Welcome.AIWelcome.AI
    Skip to content
    Generative AI

    Sophos Achieves 96% Reduction in Threat Investigation Time with AI

    By adopting OpenAI Daybreak, Sophos has drastically cut threat investigation times, achieving an average response of just 89 seconds and resolving 52% of cases through AI. This innovation represents a major leap forward in cybersecurity efficiency.

    openai.com•October 9, 2026•2 min read

    Key Facts

    • Sophos reduced threat investigation time by 96%, enhancing operational efficiency and customer trust.
    • 52% of MDR cases resolved by AI indicates a competitive edge in automation over traditional methods.
    • Average response time dropped to 89 seconds, showcasing significant improvements in service delivery.
    • Sophos protects 625,000 organizations, highlighting its market dominance and extensive customer base.
    • AI integration allows Sophos to scale operations without proportional headcount growth, optimizing costs.

    Summary

    Summary

    Sophos, a cybersecurity company protecting over 625,000 organizations, faced challenges in threat investigation efficiency. By implementing OpenAI Daybreak, they reduced investigation time by 96%, achieving an average response time of just 89 seconds for cases using AI agents. This transformation allowed Sophos to automate 52% of Managed Detection and Response (MDR) cases end-to-end.

    Background

    Sophos is a leading cybersecurity firm with a history spanning over four decades. They provide protection to a diverse range of sectors and regions, leveraging extensive expertise to combat a wide variety of cyber threats. Before deploying OpenAI Daybreak, Sophos relied heavily on human analysts to investigate and respond to security incidents, which averaged around 38 minutes per case.

    Challenge

    The primary challenge Sophos aimed to address was the lengthy investigation and response times associated with their existing processes. With the increasing complexity and volume of cyber threats, there was a pressing need to enhance efficiency and speed in threat investigations.

    Solution

    Sophos implemented OpenAI Daybreak to integrate advanced AI capabilities into their threat investigation processes. This involved developing investigation agents that gather customer context, detections, indicators of compromise (IoCs), and relevant threat intelligence for each case. The AI models create a plan-execute-review loop, allowing for quicker case handling and enabling other agents to perform parts of the response. Sophos also established three operating modes for customer control: Notify, Collaborate, and Authorise.

    Results

    The deployment of OpenAI Daybreak led to a significant reduction in investigation time, with the average response time for cases using AI agents dropping from approximately 38 minutes to just 89 seconds. Additionally, 52% of MDR cases are now resolved end-to-end by AI, allowing Sophos to scale their operations without a proportional increase in cybersecurity personnel. This automation has improved the consistency and speed of investigations for customers.

    Key Insights

    Security leaders should focus on the fundamentals of cybersecurity, including patch management and layered security approaches. Maintaining a robust security posture is crucial as vulnerabilities are discovered and exploited at unprecedented rates. Leveraging AI can significantly enhance operational efficiency and allow human analysts to concentrate on more complex threats.

    Customer Testimonial

    “Anything we don’t feel comfortable with an agent handling gets passed off for human judgement.” — John Peterson, Chief Technology Officer, Sophos

    Entities Mentioned

    Companies

    Sophos
    OpenAI

    Products

    OpenAI Daybreak
    Sophos Fusion
    Sophos Managed Detection and Response (MDR)

    Technologies

    AI
    automation
    multifactor authentication (MFA)

    People

    John Peterson

    Key Concepts

    threat investigation
    cybersecurity
    AI agents
    automation in security
    customer control
    response capabilities
    layered security approach
    vulnerability management

    Definitions

    MDR
    Managed Detection and Response (MDR) is a cybersecurity service that provides continuous monitoring and response to threats.
    IoCs
    Indicators of Compromise (IoCs) are pieces of forensic data that identify potentially malicious activity on a system.
    Daybreak
    OpenAI Daybreak is a program that integrates AI models with cybersecurity expertise to enhance threat investigation and response.
    automation
    Automation in cybersecurity refers to the use of technology to perform tasks without human intervention, improving efficiency and response times.
    layered security approach
    A layered security approach involves implementing multiple security measures to protect an organization's assets from various threats.

    Use Cases

    • →Reducing investigation time from 38 minutes to 89 seconds
    • →Resolving 52% of MDR cases end-to-end with AI
    • →Providing customers with a faster investigation experience
    • →Scaling compute resources without increasing headcount
    • →Enhancing analyst focus on critical threats
    • →Maintaining human oversight for sensitive actions

    Frequently Asked Questions

    How does OpenAI Daybreak improve threat investigation?

    OpenAI Daybreak combines AI models with Sophos's cybersecurity expertise, significantly reducing investigation times and automating many processes. This allows analysts to focus on more complex threats.

    What is the role of AI agents in Sophos's cybersecurity strategy?

    AI agents are designed to gather context and intelligence for threat cases, creating investigation plans and executing responses. They help automate routine tasks, improving efficiency.

    What are the operating modes of Sophos's MDR service?

    Sophos's MDR service operates in three modes: Notify, where Sophos recommends actions; Collaborate, where Sophos and the customer work together; and Authorise, where Sophos acts on behalf of the customer.

    Why is a layered security approach important?

    A layered security approach is crucial because it provides multiple defenses against various threats, ensuring that if one layer fails, others can still protect the organization. This is especially important given the rapid discovery and exploitation of vulnerabilities.

    What advice does John Peterson give to security leaders?

    John Peterson advises security leaders to focus on security fundamentals, including patching and maintaining a layered security approach. He emphasizes that doing these basics well is more critical than ever in today's threat landscape.

    Where AI Leaders Stay Informed

    The latest AI intelligence, case studies, and research — delivered to your inbox every week.

    Free to read. Unsubscribe anytime.