OpenAI has expanded its Daybreak Cyber Partner Program, granting selected cybersecurity firms and technology partners access to its advanced cyber models for security testing and defensive operations. The program, which was expanded on August 10, is designed to allow these partners to leverage OpenAI's models to identify and exploit vulnerabilities in client applications and infrastructure, without directly transferring the models to the end customers.
The Daybreak program offers two tiers: Daybreak Blue, which supports a broad range of defensive security workflows, and Daybreak Red, intended for more specialized and closely governed work such as red teaming and penetration testing. Access to both tiers is facilitated through Daybreak Access.
Sixteen companies have been named as initial partners. Nine are security and services firms: Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps. The remaining seven are technology partners: Palo Alto Networks Unit 42, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare.
Partners can utilize the models for various security engagements, including vulnerability discovery and validation, red teaming, penetration testing, incident response, and remediation across complex enterprise systems. The rationale behind this model is that partners, already familiar with their customers' systems and security operations, can effectively apply the models to identify exploitable weaknesses, assess risks, and implement fixes. This approach aims to provide advanced defensive capabilities to organizations that may not be able to deploy such models independently.
Milan Patel, global head of MDR services at Sophos, described the program as delivering "frontier-grade defense at scale." The program emphasizes that simply finding a flaw is insufficient; the critical work involves determining if a weakness is exploitable, identifying affected systems, defining the fix, and ensuring its deployment.
Safeguards within the program vary depending on the specific engagement. These can include identity verification, defined testing scopes, logging, monitoring, and human oversight. The exact controls applied are determined by the partners and their customers during contract negotiations, with partners reviewing findings and applying their judgment before any actions are taken.






