As organizations have strengthened their cyber defences, threat actors are turning to new ways of accessing critical assets, without ever needing to breach a system 

Criminal groups, competitors and state-sponsored actors are increasingly attempting to gain direct employment, using roles as employees or contactors to obtain trusted access from within a company. By concealing their identities, falsifying credentials or exploiting gaps in Talent Acquisition screening, they can gain legitimate access to an organization's people, systems and most sensitive data from the outset. 

Why this threat is difficult to identify

What makes this challenge particularly difficult is that threat actors often appear to be highly credible candidates, possessing the technical skills, expertise and professional background an organization is actively seeking. This combination of factors often makes them difficult to distinguish from legitimate candidates. 

At the same time, the teams expected to identify them are not always equipped to do so. Talent Acquisition teams are increasingly being asked to identify sophisticated threat actors without the insider threat-training, awareness or support traditionally associated with Security, Cyber or Intelligence functions. As threat actors continue to evolve their tactics, this creates a growing vulnerability within the hiring process itself. 

Why it matters at board level 

This is not simply a recruitment challenge. It is an enterprise risk issue, with implications for security, operations, intellectual property, legal exposure, financial performance and reputation. 

Cost is a significant factor. Once a threat actor has gained employment, organizations can find that identifying, investigating and removing them is significantly more complex and expensive than preventing them from entering in the first place. The consequences can include lengthy investigations, operational disruption, financial losses, litigation and reputational damage. For this reason, many organizations are shifting their focus earlier in the process, from reacting to incidents to preventing threat actors from gaining a foothold during the pre-employment phase. 

The test now is whether screening and vetting processes are effective enough to identify threat actors who are posing as legitimate candidates. 

What good practice looks like

Addressing this challenge means recognizing hiring as part of insider threat prevention and equipping the teams at the front line to support that role. In practice, this involves: 

The organizations best positioned to manage this risk will be those that recognize hiring as a critical component of insider threat prevention, equip their Talent Acquisition teams with the tools and training they need, and bring HR, Security, Cyber, Legal and Risk functions together to address the challenge collectively rather than in isolation. 

That approach shifts insider threat management from a reactive to a proactive capability, helping to prevent threat actors from gaining a foothold early in the pre-employment phase. 

Make hiring part of your insider threat defence. Control Risks helps organizations strengthen pre-employment processes and screening, equip Talent Acquisition teams to identify sophisticated threat actors, and connect HR, Security, Cyber and Legal around a proactive and collaborative approach to insider risk. 

This Article is written by: Catherine Marinis-Yaqub & Ishita Khanna.

Get in touch

Can our experts help you?