!!!! Bi-Annual Double Blind Peer Reviewed Refereed Journal !!!!
!!!! Open Access Journal !!!!
Abstract:
Security Operations Centers (SOCs) represent the institutional frontline of enterprise cyber defence, yet their operational model is under acute strain. The volume of security alerts generated by contemporary enterprise environments has grown at a pace that human analyst capacity cannot match a phenomenon documented across jurisdictions as alert fatigue, wherein analysts become desensitised to notifications, miss critical signals, and experience accelerated professional burnout. Mean times to detect and respond to incidents remain measured in hours or days despite significant investment in conventional Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. Large language models (LLMs) offer a structurally different approach to this problem: rather than applying rule-based filtering to reduce alert volume, they can reason over alert context, correlate disparate signals, generate natural-language triage summaries, and initiate autonomous response actions within governed parameters. This study develops and validates LANCER the LLM-Augmented eNterprise Cyber Emergency Response framework a conceptual architecture integrating LLM-driven triage and autonomous incident response into the SOC workflow. Employing a Design Science Research methodology, the framework is evaluated against three simulated enterprise incident scenarios and assessed for alignment with NIST Cybersecurity Framework 2.0, MITRE ATT&CK, and ISO/IEC 27035 incident response standards. Findings indicate that LANCER substantially reduces mean time to triage, improves alert-to-incident correlation accuracy, and provides a governance-compliant pathway for human-supervised autonomous response in high-velocity threat environments.