Stop hiring fraud before it starts. Visit 909Shield.ai

by
Den Jones

Trust the Human: Why the Modern Workforce Needs a Multi-Layered Identity Perimeter

A resume can be generated. A face can be synthesized. A voice on a help desk call can be cloned in real time. In a world where nearly anything about a person can be faked, the most valuable currency an organization has is certainty about who it's actually dealing with.

That's the problem 909Shield exists to solve. We think of it as the security perimeter for the modern workforce — and it starts with a simple idea: trust the human, not just the credentials they present.

The Remote Hiring Crisis

Remote hiring gave companies access to a global talent pool. It also gave fraud rings, deepfake operators, and organized crews a wide-open door — and the pipeline breaks down in a predictable, four-stage pattern.

Fake applicants. Inflated pipelines built on résumés and identities that don't exist in the first place — an estimated 30% of applicants to remote roles aren't real, according to Gartner and CareerBuilder research. Proxy interviews. A different person sits the interview than the one who applied, swapped mid-process without anyone noticing. AI fraud. Deepfakes and AI answer the questions live, mimicking a real candidate's face and voice in real time, using synthetic identities to get past screening. The end result is a bad hire: the wrong person, unqualified — or a hacker with a badge, a laptop, and a login of their own.

The cost isn't abstract. U.S. firms lost an estimated $800 million to fraudulent hires in 2024, per DOJ and FBI reporting — and every fraudulent hire that slips through the pipeline also drains recruiting budget, wastes engineering time onboarding someone who shouldn't be there, and opens the door to something far more expensive: the average cost of a U.S. data breach reached $10.22 million in 2025, according to IBM.

It Doesn't Stop at the Interview

The same identity gap that lets a fake candidate through the front door also shows up at the help desk — and once an attacker is inside, the stakes get higher, not lower.

The pattern is just as predictable: an attacker builds a profile from LinkedIn and breach data, spoofs a caller ID, and calls the service desk claiming to be a locked-out employee (the pretext call). The agent accepts easily-guessed answers — date of birth, employee ID, department — with no callback, manager confirmation, or video check (weak verification). The service desk resets the password or re-enrolls MFA to a device the attacker controls, handing over a fully trusted identity (the credential reset). The attacker now holds a valid, trusted identity, free to move laterally and escalate privileges — no malware needed to get in (account takeover).

This isn't a theoretical risk. Voice-phishing attacks targeting help desks rose 442% from the first half to the second half of 2024, according to CrowdStrike's 2025 Global Threat Report. Once an attacker reaches a domain administrator account, it can take less than 40 minutes from a single help desk call — no malware deployed, per Palo Alto Networks' Unit 42 2025 Global Incident Response Report. In 2023, a roughly 10-minute impersonation call to MGM Resorts' service desk led to a breach that cost the company an estimated $100 million.

Why Single-Point Checks Fail

Both of these crises trace back to the same root cause: identity gets verified once, at one moment, and then trusted indefinitely. A recruiter eyeballs a candidate on a video call. A help desk agent takes a caller's word for their date of birth. Each of these is a snapshot, not a system — and snapshots are exactly what modern fraud is built to defeat.

Deepfake video and voice tools can now convincingly puppet a face and voice in real time. AI writing tools can generate a flawless resume for a person who doesn't exist. A single checkpoint, however well-designed, only has to be fooled once.

The 909Shield Trust Layer

909Shield is built as a layered trust system, not a single gate, because no one signal is enough to catch what modern identity fraud looks like.

Identity Proofing sets the baseline. Before a candidate or caller gets anywhere near a live interview or a sensitive request, 909Shield verifies official government-issued documents, runs initial identity authentication, and establishes a starting trust level.

Biometric Monitoring and AI Fraud Protection carry that trust through the live session. Continuous face and voice verification runs for the duration of the interview or call — not just at the start — specifically to prevent the mid-process swap where a proxy takes over once the initial check is passed. Real-time and post-session AI analysis watches for deepfake indicators and gaze anomalies that give away a synthetic or manipulated feed.

Telemetric Risk Data adds context. IP address, geolocation, and device signals are scored continuously against external threat feeds, surfacing the "laptop farm" and reused-infrastructure patterns that organized fraud rings depend on — the same patterns the FBI has flagged in large-scale remote-worker fraud schemes.

Together, these layers roll up into a single Universal Trust Score (0–100), and an emerging Portable ID capability lets a candidate's verified credentials, certifications, and experience travel with them across platforms — reducing repeat friction while keeping every verification tied back to a real, consented identity via a built-in consent ledger.

None of these layers is designed to stand alone. Biometric verification without continuous monitoring can be defeated by a proxy who takes over after the first check passes. Monitoring without identity proofing has nothing to anchor to in the first place. Telemetric data without both has signal but no subject. Stacked together, they turn identity verification from a single locked door into a system an attacker has to defeat completely, at every stage, to get through.

Built Into the Tools You Already Use

909Shield is API-first and MCP-ready, designed to sit inside the systems your teams already run rather than replace them.

For hiring, your ATS stays the system of record — Workday, Greenhouse, iCIMS, Lever, SmartRecruiters, or a custom platform. 909Shield enforces an Application Gate (identity proofing before an application is even accepted) and an Interview Gate (biometric and AI fraud protection through the live interview), then writes the trust score, session recordings, and risk flags back to the candidate record.

For IT, the same model applies to your service desk — ServiceNow, Zendesk, Freshservice, Jira Service Management, BMC Helix, or custom. A Verification Gate confirms caller identity against official documents and HR records before a technician actions a password, MFA, or access reset, and a Session Gate monitors the call itself for voice-clone and deepfake anomalies.

Every tenant configures its own rules — what gets checked, how long recordings are retained, where risk thresholds sit, and exactly what's written back into your ATS or ticketing fields — backed by a full consent ledger and audit-ready export for every session.

Trust, Without Slowing Anyone Down

The instinct with fraud prevention is often to add more friction: more forms, more manual review, more delay between a great candidate and an offer, or a locked-out employee and a working password. 909Shield is built to run in the background of the workflows you already have, verifying identity before access is granted, monitoring for tampering while it matters, and reconciling context after — without turning hiring or IT support into an interrogation.

In a world of deepfakes and identity theft, certainty is the differentiator. 909Shield is the security perimeter for the modern workforce, eliminating fake applicants, proxy interviews, AI fraud, and fraudulent access — so you can trust the human on the other side of the screen.

909Shield is consumption-based, starting at $5 per identity proofing or $10 per video call, with monthly and enterprise plans for teams verifying at scale. Learn more at 909shield.ai.


Sources: IBM, "Cost of a Data Breach Report 2025"; U.S. DOJ & FBI reporting (2025); Gartner; CareerBuilder; CrowdStrike, "2025 Global Threat Report"; Palo Alto Networks Unit 42, "2025 Global Incident Response Report: Social Engineering Edition"; MGM Resorts / Scattered Spider breach analyses, 2023.

About our Author
About our guest
Den Jones

Den Jones is a recognized leader in Zero Trust security with over 35 years of IT and cybersecurity experience spanning the tech, finance, and manufacturing industries.  Den is the host of the podcast 909Exec, focusing on helping executives in technology.  He is also an evangelist on the speaking circuit from keynote events to moderation; his blend of Scottish humor and decades of experience leaves lasting memories and education.

Prior to founding 909Cyber Den ran Enterprise Security at Adobe and Cisco and was the Chief Security Officer at SonicWall and Banyan Security.  Den’s organizations led the pro-active strategies, execution, and operation of mission critical services.  

His leadership has shaped forward-thinking cybersecurity programs, and his influence extends into the broader industry through contributions to the Identity Defined Security Alliance, Microsoft’s Cybersecurity Council, and multiple Zero Trust advisory boards.

Known for building pragmatic and scalable security solutions, Den blends technical depth with real-world execution. Outside of cybersecurity, he's a passionate music producer with vinyl releases to his name, and an avid fan of soccer, snowboarding, golf, fishing, and food—bringing creativity and balance to every challenge he tackles.

Connect with
Den Jones
on
LinkedIn

Still have questions?