Lilith.
⌕
Editorial illustration: Sophos cut threat response from 38 minutes to 89 seconds
Lilith illustration · editorial remix

OpenAI has published a customer study in which Sophos says it reduced average investigation and response time for agent handled cases from about 38 minutes to 89 seconds, a 96% drop. The company also says AI now closes 52% of its Managed Detection and Response cases from start to finish.

The agent assembles evidence before proposing action

The system runs inside Sophos Fusion, which combines the vendor's own telemetry with more than 500 third party integrations. Sophos says trillions of daily events are narrowed into roughly 1,000 to 2,000 cases for nine security operations centers.

An investigation agent collects customer context, detections, indicators of compromise and threat intelligence. A planning model builds and executes an investigation, then produces recommended response actions. Other agents can perform parts of the response. Direct access to the primary OpenAI page was blocked during verification, but its indexed text and a separate Sophos announcement support these details.

The gain comes from faster triage, not fewer alerts

The security team gets more than a quicker summary. Agents take over repeatable work between detection and judgment, leaving analysts to handle exceptions and ambiguous cases. For a SOC operator, the operational promise is more capacity without matching growth in scarce specialist headcount.

The deployment also shows where enterprise agents have a credible shape: a defined input, a constrained toolset, a recorded sequence of actions and a human who can take control. That workflow is easier to measure than a general chatbot placed over company data.

Company metrics do not reveal how many cases come back

The 89 second and 52% figures come from Sophos and OpenAI, not an independent comparison. An average also hides tail latency, incorrectly closed cases and interventions later repaired by an analyst. A fast response is not the same as a correct remediation.

Customers choose among Notify, Collaborate and Authorise modes. The boundaries apply to people and agents alike, while potentially destructive actions retain human oversight. Enforced permissions matter more here than the wording of a prompt.

Reopened cases and action logs will decide the result

The next useful measures are reopened cases, false closures, actions outside authorization and time to safe recovery. Sophos will also need to show whether 52% automation holds as it gives agents more sophisticated responses and a broader case mix.

MDR buyers should ask for an action level matrix that states what an agent may do alone, what requires approval and how each step can be reversed. Eighty nine seconds becomes an operational advantage only when it does not leave a badly resolved incident behind.

Lilith's verdict

An agent that closes an incident in 89 seconds is impressive. The audit will show whether the analyst finds an unlocked door behind it.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗ ↗