{"id":"https://openalex.org/W7155527487","doi":"https://doi.org/10.48550/arxiv.2604.21679","title":"A Sociotechnical, Practitioner-Centered Approach to Technology Adoption in Cybersecurity Operations: An LLM Case","display_name":"A Sociotechnical, Practitioner-Centered Approach to Technology Adoption in Cybersecurity Operations: An LLM Case","publication_year":2026,"publication_date":"2026-04-23","ids":{"openalex":"https://openalex.org/W7155527487","doi":"https://doi.org/10.48550/arxiv.2604.21679"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2604.21679","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.21679","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2604.21679","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5134536411","display_name":"Francis Hahn","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hahn, Francis","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5040056167","display_name":"Mohd Mamoon","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Mamoon, Mohd","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034290852","display_name":"Alexandru G. Bardas","orcid":"https://orcid.org/0000-0003-3043-5905"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bardas, Alexandru G.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062112595","display_name":"Michael Collins","orcid":"https://orcid.org/0009-0006-0119-8129"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Collins, Michael","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034790397","display_name":"Daniel H. Lende","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Lende, Daniel","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113810433","display_name":"Xinming Ou","orcid":"https://orcid.org/0009-0007-2501-7991"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ou, Xinming","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5134513165","display_name":"S. Raj Rajagopalan","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Rajagopalan, S. Raj","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11024","display_name":"Information Systems Theories and Implementation","score":0.14959999918937683,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},"topics":[{"id":"https://openalex.org/T11024","display_name":"Information Systems Theories and Implementation","score":0.14959999918937683,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.11500000208616257,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10525","display_name":"Human-Automation Interaction and Safety","score":0.05480000004172325,"subfield":{"id":"https://openalex.org/subfields/3207","display_name":"Social Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/sociotechnical-system","display_name":"Sociotechnical system","score":0.8783000111579895},{"id":"https://openalex.org/keywords/workflow","display_name":"Workflow","score":0.7221999764442444},{"id":"https://openalex.org/keywords/multinational-corporation","display_name":"Multinational corporation","score":0.5874000191688538},{"id":"https://openalex.org/keywords/usable","display_name":"USable","score":0.5296000242233276},{"id":"https://openalex.org/keywords/ethnography","display_name":"Ethnography","score":0.5004000067710876},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.4986000061035156},{"id":"https://openalex.org/keywords/skepticism","display_name":"Skepticism","score":0.4659000039100647},{"id":"https://openalex.org/keywords/workaround","display_name":"Workaround","score":0.39340001344680786}],"concepts":[{"id":"https://openalex.org/C127627568","wikidata":"https://www.wikidata.org/wiki/Q1639361","display_name":"Sociotechnical system","level":2,"score":0.8783000111579895},{"id":"https://openalex.org/C177212765","wikidata":"https://www.wikidata.org/wiki/Q627335","display_name":"Workflow","level":2,"score":0.7221999764442444},{"id":"https://openalex.org/C158016649","wikidata":"https://www.wikidata.org/wiki/Q161726","display_name":"Multinational corporation","level":2,"score":0.5874000191688538},{"id":"https://openalex.org/C2780615836","wikidata":"https://www.wikidata.org/wiki/Q2471869","display_name":"USable","level":2,"score":0.5296000242233276},{"id":"https://openalex.org/C179454799","wikidata":"https://www.wikidata.org/wiki/Q132151","display_name":"Ethnography","level":2,"score":0.5004000067710876},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.4986000061035156},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4772999882698059},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4717000126838684},{"id":"https://openalex.org/C18296254","wikidata":"https://www.wikidata.org/wiki/Q1395219","display_name":"Skepticism","level":2,"score":0.4659000039100647},{"id":"https://openalex.org/C56739046","wikidata":"https://www.wikidata.org/wiki/Q192060","display_name":"Knowledge management","level":1,"score":0.4544999897480011},{"id":"https://openalex.org/C195094911","wikidata":"https://www.wikidata.org/wiki/Q14167904","display_name":"Process management","level":1,"score":0.43880000710487366},{"id":"https://openalex.org/C194541083","wikidata":"https://www.wikidata.org/wiki/Q457174","display_name":"Workaround","level":2,"score":0.39340001344680786},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.36230000853538513},{"id":"https://openalex.org/C110354214","wikidata":"https://www.wikidata.org/wiki/Q6314146","display_name":"Engineering management","level":1,"score":0.33410000801086426},{"id":"https://openalex.org/C2777042776","wikidata":"https://www.wikidata.org/wiki/Q4583103","display_name":"Preparedness","level":2,"score":0.3319000005722046},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.3142000138759613},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.3001999855041504},{"id":"https://openalex.org/C2780554381","wikidata":"https://www.wikidata.org/wiki/Q2063340","display_name":"Sensemaking","level":2,"score":0.2994999885559082},{"id":"https://openalex.org/C2776035091","wikidata":"https://www.wikidata.org/wiki/Q7928819","display_name":"Viewpoints","level":2,"score":0.29820001125335693},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.28760001063346863},{"id":"https://openalex.org/C2780103759","wikidata":"https://www.wikidata.org/wiki/Q5264375","display_name":"Design science","level":2,"score":0.2806999981403351},{"id":"https://openalex.org/C143587482","wikidata":"https://www.wikidata.org/wiki/Q1543216","display_name":"Iterative and incremental development","level":2,"score":0.27869999408721924},{"id":"https://openalex.org/C121017731","wikidata":"https://www.wikidata.org/wiki/Q11661","display_name":"Information technology","level":2,"score":0.27489998936653137},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.27320000529289246},{"id":"https://openalex.org/C153876917","wikidata":"https://www.wikidata.org/wiki/Q899704","display_name":"Traceability","level":2,"score":0.271699994802475},{"id":"https://openalex.org/C67212190","wikidata":"https://www.wikidata.org/wiki/Q104851","display_name":"Firmware","level":2,"score":0.2531000077724457},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.25060001015663147}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2604.21679","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.21679","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2604.21679","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2604.21679","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Technology":[0],"for":[1,60,168,172],"security":[2],"operations":[3],"centers":[4],"(SOCs)":[5],"has":[6],"a":[7,56,165],"storied":[8],"history":[9],"of":[10,63],"slow":[11],"adoption":[12],"due":[13],"to":[14,84,105],"concerns":[15,21],"about":[16],"trust":[17],"and":[18,38,76,79,99,144,147,163],"reliability.":[19],"These":[20],"are":[22],"amplified":[23],"with":[24,82,90,122],"artificial":[25],"intelligence,":[26],"particularly":[27],"large":[28],"language":[29],"models":[30],"(LLMs),":[31],"which":[32],"exhibit":[33],"issues":[34],"such":[35,70],"as":[36,71],"hallucinations":[37],"inconsistent":[39],"outputs.":[40],"To":[41],"assess":[42],"whether":[43],"LLM-based":[44],"tools":[45,88],"can":[46,158],"improve":[47],"SOC":[48,59,134],"efficiency,":[49],"we":[50],"embedded":[51],"two":[52],"PhD":[53],"researchers":[54],"within":[55],"multinational":[57],"company":[58],"six":[61],"months":[62],"ethnographic":[64],"fieldwork.":[65],"We":[66],"identified":[67],"recurring":[68],"challenges,":[69],"repetitive":[72],"tasks,":[73],"fragmented/unclear":[74],"data,":[75],"tooling":[77],"bottlenecks,":[78],"collaborated":[80],"directly":[81],"practitioners":[83],"develop":[85],"LLM":[86],"companion":[87],"aligned":[89],"their":[91],"operational":[92],"needs.":[93],"Iterative":[94],"refinement":[95],"reduced":[96],"workflow":[97,138],"disruption":[98],"improved":[100],"interpretability,":[101],"leading":[102],"from":[103],"skepticism":[104],"sustained":[106],"adoption.":[107],"Ethnographic":[108],"analysis":[109],"indicates":[110],"that":[111,154],"this":[112],"shift":[113],"was":[114],"enabled":[115],"by":[116],"our":[117],"sociotechnical":[118],"co-creation":[119,156],"process":[120],"consistent":[121],"Nonaka's":[123],"SECI":[124],"model.":[125],"This":[126],"framework":[127],"explains":[128],"the":[129,155],"common":[130],"challenges":[131],"in":[132],"traditional":[133],"technology":[135,171],"adoption,":[136],"including":[137],"misalignment,":[139],"rigidity":[140],"against":[141],"evolving":[142],"threats":[143],"internal":[145],"requirements,":[146],"stagnation":[148],"over":[149],"time.":[150],"Our":[151],"findings":[152],"show":[153],"approach":[157],"overcome":[159],"these":[160],"old":[161],"barriers":[162],"create":[164],"new":[166],"paradigm":[167],"creating":[169],"usable":[170],"cybersecurity":[173],"operations.":[174]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-04-25T00:00:00"}
