⚡
Brief IA
›

Sophos Automates 52% of MDR Cases, Averaging 89 Seconds

🤖 Models & LLM·Tom Levy·

Sophos Automates 52% of MDR Cases, Averaging 89 Seconds

Sophos Automates 52% of MDR Cases, Averaging 89 Seconds
⚡
Key Takeaways
1Sophos announces it has reduced the average investigation time for cases handled by agents from OpenAI Daybreak to 89 seconds
252% of MDR cases are now automated, within limits set by analysts
3Three client control modes and human oversight frame the automation
💡Why it matters — Automation allows Sophos to accelerate threat response while maintaining human supervision over sensitive actions.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

Sophos claims to manage incidents faster thanks to agents built with OpenAI Daybreak. The company states it has reduced the average investigation time to 89 seconds and boasts a 96% reduction. Automation remains under client control, with levels of human supervision in place.

Three MDR Modes Frame Automation at Sophos

Sophos describes three operational modes in its MDR service to calibrate the level of intervention: Notify, Collaborate, and Authorize. The same limits apply whether an analyst or an agent is taking action, and potentially destructive operations remain subject to human oversight. John Peterson clarifies that anything that cannot be confidently managed by an agent is escalated to human judgment. According to the company, 52% of MDR cases can now be handled end-to-end by AI, within boundaries set by its analysts.

From 38 Minutes to 89 Seconds on AI-Processed Cases

Before the use of agents, Sophos indicates that investigations relied heavily on human expertise, with an average delay of around 38 minutes per case. John Peterson assesses this performance as better than 96% of professional SOCs. For cases processed by agents, he now places the average at around 89 seconds, representing a reduction that Sophos quantifies at 96%. The company claims to provide clients with faster and more consistent investigations, while allowing analysts to focus on critical decisions and growing its capabilities without a corresponding increase in staff. It reports that 52% of cases are managed by AI, and according to Peterson, about half of the cases are automated using Daybreak models.

A Technical Foundation Unites 500 Integrations and 1,000–2,000 Daily Cases

At the core of the system, Sophos Fusion, presented as a native AI defense system including MDR, aggregates streams from over 500 third-party integrations in addition to its own products. The company speaks of trillions of daily events reduced to about 1,000 to 2,000 cases to be processed by nine security operations centers. The agents developed via Daybreak operate at multiple levels: an investigation agent gathers context, detections, and IoCs, while a planning model chains together planning, execution, and review, with a summary and suggested actions for validation. Other agents handle certain response steps.

Daybreak Serves as a Lever, with Use Case Extensions in Sight

Sophos attributes the acceleration of its investigations to the OpenAI Daybreak program, which it leverages to combine AI models, internal intelligence, and playbooks. The stated ambition is to amplify the impact of in-house expertise for each client. John Peterson announces the ongoing enhancement of the agents, with more sophisticated responses and an expanded range of use cases, believing that this type of program helps maintain an edge over attackers. In a context where advanced models also benefit adversaries and their capabilities spread to open-weight models, the company claims to protect over 625,000 organizations. The Chief Technology Officer, drawing on four decades of experience at Sophos, advises security leaders to return to the fundamentals: apply patches, while acknowledging that they only cover known vulnerabilities, and maintain a layered approach combining endpoint protection, MFA, network segmentation, and robust operations. He considers the discovery and exploitation of vulnerabilities to be at an unprecedented pace and scale and emphasizes the quality of execution of the basics.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.