Penetration Testers

15-1299.04
Median wage $116,580/yr435,370 employed (US)Rank #274 of 923 scored · top 30% by substitution

Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.

Sub-scores

0–100 · band = confidence interval from rater disagreement

Substitution35
Exposure30
Augmentation72

Substitution — the headline: capability discounted by cost, barriers and adoption.

Exposure — technical capability alone, regardless of whether anyone deploys it.

Augmentation — how much AI assists without replacing. High here + moderate substitution = a changing job, not a disappearing one.

Tasks on the substitution scale

22 rated tasks, binned by substitution score.

Position among all scored occupations

Distribution of 923 occupation scores; the marker is this occupation.

Tasks with substitution ≥ 70

0%

Run 1.0.0-draft.1 · computed 2026-08-05 · rater panel: claude-sonnet-5, claude-haiku-4-5-20251001 · intervals span rater disagreement.

Why this score

The five weighted dimensions of the composite, averaged across this occupation's tasks (importance-weighted, panel mean). Exact weights and formulas: /api/v1/methodology.

Task automatabilityw 35%30

panel mean rating 2.2/5 → substitution pressure 30/100

Technical feasibility todayw 20%31

panel mean rating 2.2/5 → substitution pressure 31/100

Cost vs. human wagew 15%34

panel mean rating 2.3/5 → substitution pressure 34/100

Adoption barriersw 20%inverted — strong barriers lower the score44

panel mean rating 3.3/5 (barrier strength) → substitution pressure 44/100

Sector adoption velocityw 10%42

panel mean rating 2.7/5 → substitution pressure 42/100

Task breakdown (22 tasks)

Substitution pressure per task, weighted by O*NET importance in the composite. Expand a task for the full rater audit trail — every rating, every model, every rationale.

Document penetration test findings.

61

CI 5467 · exposure 58 · augmentation 88 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Cybersecurity and professional services are digitally mature and moderately embracing AI; however, adoption of AI for final reporting remains cautious due to liability and client trust. Pilots and hybrid workflows are common; full automation adoption is slower.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity firms are professional-services oriented and increasingly using AI for report drafting and summarization, but adoption is still uneven and many firms are cautious given sensitivity of the content.
Augmentation potentialclaude-haiku-4-5-202510014/5AI significantly assists penetration testers by automating formatting, organizing findings, suggesting narrative structure, and flagging common patterns, allowing the human expert to focus on judgment, context, and recommendations. This augmentation is widely adopted in practice.
Augmentation potentialclaude-sonnet-55/5AI substantially speeds up drafting, formatting, and summarizing findings while the tester still validates technical accuracy and severity judgments, making this a strong augmentation use case.
Task automatabilityclaude-haiku-4-5-202510013/5AI can automatically generate structured vulnerability reports, organize findings, and create initial documentation with significant time savings, but expert review, context-setting, and remediation prioritization require human judgment. Current tools handle template-filling and data organization well, achieving partial automation.
Task automatabilityclaude-sonnet-54/5Drafting structured findings documentation (vulnerability descriptions, severity ratings, evidence, remediation suggestions) from test logs/tool output is largely templated text generation that LLMs handle well, though final review is needed.
Adoption barriersclaude-haiku-4-5-202510013/5Organizational and liability concerns create moderate friction: documentation must be legally defensible, often requires human expert sign-off, and clients may mandate human authorship. Regulatory frameworks (e.g., SOC 2, HIPAA) sometimes require evidence of human review, but no hard licensing block exists.
Adoption barriersclaude-sonnet-52/5No licensing requirement mandates a human author these reports, though client trust, liability for missed findings, and confidentiality of sensitive vulnerability data create moderate friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510014/5AI-driven documentation can reduce the time spent on boilerplate, formatting, and organizing raw findings to a fraction of manual effort, making the cost per document substantially lower than paying a senior tester full rate. Integration and oversight costs are modest.
Cost vs. human wageclaude-sonnet-54/5Generating draft documentation via LLMs is very cheap compared to analyst hours spent writing reports, even after accounting for human review and editing time.
Technical feasibility todayclaude-haiku-4-5-202510013/5Products exist (security report generators, AI-assisted documentation tools) that reliably produce initial drafts, but material gaps remain in nuance, accuracy of risk classification, and legal defensibility. Output typically requires substantial human review before client delivery.
Technical feasibility todayclaude-sonnet-53/5Report-generation features exist in pentest tooling and LLM-assisted drafting is used by some teams, but most firms still rely heavily on human-written narrative and quality/consistency checks, so deployment is partial rather than fully reliable at scale.

Conduct network and security system audits, using established criteria.

60

CI 5070 · exposure 62 · augmentation 88 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510014/5Enterprise security operations, financial services, and cloud-native organizations are rapidly adopting automated vulnerability scanning, continuous compliance monitoring, and AI-assisted audit tools. Displacement of manual scanning is accelerating across well-digitized sectors.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately fast-adopting tech sector, with growing use of AI-assisted scanning and triage tools, though full agentic pentesting remains in pilot/early-adoption phase rather than deep production use.
Augmentation potentialclaude-haiku-4-5-202510015/5AI tools dramatically augment penetration testers by automating routine scanning, organizing findings, correlating data, and suggesting interpretations—allowing testers to focus on strategic analysis, novel attack vectors, and high-value target prioritization. This is a textbook case of AI-assisted productivity enhancement in cybersecurity.
Augmentation potentialclaude-sonnet-54/5AI substantially accelerates vulnerability discovery, log analysis, and report drafting for auditors, significantly boosting productivity while a human tester still directs strategy, validates findings, and signs off on results.
Task automatabilityclaude-haiku-4-5-202510014/5Significant portions of network and security audits—vulnerability scanning, port mapping, credential testing, log analysis, and compliance checking against known standards—can be fully automated with established tools and AI agents. However, interpreting results, prioritizing findings, and adapting strategy based on context still typically require human judgment, preventing a full 5 rating.
Task automatabilityclaude-sonnet-53/5Automated scanning and vulnerability assessment tools can perform much of a checklist-based audit against established criteria, but interpreting findings, chaining exploits, and contextualizing risk still requires human expertise, so only part of the workflow meets the 50% time-savings bar.
Adoption barriersclaude-haiku-4-5-202510013/5While regulatory frameworks (SOC 2, PCI-DSS, HIPAA) often require audits, they typically permit automated tooling as a component and do not require a licensed human to run the scan. However, the responsibility and liability for findings interpretation, reporting, and remediation recommendations still typically rest with qualified humans, creating organizational and contractual friction.
Adoption barriersclaude-sonnet-53/5There's no licensing requirement to perform such audits, but liability, legal authorization scoping, and client trust in named certified professionals (e.g., OSCP, CEH) create moderate organizational friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510014/5Automated scanning tools and AI-driven audit agents cost a small fraction of the loaded cost of a penetration tester's time per audit cycle. Licensing and integration overhead is modest compared to hourly rates of security professionals ($75–150+ loaded).
Cost vs. human wageclaude-sonnet-53/5Automated scanning tools are cheap to run compared to a full manual audit, but the need for skilled human validation, remediation guidance, and report generation keeps overall costs comparable to human-led engagements when done properly.
Technical feasibility todayclaude-haiku-4-5-202510014/5Mature products (Nessus, Qualys, OpenVAS, and AI-enhanced agents) demonstrably perform systematic vulnerability scanning and audit tasks in production. These tools reliably execute against established criteria, though nuanced interpretation and social engineering tests still benefit from human oversight.
Technical feasibility todayclaude-sonnet-53/5Products like Nessus, Qualys, and AI-assisted pentest tools (e.g., agentic scanners) are deployed in production for compliance-style audits, but reliable end-to-end automated pentesting with low false-positive rates and correct exploit validation is still narrow in scope.

Maintain up-to-date knowledge of hacking trends.

46

CI 4646 · exposure 34 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security teams increasingly adopt AI-assisted threat monitoring and trend dashboards, but the practice remains pilot-heavy rather than a systematic replacement of human monitoring roles. Adoption is faster in large enterprises than small firms.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately fast-adopting, digitized field with growing use of AI-driven threat intelligence tools, but full production reliance on AI for trend awareness (versus human analyst curation) remains a pilot/hybrid stage.
Augmentation potentialclaude-haiku-4-5-202510014/5AI significantly augments this task: automated feeds, trend pattern detection, and summaries of emerging techniques help penetration testers stay current faster than manual research alone. The human remains in control but their productivity on trend awareness is materially enhanced.
Augmentation potentialclaude-sonnet-54/5AI substantially aids penetration testers by aggregating, summarizing, and flagging emerging vulnerabilities and attack techniques from large volumes of text, letting humans focus on validation and application rather than manual searching.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist in monitoring security news feeds and summarizing emerging threats, penetration testers must synthesize findings into actionable, contextualized knowledge and evaluate which trends are relevant to their specific threat landscape. Current AI systems cannot autonomously maintain the deep, judgment-driven situational awareness this requires at 50% time savings with equal quality.
Task automatabilityclaude-sonnet-52/5Staying current on hacking trends requires continuous synthesis of disparate, fast-moving sources (forums, CVE feeds, dark web chatter, conference talks) and judgment about relevance; AI can summarize feeds but cannot independently replace the ongoing human curation and contextualization process end-to-end.'
Adoption barriersclaude-haiku-4-5-202510012/5While there are no hard legal barriers preventing AI assistance, organizational risk aversion, liability concerns around acting on AI-flagged threats without human validation, and professional accountability norms favor human oversight, creating modest adoption friction.
Adoption barriersclaude-sonnet-52/5No licensing or legal requirement mandates a human perform this specific knowledge-maintenance task, though organizational reliance on trusted human judgment for security-critical decisions creates some friction.
Cost vs. human wageclaude-haiku-4-5-202510013/5Commercial threat intelligence and AI-assisted monitoring services are available and moderately priced, but a skilled penetration tester's hourly wage is high and the ongoing cost of subscriptions plus oversight approximates the human cost for this knowledge-maintenance task.
Cost vs. human wageclaude-sonnet-53/5AI tools for monitoring and summarizing security feeds are relatively cheap to run, but the oversight and expert interpretation needed to validate relevance and accuracy keeps overall cost roughly comparable to a skilled analyst's time investment.
Technical feasibility todayclaude-haiku-4-5-202510013/5Products exist (e.g., threat intelligence platforms with AI summaries, automated news aggregation tools) that help track hacking trends, but they require significant human curation and verification to avoid false positives or misinterpreted threat signals. Deployed systems provide useful input but not end-to-end trend analysis.
Technical feasibility todayclaude-sonnet-53/5Products like threat intelligence platforms and AI-assisted summarization tools (e.g., news aggregators, LLM-based digesting of CVE/exploit databases) exist and are used in security operations, but they require human verification and are narrow in scope, not full replacements for expert trend-tracking.

Prepare and submit reports describing the results of security fixes.

46

CI 2567 · exposure 45 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Penetration testing remains a specialized, human-expertise-dependent function in security firms; adoption of autonomous AI reporting is slow because clients demand human judgment and accountability, and the sector has not moved to production-scale automation of report generation.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately digitized, tech-forward field increasingly integrating AI into reporting and triage, but many firms still rely on manual, customized reporting workflows.
Augmentation potentialclaude-haiku-4-5-202510013/5AI can meaningfully assist by drafting initial report structure, summarizing technical findings, and suggesting language for remediation steps, improving speed and consistency; however, the pentester must validate all claims and tailor recommendations, making it assistive rather than transformative.
Augmentation potentialclaude-sonnet-55/5AI substantially speeds up drafting, formatting, and summarizing findings, letting testers focus on validation and judgment while retaining oversight of technical accuracy.
Task automatabilityclaude-haiku-4-5-202510012/5Current AI can help draft sections of reports and summarize test results, but the task requires judgment about security implications, risk assessment, and tailored remediation advice that demands human expertise. End-to-end automation would not reliably meet quality thresholds for security-critical documentation.
Task automatabilityclaude-sonnet-54/5Drafting structured penetration test reports summarizing vulnerabilities, fixes, and outcomes from technical logs and scan data is largely a text-synthesis task, which current LLMs handle well when given structured input.
Adoption barriersclaude-haiku-4-5-202510014/5Security reports often must be signed by qualified professionals and may carry legal/liability implications; clients typically require reports authored by credentialed testers, and regulatory contexts (compliance frameworks) may mandate human accountability for findings.
Adoption barriersclaude-sonnet-52/5No licensing requirement mandates a human write the report, though liability for accuracy and client trust in the assessment findings creates moderate incentive for human oversight and sign-off.
Cost vs. human wageclaude-haiku-4-5-202510012/5The overhead of AI-assisted drafting plus mandatory expert review and revision means the total cost (inference + integration + expert oversight) remains comparable to or exceeds having a skilled pentester write the report directly.
Cost vs. human wageclaude-sonnet-54/5Generating a draft report via AI is dramatically cheaper than a tester spending hours writing narrative summaries and remediation verification sections, even with human review overhead.
Technical feasibility todayclaude-haiku-4-5-202510012/5While LLMs can generate report templates and summarize findings, no deployed product reliably produces security reports at the depth and accuracy required for professional penetration testing work; human penetration testers must review and substantially revise AI-generated content.
Technical feasibility todayclaude-sonnet-53/5Some security platforms and AI-assisted reporting tools generate draft reports from scan/test data, but human review and customization for client context and accuracy remain standard practice, limiting fully autonomous deployment.

Keep up with new penetration testing tools and methods.

46

CI 3854 · exposure 30 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510014/5Security and cybersecurity firms are digitally mature and actively adopting AI for threat intelligence aggregation and tool discovery; adoption is relatively fast within these information-intensive sectors.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity professionals increasingly use AI search/summarization tools and LLMs to track trends, but this is still informal and uneven across the field rather than a deep production-grade adoption pattern.
Augmentation potentialclaude-haiku-4-5-202510014/5AI excels at surfacing, categorizing, and summarizing emerging tools and methodologies from research publications and security feeds, substantially accelerating a tester's ability to stay current while they retain judgment on applicability and testing.
Augmentation potentialclaude-sonnet-54/5AI tools (chatbots, summarizers, aggregators) can meaningfully speed up scanning security blogs, CVEs, and tool documentation, helping testers stay current faster than manual research alone.
Task automatabilityclaude-haiku-4-5-202510012/5AI can summarize security research and flag new tools from feeds, but evaluating their applicability, hands-on testing, and contextual relevance to specific engagements requires human judgment and experimentation that cannot be fully automated today.
Task automatabilityclaude-sonnet-52/5Staying current requires ongoing human judgment, curiosity, and synthesis of scattered information across communities, conferences, and evolving exploit landscapes; AI can summarize but not autonomously drive this continuous learning process end-to-end.
Adoption barriersclaude-haiku-4-5-202510012/5No licensing requirement forces human involvement, and organizations can adopt AI-assisted learning tools freely, though some may prefer human mentorship or hands-on training culture.
Adoption barriersclaude-sonnet-51/5No licensing or regulatory barrier prevents using AI tools to research or summarize new methods; it's an informal professional development task with no gatekeeping.
Cost vs. human wageclaude-haiku-4-5-202510013/5AI monitoring and summarization tools cost moderately, but a penetration tester's time spent learning and validating new methods is still substantial; the cost trade-off is roughly comparable.
Cost vs. human wageclaude-sonnet-52/5AI subscription tools that aid research are cheap, but the task is diffuse and ongoing so cost comparison is less relevant; humans still need to spend significant time validating and contextualizing information, limiting true cost savings.
Technical feasibility todayclaude-haiku-4-5-202510013/5Products exist (security RSS aggregators, AI-assisted threat intelligence platforms) that help curate and summarize new tools and methods, but they have narrow scope and require significant manual validation by practitioners.
Technical feasibility todayclaude-sonnet-52/5No deployed product autonomously tracks and internalizes new pentesting tools/methods for a practitioner; existing tools are search/summarization aids at best, not reliable continuous learning agents.

Develop presentations on threat intelligence.

42

CI 2559 · exposure 38 · augmentation 88 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Security and penetration testing firms adopt AI cautiously due to accuracy and liability concerns; while some use LLMs for draft content and data organization, manual review by certified professionals remains standard practice, indicating slow production adoption.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity teams are moderately adopting AI for reporting and documentation tasks, though core intelligence gathering and validation remain human-led with cautious pilot adoption.
Augmentation potentialclaude-haiku-4-5-202510014/5AI can meaningfully assist by drafting initial slide structures, formatting threat data, generating visual summaries, and organizing intelligence findings, allowing the penetration tester to focus on strategic framing and validation rather than manual presentation assembly.
Augmentation potentialclaude-sonnet-55/5AI significantly speeds up drafting, summarizing, and formatting threat intelligence content, letting analysts focus on validation and strategic insights while staying in the loop.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can generate initial drafts and compile threat data into slides, creating effective threat intelligence presentations requires domain expertise, strategic framing, and audience-tailored risk communication that AI currently cannot deliver reliably end-to-end without substantial human oversight and revision.
Task automatabilityclaude-sonnet-53/5AI can draft slide content, summarize threat data, and structure a presentation, but curating accurate, current threat intelligence and tailoring it to organizational context still requires human validation.rrThus only partial automation meets the time-saving bar.
Adoption barriersclaude-haiku-4-5-202510014/5Penetration testing and threat intelligence deliverables are often subject to client contracts, security classifications, and organizational liability requirements; the human expert must validate and sign off on threat claims and recommendations, creating a hard approval barrier.
Adoption barriersclaude-sonnet-52/5No licensing requirement for creating presentations; main friction is need for accuracy and organizational trust in threat data, not regulatory barriers.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI tools (LLMs, slide generators) have low inference costs but require significant human expert review and rework to meet security standards, making total cost-per-reliable-presentation comparable to or exceeding a junior analyst's effort.
Cost vs. human wageclaude-sonnet-54/5Generating a draft presentation via AI is far cheaper than a security analyst spending hours researching and formatting, though human review adds some cost back.
Technical feasibility todayclaude-haiku-4-5-202510012/5No production systems demonstrably create comprehensive threat intelligence presentations autonomously; tools exist for data visualization and summarization, but real presentations demand custom threat modeling, validated intelligence curation, and narrative coherence that deployed products do not reliably achieve.
Technical feasibility todayclaude-sonnet-53/5Tools like ChatGPT, Copilot, and specialized threat-intel platforms with AI summarization are used in production to draft reports and slides, but outputs need review for accuracy and relevance.

Gather cyber intelligence to identify vulnerabilities.

37

CI 2550 · exposure 38 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5While information-security sectors digitize quickly, actual automation of pentesting lags. Most organizations still rely on human-led security assessment services; automated scanning is deployed as a complement, not replacement. Adoption of fully autonomous pentesting remains in early pilot phases.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately fast-adopting sector with many AI-assisted tools in pilot or production use for recon and vulnerability discovery, though full automation of the judgment-heavy synthesis step lags.
Augmentation potentialclaude-haiku-4-5-202510014/5AI-powered vulnerability scanning, exploit databases, and reporting tools substantially assist human testers, accelerating reconnaissance and helping prioritize findings. Testers use these tools routinely to amplify their productivity while maintaining control over strategy, exploitation decisions, and business-risk assessment.
Augmentation potentialclaude-sonnet-54/5AI significantly accelerates OSINT collection, vulnerability database correlation, and initial triage, letting testers cover more ground and focus expertise on higher-value analysis and exploitation planning.
Task automatabilityclaude-haiku-4-5-202510012/5Vulnerability scanning and some reconnaissance can be automated with existing tools, but meaningful penetration testing requires human judgment to interpret findings, understand business context, and craft sophisticated attack chains. Current AI cannot reliably replicate the creative problem-solving and adaptive tactics needed to achieve a 50% time savings at equal quality end-to-end.
Task automatabilityclaude-sonnet-53/5AI tools can automate reconnaissance, OSINT gathering, and vulnerability scanning aggregation, but synthesizing findings into an actionable threat picture still requires human judgment and contextual analysis of the specific target environment.
Adoption barriersclaude-haiku-4-5-202510014/5Penetration testing carries high legal and liability barriers: contracts must explicitly authorize testing, unauthorized access remains illegal, and organizations often require certified professionals (OSCP, CEH) to conduct or sign off on results. Client accountability and regulatory compliance (HIPAA, PCI-DSS) typically mandate human expert involvement.
Adoption barriersclaude-sonnet-53/5No strict licensing requirement for intelligence gathering itself, but engagements require authorization, contracts, and liability considerations, and clients often expect human-vetted results before acting on findings.
Cost vs. human wageclaude-haiku-4-5-202510012/5Vulnerability scanning tools are relatively cheap, but a full penetration test combines automated scanning with expensive human expertise. Total cost per engagement remains comparable to or higher than hiring skilled testers, especially when factoring in oversight and remediation guidance.
Cost vs. human wageclaude-sonnet-53/5Automated scanning and OSINT tools reduce time spent on repetitive reconnaissance significantly, but human analysts are still needed for validation, target-specific tuning, and correlation, keeping costs roughly comparable when factoring in oversight.
Technical feasibility todayclaude-haiku-4-5-202510012/5Deployed security tools (Nessus, Rapid7, Burp) automate parts of vulnerability scanning, but they struggle with manual testing, social engineering, and nuanced exploitation that defines professional pentesting. No production system fully performs this complex task reliably without significant human expert oversight.
Technical feasibility todayclaude-sonnet-53/5Deployed products (automated OSINT scrapers, vulnerability scanners, AI-assisted recon tools like AI-enhanced Shodan/Nmap wrappers) exist and are used in practice, but they have material false-positive rates and narrow scope compared to full intelligence gathering workflows.

Write audit reports to communicate technical and procedural findings and recommend solutions.

37

CI 2550 · exposure 38 · augmentation 63 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Cybersecurity and penetration testing remain relatively conservative sectors with strong emphasis on human expertise and accountability. While AI-assisted drafting tools are emerging, adoption of autonomous or near-autonomous report generation remains limited; most firms retain tight human control over audit output.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity firms are professional-services oriented and increasingly pilot AI-assisted reporting tools, but widespread production deployment for full report authorship remains limited.
Augmentation potentialclaude-haiku-4-5-202510013/5AI can usefully assist penetration testers by drafting report sections, suggesting risk framings, improving clarity, and helping organize findings—raising writing productivity. However, the human must still validate technical accuracy, assess business context, and make final recommendations, so augmentation is moderate rather than transformative.
Augmentation potentialclaude-sonnet-54/5AI substantially speeds up drafting, summarizing findings, and suggesting remediation language, letting testers focus on validation and client-specific judgment.
Task automatabilityclaude-haiku-4-5-202510012/5Writing audit reports requires synthesizing complex technical findings into clear recommendations tailored to organizational context and stakeholder needs. While AI can draft sections and improve clarity, the task demands nuanced judgment about risk severity, business impact, and solution appropriateness that currently requires substantial human direction and validation.
Task automatabilityclaude-sonnet-53/5AI can draft substantial portions of audit reports from structured findings, but synthesizing technical nuance, prioritizing risk, and tailoring recommendations to organizational context still requires significant human review and editing.imensional judgment.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.rewrites.review.finalize.iteration.
Adoption barriersclaude-haiku-4-5-202510014/5Regulatory frameworks (SOC 2, ISO 27001, compliance standards) and contractual obligations often require reports to be reviewed and signed by licensed or certified security professionals. Client expectations and liability concerns create strong organizational resistance to autonomous or minimally-supervised AI report generation.
Adoption barriersclaude-sonnet-53/5No licensing mandate requires a human signatory in most jurisdictions, but liability for missed vulnerabilities and client trust in certified professionals creates real friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI writing assistance costs less than the human labor to write reports from scratch, but the value is limited because AI outputs typically require substantial expert review, correction, and rewriting. The net cost savings remain modest compared to a skilled penetration tester's fully loaded rate, especially factoring in oversight burden.
Cost vs. human wageclaude-sonnet-53/5AI drafting reduces time on boilerplate and formatting, but the need for expert review of security findings keeps overall cost savings moderate rather than order-of-magnitude.
Technical feasibility todayclaude-haiku-4-5-202510012/5No deployed product reliably generates complete, production-ready penetration test audit reports end-to-end. AI writing tools can assist with drafting, but they lack the domain expertise to independently assess findings, prioritize vulnerabilities, and formulate business-aligned recommendations without expert human oversight and significant revisions.
Technical feasibility todayclaude-sonnet-53/5Several cybersecurity platforms and LLM-based tools generate draft pentest report sections, but human experts still validate technical accuracy and craft final recommendations before delivery to clients.

Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.

34

CI 3136 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security teams use automated scanning widely, but the evaluation and judgment phases remain heavily manual. Adoption of AI for the full assessment task is slow; many organizations still prefer human pentester involvement for compliance and liability reasons, though tool-assisted workflows are standard.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately fast-adopting sector for AI copilots and automated scanning, though full evaluative judgment tasks remain in pilot/augmentation stages rather than fully deployed replacement.
Augmentation potentialclaude-haiku-4-5-202510014/5AI-powered scanning and prioritization tools significantly assist human penetration testers by rapidly generating and filtering vulnerability reports, highlighting high-risk findings, and correlating weaknesses. This materially increases tester productivity while keeping the human in the loop for validation and decision-making.
Augmentation potentialclaude-sonnet-54/5AI significantly aids by correlating scan data, prioritizing vulnerabilities, and drafting reports, meaningfully speeding up analyst workflows while humans retain final evaluative responsibility.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist in scanning and identifying known vulnerabilities, evaluating assessments requires contextual judgment about business criticality, risk tolerance, and remediation prioritization that demands human expertise. Current AI systems lack the nuanced understanding of complex network architectures and the ability to synthesize findings into actionable recommendations at scale.
Task automatabilityclaude-sonnet-52/5AI tools can scan and flag known vulnerabilities but evaluating assessments requires contextual judgment about business risk, exploitability, and false positives that current systems cannot reliably automate end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Penetration testing is heavily regulated in many sectors (financial services, healthcare, defense) and often requires authorized personnel or third-party certifications (CEH, OSCP). Liability for missed critical vulnerabilities and the need for human accountability in security decisions create strong organizational and legal barriers to full automation.
Adoption barriersclaude-sonnet-53/5No strict licensing requirement for pentesters generally, but organizational risk tolerance, liability for missed vulnerabilities, and compliance frameworks (e.g., PCI-DSS) create meaningful friction against pure automation.
Cost vs. human wageclaude-haiku-4-5-202510013/5Automated vulnerability scanners are inexpensive to run, but the labor cost of a human penetration tester evaluating and validating results remains substantial. The all-in cost of AI tools plus human oversight approaches parity with full human execution.
Cost vs. human wageclaude-sonnet-53/5AI-assisted scanning reduces some labor costs, but the evaluative and judgment-heavy portions still require skilled human oversight, keeping overall cost roughly comparable to fully human-driven processes.
Technical feasibility todayclaude-haiku-4-5-202510012/5Vulnerability scanning tools exist and can detect known issues, but AI systems today cannot reliably perform the full evaluation task—interpreting results, assessing false positives, contextualizing findings within an organization's infrastructure, and making prioritization decisions. Deployed products handle narrow sub-tasks but not end-to-end evaluation with human-level reliability.
Technical feasibility todayclaude-sonnet-52/5Vulnerability scanners and AI-assisted triage tools exist and are used in production, but evaluation of assessments—synthesizing findings into prioritized, actionable judgments—still relies heavily on human analysts.

Identify new threat tactics, techniques, or procedures used by cyber threat actors.

32

CI 2838 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Enterprise security teams are adopting AI-assisted threat detection at moderate pace (SOCs increasingly use ML-based anomaly detection), but the identification of *new* tactics remains a human-led, expert-driven function with AI playing a supporting role rather than driving displacement.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a fast-moving, digitized field with growing AI-assisted threat intelligence tools, but mission-critical novel-threat identification still sees cautious, partial adoption rather than full production deployment.
Augmentation potentialclaude-haiku-4-5-202510014/5AI significantly augments threat hunters and pentesters by surfacing anomalies, clustering similar events, and suggesting indicators of compromise, enabling analysts to focus creative effort on validation and new tactic classification—a clear productivity multiplier within a human-led workflow.
Augmentation potentialclaude-sonnet-54/5AI substantially aids analysts by summarizing threat feeds, correlating IOCs, and flagging anomalies for review, meaningfully speeding up the process even though the final identification requires human expertise.
Task automatabilityclaude-haiku-4-5-202510012/5AI can assist in pattern recognition within threat data and flagging suspicious indicators, but identifying truly novel tactics requires adversarial thinking, contextual understanding of attacker motivation, and validation against real-world evidence—tasks that remain difficult for current systems without substantial human oversight and judgment.
Task automatabilityclaude-sonnet-52/5Identifying genuinely novel adversary TTPs requires synthesizing weak signals from threat intel, forums, malware analysis and intuition about attacker creativity; AI can assist but cannot reliably discover truly new tactics end-to-end today.
Adoption barriersclaude-haiku-4-5-202510014/5Strong organizational and regulatory barriers exist: firms rely on human security experts for liability protection, compliance (SOC2, ISO27001), and insurance; regulators expect licensed or certified personnel to own threat identification; false positives in novel-threat detection carry high business risk.
Adoption barriersclaude-sonnet-52/5No licensing requirement dictates a human must do this, but organizational trust, liability for missed threats, and the specialized judgment involved create moderate friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI-assisted threat detection has high infrastructure and integration costs (security tools, data pipelines, analyst time for validation), making it comparably expensive or more expensive than employing skilled penetration testers who combine automation with human insight.
Cost vs. human wageclaude-sonnet-52/5AI can cheaply process large volumes of logs and OSINT, but the human validation and interpretation needed to confirm a 'new' tactic still requires expensive skilled analyst time, keeping overall cost comparable to human-led work.
Technical feasibility todayclaude-haiku-4-5-202510012/5While SIEM systems and threat intelligence platforms exist, they primarily detect known signatures and IoCs rather than identifying genuinely new tactics; current AI products struggle reliably with novel, zero-day, or sophisticated attacker innovations without expert validation.
Technical feasibility todayclaude-sonnet-52/5Some threat intel platforms use AI/ML for anomaly detection and pattern clustering, but genuine novel TTP discovery still depends heavily on human analyst review; no deployed product autonomously identifies new attacker techniques reliably.

Update corporate policies to improve cyber security.

31

CI 2536 · exposure 25 · augmentation 63 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Cybersecurity and policy development remain heavily human-driven, even in digitally mature organizations. While AI-assisted drafting tools are emerging, actual production deployment of autonomous policy generation is rare; most organizations still rely on human experts and consultants for policy authoring.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity and professional/tech sectors are adopting AI assistance at a moderate-to-fast pace for drafting and analysis tasks, though governance/policy work lags technical security tasks.
Augmentation potentialclaude-haiku-4-5-202510013/5Current AI can usefully augment penetration testers by suggesting policy language, identifying compliance gaps, or generating initial drafts for human review and refinement. However, the assistance is partial rather than transformative, as the core judgment and decision-making authority remains with the human expert.
Augmentation potentialclaude-sonnet-54/5AI can meaningfully speed up drafting, benchmarking against frameworks, and summarizing gaps, giving penetration testers or security staff a strong productivity boost while they retain judgment and approval authority.
Task automatabilityclaude-haiku-4-5-202510012/5This task requires deep understanding of organizational risk posture, threat landscape, legal/compliance context, and strategic judgment about acceptable security trade-offs. While AI can draft policy language or suggest improvements, end-to-end policy creation meeting the 50% time-saving threshold demands human expertise in threat modeling, business alignment, and organizational context that current systems cannot reliably provide independently.
Task automatabilityclaude-sonnet-52/5Drafting policy language can be AI-assisted, but updating corporate cybersecurity policy requires synthesizing organizational context, risk appetite, legal/regulatory requirements, and stakeholder buy-in that AI cannot reliably do end-to-end today.
Adoption barriersclaude-haiku-4-5-202510014/5Strong organizational and liability barriers apply: security policies typically require sign-off by senior leadership, legal counsel, and compliance officers; errors carry material risk (breach liability, regulatory violations); and decision-making authority is vested in humans with fiduciary responsibility. These governance requirements create high friction against full automation.
Adoption barriersclaude-sonnet-53/5No licensing requirement to write policy, but organizational approval chains, legal review, and executive sign-off create real friction against pure automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5Penetration testers command high specialist wages (~$100k+), and the cost of errors in security policy is severe. AI assistance tools are relatively inexpensive but cannot yet replace the full workflow; the all-in cost of AI + required human oversight/revision remains comparable to direct human expertise.
Cost vs. human wageclaude-sonnet-53/5AI drafting assistance is cheap compared to senior security staff time, but the overall task still requires substantial human review, negotiation, and approval that keeps blended costs comparable.
Technical feasibility todayclaude-haiku-4-5-202510012/5No production systems demonstrably perform comprehensive corporate policy updates autonomously. AI tools can assist with drafting or compliance checking, but deployed products lack the domain expertise and organizational knowledge required to independently author policies that meaningfully improve security posture with acceptable error rates.
Technical feasibility todayclaude-sonnet-52/5LLM tools can generate draft policy text or checklists against frameworks like NIST/ISO, but no deployed product autonomously identifies gaps and pushes through organizational policy updates reliably.

Identify security system weaknesses, using penetration tests.

30

CI 2832 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security and financial services sectors are actively experimenting with AI-assisted tools for vulnerability scanning and triage, but human-led penetration testing remains the norm. Adoption of AI-only testing is rare; most deployments augment rather than replace testers, indicating middling adoption velocity for automation.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a tech-forward field adopting AI tools for scanning and triage at a moderate pace, but full agentic pentesting remains largely in pilot/early-adoption stages rather than widespread production use.
Augmentation potentialclaude-haiku-4-5-202510014/5AI systems demonstrably assist penetration testers by accelerating vulnerability scanning, generating payloads, analyzing logs, and identifying attack paths—all while the human retains judgment over strategy, scope, and liability. This augmentation significantly raises a testers's productivity on reconnaissance and routine scans.
Augmentation potentialclaude-sonnet-54/5AI significantly boosts pentesters' productivity by automating reconnaissance, generating exploit code suggestions, and triaging scan results, while humans remain essential for strategy, validation, and reporting.
Task automatabilityclaude-haiku-4-5-202510012/5AI can assist with some penetration testing components (vulnerability scanning, payloads, log analysis) but cannot independently devise novel attack strategies, adapt to novel defenses, or make contextual judgments about what weaknesses matter in a specific environment. The 50% time-saving threshold requires end-to-end execution at equal quality, which is not achievable today.
Task automatabilityclaude-sonnet-52/5AI can assist with scanning, fuzzing, and identifying known vulnerability patterns, but full penetration testing requires creative attack chaining, business-context judgment, and adaptive exploitation that current systems cannot reliably perform end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Penetration testing is heavily regulated (contractual authorization required, legal liability for access/damage, industry compliance frameworks like PCI-DSS, SOC 2), and clients typically require a qualified, credentialed human to sign off on findings and assume liability. The legal and contractual obligation for human authorization creates substantial barriers to full automation.
Adoption barriersclaude-sonnet-53/5While not formally licensed everywhere, penetration testing often requires signed authorization, contractual liability coverage, and client trust in human expertise, creating moderate organizational and legal friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5Current AI-assisted security tools reduce time on routine scanning and preliminary reconnaissance, but a penetration tester's loaded cost remains low relative to the specialized expertise required and the liability attached to findings. Full automation would require perfect accuracy, which AI has not yet achieved, making integrated cost still comparable to or higher than expert labor.
Cost vs. human wageclaude-sonnet-52/5AI tools can cheaply automate reconnaissance and basic vulnerability scanning, but comprehensive penetration testing still requires expensive skilled human oversight to validate findings and avoid costly false negatives, keeping overall cost comparable to human-led engagements.
Technical feasibility todayclaude-haiku-4-5-202510012/5Several tools (e.g., Burp Suite, Nessus, AI-enhanced scanners) exist and are deployed in security teams, but they handle narrow, well-defined subtasks (standard vulnerability detection, fuzzing). No deployed product independently conducts a full penetration test with the creativity and judgment required for novel or sophisticated environments.
Technical feasibility todayclaude-sonnet-52/5AI-assisted vulnerability scanners and some autonomous pentest agents exist commercially, but they are narrow, produce false positives/negatives, and are typically deployed as aids alongside human testers rather than standalone reliable pentest solutions.

Collect stakeholder data to evaluate risk and to develop mitigation strategies.

29

CI 2532 · exposure 25 · augmentation 63 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Security and penetration testing sectors remain conservative in automation adoption due to high liability costs, regulatory constraints, and the requirement for human accountability; most firms use AI only for preliminary analysis support rather than autonomous decision-making.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity and professional services are moderately fast adopters of AI tools for drafting and analysis, but the stakeholder-facing elicitation portion of this task sees slower, more cautious adoption.
Augmentation potentialclaude-haiku-4-5-202510013/5AI can usefully assist with data aggregation, stakeholder survey distribution, document analysis, and preliminary risk categorization, helping penetration testers work faster, though the human expert remains essential for judgment calls and strategy formulation.
Augmentation potentialclaude-sonnet-54/5AI can strongly assist by summarizing prior assessments, drafting risk questionnaires, synthesizing stakeholder input, and helping structure mitigation strategies, meaningfully boosting analyst productivity while humans remain in the loop.
Task automatabilityclaude-haiku-4-5-202510012/5Collecting raw stakeholder data (surveys, interviews, documentation) has some automatable components (parsing documents, aggregating structured responses), but evaluating risk and developing mitigation strategies require human judgment, contextual understanding, and stakeholder engagement that current AI cannot reliably perform end-to-end at 50% time savings with equal quality.
Task automatabilityclaude-sonnet-52/5Gathering stakeholder input involves interviews, reading organizational context, and judgment about business priorities that current AI cannot reliably substitute for end-to-end, though it can assist with parts like summarizing documents.5, however the core elicitation and trust-building with humans limits full automation.
Adoption barriersclaude-haiku-4-5-202510014/5Penetration testing is heavily regulated (compliance requirements, contractual obligations, liability for false positives/negatives), and risk evaluation typically requires a certified human professional to sign off on findings and mitigation strategies for legal and organizational accountability.
Adoption barriersclaude-sonnet-53/5While not licensed work, stakeholder trust, organizational politics, and confidentiality concerns create friction against full AI substitution, and clients often expect direct human engagement for risk discussions.
Cost vs. human wageclaude-haiku-4-5-202510012/5The cost of deploying AI for data collection plus necessary human validation, interpretation, and strategy formulation remains comparable to or higher than a skilled penetration tester performing the task directly, given the low-volume, high-stakes nature of security risk assessment.
Cost vs. human wageclaude-sonnet-52/5Human analysts still must conduct interviews and interpret organizational nuance, so AI tools reduce some documentation time but don't yet displace most of the labor cost involved.
Technical feasibility todayclaude-haiku-4-5-202510012/5While AI can assist with data aggregation and initial analysis, no deployed product reliably performs the full cycle of stakeholder data collection, risk evaluation, and mitigation strategy development without significant human oversight and domain expertise.
Technical feasibility todayclaude-sonnet-52/5No deployed product autonomously collects stakeholder risk data and develops mitigation strategies in production; existing tools support analysts but don't replace the human-driven stakeholder engagement process.

Configure information systems to incorporate principles of least functionality and least access.

29

CI 2532 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Penetration testing and security configuration remain concentrated in specialized, conservative teams with high barriers to automation adoption. While security tools proliferate, the actual configuration of least-privilege postures is still primarily driven by certified professionals in controlled, risk-averse environments where displacement is minimal.
Sector adoption velocityclaude-sonnet-53/5Security and IT operations are adopting AI-assisted tooling (e.g., policy-as-code, automated hardening suggestions) at a moderate pace, with pilots common but full autonomous deployment still limited.
Augmentation potentialclaude-haiku-4-5-202510014/5AI can substantially augment penetration testers by generating candidate configurations, highlighting security mismatches, automating compliance checks, and surfacing risky deviations from security baselines—enabling the tester to focus judgment on context-specific decisions. AI-driven scanning and suggestion tools demonstrably increase tester productivity while humans retain final authority over security posture.
Augmentation potentialclaude-sonnet-54/5AI can generate configuration templates, flag overly permissive settings, and suggest least-privilege policies, significantly speeding up the analyst's implementation work while they retain final control.
Task automatabilityclaude-haiku-4-5-202510012/5This task requires deep architectural judgment about system-specific security trade-offs between functionality and access control, decisions that depend on business requirements and threat modeling that vary per organization. While AI can help generate configuration templates or suggest settings, it cannot reliably determine the correct least-functionality posture for a particular system without extensive human expertise and context.
Task automatabilityclaude-sonnet-52/5This requires understanding system architecture, business needs, and risk tolerance to configure specific access controls and services, which AI can assist with but not fully execute without human judgment on trade-offs.-not fully automatable end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Strong regulatory and liability barriers protect this task: misconfiguration can expose systems to breach, and the penetration tester typically bears or shares responsibility for security outcomes. Organizations and compliance frameworks (SOX, HIPAA, PCI-DSS) typically require qualified human sign-off on security configurations, and error costs are asymmetrically high.
Adoption barriersclaude-sonnet-53/5No strict licensing requirement for this specific task, but organizational risk aversion, change management processes, and liability for misconfiguration create meaningful friction against pure automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI-assisted configuration tools are emerging but remain significantly more expensive than their time savings when accounting for the expert oversight required to validate security decisions. A skilled penetration tester's judgment, once applied, is more cost-effective than the iterative refinement and validation that AI-generated configurations demand.
Cost vs. human wageclaude-sonnet-52/5Configuration work still requires skilled human oversight to validate changes don't break functionality or introduce risk, so AI assistance reduces but doesn't eliminate the dominant labor cost.
Technical feasibility todayclaude-haiku-4-5-202510012/5No deployed AI product reliably performs end-to-end system configuration for least privilege across heterogeneous environments at production quality. Tools exist to scan configurations and suggest hardening, but they require significant human validation and domain knowledge to apply safely, and cannot independently determine organizational security requirements.
Technical feasibility todayclaude-sonnet-52/5Some tools offer configuration recommendations or hardening scripts, but no mature product autonomously configures production systems for least functionality/access across diverse environments reliably.

Design security solutions to address known device vulnerabilities.

29

CI 2532 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Penetration testing and security architecture remain human-centric, specialized fields with high organizational friction. AI-driven vulnerability scanning is adopted, but design and remediation architecture still depend on expert review; adoption of autonomous design remains minimal.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately digitized, tech-forward field with growing AI tool adoption, but production-level full automation of solution design remains limited to pilots and augmented workflows.
Augmentation potentialclaude-haiku-4-5-202510014/5AI tools meaningfully augment security professionals by automating vulnerability discovery, suggesting mitigations, and analyzing attack surfaces, freeing experts to focus on complex architectural decisions and business-critical trade-offs. This assistance is broadly deployable and raises productivity.
Augmentation potentialclaude-sonnet-54/5AI tools substantially help testers by suggesting mitigations, referencing vulnerability databases, and drafting remediation plans, meaningfully speeding up the design process while humans finalize decisions.
Task automatabilityclaude-haiku-4-5-202510012/5Designing security solutions requires domain expertise, contextual judgment, and understanding of organizational risk tolerance. While AI can assist in vulnerability analysis and suggest patches, end-to-end solution design—including trade-offs, integration, and business alignment—remains heavily dependent on human expertise and cannot achieve 50% time savings at equal quality today.
Task automatabilityclaude-sonnet-52/5Designing security solutions requires contextual judgment about system architecture, business risk tolerance, and tradeoffs that AI cannot yet fully replicate end-to-end; AI can draft options but a human must validate and tailor them.ed
Adoption barriersclaude-haiku-4-5-202510014/5Security solution design often requires licensed professionals (CISSP, CEH) and must comply with industry standards (ISO 27001, NIST), liability frameworks, and organizational governance. Regulatory and accountability requirements create strong friction against full automation or substitution.
Adoption barriersclaude-sonnet-53/5No licensing mandate for this specific design step, but liability for security failures and organizational risk-aversion create meaningful friction against fully automated designs.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI tools (vulnerability scanners, code analysis) reduce some analytical overhead but cannot replace the expert judgment of penetration testers in solution design. Overhead from oversight, integration, and human validation likely makes AI assistance cost-comparable to or more expensive than direct human work for this task.
Cost vs. human wageclaude-sonnet-52/5AI can cut research time but the design still requires senior security engineer review and integration effort, keeping costs comparable to or only modestly cheaper than human-only work.
Technical feasibility todayclaude-haiku-4-5-202510012/5No deployed AI product reliably designs complete security solutions independently. Existing tools can identify vulnerabilities and recommend mitigations, but they lack the architectural reasoning, organizational context, and accountability required for production security decisions.
Technical feasibility todayclaude-sonnet-52/5Some AI-assisted vulnerability scanners and remediation suggestion tools exist, but no deployed product reliably designs comprehensive, context-specific security solutions without expert oversight.

Develop infiltration tests that exploit device vulnerabilities.

29

CI 2532 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security teams widely adopt vulnerability scanning and SAST tools, but infiltration testing itself remains a specialist, human-led function. Adoption of AI-assisted testing is growing in enterprise security but has not reached deep, production-scale displacement of penetration testers.
Sector adoption velocityclaude-sonnet-52/5Security testing is a specialized, high-stakes technical field where AI tool adoption is growing but still largely pilot-stage; most firms rely on human-led methodologies with AI as a minor assistive layer.
Augmentation potentialclaude-haiku-4-5-202510014/5AI significantly assists penetration testers by automating reconnaissance, vulnerability enumeration, payload generation, and result analysis. These augmentations measurably increase a tester's coverage and speed, even though the tester remains the decision-maker and validator throughout the engagement.
Augmentation potentialclaude-sonnet-54/5AI significantly aids reconnaissance, vulnerability research, payload generation, and report drafting, meaningfully speeding up a skilled tester's workflow even though the human designs and validates the actual exploit strategy.
Task automatabilityclaude-haiku-4-5-202510012/5Identifying and exploiting device vulnerabilities requires deep contextual knowledge, creative problem-solving, and understanding of target-specific security architectures. While AI can assist in vulnerability scanning and payload generation, designing coherent infiltration strategies that adapt to specific defenses remains largely human-dependent.
Task automatabilityclaude-sonnet-52/5AI can help identify known vulnerabilities and suggest exploits, but crafting novel infiltration tests against specific device configurations requires creative chaining, environment-specific adaptation, and validation that current AI cannot reliably do end-to-end without expert oversight.
Adoption barriersclaude-haiku-4-5-202510014/5Penetration testing is heavily regulated; authorization, contractual liability, and legal compliance requirements mandate human accountability and sign-off. Industry standards and client contracts typically require credentialed humans to conduct and vouch for test results.
Adoption barriersclaude-sonnet-53/5No licensing mandate universally requires a human, but liability for damaging production systems, client trust requirements, and certification expectations (e.g., OSCP) create meaningful organizational friction against pure automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI tools (SAST/DAST platforms, vulnerability scanners) reduce initial scanning costs but cannot replace the skilled penetration tester's reasoning. Integration, validation, and bespoke exploit development remain labor-intensive, keeping total cost comparable to or higher than human specialists.
Cost vs. human wageclaude-sonnet-52/5AI tools can cheaply scan for known CVEs, but developing genuine exploit chains still requires skilled human testers for validation and customization, keeping all-in cost comparable to or only modestly below human-only costs.
Technical feasibility todayclaude-haiku-4-5-202510012/5Current AI tools can identify known vulnerabilities and generate basic exploit code, but no deployed product reliably designs and executes full infiltration test campaigns end-to-end. Most production systems require human testers to orchestrate, customize, and interpret results.
Technical feasibility todayclaude-sonnet-52/5Some AI-assisted vulnerability scanners and exploit suggestion tools exist (e.g., AI-augmented fuzzers, Metasploit integrations), but no deployed product autonomously develops and executes reliable infiltration tests across diverse device types in production.

Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.

29

CI 2532 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Adoption of full automation is slow because penetration testing is a high-stakes, judgment-driven activity in regulated industries. While automated tools are widely used to assist testers, meaningful displacement of skilled penetration testers remains limited; the sector continues to rely on human expertise for complex engagements.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a digitized, fast-moving field with growing AI tool adoption (AI-augmented scanners, copilot-style assistants), but full autonomous pentesting agents remain in pilot/early-adopter stages rather than widespread production use.
Augmentation potentialclaude-haiku-4-5-202510014/5AI-powered security tools (vulnerability scanners, SIEM analysis, automated payload generation, report generation) significantly augment penetration testers today, helping them prioritize targets, document findings, and accelerate routine tasks while the human remains responsible for strategy, complex chaining, and sign-off.
Augmentation potentialclaude-sonnet-54/5AI significantly boosts productivity by automating reconnaissance, vulnerability correlation, payload generation, and report drafting, letting human testers focus on complex exploitation and validation.
Task automatabilityclaude-haiku-4-5-202510012/5Some components like vulnerability scanning, exploit delivery, and network mapping can be partially automated, but the creative problem-solving, social engineering, payload customization, and contextual judgment required for realistic penetration testing remain largely outside current AI capabilities. A human penetration tester would still save significant time and effort.
Task automatabilityclaude-sonnet-52/5AI can automate reconnaissance, scanning, and some exploit chaining, but creative chaining of vulnerabilities, business-logic flaws, and adapting to bespoke environments still require significant human expertise, so full end-to-end automation at equal quality is not yet reliable.
Adoption barriersclaude-haiku-4-5-202510014/5Legal and contractual barriers are substantial: penetration testing often requires explicit written authorization to avoid prosecution, liability for damages from unauthorized access attempts is severe, and many jurisdictions impose licensing or certification expectations. Organizations typically require certified humans to sign off on the scope and findings.
Adoption barriersclaude-sonnet-53/5Many engagements require signed authorization (rules of engagement), contractual liability, and sometimes certified professionals (e.g., for compliance audits like PCI-DSS), creating moderate legal/organizational barriers to full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5Penetration testing requires specialized expertise commanding high hourly rates ($150–300+). Automated tooling is inexpensive but cannot replace the judgment and creativity of a skilled tester, making the all-in cost of AI-only solutions economically unfavorable compared to a human.
Cost vs. human wageclaude-sonnet-52/5Automated scanning tools are cheap, but a credible pentest still requires expensive skilled oversight, report writing, and validation to avoid false positives/negatives, keeping overall cost comparable to human-led work.
Technical feasibility todayclaude-haiku-4-5-202510012/5While automated security tools (scanners, fuzzers, exploit frameworks) exist in production, they handle routine checks only. Current AI systems cannot reliably execute a full end-to-end penetration test that requires adapting to novel system architectures, chaining exploits creatively, or simulating sophisticated attack chains without human oversight.
Technical feasibility todayclaude-sonnet-52/5AI-assisted tools (automated scanners, LLM-guided exploit suggestion agents) exist but are used as aids within human-led engagements rather than independently performing full penetration tests reliably in production.

Develop and execute tests that simulate the techniques of known cyber threat actors.

28

CI 2432 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Cybersecurity firms and enterprises are adopting automated scanning and AI-assisted tools in pilots and limited production (vulnerability scans, payload generation), but full-cycle penetration testing remains human-led. Adoption is middling—tools augment rather than displace.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a fast-adopting technical sector using AI for threat intel and automation, but full adoption of AI-driven autonomous penetration testing remains in pilot/early production stages due to trust and accuracy concerns.
Augmentation potentialclaude-haiku-4-5-202510014/5AI tools substantially enhance penetration testers' productivity by automating reconnaissance, generating payloads, identifying common vulnerabilities, and parsing logs. These assistive technologies materially increase a human penetration tester's scope and speed while they retain control over strategy and risk assessment.
Augmentation potentialclaude-sonnet-54/5AI significantly aids penetration testers by automating reconnaissance, generating attack scripts, summarizing vulnerabilities, and suggesting exploit chains, meaningfully increasing productivity while humans retain strategic control.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can generate some payloads and scan for vulnerabilities, penetration testing requires deep contextual judgment, social engineering, and adaptive decision-making based on defensive responses. Current AI systems cannot autonomously execute a full adversarial campaign with the creativity and legal/ethical judgment required, and no end-to-end automation achieves 50% time savings at equal quality.
Task automatabilityclaude-sonnet-52/5AI can automate certain scanning, reconnaissance, and script-generation steps but crafting and executing realistic multi-stage attack simulations mimicking specific threat actor TTPs still requires substantial human judgment, adaptation, and creativity to bypass unique defenses.
Adoption barriersclaude-haiku-4-5-202510014/5Strong barriers exist: penetration testing often requires explicit legal authorization, client contracts typically mandate human accountability for findings, regulatory compliance (SOC 2, PCI-DSS audits) requires certified professionals to sign off, and legal liability for false negatives or unintended damage strongly incentivizes human judgment and accountability.
Adoption barriersclaude-sonnet-53/5While not licensed like law or medicine, penetration testing often requires certifications (OSCP, CEH), signed authorization/rules of engagement, and legal liability for unauthorized access, creating moderate barriers to full automation.
Cost vs. human wageclaude-haiku-4-5-202510011/5Penetration testers command high salaries ($100k+) due to specialized expertise. Current AI tooling does not reduce per-engagement cost below expert human labor when accounting for required oversight, remediation of false positives, and liability exposure.
Cost vs. human wageclaude-sonnet-52/5Tooling and AI assistance can reduce some labor costs, but liability, need for skilled interpretation, and client trust requirements keep human oversight costs high, keeping overall cost roughly comparable rather than dramatically cheaper.
Technical feasibility todayclaude-haiku-4-5-202510012/5Products exist for automated vulnerability scanning and payload generation, but they operate narrowly and require heavy human oversight. Deployed penetration testing remains primarily human-driven; automated tools serve as assistants rather than end-to-end replacements for test design and execution against realistic threat modeling.
Technical feasibility todayclaude-sonnet-52/5AI-assisted tools (e.g., automated recon, exploit suggestion, fuzzing) exist and are used in production, but full autonomous execution of realistic adversary emulation campaigns is still rare and mostly research/pilot stage with human pentesters in the loop.

Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.

28

CI 2828 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security organizations are adopting AI-assisted SIEM and threat detection tools at a middling pace, with pilots widespread but autonomous incident investigation rare; human-led investigation remains the norm in production environments despite interest in automation.
Sector adoption velocityclaude-sonnet-53/5Security operations centers in tech/finance sectors are adopting AI-assisted detection and triage tools at a moderate pace, but deep, autonomous forensic investigation adoption remains uneven and mostly pilot-stage.
Augmentation potentialclaude-haiku-4-5-202510014/5AI substantially augments incident investigators through automated log analysis, malware behavior flagging, pattern correlation across datasets, and rapid triage—freeing analysts to focus on complex root cause analysis and evidence synthesis while the human retains full investigative control.
Augmentation potentialclaude-sonnet-54/5AI significantly accelerates malware analysis, log correlation, and anomaly detection, giving investigators strong productivity gains while they retain responsibility for root-cause conclusions and reporting.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist with some components (malware signature matching, log analysis, pattern detection), investigating security incidents requires complex judgment, contextual reasoning, and adaptive response to novel attack vectors that current systems struggle with end-to-end. The human must synthesize evidence, make tactical decisions, and pivot strategies—tasks where AI support is partial rather than substitutional.
Task automatabilityclaude-sonnet-52/5Incident investigation requires piecing together ambiguous evidence, hypothesis generation, and judgment calls that current AI can assist but not reliably complete end-to-end at equal quality across diverse incidents.
Adoption barriersclaude-haiku-4-5-202510014/5Strong barriers exist: incidents often involve legal/compliance obligations that require certified human sign-off, liability for missed threats or false conclusions falls on the organization, and regulatory frameworks (SOC 2, HIPAA breach reporting) mandate human responsibility and attestation in incident response.
Adoption barriersclaude-sonnet-54/5Forensic findings often feed legal, compliance, or breach-disclosure processes requiring certified/licensed professionals and defensible chain-of-custody, creating strong institutional and liability barriers to full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5High-quality incident investigation requires specialized human expertise and careful analysis; AI tools reduce time on routine triage but do not yet match the cost efficiency of human investigation at equivalent depth and accuracy, especially for sophisticated incidents.
Cost vs. human wageclaude-sonnet-52/5AI tools reduce some log-parsing and initial triage costs, but complex investigations still require expensive analyst oversight, verification, and legal/chain-of-custody rigor, keeping all-in costs comparable to human-led work.
Technical feasibility todayclaude-haiku-4-5-202510012/5Deployed products exist for isolated subtasks (SIEM analysis, malware scanning, log parsing) but no production system reliably performs full incident investigation autonomously. Real incidents demand novel problem-solving, adversarial reasoning, and integration of multiple forensic streams that exceed current AI reliability in operational settings.
Technical feasibility todayclaude-sonnet-52/5Some SOC/XDR products offer AI-assisted triage and automated log correlation, but full forensic investigations combining network, host, and malware analysis still rely heavily on skilled human analysts in production.

Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.

27

CI 2132 · exposure 25 · augmentation 75 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Adoption is uneven and slow despite being an information-sector task. Many organizations still conduct penetration testing via retained human consultants or specialized firms rather than deploying autonomous AI agents, and the highly regulated nature of security work limits rapid substitution.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately digitized, fast-moving field with growing AI tool adoption for reconnaissance and scripting, but full process design remains human-led with pilots more common than production-scale automation.
Augmentation potentialclaude-haiku-4-5-202510014/5AI tools significantly assist penetration testers by automating reconnaissance, vulnerability scanning, report generation, and payload crafting, substantially raising analyst productivity. The human expert remains in the loop to design strategy, interpret results, and manage client relationships, making augmentation a strong current reality.
Augmentation potentialclaude-sonnet-54/5AI can meaningfully assist by suggesting methodologies, generating checklists, summarizing best practices, and drafting test plans, significantly speeding up a human expert's process development work.
Task automatabilityclaude-haiku-4-5-202510012/5Penetration testing involves complex judgment, creativity in attack vectors, and real-time adaptation to novel security postures. While AI can assist with reconnaissance and vulnerability scanning, the core task of developing novel testing processes and deciding attack strategies remains heavily dependent on human expertise and cannot be reliably automated end-to-end at the 50% time-saving threshold.
Task automatabilityclaude-sonnet-52/5Designing testing processes requires deep judgment about organizational context, threat models, and creative attack chaining that current AI cannot reliably originate end-to-end.assistive drafting is possible but full process design isn't yet at the 50% time-saving-equal-quality bar.
Adoption barriersclaude-haiku-4-5-202510014/5Legal authorization and liability constraints are substantial: penetration testing often requires explicit written contracts, client authorization, and professional certification (OSCP, CEH, etc.). Regulatory frameworks (CFAA, GDPR, industry compliance) and the high cost of false positives or unintended harm create strong legal and organizational barriers to full automation.
Adoption barriersclaude-sonnet-53/5No strict licensing mandates a human specifically design the process, but liability, client trust, and certification expectations (e.g., OSCP-certified testers) create meaningful organizational friction against pure automation.
Cost vs. human wageclaude-haiku-4-5-202510011/5Penetration testers command high hourly rates ($150–$300+) due to specialized expertise and liability risk. AI tools for scanning and reconnaissance add infrastructure costs but do not yet substitute for the strategic development of testing processes, making the all-in cost of AI solutions comparable to or exceeding the human wage.
Cost vs. human wageclaude-sonnet-52/5Because human expert oversight and validation remain essential, AI only reduces some drafting time; the all-in cost including required human review is not dramatically cheaper than a skilled tester's time.
Technical feasibility todayclaude-haiku-4-5-202510012/5No deployed product reliably develops penetration testing processes autonomously. Tools like automated vulnerability scanners and OSINT gatherers exist, but developing entire testing methodologies—especially for wireless, data networks, and telecom—requires human judgment and cannot be substituted by off-the-shelf systems in production environments.
Technical feasibility todayclaude-sonnet-52/5Some AI-assisted tools exist to suggest test plans or checklists, but no deployed product autonomously develops comprehensive, validated pentesting methodologies across wireless, network, and telecom domains in production.

Discuss security solutions with information technology teams or management.

23

CI 1432 · exposure 17 · augmentation 63 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510011/5Security practices remain highly regulated and risk-averse; stakeholder discussions are rarely automated, and there is minimal evidence of penetration testing firms deploying AI agents to lead security consultations with client management.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity and IT sectors are moderately fast adopters of AI tools for drafting and analysis, but interpersonal advisory discussions remain largely human-led with pilots only for support tasks.
Augmentation potentialclaude-haiku-4-5-202510013/5AI can usefully assist penetration testers by drafting presentation materials, summarizing technical findings, suggesting communication strategies, or generating risk analyses that the human then refines and delivers, raising efficiency without removing the human from the discussion itself.
Augmentation potentialclaude-sonnet-54/5AI can significantly aid by summarizing vulnerabilities, drafting reports, and suggesting remediation options that inform the human-led discussion, boosting preparation efficiency.
Task automatabilityclaude-haiku-4-5-202510011/5This task fundamentally requires persuasive communication, stakeholder judgment, and nuanced understanding of organizational context and risk tolerance. Current AI cannot reliably conduct the interactive, adaptive dialogue and credibility-building necessary for discussing technical solutions with teams and management.
Task automatabilityclaude-sonnet-52/5This is a live, contextual discussion requiring judgment, negotiation, and organizational knowledge; AI can prepare talking points but cannot conduct the interactive discussion itself end-to-end.dev
Adoption barriersclaude-haiku-4-5-202510014/5Organizations strongly prefer human security professionals for security discussions due to liability concerns, the need for accountability, professional responsibility, and the requirement that recommendations be backed by an accountable expert who can be held liable for errors or oversights.
Adoption barriersclaude-sonnet-53/5No strict licensing barrier, but organizational trust, accountability for security decisions, and need for human judgment in cross-team communication create moderate friction.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI can assist with preparation (drafting talking points, analyses), but the core discussion requires a skilled penetration tester whose loaded hourly rate and credibility are difficult to replace cost-effectively with current AI inference and oversight.
Cost vs. human wageclaude-sonnet-52/5Human discussion time is still required for real-time dialogue, so AI mainly reduces prep time rather than replacing the interaction cost, limiting savings compared to human wage.
Technical feasibility todayclaude-haiku-4-5-202510012/5While AI can draft security recommendations and summarize findings, no deployed product reliably conducts real-time discussions that incorporate live feedback, stakeholder concerns, and organizational politics. Tools exist for report generation but not for the interactive consultation aspect.
Technical feasibility todayclaude-sonnet-52/5Chatbots and copilots can summarize findings or draft recommendations, but no deployed product autonomously conducts stakeholder security discussions in production today.

Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.

11

CI 516 · exposure 8 · augmentation 25 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Adoption remains slow because most organizations still rely on human penetration testers for physical security assessments, and regulatory/contractual requirements often mandate human judgment and accountability. Only advanced tech/finance firms pilot robotic or semi-autonomous approaches, and these remain exceptions rather than industry standard.
Sector adoption velocityclaude-sonnet-51/5Physical security assessment is an inherently manual, low-digitization task within penetration testing, with no meaningful AI-driven displacement occurring in this specific niche.
Augmentation potentialclaude-haiku-4-5-202510012/5AI can assist by processing photographs for thermal analysis or structural anomaly detection, or by pre-filtering environmental data, but the human tester's expertise in context, risk judgment, and real-time adaptation remains central. Current tools offer marginal productivity lift rather than transformative assistance.
Augmentation potentialclaude-sonnet-52/5AI can help generate checklists, analyze photos, or draft reports summarizing findings, but it offers limited assistance for the core physical inspection and judgment work.
Task automatabilityclaude-haiku-4-5-202510012/5Physical security assessment requires on-site presence, judgment about environmental conditions, and interpretation of spatial layouts that current AI cannot perform end-to-end. While AI might assist in analyzing photos or environmental data post-collection, the core assessment—walking facilities, observing vulnerabilities, and integrating multi-sensory inputs—remains heavily human-dependent.
Task automatabilityclaude-sonnet-51/5This requires physically visiting facilities, inspecting server rooms, testing locks, checking environmental controls, and assessing tangible vulnerabilities—no current AI can perform this physical inspection.-based work.
Adoption barriersclaude-haiku-4-5-202510014/5Physical penetration testing typically requires explicit authorization, site access credentials, and legal liability agreements between the tester and organization. Many facilities restrict autonomous or remote-operated devices in sensitive areas, and human sign-off is often contractually required for compliance and security purposes.
Adoption barriersclaude-sonnet-54/5Physical security assessments often require site access authorization, liability considerations, and professional judgment about real-world risks, creating strong practical barriers to any remote/automated substitute.
Cost vs. human wageclaude-haiku-4-5-202510011/5The cost of deploying mobile robotic systems with environmental sensors to conduct physical security assessments across varied facilities far exceeds the cost of sending trained human penetration testers, especially when accounting for integration, site-specific setup, and liability insurance.
Cost vs. human wageclaude-sonnet-51/5AI cannot substitute for physical presence, so there is no viable AI cost comparison—human inspectors remain the only option.
Technical feasibility todayclaude-haiku-4-5-202510011/5No deployed product performs autonomous physical facility security assessment. The task requires embodied presence (robots exist for specific inspection but not general penetration testing assessment), real-time environmental sensing, and security clearance awareness that production systems do not reliably handle at scale.
Technical feasibility todayclaude-sonnet-51/5No deployed AI product conducts physical security assessments of data centers or equipment; this remains a manual, on-site inspection task.

Related occupations — Computer & Mathematical

How to read this

A high substitution score does not mean this job disappears — it means a large share of its current tasks face replacement pressure, so the mix of tasks is likely to change. High augmentation alongside substitution typically means the occupation reorganizes around the protected tasks. Wide confidence intervals mean the rater panel disagreed: treat those scores as open questions, not verdicts.

What would change this score

New model capabilities (automatability, feasibility), falling inference costs (cost ratio), regulation and licensing shifts (barriers), and measured sector adoption (velocity) all re-enter at every index release. Each release is recomputed, versioned and kept queryable — scores are claims with a date on them, not permanent labels.