Information Security Engineers

15-1299.05
Median wage $116,580/yr435,370 employed (US)Rank #216 of 923 scored · top 23% by substitution

Develop and oversee the implementation of information security procedures and policies. Build, maintain and upgrade security technology, such as firewalls, for the safe use of computer networks and the transmission and retrieval of information. Design and implement appropriate security controls to identify vulnerabilities and protect digital files and electronic infrastructures. Monitor and respond to computer security breaches, viruses, and intrusions, and perform forensic investigation. May oversee the assessment of information security systems.

Sub-scores

0–100 · band = confidence interval from rater disagreement

Substitution38
Exposure35
Augmentation77

Substitution — the headline: capability discounted by cost, barriers and adoption.

Exposure — technical capability alone, regardless of whether anyone deploys it.

Augmentation — how much AI assists without replacing. High here + moderate substitution = a changing job, not a disappearing one.

Tasks on the substitution scale

20 rated tasks, binned by substitution score.

Position among all scored occupations

Distribution of 923 occupation scores; the marker is this occupation.

Tasks with substitution ≥ 70

5%

Run 1.0.0-draft.1 · computed 2026-08-05 · rater panel: claude-sonnet-5, claude-haiku-4-5-20251001 · intervals span rater disagreement.

Why this score

The five weighted dimensions of the composite, averaged across this occupation's tasks (importance-weighted, panel mean). Exact weights and formulas: /api/v1/methodology.

Task automatabilityw 35%33

panel mean rating 2.3/5 → substitution pressure 33/100

Technical feasibility todayw 20%38

panel mean rating 2.5/5 → substitution pressure 38/100

Cost vs. human wagew 15%36

panel mean rating 2.4/5 → substitution pressure 36/100

Adoption barriersw 20%inverted — strong barriers lower the score40

panel mean rating 3.4/5 (barrier strength) → substitution pressure 40/100

Sector adoption velocityw 10%51

panel mean rating 3.0/5 → substitution pressure 51/100

Task breakdown (20 tasks)

Substitution pressure per task, weighted by O*NET importance in the composite. Expand a task for the full rater audit trail — every rating, every model, every rationale.

Scan networks, using vulnerability assessment tools to identify vulnerabilities.

85

CI 8486 · exposure 84 · augmentation 88 · importance 4.3/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510015/5Vulnerability scanning automation is deeply embedded in modern information security and DevSecOps practices across financial, tech, healthcare, and critical infrastructure sectors, with continuous scanning now standard in many enterprises.
Sector adoption velocityclaude-sonnet-54/5Cybersecurity is a fast-adopting, digitized field where automated scanning has been standard practice for over a decade across most mature organizations.
Augmentation potentialclaude-haiku-4-5-202510014/5AI-powered vulnerability scanners augment security engineers significantly by automating the discovery phase, flag prioritization, and threat correlation, allowing humans to focus on analysis and remediation rather than running scans and parsing raw results.
Augmentation potentialclaude-sonnet-55/5AI-enhanced scanning and prioritization tools significantly boost engineer productivity by surfacing, triaging, and contextualizing vulnerabilities faster than manual review, while humans retain judgment over remediation.
Task automatabilityclaude-haiku-4-5-202510014/5Vulnerability scanning itself is highly automatable—current tools like Nessus, OpenVAS, and Qualys can be deployed end-to-end to identify network weaknesses with minimal human intervention, easily exceeding 50% time savings. However, interpreting results, prioritizing findings, and determining remediation strategy still typically require human expertise, preventing a full 5.
Task automatabilityclaude-sonnet-54/5Vulnerability scanning is largely mechanical and automated tools (Nessus, Qualys, OpenVAS, etc.) already run scans and generate reports with minimal human intervention, meeting the time-saving threshold for the scanning portion itself, though interpretation and remediation planning remain human-led.'
Adoption barriersclaude-haiku-4-5-202510012/5Few hard regulatory or legal barriers prevent automated scanning; however, organizational friction exists (IT sign-off, change management, customer communication policies) and the sensitivity of security testing may require human authorization before deployment in some contexts.
Adoption barriersclaude-sonnet-52/5No licensing mandates a human perform the scan itself, though compliance frameworks (PCI-DSS, etc.) often require human-certified interpretation or sign-off on results, creating minor procedural friction.
Cost vs. human wageclaude-haiku-4-5-202510015/5Automated vulnerability scanning costs (SaaS subscriptions + infrastructure) are typically one to two orders of magnitude cheaper than the loaded cost of employing security engineers to manually probe networks, even accounting for oversight and tuning overhead.
Cost vs. human wageclaude-sonnet-55/5Automated scanning tools cost a small licensing/subscription fee compared to the labor cost of manually probing networks, making automation dramatically cheaper per scan cycle.
Technical feasibility todayclaude-haiku-4-5-202510015/5Mature, production-grade vulnerability scanning tools are ubiquitously deployed across enterprises and security operations today. Products like Nessus, Qualys, and cloud-native scanners reliably perform this task at scale with well-understood accuracy and false-positive rates.
Technical feasibility todayclaude-sonnet-55/5Mature commercial and open-source vulnerability scanners are deployed at scale in production environments across virtually all industries today, performing automated scans reliably and continuously.

Review security assessments for computing environments or check for compliance with cybersecurity standards and regulations.

60

CI 5070 · exposure 62 · augmentation 88 · importance 3.8/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510014/5Information security and financial/cloud-native organizations are rapidly deploying automated compliance scanning and vulnerability assessment tools in production. Adoption is deep in digitized sectors, though conservative legacy environments lag.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity and IT sectors show above-average digitization and growing GRC tool adoption, but many compliance review processes remain manual or semi-automated with AI pilots rather than full production deployment.
Augmentation potentialclaude-haiku-4-5-202510015/5AI-powered security tools dramatically augment human engineers by continuously monitoring environments, surfacing anomalies, and pre-filtering findings—allowing engineers to focus on investigation, decision-making, and remediation rather than manual scanning and routine compliance checks.
Augmentation potentialclaude-sonnet-54/5AI substantially aids compliance reviewers by rapidly cross-referencing controls, summarizing gaps, and drafting audit documentation, meaningfully increasing throughput while humans retain final judgment.
Task automatabilityclaude-haiku-4-5-202510014/5AI systems can automatically scan computing environments, flag deviations from cybersecurity standards, and generate compliance reports with high consistency. While human judgment on complex risk trade-offs and novel threat patterns remains valuable, the core review and checking work—comparing configs to baselines, identifying missing patches, verifying policy adherence—can achieve >50% time savings at equal quality with current tools.
Task automatabilityclaude-sonnet-53/5AI can review assessments against known frameworks (NIST, ISO 27001) and flag gaps or compliance issues, but final judgment on risk acceptance and nuanced organizational context still requires human expertise, so only partial time savings are realized end-to-end.
Adoption barriersclaude-haiku-4-5-202510013/5Regulatory frameworks (SOC 2, HIPAA, PCI-DSS) often require documented human review and sign-off, creating organizational friction. Liability concerns and the need for expert human judgment on remediation decisions introduce meaningful but not absolute barriers to full automation.
Adoption barriersclaude-sonnet-53/5No strict licensing mandate for this specific review task, but regulatory frameworks (e.g., PCI-DSS, HIPAA, SOC2) often require qualified personnel attestation, and liability for missed compliance issues creates moderate friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510014/5Automated scanning and compliance checking infrastructure costs are typically one-tenth or less of hiring and deploying a dedicated security engineer for the same coverage, especially at scale. Infrastructure and oversight costs are low relative to loaded engineer wages.
Cost vs. human wageclaude-sonnet-53/5AI-assisted compliance tools reduce review time significantly but still require licensed/experienced security engineers for oversight and sign-off, keeping costs roughly comparable rather than order-of-magnitude cheaper.
Technical feasibility todayclaude-haiku-4-5-202510014/5Deployed products (vulnerability scanners, compliance automation tools, SIEM systems with automated rule engines) reliably perform large portions of this task in production across enterprises. Limitations exist for nuanced context assessment and novel attack vectors, but standard compliance checking and environment scanning are mature and widely used.
Technical feasibility todayclaude-sonnet-53/5Compliance automation and GRC tools with AI features exist in production (e.g., automated control mapping, policy gap analysis) but still require human validation and have notable false positive/negative rates on complex environments.

Develop information security standards and best practices.

47

CI 3262 · exposure 45 · augmentation 88 · importance 3.9/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security teams are beginning to pilot AI for policy drafting and baseline generation, but most organizations still require human security architects to own standards development; production-scale autonomous generation remains uncommon.
Sector adoption velocityclaude-sonnet-53/5Information security is a digitized, fast-moving field with growing AI tool adoption for drafting and research, but authoritative standard-setting still largely involves human-led committees and review cycles.
Augmentation potentialclaude-haiku-4-5-202510015/5AI assistants substantially accelerate standards development by generating initial drafts, regulatory mapping, and threat-aligned recommendations, allowing security engineers to focus on validation, customization, and strategic governance—a high-impact augmentation pattern already seeing real adoption.
Augmentation potentialclaude-sonnet-54/5AI can significantly speed up drafting, benchmarking against frameworks (NIST, ISO), and summarizing best practices, meaningfully boosting analyst productivity while humans retain final judgment.
Task automatabilityclaude-haiku-4-5-202510014/5AI can draft comprehensive security standards by synthesizing regulatory frameworks, threat intelligence, and industry best practices, achieving significant time savings on the bulk composition and structure. However, final validation and strategic judgment on organization-specific risk posture typically require human expert review, preventing full 5-level automation.
Task automatabilityclaude-sonnet-52/5Drafting standards requires synthesizing organizational risk context, regulatory requirements, and business constraints that AI cannot fully originate autonomously, though it can help draft sections; full end-to-end automation with equal quality is not yet achievable.
Adoption barriersclaude-haiku-4-5-202510013/5While no hard legal requirement mandates a licensed human author standards, organizational liability concerns, compliance auditor expectations, and the need for expert sign-off on risk-critical policies create meaningful friction that prevents outright substitution.
Adoption barriersclaude-sonnet-53/5No licensing requirement mandates a human sign-off, but organizational accountability, compliance audits, and liability for security failures create meaningful friction against fully automating standard-setting.
Cost vs. human wageclaude-haiku-4-5-202510014/5AI inference and integration costs for generating policy documents are substantially lower than senior security engineer labor (typically $150k–$250k+ loaded), with minimal overhead for prompt engineering and review cycles.
Cost vs. human wageclaude-sonnet-52/5While AI can cheaply generate draft text, the human expert time needed for validation, contextualization, and stakeholder alignment remains substantial, keeping overall cost savings modest.
Technical feasibility todayclaude-haiku-4-5-202510013/5Products exist (LLMs, policy-generation tools) that can generate credible security standards drafts, but deployed systems still show material gaps in regulatory alignment, context awareness, and specificity to organizational threat models. Reliability remains mixed without human oversight.
Technical feasibility todayclaude-sonnet-52/5AI tools (e.g., LLM-based drafting assistants) can produce policy templates and boilerplate language, but no deployed product reliably generates organization-specific security standards without heavy human review and customization.

Write reports regarding investigations of information security breaches or network evaluations.

46

CI 3062 · exposure 50 · augmentation 88 · importance 3.7/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Information security remains a highly regulated, liability-sensitive domain where organizations retain human experts and resist full automation of investigative reporting. Adoption is limited to assistive drafting in pilot programs rather than end-to-end replacement in production.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity and IT sectors are moderately fast adopters of AI tooling (SOC copilots, threat-detection AI), but report-writing specifically is still mostly augmentative rather than fully deployed in production workflows.
Augmentation potentialclaude-haiku-4-5-202510014/5AI can significantly assist by auto-generating report structure, summarizing technical logs, flagging patterns, and drafting initial text that engineers then validate and refine. This raises productivity without removing the security engineer from the investigation loop.
Augmentation potentialclaude-sonnet-55/5AI is highly effective at drafting, summarizing findings, structuring narrative sections, and improving clarity and speed of report writing while the security engineer retains responsibility for verifying facts and conclusions.
Task automatabilityclaude-haiku-4-5-202510012/5AI can draft sections of breach reports (timelines, technical findings summaries) but cannot independently investigate, validate evidence, or make forensic conclusions. Human security experts must conduct the investigation and verify all claims, limiting time savings to <50% for a complete, defensible report.
Task automatabilityclaude-sonnet-54/5Drafting structured incident reports and network evaluation summaries from logs, ticket data, and findings is well-suited to LLMs, which can generate coherent narrative text and executive summaries with substantial time savings, though a human must verify technical accuracy and sensitive conclusions.
Adoption barriersclaude-haiku-4-5-202510014/5Regulatory frameworks (GDPR, HIPAA, SEC, etc.) often require human expert certification and sworn attestation of breach findings. Liability asymmetry is extreme—false or incomplete breach reports expose organizations to legal jeopardy, creating strong incentive for human accountability and authorization.
Adoption barriersclaude-sonnet-53/5No licensing requirement mandates a human write the report, but liability for inaccurate security findings, confidentiality of breach details, and organizational sign-off requirements create moderate friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI can reduce drafting overhead, but security breach reporting requires licensed or experienced human sign-off, and the cost of errors (liability, regulatory fines) means human oversight remains the dominant cost component. All-in cost remains comparable to or higher than human-only workflow.
Cost vs. human wageclaude-sonnet-54/5Generating a draft report via AI costs a fraction of an engineer's hourly rate, even accounting for the human review and editing time needed to finalize a technically accurate report.
Technical feasibility todayclaude-haiku-4-5-202510013/5AI writing assistants and template-based report generators exist in security workflows, but they typically handle formatting and boilerplate; no deployed system reliably produces investigation-grade breach reports without substantial human review and rework of technical conclusions.
Technical feasibility todayclaude-sonnet-53/5AI writing assistants and SOC copilots (e.g., Microsoft Security Copilot, various SIEM-integrated tools) can draft incident summaries today, but adoption for final, authoritative security reports is still limited and requires heavy human review before deployment in production.

Provide technical support to computer users for installation and use of security products.

42

CI 3746 · exposure 34 · augmentation 75 · importance 3.4/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Tech and enterprise sectors have begun deploying AI-assisted support, but adoption remains mixed: many organizations still rely on human technical support teams. Pilots are common; production displacement remains moderate.
Sector adoption velocityclaude-sonnet-53/5IT/security functions are moderately fast adopters of AI-assisted support tools (chatbots, ticket triage), though full automation of hands-on security support remains limited in production.
Augmentation potentialclaude-haiku-4-5-202510014/5AI excels at augmenting support engineers by providing instant access to documentation, suggesting solutions, drafting responses, and handling ticket triage, allowing humans to focus on complex troubleshooting and customer rapport. This represents meaningful productivity gain while the human remains in control.
Augmentation potentialclaude-sonnet-54/5AI assistants can significantly speed up diagnosis, generate step-by-step guides, and draft responses for common security product issues, meaningfully boosting support engineer productivity.
Task automatabilityclaude-haiku-4-5-202510012/5Most of this task requires human judgment in troubleshooting, understanding user context, and tailoring explanations to individual technical levels. While AI can handle routine script execution and documentation lookup, the interactive problem-solving with variable user contexts and non-standard configurations resists full automation.
Task automatabilityclaude-sonnet-52/5Hands-on troubleshooting and installation of security software on diverse user systems requires physical access, environment-specific diagnosis, and interactive back-and-forth that current AI cannot fully replace end-to-end.
Adoption barriersclaude-haiku-4-5-202510013/5Some organizations have liability concerns about automating security product support without human verification, and users often prefer human contact for security-sensitive issues. Regulatory and organizational friction exist but are not absolute legal bars to deployment.
Adoption barriersclaude-sonnet-52/5No licensing requirement, but some organizational risk aversion exists since security misconfigurations have significant liability and error costs, warranting human oversight for many issues.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI-powered support chatbots have low inference costs but require significant integration, customization to security products, and ongoing human oversight for escalations and complex cases. The all-in cost approaches or sometimes exceeds junior technical support labor, especially when factoring oversight.
Cost vs. human wageclaude-sonnet-53/5AI-driven tier-1 support reduces ticket volume cheaply, but complex security support still requires skilled engineer time, keeping overall cost roughly comparable once escalations are factored in.
Technical feasibility todayclaude-haiku-4-5-202510013/5Chatbots and AI assistants can answer common installation questions and provide basic support today, but deployed products struggle with complex troubleshooting, unusual system configurations, and the adaptability required for diverse user needs. Production systems exist but with material limitations.
Technical feasibility todayclaude-sonnet-53/5AI chatbots and IT helpdesk assistants exist and handle common installation/configuration queries in production, but complex or edge-case security product issues still need escalation to human engineers.

Assess the quality of security controls, using performance indicators.

39

CI 2850 · exposure 38 · augmentation 75 · importance 4.4/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security firms are adopting automated control monitoring and analytics tools widely, but human-led assessment remains the norm; pilots of autonomous assessment are common but full production replacement is not yet prevalent in most organizations.
Sector adoption velocityclaude-sonnet-53/5Information security is a digitized, fast-moving sector with growing AI tool adoption (e.g., AI-driven SOC tools), but pilots for full autonomous control assessment remain more common than mature deployment.
Augmentation potentialclaude-haiku-4-5-202510014/5AI tools (automated metrics collection, anomaly detection, compliance gap analysis) substantially augment security engineers by handling data aggregation and flagging control drift, allowing engineers to focus on contextual judgment and remediation strategy while staying firmly in the loop.
Augmentation potentialclaude-sonnet-54/5AI significantly aids by aggregating logs, flagging deviations, and suggesting metrics interpretation, greatly boosting analyst efficiency while humans retain final judgment.
Task automatabilityclaude-haiku-4-5-202510013/5AI can partially automate assessment of security controls by analyzing logs, metrics, and compliance data to evaluate performance indicators, but requires human judgment to contextualize findings, interpret policy alignment, and make risk decisions that determine control adequacy.
Task automatabilityclaude-sonnet-52/5Assessing security control quality requires contextual judgment about organizational risk, business impact, and interpreting metrics that AI can support but not independently perform end-to-end reliably.
Adoption barriersclaude-haiku-4-5-202510014/5Organizations face regulatory requirements (SOC 2, ISO 27001, HIPAA) that typically mandate human security professionals sign off on control assessments; liability and compliance frameworks create strong incentives to retain human judgment and accountability in quality evaluation.
Adoption barriersclaude-sonnet-53/5While not licensed like some professions, security assessments often require accountability, compliance sign-off, and organizational trust, creating moderate friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510013/5Automated security monitoring and control assessment tooling costs are now comparable to portions of a security engineer's wage for routine indicator analysis, but comprehensive assessment still requires expert validation, keeping overall cost near parity.
Cost vs. human wageclaude-sonnet-52/5AI tools can reduce data-gathering time but human security engineers still must interpret results and validate findings, keeping overall costs closer to comparable rather than order-of-magnitude cheaper.
Technical feasibility todayclaude-haiku-4-5-202510013/5Products exist (SIEM platforms, security analytics tools, automated compliance scanners) that perform components of this task at scale, but they typically flag metrics and anomalies rather than fully assess control quality; human interpretation remains standard practice.
Technical feasibility todayclaude-sonnet-52/5Some SIEM/GRC tools and AI-assisted analytics can surface performance indicators and flag anomalies, but no deployed product autonomously performs full control-quality assessments in production without expert review.

Develop or implement software tools to assist in the detection, prevention, and analysis of security threats.

37

CI 3242 · exposure 34 · augmentation 75 · importance 3.7/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security teams use AI-assisted analysis tools in pilots and testing, but production deployment of AI-generated security tools is cautious due to liability and trust concerns; adoption is faster in large, well-resourced information security operations but lags elsewhere.
Sector adoption velocityclaude-sonnet-53/5Information security and tech sectors are relatively fast adopters of AI-assisted coding and SOC copilots, though full tool development automation remains at the pilot stage rather than deep production use.
Augmentation potentialclaude-haiku-4-5-202510014/5AI significantly assists security engineers through code suggestion, threat pattern recognition, vulnerability scanning automation, and analysis acceleration; engineers remain in control but their productivity is materially enhanced on tool development and threat investigation.
Augmentation potentialclaude-sonnet-54/5AI coding assistants, threat intelligence summarization, and automated rule generation meaningfully speed up building and refining detection/prevention tools while engineers retain oversight and validation responsibilities.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist with threat detection and analysis (pattern matching, anomaly identification), developing and implementing security tools requires domain expertise, architectural decisions, integration with existing systems, and security validation that cannot be fully automated end-to-end with current systems at 50%+ time savings and equal quality.
Task automatabilityclaude-sonnet-52/5AI can help draft code snippets, scripts, or detection rules, but designing and validating robust security tools that handle novel threats and integrate with complex infrastructure still requires significant human architecture, testing, and domain judgment.
Adoption barriersclaude-haiku-4-5-202510014/5Security tool implementation is subject to regulatory oversight (SOC 2, HIPAA, PCI-DSS compliance), organizational risk assessment, and liability exposure; security decisions must be justified and auditable, creating strong friction against full automation.
Adoption barriersclaude-sonnet-52/5No licensing requirement mandates a human build security tools, but organizational risk aversion around security-critical code and the liability of flawed detection tools create moderate friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI code generation and threat analysis tools reduce engineering time on routine detection logic, but the complexity of security tool development, required testing, and human review keep total costs close to or exceeding specialized engineer wages.
Cost vs. human wageclaude-sonnet-52/5While AI can accelerate coding tasks, the overall tool development lifecycle—design, testing, validation against adversarial threats, integration—still demands substantial skilled engineer time, keeping costs closer to comparable than dramatically cheaper.
Technical feasibility todayclaude-haiku-4-5-202510013/5AI tools exist for threat detection and code analysis (e.g., SIEM assistants, static analysis), but they operate within narrow scopes and require significant human oversight; no end-to-end product reliably develops new security tools from scratch in production without substantial human direction.
Technical feasibility todayclaude-sonnet-53/5AI coding assistants and security copilots are deployed in production to help write detection rules, scripts, and threat analysis code, but they still require expert review and don't autonomously build complete security tooling.

Coordinate monitoring of networks or systems for security breaches or intrusions.

36

CI 3240 · exposure 34 · augmentation 88 · importance 4.4/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Mid-market and enterprise organizations are piloting AI-augmented SIEM and threat detection, but full automation of coordination remains rare; most deployments use AI as a triage tool requiring human analysts. Adoption is expanding but not yet at the velocity of other information-sector automations.
Sector adoption velocityclaude-sonnet-54/5Cybersecurity is a fast-adopting, highly digitized sector with widespread deployment of AI-driven SIEM, EDR, and XDR tools integrated into SOC workflows.
Augmentation potentialclaude-haiku-4-5-202510014/5AI-driven anomaly detection, alert enrichment, and threat scoring significantly amplify human analyst productivity by filtering noise and surfacing high-risk events. Security engineers use these tools to handle larger networks and respond faster while retaining investigative and decision authority.
Augmentation potentialclaude-sonnet-55/5AI significantly enhances this task by correlating logs, flagging anomalies, reducing alert fatigue, and prioritizing incidents, letting security engineers coordinate response more effectively.
Task automatabilityclaude-haiku-4-5-202510012/5AI can assist with anomaly detection and alert generation, but network security monitoring requires contextual judgment about threat severity, false positive filtering, and incident prioritization that humans currently must perform. Full end-to-end automation meeting the 50% time-saving threshold is not yet demonstrated.
Task automatabilityclaude-sonnet-52/5The task centers on 'coordinating' monitoring—an oversight and management function requiring judgment, escalation decisions, and cross-team communication that current AI cannot fully replace, though AI can automate underlying detection subtasks.
Adoption barriersclaude-haiku-4-5-202510014/5Regulatory compliance (SOC 2, ISO 27001, HIPAA, PCI-DSS) often requires documented human accountability for security decisions, and many organizations face liability asymmetry where missed breaches trigger breach notification laws. Customer trust and contractual obligations frequently mandate human security engineers in the loop.
Adoption barriersclaude-sonnet-53/5No licensing requirement mandates a human specifically, but liability for missed breaches, compliance/regulatory reporting obligations, and organizational trust in human judgment for incident coordination create meaningful friction.
Cost vs. human wageclaude-haiku-4-5-202510012/5Current AI monitoring solutions require significant infrastructure, tuning, and ongoing human analyst review to filter noise. The all-in cost of an AI system plus required human oversight approximates or may exceed the cost of dedicated human security engineers.
Cost vs. human wageclaude-sonnet-52/5AI-assisted monitoring tools reduce headcount needs somewhat, but licensing costs for enterprise security platforms plus required human oversight keep costs from being dramatically lower than a security engineer's time for coordination duties.
Technical feasibility todayclaude-haiku-4-5-202510013/5Security information and event management (SIEM) systems and AI-driven threat detection tools exist in production, but they generate substantial false positives and require human analysts to validate alerts and coordinate response. Deployed products perform parts of the monitoring reliably but not the full coordination task.
Technical feasibility todayclaude-sonnet-53/5SIEM/SOAR platforms with AI-driven anomaly detection and alert triage are widely deployed in production, but they still require human coordination, tuning, and escalation decisions, especially for complex or novel threats.

Coordinate documentation of computer security or emergency measure policies, procedures, or tests.

35

CI 2545 · exposure 33 · augmentation 75 · importance 3.7/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5Security-focused organizations remain cautious with AI automation in policy-critical domains; most adoption is limited to drafting assistance rather than autonomous coordination, reflecting slow production deployment in this risk-sensitive sector.
Sector adoption velocityclaude-sonnet-53/5Information security is a digitized, tech-forward field with growing AI tool adoption for documentation and compliance tasks, though coordination workflows remain largely manual in most organizations.
Augmentation potentialclaude-haiku-4-5-202510014/5AI can meaningfully assist by generating initial policy drafts, organizing documentation templates, flagging compliance gaps, and tracking version control—substantially raising a security engineer's drafting speed while they retain judgment on coordination and approval workflows.
Augmentation potentialclaude-sonnet-54/5AI significantly speeds up drafting, formatting, and updating policy and test documentation, letting security engineers focus on coordination, review, and judgment calls.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can draft and organize documentation, coordinating security policies requires judgment about organizational context, compliance requirements, and stakeholder input that current systems handle poorly. Meaningful automation would need human review and iteration at each step, falling short of the 50% time-saving threshold.
Task automatabilityclaude-sonnet-53/5AI can draft, organize, and update policy documentation and test procedures given source material, but coordinating input across stakeholders and verifying accuracy still requires human oversight, limiting full end-to-end automation.
Adoption barriersclaude-haiku-4-5-202510014/5Information security documentation often falls under regulatory and compliance requirements (SOC 2, ISO 27001, HIPAA, etc.) and liability concerns; human security engineers must typically sign off on policies, and organizational risk-aversion around security creates strong friction against full automation.
Adoption barriersclaude-sonnet-53/5Security and compliance documentation often requires sign-off by authorized personnel and audit trails, creating moderate organizational and regulatory friction against pure automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI-assisted drafting reduces initial documentation work, but the coordination function—scheduling reviews, reconciling stakeholder feedback, ensuring compliance—still requires human labor that dominates total cost, making the combined cost similar to or higher than human-only approaches.
Cost vs. human wageclaude-sonnet-53/5AI can cheaply generate drafts and templates, but the coordination, review, and validation work still requires paid human time, so overall cost savings are moderate rather than dramatic.
Technical feasibility todayclaude-haiku-4-5-202510012/5No deployed products reliably handle the full coordination task end-to-end; LLMs can assist with drafting but cannot independently coordinate across teams, validate policy alignment with standards, or ensure organizational consensus without significant human oversight.
Technical feasibility todayclaude-sonnet-52/5LLM tools are used to help draft security documentation, but no deployed product reliably 'coordinates' the cross-team process of gathering, validating, and finalizing security/emergency policy documentation at scale.

Coordinate vulnerability assessments or analysis of information security systems.

32

CI 2837 · exposure 30 · augmentation 75 · importance 3.8/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security teams widely use automated scanning tools, but coordination of assessments remains human-driven. Adoption is uneven: large enterprises integrate AI-assisted scanning into workflows, but end-to-end autonomous coordination is rare; most organizations remain in pilot or partial-automation phases.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity as a field has moderate AI tool adoption (automated scanning, some AI-assisted triage) but coordination and strategic oversight functions remain largely human-driven in most organizations.
Augmentation potentialclaude-haiku-4-5-202510014/5AI-powered vulnerability scanners, risk scoring, report generation, and remediation recommendations significantly amplify security engineer productivity by automating routine scanning and triaging, allowing engineers to focus on strategy and high-touch investigation. Assistive tools demonstrably improve speed and coverage when humans remain in the loop.
Augmentation potentialclaude-sonnet-54/5AI significantly aids vulnerability discovery, report generation, and prioritization scoring, meaningfully speeding up the work of security engineers who coordinate assessments.
Task automatabilityclaude-haiku-4-5-202510012/5Current AI can assist in scanning for known vulnerabilities and generating reports, but cannot autonomously design comprehensive assessment strategies, interpret complex business contexts, or make end-to-end risk trade-offs that meet the 50% time-saving threshold. Human expertise is still required for vulnerability prioritization, remediation planning, and validation.
Task automatabilityclaude-sonnet-52/5AI tools can run scans and flag known vulnerabilities, but 'coordinating' assessments involves scoping, prioritization, stakeholder communication, and judgment calls that current AI cannot fully own end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Vulnerability assessment and coordination often require licensed security certifications (CISSP, OSCP, CEH) and internal authorization; findings carry liability and must be signed off by qualified personnel. Regulatory frameworks (SOC 2, ISO 27001, PCI-DSS) typically mandate human expert judgment in assessment planning and validation.
Adoption barriersclaude-sonnet-53/5No licensing requirement mandates a human, but liability for missed vulnerabilities, compliance frameworks (PCI-DSS, SOC2), and organizational risk tolerance create meaningful friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5While scanning tools have low per-unit costs, the overhead of expert human review, false-positive filtering, and coordination of multi-stage assessments means total cost remains comparable to or slightly cheaper than human assessment, not orders of magnitude cheaper.
Cost vs. human wageclaude-sonnet-52/5Scanning tools are cheap per-scan, but the coordination task requires skilled human oversight, contextual risk assessment, and cross-team communication that keeps overall costs comparable to human-led processes.
Technical feasibility todayclaude-haiku-4-5-202510012/5Automated vulnerability scanners and SAST/DAST tools exist in production, but they generate high false-positive rates and require significant human triage and interpretation. No deployed system can coordinate a full vulnerability assessment independently; tools are aids within human-led workflows, not autonomous performers.
Technical feasibility todayclaude-sonnet-53/5Automated vulnerability scanners (Nessus, Qualys, AI-augmented SAST/DAST tools) are mature and widely deployed, but the coordination and interpretation layer still relies heavily on human security engineers.

Train staff on, and oversee the use of, information security standards, policies, and best practices.

32

CI 2836 · exposure 25 · augmentation 75 · importance 4.3/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security teams are moderately digitized and early-to-middle in AI adoption for content generation and anomaly detection, but actual displacement of training leadership and policy oversight has been limited; tools like LMS and SIEM are widespread, but human trainers and security officers remain central.
Sector adoption velocityclaude-sonnet-53/5IT/security functions in tech-forward firms are adopting AI-assisted training tools at a middling pace, with pilots for phishing simulation and content generation more common than full automation of oversight.
Augmentation potentialclaude-haiku-4-5-202510014/5AI assistants can significantly augment security engineers by generating policy drafts, creating training scenarios, automating compliance checklists, and summarizing staff assessment data—substantially raising their productivity in content and oversight preparation while the engineer retains judgment on organizational fit and enforcement.
Augmentation potentialclaude-sonnet-54/5AI substantially aids in creating training materials, simulating phishing attacks, and monitoring compliance logs, meaningfully boosting the efficiency of the human overseeing the task.
Task automatabilityclaude-haiku-4-5-202510012/5AI can help draft training materials and generate security policy documentation, but the core task—training staff on standards and overseeing compliance in real-world organizational contexts—requires understanding nuanced organizational culture, addressing employee questions, assessing comprehension, and adapting messaging. AI cannot reliably replace the supervisory and pedagogical judgment needed for meaningful adoption.
Task automatabilityclaude-sonnet-52/5AI can generate training materials and quizzes, but delivering staff training and ongoing oversight requires human judgment, authority, and interpersonal engagement that current AI cannot replicate end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Regulatory frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS) often require documented human accountability for security training and policy oversight; moreover, liability for security breaches attributable to inadequate training or lax enforcement creates organizational and legal barriers to full automation of the supervisory role.
Adoption barriersclaude-sonnet-53/5No licensing requirement to deliver security training, but organizational accountability, compliance sign-off, and human oversight expectations create moderate friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5Generating training templates and policy documents via AI is cheap, but the full task—delivering live training, measuring comprehension, enforcing policies, and handling exceptions—still requires human oversight. Cost parity is not achieved when human supervision dominates the actual value-delivery.
Cost vs. human wageclaude-sonnet-53/5AI-generated training content is cheap, but the oversight and enforcement component still requires human labor, making overall cost roughly comparable rather than dramatically cheaper.
Technical feasibility todayclaude-haiku-4-5-202510012/5While AI can generate training content and draft policy materials, no deployed product reliably delivers end-to-end staff training with genuine behavioral change, or comprehensive policy oversight in production. Current systems lack the contextual authority and interactive capability to oversee compliance at organizational scale.
Technical feasibility todayclaude-sonnet-52/5Products exist for security awareness content generation and simulated phishing tests, but no deployed system autonomously trains and oversees staff compliance with policies reliably.

Identify security system weaknesses, using penetration tests.

30

CI 2832 · exposure 25 · augmentation 75 · importance 4.6/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security teams increasingly use AI-powered vulnerability scanners and OSINT tools in workflows, but autonomous penetration testing remains rare in production. Adoption of AI assistance is growing, but replacing human testers remains limited due to legal and trust requirements.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a fast-moving tech sector with growing AI tool adoption for scanning and triage, but full automation of penetration testing remains in pilot/tool-assisted stages rather than widespread production replacement.
Augmentation potentialclaude-haiku-4-5-202510014/5AI significantly augments penetration testers through automated reconnaissance, vulnerability scanning, payload generation, and log analysis, allowing human testers to focus on sophisticated attack chains and business-context interpretation. This assistance materially raises tester productivity while keeping humans in control and accountable.
Augmentation potentialclaude-sonnet-54/5AI significantly aids penetration testers by automating reconnaissance, vulnerability scanning, and report generation, allowing human experts to focus on complex exploitation and validation.
Task automatabilityclaude-haiku-4-5-202510012/5Penetration testing requires creativity, contextual judgment, and social engineering that current AI systems cannot fully replicate end-to-end. While AI can assist with vulnerability scanning and some exploitation steps, human testers design attack strategies, interpret findings in business context, and adapt to novel defenses—activities that resist full automation today.
Task automatabilityclaude-sonnet-52/5AI tools can assist with scanning and some exploit suggestion, but full penetration testing requires creative attack chaining, contextual judgment, and adapting to unique environments that current AI cannot reliably do end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Penetration testing faces high legal and contractual barriers: explicit written authorization is required, liability for mistakes is severe (unauthorized access is a crime), and most clients contractually require licensed, accountable humans to perform and sign off on tests.
Adoption barriersclaude-sonnet-53/5While not strictly licensed in most jurisdictions, penetration testing often requires contractual authorization, liability considerations, and client trust in human-certified testers (e.g., OSCP, CEH), creating moderate friction.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI-assisted vulnerability scanning tools have low marginal cost, but comprehensive penetration testing still requires licensed security engineers ($100k+ loaded cost) to design, execute, and validate findings. AI reduces time on routine scanning but cannot yet replace the human cost of the full engagement.
Cost vs. human wageclaude-sonnet-52/5AI-assisted scanning tools can reduce some labor costs, but comprehensive penetration testing still requires expensive human expertise and oversight to avoid false positives/negatives and legal risk.
Technical feasibility todayclaude-haiku-4-5-202510012/5No mature product performs comprehensive penetration testing autonomously in production. Tools like vulnerability scanners and OSINT AI exist, but actual penetration testing requires human authorization, legal oversight, and nuanced decision-making about which attacks to execute—making independent AI deployment infeasible at scale.
Technical feasibility todayclaude-sonnet-52/5Deployed products include automated vulnerability scanners and some AI-assisted pentest tools, but they are narrow in scope and still require skilled human testers to interpret results and conduct real exploitation.

Conduct investigations of information security breaches to identify vulnerabilities and evaluate the damage.

30

CI 2832 · exposure 25 · augmentation 75 · importance 4.2/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Security organizations are adopting AI-assisted tools for detection and triage, but adoption of end-to-end automated investigation remains limited. Most deployments use AI for augmentation rather than replacement, with human-led investigation workflows still dominant.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a digitized, fast-moving field with growing AI-assisted SOC tooling, but full investigative automation remains at pilot/augmentation stage rather than deep production replacement.
Augmentation potentialclaude-haiku-4-5-202510014/5AI augments investigation significantly through automated log parsing, anomaly detection, threat correlation, and preliminary vulnerability scanning, materially accelerating human investigators' work. The human expert remains essential for judgment and accountability, but AI substantially raises investigator productivity.
Augmentation potentialclaude-sonnet-54/5AI significantly boosts investigator productivity by summarizing logs, correlating alerts, flagging anomalies, and drafting incident reports, while the human retains judgment over root cause and impact assessment.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist with log analysis, pattern detection, and initial triage of security breaches, the task requires significant human judgment to interpret context, evaluate business impact, and determine root causes. Current systems cannot reliably conduct end-to-end investigations meeting the 50% time-saving threshold without expert human oversight and decision-making.
Task automatabilityclaude-sonnet-52/5AI can assist with log analysis, anomaly detection, and pattern matching, but full breach investigation requires contextual judgment, correlation across disparate systems, and interpretation of ambiguous evidence that current AI cannot reliably do end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Legal and regulatory requirements (compliance reporting, chain of custody, forensic standards) often mandate human experts and documented accountability. Industry practice and liability concerns create strong organizational friction against full automation of breach investigations.
Adoption barriersclaude-sonnet-53/5No licensing requirement mandates a human specifically, but liability, chain-of-custody/forensic evidentiary standards, and organizational risk tolerance create meaningful friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5Security engineers command high salaries ($100k+), and current AI tooling still requires substantial human oversight, integration effort, and validation. The all-in cost of AI-assisted investigation approaches human labor costs rather than achieving significant savings due to expertise requirements.
Cost vs. human wageclaude-sonnet-52/5AI tools reduce some analyst hours (log triage, alert correlation) but the overall investigation still requires substantial skilled human time, so total cost savings are moderate rather than an order of magnitude.
Technical feasibility todayclaude-haiku-4-5-202510012/5Products exist for automated threat detection and log analysis (e.g., SIEM tools with ML), but they operate as assistants rather than autonomous investigators. Reliable end-to-end breach investigation requiring vulnerability assessment and damage evaluation remains dependent on skilled human analysts; no product performs this task reliably in production without significant human input.
Technical feasibility todayclaude-sonnet-52/5Deployed SIEM/SOAR tools with AI features exist and assist analysts, but no product autonomously conducts full breach investigations reliably; human security engineers still drive the process.

Identify or implement solutions to information security problems.

30

CI 2832 · exposure 25 · augmentation 75 · importance 3.9/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security organizations are actively piloting AI-assisted threat detection and vulnerability management, but production deployment of AI-driven security solution implementation remains limited. Adoption is faster in detection than in remediation.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a moderately fast-adopting tech-forward field with growing AI-assisted tooling (e.g., AI-driven threat detection), but full automation of solution design and implementation remains at the pilot stage in most organizations.
Augmentation potentialclaude-haiku-4-5-202510014/5AI substantially augments security engineers by automating log analysis, generating prioritized vulnerability reports, and suggesting remediation steps, allowing engineers to focus on strategic decisions and complex incidents. This human-in-the-loop assistance meaningfully raises productivity.
Augmentation potentialclaude-sonnet-54/5AI significantly augments this task by accelerating vulnerability identification, threat intelligence synthesis, and drafting remediation steps, while engineers retain responsibility for validation and implementation decisions.
Task automatabilityclaude-haiku-4-5-202510012/5Current AI can assist in identifying some security problems through pattern matching and detection (e.g., flagging anomalous logs), but implementing solutions at scale requires domain expertise, architectural judgment, and accountability that AI cannot reliably provide end-to-end. The task is too context-dependent and consequences-heavy for 50% time savings at equal quality with off-the-shelf systems.
Task automatabilityclaude-sonnet-52/5Diagnosing and implementing security solutions requires contextual judgment about specific systems, threat models, and business tradeoffs that current AI cannot reliably handle end-to-end; AI can assist with sub-parts like log analysis or patch suggestions but not the full identify-and-implement cycle.
Adoption barriersclaude-haiku-4-5-202510014/5Information security has strong regulatory and liability barriers: security decisions often fall under compliance regimes (SOC 2, HIPAA, PCI-DSS), and liability for a breach traceable to an AI-recommended misconfiguration creates asymmetric error costs. Organizations demand human accountability for security architecture and implementation choices.
Adoption barriersclaude-sonnet-53/5No strict licensing requirement for this task, but organizational risk tolerance, compliance frameworks, and liability for security failures create meaningful friction against fully automating decision-making and implementation.
Cost vs. human wageclaude-haiku-4-5-202510012/5Current security-focused AI tools (SIEM enhancement, vulnerability scanning) cost significant licensing and integration fees; combined with the human oversight required to validate and implement recommendations, all-in costs remain high relative to the specialized engineer wage.
Cost vs. human wageclaude-sonnet-52/5AI tools reduce some analyst time but still require expensive human security engineers to verify and implement solutions, so all-in cost savings versus a human engineer are modest rather than order-of-magnitude.
Technical feasibility todayclaude-haiku-4-5-202510012/5While security scanning and threat detection tools exist and are deployed, they identify problems more reliably than they implement solutions. Implementation requires deciding between competing architectures, testing, rollback planning, and stakeholder sign-off—areas where AI products remain immature and error-prone in production settings.
Technical feasibility todayclaude-sonnet-52/5Deployed security copilots and SIEM-integrated AI tools exist and help triage alerts or suggest fixes, but reliable autonomous identification and implementation of security solutions in production is narrow and error-prone, requiring human validation.

Recommend information security enhancements to management.

30

CI 2832 · exposure 25 · augmentation 75 · importance 3.9/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security is digitized and early-adopting of AI tools, but augmentation (AI-assisted recommendations reviewed by humans) is common, while displacement of the recommendation role itself remains rare in production environments.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a fast-adopting professional services-adjacent field with many AI-assisted tools (vulnerability scanners, threat intel summarization) in pilot and some production use, though full recommendation authorship remains human-led.
Augmentation potentialclaude-haiku-4-5-202510014/5AI excels at summarizing vulnerability data, mapping threat landscapes, and drafting initial recommendations, significantly boosting the speed and coverage of a security engineer's analysis while the engineer retains oversight and final judgment.
Augmentation potentialclaude-sonnet-54/5AI can significantly assist by analyzing logs, benchmarking against frameworks like NIST, drafting reports, and summarizing threat intelligence, substantially speeding up the engineer's preparation of recommendations.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can generate security recommendations based on vulnerability scans and threat intelligence, synthesizing contextual business constraints, legacy systems, and organizational risk appetite requires human judgment that current AI cannot reliably perform end-to-end with 50% time savings at equal quality.
Task automatabilityclaude-sonnet-52/5Recommending security enhancements requires synthesizing organizational context, risk tolerance, budget constraints, and political factors that AI cannot fully assess or own end-to-end today.think generate draft lists of recommendations but the judgment-heavy, context-specific synthesis and stakeholder-aware framing limits full automation.
Adoption barriersclaude-haiku-4-5-202510014/5Organizations are typically liable for the security recommendations they act on; recommending changes without a qualified human security engineer's sign-off creates legal and compliance risk, making human accountability a strong barrier to full automation.
Adoption barriersclaude-sonnet-53/5No strict licensing requirement mandates a human make these recommendations, but liability, trust, and organizational accountability structures create meaningful friction against fully AI-generated advice reaching management unchecked.
Cost vs. human wageclaude-haiku-4-5-202510012/5Current AI tools (vulnerability scanners with recommendation engines, LLMs for drafting) are still cheaper per task than senior security engineers, but the output quality gap means human engineers must substantially rework and validate recommendations, reducing the effective cost advantage.
Cost vs. human wageclaude-sonnet-52/5While AI-assisted drafting is cheap, the human security engineer's contextual analysis, stakeholder communication, and accountability for the recommendation still dominate the cost, so overall savings are modest.
Technical feasibility todayclaude-haiku-4-5-202510012/5No deployed product reliably generates strategic security recommendations that management would act on without significant human expert review; AI can assist with data collection and initial frameworks, but the decision-critical synthesis and business-context fitting remain manual.
Technical feasibility todayclaude-sonnet-52/5AI tools can generate generic security recommendations from scans or frameworks, but no deployed product reliably produces context-aware, organization-specific recommendations that management would accept without heavy human review.

Troubleshoot security and network problems.

30

CI 2832 · exposure 30 · augmentation 75 · importance 3.7/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Enterprise security teams are experimenting with AI-assisted threat detection and automation, but adoption remains cautious due to the critical nature of security work and lingering concerns about false negatives. Most deployments are augmentative rather than replacement-oriented.
Sector adoption velocityclaude-sonnet-53/5IT/security is a moderately fast-adopting sector for AI copilots and anomaly detection, but full automation of hands-on troubleshooting remains at the pilot stage in most organizations.
Augmentation potentialclaude-haiku-4-5-202510014/5AI significantly augments security engineers through automated log analysis, anomaly detection, correlation of disparate signals, and guided investigation workflows. These tools substantially accelerate diagnosis when engineers remain in control and interpret results.
Augmentation potentialclaude-sonnet-54/5AI tools significantly help by summarizing logs, flagging anomalies, suggesting root causes, and referencing documentation, substantially speeding up an engineer's troubleshooting workflow.
Task automatabilityclaude-haiku-4-5-202510012/5Troubleshooting security and network problems requires complex diagnosis combining multiple data sources, pattern recognition, and contextual judgment. While AI can assist in log analysis and anomaly detection, current systems struggle with novel attack vectors and require significant human expertise to validate findings and determine root causes.
Task automatabilityclaude-sonnet-52/5Troubleshooting security and network issues requires diagnosing novel, context-specific problems across live systems, correlating logs, and making judgment calls that current AI cannot reliably do end-to-end without heavy human oversight.
Adoption barriersclaude-haiku-4-5-202510014/5Security decisions carry substantial liability and error costs; regulatory frameworks (HIPAA, SOC 2, PCI-DSS) often require human security professionals to authenticate and sign off on remediation decisions. Organizations face legal and compliance pressure to maintain human oversight.
Adoption barriersclaude-sonnet-54/5Security incident response often has compliance, liability, and audit requirements mandating qualified human sign-off, and errors in security troubleshooting carry high consequences, creating strong barriers to full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5Specialized security infrastructure (SIEM, threat intelligence platforms) carries significant ongoing costs, and human security engineers remain essential for validation and decision-making, making the combined cost still higher than automation savings.
Cost vs. human wageclaude-sonnet-52/5Deploying and maintaining AI-assisted security tooling plus the required human oversight for validation and remediation still costs comparably to or more than existing engineer time for complex troubleshooting.
Technical feasibility todayclaude-haiku-4-5-202510013/5Products like SIEM systems with AI-assisted alerting and automated anomaly detection exist in production, but they generate substantial false positives and require expert human review. No system reliably performs end-to-end troubleshooting without human intervention.
Technical feasibility todayclaude-sonnet-52/5AI-driven anomaly detection and log analysis tools exist in SIEM/SOAR products, but they narrowly assist detection rather than perform full troubleshooting reliably in production without engineer intervention.

Develop response and recovery strategies for security breaches.

29

CI 2532 · exposure 25 · augmentation 63 · importance 4.3/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5While information security is digitized, actual adoption of AI for strategic breach response planning remains limited to tactical incident handling aids; most organizations still rely on human-led strategy development and incident response playbooks.
Sector adoption velocityclaude-sonnet-53/5Cybersecurity is a digitized, fast-moving field with growing AI tool adoption (e.g., AI-assisted SOC tools), but strategic planning tasks still see more pilots than full production reliance.
Augmentation potentialclaude-haiku-4-5-202510013/5AI can assist security engineers by analyzing breach data, suggesting remediation patterns, and drafting response components, thereby raising productivity; however, human expertise must remain central to strategy formulation and organizational decision-making.
Augmentation potentialclaude-sonnet-54/5AI can meaningfully assist by drafting incident response templates, summarizing threat intelligence, and suggesting recovery steps, significantly speeding up the human-led strategy development process.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist with analysis of breach patterns and generate boilerplate recovery procedures, the task requires substantial human judgment about organizational context, risk prioritization, and strategic decisions that current AI systems cannot handle end-to-end with 50% time savings at equal quality.
Task automatabilityclaude-sonnet-52/5Developing incident response and recovery strategies requires contextual judgment about business risk, systems architecture, and organizational priorities that current AI cannot fully replicate end-to-end.rate what current, generally available AI systems can do today
Adoption barriersclaude-haiku-4-5-202510014/5Strong barriers exist: liability and legal exposure are asymmetric (AI errors in breach response can compound damage), regulatory requirements often mandate qualified human judgment, and organizations retain explicit accountability for breach response strategies that resist full automation.
Adoption barriersclaude-sonnet-53/5No licensing mandates a human specifically, but liability for breach response failures, regulatory compliance (e.g., data breach notification laws), and organizational risk tolerance create meaningful friction against full automation.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI tools for security analysis are expensive and require significant human oversight, integration, and validation—meaning the all-in cost remains comparable to or higher than hiring experienced security professionals for strategy development.
Cost vs. human wageclaude-sonnet-52/5AI can draft frameworks quickly but requires significant expert oversight and validation, so overall cost savings versus a skilled engineer are modest rather than order-of-magnitude.
Technical feasibility todayclaude-haiku-4-5-202510012/5No deployed products reliably perform comprehensive breach response and recovery strategy development autonomously; security orchestration tools exist for tactical incident response but lack the strategic, contextual decision-making required for this task in production environments.
Technical feasibility todayclaude-sonnet-52/5Some products offer playbook generation and SOAR automation suggestions, but strategic response and recovery planning still relies heavily on human security architects reviewing and customizing outputs.

Oversee performance of risk assessment or execution of system tests to ensure the functioning of data processing activities or security measures.

29

CI 2532 · exposure 25 · augmentation 75 · importance 3.9/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510012/5While security engineering is digitized, adoption of AI for autonomous oversight of risk assessment and test execution remains limited and cautious. Organizations pilot AI-assisted analysis but retain human engineers as decision-makers and sign-off authority, slowing deep adoption.
Sector adoption velocityclaude-sonnet-53/5Information security is a digitized, fast-moving field with growing AI tool adoption (SOAR, AI-driven SIEM), but full oversight automation remains at the pilot stage in most organizations.
Augmentation potentialclaude-haiku-4-5-202510014/5AI demonstrably augments security engineers by automating test generation, scanning logs for anomalies, flagging patterns, and generating draft reports. Engineers remain in the loop for interpretation, prioritization, and sign-off, with substantial productivity gains on the analytical portions of the task.
Augmentation potentialclaude-sonnet-54/5AI significantly assists by automating parts of test execution, log analysis, and vulnerability detection, allowing engineers to focus oversight effort more efficiently while remaining in the loop.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist in generating test scripts and flagging anomalies in security logs, the core task of overseeing and ensuring proper execution of risk assessments requires contextual judgment, exception handling, and accountability that current AI cannot fully replicate at 50% time savings. Human oversight remains essential for interpretation and sign-off.
Task automatabilityclaude-sonnet-52/5This task centers on oversight and judgment across risk assessment and test execution, which requires contextual understanding of business risk and human accountability that current AI cannot fully replace end-to-end.ract
Adoption barriersclaude-haiku-4-5-202510014/5Regulatory frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS) typically require documented human responsibility for security test oversight and sign-off. Liability asymmetry is high: an AI failure in security testing can cascade into breach liability, creating legal and organizational friction against full automation.
Adoption barriersclaude-sonnet-53/5Security oversight often involves compliance obligations, audit trails, and accountability structures that push organizations to keep humans formally responsible, though not always requiring specific licensure.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI-driven security testing tools exist but require significant expert human oversight, integration, and validation work. The total cost of AI infrastructure plus mandatory human review approaches or exceeds the cost of direct human execution, particularly for high-stakes environments.
Cost vs. human wageclaude-sonnet-52/5While automated scanning tools reduce some labor costs, the oversight and judgment components still require a skilled engineer, so the all-in cost of an AI-augmented process is not dramatically cheaper than a human-led one.
Technical feasibility todayclaude-haiku-4-5-202510012/5Some products assist with vulnerability scanning and test report generation, but no deployed system reliably oversees the *execution* and *performance* of security tests end-to-end with the rigor required in production environments. Benchmark demonstrations exist, but production-scale automation of this oversight function is rare.
Technical feasibility todayclaude-sonnet-52/5AI-assisted vulnerability scanners and automated test frameworks exist and are deployed, but the 'oversight' function—interpreting results and validating that security measures function correctly—remains a human-led activity in production environments.

Develop or install software, such as firewalls and data encryption programs, to protect sensitive information.

28

CI 2828 · exposure 25 · augmentation 75 · importance 4.1/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security teams are adopting AI-assisted scanning and analysis tools, but adoption of autonomous security software development/installation remains limited due to risk aversion, regulatory constraints, and the mission-critical nature of security infrastructure. Pilots exist but production replacement is rare.
Sector adoption velocityclaude-sonnet-53/5Tech/security sectors are moderately fast adopters of AI-assisted coding tools, but core security architecture decisions remain largely human-driven with cautious rollout given risk sensitivity.
Augmentation potentialclaude-haiku-4-5-202510014/5AI meaningfully augments security engineers through automated vulnerability detection, policy suggestions, encryption best-practice guidance, and code review assistance, substantially accelerating their work while they retain control over architectural and deployment decisions. This is an area of proven AI productivity gains in practice.
Augmentation potentialclaude-sonnet-54/5AI coding assistants and security-specific tools meaningfully speed up writing configuration code, drafting policies, and identifying known vulnerabilities, aiding engineers substantially.
Task automatabilityclaude-haiku-4-5-202510012/5While routine deployment of standard firewall and encryption tools can be partially automated, developing or installing security software requires significant architectural decisions, threat assessment, and integration with existing systems that demand human expertise and contextual judgment. Current AI cannot reliably perform the full decision chain for enterprise security infrastructure.
Task automatabilityclaude-sonnet-52/5AI can help write configuration scripts or generate code snippets for encryption/firewall setups, but selecting architecture, integrating with existing infrastructure, and validating security posture still requires substantial human engineering judgment and testing.
Adoption barriersclaude-haiku-4-5-202510014/5Strong regulatory (SOC 2, HIPAA, PCI-DSS, FedRAMP) and organizational barriers require human sign-off on security controls, and liability for breaches creates high error costs that discourage full automation. Compliance audits typically mandate documented human responsibility for security infrastructure decisions.
Adoption barriersclaude-sonnet-54/5Security-critical infrastructure changes typically require sign-off, compliance audits, and accountability from certified professionals due to high liability from misconfiguration or breaches.
Cost vs. human wageclaude-haiku-4-5-202510012/5The specialized expertise, liability, and compliance requirements mean human security engineers remain significantly cheaper on a cost-per-successful-deployment basis than AI-driven solutions when accounting for setup, customization, testing, and ongoing oversight needed to catch errors.
Cost vs. human wageclaude-sonnet-52/5AI can reduce drafting time for scripts/configs but human security engineers must still validate, test, and deploy, so overall labor cost savings are modest rather than order-of-magnitude.
Technical feasibility todayclaude-haiku-4-5-202510012/5Deployed products exist for automated vulnerability scanning and policy-based firewall rule generation, but these operate within narrow scopes and still require security engineers to validate, customize, and approve deployments. No production systems reliably handle end-to-end security software development or installation without substantial human oversight.
Technical feasibility todayclaude-sonnet-52/5Copilot-style tools assist with code generation and config templates, but no deployed product autonomously develops or installs full firewall/encryption systems end-to-end in production without expert oversight.

Oversee development of plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure or to meet emergency data processing needs.

28

CI 2828 · exposure 25 · augmentation 75 · importance 4.1/5 · click for rater detail

Panel ratings per dimension for this task
DimensionModelRatingRationale
Sector adoption velocityclaude-haiku-4-5-202510013/5Information security teams are moderately digitizing their workflows with AI-assisted tools for threat detection and policy drafting, but actual plan oversight remains human-centric in most organizations. Pilot adoption of AI co-pilots for security engineering is growing, but production-level replacement of oversight roles remains limited due to liability and regulatory concerns.
Sector adoption velocityclaude-sonnet-53/5Information security is a digitized, fast-moving field with growing AI tool adoption for threat detection and drafting, but oversight/governance roles still see slower AI penetration than technical execution tasks.
Augmentation potentialclaude-haiku-4-5-202510014/5AI can substantially augment security engineers by automating threat modeling, generating policy templates, identifying regulatory gaps, and analyzing logs—all while the engineer retains final decision authority. These capabilities meaningfully accelerate the planning process and reduce manual research, enabling engineers to focus on strategic risk assessment and organizational alignment.
Augmentation potentialclaude-sonnet-54/5AI significantly aids by drafting policy language, generating risk scenarios, summarizing compliance requirements, and suggesting emergency data processing procedures, boosting the engineer's efficiency substantially.
Task automatabilityclaude-haiku-4-5-202510012/5While AI can assist in drafting security plans and identifying common vulnerabilities, oversight of plan development requires strategic judgment about organizational risk tolerance, regulatory context, and emerging threat landscapes that current systems cannot reliably do end-to-end. The task inherently involves human decision-making about trade-offs between security, usability, and cost that AI cannot autonomously perform at acceptable quality.
Task automatabilityclaude-sonnet-52/5This is an oversight and planning task requiring judgment, organizational context, and accountability; AI can draft policy templates but cannot own or lead the strategic planning process end-to-end.
Adoption barriersclaude-haiku-4-5-202510014/5Regulatory frameworks (HIPAA, SOX, PCI-DSS, GDPR) and liability standards often require that qualified security engineers personally oversee and sign off on safeguarding plans, creating legal accountability barriers. Many organizations also have compliance requirements that explicitly mandate human security professional involvement in plan development and oversight.
Adoption barriersclaude-sonnet-54/5Data protection regulations, compliance frameworks, and organizational liability typically require a designated accountable human (often certified/licensed) to oversee such plans.
Cost vs. human wageclaude-haiku-4-5-202510012/5AI assistance for security planning (threat modeling, policy generation) is relatively expensive due to integration costs and necessary human oversight, while the task's high stakes demand expert human judgment that cannot be fully substituted. The cost of errors in security oversight is prohibitively high, making the all-in cost of AI-only approaches uneconomical compared to human engineers.
Cost vs. human wageclaude-sonnet-52/5Human oversight, stakeholder coordination, and accountability for these plans remain necessary, so AI reduces drafting time but doesn't substantially replace the human cost of oversight and sign-off.
Technical feasibility todayclaude-haiku-4-5-202510012/5AI tools exist for vulnerability scanning and security policy templates, but no deployed product can independently oversee the full scope of safeguarding plan development with the accountability and contextual judgment this role demands. Existing security tools require substantial human oversight and cannot replace the engineer's responsibility for plan quality and legal compliance.
Technical feasibility todayclaude-sonnet-52/5AI tools assist with drafting security policies, risk assessments, and DR plans, but no deployed product independently oversees or manages development of such safeguarding plans in production.

Related occupations — Computer & Mathematical

How to read this

A high substitution score does not mean this job disappears — it means a large share of its current tasks face replacement pressure, so the mix of tasks is likely to change. High augmentation alongside substitution typically means the occupation reorganizes around the protected tasks. Wide confidence intervals mean the rater panel disagreed: treat those scores as open questions, not verdicts.

What would change this score

New model capabilities (automatability, feasibility), falling inference costs (cost ratio), regulation and licensing shifts (barriers), and measured sector adoption (velocity) all re-enter at every index release. Each release is recomputed, versioned and kept queryable — scores are claims with a date on them, not permanent labels.