Zürich, 22.09.2026 (PresseBox) - In many organisations, Human Resources and Information Security still operate in silos: the CHRO manages hiring and talent development, while the CISO protects systems and data. Yet both functions share the same blind spot – the risk associated with people themselves, from a candidate who falsifies a qualification to an employee with privileged access who becomes a target of social engineering.
Validato believes background checks should neither be treated solely as an HR compliance formality nor remain outside the CISO’s scope as a “purely human” issue. “Human risk does not respect departmental boundaries. When CHRO and CISO jointly define which roles require which level of verification, and at what frequency, they close a gap that neither technology nor HR policy can address on its own,” says André Naef, CEO of Validato.
Validato proposes a Human Risk Management model that classifies roles according to their exposure – for example access to critical systems, financial data or customer information – and aligns the scope of checks with that exposure. In Spain, each processing activity must be assessed separately and supported by a valid legal basis; necessity and proportionality are essential. Consent should not be presented as a universal solution in employment, where an imbalance of power may exist between the company and the candidate or employee.
About Validato: Validato is an international provider of background checks and Human Risk Management, headquartered in Zurich, Switzerland, and operating internationally. Its modular, ISO 27001-certified platform enables companies to configure candidate and employee checks according to the role and within the applicable legal framework. Core data is processed and stored in Switzerland and the EU and, under Validato policy, deleted within a maximum of 120 days. No minimum volumes and no setup fees.
-
IT-Awards
Aktuelle Beiträge aus "IT-Awards"
-
Bedrohungen
Aktuelle Beiträge aus "Bedrohungen"
- Netzwerke
-
Plattformen
- Schwachstellen-Management
- Betriebssystem
- Server
- Endpoint
- Storage
- Physische IT-Sicherheit
- Verschlüsselung
- Allgemein
- Cloud und Virtualisierung
- Mobile Security
Aktuelle Beiträge aus "Plattformen" -
Applikationen
Aktuelle Beiträge aus "Applikationen"
-
Identity- und Access-Management
- Benutzer und Identitäten
- Authentifizierung
- Biometrie
- Smartcard und Token
- Access Control / Zugriffskontrolle
- Blockchain, Schlüssel & Zertifikate
- Zugangs- und Zutrittskontrolle
- Passwort-Management
- Allgemein
Aktuelle Beiträge aus "Identity- und Access-Management" -
Security-Management
- Compliance und Datenschutz
- Standards
- Sicherheits-Policies
- Risk Management / KRITIS
- Notfallmanagement
- Awareness und Mitarbeiter
- Sicherheitsvorfälle
- Allgemein
- Digitale Souveränität
Aktuelle Beiträge aus "Security-Management" -
Specials
Aktuelle Beiträge aus "Specials"
- eBooks
- Security Visionen 2026
- Zukunft der IT-Sicherheit 2024
- Kompendien
- Anbieter
- Cyberrisiken 2025
- Bilder
- CIO Briefing
-
IT Security Best Practices
Aktuelle Beiträge aus "IT Security Best Practices"
-
mehr...