← All publications

Academic paper

AI-Enhanced CTI for SOCs: Practitioner Priorities from a Multi-Sector Survey

A multi-sector survey translating SOC and CERT practitioners' priorities for AI-enhanced cyber threat intelligence into deployable recommendations.

Abstract

Security Operations Centers (SOCs) and Computer Emergency Response Teams (CERT) are increasingly relying on Cyber Threat Intelligence (CTI) to accelerate detection and response in cluster, cloud, and edge environments. However, teams struggle with alert overload, heterogeneous feeds, and limited analyst capacity. We present the results of a survey of practitioners from the public sector, critical infrastructure, and private organisations that identify what SOC/CERT teams expect from AI-enhanced CTI. Respondents highlight ransomware/malware and phishing as dominant threats, while operational bottlenecks cluster around data deluge, insufficient automation, and weak tool interoperability. We translate these practitioner requirements into concise, deployable recommendations for cluster/cloud/edge settings and outline a lightweight validation plan focused on false-positive reduction and improvements in Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR).

Authors

  • Anna Felkner — NASK - National Research Institute, Warsaw, Poland
  • Antonio Monte Pegado — NOVA University Lisbon, NOVA School of Science and Technology (FCT NOVA), Caparica, Portugal

AIPITCH contribution

The survey connects practitioners’ operational priorities with deployable AI-enhanced CTI recommendations for SOC and CERT teams working across cluster, cloud, and edge environments.

Citation

Anna Felkner and Antonio Monte Pegado. “AI-Enhanced CTI for SOCs: Practitioner Priorities from a Multi-Sector Survey.” IEEE Xplore. Bibliographic details and citation formats are available from IEEE Xplore and Google Scholar.