Paper Type

Short

Paper Number

PACIS2026-1583

Description

This study examines how organizations adjust cybersecurity governance as they integrate SOAR into SIEM-centered security operations. Increasing alert volumes and regulatory pressures are prompting a shift from analyst-driven, manual workflows toward more standardized, auditable, and automation-supported incident handling. Using a qualitative case study based on interviews, field observations, and archival materials, the research analyzes how practitioners interpret operational rules, coordinate response decisions, and maintain accountability in the pre-automation stage. A ludological lens conceptualizes security operations as evolving interaction systems composed of rules, tools, actors, and feedback mechanisms. Guided by the Gioia methodology, the study identifies which operational practices require reassessment when SOAR capabilities are incorporated into SIEM environments and examines how governance structures adapt as automation becomes operational.

Comments

08-Security

Share

COinS
 
Jul 5th, 12:00 AM

A Ludology Perspective on Preparations Required to Support SOAR Adoption in Security Operations

This study examines how organizations adjust cybersecurity governance as they integrate SOAR into SIEM-centered security operations. Increasing alert volumes and regulatory pressures are prompting a shift from analyst-driven, manual workflows toward more standardized, auditable, and automation-supported incident handling. Using a qualitative case study based on interviews, field observations, and archival materials, the research analyzes how practitioners interpret operational rules, coordinate response decisions, and maintain accountability in the pre-automation stage. A ludological lens conceptualizes security operations as evolving interaction systems composed of rules, tools, actors, and feedback mechanisms. Guided by the Gioia methodology, the study identifies which operational practices require reassessment when SOAR capabilities are incorporated into SIEM environments and examines how governance structures adapt as automation becomes operational.