Why workforce trust must be earned, not assumed

Why workforce trust must be earned, not assumed

Artificial Intelligence is transforming recruitment, but increasingly sophisticated employment fraud is creating a new security challenge for organisations seeking to protect their systems, data and workforce. Jim Desmond, Chief Information Security Officer, HireRight, tells us why organisations must treat workforce identity assurance as an ongoing cybersecurity discipline, applying a ‘verify before trust’ approach to ensure the people receiving access to sensitive systems are genuinely who they claim to be.

How is AI transforming employment fraud, and why should CISOs be concerned?

For years, security leaders have embraced the principle that trust must be earned, never assumed. We don’t automatically trust devices or users. We continuously verify identity before granting access to systems and sensitive data. Yet, during the recruitment process, many organisations still rely on an increasingly dangerous assumption that would never survive a cybersecurity review: That the person
applying for a job is actually the person who will receive access to company systems.

The conversation around AI in hiring has largely focused on productivity. Organisations are using AI tools to screen resumes, summarise interviews, and accelerate recruiting workflows. Candidates are using AI tools to optimise applications and prepare for interviews. However, the same technology making hiring more efficient is also opening the door to sophisticated employment fraud.

Today, AI tools can help candidates create convincing resumes with fabricated employment histories, generate professional online personas, manipulate documents, translate interview responses in real time, and even alter their voice or video during remote interviews. What was once the work of skilled fraudsters can increasingly be accomplished with widely available and low-cost AI tools.

For cybersecurity leaders, this isn’t simply an HR challenge. It’s a substantial shift in how attacks are being carried out, and many organisations aren’t ready to defend against it at scale.

How has employment fraud evolved, and what does this changing threat mean for CISOs?

Historically, employment fraud was largely claim-based, with candidates misrepresenting facts about themselves in order to obtain a role. Traditional background screening was designed to address this issue by validating key claims, such as those around a candidate’s employment, criminal and education histories. 

But the modern threat is different because the objective is increasingly access rather than employment alone. Employment fraud now falls into several overlapping categories: interview fraud, credential fraud, document fraud, identity fraud and workforce infiltration.

The practical challenge is that these categories often appear together. A single fraudulent candidate may present a synthetic identity, use AI-generated credentials, conduct a proxy interview, accept a company device through a facilitator, and then use remote access tools to work from a prohibited geography.

This progression is why employment fraud should be evaluated as a kill chain rather than as a one-time screening exception. An organisation is not merely assessing whether a candidate exaggerated qualifications. It is determining whether the person who may receive access to sensitive data and systems – including cloud environments, customer records, internal documentation, production
infrastructure and source code – is authentic, authorised, and trustworthy enough for the role.

How is AI amplifying employment fraud, and what challenges does this create for CISOs?

While employment fraud existed long before AI, the widespread availability and low cost of AI tools has dramatically reduced the time, expenditure and expertise required to execute such deception at scale. Candidates can now generate highly tailored resumes in seconds. Synthetic professional profiles
appear increasingly authentic. Interview coaching can happen in real time. Documents can be manipulated with unprecedented realism.

As these capabilities improve, distinguishing between legitimate candidates and fraudulent identities through manual review alone becomes significantly more difficult. That’s why organisations should stop thinking about employment fraud as isolated incidents of dishonesty and start viewing it as part of a broader issue that is becoming more prevalent.

Why should closing the workforce identity verification gap be a priority for CISOs?

Security teams routinely secure endpoints, identities and cloud environments – but often workers do not receive the same level of scrutiny.

Remote work has removed many of the natural identity checkpoints that once existed during hiring. Many organisations now recruit, interview and onboard employees without ever meeting them in person. Meanwhile, privileged access might be granted within hours of onboarding. The result is a growing gap between how rigorously organisations verify digital identities and how rigorously they
verify workforce identities.

How can CISOs apply a ‘verify before trust’ approach to workforce identity?

Most organisations apply a ‘verify before trust’ philosophy to networks, devices and applications – but not necessarily for hiring.  

While everybody with access to a company’s systems should have their identity and credentials verified before access is granted, not every role carries the same risks and requires the same level of scrutiny. For example, engineers or IT administrators working with sensitive data and company systems may require deeper identity assurance than workers with limited access. Additionally, contractors and third-party workers should undergo similarly robust checks based on their roles and levels of access, which could be equivalent to or greater than those granted to members of their permanent workforce. 

Organisations should stop thinking about workforce identity assurance as just a pre-hire HR checkpoint, instead considering it an ongoing security discipline that combines identity verification, document authenticity, interview integrity, secure device delivery, access governance, continuous monitoring and periodic evaluation. Together, these interconnected controls can help answer a fundamental security question: Can you trust the person you’re hiring?

How should CISOs prepare for the next generation of AI-assisted employment fraud?

Over the next several years, AI-assisted employment fraud will likely become more sophisticated, more scalable and harder to detect. Attackers will continue looking for the easiest path to infiltrate organisations. Increasingly, that may not be through phishing emails or software vulnerabilities but instead through the hiring process itself.

Security leaders have spent years extending continuous verification across technology. The next frontier is extending it to the workforce. Because trust is not something organisations can assume – it must be earned before access is granted.

Browse our latest issue

Intelligent CISO

View Magazine Archive