# Building the partner ecosystem with Sophos

## Executive summary

Sophos, a major cybersecurity firm, detailed how its partnership with OpenAI and the use of 'Daybreak' programs allows it to leverage Frontier Intelligence to significantly automate and accelerate threat detection and response. The discussion highlighted that while AI agents can drastically reduce investigation times (from an average of 38 minutes to 89 seconds), human expertise remains critical for final judgment, especially for destructive response actions. The overall trend emphasizes scaling compute power and automation over relying solely on scarce human security talent.

## Key takeaways

- The Accelerating Threat Landscape: The 'defender's window' is narrowing due to the rapid pace of frontier intelligence, leading to more sophisticated cyber capabilities and a massive increase in reported CVEs.
- AI-Driven Response Acceleration: By leveraging Daybreak-powered agents, Sophos has reduced the average investigation time for security cases from approximately 38 minutes to about 89 seconds, automating half of the cases handled.
- Scaling Compute vs. Personnel: The value of advanced MDR solutions lies in helping organizations scale compute resources and automation capabilities, mitigating the global shortage of skilled security operations analysts.

## Technical details

- Sophos Fusion System: This system powers Sophos' Managed Detection and Response (MDR), EDR, and XDR products, leveraging sensor data from over 500 third-party integrations and internal products. It processes trillions of daily events, distilling them into a manageable number of investigation cases.
- Automated Investigation Workflow: Investigation agents take case information (detections, IoCs, customer context) and feed it into a planning model, which executes a 'plan-execute-review' loop to create an investigation plan, conduct steps, and generate recommended response actions for human analysts.
- MDR Operating Modes: Sophos structures its MDR service into three modes to align with customer comfort and expertise: 1) Notify (SOC investigates, recommends, but never acts); 2) Collaborate (Full investigation, but requires customer involvement for response); and 3) Authorize (Fully authorized to take response actions on behalf of the customer).

## Practical implications

- For build engineers, the shift toward automated security response models (XDR/MDR) demonstrates a clear trend: operational efficiency is achieved by integrating advanced AI models into core infrastructure processes.
- The concept of 'plan-execute-review' loops, used in security agents, is analogous to advanced CI/CD pipelines, where automated steps are followed by mandatory human review before deployment/action.
- The necessity of maintaining strong fundamentals (MFA, network segmentation, patching) must be balanced with the adoption of cutting-edge AI capabilities.

## Topics

Cybersecurity, AI/Machine Learning, Automation, MDR/XDR, Threat Intelligence, Sophos, Daybreak Program, Sophos Fusion

Source: https://www.youtube.com/watch?v=zoohZ1BiHs0
