Sophos cuts threat investigation time by 96% with OpenAI Daybreak
Oct 9, 2026, 12:00 AM · OpenAI

Sophos says agents now close about half its managed-detection cases in seconds. That is a real win for defenders, and it raises the stakes on where human judgment stays in the loop.
Why it matters
Sophos, which says it protects more than 625,000 organisations, reports that agents built through OpenAI's Daybreak program cut average response time on the cases they handle from roughly 38 minutes to about 89 seconds. It says 52% of its managed detection and response cases are now resolved end-to-end by AI, within limits its analysts set.
This is a vendor case study published by OpenAI, so the numbers come from the two companies with the most to gain. Still, the shape of the claim matters. Security operations is one of the clearest places where speed is the whole game, and a security company is saying out loud that software, not headcount, is now doing the first pass on most of its work.
From the desk
We are inclined to take this one seriously, with caveats. Security is a field where defenders are chronically outnumbered and analysts burn out triaging alerts. If an investigation agent can gather the context, indicators and threat intelligence for a case and hand a person a plan and a recommended response, that is useful AI doing exactly the kind of grinding work humans do badly at 3 a.m.
The part we like most is the structure Sophos describes. Customers choose whether Sophos only notifies them, collaborates with them, or is authorised to act on their behalf, and the company says the same boundaries apply whether a person or an agent is doing the work. Potentially destructive actions, it says, still need the right level of human oversight. That is the right instinct. Speed without guardrails in security is just a faster way to take down a customer's network by mistake.
Now the downside. A 38-minute baseline that Sophos says already beat most security operations centres, collapsed to 89 seconds, means the agent is increasingly the first and sometimes only reader of an incident. When it is wrong, it will be wrong quickly and at scale. Half of cases closed by AI also means half of cases where a junior analyst never gets the reps. I'm watching whether the industry quietly loses its bench of experienced investigators while celebrating the throughput.
There is also the arms race framing, and the source is candid about it: the same frontier capabilities are spreading to open-weight models that attackers can use. Defender automation is not optional in that world. But it does mean the baseline expectation for response time is about to move for everyone, and smaller security teams without a frontier partnership may find themselves measured against numbers they cannot match.
Our read: this is a credible example of agents earning their keep, with sensible human-in-the-loop design. The honest test is not the averages. It is what happens on the hard cases, the false positives, and the incidents the agent hands back.
Context
Daybreak is OpenAI's program for pairing its models with security companies' own expertise and data. Sophos says its Fusion system draws on more than 500 third-party integrations and its own products, distilling trillions of daily events into roughly 1,000 to 2,000 cases for nine security operations centres. Its CTO, John Peterson, also used the case study to push basics like patching, MFA and network segmentation.
Who feels it
- Security teams
- Expect sub-minute triage to become a benchmark. Teams will need to show where agents stop and analysts decide.
- Enterprise customers
- The notify, collaborate and authorise modes are worth scrutinizing in any managed-security contract that now involves agents.
- Security analysts
- Less alert drudgery, but fewer routine cases to learn on. Career paths in the SOC may need redesigning.
- Attackers
- Faster defender response shrinks dwell time, which pushes attackers toward speed and automation of their own.
What to watch
- Independent data on false-positive and missed-detection rates for agent-handled cases
- Whether Sophos expands the range of response actions agents can take without a human
- Other security vendors publishing comparable Daybreak results
- Any incident where an automated response causes customer disruption
Companies: OpenAI