AI exposure: Information Security Analysts
Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.
Reading this score
computed47.4% of this occupation's weighted task load is exposed, which puts Information Security Analysts at the 86th percentile of 923 occupations. The capability is largely there. Its average task scores 3.0 out of 4 on what a current system can produce, and the frictions that hold other jobs in place are comparatively weak here.
What holds the line here is context. Across this occupation's 11 tasks it averages 1.91 out of 3, the highest of the five friction dimensions. In plain terms, the work depends on knowledge the model cannot hold. Much of this job runs on things that were never written down: what this particular organisation does, what happened last week, what the person across the table actually meant. That context is the barrier, and it erodes as systems are given more access.
The most exposed thing this job does is Document computer security and emergency measures policies, procedures, and tests, at 73.3%. The least is Coordinate implementation of computer system plan with establishment personnel and outside..., at 26.7%. A gap of 46.7% between two parts of the same job is the reason this index publishes at task level. An occupation-wide number would have hidden both.
Within computer and mathematical occupations, this one is less exposed than the median of 57.8% across the group's 36 roles, with 31 scoring higher. Being in an exposed family does not make a particular job exposed, and the reverse holds too.
What would move this score. Of 11 tasks, 8 are currently banded exposed, 3 assisted and 0 untouched. For that distribution to shift materially would take cheaper ways to verify output, since the cost of checking is currently doing more to hold this work in place than the cost of producing it. The score is re-computed every quarter against a fresh capability reference, and the change is published rather than quietly applied.
Task by task
11 tasks, O*NET 31.0| Task | Exposed | Assisted | Untouched | Importance | Band |
|---|---|---|---|---|---|
| Document computer security and emergency measures policies, procedures, and tests. | 73.3% | 26.7% | 0.0% | 3.94 | exposed |
| Monitor current reports of computer viruses to determine when to update virus protection systems. | 65.0% | 10.0% | 25.0% | 4.23 | exposed |
| Train users and promote security awareness to ensure system security and to improve server and network efficiency. | 55.0% | 20.0% | 25.0% | 3.81 | exposed |
| Develop plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure and to meet emergency data processing needs. | 50.0% | 25.0% | 25.0% | 4.40 | exposed |
| Perform risk assessments and execute tests of data processing system to ensure functioning of data processing activities and security measures. | 50.0% | 25.0% | 25.0% | 4.12 | exposed |
| Confer with users to discuss issues such as computer data access needs, security violations, and programming changes. | 50.0% | 25.0% | 25.0% | 3.94 | exposed |
| Monitor use of data files and regulate access to safeguard information in computer files. | 40.0% | 35.0% | 25.0% | 3.89 | exposed |
| Encrypt data transmissions and erect firewalls to conceal confidential information as it is being transmitted and to keep out tainted digital transfers. | 35.0% | 40.0% | 25.0% | 4.18 | assisted |
| Modify computer security files to incorporate new software, correct errors, or change individual access status. | 35.0% | 40.0% | 25.0% | 4.10 | assisted |
| Review violations of computer security procedures and discuss procedures with violators to ensure violations are not repeated. | 35.0% | 40.0% | 25.0% | 4.04 | assisted |
| Coordinate implementation of computer system plan with establishment personnel and outside vendors. | 26.7% | 23.3% | 50.0% | 3.87 | exposed |
Task text and importance ratings sourced from O*NET 31.0. Shares computed. The occupation score is the importance-weighted mean.
Where the score comes from
judgedEvery task is scored through the standardised work activities it maps to. These are this occupation’s averages on the six rubric dimensions. Capability is what AI can do; the other five are what stands in the way.
| Dimension | Mean | Scale |
|---|---|---|
| Capability | 3.00 | 0-4 |
| Embodiment | 0.50 | 0-3 |
| Presence | 0.32 | 0-3 |
| Accountability | 1.18 | 0-3 |
| Context | 1.91 | 0-3 |
| Verification cost | 1.82 | 0-3 |
What this means in practice
Where most of a role's weighted task load is exposed, the work that survives is usually the part of the job nobody wrote into the job description: deciding what should be produced rather than producing it, and being answerable for the result. The tasks lowest on this page are a better guide to where to spend your time than any general advice about the future of work.
Occupations either side of this one
The four closest scores in the same occupational family, then the four closest anywhere in the index.
Read this carefully. Exposure is not displacement. A high score means current AI systems can produce this work, not that anyone will stop paying a person to do it. Adoption depends on economics, regulation and inertia that this index deliberately does not model. How the score is built.