Back to all lessons
Awareness Lessons
3 days ago

Zero Trust Has a Day-One Blind Spot: The Onboarding Identity Gap

Zero Trust architectures assume strong identity verification, but the onboarding window — before MFA and robust credentials are fully established — creates a critical vulnerability that attackers actively exploit. North Korean state-sponsored actors have demonstrated this by infiltrating organizations using fraudulent identities during remote hiring processes, effectively bypassing the security controls that Zero Trust promises. The core failure is treating new user onboarding as a lower-risk process than ongoing authentication, when in reality it is the most exploitable moment in the identity lifecycle. Without rigorous identity proofing at the point of hire — equivalent to or stronger than controls applied to existing users — organizations are handing adversaries a trusted foothold before security controls are even applied.

Tactical Insight

Immediate actions

  • Implement government-grade identity proofing (e.g., verified ID documents + liveness checks) for all new remote hires before issuing any credentials.
  • Restrict Day-One access to a minimal, isolated environment with no lateral movement capability until full identity verification is confirmed.
  • Flag and manually review all fully remote job applicants who decline video onboarding or exhibit inconsistencies in identity documentation.

Long-term improvements

  • Establish a formal Identity Proofing Policy that mandates equivalent verification rigor for new users as for privileged access re-certification.
  • Integrate third-party background verification and identity-proofing services (e.g., NIST SP 800-63-3 IAL2/IAL3 compliant) into the HR and IT onboarding pipeline.
  • Design Zero Trust onboarding workflows that enforce progressive trust elevation, granting broader access only after behavioral and identity signals are validated over time.

Detection measures

  • Deploy User and Entity Behavior Analytics (UEBA) tuned specifically to flag anomalous behavior patterns in newly onboarded accounts during the first 90 days.
  • Log and alert on all access attempts made by accounts in a 'probationary' identity state, escalating unusual off-hours or bulk-data-access activity for immediate review.