OpenAIOriginal · English

Sophos cuts threat investigation time by 96% with OpenAI Daybreak

Discover how Sophos uses OpenAI’s Daybreak to cut cyber-threat investigation time by 96% and automate 52% of MDR cases while preserving human oversight.

Image source · OpenAI

Staying ahead as the defender’s window narrows

Frontier AI is changing cybersecurity on both sides⁠(opens in a new window). Advanced models can help defenders find and investigate threats faster. But those capabilities are also spreading to open-weight models, giving attackers new ways to discover vulnerabilities and accelerate exploitation.

Sophos⁠(opens in a new window) is one of the companies standing in their way, protecting more than 625,000 organisations across sectors and regions. “We see a huge variety of different attacks,” says John Peterson, the company’s Chief Technology Officer. “We’ve cultivated vast expertise in combating them over four decades in the cybersecurity business.”

Through OpenAI Daybreak, Sophos is combining OpenAI models with its own threat intelligence, response playbooks and security expertise. The aim isn’t simply to give analysts another tool. It’s to increase the impact of Sophos’s expertise across every customer it protects.

“Sophos brings the domain expertise and the know-how to combat attacks at scale. Programmes like Daybreak, and companies like OpenAI, bring frontier intelligence that allows us to take that domain expertise and scale it to support all of our customers.”

—John Peterson, CTO, Sophos

Inside the rollout

At the centre of the work is Sophos Fusion, the Sophos AI-native cyber defense system that includes Sophos Managed Detection and Response (MDR). It brings together sensor data from more than 500 third-party integrations alongside Sophos’s own products. Together, those sensors generate trillions of events every day, which Sophos distills into roughly 1,000 to 2,000 cases for its nine security operations centres to investigate.

Agents built through Daybreak have changed how those cases are handled. An investigation agent gathers the customer context, detections, indicators of compromise (IoCs) and relevant threat intelligence for each case. A planning model then creates a plan–execute–review loop: building an investigation plan, completing the steps and producing a summary with recommended response actions for analysts to review. Other agents can carry out parts of the response.

Before Daybreak, investigating and responding to a case depended primarily on human expertise. Sophos’s existing process averaged around 38 minutes — performance Peterson says was better than 96% of professional security operations centres.

“Now, because of the agents we’ve been able to build through the Daybreak programme, the average response time for cases using those agents has fallen to about 89 seconds. About half of the cases we handle are now being automated by agents we developed using the Daybreak models.”

—John Peterson, CTO, Sophos

Keeping judgement at the centre

Sophos has built customer control into its MDR service through three operating modes:

  • Notify: Sophos investigates the case and recommends a response, but the customer acts.

  • Collaborate: Sophos and the customer work together before action is taken.

  • Authorise: Sophos can respond directly on the customer’s behalf.

The same boundaries apply whether work is completed by a person or an agent. Sophos uses automation to move quickly and make better use of analysts’ time, but potentially destructive actions still require the right level of human oversight.

“Anything we don’t feel comfortable with an agent handling gets passed off for human judgement,” Peterson confirms.

Results at a glance

  • Reduced the average response time for cases using agents from approximately 38 minutes to 89 seconds.

  • Enabled Sophos to resolve 52% of MDR cases end-to-end with AI, within boundaries calibrated by Sophos analysts.

  • Gives customers a faster and more consistent investigation experience.

  • Helps Sophos scale compute rather than relying on equivalent growth in scarce cybersecurity headcount.

  • Returns analysts’ attention to the threats, exceptions and decisions where their expertise matters most.

What’s next

Peterson says Sophos will keep expanding what its agents can do. “The response capabilities are going to continue to become more sophisticated, and we’re going to broaden the range of use cases we address with the agents we’ve built.”

“With programmes like Daybreak, we have an opportunity to stay a step ahead of the attacker community.”

—John Peterson, CTO, Sophos

His advice for other security leaders is simple: “The one thing security leaders should do tomorrow is really come back to focusing on the security fundamentals for their organization,” he says. “That of course includes patching. But patches are only ever going to include vulnerabilities that are known by the vendor.”

The answer is to maintain “a layered security approach” that includes endpoint protection, multifactor authentication (MFA), network segmentation and strong security operations. “Vulnerabilities are being discovered at an alarming rate and exploited at a scale that we’ve never seen. So I think doing the fundamentals well is more important today than it’s ever been.”

Join the new era of work

More than 1 million businesses around the world are achieving meaningful results with OpenAI.Contact sales
Original source

OpenAI

Content notes

Original publication and rights belong to the source.