WIV Benchmark WIV Benchmark
WIV BENCHMARK
0 / 12
The Workforce Identity Verification Maturity Benchmark

How exposed is your help desk to identity-based attacks?

Most organisations cannot answer this with confidence. The help desk is the last line of defence against social engineering — and the first line attackers test. This 5-minute benchmark scores your maturity across the four dimensions that determine whether your help desk is part of your security posture, or part of the attack surface.

12 questions, 4 dimensions Free & ungated Optional shareable PDF report Used by CISOs, IAM & ITSM leaders
Maturity Score
Across Four Dimensions
Your organisation rated on a 4-level scale — Exposed, Reactive, Managed, Governed — for each of the four dimensions of WIV maturity. Reflects industry framing used by ISO, NIST and the IBM/Ponemon breach reports.
Weakest-Link View
Reflects Real Attacker Logic
Attackers don't average your defences — they probe them and exploit the weakest one. The benchmark surfaces your weakest dimension explicitly, because that's where the next breach starts.
Action Plan
Tailored to Your Score
A specific, prioritised list of next steps based on the level you scored in each dimension. The improvements that move you from where you are to the next level — not generic best practice.

What is Workforce Identity Verification?

Workforce Identity Verification (WIV) is the discipline of confirming that the person asking your help desk to take a privileged action — reset a password, unlock an account, change an MFA device — is actually the legitimate employee they claim to be. It is the control that sits between an attacker with stolen credentials and your entire identity infrastructure.

Why this matters now

According to the 2025 IBM/Ponemon Cost of a Data Breach Report, phishing and stolen credentials are the top two initial attack vectors, and AI-generated impersonation has collapsed the cost and skill required to socially engineer a help desk agent. The control most organisations rely on — agent judgement — is no longer fit for purpose.

The four dimensions measured

  • Threat Awareness & Visibility — do you know what's hitting you?
  • Process Discipline & Agent Discretion — is policy enforced or improvised?
  • Verification Method Strength — what actually proves identity?
  • Audit, Logging & Detection — would you see an attack in progress?

The four maturity levels

Exposed — critical gaps, high breach risk. Reactive — partial controls, significant exposure remains. Managed — solid foundation, key gaps to close. Governed — best practice, maintain and extend. Your overall level is the level of your weakest dimension — because that is the dimension an attacker will find.

Scroll to Top
Scroll to Top
Generating your PDF report…
USUALLY 1–2 SECONDS