
Tech • AI • Robotics • Game
Sophos says AI-driven security operations have cut average investigation times from 38 minutes to 89 seconds for many cases, while human oversight remains central for higher-risk response actions.
Sophos describes itself as one of the world’s largest cybersecurity companies, serving about 650,000 customers across sectors and regions. That scale gives it visibility into a wide range of attack techniques and operating environments, built on roughly four decades in cybersecurity.
The company says the pressure on defenders is rising as advanced AI capabilities spread from frontier models into more accessible tools. At the same time, vulnerability volume has climbed sharply, increasing the speed at which attackers can identify and exploit weaknesses and narrowing the time defenders have to react.
Sophos positions its role as combining cyber domain expertise with advanced AI. That includes threat intelligence, incident-response playbooks and analyst knowledge, while AI is used to scale those capabilities across a large customer base rather than relying only on scarce human specialists.
The company’s Fusion platform underpins its managed detection and response service as well as its EDR and XDR products. It ingests sensor data from more than 500 integrations spanning third-party and in-house security tools, generating trillions of events per day that are reduced to about 1,000 to 2,000 cases daily for investigation across nine security operations centers.
About 18 months ago, Sophos said its average investigation time was 38 minutes, a level it said outperformed 96% of professional security operations centers. With AI agents now handling roughly half of cases, the average response time for those agent-assisted investigations has dropped to around 89 seconds, a change the company called transformative for both efficiency and customer outcomes.
Sophos said its investigation agent takes in case data, customer context, detections, indicators of compromise and threat-landscape knowledge. A planning model then runs a plan-execute-review loop, produces an investigation plan, carries out steps, summarizes findings for analyst review and recommends response actions, with additional agents able to automate parts of remediation.
The company argues that AI helps it use limited expert talent more effectively in a market where experienced security analysts remain in short supply. Rather than scaling only through headcount, Sophos says automation lets it expand protection by scaling compute and workflows while keeping expert staff focused on the cases that most need judgment.
Sophos structures its managed response service around three modes: Notify, where investigations are completed but no response action is taken on the customer’s behalf; Collaborate, where action is taken only with direct customer involvement; and Authorize, where Sophos is permitted to respond independently. The model is designed to match a customer’s own expertise, risk tolerance and comfort with delegated response.
Even as investigation automation expands, Sophos says potentially destructive actions in customer environments still require human supervision. The company expects response capabilities to become more sophisticated and cover more use cases, but maintains that protecting customers and preserving operations requires human judgment whenever the stakes are high.
Despite the focus on AI, Sophos argues that fundamentals matter more than ever: strong patching programs, high-quality endpoint protection, MFA across identity systems, network segmentation and a mature security operations capability. Its message is that AI can accelerate defense, but it does not replace the core controls needed to reduce exposure.
Sophos is betting that AI agents can dramatically accelerate cyber investigations without removing human accountability from critical decisions. The broader lesson for security leaders is that faster automation works best when built on strong operational fundamentals and clear boundaries for machine-led response.
Ask a question