Sophos Deploys OpenAI Daybreak Agents in Managed Threat Response
The cybersecurity provider says its agents now resolve 52% of managed detection and response cases end to end, while customer permissions and analyst review still govern sensitive actions.
Edited by Tyronne Panaino
Sophos is using agents built through OpenAI's Daybreak program inside its managed detection and response workflow, according to an OpenAI customer case study published October 9. Sophos reports that 52% of its MDR cases are now resolved end to end with AI within boundaries set by its analysts, and that the average response time for cases using the agents fell from about 38 minutes to 89 seconds.
The deployment matters to security operations leaders because it shows an agent system being used across investigation and response rather than only for isolated analyst assistance. It also exposes the controls that remain around the automation: Sophos keeps customer authorization modes in place and says potentially destructive actions still require an appropriate level of human oversight.
What changed inside Sophos Fusion
OpenAI describes Sophos Fusion as the operating centre for this work. The system combines signals from more than 500 third-party integrations with Sophos products. Sophos says those sensors generate trillions of events each day, which are narrowed to roughly 1,000 to 2,000 cases for nine security operations centres to investigate.
Agents built through Daybreak now participate in handling those cases. An investigation agent assembles customer context, detections, indicators of compromise and relevant threat intelligence. A planning model then creates a plan, performs the steps, reviews the work and prepares a summary with recommended response actions for an analyst. Other agents can carry out parts of the response.
This is a more consequential use than drafting a query or summarizing an alert. The agent loop has access to case context and can help move an incident from evidence collection toward a recommended or executed response. The practical question is therefore not only whether the model is capable, but also which authority it receives and when a person must intervene.
Customer permissions still shape agent authority
Sophos retains three operating modes for its MDR customers. In Notify mode, Sophos investigates and recommends a response while the customer performs the action. Collaborate mode requires Sophos and the customer to work together before action. Authorise mode allows Sophos to respond directly for the customer.
The same boundaries apply whether the work is performed by a person or an agent. That design keeps the automation inside the service's existing authorization model instead of granting every agent the same ability to act. Sophos also says work it does not consider suitable for an agent is escalated for human judgement.
For buyers, that makes configuration and governance as important as speed. A faster investigation loop is useful only when identity, logging, escalation, customer consent and response authority remain clear for each action. The case study establishes Sophos's stated operating model, but it does not independently verify how consistently those controls work across customers or incident types.
The reported speed gain needs context
Sophos reports that its earlier process averaged around 38 minutes and that cases using the new agents average about 89 seconds, which OpenAI presents as a 96% reduction. It also reports that AI resolves 52% of MDR cases end to end within analyst-calibrated boundaries. Those are material operational claims, but they come from a partner case study rather than an independent evaluation.
The published page does not provide the measurement window, case mix, sample size, control group, false-positive rate or customer-level outcome data behind the figures. It also does not separate time saved in evidence gathering from time saved in remediation. The results should therefore be read as Sophos's reported production experience, not as a general benchmark for every security operations centre or every Daybreak deployment.
What to watch next
The next useful checkpoints are independently reviewed results, a clearer account of which cases qualify for end-to-end automation, error and escalation rates, and evidence that faster handling improves containment without increasing harmful actions. Buyers will also need to understand how the three customer modes are audited and how Sophos measures performance when an agent hands a case back to a person.
OpenAI says Sophos protects more than 625,000 organisations, so the operating pattern is relevant beyond a small pilot. Scale alone does not prove effectiveness, however. The strongest future evidence would connect the reported response-time improvement to incident quality, customer outcomes and stable human-control performance over time.
Status
Confirmed. OpenAI has published Sophos's operational account and the described workflow is presented as live. Internal confidence is medium because the evidence is a single first-party partner case study and its performance figures have not been independently validated in the fetched record.
Sources
Update note: Last reviewed 2026-10-09. We will revise this post if Sophos or an independent evaluator publishes methodology, error rates, customer outcomes or broader deployment evidence.
Sources
- OpenAI — Sophos Daybreak customer case study — official
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.