# IT worker scams call for stronger HR processes

> IT worker scams show why business applications need identity checks, role based access, and audit logs.

**URL:** https://www.ciptadusa.com/blog/penipuan-pekerja-it-proses-hr-keamanan  
**Type:** blog  
**Author:** PT Cipta Dua Saudara  
**Category:** Application Security  
**Published:** 2026-09-28  
**Cover:** https://cdn-uagents.enitip.com/uploads/blog/2026-09/daily-appsec-20260928-021328.jpg  

## Article

# IT worker scams call for stronger HR processes

A Dark Reading report on IT worker scams shows that company security does not stop at the firewall. Attackers can enter through hiring processes, false identities, and internal access granted too quickly. Companies need an Indonesian IT consultant who can improve the human process and the technical controls together.

## Summary

Fake-worker cases expose gaps between candidate verification, onboarding, access provisioning, and activity monitoring. A one-time identity check is not enough when an internal account receives broad rights on its first day.

## The challenge for an Indonesian IT consultant

Companies often separate HR, IT, and security. HR checks documents. IT creates accounts. Security monitors logs. Attackers use the gap between those teams.

A safer process connects a candidate's identity to the right device, account, and work assignment. Initial access should stay limited. The system should request extra approval when someone reaches sensitive repositories, customer data, or production environments.

## Business application development needs identity controls

A business application should not only check whether a username and password are correct. It should also record the device, unusual location, permission changes, and administrative actions.

Use role based access. Separate daily accounts from admin accounts. Set expiry dates for contractor and vendor access. When employment ends, HR and IT should share one trigger that revokes accounts, tokens, VPN access, and cloud permissions.

Logs help companies find behavior that does not fit a person's work. An account downloading many repositories, creating new tokens, or reaching servers outside normal hours should enter a review process. These signals do not prove wrongdoing. They do justify another verification step.

## Checks teams can run

Start with an access inventory. Who can read code, customer data, HR documents, and production systems? Match every permission to a role and an employment contract.

Test offboarding. Revoke a sample account and measure how long it takes for tokens, groups, and device access to stop working. Check service accounts with no clear owner as well.

When choosing a custom software development service, ask the vendor to explain audit logs, approvals, role separation, and recovery procedures. A login feature without an audit trail makes an investigation much slower.

## References

- [Dark Reading: Stopping IT Worker Scams Requires Revamped HR Process](https://www.darkreading.com/cyber-risk/stopping-it-worker-scams-revamped-hr-process)
- [NIST Digital Identity Guidelines](https://pages.nist.gov/800-63-4/)
- [CISA: Insider Threat Mitigation](https://www.cisa.gov/topics/physical-security/insider-threat-mitigation)

Identity security needs daily testing, not only a hiring checklist. If your internal system needs to be built or repaired, discuss it with [an Indonesian software house team that builds custom applications](https://wa.me/6285792071380).

---

*Markdown version of https://www.ciptadusa.com/blog/penipuan-pekerja-it-proses-hr-keamanan — generated for AI agents and LLM crawlers.*
