Security Managers
11-3013.01Direct an organization's security functions, including physical security and safety of employees and facilities.
Sub-scores
0–100 · band = confidence interval from rater disagreement
Substitution — the headline: capability discounted by cost, barriers and adoption.
Exposure — technical capability alone, regardless of whether anyone deploys it.
Augmentation — how much AI assists without replacing. High here + moderate substitution = a changing job, not a disappearing one.
Tasks on the substitution scale
28 rated tasks, binned by substitution score.
Position among all scored occupations
Distribution of 923 occupation scores; the marker is this occupation.
Tasks with substitution ≥ 70
0%
Run 1.0.0-draft.1 · computed 2026-08-05 · rater panel: claude-sonnet-5, claude-haiku-4-5-20251001 · intervals span rater disagreement.
Why this score
The five weighted dimensions of the composite, averaged across this occupation's tasks (importance-weighted, panel mean). Exact weights and formulas: /api/v1/methodology.
panel mean rating 2.0/5 → substitution pressure 26/100
panel mean rating 2.0/5 → substitution pressure 25/100
panel mean rating 2.1/5 → substitution pressure 28/100
panel mean rating 3.9/5 (barrier strength) → substitution pressure 28/100
panel mean rating 2.3/5 → substitution pressure 32/100
Task breakdown (28 tasks)
Substitution pressure per task, weighted by O*NET importance in the composite. Expand a task for the full rater audit trail — every rating, every model, every rationale.
Attend meetings, professional seminars, or conferences to keep abreast of changes in executive legislative directives or new technologies impacting security operations.
54CI 21–87 · exposure 45 · augmentation 75 · importance 3.6/5 · click for rater detail
Attend meetings, professional seminars, or conferences to keep abreast of changes in executive legislative directives or new technologies impacting security operations.
54| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 4/5 | Enterprise security and compliance functions are digitally mature and already widely adopting AI for monitoring, threat intelligence, and policy tracking. Adoption of automated briefing tools is rapid in large organizations and financial/tech sectors. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security management is a moderately digitized field with slow uptake of AI for professional development and networking activities specifically. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI can substantially augment managers by pre-filtering relevant legislative and technological changes, generating summaries before selective in-person attendance, and enabling faster synthesis of insights from attended sessions. Human judgment on strategic priorities and organizational fit remains valuable even as automation handles the bulk of monitoring. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI tools can efficiently summarize legislative changes, technology trends, and conference content, helping managers stay informed with less manual research time. |
| Task automatability | claude-haiku-4-5-20251001 | 5/5 | Current AI systems can autonomously monitor legislative databases, security publications, and conference agendas; synthesize summaries of changes; and deliver executive briefings with 50%+ time savings compared to human attendance. Large language models can extract, categorize, and contextualize relevant updates in real-time, eliminating the need for physical presence at most events. |
| Task automatability | claude-sonnet-5 | 1/5 | Physically or virtually attending meetings, seminars, and conferences to build professional awareness is an inherently human networking and presence-based activity that AI cannot substitute for end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 2/5 | Few legal or regulatory barriers exist to automating meeting attendance; the task involves information gathering rather than licensed decision-making. Organizational culture preferring in-person networking and relationship-building creates modest friction, but nothing prevents substitution. |
| Adoption barriers | claude-sonnet-5 | 2/5 | No formal licensing barrier prevents AI assistance, but professional norms and networking value create organizational friction against full substitution. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 5/5 | AI monitoring and synthesis costs (subscriptions to tracking services plus inference) are a fraction of the loaded cost of sending a manager to conferences, including travel, lodging, time away, and follow-up. The ratio favors automation by at least an order of magnitude. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can cheaply summarize content afterward, but it cannot replace the attendance and networking value itself, so overall cost comparison favors humans doing the actual task. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 4/5 | Deployed products (news aggregators, legislative tracking tools, AI-powered research platforms) reliably perform core aspects of this task—monitoring for relevant changes and generating summaries. Mature systems exist in production, though some still benefit from human review of edge cases or emerging threat interpretations. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed product attends conferences or professional meetings on a manager's behalf; this remains a human-attendance task. |
Write or review security-related documents, such as incident reports, proposals, and tactical or strategic initiatives.
50CI 46–54 · exposure 50 · augmentation 88 · importance 3.8/5 · click for rater detail
Write or review security-related documents, such as incident reports, proposals, and tactical or strategic initiatives.
50| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security is a regulated, risk-averse domain with slow digital transformation relative to finance or tech. Adoption of AI for document automation remains pilot-stage in most enterprises; production use is concentrated in large tech and financial firms, not yet mainstream. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security/corporate risk functions are adopting AI writing tools moderately, following broader enterprise trends, but lag top-tier professional services in production deployment. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI drafting and real-time compliance checking for security documents substantially assists managers by reducing first-draft burden and flagging inconsistencies or missing clauses. The human retains authority and judgment while AI accelerates research, structure, and consistency review. |
| Augmentation potential | claude-sonnet-5 | 5/5 | AI is highly effective as a drafting and editing aid for incident reports and proposals, significantly speeding up writing while the manager retains judgment and final approval. |
| Task automatability | claude-haiku-4-5-20251001 | 3/5 | AI can draft routine security documents (incident reports with structured data, standard proposals) and review for syntax/compliance, saving time on boilerplate. However, strategic judgment, organizational context, and liability-bearing conclusions require human review and sign-off, preventing full end-to-end automation at equal quality. |
| Task automatability | claude-sonnet-5 | 3/5 | AI can draft incident reports and proposal text well from structured inputs, but strategic/tactical security initiatives require organizational context, risk judgment, and situational awareness that current AI cannot fully supply end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security documents often feed into legal, regulatory, and liability contexts (incident reports used in litigation, compliance audits, breach notification). Organizational policy, regulatory frameworks (SOC 2, ISO 27001), and insurance requirements typically mandate human authority and sign-off, creating meaningful friction. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement to write these documents, but liability, confidentiality, and organizational sign-off norms create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 4/5 | LLM inference for drafting and review is cheap (cents per document); integration and light human oversight add modest cost. This is substantially cheaper than hiring security writers or having managers draft and refine manually, likely 3–5× cost reduction. |
| Cost vs. human wage | claude-sonnet-5 | 4/5 | Drafting and reviewing text is inexpensive via AI compared to a security manager's loaded wage, though human review/editing time still adds cost. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Document generation and review tools exist in production (enterprise LLMs, legal tech platforms), but their error rates on domain-specific security language, threat classification, and regulatory compliance are material. Products serve narrow use cases reliably; broad strategic document creation remains oversight-heavy. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | LLM-based writing assistants are widely deployed for drafting and reviewing business documents, but security-specific documents require domain accuracy and sensitive-data handling that limits fully autonomous production use. |
Create or implement security standards, policies, and procedures.
49CI 28–71 · exposure 58 · augmentation 88 · importance 4.2/5 · click for rater detail
Create or implement security standards, policies, and procedures.
49| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security and compliance functions show moderate AI adoption: many organizations pilot policy-generation tools, but systematic displacement remains slow due to regulatory caution, risk-aversion in security roles, and organizational inertia around policy governance. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security and IT-adjacent functions are moderately fast adopters of AI tools for drafting and analysis, but full policy creation and implementation workflows remain largely human-led with pilots only for drafting support. |
| Augmentation potential | claude-haiku-4-5-20251001 | 5/5 | AI dramatically augments security managers by drafting, comparing, and iterating policies in real-time, allowing humans to focus on organizational fit, legal nuance, and stakeholder alignment rather than repetitive policy writing. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly speed up drafting, benchmarking against frameworks like NIST or ISO, and summarizing threat landscapes, meaningfully augmenting a security manager's productivity in creating policy documents. |
| Task automatability | claude-haiku-4-5-20251001 | 5/5 | AI can generate security standards, policies, and procedures by synthesizing regulatory requirements, industry benchmarks, and organizational context through prompting and retrieval-augmented generation, reducing policy-development time from weeks to hours while maintaining quality comparable to human-authored baselines. |
| Task automatability | claude-sonnet-5 | 2/5 | Drafting policy language can be AI-assisted, but creating and implementing standards requires organizational judgment, risk assessment, and stakeholder negotiation that AI cannot fully replace end-to-end today. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Organizational risk, legal liability, and compliance sign-off requirements mean a human security manager or legal counsel must review and approve policies before implementation, creating a meaningful procedural gate that slows substitution. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security policy creation often requires accountable human sign-off tied to compliance frameworks, regulatory audits, and liability for breaches, creating strong organizational and legal barriers to full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 4/5 | AI policy generation costs pennies per artifact with minimal oversight, compared to security managers billing $150–250/hour for the same work; the cost differential is substantial, though human review still adds overhead. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can cheaply generate draft text, but the substantial human time needed for risk assessment, stakeholder buy-in, and implementation oversight keeps overall cost comparable to or only modestly below human-only approaches. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 4/5 | Deployed AI tools (LLMs, policy-generation platforms, and compliance frameworks) reliably produce draft policies and procedures in production environments; however, final legal review and organizational sign-off remain required, placing it slightly below fully autonomous deployment. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | AI writing tools can produce draft security policies, but no deployed product reliably creates and implements a full security standards program tailored to an organization's specific risk context and operations. |
Develop, recommend, or manage security procedures for operations or processes, such as security call centers, access control, and reporting tools.
41CI 25–57 · exposure 45 · augmentation 75 · importance 4.1/5 · click for rater detail
Develop, recommend, or manage security procedures for operations or processes, such as security call centers, access control, and reporting tools.
41| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security and financial services sectors show moderate to active adoption of AI-driven security tools, but adoption remains concentrated in larger enterprises. Broader SMB penetration is slower, and the requirement for human expert review and governance slows velocity compared to lower-stakes automation domains. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security management is a specialized, often physical-security-adjacent field with slower AI tool adoption compared to fast-digitizing sectors like finance or software. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly assists security managers by automating policy drafting, threat analysis, configuration recommendation, and compliance checking, substantially raising their output and decision-making quality. Human experts remain essential for context, risk judgment, and strategic choices, making this a strong augmentation scenario. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by drafting procedure documents, analyzing incident data, benchmarking against best practices, and suggesting improvements, significantly speeding up the manager's workflow. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | AI can substantially automate the generation and management of security procedures through policy templates, risk analysis, access control configuration, and automated compliance reporting. However, final approval and strategic security decisions typically require human judgment, preventing true end-to-end automation at the ≥50% time-saving threshold without oversight. |
| Task automatability | claude-sonnet-5 | 2/5 | This involves judgment-heavy policy design, risk tradeoffs, and stakeholder alignment that current AI cannot autonomously execute, though it can assist with drafting and analysis components. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security procedures often face regulatory compliance mandates (SOC 2, ISO 27001, HIPAA, etc.) and liability concerns that typically require a licensed or experienced security professional to sign off. Many organizations and frameworks legally require human accountability for security posture, creating friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security procedure decisions often carry legal, regulatory, and liability implications (e.g., compliance with security regulations, insurance requirements) that typically require accountable human managers to approve. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 4/5 | AI-powered security tools and policy engines are substantially cheaper at scale than hiring dedicated security managers to manually develop and iterate procedures. One AI system can serve many organizations, yielding significant cost savings compared to loaded human wages, though integration and oversight costs prevent a full order-of-magnitude advantage. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can cheaply generate draft policies or summarize best practices, but the overall task requires costly human oversight, site-specific customization, and validation, keeping total cost comparable to human-led work. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Several deployed products (identity management platforms, security orchestration tools, policy generators) handle portions of this task reliably, but comprehensive end-to-end procedure development and recommendation still requires significant human oversight and customization. Production systems exist but handle narrower scopes rather than the full range of operations. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | No deployed product manages end-to-end security procedure design; existing GRC and security tools automate narrow sub-tasks like access logging or alerting but require human strategy and sign-off. |
Prepare reports or make presentations on internal investigations, losses, or violations of regulations, policies and procedures.
39CI 29–50 · exposure 38 · augmentation 63 · importance 3.7/5 · click for rater detail
Prepare reports or make presentations on internal investigations, losses, or violations of regulations, policies and procedures.
39| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security and compliance functions are typically risk-averse, heavily regulated, and slower to automate sensitive processes. While data analytics and dashboarding are adopting AI, autonomous or light-touch AI-generated investigation reports remain rare in production due to liability and regulatory concerns. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Corporate security and compliance functions are adopting AI writing tools at a middling pace, with pilots for report drafting more common than full production deployment for sensitive investigations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can usefully assist by organizing evidence, suggesting findings based on patterns, drafting boilerplate sections, and formatting—raising a security manager's productivity in collating and structuring reports. However, the core task of investigation judgment and liability-aware presentation remains firmly human-led. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully speed up drafting, organizing findings, and generating presentation materials, letting security managers focus on judgment and verification while staying in the loop. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | AI can draft report templates and organize data, but preparing presentations on sensitive investigations requires judgment about disclosure, liability implications, and organizational politics that substantially exceed current autonomous AI capability. Even with significant setup, humans must review, validate findings, and make discretionary decisions on what to present. |
| Task automatability | claude-sonnet-5 | 3/5 | AI can draft reports and summarize investigation findings from structured notes, but synthesizing sensitive investigative facts, judgment calls on severity, and framing for stakeholders still requires substantial human review and input. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Investigation reports often trigger legal, compliance, and HR implications; many organizations require sign-off by licensed security professionals or legal counsel, and liability concerns over inaccurate or incomplete investigation findings create strong incentives to retain human responsibility and judgment in the final output. |
| Adoption barriers | claude-sonnet-5 | 3/5 | Internal investigation reports on regulatory violations often require sign-off from authorized security/compliance personnel and carry liability implications, creating moderate barriers to full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 3/5 | AI-assisted report drafting and data organization can offset some clerical labor costs, but the high-touch review and judgment work required to finalize investigation reports keeps total cost comparable to or only moderately cheaper than a security professional preparing the report manually. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI drafting can cut time spent on report writing, but the sensitive nature of the content requires security professional oversight, keeping overall cost savings moderate rather than order-of-magnitude. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with document generation and basic data summarization, no deployed product reliably handles the nuanced, contextual decision-making required for investigation reports (witness credibility assessment, legal sensitivity, evidentiary weight). Existing tools require heavy human oversight and are not used autonomously in production for this purpose. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | Generative AI writing tools and enterprise report-drafting assistants are deployed today for compliance and investigative summaries, but accuracy on nuanced security incidents still requires heavy human editing and fact-checking. |
Develop, conduct, support, or assist in governmental reviews, internal corporate evaluations, or assessments of the overall effectiveness of facility and personnel security processes.
38CI 25–51 · exposure 45 · augmentation 75 · importance 3.5/5 · click for rater detail
Develop, conduct, support, or assist in governmental reviews, internal corporate evaluations, or assessments of the overall effectiveness of facility and personnel security processes.
38| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security assessment and review remain conservative domains where regulatory risk and liability concerns slow automation adoption. Most organizations still employ security managers to conduct these assessments; AI-assisted tools are emerging but widespread autonomous or delegated use is limited, particularly in highly regulated sectors. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security and corporate compliance functions have historically been slower to adopt AI compared to purely digital, information-centric sectors; pilots exist but production-scale AI-led assessments remain rare. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI can meaningfully augment security managers by rapidly processing security logs, flagging anomalies, generating compliance checklists, and drafting preliminary assessment reports, allowing the human expert to focus on interpretation, strategic judgment, and stakeholder communication rather than data gathering. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by analyzing incident data, drafting reports, flagging anomalies, and summarizing policy compliance, significantly speeding up parts of the review while a human retains final oversight and judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | AI can automate substantial portions of this task by analyzing security logs, compliance documents, and personnel records to identify gaps and generate preliminary assessment reports with 50%+ time savings. However, the final judgment on overall effectiveness and strategic recommendations typically requires human expertise and organizational context that current AI cannot fully replace end-to-end. |
| Task automatability | claude-sonnet-5 | 2/5 | The task requires judgment-based synthesis of physical security, personnel policy, and regulatory compliance across a specific facility context, which current AI cannot independently execute end-to-end despite being able to assist with document review or checklist generation. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory frameworks (SOX, NIST, ISO 27001) and organizational liability often require a qualified human security professional to conduct, approve, or take responsibility for formal assessments. Internal corporate policy and audit standards typically mandate human sign-off on effectiveness conclusions, creating legal and procedural gatekeeping. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Many security assessments involve regulatory compliance (e.g., government facility clearances) and organizational accountability requiring a qualified, often cleared or certified human to sign off, creating strong barriers to full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 3/5 | Automated security assessment tools have low per-instance inference costs, but full integration with organizational systems, data cleaning, and mandatory human review and sign-off add overhead that brings total cost near parity with a human security professional's time for thorough assessments. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can lower costs for drafting reports or analyzing logs, but the overall evaluation still requires expensive human expertise for site assessments, interviews, and judgment calls, keeping costs comparable to human-led reviews. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Products exist for automated security auditing, compliance checking, and gap analysis (e.g., SIEM analysis, compliance scanning tools), but they operate within narrow technical scopes and require significant human interpretation, validation, and judgment about organizational effectiveness. Deployments are common but typically in support roles rather than autonomous end-to-end assessments. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some GRC and compliance software products offer automated checklists and gap analysis, but no deployed product independently conducts full security program evaluations or governmental reviews at production scale. |
Review financial reports to ensure efficiency and quality of security operations.
33CI 25–41 · exposure 30 · augmentation 63 · importance 3.5/5 · click for rater detail
Review financial reports to ensure efficiency and quality of security operations.
33| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security management remains a traditionally human-centric field with slow digitization in many organizations. While larger enterprises and finance-focused firms are adopting analytics tools, widespread agent-based automation of financial review in security contexts is not yet established. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security management sits within corporate/professional services functions where BI and reporting tools are adopted moderately, though full financial review automation is still uncommon. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can assist security managers by automating data extraction, highlighting spending trends, and generating variance summaries, reducing time spent on routine analysis. However, the human remains essential for strategic interpretation and operational decisions, making this a supportive rather than transformative augmentation. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI tools can significantly speed up data aggregation, trend analysis, and anomaly detection in financial reports, greatly aiding the manager's review process. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Financial report review requires domain judgment, interpretation of variance drivers, and strategic decision-making about security operations. While AI can extract data and flag numerical anomalies, the contextual analysis and efficiency/quality assessment that security managers perform remains largely manual and requires human judgment. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can extract and summarize financial data and flag anomalies, but judging efficiency/quality of security operations requires contextual managerial judgment that current systems cannot fully replicate end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security operations are heavily regulated in many jurisdictions, and financial audits often require human sign-off and professional accountability. Organizational controls over operational budgets and the need for human judgment on resource allocation create friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement blocks AI use, but organizational accountability and fiduciary responsibility for security budgets create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI tools for financial analysis are affordable, but security managers' salaries are relatively high, and the oversight required to validate AI-generated insights on security operations still demands significant human time, keeping total cost-per-task near parity with manual review. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI-assisted analytics tools are relatively cheap to run, but human oversight and interpretation still add significant cost, keeping ratio near parity rather than order-of-magnitude cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | AI systems can perform document parsing, anomaly detection, and automated summarization of financial reports with reasonable accuracy. However, production deployments in security operations are not yet widespread, and error rates on contextual interpretation remain material, limiting current real-world reliability. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Financial analytics and BI tools are deployed widely, but no product specifically performs security-operations financial review reliably as an integrated managerial task. |
Train subordinate security professionals or other organization members in security rules and procedures.
31CI 25–36 · exposure 25 · augmentation 63 · importance 3.8/5 · click for rater detail
Train subordinate security professionals or other organization members in security rules and procedures.
31| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security training remains largely human-led across sectors; while some organizations use LMS platforms with automated quizzes, actual instructor-led training—especially for subordinate managers—is slow to move toward full AI autonomy due to regulatory and accountability requirements. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Corporate security and compliance training increasingly uses digital and AI-assisted platforms, but adoption varies by sector and full replacement of manager-led training remains uncommon. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can meaningfully assist by generating training outlines, drafting procedure documents, creating interactive quizzes, and handling asynchronous Q&A, raising productivity for human trainers. However, the core mentoring and assessment function remains human-led. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly assist by generating training materials, quizzes, scenario simulations, and tracking compliance, greatly improving efficiency while the security manager still leads and customizes delivery. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can generate training materials and deliver content delivery, training subordinates requires adaptive pedagogical judgment, real-time responsiveness to questions, and interpersonal relationship-building that remains heavily human-dependent. Limited automation is possible for content creation, but the full task of training others demands human instructors. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can generate training content and quizzes, but delivering training, adapting to trainee questions, assessing hands-on competence, and reinforcing organizational culture requires human judgment and interaction that current AI cannot fully replace end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong organizational and legal barriers protect this task: human sign-off on compliance training is often mandated by regulations (e.g., SOC 2, ISO 27001), security procedures require contextual judgment that varies by organization, and liability for training failures typically falls on the organization and responsible manager, not an AI system. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement mandates a human trainer, but many security roles involve regulatory compliance training, liability concerns, and organizational preference for accountable human oversight of security protocol training. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Building and maintaining AI training systems, integrating them with organizational security protocols, and providing human oversight are costly. The loaded wage of a security manager trainer remains competitive with current AI deployment costs for this task, especially when accounting for customization and failure risk. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI-generated training materials and LMS-based modules can be cheaper per delivery than manager time, but customization, updates, and in-person components still require human involvement, keeping overall cost roughly comparable. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Some AI-driven learning platforms and chatbots exist for delivering procedural training, but deployed systems typically serve as supplements, not replacements for instructor-led training. Production systems in real organizations still rely on human trainers to conduct assessments, answer contextual questions, and enforce accountability. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | E-learning platforms and AI-generated training modules exist and are used for security awareness training, but they typically supplement rather than replace manager-led training, especially for site-specific procedures and hands-on drills. |
Identify, investigate, or resolve security breaches.
30CI 28–32 · exposure 30 · augmentation 75 · importance 4.6/5 · click for rater detail
Identify, investigate, or resolve security breaches.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security operations centers are actively piloting AI-assisted detection and triage (SOAR platforms, ML-based anomaly detection), but human-in-the-loop investigation and resolution remains the norm. Adoption is accelerating in large enterprises but slower in smaller organizations and still heavily dependent on human analysts. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity and physical security sectors have moderate AI adoption for detection tooling, but full investigative/resolution workflows are adopted more slowly due to complexity and liability concerns. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly augments security managers by automating log analysis, flagging anomalies, suggesting response actions, and correlating events across systems—raising analyst productivity substantially. Human security expertise remains central to validating findings and executing remediation, but AI transforms the speed and coverage of the investigation process. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly aids in detecting anomalies, correlating logs, and drafting incident reports, meaningfully speeding up parts of the investigative workflow even though humans remain essential for judgment and resolution. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Security breach investigation requires judgment about threat severity, root cause analysis, and contextual interpretation that AI alone cannot reliably perform end-to-end. While AI can flag suspicious events or patterns, human expertise is essential for deciding on containment actions, legal implications, and response strategies that meet the 50% time-saving bar with equal quality. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can flag anomalies and surface logs, but identifying root cause, investigating context, and resolving breaches requires judgment, physical/organizational coordination, and accountability that current systems cannot fully replicate end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong barriers exist: regulatory requirements (SOC 2, HIPAA, PCI-DSS) mandate documented human review and sign-off on breach investigations; liability and legal compliance demand human accountability; and incident response often requires human judgment on disclosure, law enforcement reporting, and customer communication that cannot be delegated to AI. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security breach resolution often has legal, regulatory, and liability implications (e.g., breach notification laws, chain of custody, HR/legal involvement) that require accountable human decision-makers. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI-driven security tools have significant upfront licensing and integration costs, plus require 24/7 human oversight, tuning, and incident response. The all-in cost per breach investigated remains comparable to or exceeds hiring experienced security analysts, especially when accounting for liability and the cost of missed detections. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI monitoring tools reduce some detection costs, but the investigation and resolution phases still require skilled human labor, oversight, and legal/organizational judgment, keeping blended costs relatively high. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Products exist (SIEM platforms, threat detection tools, automated response systems) that can identify and partially resolve some breaches, but they operate with material false-positive rates and typically require human analysts to confirm findings and execute critical remediation steps. Deployed systems assist but do not independently handle the full task reliably. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | SIEM/SOAR tools and AI-driven anomaly detection are deployed in production for alerting, but actual investigation and resolution still rely heavily on human security analysts and managers making final calls. |
Analyze and evaluate security operations to identify risks or opportunities for improvement through auditing, review, or assessment.
30CI 28–32 · exposure 25 · augmentation 75 · importance 4.2/5 · click for rater detail
Analyze and evaluate security operations to identify risks or opportunities for improvement through auditing, review, or assessment.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | High-digitization sectors (finance, tech, large enterprises) are piloting AI-assisted security analysis and anomaly detection, but production-grade autonomous auditing remains rare. Most adoption is for narrower detection/triage tasks, not full risk evaluation and reporting. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security and risk management functions are increasingly adopting AI-driven analytics platforms, but full displacement of human judgment in comprehensive audits remains at the pilot stage in most organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI systems demonstrably assist security managers by automating log analysis, flagging anomalies, and surfacing data patterns, allowing human auditors to focus on interpretation and recommendation. This augmentation is already deployed and materially improves auditor productivity on structured analysis tasks. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly enhances this task by rapidly analyzing large volumes of security logs, incident data, and compliance documents, surfacing patterns and anomalies that speed up the human reviewer's assessment process. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | AI can assist with data analysis and pattern identification in security logs and systems, but security auditing requires contextual judgment, risk prioritization, and domain expertise that current systems handle inconsistently. Full end-to-end automation with 50% time savings at equal quality is not yet achievable. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can assist with data analysis and pattern detection in security audits, but the holistic judgment of evaluating operations, contextualizing risks, and making improvement recommendations requires human expertise and organizational knowledge that current AI cannot fully replicate end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security auditing is often subject to regulatory requirements (ISO 27001, SOC 2, HIPAA, etc.) that mandate documented, defensible assessments; liability for missed risks is asymmetrically high; and organizational risk appetite favors human accountability. These governance and legal barriers significantly constrain full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | Security audits often have compliance and liability implications (e.g., regulatory reporting, insurance requirements) that create moderate friction, though no strict licensing mandate typically requires a human signature for this specific task in most industries. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI-powered security tools (SIEM, anomaly detection) have moderate to high infrastructure and integration costs, and require substantial human oversight by skilled security managers. The all-in cost per audit cycle remains comparable to or exceeds the cost of experienced human auditors. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While AI tools can reduce time spent on data aggregation and initial risk flagging, the overall audit still requires significant human oversight, interviews, and judgment calls, keeping all-in costs closer to comparable rather than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Some AI products can analyze security event logs and identify anomalies, but comprehensive security auditing and evaluation—which requires interpreting organizational context, threat landscape, and complex policy compliance—lacks mature production systems. Most deployments are narrow tools, not full audit solutions. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some security analytics and GRC (governance, risk, compliance) products offer automated log analysis and risk scoring, but comprehensive security operations audits combining physical, procedural, and cyber elements are still predominantly human-led with AI as a supporting tool. |
Develop budgets for security operations.
29CI 25–32 · exposure 25 · augmentation 63 · importance 4.7/5 · click for rater detail
Develop budgets for security operations.
29| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security organizations have low historical adoption of automation for strategic planning tasks; budget development remains a high-touch, human-led process in most enterprises, with only early pilots of AI-assisted forecasting in large firms. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security management sits within corporate/professional services functions where AI tools for financial planning and reporting are being piloted, but widespread production deployment specifically for security budgeting is still emerging. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can assist by automating data collection, cost analysis, and scenario modeling (e.g., 'if we increase surveillance by 20%, what is the cost?'), raising manager productivity on the analytical side while the human retains judgment on priorities and trade-offs. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by analyzing historical spending data, forecasting costs, benchmarking against industry standards, and drafting budget documents, significantly speeding up the process while the manager retains final judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can gather data, format spreadsheets, and perform calculations, budget development requires judgment about priorities, risk trade-offs, and strategic allocation that depends on organizational context and threat assessment. Current systems cannot reliably replace the human decision-making loop. |
| Task automatability | claude-sonnet-5 | 2/5 | Budget development requires understanding organizational context, negotiating priorities, and judgment calls that AI can support but not fully execute end-to-end without significant human input.dollars.co The task involves financial planning that benefits from AI-assisted analysis but the overall process of gathering requirements, stakeholder negotiation, and final decision-making remains largely human-driven. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Budget decisions carry organizational and fiduciary weight; approval chains typically require sign-off by senior leadership and finance officers. Security managers retain decision authority, and liability for inadequate budgeting creates strong organizational friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement mandates a human perform this task, but organizational accountability, fiduciary responsibility, and internal approval processes create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI tools for budget support (data aggregation, scenario modeling) cost less per unit task than a human, but the setup, validation, and oversight required to ensure correctness is material, making the all-in cost comparable to hiring junior financial support. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can reduce time spent on calculations and drafting, but the human oversight, contextual judgment, and stakeholder negotiation required keep overall costs comparable to human-led budgeting rather than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed AI product reliably develops security budgets end-to-end; tools exist for data aggregation and basic forecasting, but budget decisions require human judgment on resource allocation and risk weighting that current systems cannot automate. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | While generic financial planning and spreadsheet tools exist, no deployed product autonomously develops complete security operations budgets integrating threat assessments, staffing needs, and equipment costs at production scale. |
Conduct threat or vulnerability analyses to determine probable frequency, criticality, consequence, or severity of natural or man-made disasters or criminal activity on the organization's profitability or delivery of products or services.
29CI 25–32 · exposure 25 · augmentation 75 · importance 4.0/5 · click for rater detail
Conduct threat or vulnerability analyses to determine probable frequency, criticality, consequence, or severity of natural or man-made disasters or criminal activity on the organization's profitability or delivery of products or services.
29| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Mid-stage adoption: large enterprises deploy AI-assisted threat detection and log analysis tools, but human security analysts remain central to analysis and decision-making; smaller organizations lag significantly in both AI and sophisticated threat analysis practices. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security and risk management functions are adopting AI-assisted tools (threat intelligence, SIEM analytics) at a modest pace, but full analytical automation is uncommon and pilots dominate over production deployment for this specific task. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI substantially augments this task by automating threat data collection, identifying anomalies, and surfacing patterns at scale, allowing security managers to focus on prioritization, contextualization, and strategic risk assessment rather than manual log review. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly enhances threat/vulnerability analysis by processing large datasets, flagging risks, and providing predictive insights, substantially boosting analyst productivity while the human retains decision authority. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with data gathering and pattern recognition in threat assessment, the task fundamentally requires human judgment to synthesize complex organizational context, assess criticality relative to business strategy, and determine severity implications—requiring significant human direction and validation at each stage. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can assist with data aggregation and pattern recognition for parts of threat analysis, but synthesizing organizational context, judgment about criticality/consequence, and decision-making requires human expertise that current systems cannot fully replicate end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong regulatory and organizational barriers exist: compliance frameworks (SOC 2, ISO 27001, NIST) often mandate human expert sign-off, liability for missed threats falls on the organization, and risk assessments directly inform board-level decisions requiring human accountability and judgment. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No formal licensing typically required, but organizational liability, insurance requirements, and the need for accountable human judgment in risk assessments create moderate friction against pure automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI systems (scanning, log analysis tools) reduce data collection overhead but still require expensive security professionals to design analyses, interpret results, and make judgment calls; the all-in cost remains comparable to or higher than traditional analysis given expertise requirements. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While AI tools can reduce data-gathering time, the analysis still requires significant human oversight, contextual judgment, and validation, keeping costs closer to comparable rather than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No mature production system reliably performs end-to-end threat and vulnerability analysis independently; existing tools (SIEM, vulnerability scanners) provide inputs but require security experts to interpret, prioritize, and contextualize findings within organizational risk frameworks. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some security analytics and risk-scoring products exist (e.g., threat intelligence platforms), but comprehensive vulnerability analyses tying to organizational profitability and service delivery remain largely manual, expert-driven processes in production environments. |
Communicate security status, updates, and actual or potential problems, using established protocols.
29CI 25–32 · exposure 25 · augmentation 63 · importance 3.8/5 · click for rater detail
Communicate security status, updates, and actual or potential problems, using established protocols.
29| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Adoption of AI for security communication remains limited; most organizations use traditional monitoring dashboards and manual reporting. Security roles are generally risk-averse and slow to adopt AI for communication without extensive validation, keeping adoption in pilot or partial-automation phases. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security and corporate risk functions are adopting AI-assisted reporting and monitoring tools at a moderate pace, with pilots and some production use in larger organizations but not yet widespread. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can assist by drafting alert summaries, flagging anomalies, and organizing data, improving a manager's speed in composing and prioritizing communications. However, the human judgment required for sensitive interpretations limits the transformative impact of augmentation. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly assist by drafting reports, summarizing incident data, and standardizing protocol-based communications, meaningfully boosting productivity while the manager retains final judgment and delivery. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can generate routine status reports and format updates, the task requires judgment about severity, context-sensitivity, and protocol compliance that varies by organization. Actual automation would need human review for accuracy and appropriateness, preventing the 50% time-saving threshold from being met end-to-end. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can draft status reports and summaries from structured data, but synthesizing situational awareness, judgment calls on severity, and communicating with appropriate stakeholders still requires human oversight, so only partial time savings are achievable today. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security communication is tightly governed by organizational protocols, compliance requirements (HIPAA, SOX, industry standards), and liability concerns. In many sectors, a licensed or credentialed manager must sign off on or personally deliver security information, creating legal and procedural barriers to full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement to communicate updates, but liability, chain-of-custody expectations, and organizational trust in security communications create meaningful friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI systems for report generation and notification distribution have modest costs, but the oversight, customization, and human review required for security communications mean total integrated cost is not dramatically lower than a security manager handling communication directly. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | Drafting and templating communications can be cheaper via AI, but the overall task requires human validation, judgment on escalation, and accountability, keeping costs closer to comparable rather than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Some organizations use AI-assisted alert aggregation and template-based report generation, but deployed systems still rely heavily on human managers to interpret, prioritize, and communicate sensitive security information. No mature product reliably handles the full scope of protocol-compliant communication independently. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Products exist for incident reporting, dashboards, and automated alerting, but reliable end-to-end generation and communication of security status updates in production security operations is still narrow and human-reviewed. |
Monitor security policies, programs or procedures to ensure compliance with internal security policies, or applicable government security requirements, policies, and directives.
28CI 28–28 · exposure 25 · augmentation 75 · importance 4.0/5 · click for rater detail
Monitor security policies, programs or procedures to ensure compliance with internal security policies, or applicable government security requirements, policies, and directives.
28| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security and compliance teams are adopting AI-assisted monitoring tools (SIEM, log analysis, vulnerability scanning) at moderate pace, but automation remains limited to flagging and reporting rather than autonomous compliance sign-off. Regulatory risk aversion slows production-stage deployment of fully autonomous monitoring. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security and compliance functions are adopting AI-assisted monitoring tools at a moderate pace, with pilots and some production use in larger organizations, but broad deep adoption is not yet the norm. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly augments security managers by automating log analysis, identifying policy deviations, generating compliance reports, and highlighting suspicious patterns—raising productivity while the human retains judgment and final authority over compliance decisions. This assistive role is actively deployed and highly valued. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly assist security managers by continuously monitoring logs, flagging anomalies, and summarizing compliance gaps, greatly increasing productivity while the manager retains final judgment and accountability. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Monitoring compliance requires interpreting nuanced policies, understanding context-specific security risks, and making judgment calls about policy violations—tasks that depend heavily on human expertise. While AI can help flag anomalies or extract policy text, end-to-end compliance monitoring with equivalent quality and >50% time savings remains beyond current capabilities without substantial human oversight. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can help monitor logs and flag policy deviations, but interpreting compliance against complex, evolving government/internal requirements and making judgment calls requires human oversight, so full end-to-end automation is not yet achievable at equal quality. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong regulatory frameworks (SOC 2, ISO 27001, NIST, HIPAA, etc.) often require documented human accountability and sign-off on compliance findings. Liability and audit requirements mean organizations typically need licensed security professionals to own and attest compliance decisions, creating hard barriers to full automation. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security compliance often involves regulatory mandates, security clearances, and accountability requirements where a designated human security manager must be responsible for sign-off and legal liability. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Current AI solutions (SIEM tools, compliance platforms) require significant integration, specialized expertise to operate, and human oversight to validate results. These all-in costs approach or exceed the loaded wage of mid-level security compliance staff, limiting economic advantage. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can reduce some manual review time but still require significant human interpretation, configuration, and oversight for security compliance, keeping costs closer to comparable rather than order-of-magnitude cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | AI tools exist for basic audit logging, policy documentation search, and anomaly detection, but no deployed product reliably performs holistic security compliance monitoring without material false positives/negatives or narrow scope limitations. Security managers still require human verification of findings and interpretation of context-dependent compliance questions. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | GRC and compliance monitoring software with AI features exist and are used in production, but they mostly provide alerts and dashboards rather than autonomously ensuring compliance across policies and directives. |
Purchase security-related supplies, equipment, or technology.
28CI 25–30 · exposure 25 · augmentation 63 · importance 3.6/5 · click for rater detail
Purchase security-related supplies, equipment, or technology.
28| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Most organizations continue to rely on human procurement professionals and centralized purchasing departments for security equipment. AI adoption in this space remains limited to back-office tasks (data entry, basic analytics) rather than autonomous purchasing decisions. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security management is a moderately digitized function with slow uptake of AI in procurement decision-making compared to fast-adopting sectors like finance or software. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can assist with supplier discovery, price comparison, specification matching, and compliance checking, meaningfully streamlining research and analysis phases. However, vendor negotiation, risk assessment, and final approval remain substantially human-driven. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist with market research, spec comparison, price benchmarking, and drafting RFPs, significantly speeding up the procurement process while humans retain decision authority. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Purchasing decisions involve vendor evaluation, budget negotiation, and strategic technology selection that require human judgment. AI can assist with supplier research and RFQ comparison, but final procurement authority and vendor relationship management remain human responsibilities. |
| Task automatability | claude-sonnet-5 | 2/5 | Procurement involves vendor research, specification comparison, negotiation, and judgment about organizational security needs that AI can support but not fully execute end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security purchasing often requires authorization controls, compliance sign-off (regulatory standards for equipment), and formal vendor certification processes. Organizational policy and institutional procurement governance create substantial friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement to purchase, but organizational approval chains, budget authority, and accountability for security decisions create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI procurement assistants have material setup and oversight costs, while security purchasing is episodic and involves high-value, low-volume transactions where vendor relationships and custom specifications dominate. Human procurement managers remain cost-effective for this domain. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can cut research and comparison time, but human oversight, vendor relationships, and approval workflows remain necessary, limiting net cost savings. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | While AI-powered procurement tools exist, they operate narrowly on structured tasks like invoice processing or purchase order generation. End-to-end purchasing—including vendor selection, negotiation, and contract review for security equipment—lacks reliable, deployed products that handle the full workflow autonomously. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Procurement software and AI-assisted sourcing tools exist but are not deployed as autonomous purchasers of specialized security equipment; humans still make final vendor and spec decisions. |
Plan, direct, or coordinate security activities to safeguard company employees, guests, or others on company property.
26CI 25–28 · exposure 25 · augmentation 75 · importance 4.5/5 · click for rater detail
Plan, direct, or coordinate security activities to safeguard company employees, guests, or others on company property.
26| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security organizations are adopting AI-driven surveillance and monitoring tools at a moderate pace, but human security managers remain firmly in control of strategy and operations. Pilots of autonomous systems are common; production-level replacement of management functions is rare. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Physical security and facilities management sectors have historically been slower to adopt AI compared to information/professional services, though camera analytics and access systems are spreading gradually. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI substantially augments security managers through real-time threat detection, pattern analysis of surveillance data, automated alerting, and incident logging. These tools materially improve a manager's ability to oversee sites and respond to threats while remaining under human oversight. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully augment security managers through predictive analytics, anomaly detection in camera feeds, automated incident reporting, and risk assessment tools, improving efficiency while the manager retains decision authority. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Security planning requires judgment about risk factors, stakeholder needs, and dynamic threat assessment that AI cannot fully automate. While AI can assist with monitoring data and alerting, end-to-end planning and coordination of physical security operations remains heavily dependent on human decision-making and situational awareness. |
| Task automatability | claude-sonnet-5 | 2/5 | Planning and directing security operations requires situational judgment, physical-world coordination, and accountability that current AI cannot autonomously execute end-to-end, though AI can assist with scheduling, risk analysis, and data aggregation. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong barriers exist: security management often requires licensed personnel, legal liability for inadequate security falls on the organization and its managers, and regulatory frameworks (building codes, insurance requirements, industry standards) typically mandate human accountability and decision-making authority. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security management often involves legal liability, licensing (e.g., security director certifications in some jurisdictions), insurance requirements, and the need for human judgment in emergencies, creating strong barriers to full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI monitoring systems (cameras, sensors) reduce some operational costs, but the overhead of integration, tuning, and human oversight is substantial. A security manager's salary cannot be replaced by AI systems alone; AI augments but does not substitute the core role at a cost advantage. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can reduce some analytical and monitoring costs, but the managerial oversight, liability, and human coordination required keep overall costs comparable to or only modestly cheaper than a human manager. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed products reliably perform comprehensive security planning and coordination autonomously. AI excels at surveillance analytics and alert generation, but directing personnel, making real-time tactical decisions, and coordinating response across multiple domains remains in the human domain with AI as a tool. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | There are deployed tools for surveillance analytics, access control, and incident logging, but no production system independently plans and directs comprehensive security operations for a facility. |
Conduct physical examinations of property to ensure compliance with security policies and regulations.
26CI 23–30 · exposure 25 · augmentation 38 · importance 4.0/5 · click for rater detail
Conduct physical examinations of property to ensure compliance with security policies and regulations.
26| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 1/5 | Adoption of autonomous physical property inspection is minimal. Security management remains a low-digitization sector reliant on human personnel conducting hands-on walkthroughs; few organizations have moved to AI-based inspection and none at scale. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Physical security and facilities management are relatively low-digitization sectors with slow, cautious adoption of autonomous inspection technology compared to information-sector functions. |
| Augmentation potential | claude-haiku-4-5-20251001 | 2/5 | AI can modestly augment physical inspections through mobile camera footage review, document analysis, or automated reporting templates, but the core task of physically examining a property in real-time remains human-dependent with limited augmentation value. |
| Augmentation potential | claude-sonnet-5 | 3/5 | AI-powered cameras, sensors, and drones can help managers monitor larger areas and flag anomalies, but the manager still needs to physically verify and interpret compliance issues. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Current AI systems cannot reliably perform end-to-end physical property examinations, which require being on-site to visually inspect multiple areas, identify vulnerabilities, and make real-time decisions about compliance. While computer vision can assist with analyzing images or video footage, actually conducting the examination—moving through spaces, checking locks, observing conditions—remains fundamentally beyond deployed automation today. |
| Task automatability | claude-sonnet-5 | 2/5 | Physical walkthroughs of premises to check locks, barriers, signage, and compliance require in-person presence and situational judgment that current AI cannot fully replicate, though some sub-tasks (documentation, checklist generation) could be assisted. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Physical security examinations are regulated and often require licensed personnel who bear liability for findings; insurers, regulators, and organizations typically demand human accountability for security compliance verification, making substitution difficult even where technical capability existed. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing mandate strictly requires a human, but liability for security failures, insurance requirements, and organizational trust in human judgment create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | The AI and robotics systems capable of mobile physical inspection (mobile robots with vision, drones with payloads) remain expensive relative to human security manager labor, particularly when considering integration, oversight, and the need for human validation of findings. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | Sensors, drones, and computer vision systems have upfront and maintenance costs comparable to or exceeding a security manager's inspection time for equivalent coverage and judgment quality. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No mature deployed system reliably performs full physical property security examinations. Computer vision and mobile inspection tools can support parts of the task (e.g., analyzing photos), but products do not yet autonomously walk through properties and generate comprehensive compliance reports at production scale. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Deployed products like camera-based anomaly detection or drone inspections exist in narrow contexts, but no mature product performs comprehensive physical security compliance examinations reliably today. |
Direct or participate in emergency management and contingency planning.
25CI 25–25 · exposure 25 · augmentation 63 · importance 4.5/5 · click for rater detail
Direct or participate in emergency management and contingency planning.
25| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | While larger organizations use analytics tools to support planning, actual automation of emergency management direction remains rare in practice. Most adoption is limited to assisted analysis rather than autonomous or delegated decision-making, reflecting the sector's conservative approach to safety-critical functions. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security and facilities management is a moderately digitized but conservative sector, with AI tools used mainly for reporting and analytics rather than emergency plan execution or direction. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can assist security managers by automating scenario simulations, analyzing risk data, generating plan templates, and coordinating information flow, meaningfully reducing planning effort while humans retain control over strategy and final decisions. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully help by drafting plan templates, running risk simulations, summarizing regulations, and supporting after-action reviews, enhancing manager efficiency while humans retain final judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Emergency management and contingency planning require human judgment, stakeholder coordination, and real-time decision-making under uncertainty. While AI can assist with data analysis, scenario modeling, and documentation, it cannot autonomously direct or lead the strategic and interpersonal aspects of actual emergency response or plan development. |
| Task automatability | claude-sonnet-5 | 2/5 | This task requires situational judgment, coordination with stakeholders, and adaptive decision-making under uncertainty that current AI cannot fully replicate end-to-end, though it can assist with drafting and scenario analysis. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Emergency management is heavily regulated and often requires licensed security professionals or certified emergency managers with legal accountability for response plans and decisions. Liability asymmetry is acute—failures in emergency response create severe consequences, making organizational and regulatory friction substantial. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Emergency and contingency planning often carries regulatory, liability, and safety-certification requirements (e.g., OSHA, fire codes) that typically require a qualified human to approve and be accountable for plans. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | While AI-powered analytical tools can reduce some planning labor, the cost of such specialized systems, integration with security infrastructure, and required human oversight is comparable to or exceeds the cost of skilled security managers performing this work directly. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can cheaply generate draft plans or checklists, but the human costs of validating, coordinating, and adapting these plans to real facilities and personnel remain substantial, keeping overall cost savings modest. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | AI systems can perform narrow subtasks like document drafting, risk assessment analysis, or simulation modeling, but no deployed product reliably performs the full scope of directing emergency management and contingency planning in production settings. The task demands accountability and final decision authority that remains with humans. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | No deployed product autonomously directs emergency management; some planning software and AI-assisted risk modeling tools exist but require heavy human oversight and customization per organization. |
Assess risks to mitigate potential consequences of incidents and develop a plan to respond to incidents.
25CI 25–25 · exposure 25 · augmentation 63 · importance 4.2/5 · click for rater detail
Assess risks to mitigate potential consequences of incidents and develop a plan to respond to incidents.
25| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | While some enterprises experiment with AI-assisted risk tools, genuine production deployment of autonomous risk assessment and incident response planning remains limited. Security teams remain cautious and risk-averse, with adoption lagging behind information-work sectors due to high-stakes consequences. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security management functions are often embedded in physical security and corporate risk contexts that have slower digitization and AI tool adoption compared to purely digital-first industries. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can meaningfully augment security managers by automating threat data collection, generating initial incident response drafts, and supporting scenario analysis. However, the human must retain and exercise substantial judgment, limiting the transformation potential compared to tasks with lower stakes. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by synthesizing threat intelligence, generating draft risk matrices, and suggesting response plan templates, significantly speeding up the manager's workflow while they retain final judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Risk assessment and incident response planning require domain expertise, contextual judgment about organizational priorities, and coordination with multiple stakeholders. While AI can help gather data and draft documents, the critical decision-making and strategic planning remain predominantly human-driven, falling short of 50% time savings at equal quality. |
| Task automatability | claude-sonnet-5 | 2/5 | Risk assessment and incident response planning require contextual judgment, organizational knowledge, and accountability that current AI cannot fully replicate end-to-end, though AI can support data gathering and drafting portions. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security risk assessment and incident response planning are heavily regulated in many sectors (finance, healthcare, critical infrastructure) and often require licensed professionals (CISSP, CISM) to sign off. Organizational liability and compliance requirements create strong legal and operational barriers to full automation. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security managers often hold professional certifications and legal accountability for incident response plans, insurance and regulatory compliance requirements, and liability concerns that necessitate human ownership and sign-off. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Integrating AI for risk assessment requires expert oversight, validation, and refinement of outputs. The cost of AI infrastructure, expert review to catch errors, and liability mitigation is comparable to or exceeds the cost of security managers performing the work themselves, especially given the high consequence of errors. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can reduce time spent on research and drafting, but human expertise, site-specific knowledge, and sign-off are still required, keeping overall costs closer to comparable rather than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed product reliably performs comprehensive risk assessment and incident response planning independently. AI tools can support components (threat analysis, document generation), but production systems handling the full end-to-end task with security-grade reliability do not exist at scale. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some GRC and security-planning software includes AI-assisted risk scoring or template generation, but no deployed product autonomously performs comprehensive risk assessment and incident response planning reliably at scale. |
Develop or manage investigation programs, including collection and preservation of video and notes of surveillance processes or investigative interviews.
25CI 25–25 · exposure 25 · augmentation 63 · importance 3.7/5 · click for rater detail
Develop or manage investigation programs, including collection and preservation of video and notes of surveillance processes or investigative interviews.
25| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | While some enterprise organizations use video management and transcription tools, adoption of AI-driven investigation program management is limited. Most security teams maintain traditional human-led investigation processes with incremental tool adoption rather than systematic AI-driven investigation management. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security and corporate investigations sectors adopt AI slowly due to compliance, liability, and evidentiary concerns, with pilots more common than full production deployment. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can usefully assist security managers by automating video indexing, transcription of interviews, and evidence organization, improving efficiency in documentation and retrieval. However, the investigative decision-making and interview conduct remain human-centric, limiting the augmentation impact. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly assist by transcribing interviews, flagging video anomalies, organizing case files, and summarizing evidence, meaningfully boosting investigator productivity while humans retain control. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Collection of surveillance video can be partially automated (camera management, storage), but the investigative judgment of what to collect, how to conduct interviews, and interpretation of findings requires human expertise. Current AI cannot reliably manage the full investigation workflow with 50% time savings at equal quality. |
| Task automatability | claude-sonnet-5 | 2/5 | While some sub-elements like note-taking or video transcription could be assisted, developing and managing an investigation program requires judgment, chain-of-custody decisions, and strategic oversight that current AI cannot fully replace. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Investigation programs often face regulatory requirements (employment law, evidence handling standards, chain-of-custody rules) and potential liability for improper investigation or interview practices. Many jurisdictions require human security professionals to conduct and oversee investigations, particularly in sensitive contexts. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Evidentiary integrity, chain-of-custody rules, and legal admissibility standards typically require human accountability and often licensed security or legal professionals to oversee investigations. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI video storage and basic transcription tools are inexpensive, but comprehensive investigation program management with proper oversight, legal compliance, and interviewer coordination still requires significant human security professional involvement, keeping total cost comparable to or higher than pure human management. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can reduce costs for transcription and video review, but the managerial and legal oversight components still require costly human expertise, keeping overall cost comparable to human-led programs. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | While video storage and basic indexing tools exist, no deployed product reliably manages end-to-end investigation programs with collection protocols, interview documentation, and evidence preservation to legal standards. Products exist for individual components (video management, transcription) but not the integrated program management. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Products exist for video storage, transcription, and analytics but no deployed product manages an entire investigation program including interview strategy and evidentiary preservation reliably. |
Develop, implement, manage, or evaluate policies and methods to protect personnel against harassment, threats, or violence.
23CI 20–25 · exposure 20 · augmentation 63 · importance 4.1/5 · click for rater detail
Develop, implement, manage, or evaluate policies and methods to protect personnel against harassment, threats, or violence.
23| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security policy development remains conservative and legally risk-averse; adoption of AI is primarily in monitoring and alert systems rather than in autonomous policy formulation and implementation. Most organizations maintain human-led policy governance despite AI tooling availability. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security/corporate risk management functions are historically slow AI adopters relative to information/finance sectors, with AI use mostly limited to surveillance analytics rather than policy governance. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can meaningfully assist security managers by analyzing incident data, flagging patterns, generating policy drafts, and monitoring threat signals, improving productivity in research and documentation phases. However, augmentation is limited to support functions; final decisions require human expertise and accountability. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by drafting policy language, benchmarking best practices, analyzing incident trends, and flagging risks, substantially speeding up the manager's evaluation and drafting work. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with policy drafting, threat detection algorithms, and data analysis of incident patterns, the core task requires contextual judgment, stakeholder engagement, organizational culture understanding, and legal/HR expertise that current AI cannot reliably handle end-to-end. Implementation and management remain heavily dependent on human decision-making and accountability. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can help draft policy documents and analyze incident data, but developing, implementing, and evaluating protective policies requires contextual judgment, stakeholder negotiation, and organizational authority that current AI cannot execute end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong regulatory, legal, and organizational barriers exist: policies must comply with labor law, HR regulations, and industry standards; liability for inadequate harassment/violence prevention falls on organizational leadership; and stakeholder trust in human judgment (employees, legal counsel, executives) creates institutional resistance to full automation. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Liability exposure, legal compliance (OSHA, employment law), and the need for accountable human judgment in violence-prevention policy create strong organizational and legal barriers to full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI tools for threat monitoring and policy analysis have moderate costs, but the overhead of integration, human review, legal oversight, and the critical nature of policy errors make the all-in cost comparable to or exceeding that of employing security managers for this specialized work. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI drafting assistance is cheap, but the human oversight, legal review, stakeholder buy-in, and implementation work still dominate cost, so overall savings versus a human security manager are modest. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | AI tools exist for threat assessment, sentiment analysis, and policy templating, but no deployed product reliably performs the full suite of policy development, implementation, and evaluation in production environments. Systems work best as assistants rather than autonomous executors, and organizations still require human security managers to own outcomes. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed product manages full lifecycle policy creation and evaluation for workplace violence/harassment protection; existing tools are narrow (e.g., threat detection software, HR case management) rather than comprehensive policy management systems. |
Plan security for special and high-risk events.
23CI 20–25 · exposure 20 · augmentation 63 · importance 4.1/5 · click for rater detail
Plan security for special and high-risk events.
23| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Adoption of AI for event security planning is slow. While security firms use data analytics tools, the core planning function remains manual and human-centric. Organizational risk aversion, regulatory requirements, and the bespoke nature of each event limit broad automation uptake. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security management is a specialized, relationship- and trust-dependent field with limited AI agent deployment in production; adoption is slow and mostly limited to analytics/support tools. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can meaningfully assist by analyzing historical threat data, generating risk assessments, optimizing personnel deployment logistics, and flagging potential vulnerabilities, but the human security manager retains central responsibility for judgment and approval. Assistance is useful on components but does not fully transform productivity. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist with risk assessment data aggregation, threat intelligence summarization, scenario simulation, and drafting security plans, improving efficiency while the manager retains final judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | AI can assist with data analysis, threat assessment frameworks, and logistics optimization, but the task requires contextual judgment about venue-specific risks, stakeholder coordination, and real-time decision-making under uncertainty that current systems cannot perform end-to-end. Human oversight of security planning decisions is essential and unavoidable. |
| Task automatability | claude-sonnet-5 | 2/5 | Planning security for special or high-risk events requires situational judgment, physical site assessment, coordination with law enforcement, and risk tradeoffs that current AI cannot execute end-to-end reliably.'},'automatability capped low because core deliverable is a judgment-based plan tied to physical/human context.' |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Significant legal and liability barriers exist: security planning for high-risk events often requires licensed security professionals, regulatory compliance (venue codes, law enforcement coordination), and liability for failures falls on organizations and designated humans. Customer and stakeholder expectations also strongly favor human accountability and decision-making. |
| Adoption barriers | claude-sonnet-5 | 4/5 | High-risk event security often involves regulatory compliance, liability, coordination with police/emergency services, and accountability that typically requires a credentialed human security manager to sign off. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Current AI tools (risk assessment software, logistics optimization) are useful supplements but do not replace the security manager's salary; integration costs, domain expertise requirements, and mandatory human oversight make the total cost comparable to or higher than specialized human labor. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | Given the low automatability, most of the human planner's time and liability remain, so AI tools add cost/oversight without replacing the bulk of billable expert work. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed product reliably plans comprehensive security for high-risk events autonomously. While AI tools exist for threat detection and risk scoring in narrow domains, the full planning task—venue assessment, personnel deployment, contingency design, stakeholder negotiation—remains dependent on human security professionals in production environments. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed product autonomously plans event security operations; this remains a human-led, expert-driven process with AI at most assisting with data lookups or checklists. |
Supervise or provide leadership to subordinate security professionals, performing activities such as hiring, investigating applicants' backgrounds, training, assigning work, evaluating performance, or disciplining.
14CI 3–25 · exposure 13 · augmentation 50 · importance 4.1/5 · click for rater detail
Supervise or provide leadership to subordinate security professionals, performing activities such as hiring, investigating applicants' backgrounds, training, assigning work, evaluating performance, or disciplining.
14| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security management remains heavily human-centric; while background-check automation is widespread, end-to-end supervisory automation is not. Security firms and internal teams continue to rely on human managers for hiring, training, and discipline. Adoption is limited to narrow administrative tasks, not the broader leadership role. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security management is a moderately digitized but people-centric field; while some HR-adjacent tools are adopted, actual managerial decision-making authority is not being automated in practice. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can usefully augment security managers by pre-screening applicants, flagging performance anomalies, summarizing background findings, and recommending training resources, improving efficiency on routine analytical tasks. However, the augmentation is limited to information support; final decisions remain with the human manager. |
| Augmentation potential | claude-sonnet-5 | 3/5 | AI can meaningfully assist with background check research, performance evaluation documentation, scheduling, and training material generation, improving manager efficiency on sub-tasks. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with initial resume screening, background checks, and performance data analysis, the core interpersonal elements—hiring decisions, discipline, training delivery, and real-time leadership—require human judgment, trust-building, and accountability that current systems cannot fully replicate. Meaningful automation would require replacing most supervisory judgment, not just administrative overhead. |
| Task automatability | claude-sonnet-5 | 1/5 | This is a managerial leadership task requiring interpersonal judgment, disciplinary decisions, and personnel accountability that cannot be executed end-to-end by current AI systems. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Hiring and disciplinary decisions carry legal liability and often require compliance with employment law and security clearance protocols; many jurisdictions mandate human sign-off on hiring and termination. Subordinates and customers expect human-led supervision. These regulatory and cultural barriers substantially protect human security managers. |
| Adoption barriers | claude-sonnet-5 | 5/5 | Hiring, disciplinary actions, and background investigations involve legal liability, labor law compliance, and often licensing/certification requirements that mandate human accountability. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI tools for hiring and background screening are relatively affordable, but integrating them with oversight and managing the liability and errors in hiring/discipline decisions requires significant human management cost, keeping total automation cost comparable to or above a security manager's labor for this ensemble of tasks. |
| Cost vs. human wage | claude-sonnet-5 | 1/5 | AI cannot substitute for the human manager role itself, so there is no viable cost comparison—human oversight and legal accountability remain mandatory. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Some HR tech platforms offer applicant ranking and background-check assistance, but no deployed system reliably performs the full supervisory task: hiring, investigations, training design, performance evaluation, and disciplinary action at scale without substantial human oversight. Products address fragments but not the integrated leadership dimension. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed product performs supervisory leadership, hiring decisions, or employee discipline autonomously; at best AI assists with background check data aggregation or scheduling. |
Develop, arrange for, perform, or assess executive protection activities to reduce security risks.
13CI 0–25 · exposure 13 · augmentation 50 · importance 3.6/5 · click for rater detail
Develop, arrange for, perform, or assess executive protection activities to reduce security risks.
13| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Adoption of AI-assisted tools in security management is moderate; however, replacement of human protective personnel remains minimal. Most executive protection remains labor-intensive and resistant to automation due to liability, trust, and regulatory requirements limiting algorithmic control. |
| Sector adoption velocity | claude-sonnet-5 | 1/5 | Physical security and protective services are a low-digitization, human-presence-dependent sector with minimal AI displacement. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can meaningfully assist security managers in threat modeling, risk assessment, event monitoring, and coordination logistics, raising productivity on analytical and administrative tasks. However, the protective judgment and presence components remain anchored to human expertise. |
| Augmentation potential | claude-sonnet-5 | 3/5 | AI can assist with threat intelligence gathering, route planning, and risk assessment analytics, improving planning even though execution remains human-driven. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with risk assessment, threat detection, and planning coordination, the core task—protecting an executive from security threats—requires real-time human judgment, physical presence, and decision-making under uncertainty that cannot be fully automated. Current AI systems lack the embodied agency and adaptive response capability needed for end-to-end autonomous protection. |
| Task automatability | claude-sonnet-5 | 1/5 | Executive protection involves physical presence, threat assessment in real-world environments, and split-second human judgment that current AI cannot perform end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong barriers exist: liability for failure is severe and asymmetric, executives typically demand human security personnel for legal accountability and presence, and many jurisdictions require licensed security professionals to perform or sign off on protection measures. Organizational culture strongly favors human judgment in life-safety contexts. |
| Adoption barriers | claude-sonnet-5 | 5/5 | Executive protection requires licensed, often armed personnel with legal authority to act, background checks, and liability considerations that mandate human performance. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Executive protection involves high-stakes liability and requires trained personnel with legal responsibility; AI tools for threat analysis are relatively cheap, but they augment rather than replace the bulk cost of skilled human protection teams. All-in cost remains dominated by human security professionals. |
| Cost vs. human wage | claude-sonnet-5 | 1/5 | AI cannot substitute for the physical bodyguard/protective agent role, so there is no viable AI cost comparison for the core task. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Security products exist for threat monitoring, access control, and risk analysis, but no deployed AI system reliably performs integrated executive protection end-to-end. Most protection tasks remain dependent on human operatives with legal authority and situational awareness that AI alone cannot provide in production environments. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed AI product performs physical protective services; this remains a human security professional function with only ancillary software support. |
Support efforts to reduce substance abuse or other illegal activities in the workplace.
12CI 7–16 · exposure 5 · augmentation 50 · importance 3.4/5 · click for rater detail
Support efforts to reduce substance abuse or other illegal activities in the workplace.
12| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Adoption remains slow and cautious. Organizations typically rely on human security managers and HR professionals for these functions; fear of legal liability, regulatory ambiguity, and the need for human judgment in sensitive interventions keep AI deployment to narrow surveillance roles rather than end-to-end substitution. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security and HR compliance functions adopt AI slowly for sensitive personnel matters, with pilots limited to monitoring/detection tools rather than program leadership. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can meaningfully assist security managers by flagging anomalous access patterns, summarizing incident reports, organizing case data, and suggesting relevant policies—but humans must retain control over investigation, intervention decisions, and legal/disciplinary outcomes. This represents useful partial augmentation rather than transformation. |
| Augmentation potential | claude-sonnet-5 | 3/5 | AI can assist by analyzing data patterns (e.g., flagging anomalies, absenteeism trends) or drafting policy documents, but the core support and intervention role remains human-led. |
| Task automatability | claude-haiku-4-5-20251001 | 1/5 | This task requires nuanced human judgment, contextual understanding of workplace dynamics, legal considerations, and sensitive interpersonal engagement. Current AI systems cannot autonomously support substance abuse reduction or illegal activity prevention in ways that meet the 50% time-saving bar at equal quality. |
| Task automatability | claude-sonnet-5 | 1/5 | This task involves organizational leadership, judgment calls on personnel issues, policy design, and interpersonal intervention that AI cannot execute end-to-end today.' |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong barriers exist: substance abuse interventions often touch on medical and privacy law (ADA, HIPAA in the US), employer liability is high, many jurisdictions require licensed professionals (counselors, investigators) to sign off, and unions or employee advocates often resist automation of discipline/investigation. Legal exposure prevents full automation. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Legal, HR, and liability considerations (drug testing policy, disciplinary action, employee rights) require human authority and accountability, creating strong organizational and legal barriers to automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI monitoring and flagging tools exist but typically require significant human oversight, integration, and expertise to interpret. When you factor in the need for human investigation and intervention, the total cost per outcome is unlikely to be materially cheaper than a security manager handling cases directly. |
| Cost vs. human wage | claude-sonnet-5 | 1/5 | There is no viable AI substitute performing this function, so cost comparison favors the human entirely. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Some narrow products exist for monitoring (access logs, flagging patterns), but no deployed system reliably handles the full scope of supporting abuse reduction efforts—which requires investigation, counseling guidance, policy design, and legal/HR coordination. Existing tools have significant scope limitations. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed AI product manages workplace substance abuse or illegal activity reduction programs; this remains a human management function. |
Monitor and ensure a sound, ethical environment.
9CI 3–16 · exposure 5 · augmentation 50 · importance 3.9/5 · click for rater detail
Monitor and ensure a sound, ethical environment.
9| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Although security and compliance sectors are digitizing, the deployment of AI for autonomous ethical governance remains limited; most organizations still rely on human security managers with AI-assisted tools rather than AI-driven enforcement, indicating slow deep adoption. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security and compliance management functions are adopting AI tools for monitoring and analytics, but the ethical-oversight and culture-setting aspects remain largely untouched by automation in practice. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can augment security managers by automating data collection, pattern detection, and initial flagging of potential violations, allowing managers to focus investigation and judgment on confirmed anomalies, but the human remains essential to ethical decision-making. |
| Augmentation potential | claude-sonnet-5 | 3/5 | AI can assist by flagging compliance violations, analyzing communications for risk signals, or summarizing incident reports, helping managers monitor more efficiently even though ethical judgment remains human-led. |
| Task automatability | claude-haiku-4-5-20251001 | 1/5 | Monitoring and ensuring a 'sound, ethical environment' requires nuanced judgment about human behavior, organizational culture, and context-dependent moral reasoning that current AI systems cannot reliably perform end-to-end. No deployed AI can autonomously assess ethics violations or enforce ethical standards across an organization with the judgment needed to replace human oversight. |
| Task automatability | claude-sonnet-5 | 1/5 | This task requires ongoing human judgment, ethical reasoning, organizational culture-shaping, and interpersonal leadership that current AI cannot perform end-to-end; it is a broad managerial responsibility, not a discrete automatable process. |
| Adoption barriers | claude-haiku-4-5-20251001 | 5/5 | Ensuring an ethical environment involves legally-mandated compliance roles, fiduciary duty, and often requires a licensed professional or authorized human to make final determinations on misconduct and corrective action. Liability for false positives or missed violations creates strong legal barriers to full automation. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Ethical oversight and security governance typically require accountable human managers due to liability, regulatory compliance, and organizational trust requirements, though not always a formal license. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI-based monitoring systems have non-trivial licensing and integration costs, but the high human expertise required (security managers, HR, compliance staff) for validation and decision-making keeps overall cost competitive with or higher than human labor alone. |
| Cost vs. human wage | claude-sonnet-5 | 1/5 | Because no AI system performs this task end-to-end, there is no viable AI cost comparison—human judgment and accountability remain necessary, making AI substitution infeasible rather than cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with narrow components like anomaly detection in transaction logs or flagging policy violations, no mature product performs the full task of ensuring an ethical organizational environment reliably. Existing tools require substantial human interpretation and judgment, falling short of production-ready end-to-end solutions. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed product monitors or ensures organizational ethics holistically; AI tools exist for narrow compliance monitoring or anomaly detection but not for the full managerial function described. |
Coordinate security operations or activities with public law enforcement, fire and other agencies.
4CI 0–7 · exposure 0 · augmentation 38 · importance 4.0/5 · click for rater detail
Coordinate security operations or activities with public law enforcement, fire and other agencies.
4| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 1/5 | Despite digitization in security, inter-agency coordination remains a human-centric, relationship-driven function that has seen minimal AI adoption even in forward-looking organizations. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Security management is a moderately digitized but relationship- and physical-presence-driven field where AI adoption for external coordination is minimal and slow. |
| Augmentation potential | claude-haiku-4-5-20251001 | 2/5 | AI could assist with minor tasks like scheduling coordination meetings or summarizing agency communications, but the core work of negotiating, deciding, and building trust with external agencies requires human presence and judgment. |
| Augmentation potential | claude-sonnet-5 | 3/5 | AI can assist with scheduling, incident logging, communications drafting, and information-sharing support, but the core coordination and relationship-building remains human-driven. |
| Task automatability | claude-haiku-4-5-20251001 | 1/5 | This task requires real-time coordination, negotiation, and relationship-building with external agencies that involves human judgment, contextual decision-making, and accountability. AI cannot independently establish or maintain the inter-organizational partnerships and authority required to coordinate with law enforcement and fire agencies. |
| Task automatability | claude-sonnet-5 | 1/5 | This requires real-time interpersonal negotiation, judgment calls with external agencies, and trust-building relationships that AI cannot perform end-to-end today.atch |
| Adoption barriers | claude-haiku-4-5-20251001 | 5/5 | This task has hard legal and organizational barriers: only authorized human security managers can represent their organization to law enforcement and fire agencies, and liability for coordination failures rests with humans, not AI systems. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Liaison with law enforcement and fire agencies often involves legal accountability, incident command protocols, and requires an authorized human representative, creating strong organizational and regulatory barriers. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 1/5 | A security manager's coordination role involves high-stakes decision-making and relationship maintenance that require human expertise and authority; AI oversight would not reduce costs below the human wage for this task. |
| Cost vs. human wage | claude-sonnet-5 | 1/5 | There is no viable AI substitute performing this coordination role, so cost comparison favors the human by default since AI cannot deliver the output. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 1/5 | No deployed AI system can autonomously coordinate with external government agencies on security operations; this requires legal authority, contractual relationships, and human accountability that AI cannot assume. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed product coordinates live cross-agency security operations autonomously; this remains firmly human-led with only administrative support tools available. |
Respond to medical emergencies, bomb threats, fire alarms, or intrusion alarms, following emergency response procedures.
1CI 0–3 · exposure 0 · augmentation 38 · importance 4.3/5 · click for rater detail
Respond to medical emergencies, bomb threats, fire alarms, or intrusion alarms, following emergency response procedures.
1| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 1/5 | Adoption of autonomous AI for emergency response is virtually non-existent; the sector remains bound to on-site human responders by regulation, liability, and the inherent need for physical presence and real-time adaptive judgment that is not being displaced by AI in practice. |
| Sector adoption velocity | claude-sonnet-5 | 2/5 | Physical security sectors adopt AI mainly for detection/alerting (cameras, sensors) but actual emergency response execution remains almost entirely human-driven with slow structural change. |
| Augmentation potential | claude-haiku-4-5-20251001 | 2/5 | AI can marginally assist by automating alert routing, logging incidents, or providing reference materials during response, but these augmentations are minor compared to the core human judgment and physical action required and do not meaningfully transform the security manager's productivity on this task. |
| Augmentation potential | claude-sonnet-5 | 3/5 | AI-enabled alarm systems, threat detection, and dispatch/coordination tools can speed up situational awareness and initial triage, meaningfully aiding the manager's response even though the core action stays human. |
| Task automatability | claude-haiku-4-5-20251001 | 1/5 | This task requires immediate physical presence, real-time situational judgment under high uncertainty, and direct human interaction during emergencies—capabilities fundamentally unavailable to AI systems today. AI cannot respond in person to alarms or make split-second safety decisions that depend on contextual details only discoverable on-site. |
| Task automatability | claude-sonnet-5 | 1/5 | This requires physical presence, real-time judgment, and hands-on crisis response (evacuations, coordinating with first responders, assessing physical threats) that current AI cannot perform end-to-end.' |
| Adoption barriers | claude-haiku-4-5-20251001 | 5/5 | Emergency response is heavily regulated and legally mandated to involve trained, licensed, accountable human personnel. Medical response, fire safety, and security threats all carry strict liability requirements that legally bind trained humans to the decision and execution of response procedures. |
| Adoption barriers | claude-sonnet-5 | 5/5 | Emergency response typically requires designated, often licensed or legally accountable personnel, with liability, safety regulations, and legal reporting duties tightly bound to human responders. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 1/5 | AI systems cannot substitute for the human responder; they may assist with alerting or logging but add cost without replacing the security manager's physical and decision-making role, making the all-in cost higher than a human-only approach. |
| Cost vs. human wage | claude-sonnet-5 | 1/5 | A human security manager's physical response and decision-making cannot be substituted by AI inference, so there is no comparable cost basis for full task replacement. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 1/5 | No deployed AI product can autonomously respond to these types of emergencies end-to-end. While AI can monitor sensors or dispatch alerts, the actual response (medical intervention, threat assessment, evacuation coordination) remains entirely human-dependent in production systems. |
| Technical feasibility today | claude-sonnet-5 | 1/5 | No deployed product autonomously responds to physical emergencies like bomb threats or fire alarms; AI is at most a notification/monitoring layer feeding human responders. |
Related occupations — Management
How to read this
A high substitution score does not mean this job disappears — it means a large share of its current tasks face replacement pressure, so the mix of tasks is likely to change. High augmentation alongside substitution typically means the occupation reorganizes around the protected tasks. Wide confidence intervals mean the rater panel disagreed: treat those scores as open questions, not verdicts.
What would change this score
New model capabilities (automatability, feasibility), falling inference costs (cost ratio), regulation and licensing shifts (barriers), and measured sector adoption (velocity) all re-enter at every index release. Each release is recomputed, versioned and kept queryable — scores are claims with a date on them, not permanent labels.