John Peterson, CTO of Sophos, explains how the company leverages advanced AI-driven programs like Daybreak and partnerships with organizations such as OpenAI to enhance their managed detection and response services, significantly reducing threat investigation times and improving cybersecurity efficiency. He emphasizes the importance of combining cutting-edge technology with fundamental security practices to help organizations effectively defend against increasingly sophisticated cyber threats.
In this discussion, John Peterson (JP), Chief Technology Officer at Sophos, introduces Sophos as a leading global cybersecurity company with over 650,000 customers across various sectors. He highlights Sophos’s extensive experience of over four decades in combating a wide range of cyber threats. The conversation centers around the concept of the “defender’s window,” which refers to the shrinking time defenders have to respond to increasingly sophisticated cyberattacks fueled by advancements in frontier intelligence and AI models. JP emphasizes that Sophos leverages programs like Daybreak to stay ahead of attackers and protect both their own infrastructure and their customers.
JP explains how Sophos combines its deep cybersecurity domain expertise with frontier intelligence provided by partnerships with organizations like OpenAI. Sophos brings threat intelligence, incident response playbooks, and expert personnel to the table, while AI-driven programs help scale these capabilities to handle the vast volume of security events generated daily. This synergy allows Sophos to enhance its managed detection and response (MDR) services and improve overall customer protection by automating and accelerating threat investigations.
A practical example is provided through Sophos Fusion, the system powering their MDR and endpoint detection and response (EDR) products. Fusion integrates data from over 500 security sensors, generating trillions of events daily, which are distilled into a manageable number of cases for investigation. Historically, human analysts handled these cases with an average investigation time of 38 minutes. However, with AI-powered agents developed through the Daybreak program, Sophos has reduced this average response time to just 89 seconds for half of the cases, significantly improving efficiency and consistency in threat response.
JP discusses how the time saved through automation is redirected to addressing the cybersecurity skills shortage by enabling existing analysts to focus on more complex tasks. Sophos operates its MDR service in three modes—notify, collaborate, and authorize—allowing customers to choose their preferred level of involvement in response actions. While AI agents automate much of the investigation process, human judgment remains critical, especially for potentially destructive responses, ensuring a balance between speed and caution.
To conclude, JP stresses the importance of maintaining cybersecurity fundamentals amid rapid technological advancements. He advises security leaders to prioritize basic measures such as patch management, strong endpoint protection, multi-factor authentication, network segmentation, and robust security operations programs. Sophos supports customers in all these areas and invites organizations to engage with them to strengthen their defenses in an increasingly challenging threat landscape.