HRM & Cybersecurity Blog | Living Security

The Access Equation: Identity Security Meets Human Risk

Written by Crystal Turnbull | July 17, 2026

Identity is one of the most overlooked levers for reducing human risk. Privilege creep, MFA fatigue, and provisioning errors create vulnerabilities that traditional security awareness training never addresses. At HRMCon 2025, Labcorp's Ashley Atiles and Alfonso Mancuso shared how correlating identity and access management data with behavioral patterns creates a more complete picture of human risk and enables more effective interventions.

Register for HRMCon 2026

Why Identity Is the Most Overlooked Lever for Reducing Human Risk

Most human risk management programs focus exclusively on behavior: how employees respond to phishing simulations, whether they complete training modules, and how they interact with security policies. These are important signals, but they tell only part of the story.

Identity and access data reveals the other half. A user who has never clicked a phishing email is low risk by behavioral measures, but if that same user holds domain admin privileges across critical systems, their risk profile changes dramatically. The combination of behavior and access determines actual risk exposure.

At HRMCon 2025, the Labcorp team demonstrated why identity data is essential for accurate risk assessment. MFA fatigue, where users are bombarded with authentication requests and eventually approve one they should not, is a risk pattern that only becomes visible when you correlate access data with behavioral signals.

Where Privilege Creep, MFA Fatigue, and Provisioning Errors Create Vulnerabilities

Three identity-related risk patterns are particularly dangerous and frequently overlooked:

  • Privilege creep. As employees change roles, they accumulate access rights that outlive their current responsibilities. A user who moved from marketing to finance three years ago may still hold access to systems in their former department, creating an expanded attack surface that neither department fully monitors.
  • MFA fatigue. When users receive repeated authentication push notifications, they may eventually approve one out of frustration, granting an attacker access. This is a behavioral risk pattern, but it is driven by an identity management problem: excessive authentication triggers.
  • Provisioning errors. When new employees are granted more access than their role requires, or when departing employees retain access after termination, the organization's risk posture is worse than any risk assessment would suggest. These are identity management failures that create human risk vulnerabilities.

Correlating IAM Data with Behavior Patterns to Prioritize What Matters

The breakthrough insight from the Labcorp team was that identity data and behavioral data are each incomplete without the other. Human Risk Management (HRM), as defined by Living Security, correlates three pillars: behavior, identity and access, and threat. This cross-domain correlation is what makes predictive risk intelligence possible.

By analyzing 200+ risk indicators across these domains, the Living Security platform identifies risk patterns that no single domain can reveal:

  • High privilege plus high behavioral risk. A user with elevated access who also exhibits risky behaviors represents an urgent risk priority.
  • Low privilege plus emerging behavioral risk. A user with limited access whose behavioral patterns are trending toward risk may be developing habits that will become dangerous as their access grows.
  • Access anomalies without behavioral signals. A user whose behavior is compliant but whose access profile suddenly changes may be a compromised account that traditional monitoring would miss.

Learn how HRM correlates identity, behavior, and threat data

Moving from Identity Visibility to Targeted, Scalable Interventions

Once identity and behavioral data are correlated, the next step is using those insights to drive targeted interventions. The Labcorp team outlined a scalable approach:

  1. Identify the highest-risk combinations. Use cross-domain risk scoring to identify users whose combination of access and behavior represents the greatest organizational risk.
  2. Deploy automated interventions. For routine risks, use AI-driven automation to deliver targeted micro-learning, policy nudges, or access reviews without manual effort.
  3. Escalate complex cases. When risk indicators suggest a compromised account or intentional policy violation, escalate to the security team for investigation.
  4. Track and report. Measure risk reduction at the individual, team, and organizational level. Demonstrate how identity-behavior correlation reduces exposure over time.

Labcorp's Results: Reduced Exposure, Better Efficiency, Stronger Culture

By correlating identity data with behavioral signals, Labcorp achieved measurable improvements in their risk posture. Their human risk management program, powered by the Living Security platform, reduced data-loss exposure, improved the efficiency of their security team, and built a stronger security culture across the organization.

Their experience validates what the independent Cyentia Institute research shows: organizations that use predictive human risk management achieve a 50% reduction in risky users and a 98% decrease in data-loss exposure. For Labcorp, these outcomes are not theoretical. They are the result of treating identity and behavior as two sides of the same risk coin.

Explore how the HRM platform correlates identity and behavioral data

Frequently Asked Questions About Identity and Human Risk Management

How does identity data improve human risk assessment accuracy?

Identity data reveals the potential impact of a user's behavior. Two users may exhibit identical behavioral risk, but if one holds domain admin privileges and the other has minimal access, their actual risk to the organization is vastly different.

Do we need a separate IAM platform to integrate identity data with HRM?

No. The Living Security platform integrates with 60+ security tools, including major IAM platforms, to correlate identity data with behavioral and threat signals without requiring additional infrastructure.

Can identity-behavior correlation help with compliance requirements?

Yes. Regulated industries increasingly require organizations to demonstrate that access controls are effective and that risks are being managed. Correlating identity data with behavioral outcomes provides the evidence needed for audits.

Explore the other sessions from HRMCon 2025: The Age of Adaptive Defense | The Next Evolution of Human Risk Management | Creating Human Risk Visibility | Innovating Risk Management Without Breaking Compliance | Lessons from the Frontline | The Future of HRM: Agentic AI | Evolving the Role of the CISO