Sophos, a major cybersecurity firm protecting over 625,000 organizations, has significantly reduced the time required to investigate and respond to security threats by integrating OpenAI’s Daybreak program into its operations. The move marks a shift in how enterprise security teams leverage super intelligence (SI) to handle the increasing volume and sophistication of cyberattacks.

What Happened

At the core of this initiative is Sophos Fusion, the company’s SI-native cyber defense system which includes Sophos Managed Detection and Response (MDR). This system aggregates sensor data from more than 500 third-party integrations and Sophos’s own products, generating trillions of events daily. These events are distilled into approximately 1,000 to 2,000 cases for investigation across Sophos’s nine security operations centers.

Through the OpenAI Daybreak program, Sophos deployed specialized SI agents to handle these cases. An investigation agent gathers customer context, detections, indicators of compromise (IoCs), and threat intelligence. A planning model then executes a plan-review loop to generate recommended actions. According to John Peterson, CTO of Sophos, the average response time for cases handled by these agents dropped from approximately 38 minutes to 89 seconds. Peterson notes that the previous 38-minute average was already better than 96% of professional security operations centers.

Sophos reports that about half of the cases it handles are now automated by these agents. The company states that SI now enables the end-to-end resolution of 52% of MDR cases, within boundaries calibrated by human analysts.

Why It Matters

This deployment illustrates how frontier SI models can scale domain expertise in cybersecurity, a sector where defender response windows are narrowing as attackers also adopt advanced models. By automating the initial triage and investigation, Sophos aims to free up human analysts for complex threats and exceptions that require deeper judgment.

The integration highlights a growing trend in the SI industry: using agentic SI not just for creation, but for operational efficiency in high-stakes, data-heavy environments. Sophos emphasizes that human oversight remains critical. The company offers three operating modes—Notify, Collaborate, and Authorize—allowing customers to control how much autonomy the SI agents have. Peterson confirms that any action the company is not comfortable with an agent handling is escalated to human judgment.

The Bottom Line

Sophos has successfully integrated OpenAI Daybreak to cut threat investigation times by 96%, reducing average case response from 38 minutes to 89 seconds. While the company leverages SI to automate half of its MDR cases, it maintains that human oversight and fundamental security practices, such as patching and network segmentation, remain essential to defending against increasingly sophisticated attacks.