Location

Hilton Waikoloa Village, Hawaii

Event Website

https://hicss.hawaii.edu/

Start Date

7-1-2025 12:00 AM

End Date

10-1-2025 12:00 AM

Description

Security Operations Centres (SOCs) are pivotal in safeguarding an organisation's network infrastructure. While existing technologies focus on reactive measures, the emergence of deception tools presents an opportunity for a more proactive defence against cyber threats. Integrating such tools into SOCs, however, necessitates understanding their impact, value, and implementation challenges. To explore this, we conducted fifteen interviews with analysts from a leading SoC provider in Australia. Our thematic analysis revealed key insights: implementing cyber deception requires a shift in organisational risk tolerance, efficacy hinges on proper implementation, and it introduces new risks requiring strategic management. Analysts suggested that in-house SOCs or threat intelligence teams might be more suited for cyber deception deployment in a Managed Service Provider (MSP) SOC. This study sheds light on the implications of cyber deception for SOC operations. We conclude with recommendations to guide the integration of deception tools into SOCs.

Share

COinS
 
Jan 7th, 12:00 AM Jan 10th, 12:00 AM

Deploying Active Defence in a SOC: Analysts’ Perceptions of Cyber Deception

Hilton Waikoloa Village, Hawaii

Security Operations Centres (SOCs) are pivotal in safeguarding an organisation's network infrastructure. While existing technologies focus on reactive measures, the emergence of deception tools presents an opportunity for a more proactive defence against cyber threats. Integrating such tools into SOCs, however, necessitates understanding their impact, value, and implementation challenges. To explore this, we conducted fifteen interviews with analysts from a leading SoC provider in Australia. Our thematic analysis revealed key insights: implementing cyber deception requires a shift in organisational risk tolerance, efficacy hinges on proper implementation, and it introduces new risks requiring strategic management. Analysts suggested that in-house SOCs or threat intelligence teams might be more suited for cyber deception deployment in a Managed Service Provider (MSP) SOC. This study sheds light on the implications of cyber deception for SOC operations. We conclude with recommendations to guide the integration of deception tools into SOCs.

https://aisel.aisnet.org/hicss-58/da/cyber_deception/6