How Secure Is Secure Enough?

Share via:

Why security has to protect validity, not just tick boxes.

The third article in The Proctoring Question, a series on how remote proctoring earns and keeps trust. The first two looked at fairness across delivery channels and reviewer flag fatigue. This one asks how much security is enough.

Twenty years ago, assessment security largely meant protecting question papers, stopping impersonation and making sure that a candidate had not smuggled notes into the exam hall in their pencil case. 

Today we face bigger challenges. 

Technology has made some forms of misconduct easier, but it has also encouraged us to ask a much more fundamental question.

What is it that we are actually trying to protect? 

Recent decisions by prominent bodies to step back from remote exams for certain high-stakes cohorts have pushed private concerns into the public domain, prompting some to ask whether our current approaches are truly sufficient for the most critical assessments.

Our environment has certainly changed, in terms of proctoring we are no longer focused on whether it can catch opportunistic misconduct, but on whether it can reliably deal with organised, technology-enabled cheating at scale, without eroding candidate trust or distorting what the assessment was designed to measure.

Security can no longer be treated as just another technical checklist.

It has become part of the evidence that allows us to trust what an assessment result actually means.

Security and Validity: Two Sides of the Same Coin

At times we can be guilty of seeing security as an inconvenience, perhaps even a barrier to candidate experience, but in assessment, security and validity are inseparable.

Without meaningful security, candidates and stakeholders lose trust in the results we issue. If candidates can easily outsource answers, share live content or impersonate one another, the result no longer tells us what they know or can do. The assessment begins to measure ingenuity and technical know-how rather than competence.

But the opposite extreme is equally problematic.

If we over-engineer security, we can damage validity by changing the capability we are trying to measure. Similar to asking someone to walk a plank at height rather than on the ground: the task is identical, but you are now also measuring nerve. An assessment designed to test problem-solving can end up testing a candidate’s ability to operate under intense surveillance, manage unreliable technology and remain composed through repeated interruptions.

Controls that frequently disconnect candidates, freeze systems or flag ordinary behaviour as suspicious can disadvantage some candidates more than others. The final result may then reflect how successfully they navigated the assessment environment rather than how competent they were in the subject.

So the real question is not how much security we can impose, it is what level of security protects the result without distorting it. And that balance will look different for different assessments.

Security Is Built in Layers 

When we talk about digital security, we often turn it into a beauty parade of features. We compare platforms by the list of controls they offer: lockdown browsers, ID checks, room scans, audio monitoring, AI alerts. 

And yes, features are important, but they are only part of the answer. 

Good security starts by understanding what makes an assessment vulnerable, where that vulnerability is most exposed, and which combination of design, technology and policy is most likely to address it. Proctoring therefore sits alongside the other key layers of assessment security.

Assessment design

Highly predictable, recall-based questions are easier to game using generative AI, unauthorised notes or external assistance. More authentic and applied tasks can reduce the payoff because answers are harder to prepare in advance or outsource in real time.

Delivery and logistics

Simple measures such as randomising item order, using parallel forms, limiting re-entry and separating practice activity from high-stakes sittings can make some forms of misconduct less viable.

Policy and process

Clear rules, consistent enforcement, incident procedures and post-assessment analysis all matter. Even the strongest proctoring system cannot compensate for weak follow-through when suspected misconduct is identified.

Operational resilience

System outages, bandwidth bottlenecks and poor contingency planning can create both opportunities for misconduct and understandable doubts about the process. Being secure enough also means being robust enough to withstand predictable pressure without collapsing.

When we view the security of our assessments in its entirety, rather than as a technical issue, it becomes easier to see where proctoring adds most value, and where better design or stronger processes may be a more effective first line of defence.

Matching the control to the risk

Not all assessments are exposed to the same threats, and not all consequences are equal. Two things decide how much control is warranted: what the task exposes, and what the stakes and scale demand.

What the task exposes: Tasks that focus on short, factual recall or straightforward calculations are typically easier to complete with generative AI or unauthorised notes. Unproctored delivery of these becomes unsustainable quickly, because the gap between honest and dishonest candidates grows too wide to defend.

By contrast, tasks that require extended reasoning, applied judgement or multi-step problem-solving in realistic scenarios are much harder to outsource in real time. That does not mean they are immune to malpractice, but it does change the economics for those who might consider trying. 

What the stakes and scale demand: A high-stakes licensing decision needs greater assurance than a low-stakes formative check. A model that works well for a small cohort in a handful of venues may create entirely new fairness, operational and security problems when expanded across thousands of candidates and multiple countries. Scale is not simply a volume problem. It changes the nature of the risk.

In practice that means lighter-touch arrangements where the stakes are low, hybrid approaches combining automated alerts with targeted human review in the middle, and layered controls or centre-based delivery where an unreliable result would do real damage. Some assessments will continue to require a test centre because the stakes and the capability being measured demand it. That is a legitimate conclusion, not a failure of remote delivery.

3 questions to ask before you set your controls
  1. What is at stake if this result is wrong, for the candidate, for the public and for us?
  2. Which forms of misconduct are genuinely likely for this task, as opposed to theoretically possible?
  3. Who are our candidates, where are they sitting, and what can we reasonably assume about their environment?

    So, we should not be asking ourselves “is this secure enough?”, we should be asking “is this level of security appropriate for this assessment?”

    The Price of Getting it Wrong 

    The greatest cost of poor security is not a failed technology check or an additional six hours of proctor reviews because we got the thresholds wrong. It is the loss of confidence in the result. The moment candidates, employers, regulators and other stakeholders begin to doubt whether assessment outcomes still mean what they once did, the qualification itself starts to lose value.

    Both failure modes are expensive. Too many false positives can overwhelm review processes, increase candidate anxiety and undermine trust by treating ordinary behaviour as suspicious, a problem we examined in Flag Fatigue: The Hidden Risk in Remote Proctoring. 

    Missed incidents of malpractice cause the opposite problem. Candidates share experiences, weaknesses become known, and confidence in the integrity of the process begins to erode.

    Constantly introducing new controls can also create security fatigue. Staff and candidates may begin to follow procedures automatically rather than thoughtfully, weakening the discipline those controls were meant to create.

    Good security therefore has to focus as much on people as it does on technology. How much friction and scrutiny are candidates and staff being asked to accept, and does it feel proportionate, transparent and capable of strengthening confidence in the result?

    A Final Thought

    As remote proctoring has matured, so has our understanding of what it can, and cannot, deliver. Technology alone cannot guarantee integrity. Equally, abandoning remote assessment entirely is neither realistic nor necessary.

    I am often asked whether remote proctoring is secure enough. I think the better question is this: are we protecting the right things?

    If our security measures strengthen confidence in the meaning of the result, they are adding value. If they simply add friction, complexity or surveillance without strengthening validity, they are solving the wrong problem.

    Security is not the goal. Trust in the result is.

    Next in the series

    This is article three of eight in The Proctoring Question, a series exploring how remote proctoring earns and keeps trust. The next article asks how to choose between in-centre, live remote, AI-assisted and hybrid models. 

    If you are weighing whether your current controls are proportionate to your risk, our Assessment Process Check is a good place to start. 

    Share via:
    Topics
    Picture of Robert Burns
    Robert Burns
    Robbie works with assessment organisations on the practical realities of delivering high-stakes assessments, with a particular focus on operational resilience, assessment integrity and candidate experience in digital delivery models.
    Would you like to receive Cirrus news directly in your inbox?
    More posts in Better Assessments
    Better Assessments

    Flag fatigue: The Hidden Risk in Remote Proctoring

    Behind every AI-generated proctoring flag sits a human reviewer making the final call. When the queue grows faster than the team can think, consistency erodes, and with it the defensibility of your outcomes. The second article in The Proctoring Question turns the camera onto the review process itself, and sets out five practical things to get right.

    Read More »

    Know exactly where your assessment operation stands

    Your free personalised report in 4 minutes

    Answer 12 questions across strategy, delivery, design and data and get a clear, personalised breakdown of where your assessment operation is strong and where to focus next.