There are lots of tools and procedures that we arm our users with to protect their identity. (ex: Two Factor Authentication, Password complexity and reset rules, etc.)
But once an identity is stolen, no tools can really identify or track the incident. The responsibility for detection lies entirely on the security officer. Why? Because “That’s the way we always did it!” With identity theft running rampant, this is just plain dangerous thinking.
Why can’t we bring the user into the responsibility loop???
Consider credit card fraud, as an analogy: How does Visa/MC/Amex capture fraud? (Hint: It’s not from fancy fraud detection security software.) The vast majority of detection is from the simple feedback loop when cardholders inform about unauthorized purchases. (i.e. Your grandma and a telephone is the ultimate fraud protection tool!)
We must do the same in IT. Identity theft incidents can be detected and neutralized much quicker if we would just give users a way to flag unauthorized logins. After all, the only person who knows what a user did is the user himself/herself!
Let’s stop doing it the old way, just cuz that’s how we always did it. Let your users be your scouts. Your grandma will be very proud of you.