Sophos has moved to accelerate security operations by integrating OpenAI Daybreak agents into its Fusion platform and Managed Detection and Response (MDR) service. The company says the deployment has slashed the average time to handle a case from roughly 38 minutes to about 89 seconds and now resolves approximately 52% of MDR cases end-to-end within analyst-defined boundaries.
The OpenAI Daybreak agents are combined with Sophos’s existing threat intelligence, playbooks and security expertise to augment analyst effectiveness across more than 625,000 customer organisations. Sophos Fusion aggregates telemetry from its own sensors and more than 500 third-party integrations. Those inputs generate trillions of events each day; Sophos filters that stream down to roughly 1,000–2,000 cases that its nine security operations centres investigate.
Within that workflow agents and human investigators have clearly defined duties. An investigation agent collects contextual data for a case, including detections, indicators of compromise and relevant threat intelligence. A dedicated planning model then runs a plan–execute–review loop: it outlines investigation steps, performs permitted actions, and produces a summary with recommended response actions for analysts to review. Where configured, additional agents can carry out parts of the response plan.
Crucially, Sophos has implemented three operating modes that give customers control over automation: Notify, Collaborate and Authorise. In Notify mode Sophos investigates and recommends actions for the customer to take; in Collaborate mode Sophos and the customer coordinate before any action; and in Authorise mode Sophos is permitted to respond on the customer’s behalf. Sophos reports these same boundaries apply whether work is done by human analysts or by agents.
Potentially destructive or high-risk actions are restricted and require human oversight. Sophos says tasks that it does not trust an agent to handle are escalated to analysts, preserving human judgement for sensitive decisions. That combination of automated data gathering and human review is designed to speed routine processing while keeping responsibility and control with people and customers.
On operational outcomes, Sophos highlights dramatic reductions in case handling time. The company reports an average investigation time of about 38 minutes before deploying agents; cases handled with the Daybreak-based agents now average approximately 89 seconds. Sophos also says those agents enable it to resolve 52% of MDR cases end-to-end within analyst-calibrated limits.
Beyond raw speed, the company points to improved consistency and scale. Customers receive faster, more consistent investigations, Sophos says, and the service can expand protective coverage by increasing compute capacity rather than matching growth with equivalent specialised headcount. The firm argues that automation frees analysts to concentrate on complex threats, exceptions and judgement-heavy decisions that require human expertise.
Looking ahead, Sophos plans to broaden the capabilities of its agents, making response actions more sophisticated and widening the range of use cases addressed by the Daybreak-built agents. The company frames its work with frontier models as a way to keep pace with evolving attacker techniques by embedding leading-edge intelligence directly into operational processes.
Sophos also stresses that deploying model-driven automation does not replace basic security fundamentals. The vendor recommends maintaining layered defenses—endpoint protection, multifactor authentication, network segmentation—and good hygiene such as patching. Those measures remain important as new vulnerabilities continue to be found and exploited.
This deployment provides a concrete example of how large models can be applied to security operations: combining model-driven automation, curated domain knowledge and human oversight can materially reduce time-to-response and increase throughput for managed security services. For organisations weighing generative and frontier models, Sophos’s approach offers a template for applying those technologies to operational workflows while keeping human operators and customer controls central to decision-making.
As Sophos expands agent capabilities, the balance between automated efficiency and human governance will remain a core element of its MDR service. The company’s reported reductions in investigation time and its claim of resolving roughly half of cases end-to-end illustrate the potential payoff—and the continued need for careful controls—when applying large models in live security environments.
Source: Read the original source

Leave a Reply