Tech • AI • Robotics • Game

VIDEO
ENFR

Building the Partner Ecosystem with Sophos

8/10
AIOpenAISeptember 29, 2026 at 10:00 AM13:31
Audio player
0:00 / 0:00

TL;DR

Sophos says AI-driven security operations have cut average investigation times from 38 minutes to 89 seconds for many cases, while human oversight remains central for higher-risk response actions.

KEY POINTS

Sophos scale and market reach

Sophos describes itself as one of the world’s largest cybersecurity companies, serving about 650,000 customers across sectors and regions. That scale gives it visibility into a wide range of attack techniques and operating environments, built on roughly four decades in cybersecurity.

A shrinking defender window

The company says the pressure on defenders is rising as advanced AI capabilities spread from frontier models into more accessible tools. At the same time, vulnerability volume has climbed sharply, increasing the speed at which attackers can identify and exploit weaknesses and narrowing the time defenders have to react.

Domain expertise paired with AI

Sophos positions its role as combining cyber domain expertise with advanced AI. That includes threat intelligence, incident-response playbooks and analyst knowledge, while AI is used to scale those capabilities across a large customer base rather than relying only on scarce human specialists.

How Fusion processes security data

The company’s Fusion platform underpins its managed detection and response service as well as its EDR and XDR products. It ingests sensor data from more than 500 integrations spanning third-party and in-house security tools, generating trillions of events per day that are reduced to about 1,000 to 2,000 cases daily for investigation across nine security operations centers.

Investigation speed improved sharply

About 18 months ago, Sophos said its average investigation time was 38 minutes, a level it said outperformed 96% of professional security operations centers. With AI agents now handling roughly half of cases, the average response time for those agent-assisted investigations has dropped to around 89 seconds, a change the company called transformative for both efficiency and customer outcomes.

How the AI agent works

Sophos said its investigation agent takes in case data, customer context, detections, indicators of compromise and threat-landscape knowledge. A planning model then runs a plan-execute-review loop, produces an investigation plan, carries out steps, summarizes findings for analyst review and recommends response actions, with additional agents able to automate parts of remediation.

Addressing the cybersecurity skills gap

The company argues that AI helps it use limited expert talent more effectively in a market where experienced security analysts remain in short supply. Rather than scaling only through headcount, Sophos says automation lets it expand protection by scaling compute and workflows while keeping expert staff focused on the cases that most need judgment.

Three response models for customers

Sophos structures its managed response service around three modes: Notify, where investigations are completed but no response action is taken on the customer’s behalf; Collaborate, where action is taken only with direct customer involvement; and Authorize, where Sophos is permitted to respond independently. The model is designed to match a customer’s own expertise, risk tolerance and comfort with delegated response.

Humans still control destructive actions

Even as investigation automation expands, Sophos says potentially destructive actions in customer environments still require human supervision. The company expects response capabilities to become more sophisticated and cover more use cases, but maintains that protecting customers and preserving operations requires human judgment whenever the stakes are high.

Security basics remain the priority

Despite the focus on AI, Sophos argues that fundamentals matter more than ever: strong patching programs, high-quality endpoint protection, MFA across identity systems, network segmentation and a mature security operations capability. Its message is that AI can accelerate defense, but it does not replace the core controls needed to reduce exposure.

CONCLUSION

Sophos is betting that AI agents can dramatically accelerate cyber investigations without removing human accountability from critical decisions. The broader lesson for security leaders is that faster automation works best when built on strong operational fundamentals and clear boundaries for machine-led response.

Ask a question

More from AI