Skip to main content
Integrating Large Language Models into Security Incident Response
  1. publications
  2. ai

Integrating Large Language Models into Security Incident Response

Available Media Publication (PDF) video
Conference Symposium on Usable Privacy and Security (SOUPS) - 2025
Authors Diana Kramer , Lambert Rosique , Ajay Narotam ,
Citation BibTeX
BibTeX
@inproceedings{Kramer2025Integrating,
  title = {Integrating Large Language Models into Security Incident Response},
  author = {Diana Kramer and Lambert Rosique and Ajay Narotam and Elie Bursztein and Patrick Gage Kelley and Kurt Thomas and Allison Woodruff},
  booktitle = {Symposium on Usable Privacy and Security},
  year = {2025},
  organization = {USENIX Association}
}

Security analysts must turn complex investigations into clear summaries for stakeholders, auditors and legal teams. This study explores whether large language models can automate that work or help analysts complete it.

Experiments with 18 analysts and 50 real incidents reveal substantial problems with autonomous summaries, including missing details and factual errors. Collaborative use is more promising: analysts can benefit from more readable, consistent summaries while retaining oversight. The paper identifies both opportunities and limits for integrating LLMs into incident response.

newsletter signup
newsletter signup