Frontier AI is changing cybersecurity on both sides. Advanced models help defenders find and investigate threats faster, but the same capabilities are spreading to open-weight models, giving attackers new ways to discover vulnerabilities and accelerate exploitation. Sophos, which protects more than 625,000 organisations, is working with OpenAI through the Daybreak programme to combine OpenAI models with its own threat intelligence, response playbooks and security expertise.
At the centre of the work is Sophos Fusion, the company's AI-native cyber defense system, which includes Sophos Managed Detection and Response (MDR). It draws sensor data from more than 500 third-party integrations and generates trillions of events daily, which are distilled into roughly 1,000 to 2,000 cases for its nine security operations centres. An investigation agent gathers customer context, detections, indicators of compromise and threat intelligence for each case, while a planning model runs a plan-execute-review loop that produces recommended response actions for analysts to review.
Before Daybreak, Sophos's process averaged about 38 minutes per case. For cases handled by Daybreak-built agents, the average response time has fallen to about 89 seconds, and about half of cases are now automated. Sophos resolves 52% of MDR cases end-to-end with AI, within boundaries set by its analysts.
Customer control remains central. Sophos offers three operating modes: Notify, where the customer acts on recommendations; Collaborate, where both parties work together before action; and Authorise, where Sophos can respond on the customer's behalf. Potentially destructive actions still require human oversight, whether carried out by a person or an agent.
Source: OpenAI Blog · Summarized by HeadlinesBriefing