Cyber Security

Company’s new ‘Zero Trust’ security policy extends to doubting whether Kevin from accounts actually needs to eat lunch

A Manchester-based financial services firm has taken its implementation of Zero Trust security architecture to what IT consultants are describing as its natural conclusion, with employees now required to justify their biological functions through a series of escalating verification processes.

Hartley Bramford Financial Solutions introduced the enhanced security framework last month following a company-wide audit that determined traditional perimeter-based security was insufficient. The policy has since expanded beyond network access to encompass what head of information security Claire Denham calls “the full spectrum of potential threat vectors, including human sustenance requirements”.

Kevin Moorhouse, a accounts payable clerk who has worked at the company for seven years, now faces a minimum of three separate authentication challenges before accessing the staff kitchen. These include biometric verification, a written explanation of his nutritional objectives, and a risk assessment form evaluating whether his proposed lunch break presents an acceptable departure from his workstation.

“I had a Tesco meal deal yesterday and the system flagged it as anomalous behaviour because I normally bring sandwiches from home,” Moorhouse said. “I spent twenty minutes in a video call with the security operations centre explaining that my wife had forgotten to do the weekly shop. They’ve put me on enhanced monitoring.”

The policy documentation, which runs to 247 pages, specifies that no employee activity should be considered legitimate without continuous validation. Toilet breaks now require manager approval and GPS tracking. Coffee consumption is logged and cross-referenced against historical patterns, with any deviation triggering an automatic review. One employee was temporarily suspended after their third cup of the day was deemed inconsistent with their usual caffeine intake profile.

“The principle is actually quite simple,” Denham explained. “If we can’t trust Kevin to access a shared drive without multi-factor authentication, why would we trust him to leave his desk without verifying his stated intentions? Trust is a vulnerability. Kevin is a vulnerability.”

The company has installed verification terminals at seventeen separate locations throughout the office, including one inside each toilet cubicle. Employees must scan their security passes, provide a thumbprint, and select from a dropdown menu of pre-approved biological functions. The system times each interaction and compares it against industry-standard duration metrics.

Martin Eccleston, the firm’s chief technology officer, acknowledged that productivity has declined by approximately 40 per cent since implementation but insisted this represented an acceptable trade-off for the enhanced security posture. He noted that several employees have stopped eating lunch altogether, which he described as “encouraging evidence of cultural adaptation”.

Moorhouse has submitted a formal request to work from home, though this was rejected on the grounds that the company cannot verify the security of his kitchen.

Leave a comment

Your email address will not be published. Required fields are marked *