The Task Exposure Indexv2026.Q3
Occupation · SOC 15-1299.04 · Job Zone 4

AI exposure: Penetration Testers

Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.

Reading this score

computed

51.9% of this occupation's weighted task load is exposed, which puts Penetration Testers at the 90th percentile of 923 occupations. The capability is largely there. Its average task scores 3.1 out of 4 on what a current system can produce, and the frictions that hold other jobs in place are comparatively weak here.

What holds the line here is context. Across this occupation's 22 tasks it averages 1.91 out of 3, the highest of the five friction dimensions. In plain terms, the work depends on knowledge the model cannot hold. Much of this job runs on things that were never written down: what this particular organisation does, what happened last week, what the person across the table actually meant. That context is the barrier, and it erodes as systems are given more access.

The most exposed thing this job does is Gather cyber intelligence to identify vulnerabilities, at 93.3%. The least is Identify new threat tactics, techniques, or procedures used by cyber threat actors, at 10.0%. A gap of 83.3% between two parts of the same job is the reason this index publishes at task level. An occupation-wide number would have hidden both.

Within computer and mathematical occupations, this one is less exposed than the median of 57.8% across the group's 36 roles, with 25 scoring higher. Being in an exposed family does not make a particular job exposed, and the reverse holds too.

What would move this score. Of 22 tasks, 19 are currently banded exposed, 3 assisted and 0 untouched. For that distribution to shift materially would take cheaper ways to verify output, since the cost of checking is currently doing more to hold this work in place than the cost of producing it. The score is re-computed every quarter against a fresh capability reference, and the change is published rather than quietly applied.

Task by task

22 tasks, O*NET 31.0
TaskExposedAssistedUntouchedImportanceBand
Gather cyber intelligence to identify vulnerabilities.93.3%6.7%0.0%4.56exposed
Document penetration test findings.73.3%26.7%0.0%4.84exposed
Write audit reports to communicate technical and procedural findings and recommend solutions.73.3%26.7%0.0%4.58exposed
Prepare and submit reports describing the results of security fixes.73.3%26.7%0.0%4.11exposed
Develop presentations on threat intelligence.73.3%26.7%0.0%3.33exposed
Maintain up-to-date knowledge of hacking trends.65.0%10.0%25.0%4.53exposed
Keep up with new penetration testing tools and methods.65.0%10.0%25.0%4.47exposed
Test the security of systems by attempting to gain access to networks, Web-based applications, or computers.50.0%25.0%25.0%4.37exposed
Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters.50.0%25.0%25.0%3.89exposed
Design security solutions to address known device vulnerabilities.50.0%25.0%25.0%3.75exposed
Configure information systems to incorporate principles of least functionality and least access.50.0%25.0%25.0%3.40exposed
Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests.45.0%30.0%25.0%4.37exposed
Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries.45.0%30.0%25.0%4.32exposed
Discuss security solutions with information technology teams or management.45.0%30.0%25.0%4.05exposed
Collect stakeholder data to evaluate risk and to develop mitigation strategies.45.0%30.0%25.0%3.94exposed
Develop infiltration tests that exploit device vulnerabilities.45.0%30.0%25.0%3.84exposed
Identify security system weaknesses, using penetration tests.40.0%35.0%25.0%4.74exposed
Conduct network and security system audits, using established criteria.40.0%35.0%25.0%4.39exposed
Update corporate policies to improve cyber security.40.0%35.0%25.0%3.93exposed
Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis.35.0%40.0%25.0%3.88assisted
Develop and execute tests that simulate the techniques of known cyber threat actors.23.3%26.7%50.0%4.06assisted
Identify new threat tactics, techniques, or procedures used by cyber threat actors.10.0%40.0%50.0%4.42assisted

Task text and importance ratings sourced from O*NET 31.0. Shares computed. The occupation score is the importance-weighted mean.

Where the score comes from

judged

Every task is scored through the standardised work activities it maps to. These are this occupation’s averages on the six rubric dimensions. Capability is what AI can do; the other five are what stands in the way.

DimensionMeanScale
Capability3.140-4
Embodiment0.360-3
Presence0.300-3
Accountability1.200-3
Context1.910-3
Verification cost1.680-3

What this means in practice

Where most of a role's weighted task load is exposed, the work that survives is usually the part of the job nobody wrote into the job description: deciding what should be produced rather than producing it, and being answerable for the result. The tasks lowest on this page are a better guide to where to spend your time than any general advice about the future of work.

Occupations either side of this one

The four closest scores in the same occupational family, then the four closest anywhere in the index.

Read this carefully. Exposure is not displacement. A high score means current AI systems can produce this work, not that anyone will stop paying a person to do it. Adoption depends on economics, regulation and inertia that this index deliberately does not model. How the score is built.