
Summary
- According to a case study OpenAI published on October 9, Sophos put agents built through Daybreak into its MDR service and cut the average response time for agent-handled cases from about 38 minutes to 89 seconds.
- An investigation agent gathers customer context and indicators of compromise, an OpenAI planning model runs a plan, execute and review loop, and 52% of MDR cases are now resolved end to end by AI.
- Sophos keeps human judgment in place through three operating modes, Notify, Collaborate and Authorise, and CTO John Peterson said Daybreak lets the company design agents with less restrictive guardrails.
OpenAI on October 9 published a case study on how British security company Sophos uses Daybreak. Sophos put agents built on OpenAI models into its managed detection and response (MDR) service, and the average response time for cases handled by those agents fell from about 38 minutes to 89 seconds. OpenAI said investigation time dropped by 96% and that AI now resolves 52% of MDR cases end to end.
Sophos has been in the security business for more than four decades and protects more than 625,000 organizations across sectors and regions. "We see a huge variety of different attacks," said John Peterson, Sophos's chief technology officer. "We've cultivated vast expertise in combating them over four decades in the cybersecurity business." Daybreak is OpenAI's program for bringing cyber capabilities to defenders. Sophos announced on June 22 that it had joined the Daybreak Cyber Partner Program.
The investigations run inside Sophos Fusion, the company's AI-native defense system. According to OpenAI's case study, the system takes in sensor data from more than 500 third-party integrations alongside Sophos's own products. Those sensors generate trillions of events a day, which Sophos distills into roughly 1,000 to 2,000 cases for its nine security operations centers (SOCs) worldwide.
The agents changed how those cases are handled. For each case, an investigation agent gathers customer context, detections, indicators of compromise (IoCs) and relevant threat intelligence. An OpenAI planning model then runs a loop that builds an investigation plan, carries out the steps and reviews them, producing a summary and recommended response actions for analysts to review. Other agents carry out parts of the response. "Because of the agents we've been able to build through the Daybreak programme, the average response time for cases using those agents has fallen to about 89 seconds," Peterson said. "About half of the cases we handle are now being automated by agents."
The earlier benchmark was not a low bar. According to Peterson, the previous human-driven average of 38 minutes was faster than 96% of professional security operations centers. In the case study video, he said the MDR organization's average response time was about 38 minutes 18 months to two years ago, and that it shrank to 89 seconds as the agents were rolled out over the past year.
Human judgment is preserved through three operating modes. Under Notify, Sophos investigates and recommends a response, and the customer acts. Under Collaborate, Sophos and the customer decide together before acting, and under Authorise, Sophos responds directly on the customer's behalf. The same boundaries apply whether a person or an agent does the work, and potentially destructive actions still require the appropriate level of human oversight. "Anything we don't feel comfortable with an agent handling gets passed off for human judgement," Peterson said.
According to Sophos's May 28 press release, which METAL reviewed, the 89-second and 52% figures were first published by Sophos itself as a year of MDR production data. The 89 seconds measures the time from case creation to fully automated response for cases the AI is authorized to resolve, and the 52% is the share of cases closed without human intervention within boundaries continuously calibrated by analysts. In the same release, Sophos said its MDR customer base grew 39% year over year to 40,000. "The 52% gets the attention, but the 48% is just as important," said Rob Harrison, Sophos's senior vice president of product management, explaining that when AI takes volume off the queue, analysts can focus on novel attack patterns and high-stakes decisions.
The video also contains points that are not on the case study page. Peterson said Daybreak is an opportunity to find vulnerabilities in Sophos's own products and to design agents with less restrictive guardrails. "We're a cyber security operator, so most of the work that we do is focused in areas that will trip guardrails," he said, adding that Daybreak lets the company get around that and build far more effective agents. When it joined in June, Sophos said it would adopt the capabilities in a phased way, with analysts and controls in the loop rather than giving customers direct access to the models.
METAL has previously reported on OpenAI expanding Daybreak with the cybersecurity model GPT-5.6-Cyber and on OpenAI providing Daybreak to the Ukrainian government. Peterson said Sophos will keep making its agents' response capabilities more sophisticated and broaden the use cases they cover. His advice to other security leaders is to return to layered fundamentals: patching, endpoint protection, multifactor authentication (MFA) and network segmentation. "Vulnerabilities are being discovered at an alarming rate and exploited at a scale that we've never seen," he said.
Seen through a lawyer's lens, the core of this case is the design of authority rather than speed. Even at 89 seconds, an agent can act on a customer's behalf only in cases where the customer has chosen Authorise, and the line of responsibility is drawn by the operating mode agreed with the customer. The more a model provider opens looser guardrails to a security vendor, the more a delegation structure like these three tiers decides what that agent may do inside a customer's systems.





Comments