O. Torstensson, Dmytro Prokopovych-Tkachenko, Alona Desiatko, Zoriana Hbur, Ігор Брітченко · Journal of Cybersecurity and Privacy 2026 · 2026
DOI: 10.3390/jcp6050149
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
Security Operations Centers increasingly use artificial intelligence to rank alerts, summarize evidence, and automate repetitive response actions. However, AI-enabled security operations can also create new risks for incident response and digital forensic reliability, including false-negative prioritization, model drift, hallucinated explanations, prompt injection, automation bias, unsafe SOAR actions, and evidence contamination. This article proposes a risk-driven deployment and forensic readiness framework for AI-enabled Security Operations Centers. The framework combines Monte Carlo loss simulation, detector threshold analysis, analyst queueing, model-drift monitoring, and evidence-preserving governance controls. It explicitly separates evidence, recommendation, and action so that AI can accelerate triage while preserving source artifacts, provenance, audit trails, and chain-of-custody information needed for incident reconstruction. Illustrative simulation results show a mean annualized loss expectancy of USD 1.70 M, a 95% Value-at-Risk of USD 3.85 M and a 99% Value-at-Risk of USD 6.29 M, a detector ROC-AUC of 0.942 and PR-AUC of 0.750 with precision 0.719, recall 0.650 and F1 0.683 at the selected decision threshold of 1.873, a manual triage workload reduction of about 38%, and a reduction in mean time to respond (MTTR, defined throughout as mean time to respond rather than mean time to resolution) from about 44 to 26 min under controlled assumptions. The results are demonstration outputs rather than universal benchmarks. The main contribution is a reproducible governance method for deciding when AI reduces SOC risk, when it transfers risk, and when forensic readiness requires human approval, evidence preservation, or automation rollback.
No comments yet — start the discussion below.