Vaccine passports: the future of workplace security?

Ian Lowe, Head of Industry Solutions EMEA at Okta, explores the technology behind vaccine passports and how this could be replicated to create validation methods by authenticating identity, qualifications, and skills and improving workplace security.
Ian Lowe, Head of Industry Solutions EMEA at Okta, explores the technology behind vaccine passports and how this could be replicated to create validation methods by authenticating identity, qualifications, and skills and improving workplace security.

Proof of vaccine status is not a new idea. Vaccination history has helped to enable international travel for years, and in some countries, it is required for entry. In the US, vaccine passports were even introduced in the late 19th century to prove that passengers travelling abroad had been vaccinated from smallpox. More than 100 years later, the certification has gone digital, but the concept remains the same.

In the UK, the NHS Covid Pass app allowed double vaccinated adults to avoid quarantine when returning from amber-list countries during the summer, and it is possible that this could still play a part in everyday life. But there has been much debate on this issue. Despite scrapping the idea for now, the English Government has stated that vaccine passports will be “kept in reserve” should they be needed throughout autumn and winter, while both Scotland and Wales have confirmed they will be required for entry to large events, nightclubs and sports venues.

From a business perspective, discussions are also underway as to whether these certificates could be deployed to fully reopen workspaces to help employees feel safe. This validation method, however, requires a secure digital approach to be trusted, as vaccine passports could be easily forged or replicated. And once this technology is finetuned, it could be a trend we see continuing in the workplace to validate identity in the future.

Getting vaccine passports right

A number of organizations, including tech giants Google and Facebook, have begun to require their employees to prove their vaccine status as they return to offices. There has been some concern in the UK that this could cause potential issues surrounding existing employer policies and employment laws. But Okta’s recent research has found that 22% of office workers would feel safer returning to the workplace with compulsory vaccine passports in place, and 15% support voluntary options. 

To avoid the risk of forgery, this validation method needs to be secure. Physical vaccine passports were successful in the US at the time of the smallpox outbreak, but now would be far easier to edit or falsify. The digital vaccine records of today must be simple and secure, incorporating optimal security features that properly protect personally identifiable information (PII). This is crucial to ensuring that people are happy with their medical data being stored, and trust that it is being kept safe.

Benefits of workplace validation

Once the technology behind vaccine passports is proven to work effectively, it could then be replicated and used for other forms of validation, such as to authenticate qualifications, skills and other accreditations. For example, an outsourced electrician could show proof of accreditation to work on high voltage lines, or contractors could present evidence that they are allowed to access or view secure information, offering an additional layer of privacy and security.

Currently, an increasing number of successful fraudulent attacks on businesses happen when the perpetrator is not who they say they are. In tandem, technology is getting increasingly sophisticated, with attacks like phishing and deepfakes on the rise, looking to exploit a single case of mistaken identity. A notable case in 2019 saw attackers use biometric-based deepfake technology to imitate the voice of a chief executive in order to carry out financial fraud, conning the business out of £200,000.

By using validation technology to verify a person’s identity, a person would have to provide a digital record to prove they are who they claim to be. This could provide benefits when interacting with new acquaintances, both in person and online, and protect the workplace from the increasing threat landscape. To achieve this, organizations will need to adopt a strategic approach to managing access to PII and company data. The identity system used should be secure, neutral, and independent of any other platform used by the business. 

Ahead of this, organizations should also look to implement identity-centric Zero Trust frameworks, which analyze and control access to their systems. The core principle of Zero Trust architecture is that all network traffic should be considered untrusted until verified. With Zero Trust providing the first layer of protection, validation technology could then be used as the second, to ultimately either confirm identity or notify of a threat.

Ramping up security measures

While vaccine passports look set to be the first step in bringing workplace validation to the mainstream, the technology is still in its early phases of adoption. Cyber threats to businesses are more prevalent than ever, and employees remain the frontline when it comes to security practices, meaning traditional measures are just as important.

However, with more cyberattacks and data breaches reported by the day, many companies still have work to do when it comes to security. Okta’s research found that nearly two-fifths (39%) of office workers have admitted to using just a single password as the only security measure to protect themselves from online threats. The UK is the biggest culprit for this in Europe, more so than the Netherlands (23%), Sweden (29%), Switzerland (32%) and France (32%).

But, a password alone is no longer an effective method of proving that someone is who they say they are, and businesses should not rely on this method of authentication to protect their workforces. More secure solutions, such as adaptive multi-factor authentication (MFA), need to be implemented. This will ensure sensitive information is protected, better preparing businesses for the workplace of the future. Using a system that adopts at least two-factor authentication to combine passwords with other factors, such as biometrics, contextual information or physical tokens, will make it much easier for organizations to identify malicious actors and anomalous activity, until validation technology hits the mainstream.

READ MORE:

In sectors where disclosing vaccination status is appropriate for employers, businesses should ensure that they are adopting a secure digital approach that incorporates MFA as part of a vaccine passport. This will protect PII and enable a safe return to workspaces in the post-pandemic world. If successful, the introduction of vaccine passports could ultimately start the move towards a trend for workplace validation, and advance security measures for both employees and businesses.

For more news from Top Business Tech, don’t forget to subscribe to our daily bulletin!

Follow us on LinkedIn and Twitter

Ian Lowe

Ian Lowe is Head of Industry Solutions EMEA at Okta. In his 19 year career, Ian has become a recognised product marketing and sales enablement leader having created and launched successful cloud-based identity and access management solutions that are used by top technology firms, financial services organisations and governments around the world today.

Tech and Business Outlook: US Confident, European Sentiment Mixed

Viva Technology • 11th February 2025

The VivaTech Confidence Barometer, now in its second edition, reveals strong confidence among tech executives regarding the impact of emerging technologies on business competitiveness, particularly AI, which is expected to have the most significant impact in the near future. Surveying tech leaders from Europe and North America, 81% recognize their companies as competitive internationally, with...

How smart labels are transforming supply chains

Sharath Muddaiah • 27th January 2025

As e-commerce continues to rise globally, the impact of just-in-time manufacturing and rising consumer expectations mean the need for real-time visibility has never been greater. Smart labels directly address this demand, offering solutions to long-standing challenges like shipment delays, theft, and the lack of traceability. With the smart label market projected to grow from $14.1...

The rise of loyalty apps

Sue Azari • 17th January 2025

Increased choice and a consumer more price sensitive than ever before, has made customers far more likely to shop around for the best deals. Price is now the number one factor in brand consideration. In an effort to bag a bargain, loyalty programs have become increasingly popular with consumers, with nine out of ten in...

Rocket launch challenges Elon Musk’s space dominance

Professor Sultan Mahmud • 16th January 2025

Amazon founder Jeff Bezos’s space company has blasted its first rocket into orbit in a bid to challenge the dominance of Elon Musk’s SpaceX. The New Glenn rocket launched from Cape Canaveral Space Force Station in Florida at 02:02 local time (07:02 GMT). It firmly pits the world’s two richest men against each other in...

Giesecke+Devrient launches new Smart Label at CES 2025

Giesecke Devrient • 06th January 2025

G+D has today launched the G+D Smart Label, its innovative tracking solution that transforms any package into an IoT device. Ultra-thin and only slightly larger than a credit card, the new Smart Label proposition has been jointly developed by G+D in conjunction with its hardware partner, Sensos to enable cost-effective, accurate location tracking for a...

Choose an AI solution to transform beyond technology

Kit Cox • 09th December 2024

The first step is knowing exactly what your business wants to achieve with AI; think faster, smarter and more efficient. Once you know what you are working towards, you can start looking for a solution that can help you make it a reality. AI integration can feel like a daunting task at the beginning, so...

A Roadmap to Security and Privacy Compliance

John Lynch Director of Kiteworks • 04th December 2024

Only by understanding the current regulatory environment and implementing robust data protection measures, can organisations enhance their security posture, ensure compliance, and build resilience against the latest cyber threats. This article provides a comprehensive roadmap of how to do it.