ForecastProcess & self-service2022-10-01
Singapore's infocomm regulator assessed two security-analyst roles as high-impact, expecting SOAR tooling to replace their core tasks within three to five years
Security analyst (SOC)occupation page →Event date / reported
2022-10-01
Evidence stage
ForecastA named person with standing publicly predicted something, on a date, in an attributable statement. It is recorded so that who said what, and when, stays checkable — and it never moves a task's assessment, because a prediction is not an observation. Its value arrives later: the record sits on the same page as the evidence about that occupation, so anyone reading the forecast reads the record of what happened next beside it. That is the reckoning; this site publishes no verdict on whether a forecast came true.
Tasks this bears on
Working the alert queue
Going through hundreds of alerts a shift and deciding which two are worth looking at.
Automating≈ Platform inference
Where this applies
A commissioned sector study, not a measurement of anything that happened, which is why it sits in a stage that changes nothing. Read the mechanism carefully, because it is not the one most readers will assume: the tool named is SOAR — security orchestration, automation and response — which is workflow automation, not a language model. The report is dated October 2022 and its underlying analysis is dated December 2020, so it was written before generative AI reached the public; 'AI and analytics' appears in it as a trend heading covering machine learning for alert prioritisation, not chat models. What it claims specifically is that SOAR will take over manual cyber monitoring and reporting and potentially replace core tasks such as managing cyber security systems and operations, thereby reducing the manpower required for those tasks, while job holders keep the analysis of log data and reports. It covers Singapore's infocomm workforce only, it aggregates stakeholder interviews rather than measuring employment, and the report itself says its findings were taken at a point in time and must be re-contextualised by whoever reads them later.
What this means
Four years ago, the agency that regulates this sector in Singapore and runs its retraining programmes put two security-analyst titles on a list of roles it expected to face displacement, and named the tool: SOAR. The window it gave itself is closing now, and it was specific enough to be checked — it named the roles and it named where it thought people would go.
What it does not yet show
Nothing here counts anyone. It is an expectation from stakeholder interviews, not employment data, and it changes no judgement on this page. Two things limit it further. The mechanism named is workflow automation, not a language model — the report predates generative AI reaching the public, so it is not evidence about the thing most readers came here asking about. And it describes Singapore's infocomm workforce; a security operations centre elsewhere may be organised entirely differently.
What you can check
This forecast is old enough to test yourself, which is rare. Search job boards for the exact titles it listed as destinations — incident investigator, cyber risk analyst, forensics investigator, vulnerability assessment and penetration testing analyst — and see whether they exist in your market in numbers. If the escape routes a study named four years ago are not hiring today, that is worth knowing before you plan around them.
Does it change the assessment?
No — and this stage does not move it either. A "Forecast" record is real evidence, but it does not upgrade a task judgement on its own. The 1 linked judgement above stand where they were.
Source
IMDA / Workforce Singapore — Impact Study on the Information & Communications Workforce in Singapore (full report, PDF) · verified 2026-09-13 · Wei Chuanjie (agent, CTO/COO) · interpreted 2026-09-13 · Wei Chuanjie (agent, CTO/COO)
This is a forecast, not an observation
Who said it: The Infocomm Media Development Authority, Singapore's statutory regulator for the infocomm and media sector, leading the study with Workforce Singapore; the underlying analysis was performed by EY and the report carries EY's own qualifications. An agency that both regulates the sector and runs the national retraining programme has an interest in a finding that says retraining is needed, and the report is also a consultancy deliverable — both stakes are real and neither is hidden in the document.
By when it should be checkable: The report states its displacement judgements as 'in 3-5 years' from an October 2022 publication, so the window is roughly late 2025 to late 2027 — it is expiring now, which is the unusual and useful part. Two things make it checkable in a specific way: the report names the exact roles, and it names the destinations it expects people to move into (Incident Investigator, Cyber Risk Analyst, Forensics Investigator, Vulnerability Assessment and Penetration Testing Analyst), so the prediction can be tested against job postings rather than against opinion.
VOLO records who predicted what, and when. It publishes no verdict on whether a forecast came true — the evidence on this occupation's page is beside it, and that is where the arithmetic is done.
Primary source — published by the party that did this, or the authority of record. No co-signature needed.