Vaccine passports: the future of workplace security?

Ian Lowe, Head of Industry Solutions EMEA at Okta, explores the technology behind vaccine passports and how this could be replicated to create validation methods by authenticating identity, qualifications, and skills and improving workplace security.
Ian Lowe, Head of Industry Solutions EMEA at Okta, explores the technology behind vaccine passports and how this could be replicated to create validation methods by authenticating identity, qualifications, and skills and improving workplace security.

Proof of vaccine status is not a new idea. Vaccination history has helped to enable international travel for years, and in some countries, it is required for entry. In the US, vaccine passports were even introduced in the late 19th century to prove that passengers travelling abroad had been vaccinated from smallpox. More than 100 years later, the certification has gone digital, but the concept remains the same.

In the UK, the NHS Covid Pass app allowed double vaccinated adults to avoid quarantine when returning from amber-list countries during the summer, and it is possible that this could still play a part in everyday life. But there has been much debate on this issue. Despite scrapping the idea for now, the English Government has stated that vaccine passports will be “kept in reserve” should they be needed throughout autumn and winter, while both Scotland and Wales have confirmed they will be required for entry to large events, nightclubs and sports venues.

From a business perspective, discussions are also underway as to whether these certificates could be deployed to fully reopen workspaces to help employees feel safe. This validation method, however, requires a secure digital approach to be trusted, as vaccine passports could be easily forged or replicated. And once this technology is finetuned, it could be a trend we see continuing in the workplace to validate identity in the future.

Getting vaccine passports right

A number of organizations, including tech giants Google and Facebook, have begun to require their employees to prove their vaccine status as they return to offices. There has been some concern in the UK that this could cause potential issues surrounding existing employer policies and employment laws. But Okta’s recent research has found that 22% of office workers would feel safer returning to the workplace with compulsory vaccine passports in place, and 15% support voluntary options. 

To avoid the risk of forgery, this validation method needs to be secure. Physical vaccine passports were successful in the US at the time of the smallpox outbreak, but now would be far easier to edit or falsify. The digital vaccine records of today must be simple and secure, incorporating optimal security features that properly protect personally identifiable information (PII). This is crucial to ensuring that people are happy with their medical data being stored, and trust that it is being kept safe.

Benefits of workplace validation

Once the technology behind vaccine passports is proven to work effectively, it could then be replicated and used for other forms of validation, such as to authenticate qualifications, skills and other accreditations. For example, an outsourced electrician could show proof of accreditation to work on high voltage lines, or contractors could present evidence that they are allowed to access or view secure information, offering an additional layer of privacy and security.

Currently, an increasing number of successful fraudulent attacks on businesses happen when the perpetrator is not who they say they are. In tandem, technology is getting increasingly sophisticated, with attacks like phishing and deepfakes on the rise, looking to exploit a single case of mistaken identity. A notable case in 2019 saw attackers use biometric-based deepfake technology to imitate the voice of a chief executive in order to carry out financial fraud, conning the business out of £200,000.

By using validation technology to verify a person’s identity, a person would have to provide a digital record to prove they are who they claim to be. This could provide benefits when interacting with new acquaintances, both in person and online, and protect the workplace from the increasing threat landscape. To achieve this, organizations will need to adopt a strategic approach to managing access to PII and company data. The identity system used should be secure, neutral, and independent of any other platform used by the business. 

Ahead of this, organizations should also look to implement identity-centric Zero Trust frameworks, which analyze and control access to their systems. The core principle of Zero Trust architecture is that all network traffic should be considered untrusted until verified. With Zero Trust providing the first layer of protection, validation technology could then be used as the second, to ultimately either confirm identity or notify of a threat.

Ramping up security measures

While vaccine passports look set to be the first step in bringing workplace validation to the mainstream, the technology is still in its early phases of adoption. Cyber threats to businesses are more prevalent than ever, and employees remain the frontline when it comes to security practices, meaning traditional measures are just as important.

However, with more cyberattacks and data breaches reported by the day, many companies still have work to do when it comes to security. Okta’s research found that nearly two-fifths (39%) of office workers have admitted to using just a single password as the only security measure to protect themselves from online threats. The UK is the biggest culprit for this in Europe, more so than the Netherlands (23%), Sweden (29%), Switzerland (32%) and France (32%).

But, a password alone is no longer an effective method of proving that someone is who they say they are, and businesses should not rely on this method of authentication to protect their workforces. More secure solutions, such as adaptive multi-factor authentication (MFA), need to be implemented. This will ensure sensitive information is protected, better preparing businesses for the workplace of the future. Using a system that adopts at least two-factor authentication to combine passwords with other factors, such as biometrics, contextual information or physical tokens, will make it much easier for organizations to identify malicious actors and anomalous activity, until validation technology hits the mainstream.

READ MORE:

In sectors where disclosing vaccination status is appropriate for employers, businesses should ensure that they are adopting a secure digital approach that incorporates MFA as part of a vaccine passport. This will protect PII and enable a safe return to workspaces in the post-pandemic world. If successful, the introduction of vaccine passports could ultimately start the move towards a trend for workplace validation, and advance security measures for both employees and businesses.

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Ian Lowe

Ian Lowe is Head of Industry Solutions EMEA at Okta. In his 19 year career, Ian has become a recognised product marketing and sales enablement leader having created and launched successful cloud-based identity and access management solutions that are used by top technology firms, financial services organisations and governments around the world today.

Laying the foundations for global connectivity

Waldemar Sterz • 26th June 2024

With the globalisation of trade, the axis is shifting. The world has witnessed an unprecedented rise in new digital trade routes that are connecting continents and increasing trade volumes between nations. Waldemar Sterz, CEO of Telegraph42 explains the complexities involved in establishing a Global Internet and provides insight into some of the key initiatives Telegraph42...

Laying the foundations for global connectivity

Waldemar Sterz • 26th June 2024

With the globalisation of trade, the axis is shifting. The world has witnessed an unprecedented rise in new digital trade routes that are connecting continents and increasing trade volumes between nations. Waldemar Sterz, CEO of Telegraph42 explains the complexities involved in establishing a Global Internet and provides insight into some of the key initiatives Telegraph42...

IoT Security: Protecting Your Connected Devices from Cyber Attacks

Miro Khach • 19th June 2024

Did you know we’re heading towards having more than 25 billion IoT devices by 2030? This jump means we have to really focus on keeping our smart devices safe. We’re looking at everything from threats to our connected home gadgets to needing strong encryption methods. Ensuring we have secure ways to talk to these devices...

Future Proofing Shipping Against the Next Crisis

Captain Steve Bomgardner • 18th June 2024

Irrespective of whether the next crisis for ship owners is war, weather or another global health event, one fact is ineluctable: recruiting onboard crew is becoming difficult. With limited shore time and contracts that become ever longer, morale is a big issue on board. The job can be both mundane and high risk. Every day...

London Tech Week 2024: A Launched Recap

Dianne Castillo • 17th June 2024

Dominating global tech investment, London Tech Week 2024 was buzzing with innovation. Our team joined the action, interviewing founders and soaking up the latest tech trends. Discover key takeaways and meet some of the exciting startups we met!

The Future of Smart Buildings: Trends in Occupancy Monitoring

Khai Zin Thein • 12th June 2024

Occupancy monitoring technology is revolutionising building management with advancements in AI and IoT. AI algorithms analyse data from IoT sensors, enabling automated adjustments in lighting, HVAC, and security systems based on occupancy levels. Modern systems leverage big data and AI to optimise space usage and resource management, reducing energy consumption and promoting sustainability. Enhanced encryption...