Security analysts must turn complex investigations into clear summaries for stakeholders, auditors and legal teams. This study explores whether large language models can automate that work or help analysts complete it.
Experiments with 18 analysts and 50 real incidents reveal substantial problems with autonomous summaries, including missing details and factual errors. Collaborative use is more promising: analysts can benefit from more readable, consistent summaries while retaining oversight. The paper identifies both opportunities and limits for integrating LLMs into incident response.