{
  "source": "Cooked Index — occupational AI risk register",
  "page": "https://cookedindex.com/jobs/network-and-computer-systems-administrators/",
  "methodology": "https://cookedindex.com/methodology",
  "notice": "Verdicts are re-examined as evidence accumulates. Re-fetch before relying on this; the page above always carries the current score.",
  "scored_at": "2026-08-11",
  "model": "claude-opus-5",
  "occupation": {
    "title": "Network and Computer Systems Administrators",
    "soc_code": "15-1244",
    "category": "Tech",
    "us_employment": 314340,
    "median_annual_wage": 99130
  },
  "verdict": "EXPOSED",
  "risk_resistance": 40,
  "contested": false,
  "near_boundary": false,
  "dimensions": {
    "task_resistance": 9,
    "embodiment": 9,
    "liability_shield": 2,
    "trust_premium": 8,
    "judgment_accountability": 12
  },
  "reasoning": {
    "task_resistance": "At 9 the split is real but lopsided: Ansible/Terraform, Intune, and cloud consoles already handle the provisioning, imaging, patch rings, and certificate renewals that used to fill the week, while the residue that resists — reverse-engineering an undocumented legacy dependency, diagnosing why VLAN 40 drops at 4pm, deciding what to sacrifice during a partial SAN failure — is maybe a third of the calendar, not enough for a 14.",
    "embodiment": "A 9 reflects that you do rack switches, run and label patch cables, swap failed drives and PSUs, walk floors with a laptop hunting an AP coverage hole, and drive to the branch office when the VPN appliance bricks — but that's in server rooms, IDF closets, and offices with climate control and known layouts, not rooftops or trenches, and most days you never leave your desk.",
    "liability_shield": "A 2 is honest: no state licenses systems administrators, and CCNA, MCSE, RHCE, or Security+ are hiring filters set by employers, not legal gatekeepers — after a breach the notification duty and the fines land on the organization and its CISO under HIPAA, GLBA, or state law, and your exposure is being fired, not being sanctioned by a board.",
    "trust_premium": "An 8 accounts for the fact that internal customers ask for you by name, executives call your cell rather than open a ticket, and years of knowing which finance app breaks on a .NET update is genuinely portable capital — but the deliverable is uptime, and when an MSP takes over the contract users complain for a quarter and then adapt.",
    "judgment_accountability": "A 12 fits calls that are yours alone with no procedure to hide behind — whether to fail over or wait, whether to isolate an infected subnet and halt a department, which backup generation to trust when the newest one may be encrypted, whether to push an emergency patch on a Friday — but the change window, the RTO, and the risk appetite were set above you, which keeps it out of the 14-plus range."
  },
  "rationale": "The bread-and-butter of this job — account provisioning, patch cycles, log triage, backup verification, firewall rule edits, ticket resolution, runbook writing — is exactly what infrastructure-as-code, cloud managed services, and AI copilots are absorbing fastest; the same wave that killed manual server builds is now eating first-line troubleshooting. What holds is the physical and organizational half: racking and cabling gear, chasing an intermittent switch or AP problem across a building, restoring service at 2am when the automation itself is the thing that broke, and being the person accountable for an outage or a breach. No license protects this work, which is why the ceiling is modest.",
  "outlook": "Headcount per server keeps falling as cloud and automation consolidate the work; by 2035 the surviving roles are security-adjacent, platform/SRE-flavored, or physically tied to sites, and pure Windows-admin generalist jobs are scarce.",
  "what_would_raise_it": {
    "levers": [
      {
        "dimension": "judgment_accountability",
        "change": "Incident-command accountability being formalized: SEC cyber disclosure rules (Item 1.05, effective Dec 2023) and NYDFS Part 500 amendments require a named individual to certify materiality and control effectiveness within days of an incident. If the person who owns the environment is routinely the attestor of record — as CISOs increasingly delegate technical certification downward — the role owns consequential calls with personal exposure.",
        "plausibility": "already happening",
        "would_add": 4
      },
      {
        "dimension": "task_resistance",
        "change": "Genuine two-tier shift: as IaC and AI copilots absorb provisioning, patching, and first-line ticket triage, the residual work becomes failure-domain design, blast-radius review of AI-generated config changes, and recovering when the automation itself is the failure (the CrowdStrike July 2024 pattern). Watch for job postings retitled toward platform/reliability engineering with change-review duties.",
        "plausibility": "already happening",
        "would_add": 3
      },
      {
        "dimension": "embodiment",
        "change": "AI-driven datacenter buildout raising the share of hands-on work: power, cooling, GPU cluster cabling, and optics fault isolation in facilities where remote hands cannot diagnose intermittent physical-layer faults. Also OT/air-gapped environments under CISA critical-infrastructure guidance where remote administration is prohibited by policy.",
        "plausibility": "plausible",
        "would_add": 3
      },
      {
        "dimension": "liability_shield",
        "change": "The only credible route is cyber-insurance underwriting, not licensure: carriers already require MFA and EDR attestations signed by a named administrator, and a false attestation can void coverage. If insurers move to requiring a named, credentialed individual (CISSP-level or equivalent) to sign control attestations — as some CMMC Level 2 assessments already do for defense contractors — a weak personal-liability hook appears.",
        "plausibility": "plausible",
        "would_add": 3
      },
      {
        "dimension": "trust_premium",
        "change": "Narrow route only: classified, ITAR, or CJIS-scoped environments where cleared US-person administrators are contractually mandated and offshore or AI-mediated administration is barred. This is a compliance mandate that reads as trust premium, not buyer preference.",
        "plausibility": "already happening",
        "would_add": 2
      }
    ],
    "ceiling_note": "Even with every lever, this caps in the low-to-mid 50s. There is no licensing body, no protected title, and no path to one — attempts to license IT practitioners have repeatedly failed in the US. Most gains come from task-mix shift and insurer attestation, both of which shrink headcount while raising the value of survivors."
  },
  "adjudication": null,
  "employment_history": {
    "points": [
      {
        "y": 2019,
        "emp": 354450,
        "wage": 83510
      },
      {
        "y": 2020,
        "emp": 339560,
        "wage": 84810
      },
      {
        "y": 2021,
        "emp": 316760,
        "wage": 80600
      },
      {
        "y": 2022,
        "emp": 325930,
        "wage": 90520
      },
      {
        "y": 2023,
        "emp": 323020,
        "wage": 95360
      },
      {
        "y": 2024,
        "emp": 318570,
        "wage": 96800
      },
      {
        "y": 2025,
        "emp": 314340,
        "wage": 99130
      }
    ],
    "from": 2019,
    "to": 2025,
    "change_pct": -11.3,
    "comparable_from": 2019,
    "spans_soc_revision": false
  },
  "pivots": [
    {
      "slug": "electrical-engineers",
      "title": "Electrical Engineers",
      "verdict": "EXPOSED",
      "risk_resistance": 52,
      "median_wage": 120630,
      "overlap": 60,
      "skills_to_close": [
        "Writing",
        "Active Learning",
        "Science",
        "Speaking"
      ]
    }
  ],
  "license": "https://cookedindex.com/terms"
}