Sophos integrated OpenAI's Daybreak model into its Managed Detection and Response platform and cut threat investigation time by 96%. The system now automates 52% of MDR cases end-to-end, handling triage, correlation, and initial response without human intervention on the majority of incoming alerts.
The case study is worth reading in full because the architecture decisions matter as much as the headline numbers. Sophos did not simply bolt an LLM onto existing tooling. The implementation details around how Daybreak handles multi-signal correlation across endpoint, network, and identity telemetry, and where the system is explicitly designed to escalate to human analysts, reveal a deliberate approach to preserving oversight rather than eliminating it.
The 96% figure will dominate coverage, but the more consequential question is what happens to the 48% of cases that still require human review. The original piece addresses this directly, and the answer has implications for every security vendor now racing to make similar automation claims.
[READ ORIGINAL →]