Sophos has cut the time it takes to investigate cyber threats by 96% with OpenAI’s Daybreak, according to a new case study from OpenAI. The security company also says AI now resolves 52% of its managed detection and response (MDR) cases from start to finish. OpenAI reports that human analysts still oversee the work.
This is one of the first real-world results from Daybreak, OpenAI’s program for bringing frontier models into cyber defense. In a field where every minute of delay helps an attacker, it’s a strong early number.
🛡️ The Problem: Too Many Alerts, Too Few Analysts
MDR is a service in which a security vendor watches a customer’s systems around the clock and responds to threats for them. It’s very labor-intensive. Every suspicious alert needs someone to collect evidence, work out what happened and decide whether it’s a real attack.
Sophos does this at a huge scale. The company says it protects more than 625,000 organizations, many of them through managed service providers and channel partners. At that size, the investigation step is the bottleneck. Analysts can only look at so many cases a day, and attackers aren’t waiting.
⚙️ The Solution: Frontier AI Inside the SOC
Sophos joined OpenAI’s Daybreak Cyber Partner Program in June 2026. It didn’t give customers direct access to OpenAI’s models. Instead, it built them into its own products and services and kept its analysts and controls in the loop.
The rollout is phased. It starts with defensive workflows and tightly scoped outputs. Sophos named three early focus areas:
- Faster MDR threat investigation: AI gathers and analyzes evidence that analysts used to collect by hand.
- Deeper security assessments: Sophos Advisory Services uses the models to dig further into client environments.
- Exposure management: It helps customers find, validate and fix weak spots before attackers find them.
The two companies are also working on standards for safety and abuse prevention, plus controls to spot and block unsanctioned use. That matters here more than in most industries. A model that’s good at finding weak spots for defenders could help attackers just as easily.
📊 The Results
OpenAI’s case study reports:
- 96% less time spent on threat investigation
- 52% of MDR cases handled end to end by AI
- Human oversight kept across the whole workflow
Sophos has also described its MDR service as an “agentic” security operations center, meaning AI agents carry out multi-step tasks on their own. It reports an average response time of 89 seconds. These are company-reported numbers and haven’t been independently audited.
🔍 Why It Matters
What stands out is the split. AI fully handles about half the cases, and people handle the rest with AI’s help. That’s a realistic model for security work, where a wrong automated call can lock out a whole company or miss a breach entirely.
It also shows how OpenAI is entering the enterprise security market. It isn’t building its own security product. It’s working through established vendors who already have the customers, the telemetry and the trust. Partners like Sophos bring the distribution. OpenAI brings the model.
There are caveats worth noting. The 96% figure covers investigation time, not total incident handling. It also comes from a vendor case study, not an independent benchmark. And the remaining 48% of cases still need human judgment. Those are often the hardest and most important ones.
🔭 What Comes Next
Expect more security vendors to announce similar numbers as Daybreak partnerships mature. The real test will be whether these gains hold against new, adaptive attacks rather than routine alerts. And whether 52% can climb without weakening the human checks that make the system trustworthy. Full details are available in OpenAI’s original case study.