Summary
OpenAI hosts Sophos Chief Technology Officer John Peterson to discuss how a large cybersecurity company is using frontier AI through OpenAI’s Daybreak program. The conversation centers on the narrowing defender’s window: as frontier models and increasingly capable open-weight models make exploitation faster and CVE volumes rise, defenders need to use the same intelligence to stay a step ahead.
Peterson describes the Sophos Fusion system, which powers its managed detection and response service and EDR and XDR products. Data from more than 500 third-party integrations produces trillions of daily events, distilled to roughly 1,000 to 2,000 cases a day handled by nine security operations centers. An investigation agent now ingests case details, customer context, detections and threat intelligence, then runs a plan, execute and review loop to produce a summary and recommended response actions. Sophos reports that average investigation time, previously about 38 minutes, has been roughly halved.
The discussion also covers how the division of labor works between Sophos domain expertise and OpenAI’s frontier models, how AI lets the company scale compute instead of headcount amid a cybersecurity skills shortage, and how Sophos decides when agents should act on findings and when humans should stay in the loop.
📺 Source: OpenAI · Published September 29, 2026
🏷️ Format: Interview







