Figure 1. Athena Nike Temple on the Acropolis, February 2026.

Conference & Journal Paper

Integrating Large Language Models into Security Incident Response

Diana Kramer, Lambert Rosique, Ajay Narotam, Elie Bursztein, Patrick Gage Kelley, Kurt Thomas, Allison Woodruff

Proceedings of the 21st Symposium on Usable Privacy and Security (SOUPS '25), Seattle, WA, 133–148, 2025

August 2025

Abstract

Incident response is a manually-intensive process whereby security analysts detect and respond to security events. In this study, we explore whether large language models (LLMs) can fully automate—or otherwise assist with—the final step of an incident response investigation: summarizing findings for stakeholders, auditors, and legal experts. We run a series of experiments with 18 security analysts and 50 real-world incidents to understand (1) whether LLMs can autonomously reason about security events and produce high-quality summaries; (2) whether LLMs can collaboratively assist security analysts with summarization; and (3) what overall benefits and risks security analysts foresee with integrating LLMs into incident summarization. We find that current LLMs may lack the security reasoning necessary to operate autonomously, producing summaries that omit critical details in 35% of cases and/or inject factual inaccuracies in 42% of cases. However, when used collaboratively, LLMs reduce the effort required from analysts to produce a summary, while improving the readability and consistency of summaries. We explore opportunities for improving the security reasoning of LLMs as well as other potential applications for incident response.

Cite this paper
@inproceedings{kramer2025integrating,
  title     = {Integrating Large Language Models into Security Incident Response},
  author    = {Kramer, Diana and Rosique, Lambert and Narotam, Ajay and Bursztein, Elie and Kelley, Patrick Gage and Thomas, Kurt and Woodruff, Allison},
  year      = {2025},
  booktitle = {Proceedings of the 21st Symposium on Usable Privacy and Security (SOUPS '25), Seattle, WA, 133–148, 2025},
  url       = {https://pgk.io/papers/2025-integrating-large-language-models-into-security-incident/},
}
← Back to Papers