Labcorp on pairing phishing-resistant authentication with behavioral intelligence, and targeting interventions at the people the data points to.
Ashley and Alfonso share how Labcorp pairs identity controls with behavioral intelligence, and targets guidance where the data points.
Phishing-resistant authentication removes a major attack path — but it doesn’t cover every decision the workforce makes.
Ashley and Alfonso share how Labcorp pairs identity controls with behavioral intelligence, and targets guidance where the data points.
The risks identity controls can’t cover on their own.
Using workforce signals to see what identity misses.
Focusing guidance on the people the data points to.
Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.
0:07 Hello, y'all! Hi, everyone. Hello, y'all! Hi, everyone online. My name is Ashley Atiles. I know we both have a little bit difficult last names, but Atiles. Yeah, thank you, but… Ann? Alfonso Mancuso. And I'm not from the South, so I won't y'all. Y'all. What's that mean? Okay, well, anyway, so, so again, I'm Senior Director of Human Risk at Labcorp. what is human risk? Of course, that's all we're talking about here. So normally, when I say, what is human risk, it's all the risk that comes from a human, which sounds really daunting, but that's what I do, and I'm also, lead of… oh, excuse me, leading data protection right now, but that's just interim. Alright, and, I am, Vice President at Labcorp and the, Digital Trust Officer, and I… Have responsibility for anything that makes us advance our digital trust footprint. Security architecture engineering, our application security enablement program, product testing, and all of the identity and access management function for the enterprise.
1:15 So, the first thing I want to say is thank you to Living Security for our Precision Award. So, thank you for recognizing the hard work that my team does. So, Addison and Jen, I know you guys are watching. Very, very good job, great, thank you. That's me clapping for you guys, so sorry. Alright, and if you guys were with us last year, I mean, at HRMCon, we actually did a presentation that was kind of the precursor to this, so it's kind of going to be a continuation, but if you weren't there, it's kind of self-explanatory, so you guys weren't missing anything. So, what we'll cover today, those time limits might not work because Alfonso's on the stage with me, but they may, they may. So, what we're gonna cover… the first thing is technology doesn't make MFA stick. Actually, the people do, and we all know that people are the most important things, not just really technology. So every MFA… Every MFA workaround is a signal, not a compliance problem.
2:14 Problem? Nope. Struggling? Yes. Okay. And identity risk is no longer limited to people, now that we know AI and AI agents are first-class identities. As well as identity programs, they succeed when security aligns and how… with how the work happens. It has to be embedded, it has to be complementary, not just layered on top. So, the first thing, of course, technology doesn't make MFA, people do. So, when we talk about adoption is the real MFA challenge. So, we can say everyone is enrolled in MFA, but what are they actually doing with it? Are they using it securely? Are they using the right factors? All those types of information pieces that we can gather and kind of make decisions from there. So, security teams measure. Well, okay, well, we measure coverage, or adoption, assurance levels, and the stronger the authenticator or multi-factor type, the better. Compliance, meaning not just checking the box, but compliant with Being able to authenticate safely and securely.
3:24 And then the risk posture, right? We're extending that beyond just the application and the user, but also a combination of the application, user, and location signals, device signals, and anything we can get our hands on. Yeah, so looking from the technology, so he would be the technology part, or the identity part, and I look at it from the workforce. experience. What are they experiencing when they're going and using MFA? So, we always hear there's friction. Why do I have to do that if I… it's my data, or why do I have to do that I mean… I'm pretty sure that at least all of us have said. Why do I have to do that again, even outside of the organization? I'm talking about real life. You know, really. So, and interruptions. Is it taking too much time to actually do what we're asking them to do? learning curve, so we have everything from service workers, phlebotomists, up to CEOs, so there's a lot of different aspects that we have to consider. So, we have to meet them where they're at.
4:24 And also the trust in the process. Why is it that they need to be using phishing-resistant MFA? Why is it that we're asking them to do this? It's always the WIFM. I think we've always said that, is what's in it for them? Not only are we asking you to do it. So it's secure on our end, it's also secure on your end. So the two main questions. R? Are we… are we actually securing our credentials and our identities? Are we reducing account compromise? And the answer is yes, but… And then, always from the workforce is, but can I get my work done? Can I get my work done in time? Can I get it done without any interruptions, or the minimal amount of interruptions? And it's always the balance between friction and security, security and friction. So, every MFA workaround is a signal, not a compliance problem. So, you've heard a lot about signals and behavior signals. So, we would just want to say behavior reveals where security and work are misaligned. So, a couple years ago, and I think last year, I did a presentation with Ashley.
5:30 That said, 72% of people break security policy on purpose, whether that be MFA or anything else, because we put a barrier in their way that doesn't allow them to do the work how they need to do it. So we're not meeting them where they're at, where we actually could sit down and understand the business process and say, okay, how can you do this more securely? So what we observe is actually the behaviors. So we see delayed enrollment. So we're asking them to enroll in MFA. Are they doing that timely? And if they're not, why? And then bypass request. So, are they trying to do some type of request going around the security controls? And we all know about MFA fatigue approvals, where they're just saying the happy clicker, yes, yes, leave me alone, even if they didn't really send the request. And then, of course, what we see at Labcorp, and I'm sure a lot of people see, is the secure accounts and devices. So we have phlebotomists using one computer, maybe there's 10 of them using the same computer, maybe under a shared account or shared device. Yeah, and one of the most impressive things that we're seeing from the behavior and The encouragement, the nudging, which we'll get into a little bit more, is… Almost half of our workforce are frontline workers. They don't have an assigned asset to them, whether it's a laptop, MacBook, or a corporate phone.
6:51 And we're seeing close to 95% of our workforce is enrolled in MFA. Many of these individuals are doing so largely because of the communication and the program awareness of the importance of securing your credentials. So, and on that, Ashley always talks about her daughter, Bella, so my daughter, Carson, actually works at Labcorp as well, and she is a lab worker, and she'll message me sometimes to be like, why do I have to do that? Like, just leave me alone, like, and I'm like, okay, here, let's step back and understand what it is we're asking you to do and why. But she's really just trying to be facetious and make my life hard, but, you know. That's what kids are for. But that's what the signals are, right? We take that behavior and then look at them Well, they get translated to what we look at and consider signals. Friction. Now, why do I have to be prompted all the time? Hey, I'm on the network, why am I getting prompted for MFA every single time I try to access this application? We're taking all of that information and additional signal information and trying to analyze it, and we are using AI, analyzing what that means.
7:56 Relative to the environment, so that we can cater more targeted… a more targeted approach. To try to improve not only the behavior. But the net… the net adoption of what we really want, which is more secure, with less friction at the same time, right? And that's what phishing resistance is really all about. Gary and I keep fidgeting with my hands, because I don't know what to do with them, because you got me, like, should I have my hands closed, open, like, behind my back? I don't know what's going on. But here, I'm just going to stand like this, face forward. Alright, and how we respond using that behavior and the signal. So, our actions, so just like Alfonso said, we're trying to simplify that access. Meet the person, or the colleague, or the workforce Where they're at. excuse me, reduce that disruption, because we always know, in our line of business, the patient is the first priority. We need to make sure the patient care is not disrupted. And improved communication, so that's definitely our wheelhouse. So, under our human risk area, we don't reach out to corporate comms or anything to get communications sent out. We actually send all those in-house. So we craft them specific for whatever use case that might be, and then we send those out.
9:08 and definitely still the improved workforce experience. So we want them to think about security. kind of have it in the forefront, but not have to think about how to do it. I want to do it, but it's gonna be designed securely. I don't have to think, okay, I need to do this, this, and this to make it secure. It's just inherently secure. Oh, AI agents. Yeah, they are workforce identities. The industry… really recognizes them, and we look at them and need to look at them as a native identity class, not just a non-human identity like a service account. And why that matters, all AI agents are doing, Really, acting on behalf of a user. So, whatever the user security is, the AI agent will… will take that. I mean, prior… the prior speakers have talked about how agents will just discover what… what access you have, and use it to get the job done. That's where… that's where secure… more secure authentication methods, tighter authorization, as… as well as other controls are essential to ensure that The agents aren't doing something that they're not really… Intended or should be doing.
10:23 So, we're not going to cover this slide in depth, because you guys can read that on your own, and we don't… we just want to make sure that we mention AI, because we're in the error of AI. So, this is one of my favorite slides, is actually, identity programs succeed when security aligns with how the work happens, and that means trust connects security and the experience. So when we talk about security, experience, and trust, what are we actually talking about? So when we talk about security, we're saying protect identities without creating unnecessary barriers. So we're giving them strong authentication methods. We're allowing them to use, or we're providing phishing-resistant MFA factors to them. And then we also think about the risk-based access. Yeah, and one of those… one of those key elements of risk-based access is adopting principles of zero trust. We haven't heard that term today, I believe. But, where the device is trusted, or the location, the network you're coming from is a known trusted environment. That, paired with Strong authentication and context, Will allow us to, Provide a more seamless, frictionless experience, but at the same time, assure that we're reaching our security objective and targets for risk management.
11:37 And when we talk about experience, we're making secure behavior easier to adopt, and that's actually what we wanted to talk most about in this one slide, is what we're doing at Labcorp to allow this to connect the security with the experience and the trust. So we're trying to reduce that friction, streamline the enrollment, and support workflows. And the way we did that, we actually looked at the signals Because, again, signals is something that's going to help us to say, okay, what are people doing? Are they enrolled? Yes. We want to make sure, yes, they're enrolled. Okay, so what are they enrolled with? Are they enrolled with SMS, which we know that that's not what we want them to be enrolled with, but they were there, they were at the first step, they were at SMS, but now we want to convert that to a more phishing-resistant factor. We want to mature that factor. How do we do that? So we actually look at the data we have from our human risk platform and our human risk program and say, okay, so this, this subset of people have corporate devices. Are they using SMS?
12:32 If they are, why? They shouldn't be using SMS, because then they don't have that barrier to say, but you can't make me download something on my personal phone. This is a corporate-issued device. It's for you to use in corporate locations, so we're not asking you to do something outside the norm, quote-unquote. Yeah, and what we saw from the numbers were… when we first started with our MFA, Enterprise MFA program years ago, probably 6 or more. the overwhelming, dominant authenticator type was SMS. Why? It's easy. I have a mobile device, all I have to do is plug in my number, and I get a text message with a code. I don't have an app to install, and Labcorp doesn't… have access to my private information if I'm using my personal device. So we… we targeted our program to say it's only being used for this purpose. We don't know anything about you or your device. And it is optional if you want to use your personal device. And by doing that, we saw very high enrollment rates and adoption rates, and now that's why we're taking it to the next level. If you're willing to use your mobile device.
13:44 Use a push notification with a number challenge. making it phishing resistant, and stop using SMS, which is not… not as secure. As a matter of fact, we nudge them. with those communications, and they… their Precision Award winner, targeted at exactly the behavior that we're looking to change. So just recently, we introduced and modified the text message when you get an OTP through an SMS authentication. We give you the code, and then say, tip. Use Okta Verify, well, we're an Okta platform, no secret there. Use Okta Verify Push, it's easier, it's faster, and it's more secure. Yeah, more phishing resistant. Well, and phishing resistant, of course. Yeah, and some of the other things we did is, so when we're seeing not only corporate devices, we also used the data and said, okay, are the people outside of that using their personal phones, are they enrolled in SMS? Are they enrolled in OktaVerify? Are they using phishing Resistant?
14:46 And a combination of those, we also modified some of the communications and gave those targeted nudges to say, okay, you logged in with SMS, one time a day, but we also see that you're using, or you're enrolled in MFA, I mean. enrolled in OctoVerify, why did, you know, kind of like, please use the SMS, discontinue the use of SMS, and use the OctoVerify. Yeah, and, and… Since we started measuring, 5 weeks? we've seen a 15% decrease in SMS for authentication, and a 17% increase in phishing-resistant MFA in the authentication flow. And every time we… implement a target, one of those nudges. We see a spike, and then a sustained sustained action or sustained behavior that we then use for the next one. And we keep building on top of it. So we're not spamming people, we can send a broadcast email to all 75,000 plus of our workforce and say, every day.
15:55 do this. By day 3, it'll all be ignored, and you'll have an email rule that just trashes it. This is why we took a targeted approach, and it's not just through that one channel. It's through multiple channels, and the only way we were able to achieve that is by looking at the behavior, looking at the data. And using that to be precise. And that's kind of like where I was talking about meet them where they're at, just because, like, say my daughter is the example. She doesn't get to read her emails, she has a shared computer, but she might get that SMS text. for that, and it says, okay, thank you for using SMS, blah blah blah blah, but don't use that again. Actually use OktaVerify. So we're driving the behavior based on their behavior prior. And kind of learning from that. Small sample size, because we just enabled that knowledge on Tuesday, but we're already seeing an average, over the last 3 days of approximately 400 people a day. doing that real-time conversion and adopting. They log in with SMS, and soon after, we see them doing an active enrollment, or the next time they authenticate, it's with phishing-resistant MFA. And that's great, that's just great data in real time.
17:07 Alright, so 3 things for you all to do Monday, this is for you guys to actually take this home and into practice, is to measure adoption and not deployment. So, kind of like what we've been talking about. Are they enrolled? Great. That's not the only… kind of like what we used to say with phishing simulations. Give me that phishing simulation data, great. Okay, now we've matured to give you an entire human risk index, or we're giving you a behavior score. We want to know more, more in depth about that. So enable doesn't mean adopted. Secure behavior must become part of the work. So we want to… we want you to track your workforce adoption metrics along the MFA coverage with your identity and human risk teams, barring that you have human risk teams, but I'm sure you all have identity, or identity teams, but if you don't have human risk teams… We hope you have identities. Okay, yeah, sorry. We hope you have identity teams, and if you don't, then, I mean… Something… there's another conversation there, but… Yeah, and interpreting workarounds, right? Why are people using SMS? Because it's easy. It's something that they know. Maybe their bank app allows SMS.
18:11 We're looking at that as, okay, well, do you know that this is better, and here's why it's better, and more effective. And we're using that information at scale. just some numbers, right? We measure the number of workforce users that are using SMS, but just equally as important is the ones that are enrolled in SMS plus another authenticator, or a stronger authenticator. We're targeting them, make that shift. New hires. A lot of new hires are enrolling with MFA for the first time, they have to. Especially in a remote workforce, and what they're doing is, we're seeing that they're just picking SMSs the de facto. Well, soon, that won't be an option. If you're using a mobile device. For multi-factor, whether it's company-issued or your personal. we're not gonna allow you to do SMS any longer. Install the app, and soon.
19:09 pass keys, right? That's our next phase. That's our more advanced targeted phase, especially in labs and other areas where you can't have a mobile device. you need something different, and a hardware authenticator is key there. And of course, the last thing is expand human risk management beyond humans. I think we've heard that a few times today. Actually make sure that your agents or your AI workforce is getting the oversight that it needs. So make sure you're discussing that across your identity, security, human risk, governance. all those partners. And this is not on here, but I just wanted to make sure that I highlighted it. So you're probably like, why are they talking about MFA, and we're here talking about human risk? So we just wanted to make sure that the… you saw that we have a partnership that we've had, and we've grown using the data from the human risk management. program. So, without the data, and without all of the insights that we have.
20:05 his actual MFA project, sorry, I'm gonna take a look… wouldn't be as successful. It wouldn't. And that's the truth. But in return, we're getting that telemetry, that behavioral data, and feeding it back, right? So we can make even… better decisions for the future. So from where we were last year, where we're doing this continuous loop between identity and human risk, this is the next stage, right? And there's future stages to come, and we're just going to continue to build on that success. All right, well, thank you guys for staying awake with us. Hopefully you all did. I won't call out anybody that didn't, but no, I saw you, okay? Everyone's still awake. As indicated by the number of questions that we have. Oh, at home, okay. Is one of them how to properly pronounce my name? Point taken, so… I will, I will get on that. I'm only joking. I know, so… Do you typically report defensible improvements in your security, program.
21:12 Can you repeat the question? Sure. Do you typically report defensible improvements in your security posture? You want to take that? You can take it. I'll go right ahead. Okay, so from the identity perspective, we do, and we try to pick… these are many KPIs and KRIs, and some are both. So we try to pick the ones that are relevant, and in… not… Relative to the human risk side of the house, but in the identity space, we look at, Access recertifications is one. The number of delinquinquents, the people that we have to continue to nudge to do what they need to do, and how we can improve that. Mfa, we spent the last 20 minutes, almost 20 minutes talking about that. Don't want to beat that to death. But also from our, access management side, we… we do automation at scale. How can we get more of that adoption in place across enterprise applications? Automation, not… well, with and without AI, is more secure. Not only is it faster, but there are no mistakes, right? Our defect rate on access management and access requests and fulfillment across the environment are, .03% defect, meaning where there's a human involved, that's where the mistake is. And even then, they were very highly trained and very,
22:42 Mistake-averse. And I think if I understood the question correctly, so, like, what type of metrics we use from the Human Risk Management Program, so we actually use the behavior score from Living Securities platform to be an ESG metric, and it also gets reported to the board every month. Yeah, and we've introduced MFA enrollment or type as a contributor to the restore. Excellent answer, using the Libby, Libby metrics. Does rolling out the MFA, impact the phishing, the resistant ones, impact, for example, help desk calls, like, are they getting more? What are some of the, sort of, I guess, symptoms? So, so far, we're not seeing any… increase in help desk calls or assistance. We also leverage your enrolled MFA for account recovery and lockout, which leads to self-service.
23:38 And that's a… that's a big… that's a big win as well. Where we see some service desk impact is when people don't know that they can use a self-service flow with their enrolled authenticator to do recovery or a lockout, and we've been partnering with our service desk team and the tech ops group in general to improve on that? How can we get those numbers down? Look, there'll always be people that just want to call. Can't avoid that. But how can we make it so that we're driving them to the more secure. Better, less friction user experience, and… and… and not… talking to a human being. So, short answer, I think it's done quite the opposite. Right? Yeah. Next question is, how did employee feedback change your rollout strategy? I don't think it did. It actually, if anything, we've seen a very positive response.
24:39 People have reached out directly, hey, do you know this… the number challenge isn't available here, or you know that this is… yes, we know. We have a couple of people who said, hey, I used to be able to do a push notification on my Apple Watch. Well, that's not really something we supported anyway. So, you're not really losing much. But they were more informational questions. We've actually had some people reach out, because we have a Mission Safe, we call it Mission Safe box, so it's actually… anyone from the organization can email us and ask us any type of user behavior questions. So, we sent out the targeted comm. But someone responded back and said, can I actually roll this out to my entire team? They're overseas, can they use OctoVerify? So, although it wasn't meant for them, of course they can. Yeah, great, we would love you to. Well, please join me in thanking… Thank you. Actually, in a hunter.

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.