Scientific article
Published:
Operationalising uncertainty: The automation of threat knowledge and situational awareness
Summary:
This article examines how automated technologies produce threat knowledge in pursuit of “situational awareness”.
Focusing on intrusion detection systems (IDS), it argues that searching for “anomalies” represents not only a technical shift but a sociotechnical reconfiguration. Drawing on interviews with technical operators, engineers, and institutional actors involved in Norway's national IDS, the article shows that anomaly detection does not deliver the seamless oversight or predictive control often promised by automation and Machine Learning. Instead, it produces new forms of uncertainty and interpretive labour warranted by military doctrines of “total security”.
By exploring the conditions under which threats become known—a situated awareness—“omniboxing” is conceptualised as a lens to unpack the production of threat knowledge where uncertainty is not eradicated but operationalised. In contrast to Latour's black box, omniboxing acknowledges that while technical operators preserve an unyielding commitment to realising “total security”, technologies are not experienced as settled or self-evident.
By foregrounding the ongoing and open-ended interpretive labour of human operators, the article demonstrates how IDS are not neutral tools of detection but are active in constituting what is seen, known, and acted upon as a threat. Situational awareness, often imagined as a means of achieving omniscient oversight, is rather a reflexive and situated process, revealing cybersecurity technologies as sociotechnical configurations rather than technical objects.
Focusing on intrusion detection systems (IDS), it argues that searching for “anomalies” represents not only a technical shift but a sociotechnical reconfiguration. Drawing on interviews with technical operators, engineers, and institutional actors involved in Norway's national IDS, the article shows that anomaly detection does not deliver the seamless oversight or predictive control often promised by automation and Machine Learning. Instead, it produces new forms of uncertainty and interpretive labour warranted by military doctrines of “total security”.
By exploring the conditions under which threats become known—a situated awareness—“omniboxing” is conceptualised as a lens to unpack the production of threat knowledge where uncertainty is not eradicated but operationalised. In contrast to Latour's black box, omniboxing acknowledges that while technical operators preserve an unyielding commitment to realising “total security”, technologies are not experienced as settled or self-evident.
By foregrounding the ongoing and open-ended interpretive labour of human operators, the article demonstrates how IDS are not neutral tools of detection but are active in constituting what is seen, known, and acted upon as a threat. Situational awareness, often imagined as a means of achieving omniscient oversight, is rather a reflexive and situated process, revealing cybersecurity technologies as sociotechnical configurations rather than technical objects.
- Published year: 2026
- Full version: Click here to download the article
-
DOI:
https://doi.org/10.1093/secdia/xhag010
- Publisher: Oxford Academic
- Page count: 13
- Language: English
- Journal: Security Dialogue