Every few months, assessment security seems to find a new question to worry about. How should we respond to generative AI? Smart glasses? Deepfakes? The next emerging threat? They’re all important questions. I'm just not convinced they're the most important ones.
A recent Association of Test Publishers (ATP) webinar on security across different exam modalities reinforced that view. The most valuable part of the discussion wasn't the technologies themselves. It was the opportunity to step back and ask whether we're focusing on the questions that will still matter when the next technology arrives.
Whether you run a certification program, a licensure exam, or an admissions test, the pattern is the same: there will almost certainly be another ‘flavor’ of AI next month or next year, just as there will be new devices, new techniques, and new ways for bad actors to exploit assessment systems. If our security strategies are built around today's technology, we'll always be playing catch-up. Future-ready assessment security starts with asking better questions.
Are we building for tomorrow's threats?
Technology changes, security principles endure. We've seen this throughout the history of assessment. Hidden devices become smaller, proxy testing becomes more sophisticated, AI lowers the barrier to misconduct while creating entirely new attack vectors.
Each new tactic creates pressure to find the next countermeasure, whether that’s another policy, another tool, or another control designed to counter the latest technique. That's a race we'll never win.
Effective security isn't about predicting every new threat. It’s about understanding the underlying attack vectors, including impersonation, content theft, and unauthorized assistance, and building security architectures that remain effective as the threat landscape evolves. Technologies such as AI have an increasingly important role to play in this, helping us identify risks earlier, combat AI-enabled cheating, and strengthen assessment security. That shift in thinking is what makes security resilient; whatever comes next.
Are we creating friction for the right people?
Assessment security is often framed as a trade-off between integrity and candidate experience. I don’t think it has to be.
Good security is asymmetric: nearly invisible to honest candidates and expensive for bad actors. The goal isn’t to create more friction for everyone. It’s to create meaningful friction precisely where it belongs, for the people trying to undermine assessment integrity, while maintaining a fair, accessible, and positive experience for legitimate test takers.
When we get that balance right, security strengthens confidence without becoming a barrier to access.
Are we building controls or security architecture?
No single security control can answer every question. And it shouldn’t be expected to.
Every control contributes a different perspective:
- Identity verification establishes confidence that the right person is taking the assessment.
- Environmental controls provide confidence in the conditions under which the assessment is delivered.
- Behavioral monitoring helps identify unusual activity as it occurs.
- Connected intelligence reveals patterns that individual sessions cannot.
Individually, each provides valuable insight. Together, they provide context, which is much more powerful. More importantly, they contribute at different stages of the assessment lifecycle, from deterring and preventing fraud before an assessment has even begun, through real-time detection, post-test investigation, and continuous improvement.
That’s important because modern threats rarely rely on a single tactic. They combine people, technology, timing, and opportunity in ways that no single control can fully address. So it stands to reason that effective assessment security shouldn't rely on a single control. Confidence comes from seeing the whole picture, not relying on a single piece of it.
Are we connecting the dots?
Every assessment generates data. The important question is whether we're turning that data into intelligence.
Individual signals rarely tell the whole story. An identity check might raise no concerns; a testing session might appear uneventful; a single result may not look unusual in isolation. But when those signals are connected across candidates, sessions, devices, locations, and time, a different picture begins to emerge. Patterns become visible, relationships become clearer, risks can be identified earlier and investigated with greater confidence.
That's why I believe connected intelligence is becoming one of the most important principles in modern test security. Not because we collect more data, but because we connect it to create greater understanding. It’s also where technologies such as AI earn their place in a security program. Not as the threat we react to, but as a defensive capability that helps us identify risks earlier and connect evidence faster.
The strongest security programs don't simply respond to individual incidents. They continuously connect evidence, learn from every assessment, and strengthen their ability to prevent the next threat.
Better questions lead to better security
Future-ready assessment security isn’t defined by our ability to predict every new cheating technique. It comes from our ability to build security architectures designed for change.
That requires us to look beyond individual technologies and focus on enduring principles. It requires us to create friction for bad actors, not honest candidates. It requires us to think about security as an integrated architecture rather than a collection of standalone controls. And it requires us to turn data into connected intelligence that helps us continuously adapt as threats evolve.
Technology will keep changing, and no one can anticipate every new threat or flavor of AI. What we can do is keep asking better questions and build security architectures that are ready for whatever comes next. That's the most important conversation we should be having.