layered assessment security
/
/
Why assessment programs require layered security, not isolated controls
Blog

Why assessment programs require layered security, not isolated controls

Wally Dalrymple, Chief Security Officer, PSI and ETS

August 18, 2026
Share:

Assessment security has never been static. As testing evolves, so do the threats that can undermine the integrity of assessment outcomes.

What is different today is that credentialing programs face a growing range of technology-enabled challenges, from synthetic identities and deepfakes to global fraud-as-a-service operations. At the same time, expectations around candidate experience and accessibility continue to rise. Programs are increasingly expected to support flexible delivery options while maintaining confidence in outcomes.

In response, many organizations have invested in individual security controls, such as online proctoring, secure delivery platforms, and lockdown browser technologies. Of course, all these tools play an important role in protecting assessment integrity. However, modern threats rarely rely on a single tactic, and no single security control addresses every risk. That’s why effective assessment security requires multiple layers.

The limits of isolated controls

Security conversations frequently focus on individual technologies or controls and whether a particular tool prevents cheating, stops impersonation, or identifies misconduct. But assessment security is not a single event. It spans the entire assessment lifecycle, from candidate registration and identity verification through to test delivery, monitoring, post-test analysis, and investigation.

A candidate attempting to bypass security controls may exploit multiple vulnerabilities rather than a single weakness. For example, identity fraud can be combined with unauthorized assistance, and content theft commonly occurs alongside coordinated answer sharing. More recently, AI-enabled tools have introduced new opportunities for misconduct while making existing tactics harder to detect.

This is why isolated controls often create a false sense of security and very real blind spots. An identity check may confirm who a candidate is at the start of an assessment, but it cannot reveal what happens throughout the session. A webcam captures part of the testing environment, but not everything that happens around the candidate. Session-level monitoring might identify unusual behavior while missing broader patterns that only emerge across multiple candidates, locations, or testing events. Confidence doesn’t come from any one control, but from how multiple layers and controls work together.

Explore our A-Z of modern test security tools, from advanced IDV to web monitoring.

Modern threats require layered assessment security

Rather than viewing security as a collection of individual tools, organizations should think about assessment security as an integrated architecture. Each layer contributes a different type of confidence:

1. Identity = trust in the person

Can we confidently verify that the individual taking the assessment is who they claim to be?

2. Environment = trust in the conditions

Can we confidently understand the testing environment and identify risks that may exist outside the immediate webcam view?

3. Behavior = trust in what is happening right now

Can we identify unusual activity as it occurs and distinguish genuine concerns from normal testing behavior?

4. Analytics = trust in the patterns that emerge over time

Can we identify connections, trends, and coordinated activity that would otherwise remain hidden?

Individually, each layer provides valuable information. Together, they create a more complete picture of risk and support more informed, defensible decisions.

Moving from detection to deterrence

One of the most significant benefits of layered security is its ability to move credentialing programs from reactive detection to proactive deterrence.

Historically, many security programs relied heavily on post-test investigations. Security concerns were identified after an assessment had been completed, requiring lengthy reviews and potentially complex remediation efforts.

Modern security architectures increasingly focus on preventing issues before they occur.

For example, in ETS and PSI programs, layered security approaches have contributed to a 60% shift from post-test detection to pre-test deterrence, helping identify and address risks earlier in the assessment lifecycle.

This shift is important not only because it reduces fraud, but because it protects honest candidates, strengthens confidence in assessment outcomes, and helps safeguard the value and credibility of credentialing programs. The strongest security programs do not simply identify misconduct after the fact, they create conditions that make misconduct significantly more difficult in the first place.

Security and candidate experience are not opposing goals

A common misconception is that stronger security inevitably creates a worse candidate experience. In reality, the most effective security architectures balance security, fairness, accessibility, and usability.

Candidates should have confidence that the assessment process is fair and that all participants are held to consistent standards. Equally, credentialing programs need security controls that support defensible decisions without creating unnecessary friction.

This is another advantage of layered approaches. When multiple signals are available, decisions are informed by a broader set of evidence rather than relying on a single indicator. Identity verification, environmental context, behavioral signals, and analytical insights work together to provide a more complete understanding of risk. The result is stronger security, a more equitable testing experience, and greater confidence in assessment outcomes.

Connected intelligence reveals what individual sessions cannot

Some of the most significant security risks only become visible when data is connected. Patterns of content sharing, coordinated behavior, repeat offenders, and emerging fraud tactics may not be apparent within a single testing session. They often emerge when activity is analyzed across candidates, devices, locations, and time.

This is where advanced analytics has become an increasingly important component of modern assessment security. By connecting signals across the assessment ecosystem, organizations uncover hidden risks, accelerate investigations, and respond more quickly to emerging threats.

In ETS and PSI programs, detection times have been reduced from up to 64 days to less than 24 hours, enabling much faster investigation and response.

Building confidence through layered assessment security

Assessment security is no longer about selecting a single control and expecting it to solve every problem. Modern threats are more sophisticated, more varied, and more interconnected than ever before. Effective protection for your credentialing program requires an architecture that combines multiple complementary layers, each providing a different perspective on risk.

Identity assurance helps establish trust in the person. Environment controls help establish trust in the conditions. Behavioral monitoring helps establish trust in what is happening during the assessment. Advanced analytics helps establish trust in the patterns that emerge over time.

Together, these layers create a more complete picture of assessment integrity and help organizations make more confident, defensible decisions. For credentialing programs, that confidence supports everything from protecting credential value and employer trust to safeguarding public protection and regulatory confidence.

Explore the Four Layers of Assessment Security

Want to learn more about how layered security works in practice?

Explore the framework and download the four guides on Identity Assurance, Environment & Session Controls, Behavioral Monitoring, and Advanced Analytics.

Attend our upcoming webinar in partnership with the Institute for Credentialing Excellence (I.C.E.) to explore how credentialing programs can put layered assessment security into practice.

Share:

We're here to help

Whatever your testing needs, our friendly, experienced team is here to provide guidance and answer your questions.

Stay informed

Join our newsletter and stay tuned with the newest insights

Search

Test Takers
An ETS company