but the customer acts. Collaborate mode means Sophos and the customer work together before action. Authorize mode lets Sophos respond directly on the customer's behalf.
"Anything we don't feel comfortable with an agent handling gets passed off for human judgement," Peterson said. The boundaries are calibrated by Sophos analysts, and the company says the approach returns analysts' attention to threats, exceptions, and decisions where their expertise matters most.
The narrowing defender's window
Peterson pointed to a shifting threat landscape where advanced models help defenders find and investigate threats faster, but open-weight models also give attackers new ways to discover vulnerabilities and accelerate exploitation. His advice for security leaders centers on fundamentals rather than chasing novelty.
"The one thing security leaders should do tomorrow is really come back to focusing on the security fundamentals for their organization," he said. "That of course includes patching. But patches are only ever going to include vulnerabilities that are known by the vendor." He recommended a layered approach combining endpoint protection, multifactor authentication, network segmentation, and strong security operations. Organizations looking to build these skills internally can explore AI Security Analytics Courses that cover detection and response workflows.
"Vulnerabilities are being discovered at an alarming rate and exploited at a scale that we've never seen," Peterson said. "So I think doing the fundamentals well is more important today than it's ever been."
Why this matters for IT and security operations
For teams running security operations centers or managing detection and response, Sophos's results quantify what AI-driven investigation can deliver: not marginal improvement but order-of-magnitude speed gains. The 89-second average response time and 52% fully automated case resolution show that AI agents can handle routine triage and investigation at scale. The practical takeaway is that automation works best when paired with clear escalation boundaries - Sophos didn't remove human judgment, it redirected it toward the cases and decisions that actually need it. Teams evaluating similar tools should measure against their own mean time to investigate and define which actions must stay human-controlled before turning agents loose.