The role of Artificial Intelligence in SOC operations: Adoption, perception, and workforce impact

Daniel Boughton*, Iain Reid

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

This paper examines the incorporation of artificial intelligence (AI) in cybersecurity operations, with a specific focus on applied machine learning within Security Operations Centres (SOCs). A mixed-methods approach was used, surveying 58 cybersecurity professionals from sectors including banking, healthcare, and technology, to investigate adoption, perceived advantages and drawbacks, and the implications for the human workforce. Quantitative results indicate extensive use of machine learning for alert triage and behavioural analytics, while qualitative findings underscore conditional trust, deficiencies in training, and the evolving dynamics of analyst roles. Thematic analysis identified fundamental categories such as AI as copilot, explainability and trust, and ethical risk. These findings indicate that although machine learning improves efficiency and alleviates cognitive burden, its adoption relies on transparent governance, continuous human monitoring, and professional development. This study enhances academic and industrial discussions by prioritising practitioner perspectives and clarifying the socio-technical considerations of machine-learning adoption in SOCs.
Original languageEnglish
Title of host publicationProceedings of the 11th International Workshop on Socio-Technical Perspectives in Information Systems (STPIS 2025)
EditorsMarija Topuzovska Latkovikj, Peter Bednar, Mikko Rajanen, Joakim Kävrestad, Helena Vallo Hult, Amany Elbanna
PublisherCEUR Workshop Proceedings
Number of pages12
Volume4134
Publication statusPublished - 20 Dec 2025
Event11th International Workshop on Socio-Technical Perspectives in Information Systems: STPIS 2025 - North Macedonia, Skopje, Macedonia, The Former Yugoslav Republic of
Duration: 17 Sept 202518 Sept 2025
Conference number: 11
https://stpis.org/

Publication series

NameProceedings of the International Workshop on Socio-Technical Perspectives in Information Systems
PublisherCEUR Workshop Proceedings
ISSN (Electronic)1613-0073

Conference

Conference11th International Workshop on Socio-Technical Perspectives in Information Systems
Abbreviated titleSTPIS 2025
Country/TerritoryMacedonia, The Former Yugoslav Republic of
CitySkopje
Period17/09/2518/09/25
Internet address

Keywords

  • Artificial intelligence
  • machine learning
  • Security Operations Centres
  • SOC
  • human factors
  • workforce1

Fingerprint

Dive into the research topics of 'The role of Artificial Intelligence in SOC operations: Adoption, perception, and workforce impact'. Together they form a unique fingerprint.

Cite this