The enemy within?

March 2012 Access Control & Identity Management

Many organisations across SA have introduced modern access control technologies to cut the losses caused by economic crime in the workplace. For example, within access, attendance and payroll solutions, the use of fingerprint-based identity control is now commonplace in environments ranging from mines and factories to warehouses and ports.

The proven business benefit being delivered by this technology is straightforward: it cuts the recurring losses caused by unauthorised access and activity. In terms of ROI, the technology not only pays for itself, it provides on-going returns through continued loss reduction.

Marius Coetzee of Ideco Biometric Security Solutions champions identity control as a practical business discipline that can deliver immediate returns in terms of risk reduction and loss prevention.

Marius Coetzee
Marius Coetzee

Many of us are familiar with fingerprint applications in the workplace and we have seen their widespread use as a replacement for traditional access cards and PINs within access systems as well as in time and attendance solutions. Coetzee says that we should now perhaps be looking at fingerprint applications beyond the proven successes within these two specific areas of workplace security. He says, “Identity is at the heart of almost everything we do in the workplace and is an integral part of so many business processes.

“The recent cyber theft of R42 million from Postbank illustrates the dangers of inadequate identity control and clearly shows us how identity impacts so many other areas of our working lives beyond physical security and payroll management.”

Failures can be costly

The Postbank theft provides two examples of how identity was abused in order to perpetrate the crime. It seems that towards the end of 2011 the villains opened multiple bank accounts using false identities. These mule accounts would later be used to receive the funds that were transferred to them at the start of the new year. This represents an initial failure in identity control – the processes that govern account opening were apparently unable to accurately verify the identities of the people opening them.

The second identity control failure appears to have occurred in the transfer of funds from Postbank to the mule accounts. Media reports early in January suggest this was achieved by the exploitation of bank employees’ IT access credentials. Once the mule accounts were established, it seems that the passwords of Postbank staffers from Rustenburg were used to increase withdrawal limits on the mule accounts and to make fraudulent transfers to them.

R42m in cash was then apparently withdrawn from ATMs across the country during the first three days of 2012. Postbank acknowledged the theft in mid-January and the government has set-up a team to investigate.

A security culture

From the point where a person is considered for employment, through to when then they leave a company, Coetzee suggests that they should be included within a programme of identity control. “The first step is to confirm their identity and carry out some background screening.

Further identity-based controls should then be applied to govern who can do what, when and where. Coetzee points out that the effectiveness of such policies is entirely dependent upon being able to identify the employee accurately and consistently and to create an irrefutable identity trail.

And this is where fingerprint-based identification makes an enormous contribution to the whole process of identity Control. “Traditionally, organisations have relied on access cards, PINS and passwords to identify their employees,” says Coetzee. “But this creates a fundamental weakness in the process because anyone can use your card or your password.

One area where increased identity control is obviously critical is within corporate IT systems – which are almost universally protected with nothing more than a password, PIN or card. Since these credentials are constantly exploited to enable illicit access and activity – from making fraudulent payments to stealing sensitive data, Coetzee says: “It would make sound commercial sense to remove this glaring loophole in workplace security by replacing traditional IT access credentials with fingerprint-based identity control.”



Credit(s)




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The future of security: intelligent automation
Access Control & Identity Management AI & Data Analytics IoT & Automation
As the security landscape evolves, businesses are no longer looking for stand-alone solutions, they want connected, intelligent systems that automate, streamline, and protect.

Read more...
Smart automation is changing security
SA Technologies IntelliGuard Access Control & Identity Management
Security has come a long way from manual check-ins, logbooks, and standalone surveillance cameras. With the rise of intelligent automation, security is now faster, smarter, and more connected than ever.

Read more...
The future of security in South Africa
ATG Digital Access Control & Identity Management
Security technology is evolving rapidly, but is local innovation keeping pace? Some global players recognise the potential of South African products for international markets, but can our manufacturers and service providers thrive without external support?

Read more...
Integration enhances estate access control
Access Control & Identity Management
With one-third of residential burglaries starting at the front door, the continued seamless integration of Glovent’s estate management platform with Impro access control software is welcome news for estates.

Read more...
T&A in South Africa’s retail sector
ERS Biometrics Access Control & Identity Management
Using existing systems, ERSBio provides a practical and more cost-effective way for businesses to manage operations, reduce payroll mistakes, and enhance overall efficiency through innovative T&A processes.

Read more...
Navigating the complexities of privileged access management
Editor's Choice Access Control & Identity Management
Privileged Access Management and Identity Access Management are critical pillars of modern cybersecurity, designed to secure access to sensitive resources, enforce principles like least privilege, and implement just-in-time access controls.

Read more...
Paxton opens second experience centre
Paxton News & Events Access Control & Identity Management
Security technology manufacturer, Paxton, has opened a new experience centre in Cape Town on 12 February in partnership with its exclusive distributors, Reditron and Regal Security.

Read more...
DoorBell with built-in AI
Ajax Systems Access Control & Identity Management Products & Solutions Smart Home Automation
Ajax Systems has announced the release of Ajax DoorBell, which features built-in AI, an IR sensor, and app control, seamlessly integrating into the Ajax ecosystem to ensure efficiency and security confidence.

Read more...
Physical security evolving beyond security teams
ATG Digital Access Control & Identity Management
The landscape of physical security is undergoing a major shift. Traditionally, selecting access control and visitor management solutions fell squarely on the shoulders of security professionals, but today includes legal, IT, technical operations and more.

Read more...
A passwordless future?
Access Control & Identity Management
The digital landscape is evolving rapidly, and with it comes the urgent need for more secure authentication methods. Passwords, once the cornerstone of online security, are now easy targets for cybercriminals.

Read more...