Will AI replace Information Security Analysts?
Computer and Mathematical · O*NET 15-1212.00
Task exposure index for this occupation
Averaged across the week, this work sits at the high end of the exposure scale. O*NET breaks Information Security Analysts into 10 distinct work activities. Weighted by how much of the week each one takes, 60% of the job sits at or above the threshold where current systems can do the task end to end. The single largest contributor is "Implement security measures for computer or information systems", which scores 90 and takes roughly 26% of the week. That is the average for the job title. It is not a measurement of any particular person’s week, and the difference between the two is usually larger than the difference between job titles.
Model v1.2 · activity indices last updated 18 August 2026
What this occupation does
Plan, implement, upgrade, or monitor security measures for the protection of computer networks and information. Assess system vulnerabilities for security risks and propose and implement risk mitigation strategies. May ensure appropriate security controls are in place that will safeguard digital files and vital electronic infrastructure. May respond to computer security breaches and viruses.
The most exposed parts of the job
Scored 0–100 on how completely a current system could perform the activity.
- Document operational procedures.95
About 10% of a typical week
- Implement security measures for computer or information systems.90
About 26% of a typical week
- Troubleshoot issues with computer applications or systems.90
About 5% of a typical week
- Develop computer or information security policies or procedures.72
About 11% of a typical week
- Update knowledge about emerging industry or technology trends.66
About 9% of a typical week
The least exposed parts
The same scale. These are the activities current systems handle worst.
- Coordinate project activities with other personnel or departments.26
About 8% of a typical week
- Collaborate with others to resolve information technology issues.36
About 5% of a typical week
- Monitor the security of digital information.48
About 9% of a typical week
- Train others in computer interface or software use.50
About 9% of a typical week
- Test computer system operations to ensure proper functioning.50
About 9% of a typical week
How far off the rest is
Of those 10 activities, 4 can be performed by systems available today and 1 are outside what current approaches do at all. The remaining 5 sit in between — demonstrated in research or in narrow products, but not something you can hand over whole. We do not put dates on that middle group, because nobody can.
Compared with similar occupations
The nearest scoring roles in Computer and Mathematical.
- Information Security Analysts (this page)68
- Geographic Information Systems Technologists and Technicians68
- Database Administrators68
- Network and Computer Systems Administrators67
Why your own number is different
Two people with the title "Information Security Analysts" can spend their weeks on almost entirely different parts of this list, and the parts they choose move the number far more than the title does. Who signs off when the work is wrong, whether the job needs you physically present, and how fast you have picked up the tools all change it again — and none of that is in an occupation average.
The assessment asks you to divide your own week across these activities and answer fourteen questions about the parts of the job an occupation average cannot see. It takes six to nine minutes.
Score my own roleFree to take. The full report is a paid subscription — the price and its terms are on the pricing section, before you start.
Questions
Will AI replace Information Security Analysts?
We do not answer that, because nobody can. What is measurable is how much of the work is already doable by machine: for Information Security Analysts, about 60% of a typical week, across 10 activities. The other 40% is not, and what happens to the job depends on things this index does not contain — cost, regulation, who carries the liability, and what the people doing it decide to do next.
What part of this job is most exposed?
"Document operational procedures" — it scores 95 out of 100 on task automatability and takes roughly 10% of the week.
What part is least exposed?
"Coordinate project activities with other personnel or departments", at 26 out of 100. Work like that is where the hours you protect tend to be worth the most.
Where do these numbers come from?
The activity list and the time weights come from O*NET 30.3, the US Department of Labor's occupational database. The exposure score for each activity is ours, from a published model — the weights, the priors and the limitations are all on the methodology page. No language model is involved in the arithmetic.
Does this apply to my job?
Only roughly. This is the average for the title, and the number that matters is the one for the week you actually work. The assessment asks you to divide your own time across these activities and answer fourteen questions about accountability, the parts of the job that need you specifically, and how fast you have adapted. That produces a different number, and usually a more useful one.
The full model — the weights, the priors and what it cannot see — is on the methodology page.