Free sampler. Re-scored every six months.
Incident response and threat hunting scores 5.0 out of 10 for AI exposure, where 10 is most at risk. Tier-one SOC analyst work scores 7.4. Cybersecurity is widely sold as the safe technical career, and it is safer than most of tech — but "safer than software" and "safe" are different claims, and the entry tier is heavily exposed.
The short answer for parents: better than most technical paths, and not as protected as the marketing suggests. Nothing in this field scores in the low band. What protects it is an adversary who is actively trying to be unpredictable — and the roles that face that adversary directly are not the ones graduates start in.
Every career in this index is scored 1–10, where 10 is most exposed to AI. Same six factors, same weights, applied identically to a security analyst and a paramedic.
| Cybersecurity track | 2023 | 2025 | Now | 3-yr move | Band |
|---|---|---|---|---|---|
| Incident response / threat hunting | 4.2 | 4.6 | 5.0 | +0.8 | Moderate |
| Security architecture | 4.7 | 5.1 | 5.5 | +0.8 | Moderate |
| Penetration testing / offensive | 4.9 | 5.3 | 5.7 | +0.8 | Moderate |
| GRC / compliance | 5.2 | 5.7 | 6.1 | +0.9 | Mod–High |
| SOC analyst (tier 1) | 6.1 | 6.8 | 7.4 | +1.3 | High |
2023 and 2025 figures are reconstructed using current methodology, not archived from past editions.
For scalethe median career in this edition scores around 5.5. Entry-level software development scores 8.1. Entry data analysis scores 8.2. Licensed engineering scores 4.0.
Cybersecurity is the best-scoring pure-technology track we measure — but its floor is 5.0, not 2.5. Compare licensed engineering at 4.0 or the skilled trades at 2.5.
It is already doing most of tier-one alert triage, and struggling with everything above it.
The uncomfortable symmetry: the same tools are available to attackers. Cybersecurity is the one field we score where AI improves both sides simultaneously, which is a genuinely different situation from the rest of this index.
How incident response and threat hunting rates against each. Ratings are 0–10 on each factor's own terms.
So you can see what the analysis actually looks like.
How often does the job hit genuinely new, high-stakes situations? — rated 9.0
AI is strong on patterns and weak on genuine novelty. Most careers earn a high rating on this factor because their situations are complex — a one-off engineering site, an atypical patient, a case with no precedent.
Cybersecurity earns it because someone is deliberately manufacturing novelty against you.
That distinction matters more than it sounds. An unusual medical presentation is unusual by accident. An unusual attack is unusual on purpose, designed specifically to look like something benign or to exploit the gap between what a detection system was trained on and what is actually happening.
This creates a property no other profession in this index has: the novelty is adaptive. Whatever pattern a defensive system learns to recognize, an adversary has an incentive to stop matching it. There is no equilibrium where the patterns settle down and the work becomes routine, because the other side is paid to prevent exactly that.
That is why threat hunting rates 9.0 and holds a 5.0 score despite no physical component, no licensure, and a fully digital workflow. Almost nothing else in this index survives that combination of missing protections.
But notice where the protection does not reach. A tier-one SOC analyst is not facing adversarial novelty. They are working a queue of alerts against a playbook — pattern-matching, in a role explicitly designed to be pattern-matching, which is why it rates 4.5 rather than 9.0 and scores 7.4.
The general lesson: adversarial work resists automation better than complex work. Complexity can be learned. An opponent who changes when you learn cannot be. Any career with a genuine adversary — security, litigation, fraud investigation, negotiation, competitive strategy — carries a protection that complexity alone does not provide.
Ranked by exposure, safest first:
Better than most technical degrees, with one caveat that matters a great deal.
The field has genuine demand and the senior roles carry real protection. But the standard route in — tier-one SOC work — is the most automated part of it. That is the same entry-path problem that afflicts software, law, finance and accounting: the profession is healthy and the on-ramp is narrowing.
What still works as a route in: technical depth beyond tooling, hands-on lab and competition experience, and specialization early rather than generic security coursework. Certifications carry more weight in this field than in most, and employer-linked apprenticeship routes are more available here than in software.
Worth asking any program: what are graduates doing at year one, and does the curriculum build adversarial thinking or tool operation? The first survives automation. The second is what is being automated.
This sampler tells you where cybersecurity stands. The full profile tells you what to do about it.
Most families are weighing two or three careers seriously, and a few more they haven’t ruled out. Pick the ones you need.
Each includes a short version written directly to the student and the technical scoring appendix. Spring 2027 updates of whatever you buy are included.
Read one complete profile free → We publish computer science in full so you can judge the depth before buying anything.