[KongchangAI]
· 2 min read· 1,143 words

Sophos Cuts Threat Response Time by 96% with OpenAI Daybreak

Sophos Cuts Threat Response Time by 96% with OpenAI Daybreak

Sophos used OpenAI-powered security agents to cut MDR response time from 38 minutes to 89 seconds—a 96% drop.

Sophos partnered with OpenAI to automate its MDR workflow end to end, building a plan-execute-observe agent loop around OpenAI's planning model. The loop automatically aggregates customer context, threat intelligence, and IOCs—taking over the most time-consuming manual triage steps—reducing average response time from ~38 minutes to 89 seconds (a 96% reduction). The division of labor: Sophos provides domain expertise, OpenAI provides scalable frontier intelligence. OpenAI's Daybreak program also gave Sophos a customized channel with relaxed guardrails, resolving the conflict between general-purpose model safety policies and legitimate security defense work.

The cybersecurity industry has long faced a fundamental challenge: attacks are accelerating in speed and scale, while the core elements of defense remain heavily reliant on human analysis. Sophos CTO John Peterson shared a set of compelling numbers from the company's collaboration with OpenAI — by deploying security operations agents built on OpenAI models, their Managed Detection and Response (MDR) business reduced average response time from roughly 38 minutes to just 89 seconds, a 96% reduction.

When Security Operations Meets AI Agents

John Peterson oversees all of Sophos's R&D, spanning product development, threat intelligence, and customer-facing support. He noted that organizations of all sizes are overwhelmed by the pace of attacks, and one of Sophos's core offerings — Managed Detection and Response (MDR) — exists to take on security operations on behalf of customers, keeping them protected as attacks continue to accelerate.

Sophos's core business is handling security operations for customers

The division of labor is straightforward: Sophos brings deep domain expertise in cybersecurity, while OpenAI contributes frontier intelligence — enabling Sophos to deploy that expertise at a scale covering all customers simultaneously. In other words, the model doesn't inherently understand security, but it can amplify the knowledge of security experts to a scale no human team could match.

From Manual Investigation to Automated Closed-Loop

Sophos's approach is to automate the security operations workflow end to end. The agents it built aggregate all customer context, threat posture information, and detection results and Indicators of Compromise (IOCs) associated with a given security incident, then feed this data into OpenAI's planning model.

Sophos focuses on end-to-end automation of the security operations workflow

The entire process is designed as a "plan, execute, observe" loop. This investigative workflow, previously driven largely by human analysts, has now been substantially automated using OpenAI's models and Sophos's own agents.

The previously human-driven investigation workflow is now largely automated

The value of this architecture lies not in replacing one isolated step with a model, but in chaining intelligence gathering, analysis, action execution, and feedback into a continuously operating pipeline. The most time-consuming parts of any investigation — information aggregation and initial triage — are precisely where agents excel.

Indicators of Compromise (IOCs) are a foundational concept in security analysis: technical artifacts found in systems or networks that indicate a potential intrusion. Common forms include malicious IP addresses, domains, file hashes, and anomalous registry keys. Their value lies in being shareable and machine-processable — security systems can automatically cross-reference against known IOC databases to quickly surface suspicious activity in massive log volumes. The traditional bottleneck is that a single security incident can involve dozens or even hundreds of IOCs, requiring analysts to manually cross-validate and correlate context — an extremely time-consuming process. With agents, this aggregation and correlation step can be completed in seconds, which is one of the primary reasons Sophos's response times dropped so dramatically. The planning model's role here is to dynamically determine which tools to invoke and which intelligence sources to query based on current IOCs and context, rather than executing a fixed rule script.

What a 96% Reduction in Response Time Actually Means

The data speaks for itself. Peterson noted that roughly two years to 18 months ago, the Sophos MDR team's average response time was around 38 minutes. After rolling out these agents continuously over the past year, that number has been compressed to 89 seconds.

MDR average response time was ~38 minutes two years ago; it's now down to 89 seconds

In security operations, response time often directly determines the blast radius of an attack. The window from initial intrusion to lateral movement and data exfiltration can be mere tens of minutes. Cutting response time from the half-hour range down to 90 seconds means defenders can intervene before an attack truly unfolds. This isn't just an efficiency gain — it fundamentally changes the time dynamics between attacker and defender.

Daybreak: Loosening the Guardrails for Security Use Cases

A key element of this collaboration is OpenAI's Daybreak program. For Sophos, Daybreak provides an opportunity to work directly with OpenAI and access the most capable frontier intelligence — both to identify vulnerabilities in its own products and to design agents with less restrictive guardrails.

Peterson candidly acknowledged a real tension: as a cybersecurity operations firm, much of Sophos's work inherently focuses on areas that are prone to "triggering guardrails" — analyzing malware, studying attack techniques, identifying exploits. Under a general-purpose model's safety policies, this content is likely to be blocked. The Daybreak program allows Sophos to work around these limitations and design agents that are genuinely effective for its business.

This highlights a fundamental tension in AI safety policy for specialized vertical use cases: the guardrails that general-purpose large models implement to prevent misuse can become obstacles in legitimate security defense work. Striking the right balance between "preventing malicious exploitation" and "empowering legitimate security practitioners" is a challenge that both model providers and security vendors must solve together.

Guardrails in large language models typically refer to a set of content safety policies — embedded by the model provider during training or at inference time — that refuse to generate content potentially usable for harmful purposes, such as detailed exploit code, malware analysis techniques, or social engineering scripts. These restrictions serve a reasonable protective purpose for general users, but create systemic friction for cybersecurity professionals: penetration testers need to understand attack methods, malware researchers need to reverse-engineer virus samples, and threat intelligence analysts need to describe real attack chains — all of which are entirely legitimate professional activities that can easily trigger a general model's blocking logic. The Daybreak program is essentially an enterprise-level customization partnership mechanism that allows security vendors with verifiable legitimate use cases to access adjusted model policies within agreed-upon usage boundaries, enabling their agents to handle high-risk content that would otherwise be restricted in consumer contexts. This is a textbook solution to the "general safety policy vs. specialized use case requirements" tension in large model commercialization.

Implications for the Industry

The Sophos case offers a relatively grounded AI deployment example. It doesn't claim that models replace security experts — instead, it uses a division of labor where "domain experts provide knowledge and frontier models provide scale" to embed agents into existing operational workflows. The real value comes from the "plan, execute, observe" closed loop built around the model, and the systematic integration of customer context and threat intelligence — not the model itself.

For security teams considering AI adoption, the key takeaway from this case is that gains typically come from automating specific high-latency bottlenecks rather than replacing entire workflows wholesale. At the same time, the guardrail problem in specialized scenarios needs to be addressed proactively with vendors. The 96% figure is striking, but what underpins it is solid engineering design and a clear division of responsibilities.

Share:

Related articles