Information Security Analysts
15-1212.00Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.
Sub-scores
0–100 · band = confidence interval from rater disagreement
Substitution — the headline: capability discounted by cost, barriers and adoption.
Exposure — technical capability alone, regardless of whether anyone deploys it.
Augmentation — how much AI assists without replacing. High here + moderate substitution = a changing job, not a disappearing one.
Tasks on the substitution scale
11 rated tasks, binned by substitution score.
Position among all scored occupations
Distribution of 923 occupation scores; the marker is this occupation.
Tasks with substitution ≥ 70
9%
Run 1.0.0-draft.1 · computed 2026-08-05 · rater panel: claude-sonnet-5, claude-haiku-4-5-20251001 · intervals span rater disagreement.
Why this score
The five weighted dimensions of the composite, averaged across this occupation's tasks (importance-weighted, panel mean). Exact weights and formulas: /api/v1/methodology.
panel mean rating 2.6/5 → substitution pressure 41/100
panel mean rating 2.7/5 → substitution pressure 42/100
panel mean rating 2.8/5 → substitution pressure 46/100
panel mean rating 3.2/5 (barrier strength) → substitution pressure 44/100
panel mean rating 3.2/5 → substitution pressure 55/100
Task breakdown (11 tasks)
Substitution pressure per task, weighted by O*NET importance in the composite. Expand a task for the full rater audit trail — every rating, every model, every rationale.
Monitor current reports of computer viruses to determine when to update virus protection systems.
74CI 70–79 · exposure 75 · augmentation 88 · importance 4.2/5 · click for rater detail
Monitor current reports of computer viruses to determine when to update virus protection systems.
74| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 4/5 | Enterprise security teams have been adopting automated threat monitoring and patch management at high velocity for over a decade. Modern InfoSec-heavy sectors (finance, tech, healthcare) run these systems in production as standard practice, though small firms and legacy organizations lag. |
| Sector adoption velocity | claude-sonnet-5 | 4/5 | Cybersecurity is a fast-adopting, highly digitized field where automated threat intelligence and patch/update management are already standard practice in most mature IT organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 5/5 | AI threat feeds and automated alerts dramatically assist human analysts by filtering noise, surfacing high-confidence threats, and suggesting update timing. This maintains analyst oversight while multiplying the volume and speed of threat detection they can manage. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI-curated threat intelligence dashboards and automated alerts significantly boost an analyst's ability to track and act on emerging virus threats faster than manual review. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | AI can ingest threat feeds, parse virus reports, cross-reference signatures, and trigger updates with minimal human oversight. The core decision—when to update—is largely rule-driven and automatable end-to-end, though some security analysts prefer human validation in high-risk environments, preventing a 5 rating. |
| Task automatability | claude-sonnet-5 | 4/5 | Threat intelligence feeds, CVE monitoring, and automated signature updates already handle most of this monitoring loop with minimal human intervention, though judgment on prioritization still adds value. |
| Adoption barriers | claude-haiku-4-5-20251001 | 3/5 | No strict legal requirement that a human must approve virus definition updates, but many organizations impose internal approval workflows and risk-aversion policies for critical systems. Liability concerns around incorrect updates and system downtime create organizational friction without hard regulatory barriers. |
| Adoption barriers | claude-sonnet-5 | 2/5 | No licensing requirement blocks automated monitoring, though organizations still want a human to validate and approve major system-wide updates to avoid operational disruption. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 5/5 | Cloud-based threat feeds and automated update systems cost far less than a full-time analyst salary, and inference is lightweight. The all-in cost per update cycle is orders of magnitude cheaper than paying an analyst to manually review each report. |
| Cost vs. human wage | claude-sonnet-5 | 4/5 | Automated threat feeds and update mechanisms cost a small fraction of a full-time analyst's wage for this specific monitoring subtask, though integration and tuning add some overhead. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 4/5 | Deployed SIEM systems, threat intelligence platforms (e.g., CrowdStrike, Mandiant), and automated vulnerability scanners already perform virus monitoring and recommend updates in production. They operate reliably at scale, though human review remains common practice in many organizations, limiting it from a full 5. |
| Technical feasibility today | claude-sonnet-5 | 4/5 | Deployed SIEM/EDR platforms and threat intelligence services (e.g., automatic virus definition updates, vulnerability feeds) reliably perform continuous monitoring and updating in production environments today. |
Train users and promote security awareness to ensure system security and to improve server and network efficiency.
61CI 46–75 · exposure 55 · augmentation 75 · importance 3.8/5 · click for rater detail
Train users and promote security awareness to ensure system security and to improve server and network efficiency.
61| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 4/5 | Security-conscious organizations, especially in regulated sectors (finance, healthcare, tech) and larger enterprises, are rapidly adopting automated security awareness platforms and AI-driven training systems. Deployment is visible and accelerating across information-heavy industries. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Security awareness platforms have integrated AI-driven content generation and adaptive simulations, but adoption for fully automated training delivery is still mid-stage with many firms using blended human-AI approaches. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly augments security trainers by auto-generating customized scenarios, tracking metrics, identifying at-risk users, and personalizing content delivery, allowing analysts to focus on targeted interventions and policy refinement rather than routine training delivery. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI substantially aids in creating training materials, simulating phishing attacks, tracking user performance, and personalizing content, significantly boosting an analyst's productivity in awareness programs. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | AI can generate training materials, create phishing simulations, deliver automated awareness content, and track user progress with minimal human intervention, achieving substantial time savings. However, the interpersonal engagement and nuanced feedback in some awareness contexts still benefit from human instruction, preventing a perfect 5. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can generate training content and phishing simulations, but delivering engaging training, adapting to org culture, and driving behavioral change requires human facilitation and judgment that current AI cannot fully replace end-to-end.' |
| Adoption barriers | claude-haiku-4-5-20251001 | 2/5 | Few regulatory or licensing barriers prevent automation of user security training; organizations widely deploy self-service and automated awareness programs already. Some may prefer human trainers for high-risk roles or compliance optics, but nothing legally mandates human delivery of this task. |
| Adoption barriers | claude-sonnet-5 | 2/5 | No licensing requirement mandates a human trainer, though many organizations prefer human-led sessions for engagement and accountability, creating moderate organizational friction. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 4/5 | Automated training platforms cost a fraction of hiring dedicated trainers or security awareness staff, especially at scale. Inference and content delivery are cheap; integration and periodic review by a human security officer maintain quality at costs orders of magnitude lower than traditional instructor-led training. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI-generated training materials and automated phishing tests reduce content-creation costs, but human-led sessions, Q&A, and program customization still require significant human time, keeping costs roughly comparable. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 4/5 | Multiple deployed products (learning management systems with AI modules, automated phishing simulators like Gophish integrations, security awareness platforms from vendors like KnowBe4 and Proofpoint) successfully deliver security training at scale in production environments. Some customization and human oversight remain standard practice, but reliable end-to-end delivery is demonstrated. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | Products like KnowBe4 and Proofpoint use AI to generate phishing simulations and training modules, but human security analysts still design programs, present live training, and handle org-specific context. |
Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated.
53CI 32–74 · exposure 50 · augmentation 88 · importance 4.0/5 · click for rater detail
Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated.
53| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 4/5 | Information security and IT operations are high-digitization sectors with rapid adoption of AI-driven monitoring and alerting. Many enterprises already use automated violation detection and reporting; human review of violations is increasingly augmented or replaced by AI-generated summaries and recommendations. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | InfoSec is a fast-adopting field for AI-assisted detection and reporting, but the interpersonal violation-discussion piece sees little automation adoption yet. |
| Augmentation potential | claude-haiku-4-5-20251001 | 5/5 | AI dramatically assists analysts by instantly surfacing violations, correlating patterns, and drafting context-specific talking points, allowing analysts to focus on high-stakes or nuanced cases and conversations rather than manual log review. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can help analysts quickly identify, document, and summarize violations, and even draft talking points for the follow-up discussion, meaningfully speeding up the review portion of the task. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | AI can identify and flag security procedure violations through log analysis and pattern detection with high accuracy, and can generate or draft discussion prompts for violators. However, the nuanced, context-sensitive conversation to understand intent and ensure behavioral change typically benefits from human judgment, keeping this below a full 5. |
| Task automatability | claude-sonnet-5 | 2/5 | The investigative and evidence-review portion can be partly AI-assisted, but the interpersonal discussion with violators to ensure behavioral change requires human judgment, tone, and authority that AI cannot substitute for end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 3/5 | While security procedures must be enforced, there is no legal requirement that a licensed human must conduct violation discussions; however, organizational risk management and liability concerns around improper handling of security incidents create moderate friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | Organizational policy, HR involvement, and accountability for disciplinary/compliance conversations create friction, though not a hard licensing requirement. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 5/5 | Automated violation detection and alert generation costs a fraction of a human analyst's hourly wage, and the per-violation cost is orders of magnitude lower when scaled across thousands of events. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can cheaply summarize logs and violations, but the human-facing counseling/discussion component still requires paid staff time, keeping overall cost savings modest. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 4/5 | Deployed security monitoring tools already detect and flag violations automatically; generative AI can draft reports and talking points. Production systems exist in enterprise security platforms, though the conversational/coaching component remains semi-automated rather than fully autonomous. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Security tools can flag violations and generate reports, but no deployed product conducts the corrective conversation with employees or reliably closes the loop on behavioral compliance. |
Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.
52CI 28–76 · exposure 50 · augmentation 75 · importance 4.2/5 · click for rater detail
Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers.
52| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 5/5 | Information security is a highly digitized, well-resourced sector with rapid cloud and automation adoption. Managed firewalls, automated encryption, and security automation platforms see deep deployment in enterprise and finance organizations, with production use widespread. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT and cybersecurity sectors are fast adopters of AI tooling generally, but for core security infrastructure like firewall and encryption implementation, adoption remains cautious with AI used mainly as an assistant rather than an autonomous actor. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly assists security analysts by automating routine configuration, generating policy recommendations, monitoring traffic patterns for anomalies, and alerting to threats, while analysts remain in the loop for strategic decisions and incident response. This substantially raises analyst productivity. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist analysts by suggesting firewall rules, flagging misconfigurations, drafting encryption policies, and analyzing traffic patterns, significantly speeding up the analyst's workflow while they retain final control. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | Current AI systems can automate most of this task: encryption algorithm selection and deployment, firewall rule generation, and configuration can be handled by modern tools and agents with significant time savings. However, full end-to-end automation remains impractical because threat assessment, policy calibration, and architecture decisions still require human judgment and oversight. |
| Task automatability | claude-sonnet-5 | 2/5 | Configuring encryption protocols and firewall rules requires contextual judgment about network architecture, threat models, and compliance needs that current AI cannot fully own end-to-end, though AI can assist with drafting configs and rules.4 |
| Adoption barriers | claude-haiku-4-5-20251001 | 3/5 | Moderate barriers exist: regulatory compliance (HIPAA, PCI-DSS, SOC 2) and organizational policy require human oversight and sign-off, and security liability concerns make fully autonomous deployment risky. However, no legal requirement mandates that a human personally perform the technical encryption or firewall erection itself. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security misconfigurations carry severe liability and breach risk, and organizations typically require human sign-off and certified security professionals to implement and audit access controls and encryption schemes. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 5/5 | Automated encryption and firewall deployment via cloud platforms and managed security services is orders of magnitude cheaper per task-unit than hiring human security engineers to manually configure and maintain these systems, especially at scale. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can reduce time spent drafting configurations but human security analysts must still validate and monitor implementations, so all-in costs including oversight remain comparable to human-only work. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 4/5 | Deployed products (e.g., automated firewall management platforms, encryption-as-a-service, and security orchestration tools) reliably perform these functions in production environments across many organizations. Some error rates and configuration gaps remain, but the core task is demonstrably executed at scale today. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some AI-assisted tools exist for generating firewall rules or suggesting encryption configurations, but deployed products still require security engineers to validate, test, and implement due to high error costs of misconfiguration. |
Document computer security and emergency measures policies, procedures, and tests.
46CI 34–59 · exposure 45 · augmentation 88 · importance 3.9/5 · click for rater detail
Document computer security and emergency measures policies, procedures, and tests.
46| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | While information-sector organizations are generally tech-forward, adoption of AI for autonomous security policy documentation remains limited due to compliance requirements, liability concerns, and the critical nature of getting security measures right. Most current use is assistive (drafting aids) rather than replacement. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Information security sits in a fast-adopting professional/IT sector, but documentation-specific AI tooling adoption is still in pilot/early-production stage rather than fully mainstream. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI can substantially augment security analysts by auto-generating policy drafts from standards, organizing procedures, flagging gaps against frameworks, and helping structure test documentation, allowing the analyst to focus on validation and customization rather than initial composition. This is a strong use case for assistive AI while human expertise remains essential for approval. |
| Augmentation potential | claude-sonnet-5 | 5/5 | AI significantly speeds up drafting of policies, procedures, and test documentation, letting analysts focus on review, customization, and validation, which is a strong augmentation use case. |
| Task automatability | claude-haiku-4-5-20251001 | 3/5 | AI can draft substantial portions of security policies and procedures documents by synthesizing templates, standards, and organizational requirements, but human expertise is needed to contextualize, validate, and approve the actual security measures. The task involves domain knowledge and liability considerations that prevent full end-to-end automation at production quality. |
| Task automatability | claude-sonnet-5 | 3/5 | AI can draft policy documents, procedures, and test plans from templates and organizational input, but requires human review for accuracy, compliance context, and organization-specific nuance, so only part of the task is automatable at equal quality without setup.' |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Information security policies and emergency procedures typically require sign-off by authorized security officers or compliance personnel, and liability exposure for inadequate documentation creates strong organizational and regulatory barriers. Many regulated industries (finance, healthcare, critical infrastructure) mandate human accountability for security policy approval. |
| Adoption barriers | claude-sonnet-5 | 2/5 | No licensing requirement mandates a human write these documents, though internal governance and audit/compliance review processes create moderate organizational friction before AI-drafted content is finalized. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI inference for document drafting is cheap, but the overhead of expert human review, validation, and liability sign-off means total cost approaches or exceeds that of a human analyst writing the document, especially given the security-critical nature requiring no tolerance for errors. |
| Cost vs. human wage | claude-sonnet-5 | 4/5 | Generating draft documentation via LLMs is very cheap compared to analyst hourly rates, even after factoring in review time, making AI substantially cheaper for the drafting portion of this task. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | While generative AI tools can produce policy document drafts and help organize procedures, deployed products do not reliably handle the full scope of security policy documentation (standards mapping, compliance alignment, emergency procedure validation) without significant human review and error correction. Products exist for assistance but not for autonomous reliable production of security policies. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | Products like ChatGPT/Copilot and specialized GRC tools can generate security documentation drafts today, but reliable, accurate production use still requires significant human editing and validation, limiting scope. |
Monitor use of data files and regulate access to safeguard information in computer files.
44CI 35–53 · exposure 42 · augmentation 88 · importance 3.9/5 · click for rater detail
Monitor use of data files and regulate access to safeguard information in computer files.
44| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 4/5 | Information security is a highly digitized sector with strong regulatory and breach-cost incentives; organizations are adopting automated monitoring and SOAR platforms aggressively, though human-in-the-loop models remain standard. |
| Sector adoption velocity | claude-sonnet-5 | 4/5 | Information security sits within IT/finance/professional services, sectors with fast, deep AI adoption, and automated monitoring tools are already standard in security operations centers. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI-driven SIEM, behavioral analytics, and anomaly detection significantly amplify human analysts' ability to spot threats and prioritize investigations, enabling them to handle far more data files and access patterns than manual review alone would allow. |
| Augmentation potential | claude-sonnet-5 | 5/5 | AI significantly augments analysts by automating log correlation, flagging anomalies, and prioritizing alerts, letting humans focus on judgment calls and policy decisions. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Monitoring access logs and enforcing basic permission rules can be partially automated with SIEM tools and access control systems, but determining whether access is truly anomalous or justified requires contextual human judgment that current AI systems struggle with reliably at scale. |
| Task automatability | claude-sonnet-5 | 3/5 | AI-driven SIEM/UEBA tools can automate much of the monitoring and anomaly detection, but access regulation decisions, policy exceptions, and escalation still require human judgment, so only partial time savings are achieved end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory frameworks (HIPAA, SOX, GDPR, SOC 2) often require documented human oversight and accountability for access decisions; liability for data breaches creates strong organizational pressure to retain human analysts in the loop even where automation is technically possible. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement mandates a human specifically, but liability for data breaches, compliance frameworks (SOX, HIPAA, PCI-DSS), and organizational risk aversion create meaningful friction against full automation of access control decisions. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 3/5 | SIEM and access control automation can reduce per-alert review costs, but the infrastructure, tuning, and ongoing human validation still approach the cost of domain experts' salaries when oversight is factored in. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | Security tooling requires significant licensing, tuning, and continuous human oversight to avoid costly breaches or false positives, so total cost is not dramatically cheaper than skilled analyst labor despite automation of log parsing. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Automated access control and logging systems exist and are deployed in production, but they generate high false-positive rates and typically require human analysts to investigate and validate alerts before taking action. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | Products like SIEM platforms with ML-based anomaly detection, DLP, and IAM systems are deployed widely, but false positive rates remain material and human analysts still triage and configure access policies. |
Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.
32CI 28–37 · exposure 30 · augmentation 75 · importance 4.1/5 · click for rater detail
Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures.
32| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security teams widely use automated testing and scanning tools as assistants, but deployment of fully autonomous risk assessment and testing remains limited; most organizations still rely on human analysts to validate, prioritize, and act on AI-generated findings. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity is a fast-moving field with AI-assisted tools increasingly used for scanning and threat detection, but full autonomous risk assessment and testing remains mostly in pilot or augmented-human stages rather than widespread production replacement. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | Current AI systems meaningfully assist security analysts by automating routine scanning, generating risk reports, highlighting anomalies, and suggesting remediation steps, substantially raising analyst productivity while the expert remains the decision-maker. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly assists analysts by automating vulnerability scanning, flagging anomalies, and drafting reports, meaningfully boosting productivity while humans retain responsibility for judgment and validation. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Risk assessments require contextual judgment and business-process understanding that current AI struggles with; automated security testing (vulnerability scanning) is common, but end-to-end execution of comprehensive assessments with equal quality and ≥50% time savings is not yet demonstrated at scale. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can assist with vulnerability scanning and generating parts of risk assessment reports, but conducting comprehensive risk assessments and validating security tests across complex, organization-specific systems still requires human judgment, contextual knowledge, and accountability that current AI cannot fully replace. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS) often require documented sign-off by qualified security professionals; liability for missed vulnerabilities and false assurances create strong legal/organizational friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement mandates a human perform this specific task, but liability concerns, compliance frameworks (e.g., PCI-DSS, SOC 2), and organizational risk tolerance create meaningful friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Automated scanning and testing tools are relatively inexpensive, but the overall workflow still requires expensive security analysts for judgment, scoping, and remediation planning; AI handles only parts of the work cost-effectively. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While automated scanning tools reduce some labor costs, the overall task still requires significant human oversight, interpretation, and sign-off, keeping all-in costs closer to comparable with human analysts rather than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Deployed products exist for vulnerability scanning, penetration testing frameworks, and security policy analysis, but they operate with notable false-positive/false-negative rates and require significant human oversight and interpretation to translate findings into actionable risk assessment. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Deployed products exist for automated vulnerability scanning and penetration testing tools, but end-to-end risk assessment combining technical, business, and compliance context is not reliably automated by any production system today. |
Modify computer security files to incorporate new software, correct errors, or change individual access status.
32CI 25–40 · exposure 33 · augmentation 63 · importance 4.1/5 · click for rater detail
Modify computer security files to incorporate new software, correct errors, or change individual access status.
32| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | While information security is a digitized field, adoption of AI for security file modifications specifically remains limited; most organizations rely on manual processes, ticketing systems, or narrowly scoped automation tools rather than agent-based approaches, reflecting risk aversion in the security domain. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT/security is a digitized, fast-adopting sector for AI tooling generally, but adoption specifically for autonomous security file modification remains in pilot/copilot stage rather than widespread production use. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can meaningfully assist by suggesting necessary modifications, flagging potential policy conflicts, automating documentation, and accelerating code review, but the human analyst must retain control over approval and execution due to security and compliance requirements. Productivity gains are moderate. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI copilots effectively assist analysts by drafting configuration changes, flagging anomalies, and suggesting access corrections, meaningfully speeding up the task while a human still approves and applies changes. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist in identifying necessary modifications and generating code snippets, the task requires precise judgment about access control policies, security implications, and contextual business rules that vary significantly per organization. End-to-end automation would require 50% time savings with equal quality, but human oversight of access status changes and security file modifications remains critical due to high error costs. |
| Task automatability | claude-sonnet-5 | 3/5 | AI can draft config changes, ACL updates, and access-control scripts, but validating security implications and applying changes safely in production still requires human review, so only part of the workflow meets the 50% time-savings bar. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Significant regulatory and organizational barriers exist: most frameworks (SOC2, ISO 27001, regulatory compliance) require documented human accountability for access control changes, and many organizations require authorized personnel to approve and sign off on security modifications. Liability and audit trail requirements create hard friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Changes to security configurations carry high liability risk and often require authorized personnel sign-off under compliance frameworks (SOC2, ISO27001, etc.), creating strong organizational and regulatory friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Integration and oversight costs for AI-assisted security file modification are substantial given the liability exposure and need for human validation. The total cost is comparable to or exceeds hiring a security analyst for this work, especially when accounting for error remediation and compliance verification. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI-assisted scripting reduces time on routine changes, but the need for security review, testing, and rollback safeguards keeps overall cost roughly comparable to a skilled analyst doing it directly. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Some specialized security tools can automate narrow aspects (e.g., patching, bulk access provisioning), but no deployed product reliably handles the full scope of modifying security files while correctly interpreting organizational policy, error correction, and access status changes across diverse environments without significant manual review. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some SOAR/IAM tools and copilots can suggest or automate routine permission changes, but reliable end-to-end autonomous modification of security files in production is still narrow and closely supervised. |
Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
30CI 28–32 · exposure 25 · augmentation 75 · importance 4.4/5 · click for rater detail
Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security teams are experimentally adopting AI for threat detection and policy drafting, but adoption of AI-led plan development remains pilot-stage. Most organizations still rely on human analysts to architect safeguarding strategies, though AI tools augment the process incrementally. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT/security functions in tech and finance are adopting AI copilots for documentation and risk assessment, but plan development itself remains a slower-adopting, judgment-heavy area with pilots more common than full deployment. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI substantially assists security analysts by generating policy templates, automating threat analysis, suggesting controls, and helping prioritize risks—enabling faster, more comprehensive planning. The analyst remains responsible for validation and customization, but AI significantly boosts productivity in the planning phase. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly speed up drafting of security policies, identifying gaps against frameworks like NIST, and generating disaster recovery templates, substantially aiding the analyst's productivity. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist in generating security frameworks and analyzing threat patterns, developing comprehensive safeguarding plans requires nuanced judgment about organizational context, threat modeling, and risk prioritization that current AI systems cannot reliably perform end-to-end. The task involves strategic decision-making and accountability that AI cannot shoulder alone. |
| Task automatability | claude-sonnet-5 | 2/5 | Drafting security/backup plans requires understanding organizational context, risk tolerance, and infrastructure specifics that AI cannot fully assess autonomously, though it can accelerate drafting portions. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong regulatory and liability barriers exist: cybersecurity plans typically require certified professionals (CISSP, etc.) to design and sign off, and organizations face legal/compliance obligations tied to human expert accountability. Breach liability is asymmetric—an AI-generated plan that fails exposes the organization, pushing organizations toward human responsibility. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement mandates a human specifically, but liability for security failures and compliance frameworks (e.g., audits, regulatory standards) create strong organizational incentive to keep qualified humans accountable for these plans. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Current AI tools (policy generators, scanning automation) reduce manual effort but do not yet deliver order-of-magnitude cost savings; human oversight remains essential and expensive. Integration costs and the need for domain expertise to validate AI-generated plans keep total cost close to traditional human-led approaches. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While AI drafting assistance is cheap, the human analyst still must gather requirements, validate technical fit, and ensure compliance, making all-in cost savings modest rather than order-of-magnitude. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed product reliably generates and implements complete data safeguarding plans independently. Tools exist for specific components (vulnerability scanning, policy templates, backup automation), but production systems still require security analysts to integrate, validate, and customize these outputs for organizational context. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | AI tools can generate template security policies and disaster recovery frameworks, but no deployed product independently develops comprehensive, validated safeguarding plans without heavy analyst review and customization. |
Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.
29CI 25–32 · exposure 25 · augmentation 75 · importance 3.9/5 · click for rater detail
Confer with users to discuss issues such as computer data access needs, security violations, and programming changes.
29| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Despite high digitization in information security, adoption of AI-driven user conferencing remains minimal in production. Security teams are conservative, risk-averse, and continue to rely on human judgment for these sensitive conversations. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT security and professional services sectors show moderate AI adoption with pilots for ticketing and access management, but many organizations still route security-sensitive conversations through humans. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI can meaningfully assist by drafting response templates, summarizing violation patterns, suggesting remediation steps, and flagging policy inconsistencies—allowing the analyst to focus on judgment and relationship-building with users. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by drafting responses, summarizing security violation reports, and pre-triaging access requests, letting analysts focus on judgment-heavy conversations. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can draft responses and summarize common security issues, this task requires real-time dialogue, understanding of user context, organizational nuances, and judgment about which violations warrant escalation. Current AI cannot reliably handle the full conversational discovery and decision-making loop without substantial human oversight. |
| Task automatability | claude-sonnet-5 | 2/5 | This requires live interpersonal conversation, contextual judgment about user needs, and organizational trust-building that current AI cannot fully replace end-to-end, though chatbots can triage simple requests. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Organizational and liability barriers are substantial: users expect confidentiality and expert judgment from a named analyst, security violations carry legal/compliance implications, and many organizations maintain policies requiring human sign-off on access decisions and violation assessments. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement, but security violations often carry compliance, legal, and trust implications that create organizational friction against full automation and a preference for human judgment. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | A security analyst's loaded hourly cost remains significantly lower than the combined cost of AI infrastructure, integration, monitoring, and mandatory human oversight to validate security decisions made during these consultations. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While AI chat interfaces are cheap per interaction, the oversight, escalation handling, and liability management needed for security-sensitive conversations keep the effective cost comparable to human analysts for anything beyond routine requests. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Chatbots and virtual assistants exist but are rarely deployed as primary actors in security consultations due to liability, user trust concerns, and the need for nuanced threat assessment. Production systems today still route these discussions to human analysts. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Deployed helpdesk chatbots and ticketing assistants handle basic access requests, but nuanced security violation discussions and negotiation over programming changes still require human analysts in production settings. |
Coordinate implementation of computer system plan with establishment personnel and outside vendors.
29CI 25–32 · exposure 25 · augmentation 63 · importance 3.9/5 · click for rater detail
Coordinate implementation of computer system plan with establishment personnel and outside vendors.
29| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Information security roles remain human-centric; organizations prioritize verified human accountability for system implementation. Pilot adoption of AI coordination tools exists but production displacement is minimal, reflecting organizational risk aversion in critical infrastructure. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT/security functions in mid-to-large firms are adopting AI tools for documentation and workflow support at a moderate pace, but coordination roles remain human-led with pilots more common than full deployment. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can assist by drafting communication templates, tracking vendor status, or organizing implementation schedules, improving human coordinator efficiency on administrative aspects, though the human must retain final judgment on stakeholder concerns and implementation trade-offs. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by drafting project plans, tracking tasks, summarizing vendor communications, and flagging risks, boosting the coordinator's productivity while they retain control. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Coordination with multiple human stakeholders requires negotiation, context-sensitivity, and real-time responsiveness that current AI cannot reliably replicate end-to-end. While AI could draft communications or organize timelines, the interpersonal negotiation and conflict resolution essential to implementation coordination remain outside current capabilities at production quality. |
| Task automatability | claude-sonnet-5 | 2/5 | This task is fundamentally relational and organizational—coordinating people, schedules, vendor contracts, and negotiations—which current AI cannot reliably execute end-to-end without heavy human oversight.rn |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Legal and accountability frameworks typically require a human information security professional to take responsibility for system implementation planning and vendor coordination; liability for miscommunication or failed coordination creates strong barriers to full AI automation in regulated or risk-sensitive environments. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement, but organizational trust, accountability for security decisions, and vendor relationship management create real friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Current AI systems require substantial human oversight for coordination tasks (verification of vendor agreements, stakeholder alignment, escalation handling), making the all-in cost per coordinated implementation comparable to or higher than direct human coordination. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can support scheduling and communication drafting cheaply, but the human coordination, judgment, and vendor relationship management still require substantial human labor, keeping overall cost savings modest. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No mature deployed product reliably performs multi-party coordination and vendor management at scale. Existing project management and communication tools assist humans but do not autonomously coordinate implementation decisions across diverse stakeholders with accountability. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | No production AI system autonomously coordinates cross-organizational implementation efforts with vendors and staff; project-management chatbots assist but do not replace the coordinating role. |
Related occupations — Computer & Mathematical
How to read this
A high substitution score does not mean this job disappears — it means a large share of its current tasks face replacement pressure, so the mix of tasks is likely to change. High augmentation alongside substitution typically means the occupation reorganizes around the protected tasks. Wide confidence intervals mean the rater panel disagreed: treat those scores as open questions, not verdicts.
What would change this score
New model capabilities (automatability, feasibility), falling inference costs (cost ratio), regulation and licensing shifts (barriers), and measured sector adoption (velocity) all re-enter at every index release. Each release is recomputed, versioned and kept queryable — scores are claims with a date on them, not permanent labels.