Location
Hilton Waikoloa Village, Hawaii
Event Website
https://hicss.hawaii.edu/
Start Date
7-1-2025 12:00 AM
End Date
10-1-2025 12:00 AM
Description
Security Operations Centres (SOCs) are pivotal in safeguarding an organisation's network infrastructure. While existing technologies focus on reactive measures, the emergence of deception tools presents an opportunity for a more proactive defence against cyber threats. Integrating such tools into SOCs, however, necessitates understanding their impact, value, and implementation challenges. To explore this, we conducted fifteen interviews with analysts from a leading SoC provider in Australia. Our thematic analysis revealed key insights: implementing cyber deception requires a shift in organisational risk tolerance, efficacy hinges on proper implementation, and it introduces new risks requiring strategic management. Analysts suggested that in-house SOCs or threat intelligence teams might be more suited for cyber deception deployment in a Managed Service Provider (MSP) SOC. This study sheds light on the implications of cyber deception for SOC operations. We conclude with recommendations to guide the integration of deception tools into SOCs.
Recommended Citation
Reeves, Andrew and Ashenden, Debi, "Deploying Active Defence in a SOC: Analysts’ Perceptions of Cyber Deception" (2025). Hawaii International Conference on System Sciences 2025 (HICSS-58). 6.
https://aisel.aisnet.org/hicss-58/da/cyber_deception/6
Deploying Active Defence in a SOC: Analysts’ Perceptions of Cyber Deception
Hilton Waikoloa Village, Hawaii
Security Operations Centres (SOCs) are pivotal in safeguarding an organisation's network infrastructure. While existing technologies focus on reactive measures, the emergence of deception tools presents an opportunity for a more proactive defence against cyber threats. Integrating such tools into SOCs, however, necessitates understanding their impact, value, and implementation challenges. To explore this, we conducted fifteen interviews with analysts from a leading SoC provider in Australia. Our thematic analysis revealed key insights: implementing cyber deception requires a shift in organisational risk tolerance, efficacy hinges on proper implementation, and it introduces new risks requiring strategic management. Analysts suggested that in-house SOCs or threat intelligence teams might be more suited for cyber deception deployment in a Managed Service Provider (MSP) SOC. This study sheds light on the implications of cyber deception for SOC operations. We conclude with recommendations to guide the integration of deception tools into SOCs.
https://aisel.aisnet.org/hicss-58/da/cyber_deception/6