Search papers, labs, and topics across Lattice.
This study investigates the integration of Large Language Models (LLMs) in Security Operation Centers (SOCs) through semi-structured interviews with 20 practitioners, revealing both perceived benefits and significant limitations. While participants noted time savings for low-stakes tasks, they expressed a lack of trust in LLM outputs for high-stakes decisions due to issues like hallucinations and opaque reasoning. The authors propose a maturity rubric for assessing LLM integration readiness and advocate for enhanced auditability and transparency to improve safety in SOC workflows.
SOC practitioners view LLMs as helpful for low-stakes tasks but remain skeptical about their reliability for critical security decisions.
Large Language Models (LLMs) are increasingly being explored within Security Operation Centers (SOCs) to support text-heavy analytical work such as alert contextualization, incident summarization, and drafting investigative artifacts. Despite this interest, practitioners describe critical operational concerns, most notably hallucinations (plausible but incorrect outputs), opaque reasoning, and the verification effort required to safely use model-generated content in security workflows. In this paper, we present findings from semi-structured interviews with 20 SOC practitioners spanning frontline analysts, SOC managers, and tool developers. Participants report perceived time savings for low-stakes tasks that are quickly verifiable (e.g., summarizing logs or drafting initial investigative leads), but they consistently frame LLM outputs as preliminary drafts and suggestions rather than decision-grade conclusions. Participants also describe limited trust in LLMs for high-stakes security decisions due to unreliable outputs and unclear model reasoning, and they report relying primarily on ad-hoc verification norms and continuous human oversight rather than standardized mitigation procedures. Based on these interview-grounded accounts, we introduce a maturity rubric to characterize readiness for LLM integration and outline a research agenda emphasizing auditability and transparent explanation mechanisms to support safer adoption in SOC workflows.