When the Stakes Are Highest
Energy, transport, finance, telecommunications, healthcare — the more critical the infrastructure, the more it matters who can actually access it. These sectors, officially designated as critical infrastructure (KRITIS) in Germany, invest heavily in physical security and cybersecurity.
But even the most protected systems still need people to administer, maintain, and operate them, and that's exactly why insider threats are particularly risky for critical infrastructure operators: an external attacker has to break through defenses, while an insider may already hold a valid account, building access, privileged system rights, and detailed knowledge of how security actually works. Validato, a background screening and human risk management provider working across more than 200 countries, sees this as a risk no amount of technology alone can close.
The Insider Isn't Always on the Org Chart
The person posing that risk doesn't have to be a permanent employee. Germany's Federal Office for the Protection of the Constitution explicitly notes that business contacts and external service providers can carry the same kind of risk through their access alone. IT service providers, consultants, developers, project staff, facility management, maintenance companies, freelancers, and temporary workers all move through sensitive processes without necessarily appearing on a traditional org chart.
In Validato's view, a modern security concept shouldn't split people into "internal" and "external" — it should ask who has which access, and what risk comes with it.
A Risk Classification That Actually Fits the Role
Not every position calls for the same level of scrutiny. Validato recommends grading roles into three tiers:
• Level 1: low risk, with no or minimal access to sensitive information
• Level 2: elevated risk, where someone touches internal data, customer information, or relevant systems
• Level 3: high risk, tied to privileged IT access, critical infrastructure, development data, or strategic company information
Each level points to a different screening and security response, so there's a clear, traceable line running from role to access to risk to protection.
Layers That Work Together
A resilient security strategy for critical infrastructure rarely comes down to one control. It combines identity verification, pre-employment screening, least-privilege access, multi-factor authentication, segregation of duties, security awareness, technical monitoring, clear reporting processes, re-screening for critical roles, and structured offboarding. None of these substitute for each other — a background check can't stop a technical attack, and a firewall can't tell you whether a new hire's identity was ever properly verified.
Validato sees the strongest results where HR, security, compliance, and management work from the same picture: HR understands the person and the employee lifecycle, security understands access points, compliance understands the regulatory requirements, and management sets how much risk the organization is willing to accept.
People Are Part of the System
Critical infrastructure doesn't run on technology alone — it runs on people. Most operators already know precisely which servers, facilities, or data sets are critical. The next question is who has access to them, and how that risk has actually been assessed. That's where human risk management starts, and it's the work Validato does with critical infrastructure operators worldwide.