PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 6, 2026Security Dialogue0 citationsOpen Access

Operationalising uncertainty: the automation of threat knowledge and situational awareness

View Full Paper
CAClaudia Emilie Aanonsen

Key Points

  • The article aims to explore how automation and anomaly detection in cybersecurity affect situational awareness and threat knowledge.
  • Interviews conducted with technical operators, engineers, and institutional actors involved in Norway's national IDS.
  • Analysis of the production of threat knowledge through the lens of anomaly detection.
  • Conceptual discussion on 'omniboxing' as a framework for understanding uncertainty in cybersecurity.
  • Anomaly detection does not guarantee predictive control or seamless oversight, producing new uncertainties.
  • Technical operators engage in ongoing interpretive labour rather than relying solely on automated systems.
  • Cybersecurity technologies are revealed as sociotechnical configurations rather than neutral detection tools.

Abstract

Abstract This article examines how automated technologies produce threat knowledge in pursuit of “situational awareness”. Focusing on intrusion detection systems (IDS), it argues that searching for “anomalies” represents not only a technical shift but a sociotechnical reconfiguration. Drawing on interviews with technical operators, engineers, and institutional actors involved in Norway's national IDS, the article shows that anomaly detection does not deliver the seamless oversight or predictive control often promised by automation and Machine Learning. Instead, it produces new forms of uncertainty and interpretive labour warranted by military doctrines of “total security”. By exploring the conditions under which threats become known—a situated awareness—“omniboxing” is conceptualised as a lens to unpack the production of threat knowledge where uncertainty is not eradicated but operationalised. In contrast to Latour's black box, omniboxing acknowledges that while technical operators preserve an unyielding commitment to realising “total security”, technologies are not experienced as settled or self-evident. By foregrounding the ongoing and open-ended interpretive labour of human operators, the article demonstrates how IDS are not neutral tools of detection but are active in constituting what is seen, known, and acted upon as a threat. Situational awareness, often imagined as a means of achieving omniscient oversight, is rather a reflexive and situated process, revealing cybersecurity technologies as sociotechnical configurations rather than technical objects.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Claudia Emilie Aanonsen (2026) studied this question.

synapsesocial.com/papers/69faa30204f884e66b5339dehttps://doi.org/10.1093/secdia/xhag010
Ask AI
Helpful
Bookmark
Share
View Full Paper