Information Security Engineers
15-1299.05Develop and oversee the implementation of information security procedures and policies. Build, maintain and upgrade security technology, such as firewalls, for the safe use of computer networks and the transmission and retrieval of information. Design and implement appropriate security controls to identify vulnerabilities and protect digital files and electronic infrastructures. Monitor and respond to computer security breaches, viruses, and intrusions, and perform forensic investigation. May oversee the assessment of information security systems.
Sub-scores
0–100 · band = confidence interval from rater disagreement
Substitution — the headline: capability discounted by cost, barriers and adoption.
Exposure — technical capability alone, regardless of whether anyone deploys it.
Augmentation — how much AI assists without replacing. High here + moderate substitution = a changing job, not a disappearing one.
Tasks on the substitution scale
20 rated tasks, binned by substitution score.
Position among all scored occupations
Distribution of 923 occupation scores; the marker is this occupation.
Tasks with substitution ≥ 70
5%
Run 1.0.0-draft.1 · computed 2026-08-05 · rater panel: claude-sonnet-5, claude-haiku-4-5-20251001 · intervals span rater disagreement.
Why this score
The five weighted dimensions of the composite, averaged across this occupation's tasks (importance-weighted, panel mean). Exact weights and formulas: /api/v1/methodology.
panel mean rating 2.3/5 → substitution pressure 33/100
panel mean rating 2.5/5 → substitution pressure 38/100
panel mean rating 2.4/5 → substitution pressure 36/100
panel mean rating 3.4/5 (barrier strength) → substitution pressure 40/100
panel mean rating 3.0/5 → substitution pressure 51/100
Task breakdown (20 tasks)
Substitution pressure per task, weighted by O*NET importance in the composite. Expand a task for the full rater audit trail — every rating, every model, every rationale.
Scan networks, using vulnerability assessment tools to identify vulnerabilities.
85CI 84–86 · exposure 84 · augmentation 88 · importance 4.3/5 · click for rater detail
Scan networks, using vulnerability assessment tools to identify vulnerabilities.
85| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 5/5 | Vulnerability scanning automation is deeply embedded in modern information security and DevSecOps practices across financial, tech, healthcare, and critical infrastructure sectors, with continuous scanning now standard in many enterprises. |
| Sector adoption velocity | claude-sonnet-5 | 4/5 | Cybersecurity is a fast-adopting, digitized field where automated scanning has been standard practice for over a decade across most mature organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI-powered vulnerability scanners augment security engineers significantly by automating the discovery phase, flag prioritization, and threat correlation, allowing humans to focus on analysis and remediation rather than running scans and parsing raw results. |
| Augmentation potential | claude-sonnet-5 | 5/5 | AI-enhanced scanning and prioritization tools significantly boost engineer productivity by surfacing, triaging, and contextualizing vulnerabilities faster than manual review, while humans retain judgment over remediation. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | Vulnerability scanning itself is highly automatable—current tools like Nessus, OpenVAS, and Qualys can be deployed end-to-end to identify network weaknesses with minimal human intervention, easily exceeding 50% time savings. However, interpreting results, prioritizing findings, and determining remediation strategy still typically require human expertise, preventing a full 5. |
| Task automatability | claude-sonnet-5 | 4/5 | Vulnerability scanning is largely mechanical and automated tools (Nessus, Qualys, OpenVAS, etc.) already run scans and generate reports with minimal human intervention, meeting the time-saving threshold for the scanning portion itself, though interpretation and remediation planning remain human-led.' |
| Adoption barriers | claude-haiku-4-5-20251001 | 2/5 | Few hard regulatory or legal barriers prevent automated scanning; however, organizational friction exists (IT sign-off, change management, customer communication policies) and the sensitivity of security testing may require human authorization before deployment in some contexts. |
| Adoption barriers | claude-sonnet-5 | 2/5 | No licensing mandates a human perform the scan itself, though compliance frameworks (PCI-DSS, etc.) often require human-certified interpretation or sign-off on results, creating minor procedural friction. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 5/5 | Automated vulnerability scanning costs (SaaS subscriptions + infrastructure) are typically one to two orders of magnitude cheaper than the loaded cost of employing security engineers to manually probe networks, even accounting for oversight and tuning overhead. |
| Cost vs. human wage | claude-sonnet-5 | 5/5 | Automated scanning tools cost a small licensing/subscription fee compared to the labor cost of manually probing networks, making automation dramatically cheaper per scan cycle. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 5/5 | Mature, production-grade vulnerability scanning tools are ubiquitously deployed across enterprises and security operations today. Products like Nessus, Qualys, and cloud-native scanners reliably perform this task at scale with well-understood accuracy and false-positive rates. |
| Technical feasibility today | claude-sonnet-5 | 5/5 | Mature commercial and open-source vulnerability scanners are deployed at scale in production environments across virtually all industries today, performing automated scans reliably and continuously. |
Review security assessments for computing environments or check for compliance with cybersecurity standards and regulations.
60CI 50–70 · exposure 62 · augmentation 88 · importance 3.8/5 · click for rater detail
Review security assessments for computing environments or check for compliance with cybersecurity standards and regulations.
60| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 4/5 | Information security and financial/cloud-native organizations are rapidly deploying automated compliance scanning and vulnerability assessment tools in production. Adoption is deep in digitized sectors, though conservative legacy environments lag. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity and IT sectors show above-average digitization and growing GRC tool adoption, but many compliance review processes remain manual or semi-automated with AI pilots rather than full production deployment. |
| Augmentation potential | claude-haiku-4-5-20251001 | 5/5 | AI-powered security tools dramatically augment human engineers by continuously monitoring environments, surfacing anomalies, and pre-filtering findings—allowing engineers to focus on investigation, decision-making, and remediation rather than manual scanning and routine compliance checks. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI substantially aids compliance reviewers by rapidly cross-referencing controls, summarizing gaps, and drafting audit documentation, meaningfully increasing throughput while humans retain final judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | AI systems can automatically scan computing environments, flag deviations from cybersecurity standards, and generate compliance reports with high consistency. While human judgment on complex risk trade-offs and novel threat patterns remains valuable, the core review and checking work—comparing configs to baselines, identifying missing patches, verifying policy adherence—can achieve >50% time savings at equal quality with current tools. |
| Task automatability | claude-sonnet-5 | 3/5 | AI can review assessments against known frameworks (NIST, ISO 27001) and flag gaps or compliance issues, but final judgment on risk acceptance and nuanced organizational context still requires human expertise, so only partial time savings are realized end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 3/5 | Regulatory frameworks (SOC 2, HIPAA, PCI-DSS) often require documented human review and sign-off, creating organizational friction. Liability concerns and the need for expert human judgment on remediation decisions introduce meaningful but not absolute barriers to full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing mandate for this specific review task, but regulatory frameworks (e.g., PCI-DSS, HIPAA, SOC2) often require qualified personnel attestation, and liability for missed compliance issues creates moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 4/5 | Automated scanning and compliance checking infrastructure costs are typically one-tenth or less of hiring and deploying a dedicated security engineer for the same coverage, especially at scale. Infrastructure and oversight costs are low relative to loaded engineer wages. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI-assisted compliance tools reduce review time significantly but still require licensed/experienced security engineers for oversight and sign-off, keeping costs roughly comparable rather than order-of-magnitude cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 4/5 | Deployed products (vulnerability scanners, compliance automation tools, SIEM systems with automated rule engines) reliably perform large portions of this task in production across enterprises. Limitations exist for nuanced context assessment and novel attack vectors, but standard compliance checking and environment scanning are mature and widely used. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | Compliance automation and GRC tools with AI features exist in production (e.g., automated control mapping, policy gap analysis) but still require human validation and have notable false positive/negative rates on complex environments. |
Develop information security standards and best practices.
47CI 32–62 · exposure 45 · augmentation 88 · importance 3.9/5 · click for rater detail
Develop information security standards and best practices.
47| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security teams are beginning to pilot AI for policy drafting and baseline generation, but most organizations still require human security architects to own standards development; production-scale autonomous generation remains uncommon. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Information security is a digitized, fast-moving field with growing AI tool adoption for drafting and research, but authoritative standard-setting still largely involves human-led committees and review cycles. |
| Augmentation potential | claude-haiku-4-5-20251001 | 5/5 | AI assistants substantially accelerate standards development by generating initial drafts, regulatory mapping, and threat-aligned recommendations, allowing security engineers to focus on validation, customization, and strategic governance—a high-impact augmentation pattern already seeing real adoption. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly speed up drafting, benchmarking against frameworks (NIST, ISO), and summarizing best practices, meaningfully boosting analyst productivity while humans retain final judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 4/5 | AI can draft comprehensive security standards by synthesizing regulatory frameworks, threat intelligence, and industry best practices, achieving significant time savings on the bulk composition and structure. However, final validation and strategic judgment on organization-specific risk posture typically require human expert review, preventing full 5-level automation. |
| Task automatability | claude-sonnet-5 | 2/5 | Drafting standards requires synthesizing organizational risk context, regulatory requirements, and business constraints that AI cannot fully originate autonomously, though it can help draft sections; full end-to-end automation with equal quality is not yet achievable. |
| Adoption barriers | claude-haiku-4-5-20251001 | 3/5 | While no hard legal requirement mandates a licensed human author standards, organizational liability concerns, compliance auditor expectations, and the need for expert sign-off on risk-critical policies create meaningful friction that prevents outright substitution. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement mandates a human sign-off, but organizational accountability, compliance audits, and liability for security failures create meaningful friction against fully automating standard-setting. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 4/5 | AI inference and integration costs for generating policy documents are substantially lower than senior security engineer labor (typically $150k–$250k+ loaded), with minimal overhead for prompt engineering and review cycles. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While AI can cheaply generate draft text, the human expert time needed for validation, contextualization, and stakeholder alignment remains substantial, keeping overall cost savings modest. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Products exist (LLMs, policy-generation tools) that can generate credible security standards drafts, but deployed systems still show material gaps in regulatory alignment, context awareness, and specificity to organizational threat models. Reliability remains mixed without human oversight. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | AI tools (e.g., LLM-based drafting assistants) can produce policy templates and boilerplate language, but no deployed product reliably generates organization-specific security standards without heavy human review and customization. |
Write reports regarding investigations of information security breaches or network evaluations.
46CI 30–62 · exposure 50 · augmentation 88 · importance 3.7/5 · click for rater detail
Write reports regarding investigations of information security breaches or network evaluations.
46| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Information security remains a highly regulated, liability-sensitive domain where organizations retain human experts and resist full automation of investigative reporting. Adoption is limited to assistive drafting in pilot programs rather than end-to-end replacement in production. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity and IT sectors are moderately fast adopters of AI tooling (SOC copilots, threat-detection AI), but report-writing specifically is still mostly augmentative rather than fully deployed in production workflows. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI can significantly assist by auto-generating report structure, summarizing technical logs, flagging patterns, and drafting initial text that engineers then validate and refine. This raises productivity without removing the security engineer from the investigation loop. |
| Augmentation potential | claude-sonnet-5 | 5/5 | AI is highly effective at drafting, summarizing findings, structuring narrative sections, and improving clarity and speed of report writing while the security engineer retains responsibility for verifying facts and conclusions. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | AI can draft sections of breach reports (timelines, technical findings summaries) but cannot independently investigate, validate evidence, or make forensic conclusions. Human security experts must conduct the investigation and verify all claims, limiting time savings to <50% for a complete, defensible report. |
| Task automatability | claude-sonnet-5 | 4/5 | Drafting structured incident reports and network evaluation summaries from logs, ticket data, and findings is well-suited to LLMs, which can generate coherent narrative text and executive summaries with substantial time savings, though a human must verify technical accuracy and sensitive conclusions. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory frameworks (GDPR, HIPAA, SEC, etc.) often require human expert certification and sworn attestation of breach findings. Liability asymmetry is extreme—false or incomplete breach reports expose organizations to legal jeopardy, creating strong incentive for human accountability and authorization. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement mandates a human write the report, but liability for inaccurate security findings, confidentiality of breach details, and organizational sign-off requirements create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI can reduce drafting overhead, but security breach reporting requires licensed or experienced human sign-off, and the cost of errors (liability, regulatory fines) means human oversight remains the dominant cost component. All-in cost remains comparable to or higher than human-only workflow. |
| Cost vs. human wage | claude-sonnet-5 | 4/5 | Generating a draft report via AI costs a fraction of an engineer's hourly rate, even accounting for the human review and editing time needed to finalize a technically accurate report. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | AI writing assistants and template-based report generators exist in security workflows, but they typically handle formatting and boilerplate; no deployed system reliably produces investigation-grade breach reports without substantial human review and rework of technical conclusions. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | AI writing assistants and SOC copilots (e.g., Microsoft Security Copilot, various SIEM-integrated tools) can draft incident summaries today, but adoption for final, authoritative security reports is still limited and requires heavy human review before deployment in production. |
Provide technical support to computer users for installation and use of security products.
42CI 37–46 · exposure 34 · augmentation 75 · importance 3.4/5 · click for rater detail
Provide technical support to computer users for installation and use of security products.
42| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Tech and enterprise sectors have begun deploying AI-assisted support, but adoption remains mixed: many organizations still rely on human technical support teams. Pilots are common; production displacement remains moderate. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT/security functions are moderately fast adopters of AI-assisted support tools (chatbots, ticket triage), though full automation of hands-on security support remains limited in production. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI excels at augmenting support engineers by providing instant access to documentation, suggesting solutions, drafting responses, and handling ticket triage, allowing humans to focus on complex troubleshooting and customer rapport. This represents meaningful productivity gain while the human remains in control. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI assistants can significantly speed up diagnosis, generate step-by-step guides, and draft responses for common security product issues, meaningfully boosting support engineer productivity. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Most of this task requires human judgment in troubleshooting, understanding user context, and tailoring explanations to individual technical levels. While AI can handle routine script execution and documentation lookup, the interactive problem-solving with variable user contexts and non-standard configurations resists full automation. |
| Task automatability | claude-sonnet-5 | 2/5 | Hands-on troubleshooting and installation of security software on diverse user systems requires physical access, environment-specific diagnosis, and interactive back-and-forth that current AI cannot fully replace end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 3/5 | Some organizations have liability concerns about automating security product support without human verification, and users often prefer human contact for security-sensitive issues. Regulatory and organizational friction exist but are not absolute legal bars to deployment. |
| Adoption barriers | claude-sonnet-5 | 2/5 | No licensing requirement, but some organizational risk aversion exists since security misconfigurations have significant liability and error costs, warranting human oversight for many issues. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI-powered support chatbots have low inference costs but require significant integration, customization to security products, and ongoing human oversight for escalations and complex cases. The all-in cost approaches or sometimes exceeds junior technical support labor, especially when factoring oversight. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI-driven tier-1 support reduces ticket volume cheaply, but complex security support still requires skilled engineer time, keeping overall cost roughly comparable once escalations are factored in. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Chatbots and AI assistants can answer common installation questions and provide basic support today, but deployed products struggle with complex troubleshooting, unusual system configurations, and the adaptability required for diverse user needs. Production systems exist but with material limitations. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | AI chatbots and IT helpdesk assistants exist and handle common installation/configuration queries in production, but complex or edge-case security product issues still need escalation to human engineers. |
Assess the quality of security controls, using performance indicators.
39CI 28–50 · exposure 38 · augmentation 75 · importance 4.4/5 · click for rater detail
Assess the quality of security controls, using performance indicators.
39| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security firms are adopting automated control monitoring and analytics tools widely, but human-led assessment remains the norm; pilots of autonomous assessment are common but full production replacement is not yet prevalent in most organizations. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Information security is a digitized, fast-moving sector with growing AI tool adoption (e.g., AI-driven SOC tools), but pilots for full autonomous control assessment remain more common than mature deployment. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI tools (automated metrics collection, anomaly detection, compliance gap analysis) substantially augment security engineers by handling data aggregation and flagging control drift, allowing engineers to focus on contextual judgment and remediation strategy while staying firmly in the loop. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly aids by aggregating logs, flagging deviations, and suggesting metrics interpretation, greatly boosting analyst efficiency while humans retain final judgment. |
| Task automatability | claude-haiku-4-5-20251001 | 3/5 | AI can partially automate assessment of security controls by analyzing logs, metrics, and compliance data to evaluate performance indicators, but requires human judgment to contextualize findings, interpret policy alignment, and make risk decisions that determine control adequacy. |
| Task automatability | claude-sonnet-5 | 2/5 | Assessing security control quality requires contextual judgment about organizational risk, business impact, and interpreting metrics that AI can support but not independently perform end-to-end reliably. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Organizations face regulatory requirements (SOC 2, ISO 27001, HIPAA) that typically mandate human security professionals sign off on control assessments; liability and compliance frameworks create strong incentives to retain human judgment and accountability in quality evaluation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | While not licensed like some professions, security assessments often require accountability, compliance sign-off, and organizational trust, creating moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 3/5 | Automated security monitoring and control assessment tooling costs are now comparable to portions of a security engineer's wage for routine indicator analysis, but comprehensive assessment still requires expert validation, keeping overall cost near parity. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools can reduce data-gathering time but human security engineers still must interpret results and validate findings, keeping overall costs closer to comparable rather than order-of-magnitude cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Products exist (SIEM platforms, security analytics tools, automated compliance scanners) that perform components of this task at scale, but they typically flag metrics and anomalies rather than fully assess control quality; human interpretation remains standard practice. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some SIEM/GRC tools and AI-assisted analytics can surface performance indicators and flag anomalies, but no deployed product autonomously performs full control-quality assessments in production without expert review. |
Develop or implement software tools to assist in the detection, prevention, and analysis of security threats.
37CI 32–42 · exposure 34 · augmentation 75 · importance 3.7/5 · click for rater detail
Develop or implement software tools to assist in the detection, prevention, and analysis of security threats.
37| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security teams use AI-assisted analysis tools in pilots and testing, but production deployment of AI-generated security tools is cautious due to liability and trust concerns; adoption is faster in large, well-resourced information security operations but lags elsewhere. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Information security and tech sectors are relatively fast adopters of AI-assisted coding and SOC copilots, though full tool development automation remains at the pilot stage rather than deep production use. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly assists security engineers through code suggestion, threat pattern recognition, vulnerability scanning automation, and analysis acceleration; engineers remain in control but their productivity is materially enhanced on tool development and threat investigation. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI coding assistants, threat intelligence summarization, and automated rule generation meaningfully speed up building and refining detection/prevention tools while engineers retain oversight and validation responsibilities. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with threat detection and analysis (pattern matching, anomaly identification), developing and implementing security tools requires domain expertise, architectural decisions, integration with existing systems, and security validation that cannot be fully automated end-to-end with current systems at 50%+ time savings and equal quality. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can help draft code snippets, scripts, or detection rules, but designing and validating robust security tools that handle novel threats and integrate with complex infrastructure still requires significant human architecture, testing, and domain judgment. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security tool implementation is subject to regulatory oversight (SOC 2, HIPAA, PCI-DSS compliance), organizational risk assessment, and liability exposure; security decisions must be justified and auditable, creating strong friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 2/5 | No licensing requirement mandates a human build security tools, but organizational risk aversion around security-critical code and the liability of flawed detection tools create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI code generation and threat analysis tools reduce engineering time on routine detection logic, but the complexity of security tool development, required testing, and human review keep total costs close to or exceeding specialized engineer wages. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While AI can accelerate coding tasks, the overall tool development lifecycle—design, testing, validation against adversarial threats, integration—still demands substantial skilled engineer time, keeping costs closer to comparable than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | AI tools exist for threat detection and code analysis (e.g., SIEM assistants, static analysis), but they operate within narrow scopes and require significant human oversight; no end-to-end product reliably develops new security tools from scratch in production without substantial human direction. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | AI coding assistants and security copilots are deployed in production to help write detection rules, scripts, and threat analysis code, but they still require expert review and don't autonomously build complete security tooling. |
Coordinate monitoring of networks or systems for security breaches or intrusions.
36CI 32–40 · exposure 34 · augmentation 88 · importance 4.4/5 · click for rater detail
Coordinate monitoring of networks or systems for security breaches or intrusions.
36| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Mid-market and enterprise organizations are piloting AI-augmented SIEM and threat detection, but full automation of coordination remains rare; most deployments use AI as a triage tool requiring human analysts. Adoption is expanding but not yet at the velocity of other information-sector automations. |
| Sector adoption velocity | claude-sonnet-5 | 4/5 | Cybersecurity is a fast-adopting, highly digitized sector with widespread deployment of AI-driven SIEM, EDR, and XDR tools integrated into SOC workflows. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI-driven anomaly detection, alert enrichment, and threat scoring significantly amplify human analyst productivity by filtering noise and surfacing high-risk events. Security engineers use these tools to handle larger networks and respond faster while retaining investigative and decision authority. |
| Augmentation potential | claude-sonnet-5 | 5/5 | AI significantly enhances this task by correlating logs, flagging anomalies, reducing alert fatigue, and prioritizing incidents, letting security engineers coordinate response more effectively. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | AI can assist with anomaly detection and alert generation, but network security monitoring requires contextual judgment about threat severity, false positive filtering, and incident prioritization that humans currently must perform. Full end-to-end automation meeting the 50% time-saving threshold is not yet demonstrated. |
| Task automatability | claude-sonnet-5 | 2/5 | The task centers on 'coordinating' monitoring—an oversight and management function requiring judgment, escalation decisions, and cross-team communication that current AI cannot fully replace, though AI can automate underlying detection subtasks. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory compliance (SOC 2, ISO 27001, HIPAA, PCI-DSS) often requires documented human accountability for security decisions, and many organizations face liability asymmetry where missed breaches trigger breach notification laws. Customer trust and contractual obligations frequently mandate human security engineers in the loop. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement mandates a human specifically, but liability for missed breaches, compliance/regulatory reporting obligations, and organizational trust in human judgment for incident coordination create meaningful friction. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Current AI monitoring solutions require significant infrastructure, tuning, and ongoing human analyst review to filter noise. The all-in cost of an AI system plus required human oversight approximates or may exceed the cost of dedicated human security engineers. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI-assisted monitoring tools reduce headcount needs somewhat, but licensing costs for enterprise security platforms plus required human oversight keep costs from being dramatically lower than a security engineer's time for coordination duties. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Security information and event management (SIEM) systems and AI-driven threat detection tools exist in production, but they generate substantial false positives and require human analysts to validate alerts and coordinate response. Deployed products perform parts of the monitoring reliably but not the full coordination task. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | SIEM/SOAR platforms with AI-driven anomaly detection and alert triage are widely deployed in production, but they still require human coordination, tuning, and escalation decisions, especially for complex or novel threats. |
Coordinate documentation of computer security or emergency measure policies, procedures, or tests.
35CI 25–45 · exposure 33 · augmentation 75 · importance 3.7/5 · click for rater detail
Coordinate documentation of computer security or emergency measure policies, procedures, or tests.
35| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | Security-focused organizations remain cautious with AI automation in policy-critical domains; most adoption is limited to drafting assistance rather than autonomous coordination, reflecting slow production deployment in this risk-sensitive sector. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Information security is a digitized, tech-forward field with growing AI tool adoption for documentation and compliance tasks, though coordination workflows remain largely manual in most organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI can meaningfully assist by generating initial policy drafts, organizing documentation templates, flagging compliance gaps, and tracking version control—substantially raising a security engineer's drafting speed while they retain judgment on coordination and approval workflows. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly speeds up drafting, formatting, and updating policy and test documentation, letting security engineers focus on coordination, review, and judgment calls. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can draft and organize documentation, coordinating security policies requires judgment about organizational context, compliance requirements, and stakeholder input that current systems handle poorly. Meaningful automation would need human review and iteration at each step, falling short of the 50% time-saving threshold. |
| Task automatability | claude-sonnet-5 | 3/5 | AI can draft, organize, and update policy documentation and test procedures given source material, but coordinating input across stakeholders and verifying accuracy still requires human oversight, limiting full end-to-end automation. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Information security documentation often falls under regulatory and compliance requirements (SOC 2, ISO 27001, HIPAA, etc.) and liability concerns; human security engineers must typically sign off on policies, and organizational risk-aversion around security creates strong friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | Security and compliance documentation often requires sign-off by authorized personnel and audit trails, creating moderate organizational and regulatory friction against pure automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI-assisted drafting reduces initial documentation work, but the coordination function—scheduling reviews, reconciling stakeholder feedback, ensuring compliance—still requires human labor that dominates total cost, making the combined cost similar to or higher than human-only approaches. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI can cheaply generate drafts and templates, but the coordination, review, and validation work still requires paid human time, so overall cost savings are moderate rather than dramatic. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed products reliably handle the full coordination task end-to-end; LLMs can assist with drafting but cannot independently coordinate across teams, validate policy alignment with standards, or ensure organizational consensus without significant human oversight. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | LLM tools are used to help draft security documentation, but no deployed product reliably 'coordinates' the cross-team process of gathering, validating, and finalizing security/emergency policy documentation at scale. |
Coordinate vulnerability assessments or analysis of information security systems.
32CI 28–37 · exposure 30 · augmentation 75 · importance 3.8/5 · click for rater detail
Coordinate vulnerability assessments or analysis of information security systems.
32| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security teams widely use automated scanning tools, but coordination of assessments remains human-driven. Adoption is uneven: large enterprises integrate AI-assisted scanning into workflows, but end-to-end autonomous coordination is rare; most organizations remain in pilot or partial-automation phases. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity as a field has moderate AI tool adoption (automated scanning, some AI-assisted triage) but coordination and strategic oversight functions remain largely human-driven in most organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI-powered vulnerability scanners, risk scoring, report generation, and remediation recommendations significantly amplify security engineer productivity by automating routine scanning and triaging, allowing engineers to focus on strategy and high-touch investigation. Assistive tools demonstrably improve speed and coverage when humans remain in the loop. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly aids vulnerability discovery, report generation, and prioritization scoring, meaningfully speeding up the work of security engineers who coordinate assessments. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Current AI can assist in scanning for known vulnerabilities and generating reports, but cannot autonomously design comprehensive assessment strategies, interpret complex business contexts, or make end-to-end risk trade-offs that meet the 50% time-saving threshold. Human expertise is still required for vulnerability prioritization, remediation planning, and validation. |
| Task automatability | claude-sonnet-5 | 2/5 | AI tools can run scans and flag known vulnerabilities, but 'coordinating' assessments involves scoping, prioritization, stakeholder communication, and judgment calls that current AI cannot fully own end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Vulnerability assessment and coordination often require licensed security certifications (CISSP, OSCP, CEH) and internal authorization; findings carry liability and must be signed off by qualified personnel. Regulatory frameworks (SOC 2, ISO 27001, PCI-DSS) typically mandate human expert judgment in assessment planning and validation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement mandates a human, but liability for missed vulnerabilities, compliance frameworks (PCI-DSS, SOC2), and organizational risk tolerance create meaningful friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | While scanning tools have low per-unit costs, the overhead of expert human review, false-positive filtering, and coordination of multi-stage assessments means total cost remains comparable to or slightly cheaper than human assessment, not orders of magnitude cheaper. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | Scanning tools are cheap per-scan, but the coordination task requires skilled human oversight, contextual risk assessment, and cross-team communication that keeps overall costs comparable to human-led processes. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Automated vulnerability scanners and SAST/DAST tools exist in production, but they generate high false-positive rates and require significant human triage and interpretation. No deployed system can coordinate a full vulnerability assessment independently; tools are aids within human-led workflows, not autonomous performers. |
| Technical feasibility today | claude-sonnet-5 | 3/5 | Automated vulnerability scanners (Nessus, Qualys, AI-augmented SAST/DAST tools) are mature and widely deployed, but the coordination and interpretation layer still relies heavily on human security engineers. |
Train staff on, and oversee the use of, information security standards, policies, and best practices.
32CI 28–36 · exposure 25 · augmentation 75 · importance 4.3/5 · click for rater detail
Train staff on, and oversee the use of, information security standards, policies, and best practices.
32| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security teams are moderately digitized and early-to-middle in AI adoption for content generation and anomaly detection, but actual displacement of training leadership and policy oversight has been limited; tools like LMS and SIEM are widespread, but human trainers and security officers remain central. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT/security functions in tech-forward firms are adopting AI-assisted training tools at a middling pace, with pilots for phishing simulation and content generation more common than full automation of oversight. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI assistants can significantly augment security engineers by generating policy drafts, creating training scenarios, automating compliance checklists, and summarizing staff assessment data—substantially raising their productivity in content and oversight preparation while the engineer retains judgment on organizational fit and enforcement. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI substantially aids in creating training materials, simulating phishing attacks, and monitoring compliance logs, meaningfully boosting the efficiency of the human overseeing the task. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | AI can help draft training materials and generate security policy documentation, but the core task—training staff on standards and overseeing compliance in real-world organizational contexts—requires understanding nuanced organizational culture, addressing employee questions, assessing comprehension, and adapting messaging. AI cannot reliably replace the supervisory and pedagogical judgment needed for meaningful adoption. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can generate training materials and quizzes, but delivering staff training and ongoing oversight requires human judgment, authority, and interpersonal engagement that current AI cannot replicate end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS) often require documented human accountability for security training and policy oversight; moreover, liability for security breaches attributable to inadequate training or lax enforcement creates organizational and legal barriers to full automation of the supervisory role. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement to deliver security training, but organizational accountability, compliance sign-off, and human oversight expectations create moderate friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Generating training templates and policy documents via AI is cheap, but the full task—delivering live training, measuring comprehension, enforcing policies, and handling exceptions—still requires human oversight. Cost parity is not achieved when human supervision dominates the actual value-delivery. |
| Cost vs. human wage | claude-sonnet-5 | 3/5 | AI-generated training content is cheap, but the oversight and enforcement component still requires human labor, making overall cost roughly comparable rather than dramatically cheaper. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | While AI can generate training content and draft policy materials, no deployed product reliably delivers end-to-end staff training with genuine behavioral change, or comprehensive policy oversight in production. Current systems lack the contextual authority and interactive capability to oversee compliance at organizational scale. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Products exist for security awareness content generation and simulated phishing tests, but no deployed system autonomously trains and oversees staff compliance with policies reliably. |
Identify security system weaknesses, using penetration tests.
30CI 28–32 · exposure 25 · augmentation 75 · importance 4.6/5 · click for rater detail
Identify security system weaknesses, using penetration tests.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security teams increasingly use AI-powered vulnerability scanners and OSINT tools in workflows, but autonomous penetration testing remains rare in production. Adoption of AI assistance is growing, but replacing human testers remains limited due to legal and trust requirements. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity is a fast-moving tech sector with growing AI tool adoption for scanning and triage, but full automation of penetration testing remains in pilot/tool-assisted stages rather than widespread production replacement. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly augments penetration testers through automated reconnaissance, vulnerability scanning, payload generation, and log analysis, allowing human testers to focus on sophisticated attack chains and business-context interpretation. This assistance materially raises tester productivity while keeping humans in control and accountable. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly aids penetration testers by automating reconnaissance, vulnerability scanning, and report generation, allowing human experts to focus on complex exploitation and validation. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Penetration testing requires creativity, contextual judgment, and social engineering that current AI systems cannot fully replicate end-to-end. While AI can assist with vulnerability scanning and some exploitation steps, human testers design attack strategies, interpret findings in business context, and adapt to novel defenses—activities that resist full automation today. |
| Task automatability | claude-sonnet-5 | 2/5 | AI tools can assist with scanning and some exploit suggestion, but full penetration testing requires creative attack chaining, contextual judgment, and adapting to unique environments that current AI cannot reliably do end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Penetration testing faces high legal and contractual barriers: explicit written authorization is required, liability for mistakes is severe (unauthorized access is a crime), and most clients contractually require licensed, accountable humans to perform and sign off on tests. |
| Adoption barriers | claude-sonnet-5 | 3/5 | While not strictly licensed in most jurisdictions, penetration testing often requires contractual authorization, liability considerations, and client trust in human-certified testers (e.g., OSCP, CEH), creating moderate friction. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI-assisted vulnerability scanning tools have low marginal cost, but comprehensive penetration testing still requires licensed security engineers ($100k+ loaded cost) to design, execute, and validate findings. AI reduces time on routine scanning but cannot yet replace the human cost of the full engagement. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI-assisted scanning tools can reduce some labor costs, but comprehensive penetration testing still requires expensive human expertise and oversight to avoid false positives/negatives and legal risk. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No mature product performs comprehensive penetration testing autonomously in production. Tools like vulnerability scanners and OSINT AI exist, but actual penetration testing requires human authorization, legal oversight, and nuanced decision-making about which attacks to execute—making independent AI deployment infeasible at scale. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Deployed products include automated vulnerability scanners and some AI-assisted pentest tools, but they are narrow in scope and still require skilled human testers to interpret results and conduct real exploitation. |
Conduct investigations of information security breaches to identify vulnerabilities and evaluate the damage.
30CI 28–32 · exposure 25 · augmentation 75 · importance 4.2/5 · click for rater detail
Conduct investigations of information security breaches to identify vulnerabilities and evaluate the damage.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Security organizations are adopting AI-assisted tools for detection and triage, but adoption of end-to-end automated investigation remains limited. Most deployments use AI for augmentation rather than replacement, with human-led investigation workflows still dominant. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity is a digitized, fast-moving field with growing AI-assisted SOC tooling, but full investigative automation remains at pilot/augmentation stage rather than deep production replacement. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI augments investigation significantly through automated log parsing, anomaly detection, threat correlation, and preliminary vulnerability scanning, materially accelerating human investigators' work. The human expert remains essential for judgment and accountability, but AI substantially raises investigator productivity. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly boosts investigator productivity by summarizing logs, correlating alerts, flagging anomalies, and drafting incident reports, while the human retains judgment over root cause and impact assessment. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with log analysis, pattern detection, and initial triage of security breaches, the task requires significant human judgment to interpret context, evaluate business impact, and determine root causes. Current systems cannot reliably conduct end-to-end investigations meeting the 50% time-saving threshold without expert human oversight and decision-making. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can assist with log analysis, anomaly detection, and pattern matching, but full breach investigation requires contextual judgment, correlation across disparate systems, and interpretation of ambiguous evidence that current AI cannot reliably do end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Legal and regulatory requirements (compliance reporting, chain of custody, forensic standards) often mandate human experts and documented accountability. Industry practice and liability concerns create strong organizational friction against full automation of breach investigations. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing requirement mandates a human specifically, but liability, chain-of-custody/forensic evidentiary standards, and organizational risk tolerance create meaningful friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Security engineers command high salaries ($100k+), and current AI tooling still requires substantial human oversight, integration effort, and validation. The all-in cost of AI-assisted investigation approaches human labor costs rather than achieving significant savings due to expertise requirements. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools reduce some analyst hours (log triage, alert correlation) but the overall investigation still requires substantial skilled human time, so total cost savings are moderate rather than an order of magnitude. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Products exist for automated threat detection and log analysis (e.g., SIEM tools with ML), but they operate as assistants rather than autonomous investigators. Reliable end-to-end breach investigation requiring vulnerability assessment and damage evaluation remains dependent on skilled human analysts; no product performs this task reliably in production without significant human input. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Deployed SIEM/SOAR tools with AI features exist and assist analysts, but no product autonomously conducts full breach investigations reliably; human security engineers still drive the process. |
Identify or implement solutions to information security problems.
30CI 28–32 · exposure 25 · augmentation 75 · importance 3.9/5 · click for rater detail
Identify or implement solutions to information security problems.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security organizations are actively piloting AI-assisted threat detection and vulnerability management, but production deployment of AI-driven security solution implementation remains limited. Adoption is faster in detection than in remediation. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity is a moderately fast-adopting tech-forward field with growing AI-assisted tooling (e.g., AI-driven threat detection), but full automation of solution design and implementation remains at the pilot stage in most organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI substantially augments security engineers by automating log analysis, generating prioritized vulnerability reports, and suggesting remediation steps, allowing engineers to focus on strategic decisions and complex incidents. This human-in-the-loop assistance meaningfully raises productivity. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly augments this task by accelerating vulnerability identification, threat intelligence synthesis, and drafting remediation steps, while engineers retain responsibility for validation and implementation decisions. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Current AI can assist in identifying some security problems through pattern matching and detection (e.g., flagging anomalous logs), but implementing solutions at scale requires domain expertise, architectural judgment, and accountability that AI cannot reliably provide end-to-end. The task is too context-dependent and consequences-heavy for 50% time savings at equal quality with off-the-shelf systems. |
| Task automatability | claude-sonnet-5 | 2/5 | Diagnosing and implementing security solutions requires contextual judgment about specific systems, threat models, and business tradeoffs that current AI cannot reliably handle end-to-end; AI can assist with sub-parts like log analysis or patch suggestions but not the full identify-and-implement cycle. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Information security has strong regulatory and liability barriers: security decisions often fall under compliance regimes (SOC 2, HIPAA, PCI-DSS), and liability for a breach traceable to an AI-recommended misconfiguration creates asymmetric error costs. Organizations demand human accountability for security architecture and implementation choices. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement for this task, but organizational risk tolerance, compliance frameworks, and liability for security failures create meaningful friction against fully automating decision-making and implementation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Current security-focused AI tools (SIEM enhancement, vulnerability scanning) cost significant licensing and integration fees; combined with the human oversight required to validate and implement recommendations, all-in costs remain high relative to the specialized engineer wage. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI tools reduce some analyst time but still require expensive human security engineers to verify and implement solutions, so all-in cost savings versus a human engineer are modest rather than order-of-magnitude. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | While security scanning and threat detection tools exist and are deployed, they identify problems more reliably than they implement solutions. Implementation requires deciding between competing architectures, testing, rollback planning, and stakeholder sign-off—areas where AI products remain immature and error-prone in production settings. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Deployed security copilots and SIEM-integrated AI tools exist and help triage alerts or suggest fixes, but reliable autonomous identification and implementation of security solutions in production is narrow and error-prone, requiring human validation. |
Recommend information security enhancements to management.
30CI 28–32 · exposure 25 · augmentation 75 · importance 3.9/5 · click for rater detail
Recommend information security enhancements to management.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security is digitized and early-adopting of AI tools, but augmentation (AI-assisted recommendations reviewed by humans) is common, while displacement of the recommendation role itself remains rare in production environments. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity is a fast-adopting professional services-adjacent field with many AI-assisted tools (vulnerability scanners, threat intel summarization) in pilot and some production use, though full recommendation authorship remains human-led. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI excels at summarizing vulnerability data, mapping threat landscapes, and drafting initial recommendations, significantly boosting the speed and coverage of a security engineer's analysis while the engineer retains oversight and final judgment. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can significantly assist by analyzing logs, benchmarking against frameworks like NIST, drafting reports, and summarizing threat intelligence, substantially speeding up the engineer's preparation of recommendations. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can generate security recommendations based on vulnerability scans and threat intelligence, synthesizing contextual business constraints, legacy systems, and organizational risk appetite requires human judgment that current AI cannot reliably perform end-to-end with 50% time savings at equal quality. |
| Task automatability | claude-sonnet-5 | 2/5 | Recommending security enhancements requires synthesizing organizational context, risk tolerance, budget constraints, and political factors that AI cannot fully assess or own end-to-end today.think generate draft lists of recommendations but the judgment-heavy, context-specific synthesis and stakeholder-aware framing limits full automation. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Organizations are typically liable for the security recommendations they act on; recommending changes without a qualified human security engineer's sign-off creates legal and compliance risk, making human accountability a strong barrier to full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No strict licensing requirement mandates a human make these recommendations, but liability, trust, and organizational accountability structures create meaningful friction against fully AI-generated advice reaching management unchecked. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Current AI tools (vulnerability scanners with recommendation engines, LLMs for drafting) are still cheaper per task than senior security engineers, but the output quality gap means human engineers must substantially rework and validate recommendations, reducing the effective cost advantage. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While AI-assisted drafting is cheap, the human security engineer's contextual analysis, stakeholder communication, and accountability for the recommendation still dominate the cost, so overall savings are modest. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed product reliably generates strategic security recommendations that management would act on without significant human expert review; AI can assist with data collection and initial frameworks, but the decision-critical synthesis and business-context fitting remain manual. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | AI tools can generate generic security recommendations from scans or frameworks, but no deployed product reliably produces context-aware, organization-specific recommendations that management would accept without heavy human review. |
Troubleshoot security and network problems.
30CI 28–32 · exposure 30 · augmentation 75 · importance 3.7/5 · click for rater detail
Troubleshoot security and network problems.
30| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Enterprise security teams are experimenting with AI-assisted threat detection and automation, but adoption remains cautious due to the critical nature of security work and lingering concerns about false negatives. Most deployments are augmentative rather than replacement-oriented. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | IT/security is a moderately fast-adopting sector for AI copilots and anomaly detection, but full automation of hands-on troubleshooting remains at the pilot stage in most organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI significantly augments security engineers through automated log analysis, anomaly detection, correlation of disparate signals, and guided investigation workflows. These tools substantially accelerate diagnosis when engineers remain in control and interpret results. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI tools significantly help by summarizing logs, flagging anomalies, suggesting root causes, and referencing documentation, substantially speeding up an engineer's troubleshooting workflow. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | Troubleshooting security and network problems requires complex diagnosis combining multiple data sources, pattern recognition, and contextual judgment. While AI can assist in log analysis and anomaly detection, current systems struggle with novel attack vectors and require significant human expertise to validate findings and determine root causes. |
| Task automatability | claude-sonnet-5 | 2/5 | Troubleshooting security and network issues requires diagnosing novel, context-specific problems across live systems, correlating logs, and making judgment calls that current AI cannot reliably do end-to-end without heavy human oversight. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Security decisions carry substantial liability and error costs; regulatory frameworks (HIPAA, SOC 2, PCI-DSS) often require human security professionals to authenticate and sign off on remediation decisions. Organizations face legal and compliance pressure to maintain human oversight. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security incident response often has compliance, liability, and audit requirements mandating qualified human sign-off, and errors in security troubleshooting carry high consequences, creating strong barriers to full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | Specialized security infrastructure (SIEM, threat intelligence platforms) carries significant ongoing costs, and human security engineers remain essential for validation and decision-making, making the combined cost still higher than automation savings. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | Deploying and maintaining AI-assisted security tooling plus the required human oversight for validation and remediation still costs comparably to or more than existing engineer time for complex troubleshooting. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 3/5 | Products like SIEM systems with AI-assisted alerting and automated anomaly detection exist in production, but they generate substantial false positives and require expert human review. No system reliably performs end-to-end troubleshooting without human intervention. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | AI-driven anomaly detection and log analysis tools exist in SIEM/SOAR products, but they narrowly assist detection rather than perform full troubleshooting reliably in production without engineer intervention. |
Develop response and recovery strategies for security breaches.
29CI 25–32 · exposure 25 · augmentation 63 · importance 4.3/5 · click for rater detail
Develop response and recovery strategies for security breaches.
29| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | While information security is digitized, actual adoption of AI for strategic breach response planning remains limited to tactical incident handling aids; most organizations still rely on human-led strategy development and incident response playbooks. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Cybersecurity is a digitized, fast-moving field with growing AI tool adoption (e.g., AI-assisted SOC tools), but strategic planning tasks still see more pilots than full production reliance. |
| Augmentation potential | claude-haiku-4-5-20251001 | 3/5 | AI can assist security engineers by analyzing breach data, suggesting remediation patterns, and drafting response components, thereby raising productivity; however, human expertise must remain central to strategy formulation and organizational decision-making. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI can meaningfully assist by drafting incident response templates, summarizing threat intelligence, and suggesting recovery steps, significantly speeding up the human-led strategy development process. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist with analysis of breach patterns and generate boilerplate recovery procedures, the task requires substantial human judgment about organizational context, risk prioritization, and strategic decisions that current AI systems cannot handle end-to-end with 50% time savings at equal quality. |
| Task automatability | claude-sonnet-5 | 2/5 | Developing incident response and recovery strategies requires contextual judgment about business risk, systems architecture, and organizational priorities that current AI cannot fully replicate end-to-end.rate what current, generally available AI systems can do today |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong barriers exist: liability and legal exposure are asymmetric (AI errors in breach response can compound damage), regulatory requirements often mandate qualified human judgment, and organizations retain explicit accountability for breach response strategies that resist full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | No licensing mandates a human specifically, but liability for breach response failures, regulatory compliance (e.g., data breach notification laws), and organizational risk tolerance create meaningful friction against full automation. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI tools for security analysis are expensive and require significant human oversight, integration, and validation—meaning the all-in cost remains comparable to or higher than hiring experienced security professionals for strategy development. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can draft frameworks quickly but requires significant expert oversight and validation, so overall cost savings versus a skilled engineer are modest rather than order-of-magnitude. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | No deployed products reliably perform comprehensive breach response and recovery strategy development autonomously; security orchestration tools exist for tactical incident response but lack the strategic, contextual decision-making required for this task in production environments. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Some products offer playbook generation and SOAR automation suggestions, but strategic response and recovery planning still relies heavily on human security architects reviewing and customizing outputs. |
Oversee performance of risk assessment or execution of system tests to ensure the functioning of data processing activities or security measures.
29CI 25–32 · exposure 25 · augmentation 75 · importance 3.9/5 · click for rater detail
Oversee performance of risk assessment or execution of system tests to ensure the functioning of data processing activities or security measures.
29| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 2/5 | While security engineering is digitized, adoption of AI for autonomous oversight of risk assessment and test execution remains limited and cautious. Organizations pilot AI-assisted analysis but retain human engineers as decision-makers and sign-off authority, slowing deep adoption. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Information security is a digitized, fast-moving field with growing AI tool adoption (SOAR, AI-driven SIEM), but full oversight automation remains at the pilot stage in most organizations. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI demonstrably augments security engineers by automating test generation, scanning logs for anomalies, flagging patterns, and generating draft reports. Engineers remain in the loop for interpretation, prioritization, and sign-off, with substantial productivity gains on the analytical portions of the task. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly assists by automating parts of test execution, log analysis, and vulnerability detection, allowing engineers to focus oversight effort more efficiently while remaining in the loop. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist in generating test scripts and flagging anomalies in security logs, the core task of overseeing and ensuring proper execution of risk assessments requires contextual judgment, exception handling, and accountability that current AI cannot fully replicate at 50% time savings. Human oversight remains essential for interpretation and sign-off. |
| Task automatability | claude-sonnet-5 | 2/5 | This task centers on oversight and judgment across risk assessment and test execution, which requires contextual understanding of business risk and human accountability that current AI cannot fully replace end-to-end.ract |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS) typically require documented human responsibility for security test oversight and sign-off. Liability asymmetry is high: an AI failure in security testing can cascade into breach liability, creating legal and organizational friction against full automation. |
| Adoption barriers | claude-sonnet-5 | 3/5 | Security oversight often involves compliance obligations, audit trails, and accountability structures that push organizations to keep humans formally responsible, though not always requiring specific licensure. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI-driven security testing tools exist but require significant expert human oversight, integration, and validation work. The total cost of AI infrastructure plus mandatory human review approaches or exceeds the cost of direct human execution, particularly for high-stakes environments. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | While automated scanning tools reduce some labor costs, the oversight and judgment components still require a skilled engineer, so the all-in cost of an AI-augmented process is not dramatically cheaper than a human-led one. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Some products assist with vulnerability scanning and test report generation, but no deployed system reliably oversees the *execution* and *performance* of security tests end-to-end with the rigor required in production environments. Benchmark demonstrations exist, but production-scale automation of this oversight function is rare. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | AI-assisted vulnerability scanners and automated test frameworks exist and are deployed, but the 'oversight' function—interpreting results and validating that security measures function correctly—remains a human-led activity in production environments. |
Develop or install software, such as firewalls and data encryption programs, to protect sensitive information.
28CI 28–28 · exposure 25 · augmentation 75 · importance 4.1/5 · click for rater detail
Develop or install software, such as firewalls and data encryption programs, to protect sensitive information.
28| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security teams are adopting AI-assisted scanning and analysis tools, but adoption of autonomous security software development/installation remains limited due to risk aversion, regulatory constraints, and the mission-critical nature of security infrastructure. Pilots exist but production replacement is rare. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Tech/security sectors are moderately fast adopters of AI-assisted coding tools, but core security architecture decisions remain largely human-driven with cautious rollout given risk sensitivity. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI meaningfully augments security engineers through automated vulnerability detection, policy suggestions, encryption best-practice guidance, and code review assistance, substantially accelerating their work while they retain control over architectural and deployment decisions. This is an area of proven AI productivity gains in practice. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI coding assistants and security-specific tools meaningfully speed up writing configuration code, drafting policies, and identifying known vulnerabilities, aiding engineers substantially. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While routine deployment of standard firewall and encryption tools can be partially automated, developing or installing security software requires significant architectural decisions, threat assessment, and integration with existing systems that demand human expertise and contextual judgment. Current AI cannot reliably perform the full decision chain for enterprise security infrastructure. |
| Task automatability | claude-sonnet-5 | 2/5 | AI can help write configuration scripts or generate code snippets for encryption/firewall setups, but selecting architecture, integrating with existing infrastructure, and validating security posture still requires substantial human engineering judgment and testing. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Strong regulatory (SOC 2, HIPAA, PCI-DSS, FedRAMP) and organizational barriers require human sign-off on security controls, and liability for breaches creates high error costs that discourage full automation. Compliance audits typically mandate documented human responsibility for security infrastructure decisions. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Security-critical infrastructure changes typically require sign-off, compliance audits, and accountability from certified professionals due to high liability from misconfiguration or breaches. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | The specialized expertise, liability, and compliance requirements mean human security engineers remain significantly cheaper on a cost-per-successful-deployment basis than AI-driven solutions when accounting for setup, customization, testing, and ongoing oversight needed to catch errors. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | AI can reduce drafting time for scripts/configs but human security engineers must still validate, test, and deploy, so overall labor cost savings are modest rather than order-of-magnitude. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | Deployed products exist for automated vulnerability scanning and policy-based firewall rule generation, but these operate within narrow scopes and still require security engineers to validate, customize, and approve deployments. No production systems reliably handle end-to-end security software development or installation without substantial human oversight. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | Copilot-style tools assist with code generation and config templates, but no deployed product autonomously develops or installs full firewall/encryption systems end-to-end in production without expert oversight. |
Oversee development of plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure or to meet emergency data processing needs.
28CI 28–28 · exposure 25 · augmentation 75 · importance 4.1/5 · click for rater detail
Oversee development of plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure or to meet emergency data processing needs.
28| Dimension | Model | Rating | Rationale |
|---|---|---|---|
| Sector adoption velocity | claude-haiku-4-5-20251001 | 3/5 | Information security teams are moderately digitizing their workflows with AI-assisted tools for threat detection and policy drafting, but actual plan oversight remains human-centric in most organizations. Pilot adoption of AI co-pilots for security engineering is growing, but production-level replacement of oversight roles remains limited due to liability and regulatory concerns. |
| Sector adoption velocity | claude-sonnet-5 | 3/5 | Information security is a digitized, fast-moving field with growing AI tool adoption for threat detection and drafting, but oversight/governance roles still see slower AI penetration than technical execution tasks. |
| Augmentation potential | claude-haiku-4-5-20251001 | 4/5 | AI can substantially augment security engineers by automating threat modeling, generating policy templates, identifying regulatory gaps, and analyzing logs—all while the engineer retains final decision authority. These capabilities meaningfully accelerate the planning process and reduce manual research, enabling engineers to focus on strategic risk assessment and organizational alignment. |
| Augmentation potential | claude-sonnet-5 | 4/5 | AI significantly aids by drafting policy language, generating risk scenarios, summarizing compliance requirements, and suggesting emergency data processing procedures, boosting the engineer's efficiency substantially. |
| Task automatability | claude-haiku-4-5-20251001 | 2/5 | While AI can assist in drafting security plans and identifying common vulnerabilities, oversight of plan development requires strategic judgment about organizational risk tolerance, regulatory context, and emerging threat landscapes that current systems cannot reliably do end-to-end. The task inherently involves human decision-making about trade-offs between security, usability, and cost that AI cannot autonomously perform at acceptable quality. |
| Task automatability | claude-sonnet-5 | 2/5 | This is an oversight and planning task requiring judgment, organizational context, and accountability; AI can draft policy templates but cannot own or lead the strategic planning process end-to-end. |
| Adoption barriers | claude-haiku-4-5-20251001 | 4/5 | Regulatory frameworks (HIPAA, SOX, PCI-DSS, GDPR) and liability standards often require that qualified security engineers personally oversee and sign off on safeguarding plans, creating legal accountability barriers. Many organizations also have compliance requirements that explicitly mandate human security professional involvement in plan development and oversight. |
| Adoption barriers | claude-sonnet-5 | 4/5 | Data protection regulations, compliance frameworks, and organizational liability typically require a designated accountable human (often certified/licensed) to oversee such plans. |
| Cost vs. human wage | claude-haiku-4-5-20251001 | 2/5 | AI assistance for security planning (threat modeling, policy generation) is relatively expensive due to integration costs and necessary human oversight, while the task's high stakes demand expert human judgment that cannot be fully substituted. The cost of errors in security oversight is prohibitively high, making the all-in cost of AI-only approaches uneconomical compared to human engineers. |
| Cost vs. human wage | claude-sonnet-5 | 2/5 | Human oversight, stakeholder coordination, and accountability for these plans remain necessary, so AI reduces drafting time but doesn't substantially replace the human cost of oversight and sign-off. |
| Technical feasibility today | claude-haiku-4-5-20251001 | 2/5 | AI tools exist for vulnerability scanning and security policy templates, but no deployed product can independently oversee the full scope of safeguarding plan development with the accountability and contextual judgment this role demands. Existing security tools require substantial human oversight and cannot replace the engineer's responsibility for plan quality and legal compliance. |
| Technical feasibility today | claude-sonnet-5 | 2/5 | AI tools assist with drafting security policies, risk assessments, and DR plans, but no deployed product independently oversees or manages development of such safeguarding plans in production. |
Related occupations — Computer & Mathematical
How to read this
A high substitution score does not mean this job disappears — it means a large share of its current tasks face replacement pressure, so the mix of tasks is likely to change. High augmentation alongside substitution typically means the occupation reorganizes around the protected tasks. Wide confidence intervals mean the rater panel disagreed: treat those scores as open questions, not verdicts.
What would change this score
New model capabilities (automatability, feasibility), falling inference costs (cost ratio), regulation and licensing shifts (barriers), and measured sector adoption (velocity) all re-enter at every index release. Each release is recomputed, versioned and kept queryable — scores are claims with a date on them, not permanent labels.