AI exposure: Penetration Testers
Evaluate network system security by conducting simulated internal and external cyberattacks using adversary tools and techniques. Attempt to breach and exploit critical systems and gain access to sensitive information to assess system security.
Reading this score
computed51.9% of this occupation's weighted task load is exposed, which puts Penetration Testers at the 90th percentile of 923 occupations. The capability is largely there. Its average task scores 3.1 out of 4 on what a current system can produce, and the frictions that hold other jobs in place are comparatively weak here.
What holds the line here is context. Across this occupation's 22 tasks it averages 1.91 out of 3, the highest of the five friction dimensions. In plain terms, the work depends on knowledge the model cannot hold. Much of this job runs on things that were never written down: what this particular organisation does, what happened last week, what the person across the table actually meant. That context is the barrier, and it erodes as systems are given more access.
The most exposed thing this job does is Gather cyber intelligence to identify vulnerabilities, at 93.3%. The least is Identify new threat tactics, techniques, or procedures used by cyber threat actors, at 10.0%. A gap of 83.3% between two parts of the same job is the reason this index publishes at task level. An occupation-wide number would have hidden both.
Within computer and mathematical occupations, this one is less exposed than the median of 57.8% across the group's 36 roles, with 25 scoring higher. Being in an exposed family does not make a particular job exposed, and the reverse holds too.
What would move this score. Of 22 tasks, 19 are currently banded exposed, 3 assisted and 0 untouched. For that distribution to shift materially would take cheaper ways to verify output, since the cost of checking is currently doing more to hold this work in place than the cost of producing it. The score is re-computed every quarter against a fresh capability reference, and the change is published rather than quietly applied.
Task by task
22 tasks, O*NET 31.0| Task | Exposed | Assisted | Untouched | Importance | Band |
|---|---|---|---|---|---|
| Gather cyber intelligence to identify vulnerabilities. | 93.3% | 6.7% | 0.0% | 4.56 | exposed |
| Document penetration test findings. | 73.3% | 26.7% | 0.0% | 4.84 | exposed |
| Write audit reports to communicate technical and procedural findings and recommend solutions. | 73.3% | 26.7% | 0.0% | 4.58 | exposed |
| Prepare and submit reports describing the results of security fixes. | 73.3% | 26.7% | 0.0% | 4.11 | exposed |
| Develop presentations on threat intelligence. | 73.3% | 26.7% | 0.0% | 3.33 | exposed |
| Maintain up-to-date knowledge of hacking trends. | 65.0% | 10.0% | 25.0% | 4.53 | exposed |
| Keep up with new penetration testing tools and methods. | 65.0% | 10.0% | 25.0% | 4.47 | exposed |
| Test the security of systems by attempting to gain access to networks, Web-based applications, or computers. | 50.0% | 25.0% | 25.0% | 4.37 | exposed |
| Assess the physical security of servers, systems, or network devices to identify vulnerability to temperature, vandalism, or natural disasters. | 50.0% | 25.0% | 25.0% | 3.89 | exposed |
| Design security solutions to address known device vulnerabilities. | 50.0% | 25.0% | 25.0% | 3.75 | exposed |
| Configure information systems to incorporate principles of least functionality and least access. | 50.0% | 25.0% | 25.0% | 3.40 | exposed |
| Develop security penetration testing processes, such as wireless, data networks, and telecommunication security tests. | 45.0% | 30.0% | 25.0% | 4.37 | exposed |
| Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or enclave boundaries. | 45.0% | 30.0% | 25.0% | 4.32 | exposed |
| Discuss security solutions with information technology teams or management. | 45.0% | 30.0% | 25.0% | 4.05 | exposed |
| Collect stakeholder data to evaluate risk and to develop mitigation strategies. | 45.0% | 30.0% | 25.0% | 3.94 | exposed |
| Develop infiltration tests that exploit device vulnerabilities. | 45.0% | 30.0% | 25.0% | 3.84 | exposed |
| Identify security system weaknesses, using penetration tests. | 40.0% | 35.0% | 25.0% | 4.74 | exposed |
| Conduct network and security system audits, using established criteria. | 40.0% | 35.0% | 25.0% | 4.39 | exposed |
| Update corporate policies to improve cyber security. | 40.0% | 35.0% | 25.0% | 3.93 | exposed |
| Investigate security incidents, using computer forensics, network forensics, root cause analysis, or malware analysis. | 35.0% | 40.0% | 25.0% | 3.88 | assisted |
| Develop and execute tests that simulate the techniques of known cyber threat actors. | 23.3% | 26.7% | 50.0% | 4.06 | assisted |
| Identify new threat tactics, techniques, or procedures used by cyber threat actors. | 10.0% | 40.0% | 50.0% | 4.42 | assisted |
Task text and importance ratings sourced from O*NET 31.0. Shares computed. The occupation score is the importance-weighted mean.
Where the score comes from
judgedEvery task is scored through the standardised work activities it maps to. These are this occupation’s averages on the six rubric dimensions. Capability is what AI can do; the other five are what stands in the way.
| Dimension | Mean | Scale |
|---|---|---|
| Capability | 3.14 | 0-4 |
| Embodiment | 0.36 | 0-3 |
| Presence | 0.30 | 0-3 |
| Accountability | 1.20 | 0-3 |
| Context | 1.91 | 0-3 |
| Verification cost | 1.68 | 0-3 |
What this means in practice
Where most of a role's weighted task load is exposed, the work that survives is usually the part of the job nobody wrote into the job description: deciding what should be produced rather than producing it, and being answerable for the result. The tasks lowest on this page are a better guide to where to spend your time than any general advice about the future of work.
Occupations either side of this one
The four closest scores in the same occupational family, then the four closest anywhere in the index.
Read this carefully. Exposure is not displacement. A high score means current AI systems can produce this work, not that anyone will stop paying a person to do it. Adoption depends on economics, regulation and inertia that this index deliberately does not model. How the score is built.