Skip to content
NUPI skole

Scientific article

Published:

Operationalising uncertainty: The automation of threat knowledge and situational awareness

Security dialogue_cover.jpeg

Summary:

This article examines how automated technologies produce threat knowledge in pursuit of “situational awareness”.

Focusing on intrusion detection systems (IDS), it argues that searching for “anomalies” represents not only a technical shift but a sociotechnical reconfiguration. Drawing on interviews with technical operators, engineers, and institutional actors involved in Norway's national IDS, the article shows that anomaly detection does not deliver the seamless oversight or predictive control often promised by automation and Machine Learning. Instead, it produces new forms of uncertainty and interpretive labour warranted by military doctrines of “total security”.

By exploring the conditions under which threats become known—a situated awareness—“omniboxing” is conceptualised as a lens to unpack the production of threat knowledge where uncertainty is not eradicated but operationalised. In contrast to Latour's black box, omniboxing acknowledges that while technical operators preserve an unyielding commitment to realising “total security”, technologies are not experienced as settled or self-evident.

By foregrounding the ongoing and open-ended interpretive labour of human operators, the article demonstrates how IDS are not neutral tools of detection but are active in constituting what is seen, known, and acted upon as a threat. Situational awareness, often imagined as a means of achieving omniscient oversight, is rather a reflexive and situated process, revealing cybersecurity technologies as sociotechnical configurations rather than technical objects.

Themes

  • Defence
  • Security policy
  • Cyber
  • Intelligence
  • The Nordic countries
Relevant content
Research project
Research project
Cyber security, knowledge and practices