Modelling system collapse in multi-task SOC operators: Bayesian analysis of simulated cognitive overload
Security Operations Centre (SOC) operators sustain concurrent demands absent from standard lab paradigms: vigilance monitoring, working memory updating, conflict resolution, and decision-making under time pressure and escalating threat. Understanding how these stressors interact to produce performance collapse has implications for both cognitive capacity theory and applied cybersecurity design. We present agent-based simulations of a three-task SOC environment (PVT-like alarm dismissal, SART-like log triage, WCST-like phishing email sorting) implemented on the CogFlow platform’s multi-window SOC Dashboard with overlapping subtask schedules and varying urgency. Synthetic agents draw performance profiles from empirical RT/accuracy distributions, then face manipulated time pressure (session duration, response windows) and hazard escalation (threat severity, miss costs) in a 2×2 factorial design. Key findings from Bayesian hierarchical modelling: (1) Time pressure drives speed-accuracy trade-offs–16% faster RT but 46% more misses; (2) Critical hazard massively increases vigilance failures (102% more misses) with minimal RT effect; (3) Combined stressors show sub-additive interaction (OR=0.83), suggesting strategic adaptation rather than linear degradation. Operators under dual stress shift to conservative strategies, not collapse. Sub-additive interaction effects in realistic multi-tasking suggest adaptive mechanisms that warrant investigation through empirical studies and formal cognitive modelling (e.g., capacity architectures). Surrogate findings inform initial interface design priorities (hazard visibility over speed pressure) pending human validation.
Keywords
There is nothing here yet. Be the first to create a thread.
Cite this as: