📧 hipravat@gmail.com Support

Qualitative Research Methods

Course: RES812 — Doctoral Program in Computer Science (Cybersecurity & Information Assurance) Focus Area: AI-Driven Cybersecurity Research


Overview

This course develops doctoral-level expertise in qualitative research methodology. Topics span foundational traditions, research design selection, data collection, coding and analysis, trustworthiness, observational methods, human subject ethics, and preparation of a dissertation research prospectus — all applied to the domain of AI in Cybersecurity.


Qualitative vs. Quantitative Research

Philosophical Foundations

Dimension Qualitative Quantitative
Paradigm Constructivist / Interpretivist Positivist
Reasoning Inductive Deductive
Reality Subjective, socially constructed Objective, measurable
Goal Understand meaning and experience Test hypotheses, measure relationships
Data Text, interviews, observations Numbers, statistics
Sample Small, purposive Large, random
Analysis Thematic, narrative, content Regression, ANOVA, statistical
Outcome Rich contextual insight Generalizable findings

When to Choose Qualitative Research

Qualitative methods are best suited when:

  • The topic is understudied or lacks established theory
  • The research requires depth over breadth — understanding why and how
  • Phenomena are difficult to quantify (perceptions, lived experiences, decision-making)
  • Flexibility is needed to explore emerging themes as the study progresses
  • Human factors, context, and culture are central to the research question

Application to AI in Cybersecurity

Qualitative inquiry is well-suited for cybersecurity research because:

  • AI-driven threat response relies heavily on human judgment and perception
  • Organizations differ in how they integrate AI — context is critical
  • Ethical and cultural dimensions of AI adoption cannot be reduced to numbers
  • AI cybersecurity is an emerging field — established theories are insufficient

Qualitative Research Designs

Phenomenological Design

Phenomenology explores the lived experience of individuals concerning a specific phenomenon. It seeks the "essence" of the experience across multiple participants.

Purpose: Understand how people perceive, emotionally respond to, and make meaning of a phenomenon

Process: 1. Recruit participants with direct experience of the phenomenon 2. Conduct in-depth, semi-structured interviews 3. Identify significant statements (horizontalization) 4. Cluster statements into meaning units and themes 5. Write a composite description of the essence of the experience

Application in Dissertation (AI & Cybersecurity):

"What are the lived experiences of cybersecurity professionals in responding to AI-driven threats in enterprise environments?"

A phenomenological approach captures the emotional, cognitive, and professional dimensions of how analysts interact with AI security tools — nuances that quantitative metrics cannot reveal.

Grounded Theory

Grounded theory builds new theory directly from data through iterative coding and constant comparison.

Process: - Open Coding — Break data into concepts and label them - Axial Coding — Establish relationships between codes; form categories - Selective Coding — Identify the central category; integrate into a theory - Theoretical Saturation — Stop collecting data when no new themes emerge

Best suited for: Topics where no adequate existing theory explains the phenomenon

Application: Developing a framework explaining how organizations balance AI benefits and risks in cybersecurity operations

Case Study Design

Provides rich, contextual insights into how specific organizations implement AI-driven cybersecurity strategies. Identifies factors such as risk assessment, leadership decision-making, and gap analysis across industries.

Narrative Inquiry

Analyzes individual professional stories to understand career trajectories, motivations, and meaning-making over time. Applicable when longitudinal or biographical context matters.


Data Collection Methods

In-Depth Interview

A one-on-one conversation designed to develop deep understanding of participants' thoughts, feelings, and experiences.

Characteristics: - Open-ended, probing questions - Researcher-directed but participant-centered - Audio-recorded and transcribed

Best for: Personal narratives, complex phenomena, individual perspectives

Semi-Structured Interview

A guided but flexible interview combining pre-set questions with room for exploration based on responses.

Structure: 1. Warm-up questions — build rapport, understand background 2. Core questions — central research focus 3. Closing questions — offer participants space to add context

Best for: Exploratory studies with diverse participant experiences; most common for doctoral qualitative research

Sample Interview Protocol (AI in Cybersecurity)

Warm-Up: - How many years have you worked in cybersecurity, and what roles have you held? - Describe your current responsibilities and areas of specialization.

Core Questions: - How has AI changed the way you detect and respond to cyber threats? - What challenges have you encountered when trusting AI-generated alerts? - How do you validate recommendations made by AI-driven security tools? - What ethical concerns, if any, have you observed in AI-based threat detection?

Closing: - Is there anything important about AI in cybersecurity that we haven't covered? - Who else in your field would have valuable perspectives on this topic?

Focus Groups

Guided discussions with 6–12 participants led by a moderator. The group dynamic generates insights that individual interviews may not reveal.

Best for: Exploring community norms, shared attitudes, group consensus or disagreement

Document Analysis

Review of policy documents, incident reports, organizational records, and archival materials. Particularly valuable in cybersecurity for analyzing AI governance policies and threat response protocols.


Sampling in Qualitative Research

Core Principle

Qualitative sampling prioritizes depth, richness, and relevance — not statistical representativeness. The goal is to select participants who can best inform the research question.

Sampling Strategies

Purposive Sampling (Recommended for AI Cybersecurity Dissertation) - Deliberately selects participants with targeted characteristics - Ensures participants have the knowledge and experience relevant to the study - Example: AI developers, cybersecurity analysts, IT security managers, policymakers - Enhances credibility, transferability, dependability, and confirmability

Snowball Sampling - Initial participants refer others in their professional network - Used when the target population is hard to access (niche or sensitive roles) - Example: A security expert at a government agency refers colleagues

Convenience Sampling - Selects participants based on accessibility - Useful for exploratory or pilot studies; weaker for rigorous doctoral research

Sampling Plan for Dissertation

Target participants: - Cybersecurity analysts with 3+ years in AI-integrated SOC environments - AI/ML engineers working on security applications - IT Security managers responsible for AI tool adoption - Cybersecurity educators and researchers - Ethical hackers and penetration testers using AI tools


Qualitative Data Analysis

Stages of Analysis

1. Data Familiarization Immerse yourself in transcripts, notes, and documents. Read repeatedly. Note initial impressions and recurring ideas.

2. Coding Segment data into meaningful units and assign labels. Two approaches: - Inductive (bottom-up) — Codes emerge from the data - Deductive (top-down) — Codes are guided by existing theory

3. Theme Development Group related codes into broader themes that represent overarching patterns across the dataset.

4. Theme Review Ensure themes accurately reflect the data. Merge overlapping themes. Resolve inconsistencies.

5. Defining and Naming Themes Assign clear names; define each theme's meaning within the study context.

6. Reporting Present themes with supporting quotes and connect to research questions and existing literature.

Coding Methods

Method Description Best For
Open Coding Line-by-line labeling without predefined categories Initial exploration
Axial Coding Identifies relationships between open codes Building categories
Thematic Coding Groups codes into broader themes Pattern identification
In Vivo Coding Uses participants' own words as codes Preserving authentic voice
Descriptive Coding Summarizes data segments concisely Quick categorization

Thematic Analysis vs. Grounded Theory

Dimension Thematic Analysis Grounded Theory
Goal Identify patterns and themes Develop new theory
Coding Inductive + deductive Purely inductive
Complexity Flexible, accessible Structured, iterative, intensive
Outcome Rich thematic interpretation New theoretical model
Best when Interpreting existing data No adequate theory exists

Recommended for AI Cybersecurity Research: Thematic Analysis for dissertation studies focused on professional perceptions and experiences; Grounded Theory if the goal is to build a novel cybersecurity framework from scratch.


Observational Methods

Participant-Observer Roles

Role Description
Complete Observer Observes without interacting
Observer-as-Participant Primarily observes with minimal interaction
Participant-as-Observer Participates in the group while maintaining observer stance
Complete Participant Fully embedded; research role not disclosed

Observational Guide for AI in Cybersecurity

Central Research Question:

"How do cybersecurity professionals respond to and mitigate AI-driven security threats in an enterprise environment?"

Target Setting: Security Operations Centers (SOCs) in enterprise or government environments

Target Groups: - Security Analysts — First responders to AI-generated threat alerts - Incident Response Teams — Containment, forensics, remediation - Cybersecurity Engineers — Architects of AI-integrated defense systems - IT Security Managers — Policy, compliance, AI adoption decisions - Ethical Hackers — Adversarial simulation against AI defenses

Data Sources: - Social actions — How analysts interact with AI tools in real-time - Verbal data — Semi-structured interviews and informal conversations - Artifacts — Incident reports, alert dashboards, policy documents, training materials

Learning Points in Observational Research

1. Naturalistic Observation Enhances Validity Direct observation records actual behaviors in their natural context, overcoming the social desirability bias and recall limitations of self-reported data. Application: Observe employee responses to simulated phishing emails rather than relying on survey self-assessment.

2. Patterns and Contextual Influences Observation reveals informal structures, communication styles, and workflow realities that formal documentation does not capture.

3. Bias and Ethical Considerations Researchers must balance participation with analytical distance. Informed consent, confidentiality, and minimizing disruption are essential in sensitive organizational settings.


Trustworthiness in Qualitative Research

Lincoln and Guba's Four Criteria

Criterion Quantitative Equivalent What It Ensures
Credibility Internal validity Findings accurately reflect participants' realities
Transferability External validity Findings apply to other contexts via thick description
Dependability Reliability Study is consistent and could be repeated
Confirmability Objectivity Findings are shaped by participants, not researcher bias

Strategies for Ensuring Trustworthiness

Triangulation Using multiple data sources, methods, researchers, or theories to cross-check findings: - Data triangulation — Interviews + observations + documents - Methodological triangulation — Qualitative + quantitative components - Investigator triangulation — Multiple researchers analyze independently - Theory triangulation — Multiple theoretical lenses applied

Member Checking Return findings or transcripts to participants for verification. Ensures interpretations accurately reflect their intended meaning.

Reflexivity Maintain a reflexive journal documenting researcher biases, assumptions, and methodological decisions throughout the study.

Peer Debriefing Have a colleague critically review your coding, interpretations, and analytical choices to minimize blind spots.

Thick Description Provide detailed, rich descriptions of participants, settings, and context to enable readers to assess transferability.

Audit Trail Document all methodological decisions, coding changes, and analytical steps to support dependability and confirmability.

Prolonged Engagement Spend sufficient time with data and participants to develop deep, nuanced understanding.


Rigor and Reducing Bias

Sources of Bias in Qualitative Research

  • Researcher subjectivity — Personal worldview influences interpretation
  • Participant bias — Socially desirable responses; impression management
  • Recall bias — Inaccurate recollection of past events
  • Selection bias — Non-representative or convenience-driven sampling

Mitigation Strategies

  • Use non-leading questions; pilot test the interview guide
  • Apply purposive sampling with clear inclusion criteria
  • Maintain a reflexive journal from day one
  • Use direct participant quotes rather than paraphrased summaries
  • Apply inter-coder reliability checks — two researchers code independently, then compare
  • Conduct member checking after analysis
  • Establish anonymity to reduce social desirability bias

Human Subject Ethics

Anticipated Risks for Cybersecurity Research Participants

  • Confidentiality risk — Discussing AI vulnerabilities may inadvertently reveal sensitive organizational information
  • Professional repercussions — Participants may fear backlash from employers for critiquing AI tools or security decisions
  • Psychological stress — Reflecting on past security failures can cause anxiety

Risk Mitigation Strategies

  1. Informed Consent — Full disclosure of study purpose, data handling, and voluntary participation before any data collection
  2. Anonymization — Replace names and organizational identifiers with codes throughout all documents
  3. Data Security — Encrypt all data; restrict access to authorized researchers only
  4. IRB Approval — Submit full ethics protocol before beginning participant recruitment
  5. Right to Withdraw — Participants may exit at any stage without penalty or explanation
  6. Confidentiality Agreements — Remove or aggregate firm-specific information that could identify organizations

Computer-Aided Qualitative Data Analysis (CAQDA)

NVivo for Doctoral Research

NVivo is purpose-built for qualitative and mixed-methods research. Key capabilities:

Strengths for AI Cybersecurity Research: - AI-assisted auto-coding accelerates thematic identification across large datasets - Supports multiple data formats: text, audio, video, PDF, social media - Word frequency queries and text search identify emerging terminology patterns - Concept maps and matrix coding visualize relationships between AI attack patterns and defense strategies - Collaboration features support team-based research with full audit trails

Limitations to Consider: - Steep learning curve; plan training time before data collection begins - AI auto-coding can misinterpret technical cybersecurity context — human review is essential - Requires data pre-cleaning before import - Software license costs may be a barrier for independent researchers - Better suited for static datasets; less effective for real-time dynamic environments

When to Use CAQDA

Use NVivo or similar tools (ATLAS.ti, MAXQDA) when: - Working with large volumes of interview transcripts or policy documents - Managing data from multiple sources simultaneously - Needing audit trail documentation for doctoral committee review - Conducting team-based coding that requires version control and consistency


Research Prospectus

Purpose and Structure

The Research Prospectus is a milestone document demonstrating alignment between:

  1. Study Problem — What practice-based gap exists in the field?
  2. Study Purpose — What does this study aim to do, and how?
  3. Research Question(s) — What specific question does the study answer?
  4. Research Rationale — Why is qualitative methodology the right choice?

Study Problem Statement

The problem to be addressed by this study is the growing gap between the sophistication of AI-driven cyber threats and the ability of cybersecurity professionals to detect, understand, and respond to them in real-world enterprise environments. While AI-based security tools are increasingly deployed, there is limited research on how practitioners perceive, trust, and operationalize these tools in Security Operations Centers — particularly when AI-generated alerts conflict with human judgment or when adversarial AI techniques create novel, unpredictable attack vectors.

Research Questions (Phenomenological)

Central Question:

What are the lived experiences of cybersecurity professionals in perceiving and mitigating AI-driven security threats in enterprise Security Operations Centers?

Sub-questions:

Q1a: How do SOC analysts describe their trust in AI-generated threat alerts? Q1b: What strategies do cybersecurity professionals use to validate AI recommendations? Q1c: What ethical concerns do practitioners associate with AI-driven automated responses?

Rationale for Qualitative Approach

A qualitative phenomenological approach is most appropriate because:

  • AI-driven cybersecurity threats are adaptive and context-dependent — statistical models cannot fully capture their emergent nature
  • The study focuses on human perception, decision-making, and organizational culture — inherently non-numerical phenomena
  • The field lacks established theory for how practitioners navigate human–AI interaction in security operations
  • Semi-structured interviews with experts provide rich, first-person accounts that inform real-world practice

Course Summary and Key Takeaways

  1. Qualitative research is the right tool for complex, emerging, human-centered problems — especially in AI cybersecurity where quantitative data exists but context and meaning are missing

  2. Design selection matters — Phenomenology for lived experience, Grounded Theory for building new theory, Case Study for organizational context

  3. Sampling is purposeful — Quality over quantity; purposive sampling ensures participants can genuinely inform the research question

  4. Coding is iterative — Thematic coding is flexible and powerful; move from open codes to themes through systematic review

  5. Trustworthiness is actively built — Triangulation, member checking, reflexivity, and thick description are not optional — they are the standard of rigor

  6. Ethics extends beyond IRB — Confidentiality, power dynamics, and psychological safety require ongoing attention throughout the study

  7. NVivo accelerates analysis — But researcher judgment cannot be delegated to software; human oversight of AI-generated codes is essential

  8. The Prospectus aligns everything — Problem → Purpose → Question → Method must form a coherent, defensible chain of reasoning


References

  • Creswell, J. W., & Poth, C. N. (2021). Qualitative Inquiry & Research Design: Choosing Among Five Approaches. SAGE.
  • Creswell, J. W., & Creswell, J. D. (2014). Research Design: Qualitative, Quantitative, and Mixed Methods Approaches. SAGE.
  • Maxwell, J. A. (2013). Qualitative Research Design: An Interactive Approach. SAGE.
  • Tracy, S. J. (2024). Qualitative Research Methods. Wiley-Blackwell.
  • Lincoln, Y. S., & Guba, E. G. (1985). Naturalistic Inquiry. SAGE.
  • Charmaz, K. (2014). Constructing Grounded Theory. SAGE.
  • Mweshi, G. K., & Sakyi, K. (2020). Application of sampling methods for the research design. Archives of Business Research, 8(11).
  • Donkoh, S., & Mensah, J. (2023). Application of triangulation in qualitative research. Journal of Applied Biotechnology and Bioengineering, 10(1).
  • Poth, C. (2023). The SAGE Handbook of Mixed Methods Research Design. SAGE.