Updated
Updated · OpenAI · Oct 9
Sophos Cuts Threat Response Time 96% to 89 Seconds With OpenAI Daybreak
Updated
Updated · OpenAI · Oct 9

Sophos Cuts Threat Response Time 96% to 89 Seconds With OpenAI Daybreak

2 articles · Updated · OpenAI · Oct 9

Summary

  • 89 seconds is now Sophos’s average response time for MDR cases handled by Daybreak-built agents, down from about 38 minutes, with 52% of cases resolved end-to-end by AI.
  • Those agents sit inside Sophos Fusion, which distills trillions of daily events from more than 500 third-party integrations and Sophos products into roughly 1,000 to 2,000 cases for nine security operations centers.
  • The system uses an investigation agent to pull customer context, detections, IoCs and threat intelligence, then a planning model runs a plan-execute-review loop and recommends response actions for analyst approval.
  • Sophos said customer control remains unchanged across notify, collaborate and authorize modes, with potentially destructive actions still escalated for human judgment.
  • The company, which protects more than 625,000 organizations, said the automation lets it scale compute instead of scarce cybersecurity headcount as AI also boosts attackers’ ability to find and exploit vulnerabilities.

Insights

Can an AI that slashes response times to 89 seconds be trusted not to accidentally shut down critical business operations?
If AI resolves half of all cyber threats autonomously, what happens to human expertise when the system faces an unprecedented attack?