Skip to main content
Table of Contents
< All Topics
Print

Know Your Worker (KYW): The Intersection of Worker Risk and IAM

Publication Date: 24 October 2024

Abstract

After more than 10,000 years of human existence in an analog environment, we must all adjust to a digital world where we are prone to myriad fraud and theft schemes perpetuated by AI-savvy hackers, thieves, and adversarial nation-states. It is a different world, and enterprises will need to adjust to this new world order.

Humans today don’t typically have the cyber literacy to fend off complex influence operations and social engineering attacks that put the organizations’ information, brand, and reputation at great risk. The workers themselves are essentially the last bastion of protection an organization has. According to Verizon’s 2023 Breach Investigation Report released in March 2024, such human worker failures account for 75% of all data breaches and ransomware attacks today, either by human negligence or malfeasance. Protecting against these insider threats starts with KYW as we’ll describe in this report. This concept is an extension of the now widely supported Know Your Customer (KYC) standards, which are the processes by which banks obtain information about the identity of their customers.

In this report, TechVision Research identifies the overall worker risk management objectives in concert with existing process and technology infrastructure. We also highlight critical risk mitigation techniques and controls that can prevent the inadvertent enablement of an “insider” to cause significant damage to your organization. These insights will help establish a Know Your Worker philosophy so that people are put in positions to succeed while limiting the “blast radius” from a human-induced mistake or nefarious action. We then conclude this review with a set of pragmatic recommendations and an enterprise action plan

Authors:

Doug Simmons                                               Gary Rowe

Principal Consulting Analyst                         CEO/Principal Consulting Analyst

[email protected]              [email protected]

 

 

Executive Summary

According to Verizon’s 2023 Breach Investigation Report released in March 2024, such human worker failures account for 75% of all data breaches and ransomware attacks today, either by human negligence or malfeasance. What exacerbates this very real threat is the fact that the workforce today is typically very distributed and fragmented across the spectrum from full-time employees managed in HR and Payroll to contractors hired into various departments, managed service providers managing the network and infrastructure from “offshore” locations, supply-chain partners interacting with the enterprise resource and planning (ERP) systems, business partners and vendors who often have access to some subset of each organization’s online and social media presence, sensitive information, application development environment or system configurations. That’s a lot of people to have access to organizations’ information and brand, especially considering most 3rd parties literally have a revolving door of hires and fires.

To effectively address this most significant risk, organizations must know precisely “who the workers are and what they intend to do”. This notion may be better explained using the self-coined axiom “Know Your Worker”, or KYW. This concept is an extension of the now widely supported Know Your Customer (KYC) standards, which are the processes by which banks obtain information about the identity of their customers. These robust international standards are designed to protect financial institutions against fraud, corruption, money laundering and terrorist financing.

According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) (https://www.cisa.gov/topics/physical-security/insider-threat-mitigation/defining-insider-threats), an insider is any person who has or had authorized access to or knowledge of an organization’s resources, including personnel, facilities, information, equipment, networks, and systems. An insider threat is the potential for an insider to use their authorized access or understanding of an organization to harm that organization. This harm can include malicious, complacent, or unintentional acts that negatively affect the integrity, confidentiality, and availability of the organization, its data, personnel, or facilities. Insider threats can manifest as damage to the organization through the following insider behaviors:

  • Unauthorized disclosure of information
  • Intentional or unintentional loss or degradation of departmental resources or capabilities
  • Corruption, including participation in transnational organized crime
  • Espionage
  • Sabotage
  • Workplace violence
  • Terrorism

Because some of the most egregious security issues arise when people have too much access – which is sometimes known as aggregated access privileges, careful management of workers’ access privileges is a cornerstone of an Identity and Access Management (IAM) Program for nearly every organization of every shape, size and industry.

  1. KYW and IAM are two sides of the same “information protection coin”.
    1. We define KYW as the process of identifying, analyzing, and addressing the risks associated with worker behavior as it relates to an organization’s information management, access, processes and procedures.
    2. Identity and Access Management (IAM) has been a cornerstone of cybersecurity since the inception of modern computing – as well as today’s Zero Trust authentication and access control
  2. Mature IAM can lessen your risks associated with human error or malfeasance.
    1. The IAM infrastructure should be designed and deployed to fully enable you to Know Your Worker.
    2. The inflection points where human workers become associated with corresponding digital identities is where the rubber meets the road in terms of giving appropriate access to the right people at the right times and never otherwise. This is where the control architecture can be the place where actions by humans are limited in terms of the damage they can do.

Worker Risk Management must therefore have direct interaction with the enterprise IAM system(s) in order to Know Your Worker. This IAM visibility includes accurately and temporally facilitating access to sensitive information and configuration capabilities.

Your mission should be to help your organization increase the attention on the very real threats posed by their own (extended) workforce. This is done by identifying their high consequence information protection risks and subsequently increasing focus on improving personnel, technical and procedural controls for key individuals who have access to high consequence information and systems. This requires an actionable organizational, technical control architecture and process improvements to help reduce the potential damage (i.e., “blast radius”) to the organization if (or when) a worker makes a mistake or goes rogue.

You can do this by developing a comprehensive IAM architecture and deployment strategy that addresses the entire, distributed workforce. TechVision recommends a structured approach to identifying key worker risks across this spectrum and has developed a Reference Architecture that may be useful in evaluating the set of capabilities necessary for your future state KYW foundation. With over 30 years of helping our customers identify and mitigate these risks, TechVision can help with this process.

 

Introduction

After more than 10,000 years existing in an analog environment, humans today are cast headlong into a digital abyss where we are prone to myriad fraud and theft schemes perpetuated by AI-savvy hackers, thieves and adversarial nation states. Humans today don’t typically have the cyber literacy to fend offcomplex influence operations and social engineering attacks that put the organizations’ information, brand, and reputation at great risk. The workers themselves are essentially the last bastion of protection an organization has. According to Verizon’s 2023 Breach Investigation Report released in March 2024, such human worker failures account for 75% of all data breaches and ransomware attacks today, either by human negligence or malfeasance.

What exacerbates this very real threat is the fact that the workforce today is typically very distributed and fragmented across the spectrum from full-time employees managed in HR and Payroll, to contractors hired into various departments, managed service providers managing the network and infrastructure from “offshore” locations, supply-chain partners interacting with the enterprise resource and planning (ERP) systems, business partners and vendors who often have access to some subset of each organization’s online and social media presence, sensitive information, application development environment or system configurations. That’s a lot of people to have access to organizations’ information and brand, especially considering most 3rd parties literally have a revolving door of hires and fires.

To effectively address this most significant risk, organizations must know precisely “who the workers are and what they intend to do”. This notion may be better explained using the self-coined axiom “Know Your Worker”, or KYW. This concept is an extension of the now widely supported Know Your Customer (KYC) standards, which are the processes by which banks obtain information about the identity of their customers. These robust international standards are designed to protect financial institutions against fraud, corruption, money laundering and terrorist financing.

In this report, TechVision Research identifies the overall worker risk management objectives in concert with existing process and technology infrastructure. We also highlight critical mitigation techniques and controls that can prevent the inadvertent enablement of an “insider” to cause significant damage to your organization. These insights will help you establish a philosophy of “know your worker” (KYW) so that people are put in positions to succeed while limiting the “blast radius” from a human-induced mistake or nefarious action. We then conclude this review with a set of pragmatic recommendations and an enterprise action plan. We’ll start this process by examining worker risk as a basis for considering how enterprises can address this risk.

Examining Worker Risk

While many, if not most, organizations have had evolving and growing risk management and Governance, Risk, and Compliance (GRC) initiatives in place for the past three decades, the advent of worker risk focus is worth noting. Why? Well, as described above, whether in the form of malicious intent or negligence, workers are the most significant cause of cyber-breaches. We should also remember that the definition of “worker” is rapidly accelerating as enterprises increasingly leverage contractors, partners and “just in-time” workers. This shouldn’t really come as a surprise to anyone, but it does emphasize that the human component of our business cybernetic systems is a key point of failure.

We have, of course, myriad choices in the field of cybersecurity training and awareness (CTA) vendors, solutions, and approaches, and most organizations have a reasonably defined CTA program in place. But the breaches continue to haunt us, and these damages are exceedingly significant. Ransomware has become the bane of our corporate security and compliance existence costing organizations billions and severely damaging brands. Intellectual property theft, sensitive customer data theft, operational technology (OT) outages and on and on – the list is endless and terrifying. And again: ~75% of these are caused by humans. Let’s look at these types of “insider threats” in a little more detail in the following section.

Insider Threats

According to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) (https://www.cisa.gov/topics/physical-security/insider-threat-mitigation/defining-insider-threats), an insider is any person who has or had authorized access to or knowledge of an organization’s resources, including personnel, facilities, information, equipment, networks, and systems.  An insider threat is the potential for an insider to use their authorized access or understanding of an organization to harm that organization. This harm can include malicious, complacent, or unintentional acts that negatively affect the integrity, confidentiality, and availability of the organization, its data, personnel, or facilities. Insider threats can manifest as damage to the organization through the following insider behaviors:

  • Unauthorized disclosure of information
  • Intentional or unintentional loss or degradation of departmental resources or capabilities
  • Corruption, including participation in transnational organized crime
  • Espionage
  • Sabotage
  • Workplace violence
  • Terrorism

Outsider threats such as malicious hackers, rogue political groups and adversarial nation states now use advanced techniques such as influence operations and social engineering to “get to” or “influence” the organization’s fragmented, distributed insiders to convince them or dupe them into exfiltrating information, sharing administrative passwords and so on. With the inclusion of Artificial Intelligence (AI) to deploy extremely convincing fakes and messaging, we’ve entered a “full spectrum” insider attack vector. For example, such full-spectrum social engineering is in widespread use today by threat actors, and it is much broader and multi-modal than simple email phishing tests can address. Consider the following examples of this:

  • Attackers make phone calls to Technical Support to request password reset, or to the Accounting Department to transfer funds to “this new account”.
  • Attackers use social media accounts to “learn about you” and attempt to befriend and ultimately defraud the target specifically or the target’s place of employment.
  • Attackers use Generative-AI to sound/look/act like you in multiple modes of communication, both in the company network – and beyond to defraud.

Today, these are all serious problems that can interfere with (at least) two important facets of the organization:

  1. The veracity and effectiveness of the CTA program in terms of being able to reflect what is really happening in the cyber-crime world, and,
  2. The veracity and effectiveness of SecOps in detecting and mitigating actual threats in real-time.

This begs the question “what can be done?”, which we discuss next.

Insider Threat Controls and Procedures

Because some of the most egregious security issues arise when people have too much access – which is sometimes known as aggregated access privileges. Managing workers’ access privileges is a cornerstone of an Identity and Access Management (IAM) Program for nearly every organization of every shape, size and industry.

IAM and Worker Risk Management

In this section, we examine the intersection of worker risk management and IAM by exploring the following thesis:

  1. KYW and IAM are two sides of the same “information protection coin”.
    1. We define KYW as the process of identifying, analyzing, and addressing the risks associated with worker behavior as it relates to an organization’s information management, access, processes and procedures.
    2. Identity and Access Management (IAM) has been a cornerstone of cybersecurity since the inception of modern computing – as well as today’s Zero Trust authentication and access control
  2. Mature IAM can lessen your risks associated with human error or malfeasance.
    1. The IAM infrastructure should be designed and deployed to fully enable you to Know Your Worker.
    2. The inflection points where human workers become associated with corresponding digital identities is where the rubber meets the road in terms of giving appropriate access to the right people at the right times and never otherwise. This is where the control architecture can be the place where actions by humans are limited in terms of the damage they can do.

Worker Risk Management must therefore have direct interaction with the enterprise IAM system(s) in order to Know Your Worker. This IAM visibility includes accurately and temporally facilitating access to sensitive information and configuration capabilities. Let’s look at IAM now in a little more detail—we’ll start with contextual IAM.

A Contextual IAM Overview

The first word in IAM is identity. An “identity” is a label applied to real world objects – most often humans, but also includes Internet of Things (IoT) devices, services, applications – anything that needs to be uniquely digitally labeled. But our focus in this report is on the human workers that comprise your extended workforce. Sparing you from an in-depth “history of identity management” discourse here, suffice it to say that we are at unparalleled inflection point between our analog (human) existence and our massively expanding digital existence. At the very least, we all have many user IDs and passwords (or other tokens instead of or in addition to passwords), and these combine to act as our identities in the digital realm. As such a person’s “identity” is the data (unique user ID and password or token) that proves that the object (you, the human) is authentic or “who you say you are.”

IAM is the process of establishing identities, managing identities/attributes and programmatic access to enterprise resources through these identities. IAM technologies are relatively mature today, but there are still many ongoing developments to improve the technology landscape. This is mainly because identities and information associated with those identities (context) are growing exponentially and this will continue for many years. It is important to note that many organizations today still struggle with inconsistent directories, multiple authoritative sources, lack of internal standards, and scalability challenges. So, while IAM technology has been around for 30+ years, it is still subject to inadequate design and implementation.

Nevertheless, there has been an increased understanding that IAM is key to cyber security, privacy, personalization, data sharing, application integration, and achieving Internet-scale digitization. This is particularly important as we consider how to mitigate insider threats via an IAM-based KYW program. For a very brief rundown, here are some of the most important aspects of today’s enterprise IAM environments:

  • Identity vetting/verification upon hiring is critical, whether employee, contractor, managed service provider, business partner, vendor, etc.
    • The level of access to sensitive information resources should dictate the level of vetting required.
      • The enterprise needs to know who they are hiring and what functions they can perform within the context of the enterprise’s data and systems, including system configuration.
      • Human Resources (HR) cannot always do this well, especially for contractors and 3rd parties such as business partners or managed service providers. The concept of hiring is therefore very nebulous and difficult to canonize as a robust set of processes beyond full-time employment.
    • The lifecycle of the worker must be managed closely as the relationship of the worker to the organization changes over time.
      • This requires that identities be audited, and access rights certified perpetually. This has created a very important set of IAM services known as Identity Governance and Administration (IGA).
      • IGA helps detect and mitigate accumulation of privilege, which is a tremendous risk to many organizations who let workers accumulate access rights for the duration of their employment, often not in concert with the workers’ current job requirements.
      • Identity lifecycle management and IGA helps enforce separation of duties and enable strong Privileged Access Management (PAM) to limit functions systems administrators may perform.
    • User authentication is how a worker identifies herself unambiguously to the enterprise cybernetic systems. A reasonable IAM implementation requires workers to authenticate using methods commensurate with the risk of information loss. As a result, most enterprises today have implemented multi-factor authentication (MFA) before granting access to medium-to-high consequence data.
    • The IAM environment must proactively monitor all authentication and access activity and enforce user entity behavior analytics (UEBA), risk scoring, and other effective run-time (proactive) safeguards to ensure a worker isn’t erroneously or malevolently accessing/retrieving sensitive information or changing system configurations.

These are just a few of the many capabilities that an IAM infrastructure provides to the enterprise in terms of cybersecurity. These capabilities must be extended to support the modern worker in the context of providing services and protecting the organization. In fact, IAM is the cornerstone of the Zero Trust Architecture movement that we will discuss next.

Worker Risk, IAM and Zero Trust

TechVision Research has published several reports focusing on Zero Trust networking and enablement. Our position is that IAM is the essential underlying infrastructure that enables the adoption of zero trust architecture. The National Institute of Standards and Technology (NIST) describes Zero Trust Architecture as “an end-to-end approach to network/data security that encompasses identity, credentials, access management, operations, endpoints, hosting environments, and the interconnecting infrastructure.”

What this definition implies is that an enterprise should only trust someone or something that is granted and reestablished/verified through Identity and Access Management (IAM) services designed to:

  • Provide proper controls to securely onboard, manage, and offboard identities,
  • Enable sufficient authentication and authorization mechanisms as per enterprise risk management, and
  • Provide an extensive proactive alerting and reactive audit trail of all workers, devices, and application access to the enterprise resources.

Because Zero Trust is not a product or even a prescribed implementation strategy, it makes sense that the decisions made about solving for Zero Trust across the enterprise demonstrate the consistent application of the following capabilities:

  • Least Privilege – An identity is granted the appropriate access and entitlements for a resource based on the need to perform its intended function and only during the time the function is being performed.
  • Strong Verification – Move beyond passwords into advanced methods of authentication and practice progressive collection and disposal of credentials required to achieve least-privilege functional execution.
  • Risk-based enforcement – Evolve to decision making based on factors beyond a strongly verified identity. Factors such as resource value, location, device and network security postures, and user behavior are included in access/entitlement decisions in a least privilege regime.
  • Continuous Evaluation of Assurance –Identify and assess levels of risk to the achievement of business objectives. Considers a combination of monitoring and auditing capabilities, such as:
  • Analyzing trends
  • Correlating outliers
  • Highlighting potential exposures
  • Evaluating and remediating exposures
  • Continuous Evaluation of Entitlement – Monitor and review the application of policies that grant, resolve, enforce, revoke, and administer fine-grained access entitlements for resources.

Remember, Zero Trust is about always asking if this activity/action is “appropriate” – during runtime

To determine that level of appropriateness, you need to consider the risk, the activity, and the identity and the associated credentials to determine authentication, access, and entitlements. This means that the “identity is the perimeter” and it is the one piece of the puzzle that must be secured with the utmost care to preserve the integrity of the information ecosystem as the user “identity” traverses from the device, over the network to the actual data, as illustrated below.

 

Figure 1:  Identity Based Zero Trust

In the following section, we’ll provide some guidance on how to address worker risk for your organization.

What To Do

Remember that it is important to understand that the modern workforce is typically very distributed and fragmented across the spectrum from full-time employees managed in HR and Payroll, to contractors hired into various departments, to managed service providers managing the network and infrastructure from offshore locations, supply-chain partners interacting with the enterprise resource and planning (ERP) systems, business partner and vendors who often have access to some subset of sensitive information or system configurations. That’s a lot of people, a lot of roles, a lot of interaction and a LOT of risk.

In this light, your mission should be to help organizations increase their attention to the very real threats posed by their own (extended) workforce. This is done by identifying their high consequence information protection risks and subsequently increasing focus on improving personnel, technical and procedural controls for key individuals who have access to high consequence information and systems. This requires an actionable organizational, technical control architecture and process improvements to help reduce the potential damage (i.e., “blast radius”) to the organization if (or when) a worker makes a mistake or goes rogue.

We recommend to our customers that they establish a comprehensive Know Your Worker strategy in much the same way as the global financial services community has determined they Know Your (their) Customer.  TechVision is working with large organizations to define the KYC initiative in the context of better understanding and securing an extended workforce.

Another key challenge is the human element; humans will always be humans, and organizations need to ensure their technical controls are reasonable and prudent regarding the threats, vulnerabilities, and potential consequences their risk appetites avail. Indeed, a balance must be struck between human risk and mitigation costs to best ensure an organization’s potential breaches will be identified and mitigated before they happen.

The approach, therefore, is to discover how the enterprise information management ecosystem functions in terms of answering simple questions like:

  1. What sensitive information does the enterprise maintain?
  2. Where is it maintained?
  3. Who has access to it?
  4. How were these people vetted?
  5. Who configures all of this?
  6. How are these processes and procedures monitored for accuracy and completeness?

Below is a high-level illustration of the general methodology for identifying human risk within the enterprise.

Figure 2:  Worker Risk Management from an IAM Perspective

Knowing the answers to these questions allows the enterprise to do two principal things:

  1. Identify the individuals who have access to sensitive information and system configurations and focus attention on them in terms of training and awareness as well as increased activity monitoring.
  2. Limit the “blast radius” of an accidental or nefarious action in case something (someone) does go wrong. The blast radius can be limited through the IAM infrastructure design by establishing Privileged Access Management, separation of duties, least privilege access controls and similar techniques.

Remember, you cannot protect what you do not know.

Conclusions and Recommendations

Worker Risk Management is a sensitive issue requiring a thoughtful approach. The reason IAM plays such an important role in managing worker risk in the cyber security arena is that it is so focused on the adaptation of the analog human being into the digital enterprise work environment.

Many, if not all, enterprises today have some IAM infrastructure and are in all likelihood embarking on a Zero Trust architecture that leverages this IAM foundation. But all of this is only as strong as the humans that use it and run it. The human is the last bastion “firewall” for the enterprise. Therefore, we strongly recommend that you Know Your Workerin much the same way as the global financial services community has determined they Know Your Customer.

Because humans will always be humans, you need to ensure your technical controls are reasonable and prudent regarding the threats, vulnerabilities, and potential consequences your risk appetite avails. Indeed, a balance must be struck between KYW and IAM to best ensure your potential breaches will be identified and mitigated before they happen. There are many advancements in the IAM capabilities of IGA, PAM, UEBA, risk scoring, trust scoring and worker device security that can provide most organizations with the technology needed to reduce worker risk.

Lastly, this report acts as a foundational document for our deeper understanding of distributed workforce risk. In the near future, TechVision Research will drill down into the IAM capabilities in more detail to help you gain a clear understanding of how a well-defined, deployed and managed IAM infrastructure reduces workforce risk significantly.

Action Plan

Those organizations that are utmost prepared to protect their broad range of critical information assets in a secure-but-user-friendly ecosystem will be able to identify and mitigate worker risk. They will do this by developing a comprehensive IAM architecture and deployment strategy that addresses the entire, distributed workforce. TechVision recommends a structured approach to identifying key worker risks across this spectrum and has developed a Reference Architecture that may be useful in evaluating the set of capabilities necessary for your future state KYW foundation. With over 30 years of helping our customers identify and mitigate these risks, TechVision can help with this process.

 

About TechVision

World-class research requires world-class consulting analysts, and our team is just that. Gaining value from research also means having access to research. All TechVision Research licenses are enterprise licenses; this means everyone that needs access to content can have access to content. We know major technology initiatives involve many different skillsets across an organization and limiting content to a few can compromise the effectiveness of the team and the success of the initiative. Our research leverages our team’s in-depth knowledge as well as their real-world consulting experience. We combine great analyst skills with real world client experiences to provide a deep and balanced perspective.

TechVision Consulting builds off our research with specific projects to help organizations better understand, architect, select, build, and deploy infrastructure technologies. Our well-rounded experience and strong analytical skills help us separate the “hype” from the reality. This provides organizations with a deeper understanding of the full scope of vendor capabilities, product life cycles, and a basis for making more informed decisions. We also support vendors in areas such as product and strategy reviews and assessments, requirement analysis, target market assessment, technology trend analysis, go-to-market plan assessment, and gap analysis.

TechVision Updates will provide regular updates on the latest developments with respect to the issues addressed in this report.

 

About the Authors

Doug Simmons brings more than 30 years of experience in IT security, risk management and identity and access management (IAM). He focuses on IT security, risk management and IAM. Doug holds a double major in Computer Science and Business Administration.

While leading consulting at Burton Group for 10 years and security, and identity management consulting at Gartner for 5 years, Doug has performed hundreds of engagements for large enterprise clients in multiple vertical industries including financial services, health care, higher education, federal and state government, manufacturing, aerospace, energy, utilities and critical infrastructure.

Gary Rowe is a seasoned technology analyst, consultant, advisor, executive and entrepreneur. Mr. Rowe helped architect, build and sell two companies and has been on the forefront the standardization and business application of core infrastructure technologies over the past 35 years. Core areas of focus include identity and access management, blockchain, Internet of Things, cloud computing, security/risk management, privacy, innovation, AI, new IT/business models and organizational strategies.

He was President of Burton Group from 1999 to 2010, the leading technology infrastructure research and consulting firm. Mr. Rowe grew Burton to over $30+ million in revenue on a self-funded basis, sold Burton to Gartner in 2010 and supported the acquisition as Burton President at Gartner.

Tags:

We can help

If you want to find out more detail, we're happy to help. Just give us your business email so that we can start a conversation.

Thanks, we'll be in touch!

Stay in the know!

Keep informed of new speakers, topics, and activities as they are added. By registering now you are not making a firm commitment to attend.

Congrats! We'll be sending you updates on the progress of the conference.