OpenAI Daybreak cuts Sophos investigation time
OpenAI Daybreak agents cut Sophos’s average threat-response time from roughly 38 minutes to 89 seconds, a reported 96% reduction. The agents now resolve 52% of MDR cases end-to-end while human analysts retain control over consequential actions.
Daybreak’s strongest signal is workflow integration, not model novelty: the agents turn Sophos’s telemetry, threat intelligence, and playbooks into a governed investigation loop.
- –Agents correlate data from 500+ integrations and distill trillions of daily events into actionable cases.
- –A plan-execute-review loop gathers evidence, investigates indicators of compromise, and recommends response actions.
- –The 96% improvement is a vendor-reported customer result, applying to cases handled by the agents rather than every MDR incident.
- –Notify, Collaborate, and Authorise modes preserve human oversight for disruptive or uncertain responses.
- –The case supports managed security partnerships as a practical route for deploying frontier models without exposing customers directly to them.
DISCOVERED
1h ago
2026-10-09
PUBLISHED
1h ago
2026-10-09
RELEVANCE
AUTHOR
OpenAI