A Sociotechnical, Practitioner-Centered Approach to Technology Adoption in Cybersecurity Operations: An LLM Case
Through a six-month ethnographic study and sociotechnical co-creation process grounded in Nonaka's SECI model, this paper demonstrates that embedding researchers with cybersecurity practitioners to iteratively develop LLM companion tools effectively overcomes traditional adoption barriers like trust and workflow misalignment, leading to sustained technology integration in security operations centers.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
The Big Picture: Building a Better Co-Pilot for Cybersecurity
Imagine a Security Operations Center (SOC) as a high-stress, 24/7 air traffic control tower for a massive airport. The "analysts" are the controllers. Their job is to watch thousands of screens, spot incoming storms (cyberattacks), and guide planes (data) safely to the ground.
For years, these controllers have been overwhelmed. They are drowning in paperwork, juggling too many different radio frequencies (software tools), and trying to find needles in haystacks. They are tired, and they are skeptical of new gadgets. Every time a new "smart" tool is dropped in from the outside, they worry it will break their workflow, give them wrong directions, or make them look foolish if it fails.
The Problem: Researchers often build fancy AI tools in a lab, hand them to the controllers, and say, "Here, use this!" But the controllers usually reject them because the tools don't fit the messy reality of their day-to-day jobs.
The Solution in this Paper: Instead of handing over a finished product, two researchers (PhD students) moved into the control tower for six months. They didn't just watch; they put on the headset, sat in the chairs, and did the job alongside the analysts. They used a method called Co-Creation to build AI tools with the analysts, not for them.
The Journey: How They Did It (The "SECI" Recipe)
The researchers used a recipe for turning "gut feelings" into "working tools" called the SECI Model. Think of this like turning a secret family recipe into a cookbook that everyone can use.
Socialization (The "Coffee Chat"):
- The Metaphor: The researchers hung out with the analysts, watched them work, and listened to their complaints. They learned the "unwritten rules" and the hidden frustrations that never make it into official manuals.
- What happened: They realized the analysts were wasting hours copying and pasting data between five different screens just to answer one simple question.
Externalization (The "Whiteboard Session"):
- The Metaphor: The researchers asked, "If you could wave a magic wand, what would you change?" They turned those vague complaints ("I hate this part") into clear, written problems ("I need a tool that pulls data from Screen A and Screen B automatically").
- What happened: They identified three main pain points: writing complex search queries, finding missing computer assets, and writing incident reports.
Combination (The "Kitchen"):
- The Metaphor: This is where they started cooking. They built three specific AI "assistants" (tools) to solve those three problems.
- The Tools:
- The Query Builder: A smart assistant that helps write complex search codes (like a spell-checker for hackers).
- The Asset Detective: A tool that automatically checks which computers are "missing" from the security list.
- The RCA Writer: A tool that takes messy logs and writes a clean, structured report on what went wrong (Root Cause Analysis).
Internalization (The "Test Drive"):
- The Metaphor: They didn't just launch the tools and leave. They watched the analysts use them, saw where they got stuck, and tweaked the tools.
- The Result: Slowly, the analysts stopped saying "This is annoying" and started saying, "Hey, this saves me 20 minutes." The tools became part of their muscle memory.
The Twist: Why These AI Tools Were Different
Usually, when you give a human a tool, the tool just does what it's told. But these LLM (Large Language Model) tools were different. They were like creative interns rather than robots.
- Generative Recombination: Instead of just following a strict rule, the AI could look at past reports, search the company's internal database, and create a brand new summary or search query that didn't exist before. It was like a chef who doesn't just follow a recipe but invents a new dish based on the ingredients in the fridge.
- Trust Calibration: Because AI can sometimes "hallucinate" (make things up), the analysts didn't blindly trust it. They treated the AI's output as a draft. They would read it, check the facts, and then sign off on it.
- The Metaphor: Imagine a junior lawyer writing a contract. The senior lawyer (the analyst) doesn't just throw it away; they review it, fix the errors, and then use it. The AI became a "junior partner" that made the senior partner faster, not a replacement.
The Key Takeaways
- Don't Build in a Vacuum: You can't build a tool for a specific job unless you sit in the chair of the person doing that job. The researchers succeeded because they became "insiders."
- Trust is Earned, Not Given: The analysts were skeptical at first. Trust was built slowly by showing that the tools actually saved time and didn't break anything.
- AI is a Co-Pilot, Not the Pilot: The goal wasn't to replace the security experts with AI. The goal was to give them a "super-power" so they could focus on the hard thinking while the AI handled the boring data crunching.
- The "Human-in-the-Loop" is Essential: The AI generates the ideas, but the human validates them. This "check-and-balance" system is what made the technology safe and reliable enough for a high-stakes environment.
The Bottom Line
This paper proves that the best way to bring advanced AI into a workplace isn't to drop a shiny new gadget on their desk. It's to roll up your sleeves, work alongside the team, understand their daily struggles, and build a tool that fits perfectly into their life. When you do that, the "magic" of AI stops being scary and starts being helpful.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.