• Sicherheit

    One check is not forever: reassessing privileged-access roles over time

    Most companies screen candidates before hiring, but far fewer repeat that assessment once the person has joined the organisation. Yet an employee’s personal, financial or legal circumstances can change significantly over time, particularly in roles with access to critical systems, financial information or customer data. Validato sees this temporal blind spot as one of the less visible sources of insider risk. “A background check at the time of hiring is a snapshot, not a movie. A person with privileged access who presents no particular concern today may, two or three years later, face circumstances that make them more vulnerable to coercion or temptation,” says André Naef, CEO of Validato. Validato…

    Kommentare deaktiviert für One check is not forever: reassessing privileged-access roles over time
  • Sicherheit

    DORA and the human factor: personnel controls in critical financial-services roles

    The EU Digital Operational Resilience Act (DORA) requires banks, insurers and other financial entities to maintain a robust and documented ICT risk-management framework. This includes governance, identification of functions and assets, access controls, training and strengthened management of ICT third-party risk. DORA does not, however, impose a general obligation to conduct employee background checks. For Validato, the relevance lies in the risk-based approach. “DORA requires financial institutions to understand and control their ICT risks. For certain functions with sensitive access rights, proportionate screening can form part of a broader control environment – provided there is a valid legal basis and data-protection and employment-law limits are respected,” says André Naef, CEO…

    Kommentare deaktiviert für DORA and the human factor: personnel controls in critical financial-services roles
  • Sicherheit

    NIS2 in Spain: what CISOs need to know about personnel screening

    Spain continues to work on transposing the NIS2 Directive through the future Cybersecurity Coordination and Governance Act. As of September 2026, the transposition should still be described as an ongoing legislative process rather than as fully applicable Spanish law. NIS2 broadens the European cybersecurity risk-management framework for essential and important entities across numerous sectors. NIS2 requires proportionate risk-management measures, supply-chain security, incident management, access controls and training, among other areas. However, the Directive does not impose a general obligation to conduct background checks on employees. Validato views screening of certain individuals as a possible complementary, risk-based measure where the role and legal framework justify it. “NIS2 strengthens risk management, but…

    Kommentare deaktiviert für NIS2 in Spain: what CISOs need to know about personnel screening
  • Sicherheit

    CHRO and CISO: why HR and Information Security should manage human risk together

    In many organisations, Human Resources and Information Security still operate in silos: the CHRO manages hiring and talent development, while the CISO protects systems and data. Yet both functions share the same blind spot – the risk associated with people themselves, from a candidate who falsifies a qualification to an employee with privileged access who becomes a target of social engineering. Validato believes background checks should neither be treated solely as an HR compliance formality nor remain outside the CISO’s scope as a “purely human” issue. “Human risk does not respect departmental boundaries. When CHRO and CISO jointly define which roles require which level of verification, and at what frequency,…

    Kommentare deaktiviert für CHRO and CISO: why HR and Information Security should manage human risk together
  • Sicherheit

    Even the best technology cannot eliminate the human factor

    erizon’s 2026 Data Breach Investigations Report (DBIR) once again highlights the importance of the human factor in cybersecurity: 62% of the breaches analysed involved an unintentional human contribution. This does not mean that people are the sole cause of security incidents. It does, however, confirm that technical controls alone cannot eliminate risks related to credentials, errors, social engineering and access rights. For Validato, a European provider of background checks and Human Risk Management, the conclusion is clear: technical security controls should be complemented by proportionate human-risk management. “Cybersecurity does not end at the firewall. For sensitive roles, it can also be relevant – within the applicable legal framework – to…

    Kommentare deaktiviert für Even the best technology cannot eliminate the human factor
  • Sicherheit

    Verificar una sola vez ya no basta: empleados con acceso privilegiado necesitan revisiones periódicas

    La mayoría de las empresas verifican a un candidato antes de contratarlo, pero muy pocas repiten esa verificación una vez que ya forma parte de la organización. Sin embargo, las circunstancias personales, financieras o legales de un empleado pueden cambiar de forma significativa a lo largo de los años, especialmente en roles con acceso a sistemas críticos, información financiera o datos de clientes. Validato, proveedor de Human Risk Management, sostiene que este punto ciego temporal es una de las causas menos visibles del riesgo interno ("insider risk"). "Una verificación de antecedentes hecha en el momento de la contratación es una fotografía, no una película. Un empleado con acceso privilegiado que…

    Kommentare deaktiviert für Verificar una sola vez ya no basta: empleados con acceso privilegiado necesitan revisiones periódicas
  • Sicherheit

    DORA y el factor humano: la banca española refuerza la verificación de personal en funciones críticas

    El Reglamento europeo de Resiliencia Operativa Digital (DORA) exige a bancos, aseguradoras y otras entidades financieras un marco sólido y documentado de gestión del riesgo TIC. Incluye gobernanza, identificación de funciones y activos, controles de acceso, formación y una gestión reforzada del riesgo de proveedores tecnológicos. DORA no establece, sin embargo, una obligación general de realizar verificaciones de antecedentes a empleados. Para Validato, proveedor de Human Risk Management, la relevancia está en el enfoque basado en riesgo. "DORA obliga a las entidades financieras a comprender y controlar sus riesgos TIC. Para determinadas funciones con acceso sensible, una verificación proporcionada puede formar parte de un conjunto más amplio de controles, siempre…

    Kommentare deaktiviert für DORA y el factor humano: la banca española refuerza la verificación de personal en funciones críticas
  • Sicherheit

    NIS2 en España: qué deben saber los CISO sobre la verificación de personal

    España continúa trabajando en la transposición de la Directiva NIS2 mediante la futura Ley de Coordinación y Gobernanza de la Ciberseguridad. A septiembre de 2026, la transposición debe seguir tratándose como un proceso legislativo en curso y no como una ley española ya plenamente vigente. NIS2 amplía el marco europeo de gestión de riesgos de ciberseguridad para entidades esenciales e importantes en numerosos sectores. NIS2 exige medidas proporcionadas de gestión de riesgos, seguridad de la cadena de suministro, gestión de incidentes, control de accesos y formación, entre otros ámbitos. Sin embargo, la Directiva no establece una obligación general de realizar background checks a empleados. Para Validato, la verificación de determinadas…

    Kommentare deaktiviert für NIS2 en España: qué deben saber los CISO sobre la verificación de personal
  • Sicherheit

    RR. HH. y Seguridad de la Información: por qué CHRO y CISO deben verificar juntos el riesgo humano

    En la mayoría de las organizaciones, Recursos Humanos y Seguridad de la Información siguen operando en silos: el CHRO gestiona la contratación y el desarrollo del talento; el CISO, la protección de sistemas y datos. Sin embargo, ambos departamentos comparten un mismo punto ciego, el riesgo que representan las propias personas, desde el candidato que falsifica un título hasta el empleado con acceso privilegiado que se convierte en objetivo de ingeniería social. Validato, proveedor de Human Risk Management, plantea que la verificación de antecedentes no debería depender únicamente de RR. HH. como trámite de cumplimiento, ni quedar fuera del radar del CISO como asunto "puramente humano". "El riesgo humano no…

    Kommentare deaktiviert für RR. HH. y Seguridad de la Información: por qué CHRO y CISO deben verificar juntos el riesgo humano
  • Sicherheit

    La ciberseguridad más avanzada falla si no se verifica a las personas

    El último Informe de Investigaciones de Brechas de Datos (DBIR) de Verizon confirma una tendencia que los responsables de seguridad de la información (CISO) conocen bien: casi el 60 % de las brechas de datos analizadas en 2025 tuvo un componente humano, ya sea por error, manipulación o uso indebido de credenciales. El informe añade un dato inquietante para cualquier CISO: en muchas organizaciones, apenas un 8 % de los empleados concentra el 80 % de los incidentes de riesgo. Para Validato, proveedor europeo de verificación de antecedentes (background checks) y Human Risk Management, estas cifras confirman que ningún firewall, EDR o SOC compensa por completo a una persona equivocada…

    Kommentare deaktiviert für La ciberseguridad más avanzada falla si no se verifica a las personas