Let's Talk About Digital Identity: Recent Episodes

Ubisecure

The podcast connecting identity and business. Each episode features an in-depth conversation with an identity management leader, focusing on industry hot topics and stories. Join Oscar Santolalla and his special guests as they discuss what’s current and what’s next for digital identity. Produced by Ubisecure.

View Details

Let’s talk about digital identity with Craig Ramsay, Senior Solutions Architect at Omada.What is Identity Governance and Why is it important? Craig Ramsay, Senior Solutions Architect at Omada joins Oscar to explore all things Identity Governance including – the role of Identity Governance in compliance with regulations and standards, how it affects security and risk management for organisation, alongside some real-world examples of Identity Governance in use.

[Transcript below]

“We’re still trying to shake off the thing that – security is a barrier to efficiency. There’s an old adage that ‘efficiency is insecure, but security is inefficient’. But I don’t think that’s true anymore.”

Craig Ramsay, Senior Solution Architect at Omada, from Edinburgh, Scotland. I have worked at Omada for 3 years and have previously worked at RSA Security and different financial services organisations in the UK within their Identity functions. Outside of work my main interests are hiking and travelling.

Connect with Craig on LinkedIn.

We’ll be continuing this conversation on LinkedIn using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 102.

Podcast transcriptOscar Santolalla: This week I am joined by Craig Ramsay from Omada, here to discuss the importance of identity governance and how it is helping to solve problems in real-world. Stay tuned to find out more.

Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar.

Oscar: Hello, for today’s episode about Identity Governance and Administration, mostly known as IGA, we have invited a super interesting guest who is Craig Ramsay. He is a Senior Solution Architect at Omada. He’s from Edinburgh, Scotland. He has worked for Omada for three years and has previously worked at RSA Security and different financial services organisations in the United Kingdom within their identity functions. Outside of work, Craig’s main interests are hiking and travelling. Hello, Craig.

Craig Ramsay: Hey, Oscar. How are you doing?

Oscar: Very good. Nice talking with you.

Craig: Thank you, you too.

Oscar: So, let’s talk about digital identity. As usual, we want to hear more about our guests. Please tell us about yourself and your journey to this world of identity.

Craig: Sure. So, I mean, thank you for the introduction. And I guess, in terms of my journey into identity, it was a little bit by fluke rather than by design. I studied Computer Science and when I graduated, I joined an operational IT graduate scheme. They had recently started a new IAM project, because I think back in 2008, identity and access management, identity governance wasn’t as mature as it is now. It was still kind of seen as an operational IT project rather than an information security principle. So, the drivers there were more about the efficiency, automated provisioning and stuff. But yeah, they were looking for a graduate on that project. That was me.

And apart from a few years where I decided to try what it was like being a policeman, I have worked in identity ever since either for, as you said, financial services organisations doing the work at the coalface or for vendors, either in project delivery or, and you know pre-sales in my solution architect role.

Oscar: Excellent. So, let’s go first with the basics. We have not talked about IGA yet in this podcast, have not focused on that. So, tell us, what is that? What is Identity Governance and Administration, IGA? What is important?

Craig: Sure. So, I mean, identity governance, when you focus on it, at its core, it’s a solution that will ensure the right individuals have the right access for the right reasons at the right time in your organisation. So, it’s protecting the authorisations or the resource assignments within your organisation. And that’s often policy-driven to ensure that all of, and I think the important distinction here when we talk about IGA, that’s traditionally your internal identities, maybe your third parties and contractors.

And then in terms of the overall importance of identity governance, as I said, it’s evolved over the years from being primarily driving and focusing, looking at the provisioning element of things. But as governance has become more and more important, as we start to take a more holistic view at identity, when you look at the adjacent technologies; privileged access management, cloud infrastructure and tailored management, user endpoint, behaviour analytics, identity governance is now really being seen as the kind of control plane across that identity fabric. So, I think it is becoming crucial. And there’s a lot of visibility on the importance of identity now, right up to C-level and maybe wasn’t 10 years ago.

Oscar: You mentioned this concept about identity fabric. Could you also explain a bit more about that in this context?

Craig: Yeah, sure. So, I mean, identity fabric is a term that’s been coined in the last maybe few years by a lot of industry analysts out there. It’s maybe a new phrase, but I think the concept isn’t necessarily that new. So, I think we also hear people calling it an enriched security ecosystem. So, it’s where you look at these solutions in the PAM space, UEBA, your SIEM solutions, etc.

Those traditionally have worked in perhaps a bit more of a siloed manner. And the integrations have been maybe limited and not as seamless. Whereas now, I think this concept of that enriched security ecosystem, that fabric is that these things should be joined up and they should be – the convergence of intelligence and data between those solutions, I think is becoming more and more important so that you can take a holistic approach to reducing your identity-related risk.

Oscar: It is very important, as you said, because there will be anyway, other solutions working together with IGA. Yeah, absolutely.

What are the main problems, just – I’m sure there are many, but what are the top main problems that IGA solves?

Craig: Yeah, so from a business problem or business challenge perspective, I think the main thing that we always focus on when we’re helping people build their IGA business case, is that we focus on security, compliance and efficiency. So, it’s looking to increase the efficiency and productivity of your end users and their experience, all whilst ensuring that you’ve got increased compliance, increased security and reduced risk.

So, when we look at that, some of those common challenges and problems within that would be reducing the attack surface in the organisation. So, removing unneeded access, adhering to the principle of least privilege, making sure that your identities only have the access they should. I mean, combining those two things is going to reduce the likelihood and the impact of a potential breach in the organisation. It provides you with a unified view of access across the organisation, which a lot of people often haven’t had previously. So, understanding who has what access.

And then there’s the automation around identity lifecycle management. So that’s reducing the time taken to provision your joiners, your movers, your leavers. You’re putting governance and auditing around all of these processes too. So, when people are requesting access, you’re ensuring they’re getting it for the right reasons with the appropriate approval. And you’re cutting down on things like rogue IT administration and stuff like that.

So that’s high level, there is more obviously, but I think those are the high-level ones that we see frequently when we’re speaking to prospects out there in the market.

Oscar: It’s a security compliance, and efficiency. Yeah, we’d like to talk about this. But before actually it will be interesting to – so people can understand the broader concept, how we try to imagine in their minds.

If you can see in a real-world example, how work for a typical corporation that uses IGA. So, tell us what are these main processes that you say, mostly employees, right? What are these main processes? Let’s say a new employee goes from beginning until the end.

Craig: Yes. I mean, if we’re going to talk – the phrase we kind of, is from hire to retire. So, when I try and explain this to my friends, maybe aren’t so technically minded when they ask what I do, I sort of give them an example. I say, OK, you join an organisation, and you are working in their HR department. So, from day one, you should have access to be able to log into the network, an email account, access to various file shares to do with HR to enable you to be productive from day one.

So, the IGA solution will help you identify the policies to automate that process, to make sure that you are productive and also make sure that you’ve only got access to what you should. So, if you’re joining HR, you shouldn’t be getting access to any file shares to do with finance, R and D, anything like that. And then as you move around the organisation or your needs change, you should be able to request access that goes through the appropriate channels.

It should be reviewed regularly to make sure that it is still appropriate as you go through your life cycle as an identity in the organisation. If you are promoted or changed departments, that should change automatically in line with those policies too. And if you either leave the organisation, be it permanently or temporary for maternity leave, garden leave, that kind of thing, your IGA solution should then disable or provision that access in a timely manner too, to make sure you’re reducing risk.

So, I mean, those are kind of some of the high-level things that it’s that right access for the right people at the right time for the right reasons is kind of trying to, in a nutshell.

Oscar: Indeed, that was in a nutshell, very, very easy to understand. Thank you for that. Some of these at least main problems and how these are being solved. But IGA, let’s start with security as you put security first, how IGA is helping with security?

Craig: So, in terms of how it contributes to, you know, maybe security and risk management, I think, it’s providing stronger access control. So, it’s starting to limit access to your sensitive and privileged information. So, when you start to look at either personal identifiable information, financially sensitive information, or privileged access, so this is when you start to look at integrations with adjacent technologies in the PAM space, you’re ensuring that the access control is limiting that access.

Reducing risk. I already talked about the fact that that principle of least privilege means that if there is a breach in the organisation, the identity of the account that’s breached should have only the access needed to do the job that it can, and it shouldn’t have any elevated permissions permanently. The ability to traverse the network or to have a much more impact on that breach should be reduced. You’re also reducing the likelihood by integrating with identity providers to perform strong authentication. And those unneeded accounts or unwanted accounts or unused accounts have been removed over time as well. So that should be helping you reduce the risk and then improve your security posture.

In combination with that as well, if you look at some of the real-time monitoring and identity incidents or detection and prevention you’re starting to see integration with abnormal access patterns, maybe you know impossible logons, for example, we integrate with the Azure identity risk subscription so that’s looking at – user logged on from Edinburgh one minute and they’re trying to log on from Beijing the next. That’s impossible, so that may be an indication of compromise. And then your IGA solution could lock down that account.

So, there’s many ways you could do that and it’s obviously a maturity journey, you need to crawl before you can walk before you can run. But it’s a maturity journey you go on to take a holistic view in reducing your identity related risk.

Oscar: Yeah, indeed. From basic essential functionalities of security to much more advanced like some of the ones you described.

The second one is, of course, we’re interested about compliance is very common that someone comes, start to ask someone from Omada, or from another company even Ubisecure, we also do identity access management and one of the key drivers for them is compliance especially in some industries, it’s more important that. So, tell us about compliance.

Craig: Yeah. So, I mean, when you go out there in the market and you’re speaking to organisations like more and more and more we are speaking to organisations that operate on a global basis. So, you’ve got country or region-specific things like GDPR, SOCS, HIPAA, PCI, DSS etc that are external regulatory compliance frameworks that you must comply with. And you know we keep a track on with things like Schrems II as well. We’re always keeping an eye on that to ensure that the solution we provide is compliant with those things.

But then we’re also helping our customers comply with how they are storing, processing and managing the data in relation to those things. So, if you look at what I often say is that an identity governance solution is a technical translation of your business processes. I think you always have to look at making sure your people process and technology are working in harmony with each other. Technology alone will not resolve your problems. So, I think as part of a wider identity information security strategy you should ensure that your internal policies and standards are created in such a way that it will help you comply with those external regulations if they apply to you.

But you should always look, I think it’s a healthy thing for any organisation across any vertical to have these well-defined policies and standards and ensure that they can comply with those. And as I said that’s where identity governance comes in, because it helps you comply with those things by defining policies that can detect when you’re non-compliant, you’ve got that audit trail. So, it offers – you’ve got transparent auditing for your internal and external users to prove compliance. You will go through regular recertification, attestation, reviews, whatever you want to call it. But that also ensures that you’re demonstrating regular compliance.

And then we already talked about risk management as well, but compliance and risk often do overlap each other. So, you’re identifying and mitigating compliance risks through the definition and enforcement of these policies as well.

Oscar: Indeed. So, there is some reports that can be directly created, right, from the IGA system. And that can be directly taken by the compliance officer or whoever requires it, right?

Craig: Yeah.

Oscar: The other you mentioned there was the operational efficiency, right? So, as you mentioned, it’s one of the three main problems. Let’s – I’d like to hear more about that as well, how IGA helps.

Craig: Yeah. And I think that’s one of the things that I think separates IGA and the information security market sometimes. That it’s not always focusing on risk reduction and things that are maybe potentially seen as negative. So, you talk about fear and certainty and doubt within the sales process, etc. When you’re doing that, it can often be quite a hard sell because it’s hard to quantify the risk. We can’t help with that. There are formulas out there of calculating the impact of a risk based on, you know, and the likelihood, the cost of the actual breach, etc.

But to bring it back to what you actually asked about from an efficiency perspective, if you look at – if organisations are still heavily manual in their provisioning and their processes, there’s a huge cost to that from areas like your service desk, your operational IT administrators. And often it leads you to the potential for human error as well. So, if you start to automate those things, you see a reduction in numbers of calls to the desk, a number of manually created events and things that are being done. And you can put a pound, euro, dollar sign against that clearly from an efficiency and a cost reduction perspective.

From an end user perspective as well, I mean, it’s always, I think there’s – we’re still trying to shake off the thing that security is a barrier to efficiency. There’s an old adage that I keep using for it regularly that ‘efficiency is insecure, but security is inefficient’. And I don’t think that’s true anymore. I think if you correctly apply your policies in a way that apply the appropriate level of risk, your users – to them, it should be seamless pretty much all the time. They shouldn’t see these processes as an action. They should see it as; they request the access they need, it gets granted to them in a timely manner. When they move around the organisation, a lot of that should happen automatically.

Overall, you should see an increase in productivity. Your line managers aren’t getting frustrated when people join the organisation and they’re having to submit 10 different requests to get them functioning from day one. So, it’s overall operational efficiency and cost reduction. But the productivity. And end user experience of it as a result of a well-delivered IGA program, I think is clear to see as well.

Oscar: Yeah, cost reduction is clear and is a great reason to buy a product like IGA. Absolutely. Well, if you quantify that to a buyer, it’s like, wow, you can convince him or her very easily. Yeah.

At Ubisecure, we are working with CIAM, and I experienced directly that sometimes requests come from potential customers, and they are looking for identity and access management. And when we review closely, we see that sometimes what they need is IGA or what they need is both IGA and customer identity and access management. So, and in those cases, the customer will need to deal with these two types of system, right? The IGA and CIAM.

So, what is your perspective from your experience working integrating these two types of tools? What are the main things that a buyer bought from business and technical perspective should know at least?

Craig: Yeah, so, I mean, funnily enough, I have worked on a couple of opportunities where Omada and Ubisecure have been working together on those kinds of joint proposals where people are looking for IGA and CIAM. And I think it’s interesting because you can make a very strong case about where the overlap is, but you can also equally make a very strong case about why they should be separate because of the nature of the requirements.

From a CIAM perspective, you’re looking for that seamless, really quick response for all your consumers. And then you should be able to deal with high demand periods when you’re very, very busy, when your consumers are consuming your services. And from an IGA perspective, you’re very much looking at the internal and the control and the level of these privileges that we’re talking about. And there are similarities in the capabilities in terms of, you know, being able to provision in a timely manner, deprovision in a timely manner, ensuring that it’s the level of appropriateness.

So, if you look at it from an integration perspective, a unified management of the identities, I think, could be important whilst treating them differently. I think your end user experience again should be important. So, you’re balancing security and efficiency for your internal and external customers. And then you should be able to have that from a scalability perspective by seeing those things integrate well with each other as well.

I think what is important when you’re speaking to people, understanding their requirements is crucial. So, when they’re talking about, you know, B2B or B2C capabilities and requirements, it’s OK, well, how do you manage your B2B and B2C use cases? Because I think if you take software or technical organisation where their consumers consume their services in a far, far different way to maybe a retail bank or a supermarket. The requirements for end users from that perspective, they’re opening up a loyalty card in a store and you’re processing their personal data in that manner is very, very different to maybe a software company where people are having accounts created and consuming those services.

So, as you can probably tell, not an absolute expert in the CIAM space, but I think whenever those opportunities arise, I think the first important question is why? To understand what it is exactly they’re trying to achieve. And then you map the use cases to the functionality in each of the appropriate solutions to make sure that it’s well matched. There will be overlap in some cases. But as I said, there’s a strong case for when there’s similarities and when they should be managed separately. But ultimately, it’s part of that wider identity fabric we mentioned earlier that it’s kind of all identity in the end, I guess.

Oscar: Yeah. Indeed. As you say, you put it very clear, the importance of really knowing very well the requirements because in a conversation, they might tell you we need this one, two, three, five things and can be also in a written Excel file or whatever. But then you have to go deeply to understand what they meant by saying this B2B or anything, right? So, yeah. Indeed. Thank you for sharing that.

Looking now at the present and future, let’s say, because IGA, as many other types of products have been evolving, are evolving all the time because there are different needs. So what customers are asking today when they are clear that they need an IGA software? What they’re asking today and what are these new problems that need to be solved, are being solved now and need to be solved if they are not solved today?

Craig: Yeah. So, it’s a very timely question. To be fair, we recently released a State of IGA for 2024 report at Omada and we did a webinar discussing the findings of it and it did exactly that it looked at how seriously people were taking identity. And then as you said what are they looking for currently and what are they looking ahead at as well. So, and we just talked about the why and the use cases, so I think, number one that we still see is that the solution they’re looking at adapts and meets to their changing business needs. So, the requirements they have now and the requirements they think they’ll see in the future, it’s the core capabilities must adapt and must comply with that.

We’re seeing an increased importance being put on the ability for the solution to integrate as part of that security ecosystem we talked about. So being able to play nicely with the adjacent technologies across the identity fabric. And then from a connectivity perspective, I mean I talked earlier about a unified view of access across the board, the nature of organisations has changed massively in terms of on-premises systems to a lot more cloud services being consumed. So the ability to extend and integrate with a growing list of different target systems is important for them.

Looking ahead, we do see AI and Machine Learning coming up again and again. And I think when we see that it’s important to take those as separate things. So, from ML perspective, you know, if you look at kind of the role mining capabilities that have been there for some time, recommendations during reviews, recommendations for decisions or decision support for approvals, that stuff has been around for a little while.

From an AI perspective, I mean there’s a huge buzz around what’s happening in AI. Just now Google just released their Gemini Chatbot to rival Chat GPT and that the generative AI stuff and the practical uses of that are going to start to be seen. So, you know integrating generative AI, we have stuff where it’s looking at… you can ask questions about the documentation. So, like what is this object in Omada and like what’s the difference and it’s starting to respond to that so we’re in the process of testing and releasing that.

And then looking further down the line, it’ll be generative AI within the solution. So, user logs in and it says, “What are you trying to do today?” “I need the same access as my colleague Allison.” And it’ll say, “OK she’s got this, this and this. Maybe this is what you need to request.” Or it’s becoming more mature and more complex or sophisticated in what it can do.

So, I think ultimately what people are looking for is ensuring that the solution they have can do what they need to do today and can do it well, it’s scalable, it’s easy to upgrade, it’s easy to maintain. They’re reducing the complexity of management of it so they’re simplifying it from that perspective. But looking ahead they’re needing that generic connectivity that can allow them to connect to any of the systems they have now and ones they want in the future. And then being able to take advantage of the advances in the AI and ML space to improve end user experience and also the maintenance and administration of the system itself for their administrative users.

Oscar: So, you believe that machine learning and the other what we call artificial intelligence is going to be used. It’s to be solving those problems that today customers are bringing up.

Craig: I think it’ll augment, and I think – because that’s the thing people get worried about AI replacing us and whatnot. And maybe somebody using AI more efficiently than you might replace what you’re doing but AI itself can’t and I think any algorithm that – it does do in the output of it still needs human validation particularly in a field like IGA where OK it’s taken a huge amount of data, provided this output and most that might look OK. There’s probably some human context in terms of exactly what that business does that’s needed to say, “Yes I’m still OK with that.” Because ultimately the human’s going to have to be accountable for the decision that’s made. I don’t think and I don’t think we’re going to see algorithms being fined or sent to jail for data breaches you know, I mean.

Oscar: Yeah, a human will go to jail anyway. Hopefully not. Hopefully that doesn’t happen.

Craig: No, hopefully not that’s what we’re trying to prevent. You’re right, we’re trying to prevent that but yes.

Oscar: Exactly, exactly. Yeah, yeah definitely. Also, one thing you mentioned, it comes back to what we discussed earlier these identity fabrics. Yeah, the way to coexist all this all these tools, IGA, PAM, CIAM all together that’s also, as you say, it’s something that is becoming more important because the environments are getting more complexes.

Final question for you, Craig. For all business leaders listening to us now, what is the one actionable idea that they should write on their agendas today?

Craig: So not to spoil the magic of the podcast but we’re recording this just before Christmas towards the end of the year and I don’t know when it’s going to be released but that’s always a time for reflection and looking at where you’re at and where you want to be going. And I think for any business leader right now, I think conducting an identity maturity assessment is something that you can do actionably right now. So, look at where you’re at from an identity maturity perspective and identify gaps that you need to start filling, or priorities looking ahead and aligning that with your business goals, your business risks to ensure that your information security strategy, your policies and standards support your overall business objectives.

And then from that, building a plan of continuous improvement, some milestones as well. And I think any well-delivered IGA project should be doing that. It shouldn’t be looking to boil the ocean or deliver everything at once at big bang. It should be continuous improvement and continuous demonstration of value.

So, I appreciate that might be – that’s not something cutting edge or brand new or innovative, but I think it is really something actionably you can do now to take a step back, assess exactly where you’re at and then build that plan and start to try an action that. Do that at the end of the year, at the start of the year. There’s never a bad time to take a step back and reflect and put that plan in place. But I think that’s definitely something actionable that they could put on their agenda right now to do from today.

Oscar: I couldn’t agree more an assessment, absolutely. It’s something needed. Yeah, it takes time. And it’s very actionable, as you said. Yeah, thank you very much, Craig, for having this very interesting conversation about IGA and other topics, related topics.

So, let us know for people who would like to continue this conversation with you, or follow you, or find out more about what you do, what are the best ways for that?

Craig: Yeah, absolutely. So, you can find me on LinkedIn, Craig, I think my username is Craig86. Obviously, I work at Omada Identity, but that’s, again, if you search for Omada, you’ll find us there. I mentioned our State of IGA 2024 report, you can download that free from omadaidentity.com. And there’s also an on-demand webinar where myself and Rod Simmons, our VP of Product Strategy, discuss that report in-depth.

But yeah, please do feel free to reach out and connect. If you want to chat about all things identity or just want to know a bit more about Omada or myself. But yeah, it’s been a pleasure talking to you, Oscar, as well. Thank you.

Oscar: My pleasure as well. Well, all the best. Happy New Year. Now, this coming the new year, 2024, I wish you all the best for you, Craig, Omada, and everybody who is doing all this great job in the identity space. Thank you. All the best.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Jesse Kurtto, DPO and Data Scientist at Ubisecure.Is now the right time to invest into Identity and Access Management (IAM)? Join us for episode 101, as Oscar is exploring why now is the right time to invest into IAM with Jesse Kurtto, DPO and Data Scientist at Ubisecure – as they delve into the current economic situation and some of the key factors of investing into identity management.

[Transcript below]

“Digitalisation is ongoing, it’s accelerating, it’s unstoppable.”

Known as the guy who shortened the world and lived to tell the tale, Jesse’s career is gradually arching from the Wild West world of finance to his current position as the DPO and Data Scientist at Ubisecure. Learning to program before learning to read Finnish and visiting 25 countries before 25, he’s no stranger in exploring uncharted waters and discovering connections that others might miss. Surrounded by a delicate balance of the latest technology and dozens of carefully tended houseplants, his secret hobby is putting the hiking boots and RPGs aside for a moment in order to write to his beloved snail mail friends across the world.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 101.

Podcast transcriptOscar: Is this the right time to invest in Identity and Access Management? This week Jesse Kurtto from Ubisecure has joined us to answer this question and discuss the current economic situation. Stay tuned to find out more.

Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar: Today’s guest is Jesse Kurtto. Jesse’s career has gradually arched from the Wild West world of finance, to his current position as a Data Protection Officer and Data Scientist at Ubisecure. Learning Program before learning to read Finnish and visiting 25 countries before 25. He is no stranger to exploring unchartered waters and discovering connections that others might miss. Surrounded by a delicate balance of the latest technology and dozens of carefully tended houseplants, his secret hobby is writing to his beloved snail mail friends across the world. Welcome Jesse.

Jesse: Thank you for the invite, Oscar. Nice to be here.

Oscar: Great having you, Jesse, definitely. We’re going to have a super interesting conversation about the market in Digital Identity and Identity and Access Management.

First of all, we always want to hear more about our guests. So please tell us a bit about yourself and your journey to the world of digital identity.

Jesse: All right. So, like many or even most of us in the digital identity field, I actually never really actively sought to be a specialist, IAM specialist, on purpose. And my personal background is actually nothing technology even, but in finance and investing more specifically. So, a chance encounter and I liked the people who interviewed me and decided to stay for a while, and that while has been over seven years now. And I’m still learning something new every day, checking out how we really the world of digital identity like and frankly haven’t ever regretted decision. No two days have really been the same and the field continues to evolve and develop quite a bit every year.

Oscar: Yeah, excellent and definitely hearing at Ubisecure, we definitely appreciate having this – well call it, like a blend of knowledge – the financial market, not lesser than what you bring with the security and digital identity knowledge, very practical knowledge you also had. So, it’s always super interesting having those conversation with you.

And for the first time here on the podcast, we are going to have that, a bit more financial touch on that – What is coming, especially in this well this year, and I think also the years to come. The previous year and the year to come I think, we are already end of 2023 in which – well the financial situation is not good we’re going to talk about. But of course, no matter how the economy is, the companies organisation has to protect their services, have to upgrade the services, maintain them, so they have to invest some money in that.

So, from the perspective of companies who today need to upgrade their digital capabilities, what would you say is the piece of the current macroeconomic situation that they should know well? So that was at least what they should know well, from what is happening now?

Jesse: Well, first of all, we all know the macroeconomic situation hasn’t really been dancing on the roses over the past few years. But first, we had a massive shock with the COVID pandemic starting from spring 2020. Then we got massive economic stimulus to recover from that slump. And right after we were starting to climb up, then the war in Ukraine saw that all kinds of new problems everywhere around the world seemed to emerge just within three or four months.

The energy uncertainty in Europe and the economy went down the drain, and macroeconomic in quite a difficult situation here in Europe. But we would actually want to have some kind of stimulus in order to recover. But at the same time, we are suffering from quite persistently high inflation, which makes any kind of stimulus package basically equal to pouring more gasoline to the flames.

So, the European bank is really between a rock and a hard place here. And I can only look over the Atlantic to the States and be very jealous how they are able to both fight inflation and with high interest rates, five and a half percent this talking and meanwhile still have a blisteringly red-hot labour market all but there.

So, my first point would be that not all markets are equal. And the second important point is that now is actually a really great time to invest in any digital capabilities, including digital identities. Because now, we are in the middle of a small recession in Europe and investing in recession has historically been the very best time to invest in growth.

And if we think for a while, it actually makes perfect sense. After all, the alternative is to invest in the middle of a growth season when everybody else wants to invest in growth as well. Pushing prices even higher and reducing the availability of experts to help with these transformation projects. But now it’s still for a while kind of a buyer’s market.

So best time to invest in future growth is now.

Oscar: So, time to invest is now.

Jesse: Yes.

Oscar: Okay. So, let’s go into what – because there are many things that the company can invest now and many things that many companies might need. But if you were one of the – chief executive, like CISO, or someone who is top decision makers in companies and there has to be some budget for digital identity. Thinking of – first of all broadly. Broadly but in digital identity, what would be the most important products that today would be the top priority for buying now?

Jesse: Today I would say that the absolute top priority would be – to establish really low friction user journeys from the very beginning account registration to the actual purchase, including solid online self-service. And now this low friction user journey is no way exclusive with security or compliance, but it is actually reaping the benefits of digitalisation. Digitalisation is ongoing, it’s accelerating, it’s unstoppable.

So, the question is for every organisation – should they try to fight this change to the last or embrace it and be among the first to actually reap its benefits. It’s actually interesting because my background in finance, the many finance sector operators were among the first to embrace digital identities, but they kind of stopped it halfway there; “Okay, we can build self-service portals for our users, but for many, many procedures we still require hand signed paper documents being sent via physical mail.” And this is really only reaping a very small part of the benefits of digitalisation. So, there is plenty to go.

Oscar: Yeah. Interesting what you say in finance services. That’s correct. For reasons of security had to be always in the latest of technology for security. But some of the process has been, as you say, very old fashioned like the old school, many paper fax I think still use or cheques. So, these kind of.

Jesse: Oh yes, those ones to.

Oscar: Still alive.

Jesse: Yes. And it truly hurts the user experience a lot. It even causes direct missed opportunities. Let’s say new bond is coming to a market and you wish to buy a piece of it and participate. But if it takes three or four days just to do all the paperwork, then the opportunity has simply passed.

Oscar: And indeed, the price changed completely. Okay, so you say that the top is to – the user journey has to be digitalised. So, what is the category of products that address that?

Jesse: Would say a real CIAM system would be the one to go here, and not try to build the user journey from, let’s say 4 to 6-point solutions and then somehow glue them together. I think the best solution would be an IAM solution that’s designed for a whole user journey from the scratch and not something homemade or batched together.

Because when business grows, as it will eventually grow, no recession will last forever. And to user numbers pick up and suddenly there’s a nightmare of issues of having 4 to 6 different vendors and trying to keep their products up and running with ever increasing user numbers. And that again, is doing digitalisation the wrong way, if I may say.

Oscar: Yeah. CIAM being – so how, well the evolution of the more broadly speaking, Identity and Access Management. Maybe you can give us an overview of that evolution of the Identity and Access Management, what – how we started and what we have today.

Jesse: Yeah, that’s a very interesting topic. Through the IAM are from big enterprise internal needs at once to employee numbers just grow to a certain level, they can’t be managed with excel sheets or pen and paper before that. But these kind of internal IAM solutions scale and fit really badly for end customer facing journeys. Internal users can always be taught how to use some kind of system, even if it’s not immediately logical or it feels unwieldy.

But for the customers, it’s not realistic to expect that they would spend tens of minutes or even hours to learn how to use some kind of system to log in. And no, they would simply instead put down their laptops, pick up the phone and call your customer service. So, it will actually just cost you more money to have this kind of system.

And now, in the past ten years, there have been massive uptake of different CIAM systems. And lately, let’s say after the pandemic, it’s interesting to see that now the full circle is coming back towards internal users with remote working. Remote working, different kind of partnerships, there are more kind of internal and kind of external users than ever, and trying to keep these as fully separate groups is very challenging.

Oscar: Yes. So, what about the investment of a company in Identity and Access Management? So what does that imply if the company does not have even, let’s say, a first personal CIAM or open source, something that they started, if they if the company really doesn’t, which actually to me surprise me that, you discover companies don’t have it, don’t have it, almost anything like identity access management and they are looking for some solutions or they are or they know that they need it. Maybe the decision has not come.

So why would you say is important for the buyers to know about the product, the Identity and Access Management product?

Jesse: That’s an interesting detail what you said that there’s still about 20-25% of companies in Europe that do not have any kind of Identity and Access Management system in place. So, one could argue that every IAM’s companies’ worst competitor is doing nothing. But to the question at hand, I’d say scalability is one very important thing, and compliance. If one doesn’t have any kind of identity management system in place, then it’s extremely hard to tell where and by who are the user identities actually stored.

And of course, that is a massive no in the eyes of the GDPR and this kind of adventures just don’t usually end up well. So first job would be to map out how many identities there are in the first place, how it has evolved over the recent quarters and where they are located, how many systems actually are connected, including partners, including systems like let’s say payroll providers, insurance providers, and usually the number is quite surprising. It can often be more than ten individual systems.

And now managing all these identities from a single centralised place is frankly a godsend compared to trying to manage this and plus sprawling network identity some here, some there. And of course, it also brings centralised identity management, also brings massive security benefits. For example, if you wish to revoke the access for, let’s say some external consultants that have already finished their projects, you only have one place to do it or you can even automate it.

But if the identities are in ten systems, 15 systems, then it’s really easy to forget just one. And who knows, maybe five, ten years later, one of those passwords will get breached and now the attacker gets to your system for free.

Oscar: Yeah, what is normally called silos, identity silos. Having so many data repositories and it’s -through the years it’s easy to forget at least couple of those are forgotten but they are still there somewhere in there in some machine, in some server. So, the data is there.

Jesse: Yes. And of course, I’ve heard many times the counterargument that it’s not wise to put all eggs in one basket, but when it comes to information security, we as the defenders must secure every single system that we use. But the attacker only needs to find one weak system to exploit.

Oscar: Yeah, yeah, exactly. They can just find the forgotten one, the one that nobody remembers that.

So, what the company – the buyers should ask for a technology vendor? So, for a CIAM vendor? So, what are the most important things that’s should be – has to be asked to the vendors?

Jesse: I would ask them to demonstrate the self-service capabilities first. What exactly the users can and cannot accept less without external help? Meaning customer service assistance. Because that sets quite stringent limits on the benefits of digitalisation. And of course, all the usual user journeys should be handled by the system automatically. So, I would guess that any IAM project touches deeply.

So, I would first describe the challenges we are facing. And then I’d ask vendor to explain, just in plain English, that – how does the solution work and how does it actually solve the challenge that we just presented? And after all, one should never invest in anything that one doesn’t understand.

Another point I would like to address early in any IAM project is to what is actually included in the price and what isn’t. In order to actually accurately measure the TCO and how it would evolve as internal and external user base grows. And for example, there are many vendors out that charge ten to even hundred times for internal users compared to external users, and that’s not usually put on a large print on the front page.

And finally, I would discuss any coming changes in legislation because I would be very interested to know whether any changes will be covered under the current proposal or will it occur additional project and additional costs in the future. Change is, after all, inevitable.

Oscar: Yeah, I think that’s very important. We know in – in the European Union it’s coming the digital wallet that’s going to come in. Well, how many years do you predict at this moment?

Jesse: I’m optimistic and say late ‘24 launch for some countries. ‘25 mass adoption and hopefully organisational identities soon after.

Oscar: Yeah, and that’s something that I think very few people would argue that that will be – that will not have some considerable success because there’s a lot of time invested in people preparing all these new standards in this part of the evolution. What we have been seeing before with Self Sovereign Identity (SSI), the wallet itself is something that is already becoming very popular in the commercial side. So that will come in.

Similarly, in other geographies, there will be similar initiatives, there will be new regulations. So that, through all this, the vendor has to offer that, has to tell whether we offer or not. So that’s definitely a good, good aspect you mentioned.

Jesse: Yes. And the commission has made clear goals here to avoid repeating the mistakes of the eIDAS 1.0, that was supposed to bring cross-border digital identities to Europe. Well, we all know that it was a commercial failure, but they have really learned from that, and I have great hopes for the EUDI. Both for personal identities and for organisational identities, and especially for the latter one.

I believe that the market is currently suffering from a kind of chicken and egg problem here, that everybody’s waiting for cross-border organisational identities and not building services because they aren’t here yet. So, we might see the floodgates open in the late 2020s.

Oscar: Yeah. I also believe that as a lot will change in more or less like the, as you say in the next 12-24 months is going to change a lot, in a good way I believe. So definitely exciting to be at this moment. We’ve been talking a lot about Identity and Access Management, other aspects, other type of technology that are also in the minds of the executives who are going to upgrade their technologies. We hear a lot about passwords in the last year. Well, ‘cryptocurrencies’ is getting a bit more quiet. Today we hear a lot about artificial intelligence.

Would you recognise some technology that is actually underrated, that not many people are talking about? But these business buyers should be aware, because the impact will be even bigger than those buzzwords. So, what would you say?

Jesse: I would say that the coming EUDI and its principle of Self-Sovereign Identities is something that might cause quite big ripples in the identity landscape. The very basic idea that it’s the end user themselves who collect attributes and control to whom and when they release those attributes. That that is very different from the usual data repository centric view that – okay, we have this database, and we control everything here. Everything is set in stone.

But when the end users actually decide which attributes to release and which not. Then one can’t take for granted that, “Okay, we always have every single field in our database field. Every user record looks similar in a structural level.” That is no longer true and that might cause some changes.

As for technology, I have great hopes for machine learning and especially how it can help accomplish not zero trust, no. But zero friction user journeys. And I don’t mean a strong AI that is still decades into future, if ever. But simple things like; is the user using a different device to log in or the same device as before? And so on.

For example, I have a recently having a quick holiday in the US, and I was frankly quite shocked when I logged into some financial services – using a completely different device that I had never used, on completely opposite time of the day. I was even physically located on a different continent. And no MFA prompts, nothing. Just inputting my password, I was in.

And that’s a lot of missed risk management there, for both parties. For me as an end user and for the financial service provider. And I believe this is something that will change sooner or later. And of course, I would like, as an end user, for this to work for the opposite way as well. That if I’m logging in using the same device, about the same time of the day, from same city that I’ve done it for hundreds and hundreds of times – then perhaps I could be spared the MFA fatigue and just get in with my password managers embraced password.

Oscar: The technology doesn’t bother you when you are in the habitual way of interacting with, let’s say, the banks.

Jesse: Yeah, exactly. It should take always the context of the transaction into account. And frankly, what I would like to see many companies to do is; do a more thorough risk analysis at what they are actually trying to defend against. I can give a real-world example.

About a month ago, I drove to a gas station, put my car to charge, decided that I’ll have a coffee there. Opened the app and saw, hey, there’s an offer for a coffee and a doughnut €1 off. Great.

Okay, it seems that first, I needed to update the app to actually buy. Okay, well, I’ll do it.

Then they wanted to add the credit card directly to the app, alright. Got an MFA from that.

Then when I actually wanted to make the purchase, I got yet another prompt and confirmation, this time from my bank. That – ‘Hey, in order to buy this €3.50 product, would you please update our app again, and use it as an MFA to confirm this purchase’. For the third time.

And by that time, I already got notification that, ‘hey, your car has charged’, and my coffee was called by then and left it there.

So that was the opposite of Zero Friction. That was more of a zero trust like game. But the security solution that’s very fitting for, let’s say, authorising nuclear missile launch, is very different than the security that’s needed to confirm a €3 coffee purchased at the gas station.

And as discussed earlier, I believe this problem stems – that solution was built from very small parts and every individual vendor only looked after their own interest, only want to save their back in case of any kind of misuse. But nobody took a step backwards to actually see; What we are trying to defend against here? What is the attack vector here? That okay, somebody misuses this app and clones this coupon and gets two coffees and doughnuts for a €3 each. Okay, so how much is an attacker willing to put time and money into such attack? I guess nobody stop to think about it. And as a result, the whole user journey was just failure.

Oscar: Yeah, complete failure indeed. Very good way to bring back the very first thing you said, User Journey. Yeah, that’s a specific example how things can happen. Sounds like a marvellous opportunity, not to get a deal nice and then becomes complete failure.

Jesse, one final question I would like to ask you is – for all business leaders listening to us now, what is the one actionable idea that they should write on their agendas today?

Jesse: I would dream that every executive would dedicate one day, one whole day to actually be an end user for a day and go through their company’s entire flow. All the way from account registration to actually purchasing to product or service that they’re selling. And if there’s time trying out things like forgotten password resets. And then the next day repeating the same procedure for the top competitor and even more importantly, their newest competitor, because that is where the threat of digitalisation is coming.

Oscar: Going to be very revealing.

Jesse: Yes, and it’s important to go through the entire journey. If one, simply takes it piecemeal. And of course, every piece may look perfectly fine. Okay, this works like this. It has confirmations like this. Great. Next piece. Next piece, Next piece. All right. Everything looks fine. But then actually going through the process, one gets hit by four or five different confirmations, forced updates, all kinds of non-user-friendly things, and that won’t fly.

Oscar: Yeah, definitely a very good experiment, actionable idea. Absolutely. Well, thank you very much, Jesse for telling us all this about the – how the companies and why companies should invest in the digital identity and why today.

Let us know why people would like to get in touch with you or follow you or learn more about what we are doing. What are the best ways for that?

Jesse: All right. Thank you. First, I would ask everybody to check out ubisecure.com, and see how we are approaching these problems on the market. And if needed, I would be very happy to have a chat, over a virtual or real coffee, and I can be contacted at jesse.kurtto@ubisecure.com at anytime.

Oscar: Excellent. Again, thanks a lot for joining us, Jesse, and all the best.

Jesse: Thank you, Oscar.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Heather Flanagan, Principal at Spherical Cow Consulting and David Birch, Principal at 15 Mb, author, advisor and commentator on digital financial services.This is the 100th episode of Let’s Talk about Digital Identity – in this special episode two of our most popular guests, Heather Flanagan and David Birch, rejoined the podcast to explore what is exciting them in passwordless, identity wallets and digital money.

[Transcript below]

“Passwords have got to go. As we’re moving to passkeys, I think there’s always room for improvement on – even on them. If nothing else, focusing a little bit more on the user experience so that people will have a better understanding of what this means.”

Heather Flanagan, Principal at Spherical Cow Consulting and choreographer for Identity Flash Mob, comes from a position that the Internet is led by people, powered by words, and inspired by technology. She has been involved in leadership roles with some of the most technical, volunteer-driven organisations on the Internet, including IDPro as Principal Editor, the IETF, the IAB, and the IRTF as RFC Series Editor, ICANN as Technical Writer, and REFEDS as Coordinator, just to name a few. If there is work going on to develop new Internet standards, or discussions around the future of digital identity, she is interested in engaging in that work.

Listen Episode 74, where Heather discusses Making Identity Easy for Everyone or connect with Heather on LinkedIn.

“The thing that’s broken in digital money at the moment, is identity, not the payment bit.”

David G.W Birch is an author, advisor and commentator on digital financial services. Principal at 15Mb, his advisory company, he is Global Ambassador for the secure electronic transactions consultancy, Consult Hyperion, Fintech Ambassador for Digital Jersey and Non-Executive Chair at Digiseq Ltd. He is an internationally-recognised thought leader in digital identity and digital money. Ranked one of the top 100 fintech influencers for 2021, previously named one of the global top 15 favourite sources of business information by Wired magazine and one of the top ten most influential voices in banking by Financial Brand, he created one of the top 25 “must read” financial IT blogs and was found by PR Daily to be one of the top ten Twitter accounts followed by innovators (along with Bill Gates and Richard Branson).

His latest book “The Currency Cold War—Cash and Cryptography, Hash Rates and Hegemony” (published in May 2020) “paints a fascinating and stimulating picture of the future of the world of digital payments and its possible impact on the wider global and economic orders” – Philip Middleton, OMFIF Digital Monetary Institute. His previous book “Before Babylon, Beyond Bitcoin: From money we understand to money that understands us” was published in June 2017 with a foreword by Andrew Haldane, Chief Economist at the Bank of England. The LSE Review of Books said the book should be “widely read by graduate students of finance, financial law and related topics as well as policy makers involved in financial regulation”. The London Review of Books called his earlier book “Identity is the New Money” fresh, original, wide-ranging and “the best book on general issues around new forms of money”.

More information is available at dgwbirch.com and you can follow him @dgwbirch on X.

Listen to Episode 75 with David discussing Digital Currencies or connect with David on LinkedIn.

We’ll be continuing this conversation on X using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 100.

Podcast transcriptOscar Santolalla: This is episode number 100 of Let’s Talk About Digital Identity. And for this special occasion, we have invited back Heather Flanagan, and David Birch.

Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

We have invited back to the show two of our most popular guests. So, these two guests, let me introduce them is Heather Flanagan. She is Principal at Spherical Cow Consulting and Acting Executive Director for IDPro. Hello, Heather.

Heather Flanagan: Hello, Oscar.

Oscar: Nice having you back.

And our second guest is David Birch. David Birch is an author, advisor and commentator on digital financial services. He is Principal at 15 Mb, his advisory company. Hello, David.

David Birch: Hi. Thanks for having me.

Oscar: It’s a real pleasure having you both for this special episode, a bit different style, so being out of our usual script. But yeah, hearing a little bit more about yourselves.

So, I’d like to hear something in particular, because we want to hear something – a moment in your lives. So, what I want to hear – think of one specific moment in your career in which you told yourself, “Yes, this is why I love working in the identity industry.” Which moment would it be? Who wants to start?

David: Well, and it’s a bit self-centred, but probably when my publisher agreed to publish my first book. I thought I had some interesting ideas about identity – I mean you always think that your ideas are – but when you get that kind of validation that your ideas actually are interesting to other people. That really did change my career. Yeah, otherwise, I probably would have just carried on being a pretty average consultant and carried on in payments and banking. So yeah, it’s – but I put it all down to my publisher.

Oscar: Which one was this book? Tell us which book was this.

David: Identity is the New Money. It was Diane Coyle, the Economist, who encouraged me to publish it. So yeah.

Oscar: Fantastic. Heather?

Heather: I don’t have anything. I’ve been actually thinking about this question for a while, and it’s really hard to point to any one thing, because there were no lightning from the sky moments. It’s just, it’s always been such a foundational aspect of everything that I’ve ever done since I started in tech in the mid ‘90s. Where the first question was always – when you’re taking over something from a bulletin board system to an email server, “Who can access this? What permissions do they need to have? How do you set up accounts for them?” That was where everything always started. So, no one moment, it’s all of the moments.

Oscar: Well, that’s great that there are several exciting moments. I’m sure for all of us, it’s been like that. Several moments in which we feel that this is exciting to be in this industry. But thank you for sharing that with us.

Being already towards the end of this year 2023 – so there are some keywords which were buzzing in the last years. But some of these buzzwords today are more reality, we have access to those. What do you think, what you feel about these technologies or techniques. And let’s get started with passwordless. So, if I ask Heather, what excites you today about passwordless?

Heather: I’m really excited about the fact that the technology itself is solid, the standards themselves are really, really well-done. But as excited as I am, I am concerned. Like at all the new modern technologies, I look at them and go, “Wow, that’s really cool.” and little anxiety making because for passwordless, what I observe is when you actually get out of the tech field and talk to my mother, she doesn’t trust it because it’s too easy.

And so, I do wonder about as bad as passwords are, the friction that they add, it’s something that people can wrap their heads around. Whereas they don’t understand the magic that’s happening behind the scenes that makes passkeys better. And if they don’t trust it, they won’t use it. And if they don’t use it, we lose out on all the benefits. So, one of the things I’ve been trying to think about for you know, the future is OK passkeys are amazing, but how can we make them less magic scary?

David: I’m a bit frustrated with it really, because I’m extremely lazy. And so, you know, like eBay, for example, uses passkeys, the whole thing works perfectly. So as soon as I go to a site, as in fact I just did 10 minutes ago to look at something and it’s log back in. I’m like, “What I have an account? I didn’t even know I had the account.” And then I had to remember the password. And of course, I didn’t get it. So, I had to click on, I forgot my password, and then I got the password reset. And then I put in the new password. And it said, “You can’t have a new password that’s the same as the old password.” And we just go around in this loop. And it drives me crazy. I’m like, “Why can’t you just all implement this?” Despite the fears of your mom, which I mean I can’t discount those because they’re real. The sooner we make people stop using passwords, the better.

I was reading a fantastic story in the Insider this morning. Did you see this story about the Zelle fraud on Insider? It’s typical kind of thing, you know, guys getting some work done by a contractor. The hackers get into the contractor’s email account, they send him a thing to send money to a different account, which is the hackers’ account. And they make off with all of the money. And so, they go and talk to the contractor and said to him, “You know, did you know that your email has been compromised, you should change your email password.”

And the guy, it says in the article, “We may as well have been speaking Romanian.” The guy had absolutely no idea what they were talking about. Because he’s a normal person. He doesn’t care about all of this stuff. You don’t say to people, “Oh, here’s a car, would you like a seat belt with it? Or would you like a piece of string that you could attach in, you know, particularly opt in place.” You know, as a society, it comes to a point where you say, “I’m sorry, not wearing seatbelts, there’s just too many people dying. So, cars have to have seatbelts. And you have to put the damn things on. End of story.”

And I sort of feel we’re getting to that point. Fraud and scam, it’s just so completely out of control. And this thing about whether you know, you need to put people in charge of their own data and so on. I just don’t believe that for a moment. I just don’t. Most people don’t have the persistent competence that – including me, by the way, I’m not casting the first stone, I’m one of those people that lacks the persistent competence to make this happen. There are reservations but passkeys are a billion times better than passwords, and we should make people use them. I’m sorry, you got to stop pandering to populism.

Heather: No two ways about it – Passwords have got to go. As we’re moving to passkeys, I think there’s always room for improvement on – even on them. If nothing else, focusing a little bit more on the user experience so that people will have a better understanding of what this means. And when they click this button, why would they click this as opposed to clicking something else that might be a phishing site that they wouldn’t recognise. So, it’s an ongoing education.

David: Then you sort of think of contactless as the, you know, in the early days of contactless people, “Oh, it’s too scary.” And in some parts of the world, it appears to be witchcraft, that you can pay for things by not touching it with your card and this, people are going to come and steal all the cards. And there are going to be people of Eastern European origin on the subway system, putting their hands inside your clothes to read your cards and all this. Remember all of this stuff that was going on?

And now, you walk into a store, anywhere in the world. I’m not talking America, I’m talking about developed countries, of course. You walk into a store anywhere in the world, and there’s that little contactless symbol and you pay, and you go, and no one thinks anything about it anymore. It’s a bit different in America. In America, you have to look for the till and where’s the sign? And then you have to press some buttons. And then sometimes you have to sign something as well. It’s baffling. I don’t understand any of it.

Heather: Oh, the day you understand what happens in the United States will be a marvellous day. Because nobody understands what happens.

David: No, it’s mysterious. But the point is, generally speaking, you know, we came up with this symbol, and everybody knows, you tap your card there, and it works. And guess what? All of your money isn’t stolen by Eastern European fraudsters. So, they’re not all Eastern European, obviously, other fraudsters are available. Because the corollary is going to be basically, people like us will start using passkeys, and so all the fraud will transfer onto people like your mom. That seems a little unfair to me.

Oscar: Yeah, seeing that you are excited indeed with passwordless. But of course, there are some concerns and some things to improve. Absolutely. Interesting what Heather said that, yeah, some people have been using password for so long, but that anything else feels like how do you say the…

David: An improvement? Real security? System-wide integrity? I don’t know, what’s the word you’re searching for there? I don’t know.

Oscar: How you say the…

Heather: Magic.

Oscar: Magic. Yeah, magic.

David: So, I’m excited as Heather is, I’m probably just a bit more militant on how quickly we should be pushing it out.

Oscar: Yeah, we’ll see what comes in the next year as how it really rolls out. But the next one is about identity wallets. So, what excites you today about identity wallets?

Heather: Oh, I have a list on that one. I’m particularly excited over how – as much as I worry about people not understanding the magic, they do understand the concept of flipping through a wallet to get to the right card, the right credential, the right thing they need and then using it and giving them that level of control is a vast improvement, I think over some of the other technology has been going on today.

I’m watching what’s happening in Europe quite closely because I think that – how the governments are handling digital wallets and digital identity is a very interesting model. I will be curious to see how other countries do it. How they do it well, how they do it poorly. And if there’s some way we can actually – I’d love to standardise ‘what’s a wallet’, you know. That’s one of my little pet peeves, there is no standard for a wallet. There’s standard for credentials, but there’s not a standard for ‘what is a wallet’.

David: I mean, it’s interesting to see what the Open Wallet initiative and various other people are doing in this space. I agree with Heather. I think as much as the technology is important, and certainly, in technological terms, the wallet is the sort of crucial pivot between the kind of online and offline world. It’s very central to the next phase of evolution of commerce. A lot of it has to do with – in fact, we won’t even call our wallets now identity wallets, we just call them wallets. But if you actually open up my wallet, I mean, I won’t do it over there. If you open up my wallet, it has no money in it. Everything is in my wallet, it has to do with identity, driver’s licenses and loyalty cards. And my wallet is already an identity wallet, we just don’t call it that.

So, extending that wallet across sort of virtual and real world seems to me, pretty straightforward. But of course, that does rather interestingly open up what I think will be quite a vicious battle about who’s actually going to control those wallets. Because certainly, Heather mentioned kind of the European approach. They’re very, very unhappy with the idea of big tech controlling those wallets. We’re very unhappy with the big tech or big government controlling the wallets. People like me will prefer that it was regulated institutions – banks primarily, that control those wallets. Other people think banks should be absolutely the last people to have any sort of control over those wallets. So really, I’m not smart enough to figure out like the end dimensional gameplay as to how this is going to work out. But it’s pretty serious. It’s pretty serious.

Heather: Yeah, people understand the concept of a wallet. But what we’re talking about in today’s world is that, you know, “how many wallets are you going to have to carry?” Because there may be one that’s issued by big tech, perhaps via your browser or via your mobile device. But then, you know, as governments are saying, “No, we’re going to issue something that’s completely separate and have its own app, and what is that going to look like. And then how are people supposed to be able to find the credential they need across 2, 3, 5 different wallets?

David: No, I agree with you completely on that, Heather. But I think there’s another level of complexity there as well, which is – because is the wallet going to be like if you imagine there’s some kind of standard wallet, is that wallet the app? Or is that wallet, essentially the underlying SDK the apps plug into?

So, my British Airways app and my Barclays Bank app, they’re all actually the same wallet underneath. They’re all plugging into the same wallet. But is it going to be like that? Is there going to be like a travel industry wallet? Or is British Airways going to have its own wallet? That’s really hard to know. I would think, and this comes from kind of what I think is a reasonably rational calculus. The credentials that are going to be in those wallets are the embodiment of individual reputations.

My British Airways credential is the embodiment of my relationship with British Airways, that I want to take and show to other people. It’s not obvious to me that British Airways would benefit from owning the wallet, because they’d have to maintain it and upgrade it and whatever. They’re having enough trouble just with their own website to do that. On the other hand, I can see why they’d be nervous about just handing the whole thing over to Apple and Google, because then they’ll end up paying a tax, which I’m pretty sure they don’t want to do. So, I don’t know how that’s going to work out. But I listen to a lot of smart people about this. It’s a very fascinating topic to me.

Heather: I talked to Don Thibeau and Juliana Cafik and a couple others about “what was the Open Wallet Foundation trying to do?” And they’re trying to work towards interoperability in code and maybe a standard will come out of that someday when they see what works and what doesn’t work. But at the moment, they are not standardising wallets. They’re just…

David: No, that’s true. There’s…

Heather: They’re just putting together a platform to try and make it work together.

David: But as you pointed out earlier on, some of the components are standardised. We have VCs, we have MDL. We’ve got MDL 7 and 9 coming in a few months, a year or something. So I mean, there is some pretty useful standardisation going on anyway.

Heather: Yeah, more in the credential format space.

David: Yeah, yeah. Yeah, absolutely. That might give us enough interoperability to get started.

Oscar: We’ll see. Indeed, it sounds like it’s…

David: I’m a naturally simple and optimistic person. Heather’s looking at all the nuances here. And that’s why she’s so, that’s why my superficial, cheery approach to this – it’s not washing with her I can see it from her face.

Oscar: You seem to be both excited about identity wallets, I think.

David: Yeah, I think wallets are really interesting topic for the coming year.

Heather: Huge potential.

Oscar: You, David, mentioned that as far as I understood, you don’t carry cash anymore, that was my understanding how you have your wallet, your real wallet without cash.

David: No, actually, I mean I don’t carry my real wallet, it’s in the drawer over there. So, I had an interesting conversation with somebody last week about premium cards. That’s how interesting my life is, Heather. I just, I benchmark, I had an interesting discussion with someone else last week about premium cards. This is a tragic trajectory of my life.

But I have this fancy new American Express Platinum Card, which is made out of some sort of metal. I don’t know if it’s actually platinum, but it’s sort of metal. And it’s really fancy and heavy and solid and whatever. And I couldn’t even tell you where it is. It’s in the house somewhere. I haven’t the slightest idea.

Oscar: Don’t activate it.

David: No, no, because as soon as I got it, it’s on my phone. I only ever use it on my phone. I don’t know where the actual card is, I have no interest in that. I’m going into London in a minute, I have a ring. So, the ring I use for getting on the subway and bus because I don’t always want to take my phone out. But if I’m paying in a restaurant so I got to use my phone. I think the days of physical wallets, I mean, lots of people keep saying, well, there’s going to be a backlash at some point, and people are going to want to use cash, sort of the way they want to use vinyl records, I suppose. But I think that will just be like a few hipsters. I don’t think it’ll be the rest of us.

Heather: I don’t trust having network access consistently enough to go without some kind of physical something. Do I use my wallet on my watch and my phone more often than not? Well, when I’m in Europe, yes. When I’m in the US, maybe. I don’t count on it. I don’t think I can count on it yet. So, there’s always the physical components that I think I have to have.

David: Yeah, I mean, I would say that’s an interesting argument in favour of using offline verifiable credentials. And it’s also a crucial argument in favour as to why Central Bank Digital Currency should operate offline. So, I mean, I agree with you about that. As to the state of things at the moment, well, if the transit gates fail and can’t go online, they have to fail open, it’s a public safety issue. You can’t fail transit gate shut. So, they have to, they should have – I can always get home, you know, but it’s never happened. But when push comes to shove, I’ll get home, so I’m fine.

Oscar: Yes, and that related to my last question, but just to hear what you liked the most. So, what excites you about this digital money that we were already starting to discuss?

David: I’d say there’s probably three things. I mean, Heather’s going to disagree with me on every single one of them, which is why it makes for an interesting conversation. But I’d say there’s probably three things.

So, the first thing is digital money, well, certainly digital currency is the subject of irrational delusional comment by conspiracy theorists, which makes for entertainment. So, I get emails, “oh, you know, Central Bank Digital Currency is the mark of the devil. And we know this because Bill Gates implanted microchips in us through the vaccine, and the microchips are going to steal the digital currency from unvaccinated people and send it through the 5g towers to Satan.” Or somebody, I can’t remember exactly, I don’t remember. But you get emails like this, which add to the gaiety of the nation.

So, the first thing is, there are parts of America where non-existent digital currency is already being banned. So, this is all getting a bit, sort of witch trail-y, so that’s quite entertaining.

The second thing is, and I wasn’t joking about that offline point, which is any scale digital currency in any developed country, even where you have networks and infrastructure has to work offline. It’s the crucial design requirement of it. If you’re going to have a cash substitute, it has to work offline. And that, for me, poses very interesting technological problems, all of which I think, have already been solved. But nonetheless, it’s really intellectually interesting, so I sort of like that.

And the third thing is, I think a lot of people look at digital currency as ‘the thing’. Like, you know, we need digital currency. And that’s it. I mean, what we need is a platform for innovation and development. Digital currency in itself is sort of not that interesting. As we’ve just established, I can already buy milk in the supermarket without using physical cash. So that’s not, but this idea of permissionless innovation that you could bring into our space from the cryp– because digital it doesn’t involve any credit risk, you see. So, you could imagine a situation where as long as you’ve got an approved chip in your iPhone, or something, they’re certified as being capable of storing digital dollars or something like that, then you can use the API to do whatever you like, there’s no credit risk involved. So, allowing people to experiment with interesting new things – micro payments, and Escrow and blah, blah, blah. On top of it is really where it’s at. And that’s why, you know, I get it a bit when people say, “Well, what are the sort of key uses?” Well, I don’t know, I’m too old. Give it to some kids in a garage and let them come up with something.

Heather: OK. So, for one thing, I really want to see your emails about this because they sound hilarious. I admit, I’m absolutely a digital currency sceptic. For one thing, as David has said, right, you don’t generally need to carry cash now anyway, so what is it getting you? And everything I understand about it is like, “Well, yes, but then you’ll be able to transfer money quickly without the bank getting in the way.” And I’m like, “Hmm, you say the bank getting in the way and verifying the transaction is a bad thing.” “Oh, but it’s expensive.” And I’m like, “Well, that’s a different problem, not just because the banks are charging a lot.” So that’s like a completely different problem to solve that it’s not a technology problem at all.

So yeah, I’m definitely not convinced. Having the permission to innovate and work with this kind of currency, to me in a way, that’s like saying, “Yup, let’s turn this into a barter system, except you’re bartering these digital currency components.” “OK. Go for it, go to town.” That’s just people agreeing with each other. And it’s a completely different system in the same way that a barter system is completely different with my cash system.

David: That’s a really interesting point. And I don’t mean that in any sort of patronising sense, I really mean that because you’re right, of course. And what that means is, if this stuff worked, then downstream you could imagine an environment where if you and I engage in some sort of transaction, right, I’m going to pay you to write something or you’re going to pay me to come and speak or something like that. My, you know, supercomputer at the end of a wire, it can be a through my mobile phone, my giant killer robot artificially intelligent wallet will negotiate with your super intelligent giant killer robot Terminator wallet to exchange baskets of tokens to an agreed –

The idea that you would need money as an intermediary when you have that kind of barter that works. I think that’s really, that’s as a very interesting point. So, if our super computers could agree on these baskets of assets to exchange, which sounds weird when its people talking about it, but it’s a few nanoseconds for super computers. Why would you turn those assets into dollars or something in the first place? Why wouldn’t you just swap the assets around?

So, I actually rather agree with that point. But I think that’s much further downstream. I think, in the short term, you see the demand for dollar stable coins in particular, as an indication to me that a lot of people around the world and in America, for that matter, wants to hold digital dollars. They would find digital dollars useful to do things with that you can’t do with regular dollars, and I sort of agree.

So, I can see sort of both things. But to me, the short term and the long term are quite different there. Because I probably do drink my Kool Aid, and I’d probably do think that that’s kind of a stupid expression actually it’s, don’t drink that Kool Aid because everybody that drank the Kool Aid died, didn’t they? Or am I getting the stories mixed up?

Heather: I wasn’t going to say it.

David: Yeah, no, I think they did. OK, that’s a bad example. But the point is, I think in the long run, you might well be right. I think in the short term, digital currencies, I think would add to the net welfare. I mean, I can imagine, you and I agreeing to something, and the money just goes from my digital wallet to your digital wallet. It never goes anywhere near the banking system. It just goes over Bluetooth or whatever but yes. It is exciting. That’s true.

Oscar: Heather, what’s not so exciting to digital money?

Heather: We’ll see.

Oscar: We’ll see. We’ll see. Anything else that it’s for you is exciting?

David: What’s not working digital money, you know, these answers are intertwined, because the thing that’s broken in digital money at the moment, is identity, not the payment bit. Like the reason why you’ve got Zelle frauds and authorised push payment frauds and these massive crypto scams going on all the time. It’s because nobody knows who anybody is. It’s not because the payments don’t work properly. It’s because identity doesn’t work properly.

If the identity, you know, I’m going to sound like a broken record on this one for the teenagers there. I’m going to sound like a vinyl implement that used to go around whether it has a scratch in it. So, this sort of needle would prompt up, down and come back to this, I have to talk them through this metaphor. But I’m going to sound like a broken record on this. Because if you fix the identity problem, payments are easy.

If you know the reputation of all of the counterparties in a transaction, then pricing the risk in that transaction is easy. And that’s kind of what we should be aiming for. The next phase of evolution is really about identity. It happens that I think, and I can’t prove this with any kind of actual analysis, this is just my sort of crackpot theory about this. But actually, if central banks do drive forward with digital currency, digital currency doesn’t work unless you have digital identity. You can’t give people wallets unless you know who those people are. You can’t maintain limits on personal holdings unless you know who’s got the wallets. There must be an identity system for the currency system to work. So it could be that Central Bank Digital Currency actually turns out to be a vector for people like Heather to actually get something done about wallets and digital identity. So, there’s an interesting interrelationship there.

Heather: They are certainly tied together. There’s no two questions about that.

Oscar: Anything else that you think that is exciting today in the identity world that we have not covered?

David: Well, there’s two things I’m excited about today. I can tell you what I was doing before I came on this call. So, one is – I’m very excited about only because I’m not a normal person. I’m very excited about ultra-wideband technology. So, all iPhones for a while, you know some of the top end Samsung’s you know Apple Air Tags, things like this, they all have this thing in them called you UWB, Ultra-Wideband which a lot of people kind of overlook a little bit because we focus everything on Bluetooth and Wi-Fi. But when Bluetooth and Wi Fi came out there were actually three wireless standards. There was Bluetooth, UWB and Wi-Fi. And UWB never really got used because the Wi-Fi chips got cheaper much quicker, and everybody just started building Wi-Fi into things. And meanwhile Bluetooth ranges went up.

But ultra-wideband, which is short range, medium speed that uses this pulsed radio. Because of the way it works, it can only tell where things are, this is how Air Tags work. But it can also tell whether you’re moving towards something or away from it. So, this idea of having a phone that knows you’re walking up to the point-of-sale terminal or knows you’re walking up to a door. And the way that Apple are part of this digital car keys alliance, which I’m very interested in with Google, and I think BMW and people like that.

So, this idea that you have one technology like this, which locates you, you’re walking towards the POS terminal, and then it flips to Bluetooth to execute an actually secure transaction with real cryptography, and real keys. I’m really interested in that at the moment for a variety of different ways. So that’s the first thing.

And the second thing is, and I think we have touched on this before, we think of identity as being about people. But actually, everything needs identity. And when everything has an identity, working out how to get both privacy and security in that environment is really rather complicated. It’s very intellectually challenging. And that’s what I’m spending the rest of my time on with another startup at the moment. So yeah, there’s no end of things to be excited about in this space, honestly. And frankly, figuring out how people can log into their bank account without password is the least interesting of the things that’s going on at the moment.

Heather: Probably the most interesting thing that I’m trying to stay on top of right now is watching the standards development space, because that is like one of my favourite things to do. Because I might also be a little bit of a strange person. So, standards development space, seeing how ISO, the IETF, the W3C, as well as some of the smaller standard’s organisations like the OpenID Foundation, the Decentralised Identity Foundation, Trust Over IP, how they’re all circling closer and closer to each other and sometimes hitting each other, bouncing off.

You know, it’s becoming a really dense space to try and follow and understand what’s happening with W3C verifiable credentials? How do those relate to the ISO MDOC standards, and what’s happening with the IETF’s OAuth and CBOR and you know, all of these different standard’s groups are all starting to get closer and closer at nibbling down this problem. And they’re never going to succeed because they’re reaching the point where it’s not a technical problem anymore. It’s a societal problem. And the regulators are starting to move ahead of them and saying, “No, this is what, you know, we need to happen. And it’s not about technology, as much as it is sometimes about the society and the cultural requirements.” So, seeing these organisations tighten up, it’s pretty cool.

David: I was just going to ask you, because I’ve sort of lost the thread on this a little bit, because unless you follow it with minute detail every day, you don’t. I wonder if the whole kind of MDOC thing doesn’t have its own momentum. So, in other words, in a lot of circumstances, you can see why people are going to go to MDOC and MDL part 5, even for something that’s not a driving license, just because. It reminds me a little bit, and here’s another one of the teenagers, it reminds me of X.500. Because having spent part of my young life, she doesn’t even know what X.500 is, how he’s been part of my – X.400 was the ISO messaging standard that existed before the internet and that no longer exists. And X.500 was the directory standard for that. And that no longer exists. An X.509 was the standard for exchanging public keys in that directory. And X.509 version 3 is how everything works on the internet.

So, the whole of X.400 has disappeared, the whole of X.500 disappeared. And I just wonder if MDL isn’t going to be in the same place, like people are going to end up using MDL just because it exists. It may not be the optimum for a lot of the appli– but it doesn’t matter. The format exists. Wallets can understand it. Apple and Google Wallets can understand it. The MDOC stuff will carry on standardising, and I think maybe a lot of stuff will just get sucked into that.

Heather: What’s getting complicated about it – is the MDL standards. They are in their own way the X.509 to the modern world. They’re specifying a credential. This is a discrete concrete, and this is what this is supposed to be used for. It is your driver’s license. It is your identifier. Verifiable credentials using W3 capital V, capital C verifiable credentials. That’s not what they are really, those are much more generic thing that’s actually more an authentication thing. So, the fact that they’re hitting each other in the ways that they are is very interesting and a little disturbing. And the fact that the browser vendors are debating within themselves, which one they’re going to support when ultimately, they serve different purposes, I worry that we’re going to be driven towards…

David: No, no, I… your analysis is spot on. I agree with you completely Heather. I’m just saying that in practice, what seems to be happening is like people like me would say, “Well, actually…” you know, use the canonical example going into the bar, you know, people like me would say, “Well, you should be presenting an ISO W3C verifiable credential that says that you’re over 18 or over 21. So, I’m going…” But that doesn’t exist. The standard for the credential exists, but the contents, whereas on MDL, OK, that’s not really what it was meant for. But actually, demanding to see your MDL driver’s license, I can do because the standard exists. And I, you know, so I agree with your analysis. I’m just saying I wonder if actually, well, Trust Over IP and all these other things are kind of circling around, bumping into each other. MDOC is just steadily progressing, you know.

Heather: Told you Oscar, I told you, you’re going to have all sorts of fun things to talk about.

David: He’s going to get very bored on our – just our island, Heather. Like after the plane crashes, we’re going to be fine. He’s going to be, I don’t know what he’s going to do all day, making those little token at men or something.

Oscar: Yeah, fantastic. Hearing all this from you. You’re definitely super passionate about – many of these things that you’re talking about, frustrated about some of them, but yes, super excited about most of them. So, thank you very much for joining us in very special episode for us. So, thank you very much. And please tell us how people can learn more about you, Heather?

Heather: Oh, easiest thing is – go to LinkedIn and find me there. I check it every day. It’s one of my major social media accounts.

David: Yeah, I mean, I spend more time on LinkedIn now since Twitter kind of went all weird. So, I mean, I’m on LinkedIn too. But it also you can just look up www.dgwbirch.com.

Oscar: Excellent. Well, thank you very much. So, let’s see how exciting comes the next coming months, years and yeah, how all the things we were discussing today will roll out. So, again, thanks a lot and all the best.

Heather: Great. Bye

David: Bye guys. Talk soon.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Gautam Hazari, mobile identity guru, technology enthusiast, AI expert and futurist & is the CTO of Sekura.id.Join this episode of Let’s Talk About Digital Identity where Gautam Hazari, mobile identity guru, technology enthusiast, AI expert and futurist & is the CTO of Sekura.id joins Oscar to discuss the missing identity layer of the internet. Gautam shares details about what the missing identity layer is, more about mobile networks as well as discussing Gautam’s TEDx talk.

[Transcript below]

“Internet did not have that identity layer. So what did we do? We created a trust-less model.”

Gautam Hazari is a mobile identity guru, technology enthusiast, AI expert and futurist & is the CTO of Sekura.id, the global leader in mobile identity services. He led the implementation of the mobile identity initiative – Mobile Connect – for around 60 mobile operators across 30 countries. Gautam had also been an advisor to start-ups in digital identity, healthcare, Internet of Things and Fraud and Security management. He is a thought leader for digital identity, advocating solving the identity crisis in the digital world and speaking on making the digital world a safer place. If you ask Gautam, “What is the best password?” you’ll always get the same answer: “The best password is no password”.

Connect with Gautam on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 99.

Podcast transcriptOscar Santolalla: On this episode of Let’s Talk About Digital Identity we are joined by Gautam Hazari, from Sekura.ID as we discuss what is the missing Identity layer of the Internet. Stay tuned to find out more.

Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar: Hello and thank you for joining us, a new episode of Let’s Talk About Digital Identity. Today’s guest is Gautam Hazari. He is a mobile identity guru, a technology enthusiast, artificial intelligence expert and futurist. And he is the CTO of Sekura.id, the global leader in mobile identity services. Gautam led the implementation of the mobile identity initiative Mobile Connect for around 60 mobile operators across 30 countries. He has also been an advisor to startups in Digital Identity, healthcare, the Internet of Things and fraud and security management. Hello, Gautam.

Gautam Hazari: Hi, Oscar. How are you?

Oscar: Very good, happy to have you here in the show.

Gautam: My pleasure. Thanks.

Oscar: It’s going to be super interesting. Now, we are focusing on mobile – mobile initiatives, like the one you are working with, can help us to solve the identity problems we usually discuss in this show.

First of all, I would like to hear a bit more about yourself. So, if you can tell us your journey to this world of digital identity.

Gautam: Sure. Thanks, Oscar. I have been in the identity space for quite some time now. And it started in the telecom world and that’s why I talk about mobile identity a lot. So I spent many years of my life in the telecom, so I worked with the Vodafone group for nearly 14, 15 years. What I realised is that there is one thing that the mobile operators have done quite efficiently is solving what I call the identity crisis of the internet. I started to talk about it quite passionately in different forms.

And in 2013, end of 2013, GSMA approached me. GSMA as you know is the GSM Association which is the trade organisation for the mobile operators. So the GSMA board was discussing that there were some assets within the mobile operators which can actually help in solving the identity crisis in the internet. Then they approached me that, “Hey, you were talking about this identity thing for quite some time, do you want to come and join?” And that’s when I joined GSMA to do the initiative for mobile operators to solve the identity crisis of the internet.

Then I led the technology for what was known and still known as Mobile Connect Initiative. I was the Chief Architect for Mobile Connect. And then me and my team created the reference architecture, the specification. And then of course, that’s not enough, so I went around the world, worked with the mobile operators to implement it as well. You know, at that time, there were around 62 mobile operators around the world who implemented it. And they did very passionately and this is where I met some of the founders, Mark and Keiron, in GSMA, working with the same team. And then I’m taking that journey forward in a much more accelerated and commercial way in Sekura.id.

Oscar: Yeah, excellent. Well, definitely a lot of your journey is in identity already and mostly in mobile, as you said. Before we start going to what you are doing in Sekura.id and we definitely want to hear more about that. I know that you have a special experience which is you have even a TEDx talk. So if you can tell us a bit of that experience.

Gautam: Yeah. Thanks, Oscar. It has been a fascinating experience actually, while preparing for the TEDx talk and also after that. So I was invited to do this TEDx talk to share my vision and dream of a world without passwords. I have been talking about these things passionately and that’s kind of my personal journey has been as well.

So, I had a lot of learning, you have to compact all that you want to talk within 18 minutes and that’s very interesting, right? If you have a free floating, I mean I’m really, really passionate about this identity thing, I can keep talking for days. But if you need to give your message within 18 minutes that’s quite interesting. So I learned how to deliver the message in that concise way.

And after delivering that, and once the TED organisation published the video in their YouTube. Interestingly, they didn’t actually remove any part of that, generally they do some editing but they didn’t do that for me. I’m really thankful to TED on that. So it happened end of last year. It’s been just one year completed and it has been viewed more than 157,000 times. And I have been receiving some very, very interesting messages from all around the world. From identity enthusiasts to security specialist, and also, from general public as well, saying that awareness is important. And we are having some inertia, right? We have been using passwords since, you know, 1961 actually, even before the internet was invented in 1989. But we don’t actually think that we are actually using it, and the complication that it brings too. I have been fortunate enough to hear lots of personal stories as well. These viewers, they have been sharing their personal stories related to passwords, and discussing what is the solution that can actually solve this.

Yeah, so it has been a fascinating experience and I’m really, really thankful for all the viewers who have been watching it and also most importantly, interacting with it and sharing their stories.

Oscar: Yeah, excellent. Yeah, I also watched and as you said, the way you explained also definitely appeals to the general audience which is of course what mostly TEDx is about, reaching wider audiences. So it’s definitely a good job you have done there. And I am happy to hear also that there have been a lot of conversation because that’s also important that people not only hear the stories or the ideas but also get involved in, spreading those problems, sharing their own pains, et cetera.

Gautam: Thanks, Oscar.

Oscar: I also know that you have written, of course, you write blogs, particularly, I read the you talk about the missing identity layer of the internet, missing identity layer of the internet. Could you tell us what is that?

Gautam: Yeah, absolutely, Oscar. I mean it’s extremely important that we acknowledge and realise that. Let me go back to when the internet was invented, right? Let’s face it, the internet was never designed to identify the human users. It was designed to identify the computers, right? That’s why there are IP addresses. Fortunately, or unfortunately, we humans don’t have IP addresses.

So, in the initial days of the internet, if you remember, all we used to do in the internet was browsing, right? We used to browse AOL, we used to browse Yahoo, different stories within Yahoo. So, it did not matter if for me, Gautam, is browsing AOL or Yahoo, or it’s Oscar browsing, or there’s fraudster who is browsing, right? Because all we did was browsing the internet. Yes, the returning user needed to be identified, not as Oscar or Gautam but whoever was browsing, right? So that’s why cookies were invented just to provide a continuity of the experience, right?

But then we started to do interesting things on the internet. We started to do commerce on the internet. We started to look for things on eBay and started to pay for those things. We started to do banking on the internet. We started to interact in the social media in the internet. And then it did matter whether it’s me, Gautam, doing that commerce transaction, whether it’s me, Gautam, who is doing that banking transaction or it’s you, Oscar, or it’s the fraudster. Or, in the current days, if it is that AI chatbot who is doing that transaction, right?

Internet was not designed to do that. Internet did not have that identity layer. So what did we do? We created a trustless model. So, if I want to pay for some things that I found on eBay, or if I want to do a banking transaction, my bank will say, “Hey, you cannot do that, because I don’t trust you. First, I’m challenging you to prove that you are Gautam.” That’s what we created, because the internet didn’t have that identity layer.

So how did that challenge happen? And they initially did this, this challenge happened in the form of user ID and password, right? And again, we all aware of all the complications related to password from convenience to security, right? Then we said, “Hey, passwords are not enough. Let’s add other things.” So, we started to talk about MFA, Multi-factor authentication, we added SMS OTP, right? And again, OTP, the last P is about password, right? Just changing the acronym doesn’t change the problem.

But then again, they said, “OK, maybe that’s not enough. Let’s add the biometrics on top.” But again conceptually what we are doing is, we are creating a trustless model where these services are challenging me and the human user to identify myself, right? And whenever the human user is involving in providing a response to the challenge, for example in form of I need to type back the password, or I need to provide back the OTP, however I give, whether by typing back the OTP or some auto read happens. Or even if I do this, let’s say, biometrics in the form of facial recognition and so on, I, as a user, is the weakest link in the chain. I do something wrong, which is perfectly fine because me, as a user, is not a security architect. As a normal user, I am not aware of all those security complications that can go away, right? And that’s where all the problems that you have seen and again, why? Because the internet was not designed to identify this human user. Internet never have the identity layer. It still doesn’t have.

But we almost ignored the fact that almost at a similar time, there was a parallel internet that was getting created. So, as you know, I’m actually using the world wide web as synonym to internet, so when I say internet, it’s actually the world wide web, right? So, 1989, this wed, world wide web or internet as we call it was invented. In 1991, there was a parallel internet that was created. And we never call it the internet, we call it the mobile network, right? The first SIM-based GSM mobile network was used in 1991. And that parallel internet worked completely differently.

So, as we discussed, in the traditional internet, if I want to do any interaction, where I, as a human user, needs to be identified, I’ll be challenged, right? My bank will challenge me, my social media will challenge me, my e-commerce provider will challenge me, even my grocery store, online store will challenge me, right? But this parallel internet, which we call mobile network, worked completely differently, still works differently.

If I need to make a phone call, receive a phone call, send an SMS, receive an SMS, it doesn’t challenge me. My mobile network doesn’t say that “Hey, I don’t trust you. First, you prove that you are Gautam, then only you can make a phone call.” It doesn’t work that way. It just knows that it’s me, who is Gautam. So how did they do that? They actually created this identity layer. They actually created a mechanism which identifies this human user from day one, since 1991.

But we know this. How did they do that? They did that using this small gadget that we always carry in our mobile phone, this is the SIM. We almost forget that I, in the SIM, stands for identity. It’s Subscriber Identity Module. SIM was created to solve this identity problem in that parallel internet, which we call the mobile network, right?

So, isn’t that a solution? We were just ignoring it and also, just unfortunately, these mobile operators knowingly or unknowingly, kept this with themselves, right? What we are doing at Sekura.id, I’ll just mention here, that we are bringing in that identity layer from this parallel internet which we call the mobile network into this traditional internet so that we actually solve the fundamental problem rather than keep creating technologies on top like password, like SMS OTPs, like biometrics. And that is what will solve the problem from its root and bringing in an identity layer from this parallel internet to the traditional internet.

Oscar: Thank you for the explanation, of the lacking, missing identity layer of the internet. And then you put a parallel, I haven’t thought of it in that way, the parallel of the mobile network which always had this identifier of the subscriber. As you say, even in the term it’s subscribe, the SIM card. So, I understand that Sekura.id solution is primarily based on the SIM card. Tell us a bit more how it works and if you can give also how it works, Sekura.id besides being based on the SIM card.

Gautam: Sure. So, GSMA doing this Mobile Connect, the conceptual idea was very similar, right? It’s to utilise the assets from the mobile operators, not just the SIM card. SIM card is a cryptographic engine. But there’s a lot of data available with the mobile operators which can help to identify the human user without challenging them. And also, protect them without putting a hurdle for the user, like what user ID, password, OTPs or biometrics are. They are hurdles, right? They are actually saying, “Hey, you cannot access the service until you pass that hurdle.”

This is where Mobile Connect started and this is the journey that we are continuing in Sekular.id as well. So, in Sekular.id, what we do is, as I say, the SIM is a cryptographic engine. And now, in the digital world, there is realisation that all the different, let’s say, identification and authentication methods where the user is actively involved, which means the user is challenged to prove who they are, or authenticate themselves, that is a limitation. A limitation in the form of that you know, if let’s say the user has got an OTP they have received, these fraudsters will always call this user and say, “Hey, I’m calling from your bank, or I’m calling from the government, you have received an OTP, can you hand it over, right?” If the user is not involved, right, these fraudsters can call the user but they have nothing to handover. So in that case, we solved this problem of all the fraudulent activities that’s going on.

So now, there is a realisation in the digital world as I was seeing that we need to avoid involving the user. So we need to do passive authentication. And how do we do that? Cryptographic authentication is one way to do. So, Apple last year in WWDC announced these passkeys which is basically based on the FIDO, the Fast Identity Online mechanism, where this is reliance on cryptography and cryptographic key on the device. And then that’s how we identify the user, right?

But exactly same mechanism is what happens in the SIM. And it is happening for the last 30 years. There is a cryptographic key which sits in the SIM which the user is not even aware of. And that’s an important thing. The user is not aware. As soon as the user is aware, or the user is involved in that awareness, OK, all these problems will happen because these fraudsters will approach the user and try to do some funny things, right?

And that’s another aspect that we say that here, this cryptography is humanised. If the user is not involved, it just happens behind the scene. In that case, this technology is humanised. Invisibility is more humanised. Steve Jobs used to say that technology should either be beautiful or it should be invisible. So here, this technology is invisible so that makes it much more humanised, right?

So, at Sekura, we’re utilising this cryptography in the SIM to seamlessly, invisibly authenticate this user. At the same time, there are a lot of what we call signals associated with the SIM which can help protect the user, at the same time, identify the user. For example, one of the largest fraud happening in the digital space right now is SIM swap fraud, right?

If we can identify that hey, is there a recent SIM swap happen? By recent, I mean in the last few hours, for example, to one day. If there is a SIM swap happen, in that case, that’s a red flag, that might mean that the user who is in the transaction process, who is interacting with the digital service may not be the genuine user, it could be a fraudster who have got access to the phone number of the user and using their own SIM. That’s one data signal that’s there in the mobile, with the mobile operator, that doesn’t need to involve the user to ask if something has happened or not.

Similarly, setting up a call redirect, right? The fraudsters can actually setup a call redirect for my number calling up the operator, doing some mechanism, some process there where they can say, “Hey, I have lost my phone, or I left my phone at my home and I’m expecting an urgent call from my family who is in the hospital. Can you please redirect all the calls to my number to this?” If I can convince the operator, in that case what will happen is, all calls, SMSs will be redirected or forwarded to me as a fraudster, right? So, if we can actually identify, is their call forward active for this number? That data itself can protect the user, again, without involving the user. So, we have identified 66 such potential data signals which can invisibly protect the user and their identity. And that’s what we do at Sekura, working primarily with the mobile operators.

Oscar: I like the idea of this invisibility because from the beginning you started that the human side is going to make security fail, right? But if the human doesn’t have to be involved, yeah, I’m sure, there will be less hacking. So that is definitely the concept, it’s very interesting.

Gautam: And just to add there, Oscar, you know, of course, there is this identity protection, there is this authentication without involving the user. That element is there. At the same time, it is allowing these good guys to access the service, right? So, as I was giving that example, it’s me, right? I’m not the fraudster. It’s me who wants to pay a particular merchant online, right? And I’m assuming I’m the good guy, right? And I want to pay. In that case, there shouldn’t be a barrier for me, right? And it’s good for the business because the business will get me to pay them. That’s what they want, right? So, in that case, it’s important that the good guys should sail through, right? For them, there is no barrier.

If we make it invisible for the user, in that case, these good guys can actually access, you know, without any trouble. At the same time, because it’s invisible, we can actually protect this user behind the scene as well. What does that mean is – it’s not just helping out with the identity verification, security and authentication, it’s also getting better business. Because if we put barrier to the good customers, good users, in that case, there are dropouts happen.

We have been told by our clients all around the world that on an average globally 20% of the users dropout due to all these, let’s say, challenges. They say, “Hey, I’m not going to use it.” SMS OTP is needed to do our transaction or to pay and OTP doesn’t get delivered or it is delayed, the user say, “Hey, I’m not going to pay now, right?” So that will direct 20% on an average globally, dropouts happen.

Here, if you make it invisible, you don’t have any dropouts, right? Because there are no barriers. There is no door which is closed that needs to be opened. So, in that case, the businesses get 20% more conversion, so that’s more business, more revenue. So that element is also there, if you make is invisible using the mobile operator’s asset like the SIM and all the data. That needs to be considered as well alongside security.

Oscar: And what if, myself as a normal user, I want to try Sekura.id, how can I use it already? There might be some services which is already available?

Gautam: Yeah, absolutely, Oscar. So one element here is you know as you can understand, this is B2B service, right? So the businesses are using us. Businesses are protecting that. All our services are, you know, they go through one single API, right? So, it’s not the user who is accessing our services directly. As I was giving the example, I, as a user, accessing my banking service, right? And my banking service is using the Sekura.id services through the API, right? So that’s how I, as a user, as a consumer use it. Not directly through Sekura, through my services. And then again, I may not be even aware that that service is getting used, right? Because this service, as I said, for the human user it’s invisible.

So majority of our clients right now are mostly from the financial services, so the major banks in the UK, they are using our one or more of the services like Barclays is using our services, Virgin Money is using our services. In the US as well, Morgan Stanley, they are using our services, Flora Bank, they are using our services.

But again, just to reiterate, it’s not a B2C service, right? So it’s not that me, as a consumer, is using the Sekular.id services. It’s my business who is using the service to help me as a user getting protected. And at the same time, no buyer has been put by the businesses to access it. And we are actually expanding globally. As I mentioned to you earlier, I was in India, I came back yesterday, we are actually launching in there. We have some very, very exciting discussions happened across the use cases there, not just in the financial sector, beyond as well. And then we will be announcing those pretty soon.

Oscar: OK,as soon as they are launched, it will be interesting to know what are these use cases. So, very interesting initiative that you have in Sekura.id. So what happens for instance if – because this depends on people having good mobile networks and good phones, so what happens if that’s not available in some regions in the world?

Gautam: That’s a very important question you ask, right? And there are two elements you said, one is good mobile phone. One of the thing that we really passionately believe in Sekura is inclusiveness. And that’s very important for us. We have a mission statement for identity for all and everything. So no one should be excluded from identity protection, right? And this is why we tackle it from multiple angles.

So for example, we have platform that we have created from ground up based on all our learning from the GSMA and also my learning from Vodafone. That platform can integrate with any mobile operator in the world, right? Because all mobile operators are different. There are 700 plus mobile operators there. Right now, we are connected to around 75 mobile operators globally and we want to connect to all. Why? Because we don’t want any operators to be excluded because if we exclude that, their consumers or their users will be excluded.

So, one example is in India, one of the phone smallest operator is BSNL, right? It’s government-owned operator. They are quite small. They don’t have platform. And they were actually not included in this identity space. So what we have done is we have provided our platform to them so that, that platform can actually connect to that mobile operator and then it can actually expose their services, right? So that we don’t want to exclude their users.

At the same time, it is important, as you rightly asked. What happens if I don’t have a good phone? So, this is where the principle that we use in all our services has got two major aspects. One, I already talked about – not involving the user because if you don’t involve the user, we increase the security, because user is the weakest link, right? And rightly so. And the second thing is not depending on the mobile device, because that’s extremely critical. Because let’s say, if the user can afford an iPhone 15 right? Of course, that’s extremely secure. The key chain there where the keys are stored is a hardware, right? That’s an HSN. So, it will be extremely secure.

But what about the user in let’s say Southeast Asia or in Sub-Saharan Africa where it’s a sub $10 phone? That may not have that much security. So, it’s unfair on the user because they cannot be pay for that advanced phone, they are getting excluded from security and identity verification. At the same time, it is unfair on the businesses, they cannot rely on a security because the user cannot afford that high end phone.

That’s why that’s the principle we use. We don’t rely on the mobile device. What do we rely on? The SIM. The exact same SIM is in the iPhone 15 or any of the high-end devices or in the low-end, not so expensive phone and provides the exact same security, right? The cryptographic security that I talked about doesn’t differentiate whether it’s a very high-end, expensive phone or not so expensive, much simpler phone. So that’s an important element here, right? So, our services don’t rely on the device. It doesn’t matter what device the user is using.

Secondly, all the data elements that I talked about is in the mobile network. This is completely independent of what device it is. So that way as well, all those data elements that I talked about, all those 66 potential data elements are independent of the device. So, that’s how we use the service and then make it inclusive end to end, for any user, right?

The other thing you asked about is what if there is no mobile network? It doesn’t really matter. So, the way to look into this thing is, we are relying on the mobile network. But the user doesn’t have to use the mobile device even at that moment of time for majority of the services. For the authentication services, the mobile device need to be in the network. But again, if the mobile device is not in the mobile network, it is connected to Wi-Fi or any other networks, in that case, we have fall back mechanism because we cannot really, rely on the mobile network because the device is connected to Wi-Fi, still we have a fallback mechanism.

And in some regions, like in US, we have worked with one of the large mobile operator there. Where we have worked with them to utilise the SIM, even if the device is connected to Wi-Fi. Because even if the mobile device is not connected to the mobile network, still there is a SIM there, right? If you can reach out to the SIM, we protect the device anyway.

And the other thing I was talking about, all these 66 potential data signals, they are available at the mobile operator’s secure CRMs, CVM and all the OSS, BSS system, right? So they don’t need the user to be using the mobile device at that moment of time. For example, if there is a SIM swap that has happened in the last few hours, the mobile operators databases, they already are aware of that even if there is no network. So, all our services other than the authentication service which we call SAFr Auth, all our services are data-related or signal-related services where these businesses, let’s say, this is a bank or an e-commerce provider or even a social media provider, their server makes the API call to our platform to get this data signal. So the mobile device is not involved, mobile network is not also involved there. Because again, we want that inclusivity for every user to be involved in there.

Oscar: OK. Well, definitely very novel way of addressing these problems. So I’d like to ask you one final question, Gautam, for all business leaders listening to us now, what is the one actionable idea that they should write on their agendas today?

Gautam: Thanks a lot Oscar for asking that. The most important thing to add into their agenda is an acknowledgement that the internet doesn’t have that identity layer. Because that’s a fundamental problem. Because if we start to add technologies on top to fill the gap, that will not solve the problem. And we have seen over the years, right? We have seen user ID password, they didn’t solve that, SMS OTP or any form of OTP, they didn’t solve that. Then we added all sorts of other OTPs, right? TOTPs, authenticated apps, we even used those RSA tokens that we used to carry on. Then we evolved into biometrics. And by the way, biometrics, I’m sure your audience is aware of this, after Generative AI, every form of biometrics is challenged.

And then actually, you know, interestingly, LexisNexis, which is one of the largest fraud management provider on app based in US, their CEO of the government affairs came to the press. This person gave an interview to Fox News in June, saying that we are so much relying on these biometrics and after Generative AI revolution, there is a financial impact in the industry and then that impact is around 1 Trillion USD because every form of biometric is challenged through this Generative AI. Not just through deep fake, through all sorts of mechanism. I mean you can actually search the internet on those kind of fraudulent activities happening on almost a weekly basis.

So, let’s acknowledge that there is a fundamental issue with the internet and that’s no one’s fault because internet was not designed for that. If you acknowledge that, then we can solve the fundamental problem, right? And that can be done through the already existing identity layer which is existing in the mobile operators. Let’s work through that and solve the problem forever.

So, basically, what I am saying is, let’s bring in that identity layer from that parallel internet which we call mobile internet into the traditional internet. And let’s solve that problem at the root. And that’s what we are doing in Sekura.id. And that’s what we would invite all the leaders in the digital space to look into and solve the problem.

Oscar: Thank you very much, Gautam, for this very insightful conversation. And let us know if people would like to find more about you on the net, what are the best ways for that?

Gautam: Thanks a lot, Oscar. Thanks for inviting me. I am on LinkedIn. Please connect to me. It’s Gautam Hazari, G-A-U-T-A-M H-A-Z-A-R-I. If you Google me, you will find me there as well. And also, please visit Sekura.id, S-E-K-U-R-A.ID. You will find insightful solutions there and also we post lots of insightful stories, articles, blogs and what the future is looking like. Recently, one of my article is published in Forbes, I’m calling it Internet of Thoughts, where the future is coming and where, if you don’t solve this identity crisis in the internet it may create more issues. So, please reach out. Please look into Sekura.id and let’s solve this identity crisis together.

Oscar: Yeah, of course. Again, thank you very much Gautam for this conversation, and all the best.

Gautam: Thank you very much Oscar for having me.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Russ Cohn, the (Go-To-Market) for IDVerse.In episode 98, Russ Cohn the Go-To-Marketing for IDVerse joins Oscar to explore Generative AI within Identity Verification – including what is generative AI and deepfakes, why deepfakes are a threat for consumers and businesses, and some of the biggest pain points in the identity industry and how generative AI can support this.

[Transcript below]

“It’s very important that we understand these threats and start to mitigate and create ways of helping to support and stop these practices.”

Russ Cohn is the (Go-To-Market) for IDVerse, which provides online identity verification technology for businesses in the digital economy. Russ has spent more than 20 years scaling businesses of all sizes by delivering successful growth strategies across the UK, EMEA & US markets within fast-paced and high-growth online media, fraud, identity, SaaS, e-commerce, and data-driven technology solutions.

His strong tech knowledge is coupled with deep operational and commercial experience building teams within SaaS, advertising and marketing technology-driven revenue models. Russ was previously a key early member of the Google UK leadership team who grew the team from 25 to 3,000 people and the revenue from £10m to £1billion during his tenure. He brings deep experience supporting international technology companies and has a passion for marketing development, startup growth and technology solutions.

IDVerse empowers true identity globally. Our Zero Bias AI™ tested technology pioneered the use of generative AI to train deep neural network systems to protect against discrimination. Our fully-automated solution verifies users in seconds with just their face and smartphone—in over 220 countries and territories with any official ID document.

Connect with Russ on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 98.

Podcast transcriptWhat is generative AI? This week Russ Cohn, from IDVerse has joined us to discuss generative AI and deepfakes and the threat this imposes on businesses and consumers for their digital identities. Stay tuned to find out more.

Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining a new episode of Let’s Talk About Digital Identity. Artificial Intelligence, in particular, Generative Artificial Intelligence is a topic that has been, I believe on most of our radars in the last 12 months, particularly. And there are amazing things going on. But also, we know that the bad guys are also using those tools. And one of those is related to deepfakes that are being used to cheat the identity verification system having existing until now.

So, to see how we are going to solve those problems in identity verification, these newer problems, we have a special guest today who is Russ Cohn. He is the go-to market for IDVerse, a company which provides online identification technology for businesses in the digital economy.

Russ has spent more than 20 years scaling businesses of all sizes by delivering successful growth strategies across the UK, EMEA, and US markets, within fast-paced and high-growth online media, fraud, identity, SaaS, e-commerce, and data-driven technology solutions. His strong tech knowledge is coupled with deep operational and commercial experience building things with SaaS, advertising and marketing technology driven revenue models.

Hello, Russ.

Russ Cohn: Hello, Oscar. How are you?

Oscar: Very good. Happy to have you here.

Russ: Thank you. Very glad to be here.

Oscar: Fantastic. It’s great to have you here. And we’ll talk about the deepfakes and how the newest practices in identity verification are solving these problems. So, let’s start, let’s talk about digital identity, Russ.

So first of all, I would like to hear a bit more about yourself, your story. Tell us about yourself and your journey to the world of identity.

Russ: Absolutely. I am fairly new to identity. I’ve only really started in the industry probably just over three years ago. I was the first international employee of OCR Labs, which is we recently rebranded to IDVerse, but I joined about three years ago. We’ve since then built the international team to over half the company, and we continue to grow in EMEA and the US.

As a background, I’m a marketer, a commercial leader, investor. I’ve spent probably over 20 years in technology-driven companies of all sizes. And I was lucky enough to join Google very early on, and there were 20 people in the UK, and 600 people around the world. And I grew up with them a little bit, and I left there with 65,000 people. So, I’ve got a fairly good experience at scanning companies and have invested and advised companies since then.

I’m now, as I said at IDVerse. And I’m focused on the go-to market. So, helping them globally, to take our products and execute them in the best possible areas and help our customers with the most cutting-edge technology to drive identity verification, make it effortless. Obviously, through the use of our sophisticated technologies and techniques, including Generative AI.

I’m excited about the opportunity for identity verification, as the need for verified trusted identities has grown exponentially, globally, really, since the pandemic. And with digital growing at such a phenomenal rate as well, we’re now living in a mobile-first world, and we need the right kind of identity verification to support that growth.

Oscar: Indeed. So, let’s go to some basics. For someone who has heard about that term, Generative AI and still is not so clear what it is, particularly. Could you tell us what is that? What is Generative AI?

Russ: Yeah, sure, I think, you know, everybody is talking about ChatGPT and Bard and it’s brought these techniques, the AI techniques to the public, and we can’t get enough of them. But everyone is using ChatGPT and Bard, etc to learn more, do their jobs better, find new facts. It’s pretty addictive and very, very useful but still at the at the fairly early stage.

So Generative AI, short for Generative Artificial Intelligence refers to a class of artificial intelligence systems and techniques that focus on generating new content or data rather than simply recognising patterns or making decisions based on existing data. Now these systems are designed to create original content that resembles human created data such as images, music, texts, videos, and more.

I use Spotify extensively. I’m sure most people do. And I’ve got an AI system on there now a couple months ago that’s going through my music catalogue in my background and choosing the right music based on my tastes. Generative AI models are generally trained on large datasets, and they learn to understand the underlying patterns and structures within the data.

So once trained, they can produce new examples that are similar to the data they were exposed to during their training. These models are capable of generating content that didn’t exist in the original dataset, making them a very powerful tool for creative tasks in content creation. Now at IDVerse, we’ve been doing Generative AI for a long time, probably since the start, seven or eight years ago.

And we use a technique, a very familiar technique called Generative Adversarial Networks or GANs, I’m sure a lot of your audience will be familiar with. Now GANs, just to go back to basics, consists of two neural networks, a generator and a discriminator. These are trained together in a competitive manner. The generator creates the synthetic data, and the discriminative task is to differentiate between the real and the generated data.

So, the competition between the two networks leads to the generation of increasingly realistic content, which we see everywhere in videos, photos, documents, et cetera. Now, we’ve trained millions of synthetic and real documents and millions and millions of synthetic faces using these techniques. For us, just to be clear, we only use ethically sourced or fair source data for face biometric, particularly in the training. This refers to the facial recognition datasets collected and used in a manner that upholds strict ethical standards and respects individual’s privacy, consent and fairness.

Such data is obtained transparently with informed consent, minimal intrusion and efforts to mitigate bias. So, these measures ensure the responsible and equitable use of biometric technology. In the context of facial identity verification, training data refers to the specialised datasets of facial images used to train the machine learning algorithm, or deep neural networks that are responsible for recognising and verifying individual’s identities based on their facial features.

So that’s quite a mouthful. Hopefully, that gives you some context. But this is how we look at Generative AI in identity verification.

Oscar: Yeah, thank you for that introduction. Of course, in one of the products of this type of Generative AI, in related tools are deepfakes that we are seeing more often, sometimes we saw that only for, like, say celebrities or famous people. But now, they can be used to attack me or to attack you, actually anybody right?

So, tell us how the use of deepfakes is a threat, a real threat for both consumers and businesses?

Russ: Yeah, absolutely. I think they are a massive threat as the rise of Gen AI, and you touched on it, fraudsters use the same if not better techniques than we do, or many companies do. And they are very, very good at surging ahead of these technologies and finding ways to create very realistic synthetic identities to both impersonate real people, as well as to create brand new identities of people who actually don’t even exist in real life.

And so, while that’s exciting as we talk about Web3 and avatars and these opportunities and possibilities, I think both consumers and businesses will continue to fall victim to many of the risks out there, unless measures are taken to prevent this.

Now, I just want to highlight a couple of examples of these like disinformation and fake news, right? So, creating videos of public figures, you can grab off Facebook or YouTube, and replicate those and make them do things that they never did. That can be exploited to spread false information.

This can incite conflicts and it can really manipulate public opinion. For us, we see and obviously, we’re very close to and care a lot about frauds and scams, so businesses and consumers of course, can – in the UK particularly we have a huge fraud problem. And we see a lot of deepfake base scams that can impersonate company executives, trusted individuals, they can deceive employees or the customers who can make them reveal sensitive information for financial transactions.

We’ve seen some of that just recently with MGM in the US in this recent breach. We don’t know it exactly, but we do know, I think somebody, an employee was actually targeted. This can cause you know I think like reputation damage of people, you know, politicians, businesses and people, fake videos and audio can be created. To endorse a product or not support it and that can create problems. And of course, the things we care about a lot of, identity theft, right?

And deepfakes can be used to impersonate individuals leading to identity theft. This may result in unauthorised access to personal data or systems. And of course, manipulation in financial markets, personal bank accounts, breaches of banks. So, this can cause big issues like privacy concerns, security threats and erosion of trust, through the wide use of this, and internal security problems for businesses, and privacy for people when they violated, and their identities are stolen.

So, it’s very, very important that we understand these threats and start to mitigate and create ways of helping to support and stop these practices.

Oscar: Yeah, indeed, you already explained some cases in which these criminals are already targeting the identification system that has been existing in the last years. If we focus on these services that are today and have been protecting us or helping us in identifying people in the last years. So, what are these – the biggest pain points or the weaknesses that they are being attacked by these criminals?

Russ: Yeah, look, I mean, there’s a lot of weakness in existing systems, which can come across in the fact that vendors don’t disclose, for example, that they don’t use their own technology, and they can’t always deliver on their promises. So, I think a lack of global document coverage, old style techniques like templating exclusion, like racial bias, gender and age in these poorly designed systems can cause huge problems. And systems that don’t have the ability to understand where these attacks are coming from with these synthetic IDs.

We create all of our own tech in-house. So, we don’t use external vendors to drive our fully automated solutions. So, we feel pretty confident. But they are, as you mentioned, these legacy systems that we’ve relied on, that aren’t necessarily up to speed. We’ve seen, from a pain point of view, is badly trained human spotters in remote locations, for example. So, some people in the industry and vendors use those, this can cause slow response times, and they can’t keep up with the standards and the technology that’s being used to identify fraudulent documents.

And also, the biometrics of people that are not real. So, it’s very difficult for them to keep up. And then, we’ve seen an issue around a lot of bias or differentials in the natural bias that’s in previous ID systems designed by, traditionally older white male engineers. And that’s a problem because these biases are built into these systems. And the humans who are evaluating physical documents, depending on where and how and what can inflict their own biases on age, gender, and race as well.

Now, this can slow down experiences for customers, as they take a lot longer. And of course, they aren’t as accurate, you know, humans can’t scale. And so, technology can do a lot of that heavy lifting, and can solve a lot of that. And you can still have humans for critical tasks, but it’s important that you use technology to identify these gaps.

In fact, we ran a study a few months ago with an external testing company called BixeLabs of 1500 subjects, male, female and transgender, across eight regions in the world for our facial biometrics. And we came back with zero bias on either race or gender on the facial biometrics. So, it’s pretty important that businesses start to use, and people start to get comfortable with one of the strongest, probably the strongest biometric there is for lots of actions that we do take in our everyday lives, whether it’s on a personal or work basis.

And I think that the other things that are challenging for us in the identity space is we see a lot of unethically sourced based biometrics, right? And that can refer to the acquisition usage or distribution of these, that can violate privacy, I mentioned earlier consent or ethics.

And these practices really can result in privacy infringements, discrimination, social harm and legal issues. And some examples of that are data scraping and profiling, lack of informed consent, data breaches, of course, we’ve seen that recently and frequently, deepfakes as we talked about and manipulation of people, government surveillance, employment discrimination. These are big issues.

And I think the lack of unified government standards around these things is also difficult. And it’s important that people use the latest technologies like computer vision and Generative AI to start, to be able to scale and address some of these issues and keep users and businesses safe going forward. But those are definitely some of the issues that we’ve seen accumulate over the last few years.

Oscar: Yeah, yeah, I can see there are quite a few. And how these more recent generation of identity verification system that are working together with Generative AI. So, if you can tell us a bit of the how, how they are different to the previous products, and how they are tackling these problems?

Russ: Yeah, as I expressed in some of the technologies that we use, I mean, training data for Gen AI, for example, if you think of it, if I can frame it in like nutritional labels like food, right? So, you’re feeding a machine, essentially. And so that training data should come with some sort of nutritional label, and to know what the macro nutrients will affect performance. So, you know, it’s important that when using Gen AI, you understand that the nutritional makeup of their training data, supply chain transparency, where do you get their data from, for example.

But it’s important, these techniques are able to detect the proliferation of these fake documents. I think digital identity is becoming more and more, of course, prolific and governments are starting to bring onboard connectivity into these digital identity databases that are able to verify customers in a much more robust way than potentially documents were.

So, I think we’ll see that constant trend of digitisation of technology, mobile-first, wallets, and of course, documentation that will become digital will make life a little bit easier. But, in order to protect themselves, consumers and businesses really need to think about what they can do to stop and be vigilant, right?

So, I think consumers need to educate themselves. They need to use things like password protection and protect their devices and be aware of things like phishing tactics in social media and email. So, we can do as much as we can for businesses, but I think businesses need to invest in these systems because they are stronger, the security measures are stronger, and will help protect them and their customers ultimately.

I think the differences that we see, we believe facial biometrics is a very, very strong and has been proven externally through, you know, NIST iBeta certification, for example, we have a 99.998 certification of liveness biometrics, I mentioned the inclusion and lack of racial bias. If you want to capture and work with people of all races, all genders, all colours across the world, it’s important to use systems that are inclusive, otherwise, you’ll end up discriminating and losing customers.

So, it is important to make these investments into these systems to help protect your business and help protect the consumers behind that. But ultimately, consumers have to also be educated themselves. They have to think about what they’re doing and be aware of things that are out of the ordinary or suspicious, unsolicited requests, for example. And then lastly, I think, you know, government needs to engage in some sort of public dialogue as well to help consumers about understanding what they’re doing in these initiatives.

And government needs to work with business as well to inform the public about things like biometric technology, ethical implications, and why they should be using these. But ultimately, there should be some ethical guidelines and review boards to be able to support the usage of this new technology that’s coming at us at such a pace. It’s really strong, really powerful and really useful.

But there have to be some guardrails around that, and I think it’s going to take a collective effort from consumers, businesses and government to get us there.

Oscar: You mentioned, for instance, a liveness detection that is one of the ways that this identity verification tools are checking that the person is a real person moving in front of the camera. In terms of the end user, so when the end user is in front of this identity verification system that are based on Generative AI, so let’s say user experience is similar, is so how transparent or is different?

Russ: Yeah, I think, look, with facial recognition, for example, and the techniques we use in identifying people when they’re going through the process of verifying themselves or for account access or re-authentication, no personal data is stored. So, the use of those biometrics is the ability to give people a robust way to prove themselves and their proof of life, if you will, when doing a particular action.

And I think what’s been missing in the past is people have accepted a document which could or could not belong to that person to be the valid form of identity. The reason why identity documents around the world had been the standard is there was always a picture of your face on that document.

So, you had a passport or driver’s license, you could see it was you in a sense. So, with liveness, people are protected the same way as using phones to open up access to your phone and to those systems. But these systems are tested and there is no personal data. People should feel very comfortable that the data that they’re using to generate that action is protected and their own in terms of doing that.

We’re just using technology to be able to verify that that person is live and present, and is not a deepfake, was not a synthetic ID. Because what we see a lot is these presentation attacks when people are using video footage that are grabbed from external sources, for example, to try and fake systems or try and trick systems that they are actually live and present.

But we are able to detect these digital footprints and be able to detect using multiple sources of multiple techniques on the mobile phone that we build software for that that person is live and present and is presenting the document that they say they are in order to verify themselves.

Oscar: Thank you, for explaining better how it worked for users. So, it’s simple for users. It’s not more complicated.

Russ: Simple and seamless and quick as well. It’s not more complicated. It’s less complicated, in fact, right? So, when you presented with it – there has to be a trust of course in the environment that you’re doing, and then providing your face to do that.

But ultimately, it’s safer and quicker, and ultimately more secure than any sort of biometric that they might have used previously.

Oscar: Yeah, it’s true. You mentioned also faster sometimes I think, being in front of these systems and yeah you are, waiting a little bit in front of the camera, right until it processes.

Russ: Yeah, look, it depends on the speed and the connectivity in the region you’re in, and it might be the phone and your mobile network, for example. But we account for all of that in the software that we design in helping people to process that. So, we shoot like a live stream video, and we take the best shots out of about 100, 120 frames that we shoot out of that video. It’s a very quick two or three second capture, and we’re able to compare the best quality face to the document that’s presented in this process.

Now, we can account for age, facial degradation, loss of hair, glasses, et cetera because we are looking at the underlying structure of someone’s face when doing that. So, we’re 3D mapping essentially that person’s face, and are able to then tell against the original document that’s presented if that person is the same person.

And that you can’t do, it’s very hard to do with humans, for example. And that’s why technology can do a lot of this lifting very, very quickly. We can do it in seconds and verify the person against very old very age documents or changes to their facial structures. And so, we’re very excited about how these techniques can verify people to the grade that I mentioned before.

Oscar: Yeah, indeed, it sounds like there’s a lot of innovation hearing what you’re talking, you are describing. So, what we say looking at the future, so what is the future of Generative AI in identity verification?

Russ: We were excited about Gen AI’s ability to create these huge datasets of synthetic personas, because it’s going to help prevent fraudsters trying to use this synthetically created people and documents that they create to trick and penetrate low grade systems.

And the more people we can support, the more businesses we can get our technology into, the more we can stop this the synthetic IDs and penetration attacks that are happening. And we’ve seen the velocity of these increase as we see better and better tools and faster processing time to be able to do this.

So, the ability to cover the identities of the world’s population through technology and creating inclusivity for all ethnicities, all genders, means that people can be granted access regardless of where they live, what device they’re using, what colour they are, what gender they are.

So, we’re very excited about how Gen AI can train and help people. And again, this is all ethically sourced data, right? So, we didn’t go and grab it elsewhere. It’s very hard to get in front of tens of millions of faces of variations of age and, again, colour, ethnicity, gender, et cetera.

So, Gen AI really helps us to do that, I think detection tools. So, developing and using advanced technology like Gen AI to detect this deepfake content can be crucial to mitigate the potential harmful effects that might come from that. Authentication mechanisms. So, implementing strong authentication, like facial can help, again, verify the identity of individuals and reduce that risk of impersonation.

So, trust has to be ensured that it’s in place there. And of course, eliminating frauds and scams, so businesses and consumers fall victim to deepfake base scams and others every day. For instance, a scammer can impersonate a company executive, as I said, and deceive employees into revealing sensitive information or maybe making financial transactions.

So, we want to stop fraud at the door. We want to stop fraud internally, externally. And we want to help protect businesses and their customers, whether their business or consumers from the rising threat of what’s coming on synthetic identities and the scale of using Generative AI at the fraudster level.

Oscar: Sounds good. Final question, for all business leaders that are listening to us right now, what is the one actionable idea that they should write on their agendas today?

Russ: Yeah, look, there are a lot to choose from. I think the one action from my opinion, maybe is – you’ve got to think like we’re living in a mobile-first world, right? And Gen AI solutions, as we’ve talked about are surging.

So, the action I would take is take the time to speak to your fellow executives and to the teams and to the people inside your business and understand how identity is currently viewed in your approach to your people, your processes, your security, your products and your customers. Where I sit and where we sit, is we are seeing the velocity increase of identity usage across the world.

Governments are enforcing and implementing more and more identity standards in order to control obviously, governmental services. And so, it’s important that people think about identity for their own businesses. It’s going to become critical to protect them and their customers. They need to think about everything from employee onboarding, how well you know your employee and your customers.

And of course, ultimately, what we’re all achieving, or trying to achieve in digital is improving user experiences, anything from onboarding to account management, to customer services interaction. So, it’s everything that your customer, your employee might touch within your business, potentially has something to do with identity. And the better you know the people in your business and your customers, I think, the better positioned you’re going to be to be able to not only stop these threats but take advantage of beating your competition by staying ahead and knowing your customer much better.

Oscar: All right, thank you very much, Russ, for all this very interesting conversation about how Generative AI is going to help us for the identity verification now and in the future.

So, for the ones listening to us who would like to know more about you or get in touch with you, what are the best ways for that?

Russ: Yes, thank you again, for the time letting me talk about something we, you know, and I’m very passionate about and obviously we’re very passionate about fraud and particularly technology.

If they want to get a hold of me, I’m on LinkedIn, you know, Russ Cohn, C-O-H-N. IDVerse.com has a repository of amazing content and information and thought leadership around a lot of these areas, so please take your time to look across the site. And if you want to get in touch with us, there’s lots of ways to do that on the site.

So, look forward to seeing and speaking with anybody who’s interested in learning more about IDVerse and about – chatting about fraud and identity.

Oscar: Perfect. Again, thank you very much, Russ. And all the best.

Russ: Thank you, Oscar. Appreciate the time.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Riley Hughes, Cofounder and CEO at Trinsic.This week, Oscar is joined by Riley Hughes, Cofounder and CEO at Trinsic and host of the Future of Identity podcast. They delve into Verifiable Credentials, including what verifiable credentials are, some examples and success stories of how these are being used and implemented, the connections between verifiable credentials and wallets and whether verifiable credentials will become interoperable.

[Transcript below]

“It seems like the future of identity will be much better than it is today.”

Riley Hughes is CEO and Co-founder of Trinsic, a reusable identity infrastructure provider. As a leader in the decentralized identity community, Riley has pioneered efforts on making emerging, privacy-preserving technologies such as identity wallets and verifiable credentials adoptable to the masses. He began his career in the decentralized identity space as the second employee hired at the Sovrin Foundation where he established and led several teams.

Connect with Riley on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 97.

Podcast transcriptOscar Santolalla: This week we are discussing verifiable credentials. I am joined by Riley Hughes, the host of The Future of Identity Podcast, to explore some of the most recent success stories of verifiable credentials and how we can work to improve adoption moving forward. Stay tuned to find out more.

Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Hello, and thank you for joining a new episode over Let’s Talk About Digital Identity. One term that has been in our radar for the last – I would say four or five years has been verifiable credentials. Which I will say personally, I’m feeling that is becoming in the last one, two years pretty crystallised. And we have not talked too much about this lately, so I have a very special guest who has a lot of insight – what’s going on worldwide about verifiable credentials.

Our guest today is Riley Hughes. He is the CEO and Co-founder of Trinsic, a reusable identity infrastructure provider. As a leader in the decentralised identity community, Riley has pioneered efforts on making emerging privacy preserving technologies – such as identity wallets and verifiable credentials – adoptable to the masses. He began his career in the decentralised identity space as the second employee hired at the Sovrin Foundation, where he established and led several teams. Hello, Riley.

Riley Hughes: Hi, Oscar. Great to be here.

Oscar: It’s great to have this conversation with you. So very welcome. And let’s talk about digital identity. And as usual, I want to hear more about our guests. So, if you can tell us about yourself, and especially your journey to this world of identity.

Riley: Happy to do so. I am very fortunate to have totally fallen into this amazing industry. And it happened because while I was at college, I was seeing all those smart people around me going and getting jobs at elite places, you know, investment banks and management consulting firms, and so forth. And I thought that I wanted to kind of differentiate my resume enough that I could, maybe I could get an interview as well at one of these places. So, I thought, “What is the most, kind of, off the wall internship that I could get that would differentiate me from all of my peers?”

And I ended up getting a job at the Sovrin Foundation, as you mentioned. Sovrin at that time was very early. I was, as mentioned, the second employee hired, and it was kind of a blockchain meets identity meets nonprofit, you know, meets early employee kind of a role. And so, it, sort of, fit my criteria for differentiating my resume. But it was also just really, really exciting to be part of an early organisation. It grew up to about 25 employees in short order. And I was able to participate in some of that growth. And that was a lot of fun.

And what I realised is that there are a lot of problems to solve in this world of digital identity. I remember just thinking, “Man, it seems crazy that we are sending people to outer space, and we’re editing genes, and we’re doing all kinds of unbelievable things with science and technology. And yet, the best way to prove who I am on the internet is to take a photograph of my government-issued document and a selfie, or something. It just seems kind of backwards.” It seems like the future of identity will be much better than it is today.

And so, although I didn’t necessarily know whether Sovrin would be the ultimate manifestation of that better digital identity future, I did know that something would happen here that would lead to that better future. And so, I thought I would stick around in this space. I decided not to go for those other kind of recruiting opportunities that I alluded to. And instead, I started Trinsic with a couple of -. And that’s kind of how we got to where we are today. That was a little over four years ago.

Oscar: Yeah, super interesting that one of the first jobs – when you start to differentiate yourself – it was Sovrin. How did they find you? How did you find them?

Riley: The Chair of the Board of Sovrin was Phil Windley. And he was a professor at the university that I was attending. So, they had a job posting out for university students. And they didn’t have any money yet so they couldn’t pay very much and so they needed a university student and that’s sort of where I came in.

Oscar: Right place, right time. Fantastic, those coincidences that sometimes happened.

So, you’ve been around, as you said, four years/five years in this space already. So, what would you say has been something that has surprised you the most, something special you would like to tell us?

Riley: Yeah, that’s a great question. I think that when I started in this space, and the way we were talking about verifiable credentials, was as if it was a digital representation of a physical document. Right? And we can get into more about what verifiable credentials are and what they aspire to be. But the thing that was most kind of interesting and surprising recently, is – at Trinsic we are an infrastructure provider for verifiable credentials. And so, when companies want to incorporate a verifiable credential-based solution into their offerings, we’re an infrastructure to enable them to do that.

And as we did a kind of – an inventory or a survey of the landscape, of all of our customers and the ones that were most successful. What we realised was that people were not using verifiable credentials as a replacement for a physical document, generally. Instead, what they were using it for, is – in the same way that a FinTech developer might use an open banking API, right?

Basically, open banking allows you to unlock your data from its original silo, which is your bank account, and reuse that financial data and make it interoperable across other third-party applications. And, you know, what our customers were using verifiable credentials to do is something similar, but for personal data. Unlocking that personal data from its original silos and making it useful and interoperable and reusable across multiple applications.

And so, it actually changed, Oscar, the kind of form factor of the product we needed to build, right? And we realised that the correct – you know, we needed to change some things about how we were approaching our product.

So that’s been what we’ve been in the thick of doing for the last few months. And it’s been a fun journey. Startups are always a little bit of a roller coaster. And this is a fun part of that roller coaster.

Oscar: OK, super interesting, Riley. So, let’s jump into the main topic. So, tell us please, what are verifiable credentials?

Riley: Yeah, I alluded to verifiable credentials often being talked about as a digital representation of a physical document. And generally, when you hear the term verifiable and credential – a credential is sort of an attestation, or a claim made about one party by another party. So, in healthcare, right, your credentials are something that you’ve obtained, from a trusted source, that you can use to prove to somebody else certain things about you, and what your qualifications are, et cetera. And verifiable credentials are a way to do that verifiably, cryptographically in a digital form.

Now, if we’re talking about – I think there’s two ways that people use the term ‘verifiable credentials’ today. One is with an uppercase, V and C, an uppercase Verifiable Credentials, that is the formal official W3C Verifiable Credential Data Model Standard. And that is a specific kind of verifiable credential that is sort of an interoperable, and probably the most well-adopted, and well talked about kind of verifiable credential.

And then you have the lowercase, vc, verifiable credential. And there are lots of different kinds of lowercase verifiable credentials. Lots of things that can fit this model of an attestation that is given to you by some trusted party, and used to get access to the things you need throughout your life. So, I guess it depends on which of those you’re talking about. But I hope that that’s a helpful kind of intro.

Oscar: All right, thank you for that. And the same term can mean different things from different perspectives. Let’s make even more concrete.

So, let’s hear from you some concrete examples. If you can tell us something that is already widely used, some that most of us might already know about. So, tell us a bit of some examples of verifiable credentials.

Riley: Yeah, I mean, again, if we’re to zoom out a little bit and talk about verifiable credentials in the broadest sense. Even something like a credit card could be considered a verifiable credential. It is something that was given to you by a trusted source, likely a bank, and you can use it with third party merchants in a way that they can authenticate that card and charge your account based on your actions with that card. And so it is, you know, in the broadest sense, even something like a credit card or a government-issued ID could be considered a form of a verifiable credential.

But if we’re talking about specifically, the new W3C Verifiable Credential Standard, I think, one example that is helpful to conceptualise what this looks like, is the vaccine, or the sort of travel pass type products – that many of us used throughout the pandemic. I think this is where – this is the first use case that we found that Trinsic received broad adoption. And, you know, these are products that allowed you to prove that you were vaccinated against COVID, or that you had obtained a recent COVID test, and that you are therefore eligible to travel. And you know that is a form of verifiable credential, Apple and Google even were accepting those credentials into their native operating system wallets as verifiable credentials as well. And so that is maybe an example that a lot of people have used in the recent years.

Oscar: And those were already based on the W3C standards.

Riley: Yeah, technically, I think the smart health cards was what they were based on, and smart health cards were based on the W3C standard, so yeah.

Oscar: OK. Yes, definitely that has been a case that millions of people have used. Those helped us during the pandemic without knowing the term of ‘verifiable credential’. So that definitely has been widely used in different regions, different implementations. But yeah, that’s correct.

OK, if you tell us also some other examples, how has been, yeah, across different sectors, let’s say verifiable credentials are being implemented and as well, interesting stories.

Riley: Yeah. So, I think when you look at Trinsic, we are, again, an infrastructure provider. And so, we see companies all across the spectrum using Trinsic to accomplish their verifiable credential use cases. Everybody from a car manufacturer to a B2B supplier, an invoice management solution to a consumer product application for events and concerts, to education and healthcare use cases, I think.

A use case that I really like, is the medical staff passport. It is something that’s easy to conceptualise, really, it’s an identity wallet that a provider, a physician or a nurse could use to prove that they have the correct credentials and qualifications to do that job.

And so, if you’re a physician that needs to go to a new hospital, to substitute for some staffing shortage or something. The way this works today is there’s a big, long credentialing process where the new hospital needs to spend a lot of time checking lots of different things to make sure that you are eligible to do your job. And still, there’s fraud that gets through. With a digital staff passport, a doctor could simply prove who they are much faster, prove their credentials much faster, and get to work serving patients much sooner. So that’s a use case that I think is pretty helpful and has been succeeding, I think there’s four or five projects that I’m aware of around the world that are that are doing that, including some that are being built on Trinsic.

But I think regardless of where you look across all of those different industries that I mentioned, you see a couple of common patterns. And one of those common patterns is – you often need to anchor that credential in something, some foundational verifiable credential. So, what we’re seeing is, you know, if you’re a doctor, and you want to get your credentials in a digital verifiable credential form. The first thing that you’ll do is not actually go get your doctor credentials. But instead, the first thing that you do is verify your identity, scan a government document and authenticate yourself against some authoritative, again, government type document. And then when you obtain your doctor credentials, you can then make sure that those match. And then when you prove who you are in subsequent interactions, it’s much higher trust. Because you can cross reference the two credentials, and that brings a high degree of trust.

And so, what we see across a lot of these use cases are people doing, sort of, an identity verification step. In addition, and that becomes the foundational verifiable credential, or reusable identity (as we call it) that anchors some of these verifiable credentials. And that step is something that we at Trinsic help facilitate as well.

Oscar: OK, so the very first identity verification. So, when you mentioned that for this healthcare professionals, credential, you mentioned, there are a few worldwide. So, will these initiatives, I don’t know how much if they are in production, or is still in development? I don’t know, but if you know enough about the difference of these projects, do you think they will become interoperable or they are following different paths? What’s your view?

Riley: Yeah, I think that, yeah, I think that they will become interoperable. It’s hard for me to say a blanket statement that every single one will definitely be. But yeah, but I think that many of these projects are based on the W3C Verifiable Credential Data Model. And if they’re not based on that data model, they’re based on something else that is very similar. And I think the important thing to remember as it relates to interoperability is there’s a little bit of a conflict, actually, between two very important things.

When you’re launching a product, you want the ability to move fast, to iterate on the form factor, and change things to the extent that they’re not working, and bring the best technologies to bear, to build the best product that you can for the customer. And at the same time, you also want interoperability and compatibility across applications. And these things come into conflict because in order to be interoperable or compatible with other applications, you sort of need to slow down and agree upon a set of standards. But to be sort of innovative and moving fast, you kind of need to speed up and be willing to throw away your old solution and replace it with something better. And so, you get is this tension between innovation and interoperability.

So many of the solutions that you see out in the market today are not interoperable simply because they’re focusing more on the innovation side of the equation. And yes, there are proof points of kind of interoperability testing and interoperability suites that people can come into compliance to. But oftentimes, that’s kind of a steppingstone and will come into compliance with that. And then you’ll see another divergence of different attempts, and then they’ll sort of converge back to another point of interoperability at some point in the future. And so, it’s never quite as cut and dry as just interoperable or not.

And so, the important thing, before you build a bridge between your island and someone else’s island, you need to make sure there’s stuff on the islands for people to do, right? You need to make sure that people actually get to drive their car across the bridge. And so, in my opinion, the most important thing to do first, is get a product out there and get people using it and get happy customers where you’re solving their problem. And once you’ve done that, you can incorporate interoperability to make your product even better for those customers and solve even more problems. But I think trying to solve interoperability before you have a product in market is a little bit of putting the cart before the horse in some ways.

Oscar: Yeah, definitely. Definitely a good observation. And I agree that, yeah, you need adoption, you need adoption, you need to solve problems. To see that yeah, this new technology, this new product is really solving, solving problems for a big enough mass of users. And from that perspective also, my impression is that most of the companies who are building these products are not the big ones, right? Not the big companies, that’s my impression. So, it’s like, startup entrepreneurs, mostly. So how is the – are they doing profit in this space of verifiable credentials? What is, what you have seen?

Riley: Yeah, I don’t think I can say that there’s a, you know, hundreds of really successful, kind of, high profit generating companies out there. But there’s definitely companies earning revenue. To the extent that their revenues exceed their costs, I don’t know. But from a revenue standpoint, I think, you know, the key to making money with verifiable credentials is not the verifiable credentials. The key to making money with verifiable credentials is to – solving a problem with a customer. And to the extent that verifiable credentials can help you do that better and more effectively, that’s the extent that you will profit with verifiable credentials, right? So, you know, what we’ve seen is really not a whole cloth reinventing of the fundamental economics of the internet, or anything like that.

I’ve seen a few ways that people are making money. The first way is they build a consumer product that makes a person’s life better, and they charge the consumer for that product. Right? Password managers cost a few bucks a month. CLEAR is an identity product that you might see in airports, especially in the United States, you know, where you can skip the line at the security by enrolling in this identity company called CLEAR. These are examples of consumer products that consumers pay for because it makes their lives a little bit easier.

And I’ve seen verifiable credential type products that do the same thing. I’ve also seen products that solve a problem for our business, and they take, maybe it’s a subscription revenue, maybe it’s a usage-based fee for that. And they follow the software as a service playbook that is sort of tried and true. And, you know, this is – I mentioned the doctor, kind of the staff passport solutions a minute ago.

And I’ve seen some of these types of solutions that have done really well by leaning into a vertical, a vertical software approach. And using the kind of verification of individuals and employees of a given hospital or something like that, as a benefit, a value-add to their existing software as a service product. And so that just sort of strengthens their revenue proposition there.

And then the third way that I’ve seen are companies that are already doing some kind of an attestation, but in a non-verifiable credential way. So, for example, this might be an identity verification company, a background check company, a student ID verification company, and the list goes on.

And I’ve seen, you know, these kinds of companies incorporate reusable identity or incorporate verifiable credentials into their product. Or in other words, issue their attestation as a verifiable credential, instead of just simply, you know, an API response, and continue charging the same business model that they always have, and actually make more money than they were making previously. Because now that it’s a reusable credential, people can use it more places than they otherwise would have. Or it becomes their go-to resource for authenticating themselves, which then leads to even more revenue for the attestation provider. So, these are a few ways I’ve seen people make money with verifiable credentials, and then our fundamental kind of transformations of the business models that may have come before.

Oscar: Yeah, but it’s very interesting to see that there is value generation on top of solving problems and solving people’s problem. Excellent. So, one, relatively new term that is relatively new is wallets. And that is a term that I feel that is already reaching the masses, so people hear about that more commonly at this point, 2023, that we are having these conversations. So, what is the relationship between – or the connection between verifiable credentials and wallets?

Riley: Yeah, it’s pretty simple. I think the easy answer is wallets are where your verifiable credentials are stored. So, you get – just like in real life, you obtain a driving license. Where do you put it? Well, generally speaking, you put it in a wallet. And in a verifiable credential world, that holds true. I think this breaks down just a little bit if you think about wallet in the way that most people use the term. Most people associate a wallet with payment of some kind.

So today, your verifiable credentials are unlikely to fit inside of your Apple wallet. They’re unlikely to fit inside of your crypto wallet. They’re unlikely to fit inside of some other things, which are called wallets today. But I think that’s just a function of the maturity of the technology. I think, you know, we’ll get there.

For now, the term that I use are ID wallets, right? They’re sort of wallets that are built for verifiable credentials. And today, they sit alongside other kinds of wallets. So, in the Web3 space, we have some customers in that world. And for the users of their products, the ID wallet is a separate container or a separate data store or separate wallet that sits alongside or next to a crypto wallet for those Web3 applications. And, you know, in a Web2 world, again, a user ends up getting a wallet, oftentimes, they don’t even know that it is a wallet, they don’t even know that we refer to it as a wallet. To them, it’s just storage of their verifiable credential, or of their staff passport or something. But, yeah, hopefully that helps.

Oscar: But the ID wallet that you mentioned, it’s also from a normal user perspective, you just want one more app in the mobile, something like that?

Riley: Yeah, it could be an app. It also could not be an app. I think oftentimes if you are requiring your user to redirect out to an app store, download an app, authenticate to the app and get on boarded through the onboarding screens, and then obtain a verifiable credential. Also, that they can verify themselves and get the thing they actually want, that user experience becomes pretty tricky.

So, while we have seen some apps, you know, mobile apps, you know, succeeding and that is a model that is definitely a viable option. It definitely should not be the only option. And I think we’ve even seen web-based wallets or cloud-based wallets really taking off in much, much greater numbers than a lot of the mobile app wallets that we have, that we’ve seen. And I think it’s just a function of the friction required for a user to go through that journey is just so much less.

So yeah, it could be an app on your phone, it could be embedded into an existing app you already use. Or it could be a web resource that you, you know, authenticate to and get access to your credentials that way.

Oscar: Looking at the future from where we are now, what do you say is needed in order to see a broader adoption of verifiable credentials?

Riley: Yeah, I think we need more products, and more focus on product. So, you may have kind of heard from some of my previous answers that I, you know, I tend to think a lot about adoption. I think a lot about product. And I think a lot about business models. And that’s obviously because of my background. You know, I’m not an engineer by training.

But I do think that a lot of times, people get a little bit lost into the weeds with the technology. There’s a lot of cases where, you know, we’re talking about theoreticals in the technology, before anybody is actually using the product and we’re sort of holding up these, you know, certain technology principles as gold standards or best practices. When in reality, many verifiable credential approaches do not have product market fit yet. And so, we could build the most amazing, elegant, utopian technological solution. But if nobody uses that solution, then what’s the point?

So, I think really, the thing we need to focus on so much more is adoption and product execution over anything else. The technology is there, it’s good enough, it’s plenty good enough. It’s been good enough for – I mean, four years ago, literally, we launched the first version of our product, which allowed any developer to issue a credential within five minutes on Sovrin. And then a few weeks later, we expanded it to where there was a dashboard where even a non-technical person could issue credentials within five minutes.

So, the technology has been really accessible for a long time now. And when we look at our customer base, and we look at the success rates, and then we try to correlate those success rates with something and see what predicts success in this market. Every single time it comes down to product execution, and just being focused on solving a real problem for people. And so really what we need to get more verifiable credential adoption, is we just need – more of that, more problems being solved for businesses and people who are willing to pay for it. Right?

Oscar: Yeah, I agree. All right, thank you for the explanation of what’s going on verifiable credentials. And I agree a lot of your views on the focus on solving problems. So, leaving us with a final question, for all business leaders listening to us now, what is the one actionable idea that they should write on their agendas today?

Riley: Well, I am going to piggyback off my last answer for this one, Oscar. I’m going to say, if you are a company that has an identity product, or some kind of attestation service for people, or something like that. You should write on your agenda to explore how verifiable credentials could augment your business, because it’s likely that there’s some startup out there that is sort of doing something using verifiable credentials in your space or an adjacent space. And, you know, and they’re learning fast about what’s working and what doesn’t, and what this new world will look like. And so, as the world moves to fully digital and moves to reusable identity, the ones that sort of obtain those insights fastest and move first are going to get a lot of the benefits. And so, that’s the first thing.

If you are not in that category of a company that would sort of incorporate verifiable credentials, then the action item that I would give to you is to be a user of one of these products. And if you can’t find a product that uses verifiable credentials, if you can’t find an ID wallet that solves a problem for you, that’s maybe a little bit of an indicative of where we are as a space. But if there is something that you can use and try out and actually use it in the real world to solve some problem for you, I encourage you to do it, give it a try and give feedback to the developer of that product and let them know your experience. Because these are the kinds of things that will drive adoption of better identity systems in the future than what we have today.

Oscar: Yeah, definitely. Oh, thanks a lot for this very interesting interview, Riley. Please let us know how people can follow the conversation with you.

Riley: Yeah, I – so the first thing I’ll say is that we do a podcast as well. This has been a blast, Oscar. This is a great podcast. I love it. I think if you’re interested in reusable identity, specifically, and diving deeper into some of the stories of companies that have launched reusable identity products, or verifiable credential-based products out into the wild, I have a podcast that we do, called The Future of Identity podcast. And so that’s what I would encourage you to check out.

If you’re interested in following me or getting in touch, you can email me at riley@trinsic.id. Find me on Twitter @rileyphughes. I’m also accessible on LinkedIn. If you search my name, I’m sure you’ll find us. And I’m always open to feedback and love the conversation so please reach out if you think there’s a way we could work together.

Oscar: Yeah, thank you and indeed I’ve been listening to your podcasts, The Future of Identity, so it’s highly, highly recommended. So, if you want to learn more in identity especially the topics that Riley has been bringing us today. So again, thanks a lot Riley for joining us. And all the best.

Riley: Thanks, as well, Oscar. You as well.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let's talk about digital identity with Drummond Reed, Director of Trust Services at Gen and Andy Tobin, Commercial Director, Europe at Gen. In this series opener of Season 5, Drummond Reed and Andy Tobin join Oscar to explore vLEI’s and Self Sovereign Identity (SSI). Including building an understanding of what LEI’s and vLEI’s are, and how SSI principles are used within vLEI’s, the benefits of vLEI’s, which sectors and industries will benefit the most and some use cases of where the vLEI has been applied.

[Transcript below] “If LEIs were digitised in a way that could be instantly verifiable, it could transform company onboarding.” Drummond has spent a quarter-century in Internet identity, security, privacy, and trust infrastructure. He is Director, Trust Services at Gen, previous Avast after their acquisition of Evernym, where he was Chief Trust Officer. He is co-author of the book, ‘Self-Sovereign Identity’ (Manning Publications, 2021) and co-editor of the W3C Decentralized Identifiers (DID) 1.0 specification. At the Trust Over IP Foundation, Drummond is a member of the Steering Committee and co-chair of the Governance Stack Working Group and the Concepts and Terminology Working Group. At the Sovrin Foundation, he served as co-chair of the Sovrin Governance Framework Working Group for five years.

From 2005-2015 he was co-chair of the OASIS XDI Technical Committee, a semantic data interchange protocol that implements Privacy by Design. Drummond also served as Executive Director for two industry foundations: the Information Card Foundation and the Open Identity Exchange, and as a founding board member of the OpenID Foundation, ISTPA, XDI.org, and Identity Commons. In 2002 he received the Digital Identity Pioneer Award from Digital ID World, and in 2013 he was cited as an OASIS Distinguished Contributor.

Connect with Drummond on LinkedIn.

Andy Tobin leads European and eIDAS strategy for Gen's Digital Trust Services business. He is one of the pioneers of self-sovereign identity and helped to establish Evernym as the world leader in this field. He is a well-known public speaker and writer on the topic of digital identity and has delivered some of the largest SSI projects to date.

His career has spanned the three rapidly converging sectors of identity, mobile and payments. He has written code to control cash machines, built the world’s first mCommerce server, run a £1.2bn mobile messaging network and been CTO for Europe’s first fully mobile bank. He is a passionate technology strategist who believes that the identity ecosystem and the personal information economy is poised for massive change, enabled by the capabilities being built right now by Avast.

Connect with Andy on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 96.

Podcast transcript Oscar Santolalla: Welcome back to Season 5 of the Let’s Talk about Digital Identity podcast. In this series opener I am joined by Drummond Reed and Andy Tobin, from Gen Digital, joining us to delve into vLEIs and Self-Sovereign Identity (SSI). Stay tuned to find out more.

Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar: Today, we are very happy to have two expert guests, Drummond and Andy. And today, we are going to discuss vLEIs and what is the connection with self-sovereign identity.

First of all, we have Drummond Reed. He is Director of Trust Services at Gen, previously Avast after their acquisition of Evernym, where he was the Chief Trust Officer. He is co-author of the book Self-Sovereign Identity, published by Manning Publication in 2021. And he’s co-editor of the W3C Decentralised Identifiers, DID 1.0 Specification. At the Trust Over IP Foundation, Drummond is a member of the steering committee and co-chair of the Governance Stack Working Group and the Conc...

View Details

Let's talk about digital identity with Elizabeth Garber and Mark Haine, co-editors of the Global Assured Identity Network paper. In episode 95, Elizabeth Garber and Mark Haine, who were editors on the Global Assured Identity Network (GAIN) paper, join Oscar to share the latest updates for GAIN, including recapping what GAIN is, the challenges that have been faced, alongside successful case studies and what developments we can expect to see for the future of GAIN.

[Transcript below] "It's all interconnected with standards development and has a really big impact on how identity systems will work, interoperable, in years to come." You’ll remember Elizabeth Garber, who was one of the lead editors of the GAIN paper - we interviewed her in episode 52 (back in October 2021).

Elizabeth has a long background in Customer Strategy and Product Management. She has also led the Open Digital Trust Initiative at the Institute of International Finance and co-chairs the OpenID Foundation's GAIN technical proof-of-concept, which strives to create globally interoperable networks for exchanging high-assurance identity information. Since we last interviewed her, she co-founded IDPartner, a venture-backed startup that puts people in control of their digital identities. It will be a key player in any Global Assured Identity Network (GAIN) as interoperable networks begin to flourish.

Elizabeth and Mark recently published a draft paper for the OpenID Foundation called “Human-Centric Design: a primer for government officials” which is all about how to design identity systems to sustain and promote human rights. It is open for public comment - and may feature on a future episode. You can find it on the OpenID Foundation website and blog, openid.net.

Connect with Elizabeth on LinkedIn.

Mark is an engineer and entrepreneur who has focussed his career on building solutions that enable business and mitigate risk in financial services.

Through Considrd.Consulting Ltd. Mark and his team are providing strategic security consultancy to a range of clients. He has also taken on a leadership role in the OpenID Foundation as Co-Chair of the eKYC & Identity Assurance Working Group and is a co-author of OpenID Connect for Identity Assurance specification.  Mark also is a board member of the Open Identity Exchange.

Connect with Mark on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 95.

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, everyone. You will remember Elizabeth Garber, who was one of the lead editors of the GAIN paper. We interviewed her in episode 52, late in 2021. Elizabeth has a long background in customer strategy and product management. She has also led the Open Digital Trust Initiative at the Institute of International Finance, and she co-chairs the OpenID Foundation's GAIN technical proof-of-concept.

Since we last interviewed her, she co-founded IDPartner, a venture backed Start-Up that puts people in control of their digital identities. This will be a key player in any global assure identity network, as interoperable networks are beginning to flourish.

We have a second guest. Our second guest today is Mark Haine. He is an engineer and entrepreneur who has focussed his career on building solutions that enable business and mitigate the risk in financial services through Considrd.Consulting Ltd. Mark and his team are providing strategic security consultancy to a range of clients. He has also taken on a leadership role on the OpenID Foundation as co-chair of the eKYC and Identity Assurance Working Group and is co-author of OpenID Connect for Identity Assurance Specification. Mark also is a board member of the Open Identity Exchange.

Elizabeth and Mark recently published a draft pape...

View Details

Let's talk about digital identity with Keith Uber, VP Customer Success at Ubisecure. In episode 94, Keith joins Oscar to delve into Single Sign-On (SSO) best practises and how organisations can implement SSO – including technical aspects, how it used in practise and the advantages of SSO.

[Transcript below] "The best type of single sign-on is where the user doesn't notice it." Keith is VP Customer Success at Ubisecure. As an Identity and Access Management product expert, he leads the Sales Engineering team and is involved in many stages in the planning and design of demanding customer implementation projects. Keith is active in various industry organisations and has a keen interest particularly in government mandated digital identity systems. He holds a bachelor’s degree in I.T. and a master’s degree in Economics, specialising in software business.

Check out Keith’s SSO video series.

Connect with Keith on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 94.

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining a new episode of Let’s Talk About Digital Identity. Single Sign-On is one thing that, today we take it for granted. So, it's even hard for us to remember when was the first time we have used it. Today, we'll go a bit deeper into that and in which direction Single Sign-On is going. And for that we have a special guest, who is Keith Uber, VP at Ubisecure. Hello, Keith.

Keith Uber: Hi, Oscar.

Oscar: Thank you for joining us for the second time. So, you have been – two years ago. Two years ago, you've been here before talking about mergers and acquisitions. So happy to have you back here.

Keith: It’s a pleasure. Thank you for the invite to come back.

Oscar: Yeah, nice to have you, Keith. And we'd like to hit a few things about yourself. So, you can tell us about your journey to the world of digital identity.

Keith: Yeah. So, my entry into the world of identity probably began around the year 2000 when I had just moved to Finland from Australia. I was working for telco provider, who was in the – around the dot-com boom era had been acquiring lots of small businesses. Lots of startups, they had their own projects and all of these have many different types of identity systems and lobbying systems. And my introduction to that process was – my job was to evaluate different solutions to their problem and ultimately, take part in a commercial pilot to implement a product to solve that problem.

Oscar: Excellent. And I already can imagine that a single sign-on had some role on that. Just guessing that yes, single sign-on is something that. I was really trying to remember when was the first time that I used it and it's quite difficult. Because it has been coming in different, in different flavours I would say.

Probably the first time I used was in one of my first jobs when, you know, you go to the office - people used to go to the office every day, and today is not, not for everyone at least. And then you sit down, and you login to your computer. You login to the domain and then suddenly, you can access some of the internal applications without logging in again. So that is one of the ways. And then later it came, what we see more often today is the web single sign-on, right? So, several applications.

So, in order to start with the basics, how you define single sign-on in a nutshell?

Keith: Yeah. Single Sign-On is maybe a more technical term that the industry understands. But for the end users, they don't really understand what the single sign-on means. But they do understand that they don't want to have to sign in again and again to different parts of the same website or different sections of the same company.

View Details

Let's talk about digital identity with Kalev Pihl, CEO of SK ID Solutions. In episode 93, Oscar is joined by Kalev Pihl, to answer ‘What are the cultural aspects of digital identity?’  They delve into the role of culture in shaping digital identity and how digital identity is being treated as a detached technology, without considering cultural differences. Alongside discussing the challenges in recognising these cultural aspects, as well as sharing some of the solutions at have successfully prioritised the human aspects of digital identity.

[Transcript below] "We have to be designing mindfully those digital identity solutions for a specific culture, and I think that this is a value in the world." Kalev has worked with digital identity over 25 years. Started with the topic in governmental side preparing Estonia for electronic identity on national identity card. Has since worked in financial sector and in Microsoft. Last 15 years he has been CEO of SK ID Solutions – trust service provider that serves digital identities in Estonia, Latvia and Lithuania.

Connect with Kalev on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 93.

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining a new episode over Let’s Talk About Digital Identity. What are the cultural aspects of digital identity? So that's definitely a good question and very relevant questions and this is one of the questions that our guest today is going to answer.

Our guest today is Kalev Pihl. He has worked with digital identity over 25 years. He started with a topic in governmental side, preparing Estonia for electronic identity, or national identity cards. Since then, Kalev has worked in the financial sector and in Microsoft. During the last 15 years, he has been the CEO of SK ID Solutions, a trust service provider that serves digital identities in Estonia, Latvia, and Lithuania. Hello, Kalev.

Kalev Pihl: Hi, Oscar.

Oscar: It's nice talking with you, Kalev.

Kalev: It's been a while.

Oscar: Yes, Kalev. So, let's talk about digital identity. And the first thing we want to hear from our guest is something about yourself and especially your journey to this world of digital identity.

Kalev: I think of the journey to digital identity for me went through this very physical, governmentally controlled national identity. So that was my starting point. And I guess that's where I'm a bit stuck with my mindset as well, sometimes. And this is my limit. But that's how it started.

So, it started from the idea that in the world of physical human beings. Governments tend to have this role in society to name, number and identify the residents, they treat as their residents of the country, we are speaking about.

And whilst we have probably different other nicknames in different other societies. And somehow, globally, these governmental-issued identities have become the norm of; How do we know each other across the world. How do we identify the people whom we don't know beforehand. So, I think from that angle, I've stuck with the idea that governments have the role of naming and identifying who we are.

Oscar: Yeah, indeed. I think it’s – I mean, in my view, probably in the constitution in most countries, I'm not a lawyer, but I'm sure it's written in some of the laws. So that's one of the functions of the government. And yeah, and that has been translated in our very, let's say, not very recent time. But talking, especially in the last maybe 20 years that we have such digital identifications, like Estonia is pioneering and in a few other countries as well. It's pretty digital, pretty well-established.

Kalev: Yeah. I think that the – for the beginning of any country or state in the physical world,...

View Details

Let's talk about digital identity with Joni Brennan, President of the Digital ID & Authentication Council of Canada (DIACC). In episode 92 Joni Brennan joins Oscar to discuss how the Digital ID & Authentication Council of Canada (DIACC) are working to close the digital identity public trust gap – including the key findings from the DIACC’s 2022 research and how this can inform future policies, the issues with poorly designed solutions and the importance of balancing accessibility and ease with privacy and security within these solutions. As well as discussing how education and awareness can help bridge the gaps and what can be done within governance and policy to support digital identities, transparency and data control.

[Transcript below] "So, I think this is a call to action for us to continue to work together to provide people with the option so that they can do what they need to do in a safe and secure way." Joni Brennan is President of the Digital ID & Authentication Council of Canada (DIACC). Building on 15+ years of experience in Identity Access Management innovation, adoption, and industry standards development. Joni helps the DIACC to fulfil its vision delivering the resources needed to establish a digital identity ecosystem that accelerates the digital economy, grows Canada's GDP and benefits all Canadians. Joni builds diplomatic and impactful relationships and formalises strategic partnerships. She has participated in influential committees from organisations including: SCC Data Governance Initiative, OECD ITAC, ISOC, IEEE, OASIS, ISO, and ITU-T.

Before joining DIACC Joni was Kantara Initiative's Executive Director driving programs for business, legal, and technology interoperability to connect entities and individuals in a more trustworthy environment. Joni lead Kantara Initiative as the United States premiere trust framework provider. Delivering value to multiple industry sectors. She helped to ensure that the Kantara Initiative program is aligned with multiple eGovernment strategies. From economic regions including: Canada, New Zealand, Sweden, and the United Kingdom.

Joni Brennan previously served as the first-ever IEEE-SA Technology Evangelist for Internet Identity and Trust. Focusing on issues of governance, policy, and technology development that touch digital Identity, personally identifiable information, and trust services.

When not connecting the digital identity world for the better Joni can be found skiing in beautiful British Columbia, Canada. She can also be found playing flute or synthesizers in future thinking musical collaborations.

Connect with Joni on LinkedIn. Find out more about DIACC at diacc.ca or follow it on Twitter @mydiacc or on LinkedIn.

Take a look at the Canadian Digital Identity Research 2022 Document, in English or French.

Joni first joined Let’s Talk About Digital Identity podcast in Season 1 Episode 6. Why not take a listen to the episode on Building Canada’s Digital Identity Future.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to @Ubisecure on YouTube to watch the video transcript for episode 92.

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining us on new episode of Let’s Talk About Digital Identity and I'm super happy to bring a former guest back, she is joining for the second time. One reason is that there has been released, super interesting results on her research. Especially in a vast country like Canada.

So, our guest today is Joni Brennan. She is the president of the Digital I.D. and Authentication Council of Canada, DIACC. Building on more than 15 years of experience in identity and access management, innovation adoption and industry standards development. Joni helps the DIACC to fulfil its vision by delivering the resources needed to establish a digital id...

View Details

Let’s talk about digital identity with Michelle Beyo, CEO and Founder of FINAVATOR.In episode 91, Oscar is joined by Michelle Beyo, CEO and Founder of FINAVATOR. They discuss how Opening Banking and Open Finance is facilitating the future of finance and the role digital identity has within this. Join Michelle and Oscar as they explore what open banking and open finance are, benefits and potential privacy issues. Alongside sharing success stories from around the world and what we can except to see in the future.

[Transcript below]

“Open finance layered in with a digital identity can truly help us plan better, execute, have better offerings, save money, and be able to plan better for our future.”

Michelle Beyo is the CEO & founder of FINAVATOR, an award-winning Payments and Future of Finance Consultancy. She is also a strategic advisor to FinTechs, a Money 20/20 Rise Up alumni, a Global Council Member of Women in Payments, the Membership Chair at Canadian Prepaid Providers Organization, a Payment Advisor at National Crowdfunding and FinTech Association of Canada, and a Board Member at Open Banking Initiative Canada.

Michelle started FINAVATOR as she is passionate about payments and financial inclusion. She has 20 years of extensive industry experience driving innovation across the retail and payments industry. Michelle Beyo was named the “Top 30 Best CEOs of 2021” by The Silicon Valley Review and FINAVATOR was awarded “Most Influential Leader in FinTech Consulting – Canada” in 2020.

Find out more about FINAVATOR at www.finavator.com or Michelle Beyo at www.michellebeyo.com.

Connect with Michelle and FINAVATOR on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining a new episode of Let’s Talk About Digital Identity. And today, we’ll hear some new ideas about open finance, open banking and definitely a bit more.

For that, we have our special guest today who is Michelle Beyo. She is the CEO and Founder of FINAVATOR, an award-winning payments and future of finance consultancy. She’s also a strategic adviser to FinTech’s, a Money 20/20 Rise Up alumni, a Global Council Member of Women in Payments, the Membership Chair at Canadian Prepaid Providers Organisation, a Payment Advisor at the National Crowdfunding and FinTech Association of Canada and a Board Member at Open Banking Initiative Canada.

Michelle started for FINAVATOR as she is passionate about payments and financial inclusion. She has 20 years of extensive industry experience, driving innovation across the retail and payments industry. Hello, Michelle.

Michelle Beyo: Hi, Oscar. How are you?

Oscar: Very good. I’m really happy to have you here in the show.

Michelle: Happy to be here as well.

Oscar: Excellent. So, Michelle, let’s talk about digital identity. I want to start hearing a bit about yourself and your journey to the world of identity.

Michelle: Yeah, I’m happy to share a little bit. I actually spent 20 years in the corporate space. Six years in telco and eight years in online shopping affiliate marketing. Ran Alaska, Lufthansa, Delta, United online shopping mall platforms. I really got to understand the relationship between customer and loyalty infrastructure.

And then I moved into the payment space. Working for the largest prepaid company globally, called InComm, out of their international office for 30 countries. And was running sales and marketing, launched their B2B division, got to see what was happening in innovation across these 30 other countries, including Singapore, Australia, UK. Helped launch WeChat in North America at 711 through the Gift Card rail, QR payment system. And truly realised – a little fearful that my kids were going to end up with Asian banking. Due to the advancements, and how far beyond where we are in North America, that Asia basically was from a banking infrastructure set in 2017.

And I took a leap into the startup world focused on blockchain digital identity at a startup as a Chief Client Officer in 2018. And after a year with them and helping with Bahama digital ID infrastructure and helping consent on blockchain. I actually won Money 20/20 Rise Up. Where they picked out of 500 women, 30 women to come into the Vegas largest payments conference in the world and have a separate accelerated track.

And as soon as I found out that I had won one of this coveted 30 spots, I quit my job at the startup and started FINAVATOR. Which is actually now four years ago in July. And starting this consultancy, did not have any consultancy experience. But did have all of my background, which I felt was touching the future of finance from telco infrastructure to affiliate marketing, online shopping. The move to digital prepaid payment infrastructures, how they were backing all new challenger bank infrastructure, BaaS infrastructure, and then digital ID.

So FINAVATOR truly became my ability to try and help banks, credit unions, FinTechs and corporations move to the future of finance. And really have enjoyed my journey out on my own.

Oscar: Yeah, definitely quite interesting, because you have been involved in several industries that are pretty different itself. So many are, yeah, oriented to interacting with the customer. So, understanding how the customer – what the customer needs, etc. And then just in the last year, you came to identity. So now you have this amazing experience and you’re doing your own consultancy.

As you mentioned, you have been working on a lot of payments and that is leading you to the future of finance. So, the topics we’d like to start addressing today are open banking and open finance. So, if you can give us what are these two terms in a nutshell, what would you say?

Michelle: Yeah. I think, at its simplest point – open banking, which started in the UK in 2017. Is a safe and secure way to share data in an ecosystem. So, thinking of back to my telco days, when I started. You would sign up to one provider for three years, and you couldn’t leave. If you left, there was a penalty, and your number was owned by that telco. So, if you went to a different telco because they had a better service, you’d basically lose your identity, which was your phone number. And have to send an email to all of your friends with your new number. And they would have to reprogram your phone number in their phones.

There was something called Open Telco. Or at least number portability, that was mandated in Canada and many other countries around 2015. And this allowed to empower the consumer to officially own their phone number. So, if I left one telco to go to another, I didn’t have to lose my identity, which I had built for, let’s say, 10 years. As this phone number represents myself. So, I was able to port it to a competitor to get better service.

So, to me, open banking is that same concept of having a safe and secure way to port my data. From one bank to another bank, from one bank to a FinTech, from a bank to a wealth advisor. So really just giving me the freedom that – the information that is mine, that defines me, can be utilised to help me get a better loan. Help me get a better rate, help me get the service that is customised to myself. Based on the data that happens to live with my current bank.

So open banking was a regulated movement that started in the UK to force the CMA 9, which is the nine biggest banks in the UK, to create an API that was standardised. To allow for safe and secure data sharing, that was all based on consumer consent. As well as create competition, by allowing FinTechs or third-party providers to hit a certain bar of the certification to be allowed in the system.

So, let’s say Revolut. If you were a Lloyds customer, and you wanted to go to Revolut. And you wanted Revolut to have these five pieces of data to offer you a different product that maybe had better pricing. You were able to do that through consent through the Revolut app. And that data was then able to safely port from Lloyds to Revolut.

And the biggest point, I think on all of this is – in open banking there is a right to delete your data. So that data can then be deleted and to me, this is creating less data in the world. And having more control over it as a consumer. As well as empowering new services, new offerings, new companies to help serve the underserved and help serve the current market in a better, more efficient way.

Oscar: Yes. And I like your analogy. You started talking analogy also in telecommunication in the mobile, consumer mobile networks. The mobile number portability, which is something I think at this point, I’m not sure it’s everywhere in the world. But I think it’s by large in many countries, it’s available and it’s something that today we take for granted. But it was very painful, not long ago, it was very painful as you have described.

So just the idea of having a similar easiness in translated to the to the banks sounds like a dream for the ones who still have not experienced. I have not experienced something like that yet. Yeah, so definitely it sounds like a great thing to keep it spreading. And you have summarised saying that this open banking is in a nutshell is securely sharing data of the consumers. So, one consumer can move from one bank to another, or even a FinTech as you mentioned so.

Michelle: Yeah, and I think the evolution of that is open finance. Which I would say is a hot topic in today’s market. The UK is moving to PSD 3, which is bringing them to open finance. Australia started with open data as a concept through a Consumer Data Right for all citizens across five industries. Which I think is the most concise vision across all countries. So, they started with open banking, moved to open finance, open telco, open energy, and then they’re going to land in open data. And it’s all centred around a Consumer Data Right across all data.

Very empowering vision coming out of Australia, that many countries are just starting with open finance. Turkey, Nigeria, Saudi Arabia, Brazil, just moved to open finance. So just to describe it – it really is, instead of just being banking, FinTech, third-party payments data or bank account data. It’s broadening the spectrum to the insurance, wealth, mortgages. Kind of more of a holistic view of anything that touches your finances. So, it’s really expanding to allow you to port your data from multiple different aspects of finance.

Oscar: OK. So, the key here in open finance is that you do similar – let’s say portability. We use it, we use the same word between different services. Not necessarily financial services, but as you said, that touch some financial data, correct?

Michelle: Yes. So if you want to use some data from your Lloyds account to help you get a faster, cheaper, better mortgage that’s more customised to you. Maybe that mortgage provider is not a bank, but they’re a licensed mortgage provider that has certified in the system. Then you’d be able to facilitate that data sharing, same example to a wealth provider or an insurance provider.

Oscar: Alright. And besides that, benefits of the portability that we can, I can even visualise on my mind. What are the other benefits that there are for both the consumers and for businesses?

Michelle: Yeah, I would say one of the biggest ones is – when you think of FinTechs trying to get certain aspects of data. And not having to get data they don’t need – so only getting the five pieces of data, with clear consent from the customer. And the customer not having to screen scrape this data out of their account without their knowledge.

So, a lot of screen scraping issues are when open banking first came to fruition in the UK. It’s largely because 1 million UK citizens were screen scraping. Which is a service that is being utilised where it looks like you’re logging into your bank. You’re putting in your passcode, and then it’s giving access to that FinTech to look at your overarching account and scrape the whole data. To only grab the five pieces they need to push it into the system.

So, what this does is [A] it’s unsecure. [B] the customer has no idea they’re breaching their bank agreement by using the service. And then the FinTech ends up with all this data that they don’t need, or want. Have to store it safely and securely, when they only needed the five pieces.

So, when you get to an open banking system, they request the five pieces, they get the five pieces in a safe, secure type of API. And then, therefore, they’re able to delete those five pieces of data, because the way that it was coded into the system, if so requested by the customer. So, it’s a data management system, all based on consent.

Oscar: Yeah, it sounds pretty good absolutely. Because imagine that all my data that is on my bank is passed to the – let’s say insurance. And then the insurance has the duty to delete whatever they don’t need as well, sounds terrible. Because you know, the less data that is transferred, the less data that is stored somewhere, the lower the risk of so many data breaches that are happening nowadays.

Michelle: Yeah, on the data breach point, I always like to bring up unfortunately Marriott because they had 7.1 million data breach occurrences at one time, and it was an internal issue. They were like layering in some accounting, or loyalty system and it was an internal data breach. And this was back I think in 2018. They didn’t compensate any of the users. But think about anytime you check into a hotel. At this point, they asked for your driver’s license or your passport, plus your credit card. The amount of data a hotel has on you is pretty concerning, considering they don’t have the data security standards that you would have at a bank.

So, if we can get to a world – getting to your digital identity questions. Where a QR check in doesn’t actually have them store any of my data, but just validate I am who I say I am. So that they don’t need to actually hold my actual passport image with all of my sensitive data. In a non-secure, I don’t want to say non-secure, but not highly secure infrastructure.

Oscar: Yeah, exactly. Another good example, obviously, the hotels. They will benefit, both the businesses and the consumers would benefit with open finance. And yes, I start – while you explain this idea, I was, OK, some of the data passes from one, let’s say from the bank to the insurance company. But just a minimum should be passing, so that – also thinking from the identity point of view. I’m imagining the federation, right? So, at this point, what is on your view the role of identity on this paradigm that you just described?

Michelle: Yeah, I think it’s quite paramount as a base layer to most systems. Because if you can authenticate you are who you say you are, that’s the most important part of any one transaction. Especially a transaction that has to do with your data or has to do with your finances. So, I think it’s quite crucial that we find a way that authenticates ourselves. Especially with AI, and all of this machine learning infrastructure, cybersecurity challenges.

How do we ensure that we are the only entity that is Michelle Beyo and that I can then surely authenticate myself? Before I do a data share from one bank to the other, or before I do a financial transaction. And we’re going to have to layer up from our six-digit code being sent to a phone text to authenticate yourself. As we move forward in the future of finance. So, I think digital identity is crucial. And has to be put into a system, in a way that ensures that there’s only one identity for any one person.

Oscar: Yeah, indeed. There has to be some level of strong authentication, that that is a must. And as you have mentioned a bit earlier also, always with a consent, inevitably, data sharing transactions.

Now, moving into what are the standards to also understand – without going into too much detail. You mentioned that this started in UK and in UK, there more implementations. This is really happening in real, but what are the main standards that are making this possible? Or are going to make this even more possible if we think of open finance?

Michelle: Yeah. So you know, what’s interesting is – as you look at the world at the moment, and you look at open banking, open finance. Not all countries have a digital identity infrastructure. So, what that does is makes the open banking infrastructure more complex, harder to authenticate. And I think even more than open banking – real-time rail infrastructure needs the authentication. Digital identity for any type of fraud reduction of authenticating you are who you say you are, and it’s going to an entity who is authenticated. So that we can remove the scams out of the system.

I’d say the best digital identity infrastructure is probably the Indian-based UPI. It was government issued; it was a mass amount of people. And it was done very early on, on a global scale. It’s not the exact model that probably should be utilised for other countries. But they have definitely – through their digital identity framework, have been able to even. There’s homeless people in India with QR codes and a bank account due to their digital identity infrastructure. And when you pass them in the streets or you pass a tiny shop selling something, they have QR-based payment infrastructure that is largely attached to their digital identity. Which creates a more financial inclusive infrastructure.

In Australia, they have a digital identity framework but it’s not as widespread to the same degree as India. The UK is still working on their digital identity infrastructure. So not every country has lined up, open banking, digital identity and real-time rail. But these are three very crucial aspects to the future of finance because the authentication from digital ID is a safety point. The real-time rail is the fast and secure movement of the funds. And the open banking is the safe, consent-driven data sharing aspect. So, once you have all three of them, you’re really setting yourself up to be facilitating the future of finance.

Oscar: You mentioned one term that maybe is not so familiar, at least for me, you mentioned real, real-time rail. What is that exactly?

Michelle: Yeah, they’re real-time rail is an instant payment system, sometimes called that. And the first one ever created was in Switzerland, actually, in 1989, 66 countries have faster payment systems. The UK launched quite a long time ago. But the US just launched their FedNow, that is what it’s called in the US. Which is their real-time instant payment rail, just this year. And Canada hasn’t launched theirs just yet. So, there’s many countries who have this payment infrastructure. When you look at the US last year, or Canada, still, it takes three days, three to five days for bank payments to clear and that’s just the older infrastructure of payment settlement.

Oscar: OK, OK. Perfect. Yes, indeed, you have emphasised that all these components needed in, of course, the authentic the national digital identification is a key point. You are correct, not many countries in the world have something, I will say, suitable enough for doing this open finance. I was – in terms also of authentication that reminded me that, for instance, the FinTechs has been for a while. And not long ago the authentication was just username and password, nothing else. So, of course, now, most of the FinTechs have something better than that. But yeah, I can see something that it takes time. All this component takes time to come together to make possible some of these use cases.

So, if you can tell us some of these success stories, now seeing from the perspective of use cases. Let’s say success stories from, if you can, from different part of the world also to illustrate it better.

Michelle: Yeah, so if we’re talking digital identity, I think Scandinavia has done probably one of the best jobs. I think Estonia was one of the first. The other really crucial part of digital identity is you can’t have CBDC, or digital currency in a very safe and secure way without a digital identity framework. So, I think there’s some great examples down that front.

When we’re talking open finance, open banking, the countries I’m most impressed by, obviously, is Australia. They are a country that has five major banks. They are kind of an oligopoly in the sense that those five banks hold quite a bit of the customer base. But they took an initiative past open banking, past open finance, to embed a consumer data rights to every citizen across five different industries with a roadmap to start with open banking. Moved to open finance, open telco, open energy, land with open data, which is really future proofing their country, for the future of the ecosystem. A digital ecosystem, which every business is now turning into a digital business.

So, they’re going to have a really great base layer of understanding that the customer owns the data, the customer is able to port the data, and the customer is able to delete the data. So, by creating a data right infrastructure, and then porting it across multiple industries. I think they’re going to have incredible innovation and eyes are definitely on them as they’re enabling this ecosystem. That really is kind of the future of any one country’s vision of how do you enable digitisation of an economy.

The other country that I’m pretty impressed by is Brazil. In the sense that in the middle of the pandemic, they made their first move to open banking. They made a 12-month mandate that they were going to hit an open banking live ecosystem within 12 months. And open access to their Central Bank of Brazil. And therefore, by opening the access to registered TTPs, which are Third-Party Providers. Companies, like Pix, were able to create a FinTech that reduced the cost of sending money and took the underbanked, underserved in Brazil, and gave them a digital bank with faster, more affordable payments. And I don’t have the exact number. But I believe they’re past 7 million customers and doing billions of transactions on a daily basis. And I believe they reduced the cost something like by 40%, by being able to have direct access to the central bank and fall directly in line with the open banking system.

And after 12 months of being enabled to an open banking system, they immediately started working on an open finance system, and are launching that within 12 months. So, I think the alignment, the passion, and the execution out of the Brazilian market is pretty impressive. And just the pure enablement of new FinTechs that are more affordable services. And finding ways to serve the underbanked, underserved, they’ve done a phenomenal job.

Oscar: Yeah, it sounds like that – it sounds definitely amazing. Among all these, well, existing use cases and what comes in the future for open banking and open finance, what are some potential privacy issues that you could tell us?

Michelle: Yeah, I think every system has to be truly based in a liability model. This liability model has to be extremely clear to everybody within the system. There has to be protection on that liability model. And I think it’s just ensuring that the certification system that allows for third parties to come into the system is robust, is reviewed, that these parties that have been certified inclusive of banks are always looked at to ensure that they’re continued to be certified to have access to the system.

But I do foresee in the future that customers are going to choose to have some type of insurance on their data. That they so choose, just like you have insurance on your travel, or insurance on your health, like actual data privacy insurance.

Because – think of the Marriott issue, or gosh, there’s data breaches every day of the week, and none of the data breaches have to do with open banking, open finance, they’re internal data breaches or external data breaches, or hacks. That there’s no real repercussion to the customer, like, or to the actual party who has had this data breach. There might be a fine, but there’s no settlement to the actual end user whose data has been potentially put on the dark web or given to different parties.

There’s got to the point where, if we have enough of a safe and secure data sharing infrastructure, we should be able to insure our data and be safe and secure. And if it’s breached, have some type of offset. But we have to get to a much safer secure infrastructure of how data is shared in the first place.

So, I just truly see that open banking, open finance is creating the pipes for the water to go through and be able to turn them on and turn them off. And we just don’t have those pipes today in every country. And I think it’s just super important for the next layer of the future of finance.

Oscar: Yeah, indeed. Now, if we look at the future, what kind of use cases or what open finance can do in the future? Something that we are not seeing today.

Michelle: Yeah. So, in some countries, they started to enable dashboards, like holistic dashboards of your financial health. So, in these dashboards due to open banking, you would be able to see what your mortgage is. And then it would be able to AI predict what other offerings you should potentially layer in. To add to this product, or tell you that your current mortgage is not serving you. And that there’s three or four other offerings that would be a better mortgage based on your current finances, or the market. And then they’d be able to offer you three different companies that you might want to look into.

So, what this service can then do is you can actually put in your loans – this dashboard would be personalised, just for you to see kind of your financial health. It would help people have an ability to plan better, understand their finances a little bit better. From that perspective, I think it’s going to also create a whole bunch of things we haven’t even thought of, new services, new opportunities, and new ways to ensure you’re saving for your retirement.

Just kind of like round up did in the sense of, you know, if you’re paying for coffee, and it’s $1.50, rounding it up, or if it’s $1.40, rounding it up to $1.50 and then putting that in your pension plan or putting that into a robo-advisor. So that you’re earning money by saving without knowing it, or without feeling it, kind of perspective. So, I think just like the Internet has changed so many ways of what we are doing, and made our lives easier, in many ways. I do think that open finance, layered in with a digital identity can truly help us plan better, execute, have better offerings, save money, and really just be able to plan better for our future.

Oscar: Yeah, sounds definitely a lot to expect for the future what open finance will bring us. So, Michelle, last question for you, for all business leaders that are listening to us now, what is the one actionable idea that they should write on their agendas today?

Michelle: Yeah, I think what they should write is that innovation is driven by ideas. And that there’s an opportunity, especially now that the world has gone digital, to listen in to panels, topics that interests you, but you don’t have all the details on, similar to this podcast.

There’s panels happening in Australia on open finance, or Brazil, that you could listen into. You don’t actually have to travel to these conferences. But you can truly grasp the innovation that’s happening in other countries. And then think about how you can create something for your citizens, for your company. To pivot and start moving towards the future of finance, by learning from other countries who are already there.

Oscar: Yeah, definitely, I couldn’t agree more. And that’s really one, learning more about these interesting topics that are going to impact us mostly positively in today, in the future is also one reason why we invited you. So, thank you. Thanks a lot for being with us and this was really fascinating conversation with you, Michelle. If people would like to follow the conversation with you, or know more about what you’re doing, what are the best ways for that?

Michelle: Yeah, definitely to follow me on LinkedIn. Simply find Michelle Beyo, follow FINAVATOR on LinkedIn and Michelle Beyo as well as reaching out to us on our website at finavator.com.

Oscar: OK, excellent. Many ways to do it. So again, Michelle, it was a pleasure talking with you, and all the best.

Michelle: Thank you so much, Oscar. It was a pleasure being here. Have a wonderful day.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Magnus Kardell, Product Owner for SignPort, Knowit.In episode 90, Oscar is joined by Magnus Kardell, Product Owner for SignPort at Knowit, to explore digital signatures in Sweden – including the main challenges that public and private organisations face when looking for a digital signature solution, how to solve these challenges and what regulations signatures solutions need to comply with in Sweden.

[Transcript below]

“It’s demand for high availability, and demand for high level automation. That means you need to be able to validate the document electronically to the person who has signed it.”

Magnus Kardell is the Product Owner for SignPort, an IP product developed by Knowit enabling high-security e-identification and e-signatures. He is a specialist in identification and signing services, with a focus on IAM, and SSO federations. Magnus started his career in this field in 2013 and has since gained extensive experience in the public sector, catering to clients with high-security standards and needs. With a strong background in the industry, Magnus is dedicated to delivering innovative and secure solutions to his clients through SignPort.

To continue the conversation or to find out more, visit SignPort – signature service, reach out to Magnus via email or connect with him on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining us. As the years have been passing, I have noticed actually that, digital signatures are becoming more and more common. At a time when we need to sign some agreements, electronically or Internet services. So, let’s take some time today and hear what is going on, what the trends are, in the European Union, but particularly, in Sweden, where today’s guest is coming from.

So, our guest today is Magnus Kardell. He is the product owner of SignPort, a product developed by Knowit, enabling high security, e-identification and e-signatures. He is a specialist in identification and signing services, with a focus on IAM and SSO Federations. Magnus started his career in this field in 2013 and has since then gained extensive experience in the public sector, catering to clients with high security standards and needs. With a strong background in the industry, Magnus is dedicated to delivering innovative and secure solutions to his clients through SignPort.

Hello, Magnus.

Magnus Kardell: Yes, hello. Hello, Oscar.

Oscar: Welcome. It’s great having you. We are going to talk about signatures. But let’s get started. Let’s talk about digital identity. First of all, we want to hear about our guest, so we want to hear about you. Tell us a bit about your journey to this world of identity.

Magnus: Thank you. Yeah, Magnus Kardell is my name, and I work at Knowit Secure Solutions, as Oscar mentioned, and I’m product owner for SignPort, which is an identification and signing service. I started roughly 10 years ago with IT security and at the time we were having, and working with, identity and access management. Providing single sign on and federations between different organisations, and soon after that, we were adding also signature services.

In Sweden, there is a technical framework provided by the Swedish agency, DIGG, the agency for digital government. We have always complied to that standard, and that’s where we built our services. It’s mainly targeting public sector, but it’s also good for private sector. And I think in 2016, we made the first signatures, doing it this way and according to this standard. So, we were first with that one. And I’ve been a project manager for establishing about 40 customers in Sweden, in different configurations, and they are mainly government agencies and large municipalities.

So that’s basically my journey and where I got my experience in this.

Oscar: Sounds great. So magnus, what would you say are the main challenges that organisations, we talk about public and private, these organisations’ face, when they ask you for a digital signature solution?

Magnus: When it comes to public sector, you have to consider many things, maybe more than for a private company. For example, to start with, you need to be able to connect to different eID issuers. So, you can’t only have one.

In Sweden, BankID is the most common, but you need to be able to connect to different, both for identification and also signing. And also, there is a request for dividing into what we call private eID issuers where we use your personal number, which is more private. But that can also be as an employee at an organisation. So, you have that kind of – maybe you don’t want to mix your private entity and your employee entity, so you have to consider that. And also, international, so you can also identify yourself and sign with an eID issuer that is from another country. So that’s one of the things.

The most common eID issuer is BankID, of course, but there is also Freja e-ID, Freja org ID, which is for employees more, and foreign e-ID, that is international. So those are examples, but there are more. So, you need to cope with that, and you need to be able to connect to those.

They are also high security when it comes to signatures. It’s level three, which basically means that you need a hardware secure module, where you do the actual signing. So that’s also a bit higher in security than the general need.

A signed document must be self-supporting over time. So, you can’t rely on our service later on, it has to be self-supporting. And the supplier of the signature service must be replaceable. That’s not good for us, but it’s good that we are, because well, all companies, they are not forever. So, it’s, we should be able to replace as a supplier. So that would be in our system cemeteries that our customers that they, that the document itself is self-sustaining. And you have different things, in some cases, the documents to be signed are really sensitive, or the content is delicate, so you need to be able to sign the document without the document itself leaving the customer’s IT environment. But some requirements also on the signature service.

There are also, in some cases, you need a pure e-service, like signing portal. But in some other cases, the customer probably has their own platform that we would like to connect to our, how to say – signing engine. So, we have to provide APIs for our customers’ e-services– sometimes you have a simple signing portal, and in other cases, you let the customers e-platforms connect to our signing service. So, these are things that they need.

And then, of course, going into public sector, there can be really high volumes, when citizens in the country are using the service. It’s demand for high availability, and there is also a demand for high level automation. That means that the signatures need to be – you need to be able to validate the document electronically to the person who has signed it. If you look into the electronic signature of the PDF and read, signed by the supplier of the service, that is a no go, because then you can’t electronically extract what person who has actually signed the document.

So, this also put some specific requirements, and this is about the journey to digitalisation, and we’re not there yet. We may be in the beginning, of course, so far, when we sign a document on, electronically, like a PDF, that’s good. But often, it’s human reading it, at the end, at the other end anyway. So, we have replaced the paper, which is good. It’s much smoother. That’s very good. But still, it isn’t, the flow isn’t really digitalised. And if looking at these challenges that our customers have, they need to be able to do this high level of automation, at least have it further on.

And then, of course, there are requests for sustainable operations. For example, excess heat in the operation centre should be fed back into the district heating network. So, this kind of, you don’t really think of them, but if looking at society, you need to think about those things to be sustainable. Those requirements I mentioned now, or the challenges there were, these organisations have. Of course, they’re mainly for government authorities or municipalities, but, I mean, it could apply also for private companies. It’s not bad, it’s really good things. So that’s about the challenges.

Oscar: Yeah, I can see quite many, different types. As you mentioned, some are purely security, some more like usability, what the user is going to face. What else? And the last one, you mentioned actually, the sustainability side. So yeah, different – and some are, yeah, legal. So yeah, different for different fronts, there are these type of requirements for signature services. And when it’s great that our solutions that, yeah, fix all these together and give a great product to, for us, for the users.

So, I would like to hear now, how are you solving some of these challenges? What are the main use cases? Just, if you can illustrate some of those use cases, hot use cases, let’s say?

Magnus: Signature service that we provide, SignPort is following the, I mentioned before, DIGG, the agency for digital government in Sweden they put up a framework for how to solve these issues. But there is also architecture or reference architecture for how to cope with these challenges. So, we follow that. And if looking at our service, it’s split up in four different components, mainly, four different components, and it’s a Signing Portal, Support Service, a Digital Signing Service, and Identification Service. So, these are the four different components.

And the Signing Portal is like a web page that is an e-service, a service provider. The only thing you can do is to just create a signing assignment. Just to, for example, take a PDF document, drag and drop, and then you apply the email address to the signers, and you send it away, and create the sign message, so that’s how it works. It’s a very simple, but useful tool for just keeping the, having a web interface to the users.

Then we have a Support Service. And the support service is basically calculating the hash of the document to be signed, and then the hash is sent further on to the digital signing service.

Digital Signing Service is a bit more – has the highest security, it contains these hardware secure modules, etc. That are creating those signings with the highest security.

And then we have the Identification Service, which is actually different identity providers connecting to each e-ID issuer. And we’re splitting this up, you can facilitate several things, because the signing portal and the support service is – those are the only components that are hit by the document to be signed, and they are done in a way that they can be installed in our customers’ operations. So, by doing it that way, the document to be signed is never leaving our customers’ IT departments. So, they stay at our customer. That is one thing. And by splitting up, so you have an API towards the support service, you also facilitate the possibility that the customer has other e-services that also would like to use an API for signing documents.

Those two parts, the signing portal and support service are rather easy components, that doesn’t contain any hardware or anything like that. So, it’s easy for the customers to install and operate themselves. Some other customers might – doesn’t have that requirement. They want the software as a service solution, and we can provide that as well. So, that’s possible to do it that way.

The Digital Signing Service, containing the hardware secure modules, and everything around that, that we always operate ourselves, but that part is never hit by the documents to be signed. And then we have the Identification Service, which is basically SAML 2.0 IDP connecting to, to different. It can be used as a pure identification service only for logging into it, and e-service, for example, but not in this case, also for signing. So that’s how our service is split up with those four different components, and how we can meet all these requirements that we have from the customer. But it is possible to do it this way.

And for the signing portal, we – it is a rather simple web page, and it has a basic structure, but we can customise it for our customers. So, if a municipality use that, we can customise it for that municipality; so it states the name and everything. So, the user feels that they are in the same. But when connecting to the support service then the – our customers can fully integrate and have everything that is shown to the users and the e-service that the agency provide. So that’s a little bit how it works and how it’s set up.

Oscar: Excellent. Actually, one topic, I think you mentioned a little bit, maybe to understand even better is the self-supporting signed document. Right? So, you said – tell us a bit more about that, how it works.

Magnus: If taking a PDF, for example, the standard we use are PDF advanced electronic signatures. When I say that agency for digital government, the technical framework is based on eIDAS. So, it’s international standards that is based on. And when I say self-sustaining, then I mean that it should be able to validate the document to the person who has signed it, using only the document.

It isn’t really through, but you don’t need SignPort in order to validate it. You just need the public key from our signing service. And that’s the only thing you need, then you can validate the signature to the person who has signed the document. And the public key is – it can be downloaded, it can be stored, so that you have it. But it’s public service, so it’s, once it’s out, it is possible to achieve later on. But if you have that, you can validate the document to the person.

And then you can do, for example, if a government, an agency received a signed document, you can validate it and extract the person, electronically, that has signed a document provided that you rely on our public key. But then you also include the verification list in the document, so you can see that when it was signed, the identity wasn’t revoked. So, it’s sustainable also over time, together with a signed timestamp as well. So, basically, that makes it, self-supporting.

There might be other ways to do this onwards, the standards aren’t really set yet. But this is how we do it, in order to achieve this. Possibilities there are very replaceable, but it’s a good thing, I guess, if looking at.

Oscar: Yes. You have mentioned also that, a big part of your requirements come from the public service, and you’re following what needs to be comply in Sweden. So, let’s focus on that. So, what are signature service must comply in Sweden?

Magnus: It is for the public sector. In Sweden, the agency for digital government, they have set up a technical framework and a normative specification, and this setup addresses all the requirements that I listed above. So, it’s not a requirement on the public sector in Sweden, but it is the recommendation. And if following it, it will be much easier when, for example, different agencies collaborate and send documents between each other, if the signed documents follow the standard, the same standard. And there is also a requirement to connect to foreign eID, eIDAS.

So, for example, if you – it isn’t that many countries that is connected foreign eID yet. But, for example, if someone from Germany would like to use e-services in Sweden, it’s possible. Also, Denmark and several other countries, and there are more upcoming. So, there is a possibility to use also within Europe, both for identification and signing.

For the private sector, it isn’t – of course, there are requirements that the service has to be easy to use. I think that’s the main thing. But otherwise, there aren’t that, must have requirements as I believe on, when it comes to security or sustainability, and so on that. Maybe companies would like such things, but it isn’t a real requirement. So, you can use more or less whatever signing service you like. And there are many, and that’s OK. So, what we’ve seen in private sector is mainly, we have some customers, but they are mainly connected to either health care or law, when you’re more close to the public sector. So that’s what we’ve seen.

Oscar: All right, perfect. Definitely a good overview how signatures have being applied in Sweden. I would like to ask a final question. So, for all business leaders that are listening to us now, what is the one actionable idea that they should write on their agenda today?

Magnus: Yeah. I think if you do not yet have a digital signature service, get one. It’s so much more efficient and sustainable than paper. So, if you don’t have one, get one. And when getting one, think about the future, how is the validity of the signed document proven over time? What happens in collaboration with other parties? And also, what happens when replacing the supplier, what’s next? I think those things you should consider when choosing a signature service.

Oscar: All right, excellent. Excellent, Magnus, for this final recommendation. So please, yeah, let us know if someone would like to follow the conversation with you, or follow the work you’re doing. What are the best ways for that?

Magnus: If you want to reach me, I think it’s easiest on an email address, which is magnus.kardell@knowit.sc, M-A-G-N-U-S dot K-A-R-D-E-L-L @knowit.sc. So, you can reach me there. And I believe we’ll set up a home page for SignPort, there is one, but I think we will update it soon.

Oscar: All right, perfect. Again, thank you, Magnus, for this conversation, and all the best.

Magnus: Yeah, thanks a lot.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Oscar Santolalla, Ann Cavoukian and Katryna Dow.In this latest episode within the Identity Story Series, Ann Cavoukian, creator of Privacy by Design and Katryna Dow, CEO at Meeco, join Oscar to explore the road to becoming ISO 31700 for Privacy by Design. They discuss the importance of Privacy by Design and how it can help organisations protect their customers’ personal data and comply with data protection regulations and the impact of Privacy by Design becoming an ISO Standard.

[Transcript below]

“If you don’t have a strong foundation of security from end to end with full lifecycle protection, you’re not going to have any privacy.” ~ Ann Cavoukian

Dr Ann Cavoukian is recognised as one of the world’s leading privacy experts. Dr Cavoukian served an unprecedented three terms as the Information & Privacy Commissioner of Ontario, Canada. There she created Privacy by Design, a framework that seeks to proactively embed privacy into the design specifications of information technologies, networked infrastructure and business practices, thereby achieving the strongest protection possible. In 2010, International Privacy Regulators unanimously passed a Resolution recognising Privacy by Design as an International Standard. Since then, PbD has been translated into 40 languages! In 2018, PbD was included in a sweeping new law in the EU: the General Data Protection Regulation.

Dr Cavoukian is now the Executive Director of the Global Privacy & Security by Design Centre. She is also a Senior Fellow of the Ted Rogers Leadership Centre at Ryerson University, and a Faculty Fellow of the Centre for Law, Science & Innovation at the Sandra Day O’Connor College of Law at Arizona State University.

Listen to Episode 73, where Ann joined the podcast to discuss Privacy by Design, and connect with Ann on LinkedIn.

“One of the really challenging things about privacy and security is if you don’t bake it in at the lower layers, if you don’t build that foundation, it’s really hard to go back and put it into a product or service afterwards.” ~ Katryna Dow

Katryna Dow is the founder and CEO of Meeco; a personal data & distributed ledger platform that enables people to securely exchange data via the API-of-Me with the people and organisations they trust. Katryna has been pioneering personal data rights since 2002, when she envisioned a time when personal sovereignty, identity and contextual privacy would be as important as being connected. Now within the context of GDPR and Open Banking, distributed ledger, cloud, AI and IoT have converged to make Meeco both possible and necessary.

Find out more about Meeco at meeco.me.

For the past three years, Katryna has been named as one of the Top 100 Identity Influencers. She is the co-author of the blockchain identity paper ‘Immutable Me’ and co-author/co-architect of Meeco’s distributed ledger solution and technical White Paper on Zero Knowledge Proofs for Access, Control, Delegation and Consent of Identity and Personal Data. Katryna speaks globally on digital rights, privacy and data innovation.

Listen to Episode 30, where Katryna joined the podcast to discuss Data minimisation, and connect with Katryna on LinkedIn.

Go to our YouTube to watch the video transcript for episode 89.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.


Oscar Santolalla: Today we’re happy to bring you a new episode of our Identity Stories Series. Privacy by Design has just become an ISO standard, which we want to celebrate, so let’s go back in time and hear moments of this journey.

Let’s first hear from Privacy by Design’s creator herself, Dr Ann Cavoukian. She is recognised as one of the world’s leading privacy experts and she served an unprecedented three terms as the Information & Privacy Commissioner of Ontario, Canada.


Oscar: Dr Ann Cavoukian welcome back to Let’s talk about digital identity.

Ann Cavoukian: Thank you so much Oscar. It’s a pleasure.

Oscar: Use a time machine and bring us to the moment in which you started writing Privacy by Design.

Ann: We’ll have to go back to the nineties. So, I was first appointed Privacy Commissioner of Ontario, Canada, and I think ‘97. And when I was appointed commissioner, I joined the office, which consisted of brilliant lawyers, and they took, of course, a legal approach to protecting privacy, applying the law after a privacy harm had arisen.

But you see, I’m not a lawyer. I’m a psychologist. I took a very different view of how we should protect privacy in addition to legal means. I wanted something that would prevent the privacy harms from arising. I wanted to have a model of prevention that was proactive, baked into the code, baked into your operations, so that ideally, we can have fewer privacy infractions and data breaches.

And this is a very different approach to the legal one. So literally at my kitchen table over three nights, I created Privacy by Design, and then I took it in, and I sold it to my lawyers. And it didn’t take long, but it was a different approach. And I said, look, this will complement regulatory compliance, which is after the fact, applying a privacy law, after a privacy harm has arisen.

That’s very, very valuable. But I want ideally to minimise the number of privacy harms that arise. And that’s what Privacy by Design is all about. So, they got that. It was a win-win and they liked it. And away we went. And Privacy by Design has grown dramatically since then. It’s been translated into 40 languages. We’ve had great success with it.

Oscar: How was the whole journey since that time until now, 2023? Has the road to becoming an ISO standard been a bumpy road?

Ann: It’s always a bumpy road, there’s no question. But I had great fortune. I was very lucky in 2010. Privacy by Design was unanimously passed as an international standard by the International Assembly of Privacy Commissioners and Data Protection authorities in Brussels. So immediately in the privacy community, it grew enormously. And then when, the new law in the European Union, the General Data Protection regulation, was introduced or came into effect in 2018.

My Privacy by Design was included in the GDPR as well as privacy as the default, which is the second of seven foundational principles of Privacy by Design. This was huge. It being recognised like that was just such a huge development and it took hold globally because everyone around the world wants to do business with Europe and engage in business and trade with the European Union.

So, lots of countries started doing Privacy by Design. And whenever there was a new law that was developed, a privacy law like Brazil last year, they included Privacy by Design in it. So, it really took off. So, when ISO started considering including it as an international standard, that took years in the making. I mean, it just came into effect this year.

But my colleague Michelle Chibba, who’s amazing, I mean, she’s been sitting on committee meetings for the past, I don’t know, three, four or five years with ISO in, in an effort to make Privacy by Design an ISO standard. But we succeeded and that’s the whole thing. It is now an international standard, ISO 31700. And it’s all over the world.

It’s already becoming embraced by countries who recognise the value of ISO standards. So literally, I’m delighted by this.

Oscar: Fantastic. I can hear your, your voice of success when you are sharing this journey. And congratulations for that, of course.

Ann: Thank you.


Oscar: If you were wondering what are these ‘7 principles’, let’s hear now Dr Ann Cavoukian explaining the 7 foundational principles of Privacy by Design. Starting with Principle #1 Proactive not Reactive.


Ann: The first one ‘prevent the harms. You want to be proactive so that you could prevent the harms from arising. It’s very, very clear.

The second one is privacy as the default setting. And that’s– I talked about that quite a bit. It’s absolutely critical, in fact, it’s considered to be so important. When they enacted the GDPR in the European Union, the General Data Protection Regulation, they included not only my Privacy by Design, but specifically privacy as the default setting as well. So that’s very important.

The third one embedded in design is absolutely critical. If it’s not baked into the code into your operations, it’s going to be overlooked.

The fourth one you have to have, what I always say full functionality. Get rid of the zero-sum mindset of privacy versus security, or privacy versus data utility. It can’t be either, or, win, lose. It has to be win-win, privacy and data utility. You make a positive sum, and you get multiple positive gains, privacy and security always intertwined.

And the next one talking about security. While the term privacy subsumes a much broader set of protections and security alone, in this day and age of daily hacking and phishing, if you don’t have a strong foundation of security from end to end, with full lifecycle protection, you’re not going to have any privacy. So, start with a solid foundation of security throughout your entire organisation.

Give individuals access to their own data. I always say to companies and governments, you may have custody and control of someone’s data, but it doesn’t belong to you, it belongs to the data subject. So, give them the right of access that they have, allow them to gain access to personal information you have on them. And companies actually have come back to me, companies that are certified for Privacy by Design, and they say, “We love this. We love this principle. Because once we give customers access to their own data, they come back to us and say – No, no, that’s no longer the case. That was true about me two years ago, here’s what’s going on now.” So, they correct the information. They increase the accuracy of the information we hold. And it increases the quality of the data we have. So, they love it.

And the last principle, keep it user centric. When you keep it focused on the user, all of this flows out. Because it should all be around the individual, when it’s personal information you’re dealing with. Because personal information is about identifiable individuals. So, you have to keep it focused on the user, and what they permit, what they don’t permit, things of that nature. So that’s it. Seven foundational principles by design.


Oscar: Despite all the recognition that Privacy by Design has received for two decades, and the influence it has had in regulations such as the General Data Protection Regulation, GDPR, we saw that the vast majority of Internet products and services still didn’t use the seven foundational principles. An urgent push was necessary. What would help us make waves of such magnitude? Nothing better than a global standard published by the International Organisation for Standardisation, the ISO.

ISO standards are recognised by governments, regulatory bodies, and industry associations around the world, so becoming an ISO standard would increase the adoption of Privacy by Design and it would be recognised globally. It is not easy to become an ISO standard, with thorough review processes including, expert opinions, public consultation, and a vote by ISO members.

On 2018, a technical committee called ISO/PC 317 Consumer protection: Privacy by Design for consumer goods and services was created. Four more years, and all the efforts of this group of motivated and brilliant minds from all over the world came to fruition. On February 8th, 2023, the standard was published with the name “ISO 31700-1:2023 Consumer protection — Privacy by Design for consumer goods and services”.

Let’s now hear from another guest a perspective of a tech entrepreneur who has been incorporating Privacy by Design in their products.


Oscar: We are welcoming back Katryna Dow, who is CEO and founder at Meeco. Hello, Katryna.

Katryna Dow: Hello. It’s nice to be back. Thank you for inviting me.

Oscar: Katryna, how has Privacy by Design influenced you?

Katryna: Well, I’m very privileged. If I think back to when Ann Cavoukian and the Canadian government were at the forefront of bringing the concept of Privacy by Design into the world. I was the recipient of an early Privacy by Design Ambassador Award and I think that was twofold.

One, because after reading about the principles of Privacy by Design, we immediately decided to bake those things into the development of Meeco as a product. So architecturally, to adopt them. And secondly, we were invited, around 2016, to submit a consultation to the Canadian government in support of Privacy by Design, and really in support of why it was important from a technology design perspective and actually how it could make a difference.

We all remember, a lot of this thinking was pre GDPR. This was kind of at the forefront of the concept of considering for citizens. Initially, Canadians and now all around the world, this idea of taking a principle of privacy and considering it in every aspect of the design of a product or service.

Oscar: Thank you. And on your opinion, how has Privacy by Design influenced digital identity as an industry?

Katryna: So, I think it’s an interesting question about digital identity. Optimistically, I guess what we’ve seen with the advent and the evolution and the maturing of Self-Sovereign identity. At the heart of that are principles around human centred design and control. So, I think there are great parallels with Privacy by Design. However, if we step back and look at the whole digital identity landscape, I’m not sure that it has had a wide enough impact in the design of systems.

Certainly, large tech platforms or even some governments have not really thought about that human centred Privacy by Design, progressive disclosure, anchoring core part. And as a result of that, I think in the digital identity landscape, we have lots of really great systems and solutions, but they’re not always designed from a human centric or Privacy by Design point of view.

And I guess one topical example of that recently with the acquisition of Twitter by Elon Musk and then opening up Twitter blue for everyone and not having a proper process in place for verification or identity protection in any way. We all saw that. That was a very short-lived example of what happens if you don’t understand some of the foundation principles of identity privacy, and if you don’t design from that perspective of understanding, you want to in one way protect the individual, but another way to be able to open up that identity for authentication, authorisation or access to trusted parties in a progressive way.

So, I think sometimes that balance, we don’t see enough in the design of digital identity.

Oscar: If you have some final idea, you would like to share about Privacy by design?

Katryna: I think one of the things that we’ve noticed just recently, being involved in a community project, where privacy and security were acknowledged to be important, but not enough to slow down architecture and design. So, the desire was to be able to build something really quickly and get it out into the community.

And one of the really challenging things about privacy and security is if you don’t bake it in at the lower layers, if you don’t build that foundation, it’s really hard to go back and put it into a product or service afterwards. I sometimes think about building a house. You imagine if you, if you didn’t put down a strong foundation and you were building on sand and then you went back later and you wanted to try and reinforce that structure, it’s not impossible, but it’s costly.

It takes time and it creates all sorts of adjacent problems, particularly if you’re building a digital system. So, I think I would encourage people to think it may slow down architecture, it may slow down consensus, it may slow down the beginning of a project, but it means you can go much, much faster once you’re up and running. And it also means that you’ve not created technical debt, policy, debt, compliance, debt that you will have to circle back and address later on.

So, it’s definitely worth investing that time upfront and building on a strong foundation.

Oscar: I couldn’t agree more. There was an excellent analogy in the very visual analogy that help us understand the importance of Privacy by Design.


Oscar: The stories that Katryna Dow just shared with us might sound like we’re still in a sombre passage of this journey. But it shouldn’t surprise us. Designing Internet services is only getting more complex: tight deadlines, limited budgets, scarcity of technical experts, all this determines and shapes the outcome. And those new applications are built to help the lives of millions of citizens, students, patients, and people of all ages.

At this crossroads, how can we make sure that this ISO standard builds the required momentum so what we’ll see in the next years is an avalanche of services that really protect our privacy?


Oscar: So now that it has become an ISO standard, what is the impact of having Privacy by design an ISO standard?

Ann: I think the impact will be significant because you see we’re struggling right now at a time where surveillance is mounting steadily mounting on a daily basis. We need massive intervention to put the brakes on it. And with Privacy by Design, being recognised as an ISO standard, that will draw so much more attention to privacy, embedding it proactively into the design of your operations. Into AI, artificial intelligence. We have to embed privacy into this from the beginning in order for it to take.

And that’s why I’m so excited about the timing of this, because it will attract a lot of attention to privacy, and privacy forms the foundation of our freedom. If you want free and open societies, you have to have freedom. And this will help to preserve freedom. So, ISO standards, marrying with Privacy by Design. The sky’s the limit – privacy and freedom.

And also, privacy and security go hand in hand. While privacy subsumes a much broader set of protections than security alone in this day and age of massive phishing and ransomware attacks, and all this, if you don’t have a strong foundation of security from end to end with full lifecycle protection, you’re not going to have any privacy. So, you have to have privacy and security by design.

Oscar: No doubt. Is there something else you would like to tell or share?

Ann: And what I want to remind people is please don’t be alarmed by the odds. Meaning people say to me, you know, I tweet every morning, I have a large Twitter following and I tweet about the latest stories of the day. And someone invariably will come back to me and say, Lady, give it up. That ship has had sailed.

Privacy is dead. And I go back again. Another friggin ship. You don’t give up on privacy. You don’t give up on freedom just because the odds are small. They’re getting bigger. But you look at what is important to preserve. Freedom is the most important thing to me to preserve. I’m Armenian. I come from a background, in 1915, 1.5 million Armenians were killed.

It’s you don’t give up. You know, that’s the whole point. You always come back. You never give up on freedom. And so, I just urge people don’t be alarmed at the odds that it seems to be overwhelming that we can’t do this. Yes, you can. We can do this. We have to do this. We want to preserve freedom for ourselves, for our children, for the future. We must do this. So please stay with me and embed privacy into your operations.

And one last thing. If you do shopping, either online or in real stores physically, if you express an interest in privacy, you will get so much more protection. You can imagine I always ask what they’re going to do with my information. I’m at a store, they’re asking for my postal code or this or that, and I say, “Oh, and how will you be protecting my privacy?” The guy I’m dealing with doesn’t know, but he’ll go get the manager, and the manager will say, “Oh, you care about privacy. Here’s what we can do. Boom, boom, boom.” And immediately the protections go up.

So just express your interest in privacy and see how much more protection it will lead to. It’s a win-win.

Thank you for your time.


Oscar: Privacy is not only an Internet issue, a technology issue, it follows us everywhere we go.

From a kitchen table to an ISO standard, the world just saw how Privacy by Design arrived to this elusive, but crucial destination.

What’s our next milestone on this journey? The road that will come can be long and bumpy but as Dr Ann Cavoukian said, it’s never time to give up.


This was a special story episode of Let’s Talk About Digital Identity. Thank you to our guests Dr Ann Cavoukian and Katryna Dow. The story of this episode was edited by Chloe Hartup with help of me Oscar Santolalla.

View Details

Let’s talk about digital identity with Adrian Field, Director of Market Development at OneID.In episode 88, Adrian Field, Director of Market Development at OneID, joins Oscar to explore verifying digital identities with online banking, the importance of online banking-based identity verification alongside it’s benefits for businesses and individuals. Join as they delve into the cross-border challenges that arise from individual country verified identities and how LEIs and UK Trust framework are supporting verified digital identities.

[Transcript below]

“LEIs have been born out of the financial sector, through regulation. But we do see business use, in all sectors, is useful to be able to enable less fraud within a country, or better and smoother cross-border use cases for companies.”

Adrian Field is Adrian Field, Director of Market Development at OneID. He leads OneID’s market development, working with banks, industry groups, Government and regulators to enable the UK market for ID services to grow and succeed.

Adrian is also engaged with the Open Identity Foundation developing global open standards for identity, and global projects to connect identity schemes cross-border.

Connect with Adrian on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining to a new episode of Let’s Talk About Digital Identity. And today we’ll discuss a new perspective on verified digital identities. And for that, we have a special guest who is Adrian Field. He leads OneID’s market development, working with banks, industry groups, governments and regulators to enable the UK market for identity services to grow and succeed. He’s also engaged with OpenID Foundation developing global open standards for identity and global projects to connect identity schemes, cross-border. Hello, Adrian.

Adrian Field: Morning. Hi, thank you for inviting me.

Oscar: It’s a pleasure having you. Thank you. Let’s talk about digital identity but first, I’d like to hear a bit more about yourself. So, tell us, what was your journey into this world of identity?

Adrian: Yeah. So, my background is banking and payments originally, so I spent a long time with one of the card schemes, doing all sorts of things, but learned about the concepts of authentication and authorisation through that process. And then spent a few years at one of the UK’s large banks looking at lots of different innovation topics, but digital identity was one of those. And then I used my authentication knowledge to build on that to investigate more and more about, you know, what is identity? How do you prove that it’s the right person, in a journey, at the right time?

Oscar: And to start this conversation with common understanding, for ones who have not heard or is not completely clear. What is the concept of verified digital identity? So, what are we talking about when you use this term and why is it important?

Adrian: I normally explain this by going back to the question of, “what is identity?” without the digital part. And for us at OneID this is your, it’s the legal concept of your personhood. So, you are a person which is either a natural person, which is a human, or a kind of legal person, which is an organisation. And if you’re a person in UK law, that gives you certain rights, so you can own things, I can sign documents, I can own property. I have certain rights that non-persons, i.e., objects and things don’t have those rights. So, you get your legal identity by – as a person you’re entered into a birth register, or if you’re an organisation, you get entered into a company’s register or charities register as a legal organisation. And that’s how you get the identity part. That’s what an identity is.

The digitisation of that is, how do I securely connect that legal entity or the natural person to that legal identity in a digital process. So, I’ve got to have some way of verifying a birth certificate, or a passport, or a document or some other way to connect those two things together. And then I can store some data, which is the digital part. And I can protect that by providing that person with some secure authenticators, so they can reconnect to that digital identity and use it in other contexts. And that’s when it becomes a reusable digital identity and therefore, it’s more useful and also verified.

Oscar: In most of the countries, there are several co-existing identity verification products. There are some based on getting a passport ID cards, for instance, that’s one category. There are some based on mobile subscriptions. And the one I know you and your company, OneID, is focused is the identity verification based on online banking. So, why this category of verified digital identities are needed?

Adrian: Yeah, so we looked at the UK market, and we looked at a number of different markets that have digital identity schemes and solutions in place. And specifically for the UK, we didn’t feel the government ID was the right way to go. It was quite hard, because politically, people have looked at ID cards from the government in the past, and they didn’t really want those. Whereas in the UK, we’ve got a very strong financial services market. We’ve got open banking infrastructure, which all of the banks have put a lot of investment into. To meet Payment Services Directive 2 requirements, so some EU legislation. And part of that open banking is all around strong customer authentication. So being able to securely identify that you have the right person in place to prevent payments fraud and things like that.

So, we saw that as a very good technical platform on which to build an identity layer, so an identity scheme on top of that. So essentially, it’s a bank ID scheme. So, you leverage the Know Your Customer process that the bank has put you through, so that they know who you are, we can leverage that and make that available in any online customer journey. And it’s a very easy process, because most people in the UK already have the bank app or the credentials that they need to get through our OneID service. And we can enable that for around 40 million UK adults, for instance, already have what they need to use the service. So, it’s a lot less friction for the customers to understand what a digital identity is, all they need to do is click a button and consent to share some data.

And we do – there’s a lot of kind of documents scanning solutions in the market and we recognise, and we look at that as a kind of bridging technology. I’ve got to scan my documents which we kind of see that as a digitised identity rather than a digital identity. Because I’m digitising paper into a digital format, as a follow-on step from that I can choose to store that digital format somewhere with a provider to create a reusable identity, and then protect that in in some way. So, we see that as a long-term process as well.

And in terms of what the telco sector can bring, there’s a lot of kind of useful signals around telcos in terms of SIM swaps, when was the last date that my SIM was swapped, and where is the phone location-based data, and things like that. We definitely see telcos and banks working together and providing complementary features. Although there are some gaps in the telco market in terms of I could have multiple shared handsets on one account. So, it makes it harder for, to know all the IDs on that account, and pay as you go, for instance. If there’s no KYC on getting the device, then that becomes harder to do identities in that manner.

Oscar: Explain us a bit in a, let’s say concrete example. Thinking the user doing some transactions and doing something online in which requires the identity verification, in the case of these online bank base, verify data identities. If you can guide us to a use case to understand how it works.

Adrian: Yeah, sure. So, what our corporate customers who we – relying parties, we use that term. They would implement our service as a, we have a software development kit, an SDK. Essentially that they can embed our button within their app or website, so the consumer, as the service that consumers are trying to get to. They would then click that button, and then select the UK bank that they do their banking with. And once they’ve selected the UK bank, we would route them off to either the bank app that’s on their phone, or an online banking login page for their bank. And they login to that and they see what data that the relying party is requesting, they can consent to share that data. And then we hand off that customer back to the original service or relying party that they’re trying to access.

So, it’s a three click simple process, and the customer is completely in control and has good visibility of what data they’re sharing. And then through that process, we kind of avoid the need to educate the customer on, “This is a digital identity. This is what it is. And this is how you use it.” Because all you really see is I’m sharing my name, address, date of birth, with – I’m trying to get some car finance or trying to buy something online. That’s a lot easier for the consumer to understand in that context.

Oscar: So, so far, it’s already serving different types of relying parties, as you said, or, in practice service provider, or at least the other term just to use that. So, there are many, let’s say type of businesses and also, I guess, government that are already using this type of verified identity.

Adrian: Yes, exactly. So, we’re getting some good traction in e-signing, for instance. So currently, when you sign a document, you typically get an email into inbox, you then click the link and sign the document. But if that email goes astray, or if you, as the contracting provider, want to know that it went to the right person, you can insert a digital identity check in that process. So, we’ve built that and partnered with a number of the e-signature market to be able to have an identity and signature flow, which works really well.

Another use case we’re looking at is Disclosure and Barring Service or DBS Checks in the UK for employment. We can now do that in 100% digital process that doesn’t need documents scanning. So, it’s a much easier flow for the customer to get through.

And final use case is financial services where we’re live in the FCA Regulatory Sandbox working with one of our customers in the asset finance space where we can augment and supply some of the KYC data into their customer due diligence process for money laundering checking.

Oscar: And you have mentioned earlier that one of the reasons why this type of verified digital identity made a lot of sense in the UK is because, the UK has open banking among other parts of the system that are already working, working pretty well. So, if you can tell us a bit more about that online banking, how this approach is using or complementing open banking?

Adrian: Yes, exactly. So, we’re regulated ourselves by the Financial Conduct Authority as the UK FS regulator. We’re an Account Information Service Provider under PSD2, so we have permission to access all of the banks without permissions or contracts from the banks. But you can only get certain limited data under the PSD2 directive. And it’s, you know, eIDAS is the regulation in Europe that covers identity. PSD2 is just about triggering payments and getting bank transaction data so it’s not about identity. So, we partner with the banks to get that additional information. So, we’re using open banking as technical rails to secure the API connectivity. But we have commercial partnerships with the banks to actually get the identity data.

Oscar: And this approach can be replicated in other countries?

Adrian: Yes. So, we’re looking at other countries that have, either open banking, and digital identity frameworks. A lot of countries who will have both of those things and talking to other schemes in terms of how– sharing how people do it elsewhere; what’s worked, what hasn’t worked, and what needs to be put in place, if you haven’t got the relevant frameworks or standards. And how we can connect those things to enable cross-border journeys. So, there’s a lot of activity going on. I think there’s something like 60 countries globally have digital ID systems. They’re not all based on open banking, but open banking, online banking is emerging as a good model on which to base your identity for a number of different reasons.

Oscar: Coming back to the benefits that verified digital identities have, can you tell us what are some of those benefits both for individuals and for businesses?

Adrian: Yes. So, I’ll start with businesses. So firstly, it acts as a key capability within digital transformation. So, understanding who your customers are, and enabling them to access your services in a much quicker way, will lead to increased sales. Basically, you’ll be able to onboard more customers more quickly. They’ll typically spend more with your company, because we find convenience always wins. So, the customers will also use the path of least resistance. If I have one service that is hard to get to and I need to go and find my document and do lots of different steps to get onto that service. Versus one that takes three clicks to get through to the same thing, typically, you’ll find your conversion is better with a simpler service.

We also think this will be a cheaper route. So operationally, the cost if you haven’t got – don’t need people checking documents, then it’s a cheaper provision of service. And also, for the business, we think this will lower fraud because we can keep fraudsters out of the loop because they can’t prove that they are who they are. So typically, impersonation fraud, someone’s pretending to be someone they’re not with a different name. If you then ask them to authenticate themselves with their bank account, they won’t have a bank account in that name so they just can’t get through the process. And this will help things like authorised push payment fraud, and other frauds in the ecosystem.

And then on the on the individual life. It’s really all about making my life simple. So, make my life easier, and not more complex. If I’m trying to get to a service, when I’m out and about maybe my ID documents at home, I can onboard to service easily just with the phone I have when I’m out. It makes my life really simple. We can actually onboard you to a service provider and also do a login afterwards as well. So, there’s no new passwords to remember. I get to see what data I’m sharing so I can control my data. I consent to share exactly what data has been asked for. I can see what data I’ve shared in the past through another consent service that we offer.

And in our model, the data is protected by my bank. So, someone I already have a relationship with, I trust my bank, I trust him with my money, I trust him with my information. And they can help me when it goes wrong as well. So, if something happens and identity is compromised, I can call my bank and say, “Can you help me out? Let’s figure out what went wrong and fix it.”

Oscar: Do you see there could be some cross-border challenges that come from specific country based digital identities?

Adrian: Yeah. So, a lot of a lot of this comes from, you know, interoperability in the standards space. So, what – how do I actually connect to these services, connecting together to share data from one scheme or solution to another one? What’s the kind of data format, what does the data mean? And then from a governance perspective, what’s the level of assurance that was been through, the checking of that identity before that data was issued? And do I trust that that process was followed properly?

So, in the UK, for instance, we have a certification regime set up where I can actually get an independent auditor to verify that I’m safe and doing these things properly. And therefore, you build in different layers of trust in the data that comes out of that ecosystem. And do you have equivalents of those things across different corridors. But essentially, identity, or legal identity always comes from a national authority, so it always will be nation-based. I got my identity from being on a birth register in a country. And then they issued me with a passport, driving license, et cetera, digital identity can be added on to those things.

So, I do see we will have 200 plus countries issue identity, and in what format they do those things. And that’s where some of the work I’m doing with OpenID Foundation and others is in terms of; how do we come up with better, easier-to-use standards that can enable, all of these things, to talk to each other.

Oscar: And how are this type of approach of online bank based verified identity fits with eIDAS 2.0, if it fits?

Adrian Field: Yes, there’s a lot of interesting activity going on in Europe with eIDAS 2.0 with the whole kind of shift to digital wallets and people having a wallet or a container that they can then put digital identity credentials into. What are the kinds of standards and infrastructure that enables that to happen? And how do we give people more control and visibility about what data they have, enable them to choose to share that data with third parties, and a privacy respecting, data minimisation, all of those good things happen through that. And I think that the kind of eIDAS 2.0 framework started to drill down through the layers to say how these things actually going to be implemented, which is really good.

And we’ve got four or five large scale projects with lots of different parties involved, with lots of good capabilities. So, we’re watching that space quite closely in terms of what’s our equivalent approach in the UK to digital wallets between the government, the banking sector, us as a provider, how those things work and interoperate together. To be able to securely provision those credentials into the right wallet.

And I do think some key challenges are going to be around how do you bind the credential to the wallet? How do you bind the wallet to the device, and the person that owns it, to make sure that the credentials that are being presented actually belong to the person that’s in front of you, or in that digital journey?

Oscar: How, first of all, is the UK Trust Framework is supporting verified digital identities?

Adrian: I think the UK government is doing really well with the Department of Science, Innovation and Technology. There’s a new department, but they’ve now taken over ownership with the trust framework. The Trust Framework is in a beta version, and we have 36 providers in the UK market that have been certified under a number of different roles within that framework.

So, I think the UK government’s work has certainly catalyse the UK identity market and enabled providers, such as ourselves, to be certified for services within that. And also, they have launched – there are three schemes, there’s a right to rent, right to work and Disclosure and Barring Service schemes that have been launched under that. Where if relying parties are looking to buy services from the market, the framework is recommending that they use certified providers because you’ve got that layer of trust that you don’t have with non-certified services.

So, I think it’s been a very good framework that’s evolved and enabling the UK market to progress from where it was before. And also, for – we now have a kind of reference point for; anyone that’s doing anything and identity in the UK and point towards the framework and say, “Well, let’s do it this way. We can have that common language between each other. We all know what the inputs and outputs are in terms of a common approach. So, it has been really good.

Oscar: Yes, and as you said earlier when I asked you about the, what are the verified data identity? You mentioned very clear there are verified identity for individuals, which mostly what we’re talking in this conversation, but also you mentioned there’s also for the organisations. So, that touches the topic of the Legal Entity Identifiers, LEIs, to go your view how do LEIs are supporting verified digital identities?

Adrian: Yes, I think this is – these are essential and the whole, the work through GLEIF and the whole ecosystem of, how do we give unique identifiers to legal organisations globally? That can then be used to create security around who are the business organisations that I’m dealing with, who owns which assets, etc. Who owns – what’s the kind of parent-child relationship, in particular businesses, as well. Absolutely helps understand that kind of transparency and trust of, I know, organisationally, who I’m dealing with, who I’m contracted with.

And then we can add in the individual identities from things like OneID to say, “I know who the individuals are, and I’ve verified the individuals.” I can then start to connect those two things together. So, I’ve got OneID for an individual, I’ve got an LEI that I know it’s this particular company. And I can then join those two things together to say, this individual is acting as a director of that organisation. Or it’s the Chief Financial Officer, and they have access to the bank account information. And then you can then start to secure those channels to say, “I’ve only got certain notified people should have access to my corporate bank accounts.” It then protects the corporate bank accounts from fraudulent use of internal people, or the wrong internal people accessing those accounts.

And also, when you’re paying other companies, you can then start to verify, “Am I paying the right company? Am I dealing with the right person within that company, in terms of individual identities?” So, it becomes very powerful, the combination of both.

Oscar: Yeah, exactly. And I really hope to see this – exactly the use case that you just described I hope to see really in the in the near future. Unless, unless you have already seen them. But yeah…

Adrian: And we’re looking at those kinds of use cases as well to say, you know, how can we actually do better corporate identity, and use the LEIs for all sectors, really. So, LEIs have been born out of the financial sector, through regulation. But we do see business use in all sectors is useful, to be able to enable less fraud within a country, or better and smoother cross-border use cases for companies.

Oscar: Yeah, certainly. A final question, Adrian, for all business leaders that are listening to us now, what is the one actionable idea that they should write on their agendas today?

Adrian: I would say, come and talk to us, so my email is adrian@oneid.uk. Come talk to us, come and engage with the services, come and test and learn and try them out. So, we’re live and we have an easy-to-use API that takes a few hours to integrate. We’re also based on open standards, with OpenID Connect. So, it’s very easy to get up and running with a service and start to consume it, to see what kind of data you get from the service, what kind of assurance, and what certification? How does this interoperate in terms of other things in the market? What kind of solutions are you using today? What kind of problems you have, that these solutions can potentially address? But it’s all ready and up and running, so yes, just come talk to us.

Oscar: Again, it was very nice, very interesting discussing with you Adrian and all the best.

Adrian: OK, thanks for having me.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Henk Marsman, Public Speaker, and Principal Consultant at SonicBee.In episode 87, Oscar is joined by Henk Marsman, specialist and public speaker around ethics of digital identity and Principal Consultant of Identity and Access Management at SonicBee. Henk and Oscar explore why local municipalities may need their own digital identity schemes – including how these local schemes differ from national schemes and how they help people missed by national schemes, alongside some examples of live local identity schemes. They also discuss some disadvantages of local identity schemes and how they could be incorporated into wallet-based identification, like eIDAS 2.0.

[Transcript below]

“Put the human at the centre, what the individual’s needs, what the individuals want to achieve … and that is basically the ethical perspective, or the value perspective on digital identity solutions that we have in the world today.”

Henk Marsman combines deep knowledge on digital identity with an ethical view on the impact on individuals and society of digitalisation of identity. His research on the ‘ethics of digital identity’ is still ongoing. Henk is involved in initiatives related to national digital identity (including eIDAS2.0), municipal digital identity and specifically for undocumented persons. Next to that he’s supporting organisations through his work at SonicBee, a Dutch IAM boutique firm, in digital identity projects. He has worked for 5 years at a top-three Dutch bank (Rabobank) as the global service owner for the Identity and Access Management services, and prior to that was senior manager with Deloitte, leading the Dutch IAM practice.

Connect with Henk on LinkedIn. Find his personal blog at ThroughIdentity and other blogs and articles at SonicBee.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Learn about the commercial and technical aspects of Customer Identity & Access Management, at IAM Academy, Ubisecure’s partner training program.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining us to this episode of Let’s Talk about Digital identity. And something that we have not talked before is, digital identities in local governments. For that very interesting topic, we have a special guest who is, Henk Marsman.

He combines deep knowledge on digital identity with an ethical view on the impact of digitalisation of identity, on individuals and society. His research on the ethics of digital identity is still ongoing. Henk is involved in initiatives related to national digital identity, including eIDAS 2.0, municipal digital identity, and specifically for undocumented persons. Next to that, he is supporting organisations through his work at SonicBee, a Dutch IAM boutique firm in digital identity projects. He has worked for five years at a top three Dutch bank, Rabobank, as a global service owner for the Identity and Access Management Services. And prior to that, he was senior manager with Deloitte, leading the Dutch IAM practice.

Hello Henk.

Henk Marsman: Good morning, Oscar. Nice to be here.

Oscar: It’s great having you, Henk.

So, Henk, let’s talk about identity. But very first, I want to hear a bit about yourself and especially your journey to the world of digital identity.

Henk: Yes, that’s a good start Oscar, thank you for that. I’ve had several occasions looking back at how I ended up in this world, because there no formal training for becoming an Identity and Access Management expert. For me, it started actually when I was doing a half year of exchange study in Finland. Where a professor, in Turku, with a lot of abbreviations on a slide, and we were supposed to pick one and write an essay on it. And I chose the TTP one, which stood for Trusted Third Parties, and that let me in the world of online trust services / public key infrastructure. So, I did my graduation thesis on the same topic, and from that on I was in Cyber Security and PKI basically, and over the years through planning and through accidents, that was henceforth.

I still remember, one time in a consulting firm I was on the bench, there was a project ongoing and there was a free seat at the Sun Identity Manager Boot Camp. Sun was still a company at that time. And I didn’t really want to go, but it was a free seat, so I had to go. And then within half a year I moved over to another company, and it was Deloitte. I accidentally made the remark that I had to do this boot camp on Identity Manager, and from that point onwards I was their Identity Manager Champion. Because as we say in the Dutch, in the saying ‘In the land of the blind, a person with one eye is king.’ So, I’ve been in this area for over 20, 25 years, in consulting.

I spent five years at Rabobank, because I also wanted to see the other side of the table, where you actually need to improve year over year, work with teams and the internal politics of an organisation.

And then after five years, I decided to move back into consulting again. So, I’m with SonicBee, a boutique Identity and Access Management shop in the Netherlands. And besides doing the regular IAM consulting at organisations, I also spend some time on research and study on Digital Identity and the ethical aspects of it when you look at the digital identity solutions on a national level, sometimes even at the global level.

Oscar: Yes, super interesting. And yes, we know that from your research you have been, as you said, exploring the national level of digital identities. But also the local government, which is something particular we are very curious to hear more about that.

So first of all, what are local digital and legal identities?

Henk: Yeah, I came across that because, as part of my research I was intrigued by the gap between; on the one hand the promise of digital identity – stating that everybody has a trustworthy digital identity, we’ll have inclusion, and we can bank beyond banks, we can perhaps even provide a legal identity to persons, although that’s a completely different topic. And on the other hand, the cases where we saw that digitisation, but also digital identity solutions sometimes enhance exclusion, and enhance the inequalities that are already existing in society.

Because when we look at these type of digital identity solutions, it’s no longer in the corporate domain, with the employers, employees and third parties that need access. This is the domain of citizens and residents and how a state provides services to their population. And through my research, I came across the topic of Legal Identity and Digital Identity. And I got in conversation with a couple of municipalities where people were working, on the one hand on smart city type of projects to see how municipal services could be digitised. Which is for most governments, but also for lots of the municipalities, a strategic imperative to also enable their services to the residents and the citizens through digital channels. And on the other hand, also looking at how vulnerable groups in the population could also make use of those services, also through the digital channels, so using a digital identity.

And what I’ve seen so far is that, on a national level, there are like, there’s the supranational and the national regulation and the legislation, and there are a lot of national Digital Identity Initiatives. But on the municipal level, you really encounter the community aspect of it. So, where we can say on a national level, if you’re a Dutch citizen and these are your criteria, you can request a digital identity in these and these manners. And then you can file your taxes online, or request a permit for rebuilding a house, or engaging with the government on other topics and aspects.

But in a municipal level, you quite quickly encounter kind of the, what I would say is, the messiness of society. So, we can’t get everything in clear boxes. So, on the municipal level, you will encounter the people that don’t fit into the definitions and the boxes, that were created on a national level, to, kind of, organise society, or try to organise society by states. So, municipalities kind of struggle on that mid-level; between the local communities and the people that are actually living there, and the national directives and legislations, and they have to combine those two. And for that you see that, in a lot of cases, municipalities and cities rely on national digital identity solutions.

So, for example, in the passports of two of my children are expiring. So, I use my national digital identity, in the Netherlands that’s DigiD. I log into my municipality here and I make an appointment to renew their passports. That is one way.

But in the city, there are also people who struggle with those digital means. They sometimes also have an immigration status, which is what they call irregular, or they don’t have the means to do this digitally. And that is where you see that on the city level, there is much more effort and emphasis on also providing a physical interface for those people. Providing the services, to these residents, in the city.

And that’s where you see local governments and municipalities also sometimes struggle with groups of people, that cannot easily make use of a national level, digital identity solutions. But they still want to enable them, through digital channels, for their services. And that’s where municipalities try to create city cards or municipal discount cards. And especially, in a lot of cases, oriented towards the more vulnerable group. So, discount cards for groups in a community that live on a certain percentage of the minimum income, or by some other aspect. People who need to put in more efforts to get along in, kind of, regular society. And they get discounts through those type of cards.

Oscar: You mentioned, to see a bit of an example. Maybe you can tell me some examples in some cities, but those discount cards, are physical or digital, or there are both?

Henk: Most of the cases that I’ve been reading up, they’re physical. Because in those cases also the municipalities make use of the desks in city hall to issue these cards, to identify the people who need them, out of their central administration.

One of the initiatives, actually two initiatives, that I’m now involved with – we’re looking at also a digital version. So, an app on your phone or a wallet on a smartphone, that people could use for the same type of functionality. And I think that, that is one of the areas that will be quite interesting to see what’s happening there. Because there are a lot of wallets, the technology is already there.

For example, in one of the municipalities, we’re now in the conversation with a coalition of people who are representing more vulnerable groups, but also regular residents in the city. Which you know, the purpose of a digital ID or an identification card, would be to provide a way for people to show their identity. Regardless of their immigration status, because all – we’ll touch upon undocumented persons or irregular immigrants later on – because for some of the services is like accessing a library or a museum, perhaps even opening a bank account, you need to be able to show that you are a resident of the municipality, and not necessarily share a lot of other attributes. And this can be done through a card, but also through a wallet.

Of course, then there are other challenges that you need to address as well, because if the solution that is going to help these groups of people is digital, that means that it will be exclusion to people who cannot get along on those digital means.

So, there was a case in a city, where they were looking at an app on a phone to register for food and stay in pensions for homeless people. And it turned out that the phone that was used to make use of that app, sometimes was also used as a means for payments or the phone was lost. And then you see that that was kind of a prerequisite or requirement, to make use of a digital version in those types of solutions, there should also always be a combination of a physical and a digital solution. If the purpose is to provide access to public services for the general population in the city.

And that is also one of the things that struck me in the research; that there are a couple of angles to this topic of digital identity. And some of them are really coming out of the area of providing services, and they are more the service provider-oriented views. Which, sometimes, tend to be very focusing on, increasing the operating effectiveness, and making the delivery of service more efficient.

And the other aspect that, sometimes, is not completely served by the first perspective is that; if you put the human at the centre, they do this human centred development and analysis of what is going on, and what is needed. Then you see, all of a sudden, a completely different perspective. Where there is a huge variety in humans, in the population, in communities, especially in municipalities that cannot always make use of a digital ID. So, these two perspectives are also sometimes in tension with each other, and the research shows that the purpose or the overarching objective for a digital identity solution for a great extent, determines the success of this and the outcome of this.

So, going quickly back to a country level, but where one country deploys a digital identity solution out of surveillance purposes. So, they want to make sure that the people in the country are really citizens, not just residents. And it’s really focussed on, border control so, making sure that we don’t get the wrong people in. And that can be criminals, can be terrorists, but it can also be people who basically have no reason in this country. Such a solution will be designed on surveillance and monitoring, and more on exclusion, keeping the wrong people out, than inclusion.

Whereas if you set up a system like that to provide the basic services to all residents in a community, or in a country. And such a system will be much more designed and implemented based on inclusion, and will serve somewhat different purpose.

Oscar: So, this you mention, physical, digital, sometimes both – this discount card or this wallet, that for these people becomes the main document, correct?

Henk: For some people as well, yes. So, if I take my situation, I’m in the luxury position of, at least in the Netherlands now, I have a passport, I have a Social Security Number which we call Citizen Service Number. And in the Netherlands, the government has made the legal arrangements in such a way that, basically, all the primary or basic services that you can have here. So that’s health care, education, that is legal support, etc. They are connected to its legal rights of being permissible in the Netherlands, or being allowed to be here legally. For people who do not have that for various reasons, that makes it really difficult to get this health insurance, to visit the hospital, and get medical assistance, for example.

So, the cracks in the system is where this legal framework cannot cover every situation, and groups of people who are falling in those cracks. So, for example, undocumented persons, who do not have a Dutch passport, sometimes they have a passport from their home country, but they don’t have the residency status in the Netherlands. For these groups of people, a municipal identity or a city ID, could be a solution in situations where they are struggling now very, very much. And they struggle, for example, in what I mentioned, that’s accessing healthcare, because in the Netherlands, when you visit the hospital, you need to bring your insurance card. In order to get your insurance card, you need to get that insurance, and to get that insurance, you need to identify and have this Social Security number or a Dutch citizen number. Well, if you don’t have that, then the house of cards comes falling down.

But for these people, in some cases, they are also unable to identify them according to the regulatory framework. For example, when they’re on a bike at night, and their light does not work, and the police stops them. And in the Netherlands, you are not obliged to carry ID documentation, but you are obliged to be able to show it when police ask for it. So for these people, that’s a very scary moment, because if they can’t show the proper identity document at that point in time, because their bike light was broken, then they are at the risk of being detained under the laws for immigration and other people staying in the Netherlands, for example.

And the last example here, is that there is a universal human rights described that provides the right to education for minors. So, in this case, in the Netherlands, if a minor does not have this Dutch Citizen ID, the Social Security ID, they are still able to go to school up until they’re 18 years of age. But it gives still a lot of trouble in the administration, and after they are 18, the day they turn 19, they’re struggling with access to higher education.

That is where you see that kind of, the national regulatory framework covers about 95%, maybe 99% of all the cases. But there’s still a lot of people in this country, who do not, are not getting covered by the legal framework. And in the Netherlands, that can go up to 80 or 100,000 people. Of course, because in the case of undocumented persons, they’re not documented. So, we don’t know exactly how many there are, but it’s a significant amount of people. And they also play a significant role in in, for example, the great economy.

So, nannies and housecleaning. Now if you – during Corona that became very apparent, if you’re really forced to exclude them from society through these measures, then it has, of course, to a certain extent an economical impact. But you also push people out of the society, where their basic human rights are guaranteed. And that is for me personally, one of the triggers to say, well, let’s get engaged on this topic. Because I can walk into a hospital with a stomach-ache, and they will see me, and my expectation was that anybody in my country could do that, and it turns out not to be the case. Because of all kinds of regulations and identification, being able to identify yourself, whether it’s with a physical card or digital, is one of the stumbling blocks in that process.

So besides doing well-paid consultancy at large corporations on Identity and Access Management. I, but also my employer SonicBee, really sees this as something to engage in on society. To also and where we can make the growth a little bit better. How ambitious, or how almost over the top nice that seems, but that being part of society for us as well.

Oscar: Yes, absolutely super important and you have been illustrating very well both of the problems. So why it is needed? Why there’s motivation from the local governments? And how is it affecting is helping some people? But some people are still underserved, as you say.

If you can tell us, some examples from some cities, how has it been done?

Henk: Yes, there’s actually quite a lot of examples of cities who are already providing a city aid to their residents. And one of the most striking I found is the one in New Haven in America, the United States of America. That is a community with a large number of immigrants, and in the United States, the whole system of federal law and local law works slightly different than what I’m used to in the Netherlands, or we have in Europe.

The problem they have in that community was that these immigrants just had regular job, sometimes making a lot of money, but because they had struggles with identifying themselves, they could not open a bank account. So, they walked around on the street with sometimes a lot of cash that led to robbery and mugging, that led to unsafety in the community. So, the New Haven City Council said we need to address this, because these people need to be able to open a bank account in some way, so we can make the community as a whole safer. So, they issued the Elm City Resident Card, as they called it, and that really was designed to protect those 10 to 15000 undocumented immigrants. And that has been evolving over time.

Something similar is present in New York, where they have the ID New York that was started in 2015. Also, to provide access to city services, especially for vulnerable populations. And the trick they did there is that they did two really good things, in my opinion. Well, in the opinion of most of the analysis reports that I’ve read on it as well. They did it through a coalition, so instead of designing it for people, designed it with people. So, it was a broad coalition of representatives out of these vulnerable groups. And the other thing is also that it was not restricted to those vulnerable groups. So, it’s a generic city ID that was created there. And it showed also by the uptake because in one and a half years they had 800,000 users or holders of these cards.

With the vulnerable roots, one of the safeguards there is that it’s only for identification. In 2018 / 2019, there were two challenges to this is city ID or to ID New York solution. One was the change of administration, and the new administration had a completely different focus on immigrants and immigration and wanted to use or abuse their system. To find immigrants and deprive them of some of their rights that they had at that moment. And the other challenge was that financial service providers said it would be a good idea to connect financial services to these identity cards. And that was stopped, that initiative, because the coalition stood up and said, well, you know, financial service providers have different incentive than a city council providing public services to the residents, in the community. And also, for those financial services who will start gathering data, sharing data, analysing data to, you know, get the best financial offer to this person. But a lot of these people are in vulnerable groups and providing them really nice discounts. But then making them pay the credit rate for the next five years is not in their best interest. So that is not something that we want to do.

So, one of the lessons learned from that New York initiative was also to keep it with identity, do not combine it with other services like financial services. Because then you get different incentives and different players in, kind of, the ecosystem of search in municipal ID. And also, one of the things that New York does is that they destroy all evidence of the initial registration within two years. To also make sure that privacy of these people that that register, and you can register, of course, with a U.S. passport, but you can also register with less, I would say, assured identity documents.

So, all the way up to if you’re homeless, with a homeless residence will vouch for you and will provide you with a document stating that you have been staying overnight in their homeless residence for at least 15 days. That will make you eligible to apply for the city ID. And with that city ID again, you can identify yourself, access to basic services. And one of the things that really also showed in New York was that besides enabling vulnerable groups to access services, it also gave them a sense of belonging. So, it also did something in that community where identification was a prerequisite for services, and through that connecting with society and being part of society.

And there are quite a few others, there’s also one in Zurich, Switzerland. Where they started specifically for people without identity documents. So they call this Sans-Papiers, paper people without papers, without documents. And there, for example, you saw that they took the space there was between; what the regulator on a national level stated, and what their responsibilities as a municipality are, to provide these people with a card for identification. To make it easier for them to participate in society, to get specific discounts, etc..

And again, they’re a coalition working on this ID, where in New York they also worked closely together with the police department. It was also the case here, and together with the Red Cross and other actors in the city trying to figure it out. What are the stumbling blocks for vulnerable groups in our population? Can we provide them with an identification solution and can that identification solution also be in the form of a digital identity?

And I think on that aspect, in these situations, I’m not 100% sure to what extent there are already digital. I’ve seen in my conversations here in the Netherlands in a number of municipalities that, digital has some benefits in this case, so, an app or a wallet on a smartphone, because a lot of people have a smartphone, but not everybody.

So, on the one hand, again, you have this perspective of let’s get everybody this wallet and they can use it everywhere and the world will be a better world. On the other hand, such a perspective bypasses the fact that a community of people is very diverse. And if you, we actually had it with access to health care, we said, you know, talking to some health care providers, some GP’s saying, what if we create this this city ID card in an app and it would allow people, undocumented persons to identify. And their response, as practitioners in the field working with these people, said ‘That’s a great idea. But for that very small group of people who cannot do that because they’re not digital literate or they don’t have a smartphone, or it won’t be even more exclusionary to them.’ And that got us thinking and saying, if the objective is to work on the community and include people to a larger extent, then you need to really look at the idea identification and not focus only on the digital art of digital identification.

Although it’s a fascinating topic, it’s a cool development. With eIDAS 2.0 we’ll see a major changes in the next two years, in Europe. But the design principles should be human centric, and I love the quote of one of their one of the NGOs, one of the civic institutes working on it, says ‘Nothing for us, without us’. Because identification can become really core to travelling the society, and the municipality, and being able to access services or not.

Oscar: Absolutely. In these very clear now you have a explained these specific example in United States, Switzerland, also earlier in the Netherlands, they are definitely filling the gaps. Excellent outcomes. But could we also think if this type of local government ID have also some issues, some disadvantages? So, by what you see.

Henk: I mean in the sense of the challenges for these local initiatives, think one of the challenges or potential issues is of course, that when an administration changes or a national law changes, that means that you could be forced to adjust locally, especially if you provide a digital identity solution for vulnerable groups. Those principles of privacy and data control and data storage are critical, so that can be a challenge there. And that is kind of, I think, also to check that it’s a municipality or the community in the population, but it’s also a highly political environment. Of course, in a city council.

And one of the other challenges that we’ve seen here is that the idea is very appealing to provide everybody and methods of identification, regardless of what the national legal framework says. As the national legal framework may tie ID to immigration status. Well, some of the rights people have are not tied to immigration status, but that does leave the question of who will identify a person. So in the case of one of the cities that I’m engaged with now, we’re having that question saying, well, there are, for example, homeless people or undocumented persons or people who do not have this national ID or citizen ID. So who is going to vouch for their identity based on what? And will this identity be added to the national identity register?

Because in the Netherlands we have a person’s registration, and we already know that. The last question will be definitely a no, because that would be creating a backdoor in our national identity register. And of course, that would be very interesting for people with malicious intent. So, you would get a lot of fraud attempts there.

The question before that is basically if we can enable people to get access to all services they are entitled to. Even when they lack a national identity documents, then the challenge that we had of accessing the services actually moves upstream in the process to the question of, okay, so now they connect to social services, but who is actually identifying them? And does that need to be a city like a city council, or can it be a civic organisation? Or should it be a combination of both? And what are the minimum criteria?

So, within New York there are a number of requirements that you can use to get this ID, but for example, if you a slightly different focus, but it’s top of mind for me at the moment. If you look at Aadhaar the biometric national identity solution in India, which has been quite successful, they have a list of over 32, what they call breather documents. So, registering in the system, you have basically 32 options which range from passport to drive for license. And if all else fails there, if there is no document, then you can get two officials from your village, or your city and when they vouch for your identity, you will get registered.

Those type of questions then come up and you’re basically working on the; on the one hand, working on the fabric of society. So what does this notion of identity mean for society, and how can we make sure that it’s, on the one hand formally properly arranged, but on the other hand flexible enough? Because we are dealing with humans and once we start excluding them, then we really are sometimes violating basic human rights. With what I’ve also seen in my research that is actually happening various instances around the world.

So those could still be challenges and of course also expertise around this topic, which is something that a local government would need to build up and sustain over time.

Oscar: Yes indeed, thank you for explaining that. Absolutely, there’s still a lot of work to be done. One more question related to, you mentioned eIDAS 2.0, especially the wallet that has been in many people’s radars.

How would this type of identity, local government identities, can be incorporated into wallet-based identification? So, other existing, let’s say, or already planned, like eIDAS 2.0.

Henk: Yeah, I think that question is, I think there are two questions in there. One is, can you use a wallet? And I think there are many wallet types or hold type solutions already available in the market. So, in that sense it’s in that area, it will be more a question of, you know, which technology, which solution do we select and is it safe and also privacy safe?

What is happening in, on a European level with eIDAS 2.0. So, the ambitions for a European digital identity, based on a wallet solution, is that ties into the national governments because they have the – the national government has the authority over their citizens and their residents. So, eIDAS 2.0 is putting down a legal framework that ensures that there is a legal backing for a national digital identity, in a wallet.

So, for example, the Dutch government is now working on – how are we going to get our national identity? So, the National Identity Register enabled for an identity wallet under eIDAS 2.0. They are also working on a wallet solution, so that in two years’ time everybody who is a Dutch registered citizen can download the app, download the wallet, basically stored their national identity data in there, of course, are some questions around identification and authentication in that process. And then use it in the Netherlands, but also in Germany and in France, because the eIDAS legal framework will provide the legal backing for that cross-border order acceptance of those solutions. It can also be used on a city or municipal level, except for those people who are not part of the National Identity Register.

And that’s where it comes back to vulnerable groups in the community, where on a state level or a national level, I have this feeling that it’s easier to stick to general classes, and order, and regulations. Whereas on a municipal level, you really need to work on the translation to society with all the variety and all the and the people, the individuals and the groups of individuals in there. Even though on paper, on a national level, there are solutions for them, and they should be either out or in. You find that in reality some people are in-between and on a city level you need to deal with them because they still have basic rights, that you need to provide them regardless of whatever status they hold.

And I think for that, the eIDAS 2.0 will – well, my question is, whether eIDAS 2.0 does will make that a better world or not? Because again, this is a solution that is based on a national identity registers. Well, at least the aim is to make it an easy-to-use solution, but it means the majority of people using it will rely on it. That also means the majority of service providers will accept it, and perhaps move to a direction that they prefer that specific type of use.

So, there is the risk of enlarging again, the inequalities that you have in society there. And there have been cases already also where we’ve seen that these types of solutions, although they start as an option, as a voluntary solution, and you don’t have to join. Once you get into an ecosystem and other services are built on it or connected to it. So, kind of the generativity kicks in, of these types of solutions, then it becomes increasingly difficult to opt out. And I think as a commercial service provider, there’s a different perspective, different values at stake than as a public services organisation like a municipality.

Oscar: Indeed. Final question for you, Henk. For all the business leaders that are listening to us now, what is the one actionable idea that they should write on their agendas today?

Henk: That’s a good question. I think if I could give one actionable item is; put on your calendar to take on whatever digital identity solution you’re working. Take 5 minutes or maybe 10 minutes and basically take the perspective of the individual human. Realise that there is a huge variety in individuals. Everybody is unique, so generic solutions will only go that far. And if you put the human at the centre, what the individual’s needs, what the individuals want to achieve.

And that’s, for example, not only access to a bank account, but it is also independence, autonomy, agency, free will, also living a life that’s worth living, being able to flourish. Just spend a little bit of time on that perspective and then go back to everyday work, but take that perspective in mind that especially around identity solutions and also digital identity and digital identification in the end, there is a person on the other side of the line, which is a human, a flesh and blood, And that perspective, I feel, needs to be included more in the solutions that we build. And that’s also why I think we should have more conversations on the values that are at stake, the impacts of the solutions that we built. And that is basically the ethical perspective, or the value perspective on digital identity solutions that we have in the world today.

So I would put that on the calendar, take 5 minutes picture the human and what they need, what they want, what they are entitled to, what their privileges are, what their duties are, what their virtues are, maybe even. And then continue with the important work that I think most practitioners in this field are doing that.

Oscar: Great reminder. Thanks a lot, Henk, for this super insightful conversation. I commend you for all the work you’re doing on this. Please finally, let us know for the ones who would like to follow the conversation with you, what are the best ways?

Henk: Yeah, I’m quite active on LinkedIn, so I post a lot there and I like a lot there on this topic. That also has a link to a personal blog site of mine, which is henkmarsman.wordpress.com. I call it ThroughIdentity, because in my when I started on my research, I came across a lot of identity solutions and I thought we need to think these things through, right up to the end.

So it became, thinking through digital identity, and that ‘thinking through digital identity’ in brief is now ThroughIdentity. And also, on sonicbee.nl or just SonicBee sites itself, there are blogs and articles by me and by colleagues that people can follow. And those are the 2 or 3 main channels.

Oscar: Excellent. Thanks a lot, to Henk for this conversation and all the best.

Henk: Yes, Thank you to Oscar. Thank you for having me. And all the best also, with the blogs and with Ubisecure.


Do you want to learn the nuts and bolts of how customer identity and access management can help your business? IAM Academy is Ubisecure’s partner training program where you will learn all about commercial and technical aspects of Customer Identity and Access Management. IAM Academy has courses suitable for both business and technical people.

Enrol today at http://www.ubisecure.com/iam-academy/ and join hundreds of professionals who have graduated from IAM academy. And now are working in leading digital transformation projects in their own industries. You can also find more information on the show notes of this episode.


Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with John Jellema, VP of Product Management at Ubisecure.This is a special, bonus episode on Hybrid IAM, in the lead up to the Gartner Identity and Access Management Summit 2023. Oscar is joined by John Jellema, VP of Product Management at Ubisecure to explore the hot topic of Hybrid IAM including what is meant by hybrid IAM, why and when to consider hybrid IAM, benefits and drawbacks and considerations for orchestration between different clouds.

[Transcript below]

“Where I think identity access management is going, growing, and continuing is around the areas of security.”

For more from John take a look at his blogs or contact the team. Find more information and resources on our Hybrid IAM page.

Join us at the Gartner Identity and Access Management Summit, on the 6-7th March in London. Find the booth and session details or book a demo with the Ubisecure team.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: In the lead up to Gardner Identity and Access Management Summit 2023 in London. The Let’s talk about digital identity team have released this special episode to discuss Hybrid IAM. A trending topic in the identity management industry, IAM stakeholders are increasingly interested in understanding what Hybrid IAM really means, how we can solve modern ID challenges, and how to evaluate whether Hybrid IAM is a suitable business choice for their current identity projects.

For today’s episode and to help answer those questions, I am joined by John Jellema, Vice President of Product Management at Ubisecure. Hello, John.

John Jellema: Hi Oscar. Thanks for having me on the podcast.

Oscar: Very welcome. So, John, let’s talk about digital identity and as usual we want to hear a bit more about our guest. So please tell us about yourself and your journey to this world of identity.

John: Sure, absolutely. I started in a very old Internet company back in the United States in 1997. Moved over to Amsterdam, where I became a product owner on several security services for Verizon, the global telco. The last of which was operating an anti DDOS platform, so to ensure availability of circuits all over the globe through some of the largest DDOS attacks. Ran that platform for about 15 years and then I came over here to Ubisecure about five years ago.

I’m intensely interested in the personal access, the capabilities and the dynamic future of identity management. As we move from employee identity management into true global functioning personal identity management. That’s why I’m here at Ubisecure.

Oscar: Excellent. So, John, to get started with talking about Hybrid IAM. What do we mean when we talk about Hybrid IAM?

John: It’s a good question. It’s confusing a lot of times. There’s a lot of material out there if you search for the term hybrid IAM, what different folks are referring to or meaning. In practical terms, it’s using two dissimilar services or two dissimilar location areas to have a service deployed at the same time.

So, a lot of organisations – I mean we’re 20 – 25 years into this thing called ‘the internet’ with user accounts, and there are lots of legacy systems. That’s a term that is widely used for employee identity and access management, or your log on service that you do, or your access when you sign into your laptop or an internal machine.

It’s functionally – a legacy IAM is functionally, a server or a private cloud, at this point in time that a corporation or an organisation runs for themselves and hybrid IAM is linking that legacy service with a cloud-based service. So, something that is on a public cloud like Azure from Microsoft or AWS, Amazon Web Services, where you can get compute functionality from one of the larger providers in a dynamically scalable environment.

So, it’s kind of old school and new school coupled together and that gives you hybrid. That’s the functional area of what hybrid IAM is. Of course, the detail is, why would anyone want to have a hybrid IAM? Why add complexity? Those kinds of pieces. And the answer is, you really have different use cases.

So, your legacy service like I suggested was a B2E, so business to enterprise or business to employee. Where your public cloud-based service, that is the new component in hybrid IAM, is really you’re reaching out to consumers or citizens or business partners. So, you’re doing something that’s kind of different to what your existing business was doing, and you don’t want to have the complication of trying to onboard lots of non-employees into your employee IAM system.

Oscar: Yeah, indeed. Often, I talk with customers and they have those requirements. They might need hybrid. One might think but why don’t you stick to on prem or why don’t you do only cloud, but often both requirements are needed and hybrid IAM is what is needed.

When could you consider choosing hybrid?

John: For myself as a legacy networking individual, I would consider hybrid at any moment in time where I could make a logical DMARC. So, I’m trying to make a division in between which systems are running. It’s true, like you suggested, Oscar. You could have two implementations of your legacy stack running on your own prem, and you could say one of those is for internal and one of those is for external.

The driver or the key would kind of be, well does your legacy stack IAM actually do all of – does it serve all of the use cases? Does it do all of the functions that your new users are looking for? So, how do I integrate with a business partner or how do I offer services in a consumer way or a citizen manner?

If you’re a government organisation, you don’t necessarily want to expose all of the details or run the risk of co-mingling use access for everyone. So, putting an easy demarcation point, a DMARC point, in between the two services is key, and it will be a use case that kind of drives you to look out towards a public cloud. And it is that merging of the public cloud, that new service somewhere out there in the cloud infrastructure, along with your existing on prem legacy service or private cloud service, that really makes you hybrid.

There’s another aspect that people will, or organisations will oftentimes look at when they’re considering choosing hybrid, and that’s cost control. Your hardware or your legacy stack is expensive to run, operate. It takes your IT team an amount of time to manage and keep it going, to keep it secure, even for your employees. And you say, well, is there a way or a method to actually get all of this service function without having the core obligation. The core liability, the security risk of actually running things on prem.

Starting with B2D or a B2C out in the cloud. So, making an initial hybrid implementation that does a new feature for you, is a good starting point or a stepping off point. Where an organisation that has an existing platform, a legacy platform, can start looking in solving the question of going out to a hybrid and then eventually a full public cloud environment. Without going through the organisational trauma of completely upsetting everything. Or trying to make a dramatic shift of every use case all at once.

So, considering hybrid cloud can be for a couple of different reasons. Cost control, it can be new features, new functionality, and it can be along the general migration path, a growth path that an organisation is doing.

Oscar: Yeah, absolutely and if we go to see the benefits. Because also, mostly when we have an organisation that has to make a decision, do we go for hybrid, do we stay as we are? It’s important to know clearly, what are the benefits of choosing hybrid. So, for you, what are the main benefits of choosing hybrid IAM?

John: For me and as the head of product here at Ubisecure, it’s the same kind of decision we make in our own roadmap. We look at the use cases that customers are bringing forward in RFP’s. That’s reflective of the benefits or the benefit decision making process that we see a lot of companies doing, and that is, really a generational change.

They can be looking to utilise their IT staff, in more effective manner than managing this internal identity access management. There can be challenges with a merger acquisition, so if the company is actually considering expanding or being taken over. How do I actually make sure that my existing business partners, if I’m calling them internal at this moment, utilising my legacy stack of B2E for my partners, how can I do more for those external users?

And the more is, security as a primary driver. One of the big benefits of choosing a hybrid IAM is, like I’ve said, this big DMARC between your existing service and the new things that you’re trying to do. Or the better improved, more improved security that you’re trying for. It’s easier to implement multifactor for external users, if you’re on completely a new platform, you can multifactor that user in, and get good control points very easily. And then only with OIDC compliant tokens come back and process the specific pieces of information or specific access to your internal applications, that you might want to be giving to your partners.

So really using the public cloud, and that is the hybrid IAM, as an extra security layer or an extra layer of an onion, if you know that classic security model. That’s from my view, one of the largest benefits of choosing a hybrid IAM, you get more functions, different functions, altered functions that you don’t have to attempt to build into your legacy service. So, there’s no existing corporate disruption, while you’re growing your business, and that can be organically as your business grows or in-organically through merger and acquisition.

Oscar: Yeah, exactly. And do you see any drawbacks or downsides, that can be considered in [Hybrid IAM]?

John: Any time you add a complication right, and a hybrid IAM is a step function, you’re adding a complication, you’re talking about adding a second system. That can be considered to be a drawback. But if you consider the direction of IT in general, there are fewer and fewer prem based installations. More and more services that your corporation is using, whether that’s ticketing, whether that’s mail services, whether that’s applications for data processing or anything, more applications that we use are going towards the cloud. And there’s good reasons for going towards the cloud, that is public cloud, for all of these kinds of applications.

It’s much easier to ensure security. So, there can be security patches and feature additions that happen on a cloud environment in a much, much faster timeframe compared to what it takes to for all of us to, for example, install the latest image, latest security patch on our laptop or make a generational shift of our laptop. When all of the applications we’re using are out in the cloud, again the public cloud, then the world is just about access, and you can access those applications from anywhere you’re qualified to access them from.

So, bring your own device and as long as I can securely identify yourself or myself, then I should be able to use that item or that application. Again, be it email or be it our internal ticketing system, as an example. That’s a clear directional move that the entire world, not just identity and access management, but the entire world is moving. Saying, we no longer desire to have machine rooms in an office cabinet, or in a closet, in every office building, for every company individually.

Those are costly, they have a lot of Capex cost and it’s much easier to grow, scale, and use what you need in a public cloud offering. Starting with hybrid IAM, you get the benefit of having your existing platform being not disrupted. But you have the complication saying, now there’s this external or this additional application that your IT staff or your operations team, at least, have to pay attention. That you have internal users, Oscar and John log on to Ubisecure and you have external users, customer A, B or C logs on to our IDaaS platform. And there is extra work while corporation or organisation is going through this transition from legacy to public cloud. This transition is really hybrid IAM.

Oscar: Yeah, we can see there are many, many benefits a few, of course, drawbacks, especially complexity. If someone who is now considering, maybe already, this person made the decision that yeah, we’re going to do hybrid IAM. So, to try to visualise that – how to start the project, what happens at that moment? How to start the project? So, what are the goals or outcomes that will need to be achieved by the organisation?

John: It’s always hard to know, when starting a hybrid project is a good idea. Or replacing your existing service is a good idea. It’s best for every organisation to consider it, before they have a traumatic event like a security breach. Security breaches would be an obvious consideration or a security audit, which is one step back from a breach. Where your auditor says – hey, you’re not doing a very good job keeping your legacy system up to date. Or when you did this merger and acquisition, or integrated a business partner as B2B, or reached out to consumers or citizens as B2C, you’re starting to take on lots of liability, because you’re building a user database that’s incredibly huge. And GDPR says I should have a right to forget.

So, you have a lot of liability coming in there that you have to manage. Instead of waiting for a traumatic event, again, like a security breach or an audit event where suddenly your company is thrown into, again, a light state of trauma. Where they’re saying, I’m not going to pass my security audit next year, if I don’t resolve this kind of thing now.

We should all be kind of looking and saying, is my existing stack of software doing everything that I want? Does it serve all of the use cases that I want? Would it scale dynamically, if the marketing department said let’s go get a million more customer leads? So, could my platform scale, if we change business focus. Does it actually serve where the corporation is going, and does running internal services – is that a key function to my business?

If it’s not really a key function to your business, it’s a historical thing – you started in a B2E, so an employee or an internal enterprise-wide identity and access management platform. If you have one of those, and you’ve always had one of those because you think you need one of those, now is a good moment to actually look and say, do you really need one of those?

Can you look at Microsoft or Amazon services, here in Europe. Which are incredibly secure and incredibly compliant with all of the legislations and start to utilise hybrid to meet one of the use cases that your current platform isn’t able to do very quickly. And this for me, would be the motivation to start a hybrid project.

Is there a use case, is there a group of users that you’re not servicing very well? Is it for diversity, equity and inclusion, right? Your current UI isn’t compliant, or doesn’t look as nice as it should, or isn’t as accessible as it should be? That could be a good moment for considering, how to start a hybrid project.

Can I get a different UI as something that’s available? And again, a merger and acquisition, it’s a good kind of consideration. If you’re merging with a peer company, that same size, you don’t want to get rid of your application, they don’t want to get rid of their B2E application. Well, that sounds like the definition of a hybrid.

You need a centralised point where everybody can agree. So, there will really be obvious use cases. I think for all of our listeners, anybody who’s following this podcast, will understand that there’s a use case, that’s sitting on their desk, that isn’t being met by their current organisation and maybe can’t even be met by their current organisation.

It’s really hard for the current IT, or developer team to actually resolve and that’s going to be the genesis of the start moment of where to consider a hybrid project. Again, you don’t have to do a complete lift and shift, that’s the pure definition of a hybrid project. You can keep your existing platform, that runs, is very stable, services every use case that you currently have. And only use the hybrid public cloud service, for fulfilling those new use cases, or those difficult use cases, the ones that you aren’t currently able to do. That to me would be the starting moment for nearly all of our listeners.

Oscar: Yes, and yeah, it makes sense. And it’s a concept that actually, in this conversation with you, I’m hearing repeatedly so absolutely agree with that. How to use hybrid in order to implement, to deliver, these use cases, which are underserved by either the private cloud or the on prem. And that could be much easily and even more securely, probably more securely, delivered by using a public cloud based CIAM.

Would you also see some possible complications? Just thinking of, again, starting a project like this. Starting a project, project is having some progress – so what could be some possible complications here?

John: Absolutely. I mean there are complications when you’re putting on a second system. You do need to find a public cloud-based identity access management platform, an IDaaS service, that is secure, that is qualified to meet the use cases that you’ve identified. The reason to start the hybrid project in the first place.

So that in and of itself is work, you have to go out and look for vendors. And an RFP for an element like this can be cost to an organisation where you don’t have manpower, or time to actually cover that cost. So, you know, all of the organisations, all of the listeners should look for an IDaaS service that can make quick, easy trials.

They ought to be able to very quickly demonstrate the security additives that they bring to you. They ought to be able to demonstrate the use cases, fulfil the use cases, and it should be easily consumable for you. It shouldn’t be overly complex to try and consider how to add this layer.

There are still disadvantages – you do have extra cost. We are talking a second system that’s actually running, and any time there’s more, more systems, more anything, there’s going to be more cost. Now, if it is in your organisation’s corporate transition to go from your own servers to a public cloud, and most corporations at this point have the gradual transition to cloud somewhere on the roadmap, a hybrid IAM is a good way to start learning how to move the organisation forward. But there needs to be budget for that, there is cost inside those elements.

You will have the integration complexities, so your prem based service or your existing service has to be able to be integrated with a public cloud. Your existing applications need to be compliant to some degree, or you have to have an engine that will actually take your non-standard applications and make them standard.

Whether that’s SAML or whether that’s OIDC, you have to be able to integrate and that’s oftentimes a challenge. Knowing what your applications are, being able to do a site survey of what your applications are versus your new use cases and being able to carry out that integration is complex. That’s the reason ourselves, as a vendor, and others in the space exist. Because it is complex and there are vendors out that can help you with this, with this kind of review or integration capability.

And one of the final pieces it’s got to be latency. So, it’s not a huge factor if you’re operating inside, for example, all inside Europe here. But you need to consider – is your transaction whatever is going on or takes place with that, new user coming on to the hybrid cloud platform, way out there someplace. And then coming through, authenticating themselves with whatever public service they’ve authenticated themselves, and then coming back into your infrastructure – is your application tolerant of that amount of latency?

So, there can be gaps or difficulties, complications, even if everything looks right on paper. Even if the IDaaS service functions well, there can still be difficulties with the application or the latency in between the two clouds, as it were. The public of the IDaaS and the private of your current service, and whether that’s prem or whether that’s your server is running out on an EC2 instance in AWS for example.

Oscar: Yes. It’s definitely good that you mentioned all this, possible scenarios like latency, different potential complications. Some might happen, for instance if the company has, let’s say, office in every continent. But if that’s not the case then it’s not a complication. But there are many scenarios, as you say that has to be taken into account.

When you mentioned earlier about mergers and acquisitions, one thing that came to my mind immediately was, okay, of course. I think if there’s a merger or acquisition, I think almost for sure that a hybrid IAM project is born. It’s almost for sure that. What if one of the, let’s say there are two companies only, what if one company uses one type of cloud, like you say Azure, and the other uses Amazon Web services? They are based in, both are Cloud, they both have their identity and access management. What about this type of orchestration? Coexistence between different clouds.

John: I mean functionally, in the very early days of a merger and acquisition, you’ve got to decide who gets an account on both platforms. Right. Your IT staff are suddenly going to have two accounts, and they’re going to have to manage two accounts, one in Azure and one in AWS. That’s for simple access, administrators are always over – your IT staff are always overburdened with too many systems to run.

As a company you’re going to have to decide, and maybe many companies already have, having gone through the COVID pandemic and everybody’s starting to work remotely. But you’re going to have to decide how to authenticate a human being onto a platform that isn’t on your premises. So, the laptop isn’t plugging on to a LAN, whether that’s wireless or whether that’s cable. They aren’t plugging onto a LAN in your office building, so they’re not behind your firewall, you can’t identify them as easily. And in any good zero trust policy, you shouldn’t necessarily trust anything from out there, in the open Internet.

That’s the kind of merger and acquisition problem you’re running into where you say, I’ve got a thousand-person company on AWS, I’ve got a thousand-person company on Azure. How do I actually pull these two together? A hybrid solution can be, you know, very easy to say – well, I don’t want 100% of the applications from company Azure versus company AWS,

I don’t want to give access to everything yet. We’re only in the early days of merger and acquisition, oftentimes in an M&A, there’s staff reduction. So, you don’t necessarily need two HR departments, you don’t necessarily need all of the sales staff. That’s not always true, you could be growing, but you’re going to go through an alteration of your corporate structure. And you can use a third platform.

So that could be either on azure, or on an AWS, or somewhere else. You could use a third identity and access management platform to say – Oscar, let’s all, you and I can all, you know, identify ourselves on this third platform. And that third platform has equal access back into specific applications found within company on AWS and specific, similar, applications found on company inside Azure.

Again, it’s more complex. It’s not a straightforward kind of way, but that’s one of the easiest ways. Again, introducing a hybrid is one of the easiest ways of saying, I’m not going to immediately merge or try and slam the two corporations together. I’m simply going to set up another platform, that handles the who gets access to what, who is identified as what.

It’s actually not as strange as it sounds. Oftentimes when companies merge, you’ll see company John, company Oscar, and now we have the new company called Oscar John, right. You’ll merge the names of the company; your domains will merge and it’s a very easy transition. Saying we’re going to set up another platform. Again, could be a second one on AWS, could be a second one on Azure.

Doesn’t have to be overly complex. One of the IT departments is going to have more work, both of the IT departments are going to have access control work to do. But it shouldn’t be difficult, it shouldn’t be difficult for any company going through an M&A.

Oscar: Yes, indeed, John, we are going towards the end of this conversation with you about Hybrid IAM and for a closing question. A question that is always targeted to business leader, decision makers. What would you tell us, why should hybrid IAM be on their agendas?

John: It’s a good or a key question. It’s one that we’ve been thinking about here, inside Ubisecure for a couple of years now. Trying to resolve, how to best serve what we think the use cases are. The gradual migration from. I’ve said it a few times in the podcast – but the key point would be, a gradual migration from prem services to more secure cloud services. That ‘cloudisation’ or that migration towards cloud is going to be one of the drivers, and hybrid IAM can be an easy uptake. So, it can be a way you’re – the executive management team as well as the top end of your IT team, can start to get experience with things that aren’t their own, right. How to get onwards, how to move your company forward into a public cloud scenario.

You might already be doing this with using Office 365, and for example, not even realise that what you’re doing is, you’re taking your local Active Directory and you’re using it in a ‘clouded’ environment. Accessing all of the Microsoft applications or the Google applications, if you’re on on G suite. All the Google applications, out there in cloud, you’re not installing them on prem.

A second key driver would be for me security. Where I think identity access management is going, growing, and continuing is around the areas of security. We’ve all seen that passwords aren’t secure. You should have a fairly simple, good, memorable password that’s extremely long. For lots of, so for the big three ecosystems, those are all moving towards passwordless for the end user, which is fantastic. It makes it easy for me to log on to my phone or my laptop. Passwordless or Fido2 whichever ecosystem you happen to be most interested in.

But when you’re talking about business to business, or business to consumer, there’s the extra need of MFA. So, you need to have multi-factor authentication, you need to consider other areas of security, risk-based authentication on top of it. What your what your security stance is, how to see who is accessing what and block unneeded transactions or unwanted transactions very quickly. And moving towards a hybrid cloud again offers a good DMARC, offers a security point. Where you can lay or layover or add on multi-factor authentication for a user who is not in your system, is not identified in your system.

And probably one of the last pieces but it’s really important, especially for all of our European listeners. Is the European Union’s eIDAS project. The idea that myself as a European resident, will be able to have a digital wallet on my phone where I can conduct a majority of business with just about any organisation, public and private, anywhere on the continent. That means I can identify myself in a very strong manner, very easily, and I can chain or remain in control of all of my personal details. And that in and of itself, that kind of legislation is the clear driver that the digital world is moving.

So, you don’t want to necessarily have all of your consumers, or maybe even all of your employees, identifying themselves off their username and password and the MFA that you have on your local legacy implementation installation. You want to start considering how to move to a hybrid cloud or a full public cloud, hybrid being a good step.

So, it’s on your digital path, it’s going to be more secure, and there’s new technologies or legal requirements that are coming to your organisation. So those are going to be the three key drivers for, I think, any of our listeners.

Oscar: Yeah, definitely. Thanks a lot, John, for enlightening us about hybrid IAM. Tell us, if someone would like to follow this conversation with you, what are the best ways for that?

John: I think if anybody is interested in discussing hybrid IAM, they can reach out to anyone here at Ubisecure. We’re all very conversant on it, we – it is an opinionated field, and we’re happy to have the conversation to work through your use cases. Your specific areas of interest or your question on something that I might have said, and potentially you might disagree with. Reach out to us and we’re all available, you can find us that our ubisecure.com or reaching out to sales and we’re happy to have the conversation.

Oscar: Perfect, Again, thanks a lot John, and all the best.

John: Thank you very much, Oscar.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Petri Heinälä, Security Offering Architect at Fujitsu.In episode 85, Oscar is joined by Petri Heinälä who’s aim is ‘bringing digital identities closer to businesses and real life’. In this episode Oscar and Petri explore the importance of organisations understanding and embracing digital identities and identity solutions, including what needs to be considered when investing in identity solutions, how a lack of understanding can put the project and company at risk, as well as discussing how to get businesspeople more interested in identity.

[Transcript below]

“Because people are part of the business, so are identities.”

Petri Heinälä works in global Fujitsu as Security Offering Architect and his area of specialisation is Digital Identities. His aim is to bring Digital Identities closer to real life and businesses with common sense thinking and talking less technology language. He noticed throughout his long career that the only permanent thing is change and understanding that has helped Petri keep up with the development and changes of life, business and technology.

Connect with Petri on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Come and meet the Ubisecure team at the Gartner Identity and Access Management Summit, in London, on the 6th and 7th of March. To find out more, take a look at the Ubisecure events page – https://www.ubisecure.com/events/.

Oscar Santolalla: As our slogan says, the podcast Connecting Identity and Business. We know very well the importance of putting ourselves in business people’s own shoes when we discuss both the challenges and solutions in this identity world. So, today’s discussion is going on deep dive about that. And we have a very special guest who is Petri Heinälä. He’s working in Global Fujitsu, a security offering architect, and his area of specialisation is data identities.

He’s trying to bring other identities closer to real life and businesses with common sense thinking and talking less technology language. Petri has noticed in his long career that the only permanent thing is change and understanding that has helped him to keep up with development and changes of life, business and technology. Hello, Petri.

Petri Heinälä: Hello.

Oscar: Great having you here. So, let’s talk about digital identity. Let’s start hearing about yourself – about yourself and what was your journey to this world of digital identity?

Petri: Yes, I’ve been quite a long time in the IT industry, over 25 years in Fujitsu and I have helped multiple other industries with technology solutions during that time. And I started as a software developer and architect and then step by step, moved to service and offering development. And also, during that time moved from the local level to the regional and now global level.

The meaning of security and identities has raised dramatically during that time. And in early days in my career I, when I developed banking ATM software, I learnt that the user experience is everything and there is a strong relation in security and user experience and users, and their digital identities have a centric role there. So, step by step, identities had a bigger a role in my work and I have learnt more and trying to share my learnings to others now.

Oscar: Yeah, excellent. So, starting from developer, so a very technical role of course. And now we are going to discuss about business, the business side of this world of identity. So, I imagine a big shift through, through the to these years.

Petri: Yes, yes, yes. Very big shift. And when I talk about learning – so, there have been the failures also, more than the successes.

Oscar: Oh, yeah, I’m sure. Definitely. We want to hear more about that. So, when we discuss – why are digital identities important for organisations? In organisations, we normally think of businesses, companies, but it goes beyond that, as you know, sometimes government, can be education. So yeah, what would you say?

Petri: My learning opinion is that digital identities are part of pretty much everything and should not be treated as a separate work of identity. Even the podcast name is the word – Let’s talk about that. But I think they are part of everything. So, people, processes, and data, are the elements of almost every business function. But what we have – it was earlier people process and technology but nowadays we have to understand that business is more data driven than technology driven.

Technology is a business enabler and underpins people, processes, and data. Digital identities represent people in digital world and today, when our businesses are more and more digitalised, identities play a very important role. For example, how our customers and partners experience our business. How our employees experience their work. How smoothly our customers and employee’s engagement processes are, how we onboard them in our business and how we know our business stakeholders and enable access to them and how we ensure that outsiders can’t have access.

So, for example, these kinds of things are included in that. So, I like to keep this message as simple as possible and avoid technology jargon and unnecessary complexity. So, I say that identities – because people are part of the business, so are identities.

Oscar: Yeah, exactly. Identities are everywhere. Yes, and you say there should not be distinction that – this is correct. They are so – well I’ll call it embedded, into any process, any business, any, anything we do today. If we see from the perspective of organisations, when they need to invest. Because at some point someone will tell them, someone typically come from the IT or compliance a bit more technical side, that yeah – I need to invest in identity solutions.

So yeah, what organisations need to consider when investing in identity solutions?

Petri: Like everything else, I like that top-down approach. So, in other words holistic approach, is a good starting point. So, we’ll need to ask what our main drivers are if we invest. What we’ll want to fix or improve – is it customer user experience? What is the solution coverage – is it all customers, employees and third parties? Do we want to improve and enhance productivity, or improve security and compliance, or something else?

What is the, our main driver, what we want to do and could be the multiple of these. Then we need to find the balance between those things. For example, sometimes, user experience and security improvements are not going to get there in the same direction. So, that makes things more complicated.

So holistic approach helps us to avoid investments, to point solutions that won’t integrate easily and cause more harm than the benefits in the long run. So main thing what I want to rise is that holistic – see the big picture.

Oscar: Exactly, yeah. See the big, exactly. When investing identity comes to the table, will think of a holistic way, right? Not only trying to solve – trying to believe that it will solve a specific thing in the in the organisation.

Petri: Yeah. Yeah. Because identities are everything, everywhere. Those integrations are needed before the identity solutions. So, that means that – understanding the big picture and what the business drivers are and so on.

Oscar: Exactly, and now how we make that businesspeople from organisations, get interested in digital identity. So, what is needed to get their interest?

Petri: I like to keep the discussion in a practical level, because the businesspeople are not interested about the technical details. They are interested to, how we can help their business to success, to be more effective and profitable, to be more resilient and trusted. In the eyes of their customers and perhaps the owners of the organisation. This sounds simple, but it’s not that simple, in fact, in practice.

So, quite often the technology vendors are using huge amounts of money to make their brand and technology known in the markets. That’s very, very understandable. It easily drives a discussion in technology level I like and themes like zero trust, identity governance, or privilege access management, etc. So, these themes have multiple acronyms we are using, are not so familiar to the businesspeople. So, if we talk about like technology jargon, we put them in the, outside of their comfort zone, and they lost their interest easily.

So, they need to start the discussion in very high level, find out what are their pain points in their business. Very often these pain points are identity related and then we can focus on how we can help them. So high level and then drill down through the pain points, that are identity related solutions, how we can help them.

Oscar: Yes, it’s true, is all you say. Most of, so many technology companies that are building the products, and others who are integrating the solutions, are talking about in this jargon. Talking about the acronyms, as you said. The trendy words like zero trust, for instance, or many others that come and go. And it’s kind of like, the battle is there, in that language and the battle is there. But very few people, I think, speak in a business language, right. Okay, what are the business benefits or those innovations, because of course innovations are necessary. But I think few people are speaking in the language that businesspeople would understand.

Petri: Yeah, and I think that the trying to find those pain points, what’s the everyday problem in their business and then figure out, how – with our technology solutions and a consultancy, how we can help them to avoid those problems and to improve their processes and business.

Oscar: Yeah, exactly. So how should we speak identity to businesspeople? You just mentioned starting with a pain point, so that’s how you would start a conversation? Or what else is good for speaking identity to businesspeople?

Petri: Normally I start with a story that way – why identities are important, so they understand the relation, people and identities and that, what digital identities are, what they represent in their business. And then practical things, how you feel that your customers built your business? Do you have escalations or reclamations a lot? Or what kind of feedback you have got from your customers, from your employees? New employees, how they got their – when they started the organisation, how they got their credentials, and was it the easy to log in and start to work in the organisation and so on.

These kinds of practical things and then see how, fixing those possible problems, what is the effect to their business? How much they save money, how much they improve their customer experience and get them more business and better reputation in the market, and so on. This kind of discussion.

Oscar: Yeah, indeed. I think it’s a good approach to, to start good questions, simple questions, as the one you mentioned. You mentioned, what the customer says, for instance, and when they communicate to the customer service department, for instance. That’s already super valuable. And how the newer employees, the newest employees, they find it easy to get onboarded into the organisation, so that already could tell a lot. How things are, in terms of their internal identities in that case.

If you could now share some stories, some concrete examples, personal stories, or you have heard some examples in. For that lack of understanding of digital identity can really put in risk, not only one project in particular, but also, as you mentioned, see in a more holistic way, the whole organisation, the whole business. Could you share some, some examples.

Petri: Yeah, I have a couple. So, one example is that if the organisation is doing the investment from security and compliance perspective only. So, for example, organisation invests into privileged access management solution, but they administrators and maintenance people are using – should be used, but the reason to invest, was that they had a compliance requirement. So, they need to have at that control – who is accessing their systems and infrastructure, and investment was made only from that perspective. So, they deployed from very quick, strictly from security and compliance perspective and then in paper everything looks good.

But people who need to use that privileged access system, administrators s and maintenance people, were not informed and trained and they couldn’t access to the needed assets. They did maintain easily, because of these delays when they are accessing or they even lost, their access. This cost the service breaks and other incidents, but these maintenance people couldn’t fix, and these service breaks then affected directly to the business and their customers. So, these kinds of examples have been in – for example, in the financial sector. So still from security and compliance point of view, everything looks good. But admin people need to find a workaround to do their work and then this, very expensive solution, was bypassed.

And they continue to do their work as earlier. And then their unused solution they waste the investment, and they still have a same security and compliance problem. Additionally, they caused the business losses, because the service breaks and so on. So, this is a quite common example of how if we do the investment from the one perspective, like in this case security and compliance.

Oscar: Yes, that’s definitely a very good example, because yeah, it might feel that is the right way to do it. Right. So, you got the requirements from IT, Security, it comes from compliance. It sounds reasonable, we need to invest in that, good technology. Then make the investment, but yeah, forgot to make this holistic approach of involving everybody, who. Yeah, many more stakeholders who might be, of course not the whole company might be involved, but many more teams or organisations inside the company.

Petri: True, and then a second example is that we invest in a point solution, that cannot be integrated. So, for example, one part of organisation has immediate need to manage subcontractors’ identities and they buy the solution for that part of business. So, they buy the separate solution for that and fix the problem. And little bit later, another part of business solves the same problem with a different solution without talking again to each other. Then the organisation, for example, consolidates their internal services and they released a common service for all business parts. And it could be HR or could be ERP or CRM or whatever. And then these two business parts should use the same service and also the subcontractors and then adapting this both point solutions to the new situation might be difficult or even impossible. Anyway, it causes the delays in operations and extra costs.

So again, communication within the organisation and the holistic approach helps here, to avoid these kinds of situations.

Oscar: Yeah, exactly. That’s another really good example, right, kind of – trying to try to find a quick solution from one part of the organisation. Without thinking at that time when the decision was made that, yeah, the whole organisation should have visibility. So, if someone else in organisation needs the same, well there is already a solution so.

Petri: Yeah. Yeah. And these point solutions quite often store the identity information in the one place and then there will be several places where the identities are. So, then the consolidation of those will be another project. So that would be the costly also to clean up everything.

Oscar: Yeah, absolutely, consolidating is costly, and it’s more time because there’ll be one project to do that, in order to get that done, and in the meantime, they’re security aspects right? Having more, more isolated data repositories, that is a bigger risk from a security perspective.

Petri: Yeah. Yeah. And also, the privacy issues are there and these kinds of things. Then I have a third example. So, quite often in the organisation they are thinking that, identities are responsibility of only one department of organisation and often that responsibility is given to the IT organisation. And the expectation is that IT solve all identity related issues on behalf of other parts of organisation.

Then IT people to their job from IT perspective and then it’s also often technology oriented, because IT people are technology oriented. And then to bunch the tender resources, then IT specific, and with those resources we cannot cover all needs that organisations have. So, solution will be optimised from IT point of view and for example, issues in employee onboarding won’t be solved without human resources engagement.

So, learning here is, that within organisation you need to involve all related parts and that responsibilities is a higher level, not in the one organisation.

Oscar: Yeah, exactly. Yes. Another good example this or this different really good example, quite simple and I’m sure they happen all the time.

Petri: Yeah. Yeah. That happened quite often. And when people think that technology solves their problem, quite often it makes their problem even bigger than it was in the beginning.

Oscar: Indeed. Because yeah, you will create a new project. New project to be done.

Petri: You need to start from thinking about the people, processes and data, and then technology helps to solve those.

Oscar: Yes, super interesting, having all this perspective from the business owner, businesspeople, as I said, own shoes. So, it’s an excellent reflection we have had. So, I will ask you finally, for all the business leaders who are listening to us now, what is the one actionable idea that they should write on their agendas today?

Petri: Hopefully this is actionable enough, but people do business with people. Your business, your customers are the most important thing. And second comes your employees and other people who works for your business. Focusing on their well-being in the digital world, will accelerate your business in many ways and create the many, many benefits and simple.

Oscar: Well-Being in the in general. I mean, in the physical world or as you mentioned, virtual.

Petri: Physical world is handled quite well, I think, that’s the important thing also. But the well-being in the digital world, and that means; how their identities are handled, how they get access and how they are onboarded, these kinds of things. And I call it well-being in the digital world. So, how they experience themselves in the business systems.

Oscar: Yes, exactly. Yeah, I agree. I haven’t heard the term – well-being in the digital world. So yeah, I agree. It’s something that the organisations have to help with their employees and also in their partner, customers, to have that well-being in a digital world. Well thank you very much Petri, for sharing this very important reflection and sharing your stories. Excellent, concrete examples, that we discussed, I’m sure have been very often. Hopefully less often, it’s less and less often nowadays. But yeah, if someone would like to get in touch with you or find you on the net, one of the best ways.

Petri: Yeah, if somebody wants to discuss about this, please contact me, via LinkedIn, is a good way to contact me.

Oscar: Perfect, let’s find Petri Heinälä on LinkedIn. And again, thanks a lot Petri, for this very interesting discussion and all the best.

Petri: Thank you very much to you.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Jenny Radcliffe, The People Hacker.In episode 84, ethical burglar for hire, Jenny Radcliffe, joins Oscar to discuss the importance of educating your staff to help protect your company against social engineering attacks – including the main vulnerabilities that social engineers exploit, how individuals and businesses can protect themselves online and how user authentication technologies can help, as well as how ransomware links to social engineering.

[Transcript below]

“So, two factor or multi-factor, in any form, is always going to be a good thing. It’s better than, like you say, one thing, which can be found out or hacked like a password.”

Jenny Radcliffe is a world-renowned Social Engineer, hired to bypass security systems through a mixture of psychology, con-artistry, cunning and guile. A “burglar” for hire and entertaining educator, she has spent a lifetime talking her way into secure locations, protecting clients from scammers, and leading simulated criminal attacks on organisations of all sizes in order to help secure money, data and information from malicious attacks.

Jenny has received many industry awards and was most recently inducted into the prestigious InfoSec Hall of Fame in 2022. She has also been named as one of the top 30 female cyber security leaders in 2022 by SC Magazine, one of the top 25 Women in Cyber by IT Security Guru, and as a Top 50 Women of Influence in Cyber in 2019. She was nominated in seven categories for the 2021 Security Serious Awards in 2021 including the prestigious “Godmother of Security” award in 2020 winning the “Most Educational Security Blog” for her show The Human Factor podcast interviewing industry leaders, bloggers, experts, fellow social engineers and con artists about all elements of security and preventing people from becoming victims of malicious social engineering.

Jenny is a sought-after global keynote speaker at major conferences and corporate events and is a multiple TEDx contributor. A go-to guest expert on the human element of security, scams, cons and hacks, she has appeared on numerous television and radio shows, as well as online media and traditional press outlets, and helps create unique content for international brands and organisations. An experienced podcast host, panel chair and interviewer she hosted the live weekly cyber talkshow “Teiss Talk” for two years and is frequently asked to chair live events for clients both virtually and in-person.

Jenny’s upcoming book People Hacker – Confessions of a Burglar for Hire will be released in February 2023, published by Simon and Schuster.

Connect with Jenny on LinkedIn or Twitter.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Come and meet the Ubisecure team at the Gartner Identity and Access Management Summit, in London, on the 6th and 7th of March. To find out more, take a look at the Ubisecure events page – https://www.ubisecure.com/events/.

Oscar Santolalla: Hello and thank you for joining a new episode of Let’s Talk about digital identity, particularly for us, myself, working on companies that are building technology products to protect, secure people on Internet. It’s always surprising when we hear stories, when there are people, they just get tricked by other humans and voila, the result is – the company is hacked.

Today we’ll hear fascinating stories about social engineering, and for that we have, special guest Jenny Radcliffe. She’s a world-renowned social engineer who is hired to bypass security systems through a mixture of psychology, con artistry, cunning and guile. Jenny has received many industry awards and was most recently inducted into the prestigious InfoSec Hall of Fame 2022. She has also been named as one of the top 30 female cybersecurity leaders in 2022 by SC magazine, one of the top 25 women in cyber by I.T. security guru and in the top 50 women of influence in cyber in 2019.

Jenny is a sought-after global keynote speaker at major conferences and corporate events and is a multiple TEDx contributor. Jenny’s upcoming book People Hacker Confessions of a Burglar for Hire will be released in February, this month, published by Simon and Schuster.

Hello, Jenny.

Jenny Radcliffe: Hi, Oscar. How are you?

Oscar: Very good. Happy to talk with you. This going to be super, super interesting.

Jenny: It’s great to be here.

Oscar: Fantastic. So, we would like to start hearing more about yourself and your journey to what you do today.

Jenny: Certainly. So, I’m a social engineer and I specialise in the human side of security, and that means non-technical hacking. So, my two specialisms are psychology of scams and cons and fraud. But also, physical infiltration, so that’s the kind of red team tests that help us to infiltrate buildings and client sites for educational purposes. So, I’m an ethical burglar for hire as opposed to just a burglar for hire. And then we educate for awareness exercises and to harden the security for our clients.

Oscar: Fantastic and I understand that you started very early in your career, correct?

Jenny: Yes, it was something that – we didn’t used to call social engineering, social engineering. You know that term is relatively new and I’m older. But yes, when I was little, I had a group of cousins and family around me who looked after me, but they also enjoyed urban exploration. You know, and that means getting into empty, derelict buildings, looking around, not to take anything or break anything, but just to look around. And you learn very quickly when you do that kind of job to – a little bit about alarm systems and locks and things. But also, how people work, so that we have to talk way in or, you know, instead of breaking something to get in, a lock or whatever, it is easier to talk your way in.

So that’s where I started and pretty quickly it led to some paid work. And then with the dawn of cyber and cyber security, it was actually the cyber community that sort of told me that there was another name for it and that there were more people than me that did it. So, I’m always grateful to the cyber community for doing that because it gave the jobs. Made it legitimate, and it made me realise that there could be a business in that and a career. But I’d done it since I was really small.

Oscar: Yeah, fantastic. Super interesting and yes, you said, I don’t know how – you have said that the social engineering term is relatively new. Yeah, I hear it for the first time around 2005, I believe. So, I don’t know how long it has been for that –

Jenny: It’s nearly 20 years, Oscar. That’s the thing, time flies, but it’s still quite new, you’re right.

Oscar: Yes, yes, yes. So since then, to now, has it changed? What you would say is, what would define social engineering today?

Jenny: I think today, firstly, in the industry, in the security industry, it’s a really well-known term now because we’ve realised that a lot of the security problems that companies face and that we face as individuals come from our own human characteristics and ways of thinking. And so now it’s incorporated into lots of pen tests, but also a security awareness training for teams of for staff is so big.

And because social engineering is at the heart of almost everything, you know, so all the cyber – the breaches, the phishing, the phone, scams. A huge proportion of those are down to people being manipulated or making mistakes. So, I think what’s changed in social engineering now, is that it’s a widely known term and that it has shifted the emphasis towards humans.

But of course, humans can only do so much. And so, we need tech as well to do kind of the heavy lifting, to block as much as we can and to stop people being in a position where they have to make a decision as to whether to trust someone or click on a link or open an attachment. So, it’s changed that it’s more widespread but also, it’s now in a nice marriage with technology, which is, which is a good thing.

Oscar: And as you say, your story – you started the with like a playing with entering into houses, abandoned housing, some property. Then it became like a real job entering into properties. Now you have moved to, from physical, good doing these physical attacks, intrusions. To online attacks, you are now online hacker, as that’s my understanding. So, how enjoyable has it been for you, this switch?

Jenny: I mean we still do have to do some physical security. I do less of it now because I’m older and I have a team that, that would do that instead, that I put together a lot of the time. But I still do a few of them because there’s nothing so, so good at proving to a client that there are some issues, than showing them how something was done, you know. So, we do what the bad guys would do, up to the point of harm. So, we still do some of it.

But you’re right, a lot of the job now, did move online because so much of what we all do is remote. And so, the persuasion techniques, the influence techniques, the look – you know, the understanding of human psychology, is very important in terms of what happens with phishing emails or with business email compromise, scams, and breaches. So, we do a lot of those kind of, crafting those messages to show how criminals might do that. And then it’s part of education and awareness to say, well, this is how you might be caught, and this is why it works. So that if people understand how it works, they might be able to protect themselves against it. But you’re right, so much more of it now is online than it used to be. But I don’t think the physical side will ever go away completely.

Oscar: And is it still fun doing that?

Jenny: It is fun. You see, that’s the other thing Oscar, I’m always going to tell you I still do it because it’s still fun. It’s more fun than sitting at a computer but it’s scary as well. Whenever I do a talk or an interview like this, you know, I get lots of DMs from people, lots of emails saying I want to do that job. Can you train me? Can I work with you? Because it does sound like fun and a lot of the time it is quite fun. But it is also dangerous and it’s very hard work. So, to do it properly and professionally requires a lot of research online, and a lot of planning. But I think, people sometimes think, you know, we just tailgate and walk in. And we do that sometimes, but mostly it’s a lot of planning.

Oscar: Yeah, a lot of planning, that might not be the funnest part.

Jenny: No, it really isn’t the fun part, but it’s necessary to do the job properly. I think that’s the thing that, I just need to emphasise in the interviews I do, is that it is a professional part of security. It’s just that it sounds and is more fun than the hours we all spend looking at logs and, you know, sitting at the keyboard. But yeah, it’s still a professional part of the business.

Oscar: Yeah, absolutely. You already mention email, which seems to be – that’s my impression from hearing so much – that it might be the top way of getting hacked today and you know better that. So, why email is still one of the ways to get hacked? Even though there are so many advanced email protections, so I hear for instance, there is nowadays advanced filter, an artificial intelligence protection. A lot of these things that are being added to the mail systems, email system. Yeah, but besides that, there’s so much being hacked.

Jenny: First of all, we all receive so many emails every day. So, email is a huge part of our professional and personal lives and that means that we are – it is necessary for all of us to click on links and open attachments and join conversations with people that we’ve never met before, legitimately, as part of business. The technical tools that help with blocking malware and, you know, emails that carry payloads or that will take us to sites that carry payloads, that’s great and it does block a lot of things. But a technical solution has to be looking for something technical to block, the reason emails still get through and are so effective in social engineering attacks, is because that email may not necessarily contain a malicious file, but it might be the opening of a conversation and that’s difficult to detect with technology.

So, if you look at something like business email compromise, which is when, you know, a criminal will infiltrate someone’s email, pretend to be the boss or the finance director or someone we know and ask them usually to transfer money. That will not necessarily have any viruses or malware in that email. But it’s still an attack because they’re asking that person to do something criminal. The problem is, is it’s difficult to detect because it’s words, it’s language, its persuasion, it’s influence. And, you know, the criminals know that, and they know if they get the tone right, if someone has not been trained properly or if what they say is something that resonates with the target, that there’s a chance of that getting through.

So, I think the technology is, you know, amazing these days to help us with emails and to block some of this malicious files and malicious emails and we need it. We need that tech to do it, so that when we see an email that does get through. We’ve not got 15, or 50, or 500 emails to make decisions on whether or not to follow them up and to engage with the with the person. We’ve only got a few and it’s only on a small amount of emails that we really need to worry about people making their mind up about.

So, the tech is brilliant because it’s preventing so many things from getting past. But we still need humans to understand what a malicious approach looks like. And that’s where the awareness and everything still comes into it because they still get through despite the technology.

Oscar: Yes indeed. As you said, if they, if that first email just passes, doesn’t have anything of, anything malicious at all, it just passes that level of trust – that okay, I trust in this email I continue the conversation in.

Jenny: But you know, just to say is – so for example there are systems and there is technology in place that for example, will block key words as well. So, it might block invoice. And so, I had a colleague who hadn’t been paid by a client and when they followed that up, it was because his email with ‘invoice – to be paid’ as the title, their sort of filters caught that and stopped that getting through. But that was a legitimate email, and this is the problem, right?

The problem is, is that, of course, criminals are going to use language that we need to use to carry on with our business. And sometimes we have a sort of a false positive and a genuine email get stopped. But actually, it’s probably better that that’s the case, than have all the bad ones get through, you know.

Oscar: Yeah, certainly. That’s why, as you mentioned, education many times is focus key of this helping us. If you move to authentication – thinking of a password. A password can be stolen there, you know, there are many ways to steal a password, if the protection is only based on password. Okay, you steal a password, and you get in. So, it’s hacked.

But nowadays with more advanced technology standards, multi-factor authentication you have here, of course, WebAuthn, Fido. These more advanced authentication techniques. Are people less vulnerable, what would you say?

Jenny: Yes. I mean, I think technology helps massively, you know, and things like, let’s say like FIDO and WebAuthn. All of those things are an extra layer, and the more layers that a criminal has to get through, the harder their job is and that’s what we want. But I think for me, the sort of physical security keys that are in the marketplace, they have a sort of a another positive to them, which is – if you are using one of those things every time, you need to plug that into your machine, every time you touch that, it’s reminding you that security is something we need to be aware of.

So, I love the idea – I think anything is bypass-able, you know, because we can always get the person who’s holding the key or using the technology to go around it. They can be persuaded. But in and of themselves, it’s an extra different type of security that people are using and therefore I’m all for it. I think it’s a great, a great thing to do.

Nothing. Nothing is bullet-proof, but it’s a very good start. And two-factor or multi-factor authentication, is one of the things that I urge everyone to talk to teams about, to talk to their families and people outside of the business about. Because although it can be bypassed and got around, it would stop an awful lot of individual attacks and sort of misery. So, two factor or multi-factor, in any form, is always going to be a good thing. It’s better than like you say one thing, which can be found out or hacked – a password.

Oscar: Yeah, exactly. If you see from the perspective of companies like Ubisecure, and many other companies that are building technology products, security products, identity products. What is your best piece of advice for the ones who are building these, these tools, these cybersecurity tools?

Jenny: My advice would be, you have to make them easy to understand and use, right? It has to be easier for a person, a customer, to use your security product, whatever that is, than to get round it and forget about it. People, if something is difficult and it’s easy to do the wrong thing, they will always do the easy thing.

So, people need to understand how to use them. It needs to be as straightforward as possible. And then we need to tell them the why. You know what this prevents, why it matters and why it’s important. And then we need to trust that they will do it, you know, and check-up occasionally, of course. But that’s the key. The key is – make it easy for them to do the right thing and let them understand why it’s necessary.

Now, let me give you an example of something that’s not always good. If we look at one of the things, we tell people in security is to use VPNs, right? Because of course, we know in the business, in the industry that a VPN sort of protects your traffic to the Internet. So, people can’t do man in the middle attacks and things like that. And again, not completely impenetrable, but very good.

But if you ask people and I just mean normal people on teams, not normal people in the street, if you ask them about what a VPN is, it’s hard for them to explain what it does. But then also when you load those up onto your devices, onto your phone and your laptop, you know, this often problems, technical problems, VPN sometimes block websites people want to use. And I’ve had that myself, where I had a VPN on a phone I used, and I couldn’t use the phone because it was so secure that it was stopping me from doing normal things like internet shopping and banking. So, in the end you switch it off and this is the problem is unless people can use that easily, they will just eventually just ignore it.

So, my advice to anyone who makes this type of product and provides these services, is the most important thing is the UX, it’s the user experience every time. Because then they will adopt it and eventually hopefully become advocates for your product. But if you make it difficult, they will abandon it.

Oscar: Yeah, that’s the worst that can happen of course. That you have the best possible tool, but people abandon it because, as you said, it’s not simple enough.

Jenny: Right.

Oscar: Besides email, email phishing. I think, one word that comes up all the time, when we talk about, we hear about hacking breaches is, ransomware. So, what is the link between social engineering and ransomware?

Jenny: So, there are really two, I guess. Ransomware obviously is, gets onto someone’s system becomes a problem through the social engineering methods that we’ve already talked about. So often, these things start with an email, or they start with access escape because someone doesn’t update software. And then, you know, the attackers get onto the network and become, you know, and sort of sleep on the on the network for a while and spy on you and then a ransomware attack is then initiated.

But I think the real link to social engineering is, the key emotions that are used in ransomware, even if no conversation happens between the criminals and the target. Because what ransomware really depends on, are the things that malicious social engineers use all the time. You know, fear and shame are two of them.

So, you know, we’re on your network, we’ve got your files, we’re going to delete them or release the data. Well, people will – that’s a scary thing for a business. It makes your emotion high, your fear high and also, that fear that, you know, this will affect our brand, we’ve missed something on security, we’ve been sort of lax on security and, you know, that will be a problem. So, it relies on a very human emotion in order to make people want to comply with that.

And then there’s that very clear business decision of, you know, do we pay this, because it’s cheaper and easier to pay it than to go through all the problems that might cause if we don’t pay it. And in security, we always say, don’t pay, but it’s not always that simple. For a small company, they might be covered by insurance, pay the ransom and be able to get on with their business in a day’s time, which is a tempting thing. So even though we in security know you should never do that, it’s hard for people in reality to make that decision sometimes.

And it also relies on a big psychological tool, which is urgency. So, you know, typically ransomware, you have a time frame in which to pay the ransom. Usually, they add sort of psychological elements, like you will see counters and, you know, messages telling you the time is running out. And all of that kind of stops us making rational decisions because it’s hard to make good decisions when you’re worried and frightened and anxious about the business and, you know, the time is the factor.

So, it’s important for all those reasons, I always say that ransomware is a big part of social engineering – well, social engineering is a big part of ransomware. In as much as however distant and remote the attacker might be, even if there’s no conversation, the attack, by its nature, is a social engineering attack. It’s putting a human being or a group of human beings under pressure to do something that is not in their interest and that makes it pure social engineering.

Oscar: Yeah, very interesting that viewpoint, you talk about. The ransomware, it shows why many people are unfortunately paying and that this type of criminality continues. I’d like to hear how, I guess some time you have been – someone has tried to social engineer you, I guess. If you can tell us if that happens, if that you have ever felt that you were close to, to fall and how you protect yourself normally if someone wants to attack you this way.

Jenny: I get lots and lots of attempts at social engineering. Obviously, because it would be great to catch me out, as I’m the person that talks about it, probably, or one of the people that talks about it the most. It would be great. So, I get lots of attempts that are very obviously social engineering and particularly the ones that use all my advice or examples I give in keynotes. That’s actually quite strange.

I’ve been caught out a couple of times, one time was, I was at a conference and there was the guy at the conference who I knew, and his wife was pregnant, and she was heavily pregnant. So, she, you know, he was sort of on standby to go home in case anything happened. And he came to me, and he said, my phone’s died, I got a call from my wife, can I borrow your phone? I need to call straight back, because I knew both of them. And then he took my phone and took a picture saying I hacked Jenny’s phone, you know. But, you know, he’s dead now. No, I’m joking. So, there was that.

But no, I get quite funny attempts from kids. So, I think children sometimes see me on social media, maybe. I’ve done a few sorts of shows on social media that – I did an interview for LadBible, which is a quite a big platform. And someone had chopped up the interview and put it on TikTok and of course all the kids watch TikTok more, more I think than adults, right. And I started to get these emails that were, that were really quite funny. So, it was like – I got some that were just threatening, so it was, but really obviously a kid.

So, it was like, we’re going to get you through social engineering, click on this link and quite a lot with QR codes that led to the Rickroll, I got those. Which we open on our dirty machine in the office that we can open things on, and they were quite funny. And I knew they would be Rickroll’s before I did it, but still. I get things like that, and I also get things that try flattery, you know, so, we’re such big fans, and we took a photograph of you at an event, do you want to see and there’d be a little link, you know. And I kind of, when I know it’s just people sort of trying to catch me out and it’s not really malicious, it’s sort of a joke because it’s me, I don’t mind that.

And then I think the rest of the time when they are serious attempts by people who are criminals, I hope I catch most of them, but I would never say I caught all of them. None of us ever do. And that’s really the message is always – it doesn’t matter who you are, if it’s the right script at the right time, we will all fall for it. However alert you think you are, we’re all human and there are times when we just – our guard is down. So, people do try all time, in person I don’t think they try very much, I think probably I would know they were nervous, you know, I’m just thinking of a few times. And they probably know that. But you know, again, you can’t always say it.

Oscar: Yeah, super interesting. Yeah, of course, everybody has to be well protected and as you said, it’s a lot about getting educated, really understanding, how real hackers are acting.

Final question, for all business leaders that are listening to us now, what is the one actionable idea that they should write on their agenda today?

Jenny: So, I’m asked this a lot, you know, and there’s lots of advice that we give. We can talk about the red flags of social engineering. You know, I mentioned a couple of them, you know, getting your emotions high, urgency. We could talk about cyber hygiene, we’ve spoken about that, you know, have multi-factor in place, use good tech.

But the key really for me, the thing that I want businesses to do is – you’ve got to know your people better than the bad guys. And what that means is, a really serious attack on a business will look across all of your teams, all of your operations, your network, your architecture, and they will really dig into that to find the best way to get to you.

And if we understand that people are probably the easiest way in, a lot of the time, what we have to be able to recognise is when someone is behaving strangely or has done something wrong – and that means a culture of acceptance and of understanding and of education. So, we need to know those people, that work for all of us, have to feel confident that they can come to you and say, I think I clicked on a link that might be malicious. I think I forwarded money to someone that might not be the finance director or the CEO. I feel that – I’ve been talking to someone on social media and now I’m not sure whether they’re genuine. So, know your people well enough so that they feel they can come to you and not get into trouble for falling for a con by professional con artists.

And if you can put those things in place, we know when someone’s worried, we know when someone is scared or when someone has made a mistake, then we can help prevent it. Because what criminals are relying on, a lot of the time, is isolating their target within a business and making their target too scared to really ask for help and to tell people this might be an issue.

And that’s something that is not easy, because it requires – especially in a huge company, that means line manager level, you know, your level, knowing the people, knowing your team, looking if someone is stressed, helping someone if they’ve got issues outside the workplace, and also knowing if their behaviour is different online and in-person as well, you know, is there a break in the pattern? Are they downloading files, are they being blackmailed into helping someone from the outside?

And to do that’s not easy. It requires time and focus and a genuine interest in your people, but it doesn’t require necessarily lots of money. And I think that’s the thing. I would say, do not think you can throw money at the problem, and it be fixed. Get good technical products, good technical services. Make sure that you have the best technology that you can afford to protect your business, but at the same time, work in harmony with your people so that they are the eyes and ears for your organisation and for their security.

Oscar: Yes, I couldn’t agree more. It’s a really very good reflection and thanks a lot, Jenny, for telling us your stories. Educating us a lot about social engineering and getting protected. Please tell us, how people would like to know more about yourself on the net, how they can find you.

Jenny: It’s been such a pleasure chatting to you Oscar. If people want to find out more about me, I’m known as the People Hacker online and that’s Jenny Radcliffe. You can find me mostly on LinkedIn and Twitter and Instagram and my website’s humanfactorsecurity.co.uk and as you say the books out in February 2023, and it’s called People Hacker and you should be able to find it at most, at this point, in Europe. So, the EMEA countries; Europe, Middle East and Africa. The distribution’s a little bit weird, but you can definitely get it in the UK and then soon to be the US and further afield. So, if you keep an eye on my post, you’ll definitely see me shout about that.

Oscar: Excellent. Definitely will read your book. Fantastic.

Jenny: Thank you, Oscar.

Oscar: Again, Jenny. It was a pleasure talking with you and all the best.

Jenny: Thank you, Oscar. Goodbye.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Dr Mark van Rijmenam, Founder and Future Tech Strategist at The Digital Futures Institute.Dr Mark van Rijmenam joins Oscar to discuss the importance of Self-Sovereign Identity in the Open Metaverse – including his definition of metaverse, derived from his interviews with entrepreneurs for his latest book, the motivations for entrepreneurs to be building assets in the metaverse, the role of identity and its importance in the open metaverse.

[Transcript below]

“I think it’s crucial that we own and control our own data, that we control our own digital assets, and that we control our own identity and reputation.”

Dr Mark van Rijmenam is The Digital Speaker. He is a leading strategic futurist who thinks about how emerging technologies change organizations, society and the metaverse. He is the founder of the Digital Futures Institute, with a mission to ensure a thriving digital future for business and society. Van Rijmenam is an international keynote speaker, and 5x author. His latest book is Future Visions, which was written in five days in collaboration with AI.

Find his articles and books at The Digital Speaker.

Connect with Mark on LinkedIn or Twitter.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Come and meet the Ubisecure team at the Gartner Identity and Access Management Summit, in London, on the 6th and 7th of March. To find out more, take a look at the Ubisecure events page, www.ubisecure.com/events/.

Oscar Santolalla: Hello and thank you for joining us to this first episode of Let’s Talk About Digital Identity in this New Year, 2023. And we want to start hearing very futuristic things about a future, very futuristic. We have a really amazing guest to start this year. Let me introduce you, Dr Mark van Rijmenam. He is the digital speaker, he is a leading strategic futurist who thinks about how emerging technologies change organisations, society and the metaverse.

He is the founder of the Digital Futures Institute with a mission to ensure a thriving digital future for businesses and society. Van Rijmenam is an international keynote speaker. He is five times author, and his latest book is Future Visions, which was written in five days in collaboration with artificial intelligence. I definitely want to hear more about that. Hey, Mark, welcome.

Dr Mark van Rijmenam: Thank you very much Oscar for having me on the show. It’s great to be here.

Oscar: Yes, definitely our pleasure. Well, happy New Year.

Mark: Happy New Year to you, too.

Oscar: Yes, we are still in the beginning of 2023.

Please tell us about yourself and how – what was your journey to this world of identity, metaverse and everything that you are doing today.

Mark: I’m sure it sounds good. Well, obviously you already gave a very nice introduction, but I’ll add some things to it. So, I’ve been a keynote speaker for over a decade. I am a strategic futurist, so it means I really think about emerging technologies, and I try to understand what these technologies, these emerging cutting-edge technologies mean for you and me, for organisations, for society, and how we can benefit from them.

Because these technologies are constantly evolving. So, I’ve been doing this for over a decade. I’ve been speaking all around the world about that. I’ve been, as you said, five books. And I really try to always practise what I preach. And so that means that I – when the pandemic hit, I created myself an avatar, created myself as a hologram to deliver keynotes as such.

I’m currently working on building a digital twin of myself to understand – what are the consequences of creating a digital twin of yourself? A synthetic human, so to say. And how does it influence whatever we do? And I am very much involved in, you know, big data blockchain, artificial intelligence and the convergence of these technologies, which we are all coming together in the metaverse of, which was my fourth book, Step into the Metaverse, where a big part of that is also focused on identity. Because I believe that the metaverse will unleash a sort of a Cambrian explosion of identity, and it’s very important how to deal with that.

I’ve also been involved in a start-up, which unfortunately failed, but that’s the start-up life. Focused on identity, focused on fighting misinformation with reputation-based system. It’s very challenging to do anything in this space because we are very much used to a certain identity system that we have in our society. And shifting that is quite challenging, but I’m sure we’ll get to that during this episode.

So yes, that’s basically what I do. And yeah, indeed, my latest book, Future Visions, written, edited and designed by AI, I’m sure some of you have heard of ChatGPT, which is taking internet by storm. And the moment it arrived, I thought, I’m going to grasp this opportunity to write a book with it.

So, I literally wrote it in five days, and I didn’t change a word. I didn’t – I maybe like five or ten words that I changed myself, but the rest is exactly written by AI. And it was an experiment for me to understand what is possible with off the shelf technology, and it’s quite surprising how good it is, but also how not good it is. It’s not the Holy Grail. It’s fantastic technology, but there are definitely some caveats. And it was a fantastic experience to do.

Oscar: That, that sounds very interesting. So, you wrote a full book just using the ChatGPT that many people are talking about these days for the last, at least, last two months, I would say – quite a lot about that. And yes, super interesting journey you have had.

One of the last things you said is about the misinformation that – every time I hear that word like, we really have to do more about that – and it’s not easy, right? It’s definitely not easy.

That will come also on the metaverse, which is actually the main thing we’d like to discuss with you. So, it’s skimming through the pages of your last, second book, Step into the Metaverse, How the Immersive Internet Will Unlock a Trillion Dollar Social Economy. So, I read part of your book it is very interesting, so let’s go into that – to start with a common idea – please, could you give me your definition of metaverse?

Mark: Yes. That’s a very good point to start because the metaverse is a very, very abstract concept which many people have different perspective of what it actually is. And for the book I did about 100 in-depth interviews with the stakeholders who are building the metaverse. I did about 150 surveys, and interestingly enough, I got like almost 250 different definitions of what the metaverse is, which sort of shows you how difficult of a concept it is.

I sort of derive my own definition from this, and to me, the metaverse is the next iteration of the internet, it’s where the physical and the digital world are converging. And where the physical moving to the digital the digital moves into the physical. Now, that’s a lot of information there. And so, we can briefly unpack it a little bit.

So, if we start with the first one, you had a physical move into the digital. Basically, this conversation that we have, you could argue, is part of a very, very early phase of the metaverse because you are physically in Finland. I’m physically in Australia and we are digitally connected through our computers, and we have this conversation. It’s a 2D connection. So yes, our screens are 2D. These are not immersive.

But you could argue this is part of the metaverse. Other parts of the metaverse are, which I think are very, very important, is, for example, digital twins now. Where we create a digital replica of a physical asset that we can interact with in the digital world and we can just monitor it, or we can actually interact with it and then any changes that we make in the digital world, we will have an effect in the physical world. And that’s also part of the metaverse. And often people think that virtual reality is the most important part of the metaverse, but to me it’s only one channel to access the metaverse in an immersive way.

The other part, the other channel so to say, is augmented reality, where basically which means that we bring the digital into the physical world. I think that part is going to be much more important and much bigger because it allows us basically to create like infinite layers on top of reality. And this layer can be for entertainment, so you can have a flying purple dragon above the Opera House here in Australia, or you can use it to understand when you’re driving to have, augmented reality where there’s a parking space available or whatever you can come up with. And I think that’s also a very, very important part of the metaverse.

I think in the next decade or so we will see that computers will disappear, smartphones will disappear, tablets will disappear. They will all be replaced by headsets at first, augmented reality headsets I think, they will become a miniaturised, very sleek glasses that you can wear. And you don’t need a laptop anymore, you don’t need a smartphone anymore because you have it all in front of your eyes.

So, the metaverse is the immersive internet, and this internet will become as pervasive as the air we breathe. And it will mean it will move from making a conscious decision to go on the internet – so, if you want to go on the internet today, you have to grab your phone and start doing something. And it will switch to being “in” the internet. So being fully immersed and being part of the internet. By the internet being as pervasive to the air we breathe or energy that we use. This internet will be 3D, and that’s much more in line with what we humans are used to because we are 3D humans.

So, we thrive in a 3D environment much more so than a 2D environment. So that’s sort of what’s going to happen. There’s a lot of information, but in short, it’s where the physical and the digital world are converging, creating this immersive 3D internet that we can connect with and can be part of.

Oscar: Yes, you said that for writing this book on the metaverse. You have interview at least 100 of entrepreneurs who are building some their metaverse versions or some product related to the metaverse. So, I like to know from those conversations that you have had – so what has been their main motivation, why they are spending their time building those and not something else. So, what are, let’s say, the main motivation did you find in common amongst these entrepreneurs?

Mark: Well, I think it’s a very good question. And I think what I noticed is that everyone that I spoke to, understands that the metaverse is the next iteration of the internet. It is the future. Whether we want it or not, whether we believe in it or not, it will define the next ten, 20, 30 years, if not more.

And so, any smart entrepreneur should dive headfirst into that because if you would have done that in the 1990’s, you would have been, you know, had a good chance to be the next Amazon. And that’s what I think is happening here because first we had one, then we had like sort of the mobile app with the launch of the iPhone. We had the social web, with the launch of all the social media platforms and now we move to the immersion web.

So, there’s a ton of work to be done. There’s a ton of money to be made because, you know, several banks and a major strategy consultants say that by 2030, the metaverse will drive between 5 and 13 trillion dollars for the global economy.

Personally, I think it’s going to be a lot more, simply by looking at the impact that the internet had already on our society. So, it makes just good business sense to dive into the metaverse to see what you can contribute to this next iteration of the internet.

Besides, firstly, I think that the metaverse is a fascinating environment to work in, because it’s all novel, it’s all magical, it’s all – all the things that can become true in the metaverse. There are no laws of physics in the metaverse, so you’re not – we don’t have any restrictions on what we can build in the metaverse. And I think we can create this magical world, this magical virtual world, with these magical augmented digital experiences that are not possible in the physical world. And I personally find it fascinating.

So, I really enjoy being part of that. And I think over time when – the more we step into the metaverse, because mind you, the metaverse is still a few years out. The more a society steps into the metaverse, the more people will experience this magic as well.

Oscar: So different motivation. It sounds to me – it’s most like, I know there will be this new paradigm so that the technology is coming anyway. It sounds like that, and the entrepreneurs have to be there. Sounds like those are the main motivations.

Mark: Yeah, I want to add one to that because it’s – so my book has been, I’ve meant it as a blueprint for an open metaverse. And an open metaverse is really focused on – how can we create a metaverse that’s there for us, for you and me, consumers. And that’s owned and controlled by us and not necessarily controlled by big tech or very, very tiny elite who controls whatever we do online, which currently the current internet is like that.

We don’t control our own data; we don’t control our own digital identity. The internet is basically controlled by a handful of very, very powerful, very big technology companies. Now, with the metaverse, with the amount of data that you create in this immersive internet, which will be 100 times more than we do today, if not even more. I think it’s crucial that we own and control our own data, that we control our own digital assets, and that we control our own identity and reputation. Because we don’t want to live in a world where the Zuckerberg’s of this world can decide whether or not you have access to this immersive internet or not. And I think that’s something really, really important.

Of course, we have to build it in the correct way, because you know, with building something decentralised also come a lot of challenges. But that’s what I did for the book and most people that I spoke to, they tried to do that as well. So, for a lot of people that I spoke to, they’re driven by this quest of building an open metaverse that’s there for us. And to change the paradigm from a centralised internet to a decentralised.

Oscar: Yes, that’s something I read in your book, the concept of the Open Metaverse. So, it’s great that many of these entrepreneurs have that in mind. So, something else that you just mentioned is – it’s about, of course, identity. Again, thinking of the companies who are now building the metaverse. How in top of the mind is digital identity? So, it’s a component that they are thinking every day, like yes, this is part of metaverse or something that is neglected? So, what would you say?

Mark: Well, I think that the digital identity is a very, very important part of the metaverse. And it was also confirmed, to the very people that I talk to. Simply because, as I mentioned in the start in the metaverse, we can be whomever we want to be, whether that is, I don’t know, a flying dragon, whether that is a walking piano, whether that’s a talking mushroom, it really doesn’t matter.

You can literally be whoever you want to be. And identity in the metaverse is really, really important, much more important than we think today. And if we ask Generation Z, those born after 95 or Generation Alpha, those born after 2010 to them, and this has been done to them, their digital identity is as or even more important than their physical identity.

Let that sink in a bit because that’s the paradigm shift. Your digital identity being more important than your physical identity, completely shift of mind and mindset. And therefore, we see that in the metaverse, digital fashion is really important because just like in a physical world, you want to dress a certain way to showcase who you are, to display your identity. You also want to do that in the metaverse. So digital fashion is a multibillion industry of for people to do that.

Now, what research also has shown is that the moment people can be whoever they want to be in the metaverse, they start experimenting with their identity. And there’s research that people switch gender just to understand what that means. There’s also research which showed that if you are an introvert person in the physical world and you use an extrovert character in the metaverse or in virtual reality, and you play with that character for a couple of hours. Then you will continue to display those extrovert characteristics in the physical world afterwards. Fascinating I think, how that works the digital, our digital identity can affect our physical identity.

So now, of course I think when we talk about identity in the metaverse, we also have to think about the challenges that come with it. Because if you can be walking a piano for that matter, how do I know that that walking piano is Oscar, you know, how do I know that? How can I be certain that I’m not dealing with this with someone else who has stolen your identity?

So digital identity or in this case I would argue Self-Sovereign Identity is very, very crucial for a metaverse, especially in open metaverse. Less so a closed metaverse, which is controlled by companies because they can do your identity check and they can verify that you are a real person. Your identity can still be hacked and be stolen, but that it’s more easy to control it.

That’s also has problems to it. In an open metaverse self-sovereign identity is really, really important because it allows us to control who has access to our data, for how long, to which data, and have full control over assets and our identity. So, I think if we think that identity is important on the current web, we have to think twice because it will be a lot more important in the metaverse. And for many millions of kids and teenagers that digital identity is already more important than the physical identity.

Oscar: Yes, that thing that you just said for a second time. It’s very, very important to think about because we need to protect those identities. Because the big bunch of the people who are going to be in when metaverse is more ubiquitous, as we call it, in the next 10/ 20 years. Will be using heavily, and we have to protect those, those identities.

Another thing you mentioned is if you have some of these, what example? Like a flying dragon, for instance, Oscar is a Flying Dragon in some metaverse. Right? So, people who are inside a metaverse will see the Flying Dragon, my name, maybe. But how do I enter to this metaverse? So that’s a point that many people don’t think right? I should have been, call it, logged in or authenticated properly in order to enter to that that metaverse.

Mark: Well, that’s a major technical and cultural challenge that you just mentioned, because what we don’t want is that if I go to Fortnite and into Roblox, into Decentraland and into the sandbox and to whatever other virtual world. That I every time I have to recreate my flying dragon, every time I have to create a new account, just like we do in the real world, actually.

So that’s not what we want to happen. Now in order to achieve that, we need interoperability. So, you need to be able to have an identity that you can take to a place just like you take your identity to a pub or a restaurant or club or whatever, in the physical world. So, we need to have that same approach.

But there are some companies are working on this. Ready Player Me is a company that’s building an avatar tool so that you can create your avatar ones and then you can use that avatar in over a few thousand platforms already. So that’s a start. It’s a centralised company’s nothing self-sovereign identity with it, is nothing blockchain, nothing decentralised. So, you actually don’t control your identity, but at least it’s the first step that you create one account to do this.

But we already have that in the 2D world, which is called a Facebook login in or a Google login, you know. Login with Google account, login with your Facebook account, which by the way, I would recommend not to do. Because yes, it is easy, but it also means that your data goes to Facebook, goes to Google, and they have even more access into what you are doing. So please don’t do that. I know it’s easy, but just don’t do it.

And so from that perspective, your identity is really important and we need to be able to build this interoperability so that you can take your avatar, your identity, that you create – yours, your flying purple dragon that you’ve created to all these different platforms and all these different platforms have different graphical requirements, different computational requirements, which makes it really, really challenging to do that.

You know, if you go to platform A, it might be hyper realistic and your dragon looks really, really hyper realistic, but then you go to a platform like Minecraft or Roblox is very, very blocky, and how do you adapt that? How do you have that one identity work in both worlds? That’s a massive technical challenge, that’s definitely not solved yet and that does require probably quite a bit of work to achieve that. But yes, what we need to have is interoperability, that you can take your avatar, you can take your flying dragon, and you can fly from one world to the other.

Oscar: Yes, exactly. Now mentioned flying from one world to the other. How open these companies, like Fortnight, say Disney or whichever is the other, Minecraft, no? Are they open to that interoperability? What do you feel that they’re open, to have that? Would they prefer to have it closed?

Mark: Well, most likely they will prefer to have it closed, which I think is a very short-sighted approach. Yes, having a closed network offers you a lot of value. We can only have to look at a mobile, a mobile messaging. WhatsApp was sold for $19 billion in 2014 for a reason because it’s a closed network and you can’t send a WhatsApp message to your signal or to your telegram.

In Europe, that’s going to change with the new laws. Investor rule probably not. So, we are very much used to not having this interoperability because for such large companies it offers a lot of value. If we do have that interoperability for society, it brings a lot of value.

We only have to look at email, we are able to send an email from a Gmail account to a Hotmail account. Imagine that would not be possible or imagine that we, we don’t have interoperability for websites that you can only build a website for, I don’t know, Chrome and then you have to build a completely new website for Internet Explorer, and you can’t just switch between. Imagine what that would mean for the world, it would just ruin the internet.

And email is so successful because I can use Gmail, you can use Hotmail and we can communicate. So, I think it’s very short-sighted for these companies – I understand why they think like that, but I think it’s very short sighted and very selfish almost, to work on value extraction instead of value creation for society.

So, interoperability will add a lot more value to all these platforms. If you really make it easy and make it nice and easy for people to come and also leave, you will see that if you offer the best product, the best service then people will still come, and you will still make money. It’s a different approach, it’s approach from a short-term share approach to a long-term societal stakeholder approach.

And I think as a society, we need to make that shift from a short term to long term. And I argue and I call every organisation to, to make that shift. However, I’m also a realist and I know that that’s not very likely and that most likely regulation will have to step in to force these people because they probably will not do it by themselves.

Oscar: Yes. I couldn’t agree more with this point about that, and I hope they are listening to. They are listening to Mark and everyone else who is.

Mark: I hope so too.

Oscar: You already mentioned self-sovereign identity. Would you say that this is going to be the dominant paradigm in the metaverse?

Mark: Well, I hope so and I think it should be, because it’s a way that we control who has access to our data. And the best example here is, of course, if I go to pub and I need to show that I’m over 18 currently in the world, I have to show my driver’s licence. On my driver’s licence there’s a ton of information that’s not relevant for the question. Are you over 18, yes, or no? Which is a, just a very simple question and a self-sovereign identity allows, would allow us to answer that question, that we can trust, without providing all that information. And I think as a society, I think we should want it.

We should be able to live in a world where we are not controlled by a centralised entity because generally centralised entities, they corrupt or they get if they become too powerful – in terms of countries, democracies change to non-democracies. So, I don’t think that’s the right direction. So, for me, for a humanity perspective, I think a self-sovereign identity is the best approach.

Now obviously there’s also a lot of challenges to it because if you own and control your own digital identity and it works with the private key and public key, and your private key is 128 bits, whatever, or even ideally more whatever. And you’re going to lose this long string of numbers because people lose passports and smartphones all the time. How are we going to deal with that?

That question hasn’t been answered yet and people will lose their private key. And if your self-sovereign identity is everything that you do and you lose it, then you are in really, really deep trouble. So, we need to solve that.

It hasn’t been solved and we need to – because it’s almost an oxymoron. You know, I am I going to store my private key with a centralised entity. So, then your private key is, you know, your self-sovereign identity is no longer self-sovereign.

And we saw that with that with the collapse of the various crypto exchanges, if you don’t own your private keys, the money is not really yours. Because it can just disappear. And so, this is self-sovereign identity, very, very important. It hasn’t been cracked yet and there’s still quite some technical challenges that we need to resolve here.

Oscar: Yeah, I believe so. It’s super important to solve that problem. Absolutely. We’ve been talking about – you illustrate very nicely all these scenarios mostly for individuals, I would say. But if we now focus our attention a bit more into businesses, even government, for instance, organisations just in general. So, what are the opportunities or some scenario you can see the metaverse for, yes, for organisations and businesses?

Mark: Well as I mentioned earlier, you know, the metaverse will contribute trillions and trillions of dollars to the global economy. So, there are enormous amount of possibilities.

There are possibilities for consumer B2C, digital fashion, multibillion dollar industry, entertainment, immersive sports, watching sports or using augmented reality to bring a TV show into your living room. Well, Disney recently released a sample of that, which looks amazing. Education, you know, if you can learn something, immersive world, if you can walk around Rome for your history classes and pause whatever is happening to have a discussion with your teacher, that, of course, is a lot more powerful, but also from an enterprise perspective, you know, if I am able to collaborate in a virtual world, in a world that works, in a 3D world that’s a lot more intuitive and much, much more logical for us humans to operate in.

And that will have a big, big impact. Early last year in 2022, I was part of a training done by almost a dozen police forces around the world. And they were doing an exercise in the metaverse, in virtual reality and working with, you know, physical evidence and digital evidence. Everyone was in their own location in Singapore, in UAE, Bahrain, Senegal, France and several other countries.

And they were able to, to solve this scenario, which was a terrorist attack in a hypothetical country. And they all said afterwards that being able to collaborate in a virtual world is really nice and it’s really easy to get along with and also because there was no hierarchy, because all the avatars look the same that help the police forces are very hierarchical that, of course, and that really helped as well.

So, there are a lot of benefits to this. You also see it, for example, in design companies, car companies Volvo is doing a lot by using virtual reality or even mixed reality to design cars with remote teams. So, sort of building a claim model in a physical location, you build a digital model with your design team just living or working anywhere in the world.

It doesn’t matter where they are. All these things will have a big impact. And that will also have a big impact on society because, you know, if we think that the pandemic changed working from home, the metaverse will enable working from anywhere and where you can be literally anywhere you want in the world and eventually in early next decade, I have the feeling as if you are physically present in the office by but you are on a tropical paradise in the Pacific.

And that that’s something where we are going to still far, far away.

Oscar: Yes, from sounds nice. Final question, Mark, for all business leaders that are listening to us now, what is the one actionable idea that they should write on their agendas today?

Mark: Educate yourself and because the world is changing so fast at the moment, if you blink your eyes, you’ve missed a train. And we could have seen that. We did that with the AI, all the generative AI stuff that is happening at the moment, even for me. And it’s my job to be in to know what’s going on.

Even for me, it’s sometimes difficult to understand and to follow and to be up to date of what’s going on because the developments are going so fast. Now, if this is not your core job which for 99.99% of people, it isn’t. And it often ends up on a very long to do list at the bottom.

But you need to understand what’s happening and you need to understand ideally as an organisation, I would also start experimenting with this stuff, small experiments, just to understand what’s happening. And then you can, you can take it from there.

Oscar: Yes. Excellent. And as you say, your, um, you do what you preach. So, like your last book, just in doing your due diligence, doing this kind of stuff. Yeah, I think I have to do some experiments like that myself.

Mark: Well 100%, and for me doing these experiments, they help me to understand, to better understand these technologies. And so, if you want to understand what technology, X, Y, Z means for your business, start experimenting with it.

Oscar: Excellent. Well, thanks a lot Mark. What’s been really fascinating conversation, going for moments very deep into the digital identity, which is something that we are very passionate about, that. And you gave us really good ideas and updates what’s going on. But let us know if someone would like to follow the conversation with you or get more about what you’re doing. What are the best ways?

Mark: So, I’m pretty visible online, so the easiest ways to go to find me on my website, which is thedigitalspeaker.com, you’ll find my books there, my academic papers, my videos, my articles. I have almost a thousand articles about these topics all available to consume, feel free to email me, connect with me on LinkedIn, on Twitter. I’m happy to connect with anyone.

Oscar: Fantastic and again, it was a pleasure talking with you, Mark, and all the best.

Mark: Thank you very much for having me, Oscar. It’s been a great conversation.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up to date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s talk about digital identity with Chris Southworth, Secretary General at the ICC United Kingdom and Oswald Kuyler, Global Head of Strategy at MonetaGo.Join Oscar as he explores the Electronic Trade Documents Bill with Chris Southworth and Oscar Kuyler – including what the electronic trade documents bill is, its aims, benefits and how this is expected to be adopted globally to improve trade processes.

[Transcript below]

“The reality is that if you don’t solve identity, a lot of the inefficiencies generally won’t go away.”

Chris Southworth is Secretary General at the ICC United Kingdom. Prior to joining ICC he was Executive Director for Global Partnerships, at the British Chambers of Commerce (BCC), Head of the International Chambers of Commerce Unit at UK Trade and Investment (UKTI) and a Senior Policy Advisor to Lord Heseltine for his independent review of UK competitiveness. In 2011 he helped set up the mid-size business export programme at UKTI and was a Senior Policy Advisor for the 2011 Government Review of Mid-Size Businesses. Former roles have encompassed deregulatory policy at Better Regulation Executive, social enterprise policy at the Department for Business and stints in a local strategic partnership and the charity sector.

Connect with Chris on LinkedIn.

Oswald Kuyler is currently the Global Head of Strategy for MonetaGo, a fintech focused on global fraud prevention. Oswald is also a Digital standards advisor to the international chamber of commerce UK and is also the former Managing Director of the DSI. Oswald is the former Global Head of Data Strategy of BHP, the world’s largest diversified mining company. He has worked on initiatives covering blockchain, electronic documentation in trade, data and analytics, and automation.

Connect with Oswald on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thank you for joining this new episode. We often talk about digital transformation in this podcast. Actually one aspect that still needs to become more digital is commercial trade documents, in which there’s still a lot of paper. Today, our guests will tell us more about a game changing piece of legislation. So let’s welcome our guests, we have two guests today.

First of all, Chris Southworth, he is Secretary General at the International Chamber of Commerce, ICC, in the United Kingdom. Prior to joining ICC he was Executive Director for Global Partnerships at the British Chambers of Commerce, BCC, Head of the International Chamber of Commerce unit at the UK Trade and Investment, UKTI, and a Senior Policy Advisor to Lord Heseltine for his independent review of UK Competitiveness. Hello, Chris.

Chris Southworth: Good morning.

Oscar: Good morning. And our second guest is Oswald Kuyler. He’s currently the Global Head of Strategy for MonetaGo, a FinTech focused on global fraud prevention. Oswald is also a Digital Standards Adviser to the International Chamber of Commerce, UK. And he’s also the former Management Director of the ICC Digital Standards Initiative, DSI. He has worked on initiatives covering blockchain, electronic documentation in trade, data and analytics, and automation. Hello, Oswald.

Oswald Kuyler: Hi, how are you?

Oscar: Very good, happy to have you both in this conversation.

Oswald: Thank you for the invite. I really appreciate it.

Oscar: My pleasure. So, Chris and Oswald, let’s talk about digital identity. I would like to hear first from you, from both of you, tell us about yourself and your journey to this world of identity.

Chris: Sure, I mean, I should say that in the class of this conversation, I’m the co-chair of the Legal Reform Advisory Board and part of the leadership group at the ICC Digital Standards Initiative, and also the ICC representative to the Commonwealth, which is super relevant when we start talking about legislation and English law.

I mean, my background in digital trade really goes back to when I started getting really active around 2016-17, where we helped put together the ICC digital trade roadmap to get a framework in which we could be very clear with the actors of which there are many in the trading system of what needed to be done, by who, by when. And that was the beginning of, I think, a more structured conversation about how we go about the big task of digitalising world trade and ultimately contributed to the creation of the ICC Digital Standards Initiative, amongst other things, but also the Electronic Trade Documents Bill. So, it was quite a seminal piece of work.

And then since then, been very focused on our responsibility in the UK, because every jurisdiction needs to tackle this legal barrier in the document, trade documentation space, which is where national laws stipulate that commercial trade documents, that’s bills of lading, bills of exchange, promissory notes, those sorts of documents, there are eight actually in total, have to be handled on paper. And that’s largely because the laws in which we operate in trade go back a long time. In our case, in English law, it goes back to 1882 in the bills of exchange act.

So, it’s not surprising that that bill, which is a great piece of law, and we’re not proposing changing the law actually. All we’re doing with Electronic Trade Documents Bill is putting digital documentation or documents handled in digital form, I should say, on the same legal footing as paper documents. So, it’s actually quite a minor amendment in that, but there’s a lot more complexity behind that from a legal point of view, which is why it has taken, you know, nearly four or five years to come to fruition. So, we’re absolutely delighted that the bill has come into place.

And then alongside that, really working with the global community in the ICC Digital Standards Initiative, Oswald, and then in the UK case, with the creation of the UK Centre for Digital Trade and Innovation. You know, and the big questions there is how do we help drive a global campaign to every single government now asking them to very clearly to say that we need to remove the legal barrier to the handling of commercial trade documents. And then we need to align our national legal frameworks to what’s called the UNCITRAL Model or Electronic Transferable Records or MLETR in abbreviation terms. That’s really, really important. And unfortunately, you can’t do that at global level. Or, if you do, it have to be through the World Trade Organisation. And in the current political environment, that’s not realistic. So, it is a big task.

What I am really pleased to see now sort of forward tracking, you know, two or three years is we’re seeing real momentum, the G7 are really driving forward, the UK is obviously part of that, but the US have legislation, the Germans have legislation, the Chinese actually outside of the G7, are actively working on legislation. So, we’re starting to see the big economies now, really grasp the issue that we need to not just digitalise customs and trade facilitation where a lot of the focus has been. We need to allow the private sector, which is actually the largest share of trade, of course, because it is ultimately businesses that trade, to digitalise those documents. And that means we can get scale, we can start to really get interoperable systems into place where information can move in standard formats across platforms, systems, and processes across borders.

For anyone who’s not a sort of trade aficionado, it’s very easy to miss the sort of the reality of trade. You know, in our consumer lives, we all operate on mobile phones these days, life is pretty easy, you can tap your phone, you can get your bank details, you can do everything off your phone. And that’s simply because the systems are interoperable. It’s all standardised, doesn’t matter who your provider is, what network you’re on, the hardware and software all connects. Well, in the trade environment, none of it connects. It’s like, you know, the consumer world was 30, 40 years ago. And so, I call it the sort of Apple-Microsoft moment in trade where those two companies, and for anyone old enough to remember what it was like when those two didn’t talk to each other, it was – you had to choose one or the other.

You know, we’re at that moment when those two companies sat down, standardise their systems, and then our Word documents and all these other sort of practical pieces of information could just move across our hardware, software. Well, that’s the cusp we’re at so its super exciting. It’s, you know, effectively, we’re in the biggest transformational stage in world trade that I think we’ve ever seen in terms of the way we go about trade. It’s not just about digitalising eight documents, it’s about fundamentally changing the way we trade so it’s more efficient, you know, it’s click of a button money, goods, services, all move at the same time. And then ultimately, it’ll be about things like atomic settlement, digital currencies, you know, the transactions will happen in real time as the goods ship across the borders, rather than having to wait for two to three months at extraordinary cost and bureaucracy, because we’re all operating on paper.

And then I should just finalise, you know, just say how important this is to sustainability, because that also sometimes gets a bit missed. We can’t deliver a sustainable global economy until we get off paper. Because you can’t get transparent systems into place, you can’t aggregate the data, you can’t get a sense of real time what’s going on, where it’s going on in the trade corridors and supply chains until we get higher volume, accurate data, in digital systems. So, it’s a really important enabler to allow us then to kind of support the shift and transition towards ultimately a net zero economy but certainly more sustainable global value chains.

Oswald: Yeah, and maybe to build off of what Chris has just said, like, if I reflect a little bit on my journey on getting to the point where we are today, I used to work at a really big mining firm. And one of the key things we were actively trying to do is figure out how do we actually digitise whether it is our creative processes, with our customers, or with our suppliers and kind of what’s required to actually get that done. And we realise that if one of the largest miners in the world can’t achieve this, how are smaller companies actually going to enable the digitisation of these processes?

And to Chris’s point, there are many business cases and reasons why you actually want to do that. You know, whether it is for working capital reduction, whether it’s for ESG, and transparency, the list goes on and on and on. And a lot of these things just can’t be done using traditional paper mechanisms. And so, as a part of the journey, one of the things that Chris and I worked on a few months ago, was to try and put a lot of these things in context. And when you think about global trade, you know, 80%, and it sounds like a funny statistic, but I promise you it’s on the internet, 80% percent of global trade is actually supported by what we call trade finance. And if you have a look at trade finance, and it’s super important because it helps the world businesses actually execute business which is again foundational to having societies operate.

Now, when you think about trade finance. So how do banks really enable that? And it really comes down to really two core kind of buckets of things. The first is really, do I trust, or can I trust and identify the company or the companies that are involved in a trade transaction? And so, this is where identity and specifically the evolution of identity towards digital identity will play an absolutely key role.

The reality is that if you don’t solve identity, a lot of the inefficiencies generally won’t go away. And so, it’s fantastic seeing, even after the big global financial crash a few years ago, one of the first things that happened was GLEIF was formed, the LEI was established, you know, a lot of investments went into that. There are some additional standards that have matured and come out on the identity space, things like the W3Cs, DID specification. So, one of the things that motivated me quite a bit is this recognition that it’s not that we, as a society, need to spend another 10 years figuring out how do we solve identity. There’s a lot of great things out there. It’s more how do we actually mobilise people and businesses to actually adopt what’s out there and actually leverage it.

And the second bucket, which is just as important when you think about trade finance is the actual documents that are involved in trade. And Chris hit the nail on the head, the reality is, it’s very difficult to digitise trade documents if you don’t actually have some form of legal foundation, where you can actually transfer the possession of the documents in a way that is safe, a way that you can go into a court of law and dispute it, et cetera, et cetera. So, these two key areas are fundamentally critical. And it’s been a part of the journey that we’ve gone on, at least as a part of trying to figure out how do we contribute into the space.

Now, for your listeners, one of the key things I would highlight that Chris also touched on, because I think it’s so important, is the ICC produced a digital roadmap about four years ago. And I’ll never forget, when I left the mining company and I joined the International Chamber of Commerce, basically, it was such a fantastic foundational piece, because it highlighted all the key areas that required work, that required solving for, that industry, and government, public and private sector can actually focus on and say, “This is what we all need to do to solve the challenges so that not just the big companies can digitise trade but the smaller ones.”

Most importantly, who don’t have big innovation teams, who don’t have huge technology functions, who don’t have millions of dollars that they can allocate towards digital transformation agendas can actually digitise too as a part of this journey. And that’s been refreshed. I’m not sure Chris, if it’s yet released or not, but there’s a new roadmap, that is just brilliant. Again, it helps us all focus our efforts.

So that’s a little bit, at least at the macro level view from my side. You know, we need global trade to work. Businesses need that. Trade finance is foundational to enabling the world to trade. And digital identity and documents are the core pillars that enable global trade globally.

Chris: Yeah, this is touching on some really important points. I mean, and it links to what I was saying as well around antiquated systems. So, the role of the banks here is really important. I don’t think this is fully appreciated, actually, outside of the banking community. But in 9/11, that’s 20 years ago, at 9/11, I mean 2001, in came, you know, a huge wave of anti-terrorist financing regulation and legislation. We all understand why.

And then in 2008, financial crisis, in came another wave, anti-money laundering legislation, amongst other things. And again, capital requirements, you know, market stabilisation mechanisms. Again, we all understand why. But it came at an enormous cost. And ever since then, this particularly the financial crisis, we’ve been running at a 1.5 trillion trade finance gap. And what’s happened is the regulations have effectively tied the banks up in knots, in bureaucracy, having to verify, identify, and that’s all for legitimate reasons. The difference is, is the world’s moved on in terms of technology. All of those processes that the banks have to undertake, which nobody’s arguing with, can just be done so much more intelligently, with smarter use of technology, and it all hinges on identity.

If you can identify a company at the click of a button on a transparent register, you’re saving yourselves days, weeks, hours in time in checking, rechecking, verifications, duplication, every bank, there’s no central registry, outside of – well, I’m sure we’re going to talk about the GLEIF LEI register amongst other things.

So, you have to just – everybody has to check the same company in their own systems. And nobody gets transparency, what the other banks and other financial institutions do. None of that is necessary if we just use the Legal Entity Identifier model, which is digital identities. That’s absolutely crucial. And then it allows you, of course, to then start tackling other wider issues like fraud, VAT gaps, you know, governments are running huge VAT gaps in many areas, even in the UK, it’s 9 billion pounds. You know, in a world where government is short on public finance, like all governments, you’re looking for ways to generate more growth, economic growth and trade growth.

You know, we have a wonderful opportunity here by simply adopting, you know, the digital identity system and getting ourselves fit for purpose for the modern way of working in the trading system. And the digital identity is the absolute foundational core of that system. Without the identity, you can’t tackle the bureaucracy on verifications and anti-money laundering and KYC, all of this kind of stuff. You can’t tackle the fraud question well enough; you can’t tackle the VAT gap issue. It ticks multiple boxes in one go, and it’s not expensive.

The issue actually, that we get most feedback on in the corporate community is companies just don’t know they exist. And so, the first job is really to raise awareness, what is a digital identity? How can it help your business? And then importantly, how can you use it in your global supply chains? How do you work with your suppliers? So, you get total transparency, you can strip out all of that inefficiency, you can still meet all your regulatory requirements, but you’re just doing it in so much more efficient ways. And it’s just about using those technologies, enabling technology to help you run a more efficient, faster, quicker, simpler operation.

Oscar: Yeah, I can see definitely a lot of benefits and why we’re talking about this. So, it’s so important. Let’s go to the details. So, what is this bill? What is the Electronic Trade Documents Bill?

Chris: Well, the Electronic Trade Documents Bill is really an amendment of the two pieces of law, the Bills of Exchange Act in 1882, in English law, I should say, and the Carriage of Goods by Sea Act in 1992. Now, clearly, those are out of date in the modern world of using technology.

So, the Electronic Trade Documents Bill is really quite simple. It’s putting commercial trade documents in digital form. And it’s important, it’s not digital documents, we’re not talking about PDFs here. We’re talking about getting the information off the paper and into the IT system. That’s basically what we’re talking about. But what the bill does is it puts commercial trade information in digital form on the same legal footing as paper. So, if there’s a dispute or companies are in a disagreement in a court, if you’re working on a blockchain platform, or a technology platform or system, that will stand up in court. That’s not the case at the moment. It has to be on paper. It has to be written, signed, and so on, and so forth.

And then it also stipulates which is important, the need for secure technology platforms to handle that information. And of course, that’s where solutions like blockchain come in. I don’t think actually blockchain is the only solution. But it is clearly a major part of the solution in the current trading system. But that’s obviously very, very important in terms of data security.

So, the law really doesn’t do much more than that. It’s only a page and a half, actually. People are surprised when they see it, because it looks deceptively small. It looks like really, almost a non-piece of legislation. But, you know, what’s important here is the disproportionate positive impact that will have, because it allows us to digitise the whole transactional space. So, at the moment, you can deal with digital certificates of origin, customs declarations, all of that kind of thing can pretty much be handled in digital form, that you can’t do the commercial trade transaction, which is actually the bigger more important aspect because that’s the actual handling of the goods, the finance, and the ownership when goods are crossing over borders.

So once those that legal barriers removed, it allows industry and government to start to really standardise the whole ecosystem. And that’s where we get paperless borders, frictionless borders. We still have to undergo the processes, you still have to do a transaction but you can do it in a radically shorter periods of time. You can do it without any of the process that you currently have to do. You know, there are 27 documents, 30 documents in total that companies are having to handle. It can take up to two to three months. It can cost in total, easily $80,000 or more plus, when you add it all up. It’s an extremely expensive business. And obviously, it’s hugely bureaucratic.

There was one example in the pandemic that really just highlighted all of this in one situation. And that was when the first wave of the pandemic was hitting the global economy. We were all going into lockdown, but our ships had left the ports. So, in the UK context, you know, our ships have left the southern ports, and we’re heading out to the east, to the Chinese ports through Singapore. And then three weeks later, we all got bombarded across the media with, you know, this huge logjam, traffic jam of ships sitting in Singapore. None of them could dock in, none of the goods could get in to port. And that was because all the documents were sitting in brown envelopes at Heathrow Airport, because all the airplanes had been grounded.

Well, that was completely unnecessary. Really, all of those documents, that information should have been in the system, the digital system, and then the transactions could have actually happened in real time. And that delay, and all the disruption which we’re still feeling today for consumers, businesses, and everybody should really have never happened at that scale. That’s the kind of impact we’re talking about by the Electronic Trade Documents Bill.

And then in the English context, English law context, obviously, this is going to be – have a dramatic effects and positive effects on the UK trading system. But actually, the more exciting aspect of this for me is the Commonwealth. Because we have 53 countries who all share almost word for word the same pieces of English law. And so, the Electronic Trade Documents Bill suddenly opens up the opportunities to accelerate that legal reform process across 53 countries. I think faster than any other global network can achieve it. Because we simply share the same legal basis. That’s one of the huge advantages of the Commonwealth.

So, then it starts to get really exciting because it starts to happen at scale across big economies like India, Canada, Australia, New Zealand, UK, obviously, and then actually huge swathes of Africa as well, don’t forget. So that’s the big opportunity come mid next year, once we’ve got the law in place in the UK, certainly my mind is absolutely switching on to that global environment. And by the way, even the Chinese, the Thais, we’re working with the Thai government at the moment on helping them with their legislation. You know, they’re also interested in the Electronic Trade Documents Bill. There are translatable aspects of that bill, that can be not necessarily copied and pasted but certainly the principles can be drawn across into other legal systems.

So, you know, to put this in context of documents, 80% of bills of lading worldwide are all operating on English law. So English law, and that’s a part of our heritage, our history, our legacy in the world. English was a disproportionately larger impact on trade than any other law in the world. So, the English law piece is crucially important. And that’s why we’ve put so much energy into it.

So, it’s really exciting in terms of stage, we’re at the second, what they call, the second reading it’s the second, you know, the sort of series of committees and forums that you have to go through in Parliament. It’s on a fast-track procedure through Parliament, which is good. We don’t have to have a whole year in Parliament discussing it. We’ve had two readings, we’re into the third, but by the middle of next year, we’re expecting it to come into force. And that means no more requirements for paper on any documentation in the UK. The whole UK system can go digital, and then we can really switch on to work with our trading partners.

By the way, the UK Government is wiring all of this into our trade corridors. So, every single trade negotiation at the moment with UK has commitments in the negotiations to go digital to adopt, align our legal systems, I should say to the MLETR framework. So, you know, it’s pushing out digital corridor, just like the Singaporeans have been doing for quite some time. You know, the UK is now starting to do that in the western hemisphere. And then obviously, in due course, the Germans, the US and everyone else will start doing it too. And then the world system will start changing at a rapid, more rapid pace.

Oscar: Yeah, that’s something that clearly, I was thinking of asking you, OK, this is in the UK, it’s going to be in place next year in the UK, thinking first one single country, but now that you explain that already spills to many countries, and with the influence that you mentioned, that has the English law in even more jurisdiction is quite impressive.

Chris: Yeah, it’s not just jurisdictions actually because like, say sort of bills of lading, 80% of those operate in English law. But a lot of international contract law is actually using English law. So, there’s a lot of private sector transactional work in all parts of the world that is actually operating on English law. I mean it’s a bit deceptive in a way because you naturally think English law is England, or even Wales, I should say. It doesn’t operate like that. English law kind of has this enormous global reach into sectors, industries, jurisdictions. That’s the really exciting aspect of this Electronic Trade Documents Bill is the scale, the scale of opportunity that it opens up.

Oswald: And maybe Oscar, to double click on what Chris was just said and to build on that is today, there’s a bunch of form platforms that enables people to try to digitise, you know, trade processes. And fundamentally, what they all are based on are these private law agreements, where the two of us sign a contract and say, sure, you know, if I email you this document, or if my system says you possess it, based on the private contract you have some form of recourse. But the problem with that at the top end, so if you imagine you’re a big multinational companies, you have to go convince your entire ecosystem. So, all your suppliers, all of your banks, all of your customers, everyone to sign up to the exact same legal agreement to say this is how we’re all going to operate. And what we’ve seen is really two or three consequences of that.

Firstly, the banks are sitting in a position where they are almost forced to sign up to every single one, because they fundamentally enable trade, and it’s exceptionally difficult to navigate that complexity. The second challenge is, when you think about it in practical terms, if you have, let’s say, two of the largest mining companies in the world, one deciding to use Platform A and another one deciding to use Platform B. You end up in a situation where suppliers and especially the smaller companies are put in a position where if they wanted to engage with those mining companies, now all of a sudden, they have to be onboarded onto multiple platforms, pay more money, teach a smaller workforce how to deal with more systems, and it just doesn’t scale. And the reality is, if you don’t sign up to all of the agreements, you have no legal recourse. And that’s why we’ve been stuck at about 1-2% of trade digitisation globally for the last two decades.

The second portion, and again, this is where identity really comes in. It blows my mind when you think about it. Every single one is the existing digital trade platforms, whether its internal supplier relationship management systems, customer relationship management systems, ERP, identity is done in completely different ways today. It’s not standards based. And some of these systems were designed 20 years ago. So, a lot of the cases identity was designed by some architect that just went and said, “OK, it’s going to be a string 256 field, and people can type in whatever they want to.”

And so, what ends up happening is as you go through a supply chain, to Chris’s point, every single part of that supply chain has to recheck identity, there’s no sharing of it, because there’s no, you know, there’s no alignment, agreement, governance, et cetera, on how that needs to be done. And by using digital identity and all the promises that it entails, again, you can remove a lot of that inefficiencies. And it’s not just that we want to remove that just purely for the banks, who I firmly believe are desperate for servicing more customers. It’s not like bankers wake up in the morning and saying, “I don’t want to serve more businesses.” But this is important for those SMEs who are just so small that when a bank looks at them, and goes, “I really want to finance this, but if it’s going to cost me that much just to verify the identity of a company, it’s very difficult to extend financing into that space.”

So, my closing thoughts on what Chris also said is, when it comes to English law, let’s also not forget that, and I would argue the vast majority of trade digitisation systems are either UK-based or leveraging English law too, which is another component of this. So [A] for all of those companies who have already invested in trying to digitise trade, once English law moves, they’ll get that benefit because it would be baked in. But then more importantly, those smaller companies who go, “You know what? I don’t necessarily potentially want to use a FinTech to digitise my trade. Maybe I just want to use email, WhatsApp, SharePoint, whatever it might be.” English law will give them the freedom to make those decisions with their supply chains, which I think is desperately needed.

Chris: Yeah, we’re not the only ones of course here. So, there’s a couple of important points here. The France is important. So, France is actively now moving to working on legislation. They’ve already identified the legal barriers. That’s the first stage. The second stage is now to draft a legislation. But of course, you know, surprise, surprise many of the Francophone countries around the world like West Africa, they’re following the same laws as France. So, and then Hispanic, huge parts of Latin America following the same basis in law.

So English law obviously operates in a slightly disproportionate impact beyond just the legal jurisdictions as Oswald has just said. But other parts, other country and other countries and their legal systems playing a crucially important role here. If we’re going to have changed in Latin America at scale, legally, then we really need to kind of have that model like the Electronic Trade Documents Bill equivalent, you could almost replicate or at least use that as a reference point.

It’s a very, very good point that Oswald just referenced. And this is a core, really for corporates so if there’s anyone who’s listening to this, as a corporate, from my perspective, I’m very much looking at this whole digital identity in the UK context, because I think it’s a great case study. And it helps us understand what’s going on and other markets. So, we know every listed company has a digital identity, because the regulation says they have to, in order to trade on the market. So, we know the corporate is gone.

So, the first question is, who registered for that digital identity? That’s a board director. So that’s upstairs, somebody has done the process and put their signature and got an LEI. The person who manages that, is the company secretary, also upstairs in the boardroom environment somewhere. And then we also know, they’re not using it in the supply chain. So, they’re fulfilling a regulatory requirement. Absolutely right. But they’re not utilising it to its full benefit. And that’s because that digital identity hasn’t travelled downstairs to the procurement managers, the supply chain managers, the buyers, and so on, and so forth, who can then deploy this at scale through their global supply chain to Oswald’s point, really. And then really encouraging all that supply chain to adopt an LEI. And then you’ve got full transparency, you know, exactly who is who in that system at the click of a button on one transparent register. It’s that simple.

By the way, it’s 30 pounds a year. Cost, it’s not a cost issue. This is not expensive at all. It’s just understanding what a digital identity is, how you get one, and importantly, how you utilise it. But if you imagine 30% of the major listed companies in the FTSE 100, for instance, big international trading companies all use the digital identity through their global value chain, that would be the equivalent of what half a million up to a million businesses, all using LEIs and digital identities. That’s the sort of transformational impact that we’re talking about. And that’s the kind of strategic thinking that we need to apply in order to really get momentum around the use of these digital identities. And then with all the growth benefits that come with it, which Oswald has already set out.

Oscar: Yeah, it’s really impressive. And thanks a lot for enlightening us about this very influential bill that it’s already almost flying, right? So, I will ask a final question for both of you, for all business leaders listening to us now, what is the one actionable idea that they should write on their agendas today?

Oswald: So in practical terms, what I would say is, have a look at your five-year plan, one-year plan, whatever your projects are for the next five years that you’re going to do, especially for at a big company, look at them, and recognise that quite a few of the opportunities in front of you are ecosystem-based opportunities where you need to work with whether it’s customers, banks, your carriers, your, you know, governments or whatever. You need to work with a broader group to actually get to that value.

And so, my view would be is go into, tell your teams say, “Hey, there’s an ICC standards toolkit. And this toolkit, it highlights all the standards, whether it’s identity of objects, identity of subjects, whether it’s title documents, whether it’s non-title documents. Build off that. Whatever we’re building because it means that we can engage an ecosystem way more efficiently.”

And then the second item is if I am a smaller company, and I don’t necessarily have these innovation budgets and projects, et cetera, et cetera, to Chris’s earlier point, there is something like an LEI, for example, which is digital identity, leveraging that and baking that into either getting it today, or putting it in your budget for next year so you can get it next year. These things will become increasingly more important for banks because it will help them shorten the amount of time required to do KYC on you so you will get the value benefit. Just make sure you’ve budgeted for it, make sure you understand it, and you’ll get the value from that.

Chris: Yeah, I completely agree with that. You know, in terms of a call to action, you’re a CEO, a CFO, a supply chain manager, in the legal department, General Counsel, you’ve got a massive opportunity here to really improve the way that you’re trading across your supply chain. And that means doing things cheaper, faster, simpler in the main but ultimately also about moving to a more sustainable system where you get more transparency and security through your value chain.

The answer is simply if you’re a listed company, go find your LEI, sit down with your supply chain manager and your bank and finances, and then really talk, have that utilisation conversation. How can I use this number to better effect to drive those sorts of benefits through the business? If you’re not a listed company, go get an LEI, you can do that through the Centre for Digital Trade and Innovation, that’s www.c4dti.co.uk. It’s 30 pounds to register. You can do it through the centre very, very easy. We’ve tried to strip away that ease.

If you’re in another jurisdiction, you can go to the Global Legal Entity Identifier Foundation, GLEIF as it’s called. There’s a global register, there’s a list of all the issuers in the world, there are 35 of those. So, you can find the issuer of digital identities in your jurisdiction or region. About eight of those are global issuers. It’s very, very easy. Go get your LEI. It’s cheap, it drives massive benefit to your system. And most importantly, all trade will require in due course, digital identities. So that is 100% the future, the quicker we start to adopt them and use them, the faster we can get to that end outcome, which I think we all want.

Oscar: Yes, thank you. And if someone would like to get in touch with you or learn more about the work you’re doing, what are the best ways?

Chris: Well, for me, it’s as simple you know, just get in contact, I think in the context of this conversation, the Centre for Digital Trade Innovation, you can do that through info@iccwbo.uk. We’re easily findable on the websites, on social media, just get in touch, LinkedIn, happy to help. We’re here to support industry. Ultimately, our job is to try and accelerate that digital transformation over the coming years. Users, we’re set up here to help you, come ask and let’s do it and we’ll help make that happen.

Oswald: So, fully aligned to Chris, the Centre for Future Trade and Innovation, reach out. If you can’t find the website, find us on LinkedIn, both Chris and I are there. We can kind of move you towards that. That should be your go-to.

Oscar: Perfect. Again, thank you for this very interesting conversation and all the best.

Oswald: Thank you.

Chris: Thank you, thanks.

Thanks for listening to this episode of Let’s Talk About Digital Identity produced by Ubisecure. Stay up-to-date with episode at ubisecure.com/podcast or join us on Twitter @ubisecure and use the #LTADI. Until next time.

View Details

Let’s Talk About Digital Identity with Oscar Santolalla and Clare Rowley, Head of Business Operations at GLEIF.Episode 81 is an identity stories special, where Oscar and Clare discuss the history of identities for businesses and how and why the LEI was created and introduced – including how the LEI has been adopted globally, the challenges is has helped to solve and what the future of LEI might be.

“We see there an emerging dialogue and focus coming from the trade, the supply chain community on the importance of LEI for trade participants.”

[Transcript below]

Connect with Oscar and Clare on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

To find out more about LEIs go to the RapidLEI Knowledge Base or contact the RapidLEI team.

Go to our YouTube to watch the video transcript for this episode.

Podcast transcriptLet’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: More than 2000 years ago in Persia, Egypt, ancient China and their contemporary civilisations, the first versions of what we now know as the passport were used to travel from one region to another. As the world became more populated and connected through roads and by the sea, passports became a vital piece of paper for people to enter from one country to another. But only in the late 21st century the passport became as standardised and globally acknowledged as we know it today.

But what has been the ultimate motivation for humans to travel the world? Trade, and it’s still today.

Companies have also existed for centuries. Some of the oldest businesses existing today were established in Japan, like Nishiyama Onsen Keiunkan a hot spring hotel founded in 705. However, the need for business registries came much later in history. The United Kingdom’s Companies House was created in 1844. The goal of British lawmakers at that time was that having a list of registered companies publicly available would help reduce fraud.

On the other side of the Atlantic, Dun & Bradstreet, a company that was founded in 1841 provided credit reports about businesses through several decades with a similar goal of helping businesspeople know the companies they were planning to trade with. In 1963 Dun & Bradstreet created the Data Universal Numbering System (DUNS) a unique nine-digit identifier for businesses. A few other similar business identifiers appeared but, as with the passports, the time for a global standardisation was still to come.

Let’s hear now the history of the Legal Entity Identifier, LEI, the 20-digit identifier for businesses and other types of organisations.

Oscar: Today we have with us Clare Rowley. The head of business operations at the Global Legal Entity Identifier Foundation, the GLEIF.

Clare, what were the reasons why the LEI was created?

Clare Rowley: I will go all the way back to September of 2008. For participants in financial markets, financial institutions, this is a very memorable month because during this time there was what is now referred to as the Lehman weekend.

And of course, that led to a failure of an extremely important market institution, market player and the subsequent impact across the world. So, at this time, there were supervisors within financial markets, financial institutions, asking a very simple question to their regulated entities. That is, what is your exposure to Lehman Brothers? And the scary answer was – that was not really an easy thing to know and to determine, and it will probably take weeks and maybe even months to get that answer.

And the root of the problem was not that there was no data on the positions that were held, etc. Rather, it was the problem in identifying those several thousand legal entities associated with Lehman Brothers. So, at the time there was no design in data systems that made it easy to aggregate information across the entities and then clearly paint the different hierarchies existing, be it in the financial products or in the corporate structure itself. That left a window opening or some motivation for the leaders around the world to come together and to think about how to solve that problem.

So, if we fast forward to today, we’ll see that the Legal Entity Identifier, the LEI and that being part of the global LEI system has solved the problem of identity, largely starting in derivative markets, but bit by bit moving into all financial instruments such as securities, fixed income markets that are around the world. And you’ll see now that the LEI, it is incorporated into different regulatory reporting’s. And based on our, the foundation’s, last analysis, we are able to identify 294 regulations and policy recommendations that are coming from 24 jurisdictions around the world.

Oscar: Tell us more about how was the process behind the creation of these LEI standards.

Clare: So, it really was a fabulous international effort that was led by the Financial Stability Board. So, following the 2008-2009 financial crisis, you then had the G20 leaders coming together and making a recommendation. An open public means a system for identifying legal entities. And that recommendation was put to the Financial Stability Board.

So, the very first thing that the Financial Stability Board, an organisation international that is based out of Basel, Switzerland. Put their heads together and said, okay, first we want to look at the governance topic. So, they did a very extensive consultation to public sector entities, the regulatory, central banks, securities regulators, etc., but also an extensive outreach to private sector.

And that private sector was not just organisations like financial institutions, the intermediaries, etc., but also going into, for example, real world like the topic of supply chain, business registries. So not just focusing on the financial markets but looking into, for example, even payments, etc., where we see a lot of activity today. And overall, the Financial Stability Board concluded a governance structure that is that is very robust but inclusive of all different organisations or all different, you could say sectors.

So, let’s start at the top. We have three layers.

At the top we have the Regulatory Oversight Committee, and this is made up of more than 65 authorities from around the globe that are setting the policy and ensuring the policy evolves over time.

Then you have the Global LEI Foundation, the GLEIF, which is the organisation I represent. We are managing the operations. We are a not-for-profit Swiss foundation.

And then at the third level there is organisations called LEI issuers. And this is the most diverse grouping of organisations involved. We have 39 in total, and they are the local experts. So, they know what makes a legal entity, a legal entity, how to validate and verify that information at the local jurisdictional level.

So, this governance structure that was set up is very inclusive as you have the public sector there at the top. Then you have us, the foundation, which you could consider more like a neutral, not for profit organisation and helping to coordinate across the different layers. And then these LEI issuers, the 39 organisations are all different types of entities. You have private sector entities like London Stock Exchange, Bloomberg, you have business registers, etc. So, it’s a very mixed group and also allows the system to get a very wide input into how it should evolve into how it’s applied at the local level.

So, this public private partnership led by the Financial Stability Board, well, it was developed in a very intensive way with great participation coming from different areas. You see a governance structure that has persisted and that has really demonstrated how efficient it is.

And then on top of that, we have the LEI.

So, in parallel to the developments, the governance structure, there is also a desire to ensure that the LEI, the legal entity identifier was non-proprietary, a broad public good and therefore there was the engagement with ISO, the International Standardisation Organisation, to establish the LEI as that kind of standard, one that is open, public, freely accessible. And you will find the LEI is also represented as an ISO standard – 17442.

That standard describes the LEI itself, as well as the reference data such as official name, registered address. And something interesting there as well is the idea that it should evolve over time. So, you see already there have been updates to the standard to include, for example, references to how the LEI could be embedded in digital products like digital certificates. And that is a really fundamental principle of the system that the system in the governance structure, in the actual application of standards should evolve according to market participant needs over time.

Oscar: And when the LEI was – possibly said launch – was made available for organisations.

Clare: So, the foundation itself came into being in June of 2014. But you will find that the earliest LEIs were issued all the way back in 2012 and that gets us a bit to how it has been used since its creation. So, you might think to yourself and a standard for legal entity identity that’s really big and it also gets to the heart of data systems of how businesses interact – identify their partners. And if you think yourself or even, let’s say, as a business entity, how many identifiers you have, you will quickly think about, for example online platforms, logins with governments, logins to health insurance, whatever it is, etc.

And you will realise you have hundreds and hundreds of identifiers, either that you use personally or for businesses as well. So that therefore brings us to well, how do you get by in an interest and utilisation for such a system when it really gets to a very expensive end and difficult change for organisations, how to identify business partners itself and transactions etc. And that is where we see regulators in the first step of using the LEI.

They looked and they said, well, we know we have an area that’s changing rapidly where we have regulation coming into effect and change is occurring in industry and that was derivative markets. So back in 2012 when the first LEIs were being issued, they were being issued to help the financial market participants, both financial institutions, as well as companies that use derivatives for things like currency hedging, natural resource hedging, etc.

Those were the first entities to obtain the LEI and that was to ensure compliance with emerging regulations of the United States such as the Dodd-Frank regulation, and within Europe, the EMIR regulation and then the LEI expanded after that in to, for example, the markets in financial instruments directive in the EU so more broad use across the across the financial instruments markets.

But indeed, that’s why you see a bit of the disconnect between the first LEIs being issued in 2012 to meet the market demand, the regulatory implementations. But the actual full system itself with the GLEIF, there helping managing the operations, the publication of the data, etc. that was not fully in place until June of 2014.

Oscar: The early 2010s saw the world becoming more digital and connected. Square, Stripe and later Apple Pay made it so easy to move money from the device that was already in our pockets. OpenID Connect made it so easy to use our digital identities across a seemingly unlimited number of services.

The concept of Identities for organisations was finally starting to take off thanks to the new LEI standard. So, how LEI is used today?

The ignition factor for LEIs came from the financial industry, but it was not the emergence of mobile payments or users’ convenience. It came through an unprecedented avalanche of regulations that mandated its use. These more than 300 global regulations covered most financial activity you could think of – Payments, Capital Markets, Private Banking, Treasury, Cross Border Trade, Letters of Credit, Lending, and the list continues.

In November 2018 the Bank of England became the first central bank with plans to make LEIs mandatory within certain transactions between financial institutions.

“The notes smelled musty, as if they had been stored under the floorboards” was said by the court. This blatant example of NatWest bank shows how cash enters into the financial system in the millions to fund illegal activities when there are insufficient anti-money laundering checks. This case makes it very clear that banks and financial institutions must verify who exactly their customers are. How can bank employees know who are the beneficial owners of a company? Here is how LEIs are already helping.

Who are the job creators? The media often makes us believe that big corporations and billionaires are. But the evidence shows, as we discussed with Amit Sharma earlier in this podcast, that small and medium enterprises, SMEs, are the real job creators in both the richest and poorest countries.

Unfortunately, even in richer economies, small businesses find it very hard to get access to credit to secure their next 12 months of operation. Why? The main reason is that a company’s financial reputation is directly based on the owner’s financial score. What if the family, on top of not owning any property, never built up a good credit score to prove that they are reliable for re-payments? A bank would make its due diligence, follow their KnowYourCustomer KYC processes, and as a result deny them credit. How can we change this game and bring financial inclusion? Again, here is how LEIs can help.

There is no doubt that LEIs can make a big positive impact, and innovative companies are already making this happen.

Oscar: So now let’s talk about the future of the LEIs. So, with the pandemic and the recent economic instability, what are the new challenges that the LEI has found?

Clare: When we talk about the future, what we see at the GLEIF is a pivot to the private sector, adoption.

And we see there – first, I will focus on trade. And to quote a recent publication that came from ICC UK, “the world’s 333 million companies support a global community of almost 8 billion people, all of whom rely on these companies to earn a living and live in a prosperous and more peaceful world.” So, 330 million companies, well, you can’t have a global economy – interactions between companies, customers cross-border without having a more efficient way of answering that very basic question, who am I doing business with?

So, we see there an emerging dialogue and focus coming from the trade, the supply chain community on the importance of LEI for trade participants. And that is particularly since the COVID pandemic, where we see fraudulent transactions as people, companies ran to go digital. Fraudulent transactions also have been on the rise. And that’s where the private sector becomes engaged, looking at the LEI, the accessing of the LEI via the LEI index as a means to provide real time access to unique identification of legal entities.

It helps the first step in creating an efficient and trust-based relationship to facilitate, for example, trade finance. And then, very importantly, eliminating manual inputs and the difficulties or cost driving exercises that manual management of data causes. So, for example, if you are relying on names and addresses to try to identify business parties, to try to communicate across business partners, you have problems with translation, transliteration, shortening of names, of addresses and all of that requires manual intervention just to get a transaction initiated, just to have and establish that very first trust between two business partners.

So, there you see an emerging interest in the LEI as a solution for KYC, anti-fraud and ensuring appropriate surveillance for anti-money laundering.

Identity also is extremely important for businesses. And access to a global identity can be life changing for small businesses, especially small businesses coming from developing nations where maybe their local business registry is not easily accessible to parties outside the country, etc.

And there we did a pilot project in Zimbabwe working with a financial institution that engaged in something we call the validation agent operating model. That bank was called, NMB bank and they decided to engage, to investigate. Well, how can the global LEI system offer its small business client’s access to this global identifier so as to broaden their ability to interact digitally and also make the small businesses more present and more accessible to business partners around the world.

And through this engagement, there’s a firm called Copper Wares that became one of the first mid-sized African companies to get an LEI. And there we have a finance manager from the company that notes – regarding Copper Wares having the LEI that “once were known out there. We expect life to be much easier, funding terms to be more accessible, credit terms to be more accessible. And overall, that helps us Copper Wares to produce more, employ more people and offer better prices and boost market share.”

So, we really see that driving need the ability opportunity for small businesses to promote themselves, to make themselves more accessible via this global identity as a very important pillar to the future and the growth of the global LEI system.

Oscar: Yeah, excellent. And you have mentioned earlier that the LEIs are maintained supported by a series of organisations is an ecosystem including the GLEIF. So how has the GLEIF and this LEI ecosystem evolved to help solve the challenges that you just mentioned?

Clare: So, I already mentioned with the with the COVID pandemic, of course, you had all sorts of business processes, operations that were going digital. And with that movement toward digital, it also highlighted, you could say, one of the shortcomings of the LEI system.

So as a starting point, the global LEI system, it is open public information. We are gathering the data that is validated, verified by these LEI issuers around the world. We gather that data, we run data quality checks, ensure the quality of it, and then ultimately put it together and publish it in a way that enables an easy website search, full file download, or API access for technical programmes.

That’s our role to ensure that the LEI remains an open public good, and we’re upholding the basic principles that were put forward by the Financial Stability Board and are overseen by the Regulatory Oversight Committee. So open public data, fabulous, easily accessible. But if you take that and now apply it to establishing a trust relationship, we have a disconnect.

For example, I, Clare Rowley, I could take any one of these 2.2 million LEIs that are out there. I could just choose it from the open public data. Go to a financial institution and say, “Yep, here I am, Clare Rowley. I represent this organisation. I would like to open a bank account with you”, and that financial institution now has to do the same basic checks, confirming authorised representative, etc. again. To ensure that, I, Clare Rowley actually am an authorised representative of this LEI.

So that has driven us to look more deeply into enhancing the LEI as a digital ID management tool. And we see there is a lot of value to expand the LEI as an organisational identity management tool and the fact that it is this global unique identifier. So, we look to leverage existing technologies such as digital certificates, and we also look into a new model of decentralised business identity, looking into, for example, the principles of self-sovereign identity.

So as to evolve the LEI in that it is not just that 20-digit alphanumeric code to identify firms, but also to enable firms to use it as a way to identify themselves. And verify the authenticity of their counterparty organisations without the need for that additional human intervention. So, we look to evolve the system to ensure it can enable instant and automated trust between legal entities and their authorised representatives.

Oscar: Indeed, the importance of connecting the individual’s identity with organisations, identity. Clare, final question how do you see the LEIs in, let’s say ten years from now?

Clare: So absolutely we believe that digital will drive a lot of the LEI growth and that is just the reality of the world we live in. Indeed, we had the COVID pandemic, now it starts two years ago, but we see that business processes and sectors still struggle with digitisation. So, we believe that this movement, these efforts will continue for many years to come.

But ultimately, digital is the future for business transactions. So, we think that that area will drive a lot of growth within the global LEI system. Right now, there is a major international effort ongoing that is led by the Financial Stability Board with the intent to make cross-border payments faster, cheaper, more transparent and more inclusive.

You will find that the LEI is involved in three of the building blocks of this initiative with our primary building block, our focus being around establishing unique identifiers with proxy registries. So, the initiative it’s very ambitious, but what we really like about it is the visionary approach. So, it is looking very globally at the overall payments ecosystem and what needs to be done to ensure the evolution of the payments ecosystem to achieve those objectives faster, cheaper, more transparent, more inclusive.

And just see, in July of this year, the Financial Stability Board published a recommendation report regarding the LEI in cross-border payments. And you get that same flavour of the broader ecosystem needed to facilitate transactions cross-border in an efficient way. So, some of those recommendations go to international standard setting bodies, such as FATF, the BCBS. And there you will see the focus on using the LEI as a standardised identifier for sanctions list publications, but also as a means of identification of legal entity customers, beneficiaries within payments ecosystems, but also generally for customer due diligence.

So, we see that there will be a growth of the LEI in the cross-border payments. To facilitate that growth we envision a greater participation of financial institutions in the issuance and maintenance of the life. And I bring back this term the validation agent that is referring to financial institutions or other types of organisations that have expertise in identity validation verification where they incorporate LEI issuance into their operating procedures for corporate, for customer due diligence to seamlessly provide the LEI to the customer as a by-product of their validation verifications that they’re doing.

Today we have over ten organisations that are participating as validation agents, but we believe that the LEI will become more and more embedded in customer due diligence protocols as the cross-border payment initiative forwards.

And then the other area I mentioned briefly is sustainability reporting. So of course, this is a very hot topic across all sorts of sectors. Knowing the sustainability profile of suppliers, of merchants, etc. And there you see of course; data is core to addressing the question of sustainability and the current climate crisis. And there’s a lot of focus on, well, what metrics are being reported, the different markets, the different cuts you could say maybe it’s looking into carbon markets, human rights, labour conditions, etc. But a very important piece of that is the fundamental question, well, who is being reported on from a company level? And then how do I connect this information? So, a company, let’s just say a manufacturer, it could be reporting information on its carbon footprint, on its use of its participants, and labour markets, etc.

And those could be going to very different regulators, very different investors, consumers of information. And then, of course, there also publishing the traditional financial information on their investments, on their balance sheets, income statement, etc. All of that needs to be brought together in a way that facilitates analysis, facilitates investors to understand better the profile of the company, supervisory authorities, purchasers, the customers that would be interested in engaging in supplier relationships.

And so, you see identity is a fundamental pillar of helping us to address the data question around sustainability reporting. So, we believe that also as the interest and the as the world around sustainability reporting becomes more standardised, you will find the LEI there growing as a tool to connect. You could say some of that real world information on the sustainability reporting with then also the financial markets information coming from companies.

Oscar: Fantastic. Great to see how LEIs are going to help us on these challenges in the coming years. Thanks a lot, Clare, for joining us.

Clare: Well, thank you, Oscar. A pleasure again to catch up.

Oscar: There is no doubt that innovations will keep coming and will bring us surprises that are hard to imagine today. In the future, when you log into a digital service, not only you will have proved who you are but also which company you belong and if you can legally represent such business, all verified on real time.

These innovations will help fight against “musty” businesses, will help with international trade, will help us empower the real job creators, and more.

Don’t be surprised if a world in which LEIs are more ubiquitous than passports is the world we live tomorrow.

This was a special story episode of Let’s Talk About Digital Identity.

Thank you to our guest Clare Rowley. The story of this episode was edited by myself, Oscar Santolalla with help of Chloe Hartup and Elena Sanz. Want to hear more about LEIs? Next week we have an episode on the Electronic Trade Documents Bill. Stay tuned!

View Details

Let's talk about digital identity with Bianca Lopes, co-founder of Talle. Join Bianca Lopes and Oscar as they discuss the top challenges, solutions and achievements for digital identity within the financial industry – the connection to regenerative finance (Refi) and how this is changing identity in finance.

[Transcript below] "I think a lot of the microservices architectures that some of the banks and financial services companies have implemented in their movement to the cloud, or just in their change inside and internally, have opened up their minds to rethink identity across the organisation. " Bianca Lopes is an investor, business builder, economist, and identity expert, who focusing on driving meaningful impact through technology and regulation. Leading many significant identity projects and having helped transform how data can unlock financial and social worth. With a central focus on how we can rewire finance using the power of digital identity, ethics, and Web3.

Bianca is driven by how we negotiate competing values with data and information technologies. In her work I have supported over 40 financial institutions and 8 governments to reshape their approach to technology, rethink the role of identity, and leverage their innovation agendas. She manages an international speaking calendar to help business leaders, governments, and consumers understand the impact that data, privacy, and finance will continue to have on our lives.

Bianca’s journey and lived experience have informed her worldview. Born in Brazil, educated in Canada, based in Denmark and multilingual, she has encountered both sides of economic and digital development. Her mission is to build bridges and create value. She is honoured to work with UNESCO’s International Research Center on Artificial Intelligence. Here we facilitate cooperation in developing artificial intelligence with special emphasis on supporting the development of a vibrant AI ecosystem Globally.

Connect with Bianca on LinkedIn, Twitter or Instagram - @biasmlopes.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining a new episode of Let’s Talk About Digital Identity. And today, we'll hear how the financial industry is redefining itself. And of course, what is the role of identity on this. For that, we a have special guest who is Bianca Lopes. As an investor, business builder, economist and identity expert, Bianca Lopes focuses on driving meaningful impact through technology and regulation. Leading many significant identity projects, she has helped transform how data can unlock financial and social worth. Bianca's central focus is on how we can rewire finance using the power of digital identity, ethics, and Web 3.0. Hello, Bianca.

Bianca Lopes: Hello, Oscar, thank you for having me.

Oscar: First, tell us about yourself and what was your journey to this world of identity?

Bianca: All right. Well, I guess I'll start where my sort of journey on this Earth started. I'm from Brazil, originally. I'm an economist, as you mentioned, and my journey started in data centres. I was actually putting biometric hardware in physical parameter security. And I got into this after working at the bank for few years, I worked as a trader, and I worked in commercial banking. And then I worked in risk management and came to work with my client. And he was building this business. And this business was in the biometric space.

And back in the day, it was kind of like, you know, minority report, when you told people you worked in biometrics. And little did I know that that's where my journey in identity was meant to start. And that was about over 13 years ago. It's been incredible. It's been a journey of purpose and a journey of understanding what an industry ...

View Details

Let's talk about digital identity with Viky Manaila, Trust Services Director at Intesi Group. In episode 79 Oscar and Viky discuss eIDAS 2.0 and EU digital identity wallets – what eIDAS 2.0 is and why it was created, what lessons were learnt from eIDAS and how have these helped to build eIDAS 2.0, and how the EU digital wallets relate to eIDAS 2.0.

[Transcript below] "So, the aim of eIDAS 2.0 is to achieve the targets set in Europe's path to digital decade. Eighty percent of EU citizens being able to use a digital ID by 2030…" Viky Manaila is an international expert in the field of electronic signatures, digital identity and digital transformation processes, who has successfully promoted the electronic business globally.

She has been technical expert to the European Commission for instituting Regulation 910/2014 (eIDAS) on electronic identity assurance and the design and roll-out of European, cross-nation e-procurement platforms and operations. She is member of different high level working groups set up by the European Commission, ETSI and the US Government aimed at aligning policy and operations around trust identity, digital signatures and cross-recognition.

Viky has successfully contributed to standardisation work for the global acceptance of European Trust Services, as an expert in ETSI ESI Specialist Task Force 560. Global Acceptance of EU Trust Services is a study of existing trust services that operate in different regions of the world and their possible mutual recognition or global acceptance.  The eIDAS Regulation and corresponding standards go beyond EU boundaries, proving that interoperability and cross-border legal recognition are the keys for global electronic commerce and transactions.

Viky is also President of Cloud Signature Consortium.

Find out more about Intesi Group.

Connect with Viky on LinkedIn or Twitter.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining us in a new episode of Let’s Talk About Digital Identity. And we are going to hear more about eIDAS 2.0 that is being evolving a lot getting ready and ready. So, for that we have a special guest who is Viky Manaila. She is an international expert in the field of electronic signatures, digital identity and digital transformation processes, who has successfully promoted the electronic business globally. She has been technical expert to the European Commission for instituting Regulation 910/2014 (eIDAS) on electronic identity assurance and the design and roll-out of European cross-nation e-procurement platforms and operations.

Viky is a member of different high level working groups set up by the European Commission, the ETSI, and the US government aimed at aligning policy and operations around trust identity, digital signatures, and cross-recognition. She's also president of Cloud Signature Consortium. Hello, Viky.

Viky Manaila: Hello, Oscar. Hello, everyone. And welcome to Let’s Talk About Digital Identity in Europe this time.

Oscar: Exactly. We're talking about what is happening in Europe. Yeah, fantastic. Nice hearing you. Nice meeting you, Viky. So, let's get started.

Viky: Thank you for inviting me to your show.

Oscar: My pleasure. So, Viky, let's talk about digital identity. So, let's start by hearing a bit more about yourself in your journey to this world of identity.

Viky: Well, my journey into digital services and identity space started back in 2002 when I was preparing my master’s thesis in electronic signatures and cryptography. That time I came across the famous cartoon of New Yorker drawn by Peter Steiner with the two dogs in front of the computer, the old one telling to the smallest one, "On the internet, nobody knows you're a dog." So,

View Details

Let's talk about digital identity with Dr Salah Rustum, founder of CIELTECH. Oscar is joined by Dr. Salah Rustum, founder of CIEL and CIELtech to discuss digital identity in the middle east – what digital identity challenges the organisations in this region are facing, what solutions could be introduced to help these challenges and what cyber laws are in this region and his role in introducing these laws.

[Transcript below] "Everybody wants to be on the internet, everybody wants to apply in new technologies. The danger is that sometimes they get wrong advice." Dr Salah A. Rustum is a Ph. D. in Aerodynamics and has occupied very high positions in this field including vice presidency at Boeing.

Dr Rustum is also the founder of CIEL a Lebanese Company dealing in Cyber Security ever since 1990 and the founder of CIELTECH of Qatar which has the same concept and has set his mission to support and develop the integrity of information technology and information sent on the Internet.

Connect with Salah on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining this new episode of Let’s Talk About Digital Identity. And today, we'll have a geographical focus perspective in which today we'll focus on the Middle East. And for that we have very special guests who is Dr Salah Rustum. He is a PhD in Aerodynamics, and has occupied very high positions in this field, including a vice presidency at Boeing.

Dr Rustum is also the founder of CIEL, a Lebanese company dealing in cybersecurity ever since 1990. And he is the founder of CIELTECH of Qatar, which has the same concept and has set its mission to support and develop the integrity of information technology and information send on the internet. Hello, Dr Salah.

Dr Salah Rustum: Hi. How are you?

Oscar: Very good. It's a pleasure having this conversation with you.

Salah: It's my pleasure as well to be online with you. And I hope our meeting would be a good one and successful.

Oscar: Absolutely, I'm sure it's going to be. So, let's get started, let's talk about digital identity. And as always, I want to hear something about our guest. So please tell us about yourself and your journey to the world of digital identity.

Salah: Well, as you said, I had my PhD from MIT, I worked with Lockheed Martin to begin with. And then I had an offer from Boeing which I couldn't refuse. And later on, I was moved to, transferred actually to the Middle East, and started Boeing Middle East. It didn't work there due to political reasons. And after that returned to the States continued my aviational career. During which I became the Chairman of the Introductory Commission of the Jumbo Jet in the world. I was the chairman of the Future Planning Commission of Rome Airport, and other different positions that I held throughout the time I served in aviation.

But the most outstanding of my career is my absolute transfer from aviation to technology, which I am intruding on it as my real study is concentrated on aviation and the effect of wind on any object. But the transition was easy as everything based on physics is easy. And it is easy comprehensible. I started with introducing the electronic digital signature as early as 1996. And from there on, it became – the scope became wider and wider. And we got to the extent that we started dealing with cybersecurity, and what it meant at that time and what it means now.

Of course, we did a lot of work on bridging the digital divide, which was very important between the Middle East and the West. And of course, it was very painful in the start, it was a very, very dark tunnel, which I entered. But luckily speaking, I managed to really introduce the sense of the electronic digital signature authentication,

View Details

Let's talk about digital identity with Michael Palage, co-founder of InfoNetworks. In episode 77 Michael and Oscar discuss what DNS can bring to identity – what identity problems DNS can help to solve and how DNS fits with TRAIN. Michael also covers how LEIs are part of this solution.

[Transcript below] "I see the DNS being in an optimal infrastructure to facilitate identity discovery and look up, and one that can seamlessly integrate with the various identity technology stacks that are in the market today."

Michael Palage is an intellectual property attorney and an information technology consultant. He has been actively involved in Internet Governance and ICT issues over the last twenty years. During this time, he has been intimately involved in ICANN operational and policy matters since its formation in both an individual and leadership role, including a three-year term on the ICANN Board of Directors. Currently, Michael is President and CEO of Pharos Global, Inc. which provides consulting and management services to domain name registration authorities and other technology related companies in connection with Internet governance issues. He is also the co-founder of InfoNetworks LLC, an information technology company focused on solutions for building online trusted ecosystems incorporating the federation verified data. He has testified before the United States Congress multiple times and as an expert witness in both Federal and State Court in numerous legal proceedings.

Connect with Michael on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Related links:

FinCEN / FDIC Digital Identity Tech Sprint: Team DNS presentation

InfoNetworks/Microsoft/DigiCert – Domain Name Credential Use Case:

ICANN BC Presentation ICANN72

ICANN BC Presentation

ICANN75

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining to this episode. The DNS is something you might have heard or seen and is an important component of internet. And today, we are going to hear what DNS can bring us about identity.

And for that we have a special guest who is Michael Palage. He is an intellectual property attorney and an information technology consultant. He has been actively involved in ICANN which is the Internet Corporation for Assigned Names and Numbers for operational and policy matters since its formation, and that includes a three-year term on the ICANN Board of Directors.

Palage is President and CEO of Pharos Global, a company that provides consulting and management services to domain name registration authorities and other technology-related companies. Also, he is co-founder of InfoNetworks, which is an information technology company focused on solutions for building online trusted ecosystems incorporating the federation verified data. Hello, Michael.

Michael Palage: Thank you, Oscar. Long-time listener of your podcast, and I really welcome the opportunity to speak with you today.

Oscar: Oh, thank you. It's great having you. And Michael, let's talk about digital identity. And as usual, I want to hear a bit about our guest, so please tell us a bit about yourself and your journey to this world of identity.

Michael: Sure. My journey to identity actually started from the world of identifiers, or as you alluded to, more specifically, the world of internet domain name identifiers. In that journey, I still remember that rather specifically occurred in October of 1994. I had already finished up my engineering degree and I was pursuing my law degree at night at Temple University in Philadelphia while I worked during the day at an intellectual property firm as a law clerk.

And in 1994, I read this article by Joshua Quittner in WIRED magazine entitled Billions Registered. And in this article,

View Details

Let's talk about digital identity with Roberth Lundin, Senior Security Consultant at Knowit. In episode 76, Senior Security Consultant at Knowit, Roberth Lundin, discusses identification services in Sweden alongside Smart Cards – what identification services are available in Sweden and why should someone have a BankID or Freja e-ID as well as what smart cards are and what is interesting about these.

[Transcript below] "But if you take a smart card, for example, well, you can't copy a smart card. That's very important." Roberth Lundin is Senior Security Consultant at Knowit.

For the last years he has been working with Bankgirot as an IT-security specialist, in which one of his most important duties is to coordinate all security audits using risk-based approach, also worked with SOC/SIEM system, identity governance and administration (IGA). In his vast experience he has seen and contributed to the evolution of eIDs in Sweden including smart cards.

Connect with Roberth on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Come to meet us in person. Ubisecure are attending Security Leadership Belgium on October the 5th and 6th in Brussels. Come and meet us to find out how Ubisecure can help with your business challenges in cyber security and CIAM. To find out more, take a look at the Ubisecure events page, www.ubisecure.com/events. See you in Brussels.

Oscar Santolalla: Thank you for joining a new episode of Let’s Talk About Digital Identity. I was thinking, personally, I have been using for accessing many online services, I use many authentication methods, identification services that we have been discussing in this podcast, three years. But one that I have not used is a smart cards. For instance, even though hereby being a citizen of Finland, I have one, but I have not used it before. So that's one of the things we're going to discuss today, how to use a smart card for identification. And also, what are the other identification services in Europe and especially from Sweden that is from where our guest today is coming.

Our guest today is Roberth Lundin. He is a Senior Security Consultant at Knowit. For the last years, he has been working with Bankgirot as an IT Security Specialist in which one of his most important duties is to coordinate all security audits using risk-based approach. He also works with SOC SCM systems, Identity Governance and Administration, IGA among all the roles in his vast experience he has seen and contributed to the evolution of eIDs in Sweden, including smart cards.

Hello, Roberth.

Roberth Lundin: Hello.

Oscar: OK, Roberth. So, let's talk about data identity. But first of course, we want to hear a bit more about yourself. So please, you can tell us, yeah, your journey to this world of the that identity.

Roberth: I started in 1989 at a company named Bull. The first project I got was to finish a secure login and file transfer tool for UNIX, which use smart cards, high security smart cards, actually. Then I have been working for the next 20 years at Bull, Integris, Steria with personalisation systems for smart cards, issue system for electronic IDs and so on.

2009, I started work at Cybercom, which is now named Knowit. 2014, I started the first signing service using DIGGs framework, which I still work with part-time and been working for since 2015 to 2018 with electronic medical certificate and signing of them as a security specialist. And then for 2019, I worked at Bankgirot to secure their operations. That's my background basically, very shortly.

Oscar: Fantastic. We're going to talk about smart cards and also the eIDs in Sweden and Europe. But first, I know something interesting is to think of in a broader aspect all the authentication methods and ways of verifying identi...

View Details

Let's talk about digital identity with David Birch, Principal at 15 Mb and author, advisor and commentator on digital financial services. In episode 75 David Birch discusses digital currencies – the differences between digital currency and cryptocurrency, the role in which identity plays in digital currency and the importance on identity verification within digital currencies.

[Transcript below] "Digital currency needs some form of digital identity, that might actually drive digital identity forward and help digital identity to develop into the mass market." David G.W Birch is an author, advisor and commentator on digital financial services. Principal at 15Mb, his advisory company, he is Global Ambassador for the secure electronic transactions consultancy, Consult Hyperion, Fintech Ambassador for Digital Jersey and Non-Executive Chair at Digiseq Ltd. He is an internationally-recognised thought leader in digital identity and digital money. Ranked one of the top 100 fintech influencers for 2021, previously named one of the global top 15 favourite sources of business information by Wired magazine and one of the top ten most influential voices in banking by Financial Brand, he created one of the top 25 “must read” financial IT blogs and was found by PR Daily to be one of the top ten Twitter accounts followed by innovators (along with Bill Gates and Richard Branson).

His latest book “The Currency Cold War—Cash and Cryptography, Hash Rates and Hegemony” (published in May 2020) “paints a fascinating and stimulating picture of the future of the world of digital payments and its possible impact on the wider global and economic orders” – Philip Middleton, OMFIF Digital Monetary Institute. His previous book “Before Babylon, Beyond Bitcoin: From money we understand to money that understands us” was published in June 2017 with a foreword by Andrew Haldane, Chief Economist at the Bank of England. The LSE Review of Books said the book should be “widely read by graduate students of finance, financial law and related topics as well as policy makers involved in financial regulation”.  The London Review of Books called his earlier book “Identity is the New Money'' fresh, original, wide-ranging and “the best book on general issues around new forms of money”.

More information is available at www.dgwbirch.com and you can follow him @dgwbirch on Twitter.

Connect with David on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and welcome to a new episode of Let’s Talk About Digital Identity. Today, we'll talk about digital money, especially a type of digital money that I see that not many people are discussing today. Except, of course, our special guest who is David G. W. Birch. He is an author, advisor and commentator on digital financial services, Principal at 15 Mb, his advisory company. He is Global Ambassador for the secure electronic transaction’s consultancy, Consult Hyperion. He is Fintech Ambassador for Digital Jersey and Non-Executive Chair at DIGISEQ Limited. He is an internationally recognised thought leader in digital identity and digital money. Also, author of several books including his latest book, The Currency Cold War: Cash and Cryptography, Hash Rates, and Hegemony. Hello, David.

David Birch: Hello, Oscar. Thank you so much for inviting me.

Oscar: It's a real pleasure talking with you and super interesting topic we're going to discuss today about digital money. So yeah, let's start a conversation. Let's talk about digital identity. I would like to hear first, a bit about yourself and your journey to the world of identity.

David: Oh, sure. OK. Well, my background originally was in secure communications, and originally for military and government purposes. And then, of course,

View Details

Let's talk about digital identity with Heather Flanagan, Principal at Spherical Cow Consulting. In episode 74, Heather Flanagan discusses making identity easy for everyone – how to explain digital identity to people outside of the identity industry, why is it important for everyone to understand, and what the industry can do to improve the understanding of identity for everyone.

[Transcript below] "If you talk to any identity professional, they will agree that passwords are one of the biggest, possibly the biggest challenge facing the industry. So how are we solving it?" Heather Flanagan, Principal at Spherical Cow Consulting and choreographer for Identity Flash Mob, comes from a position that the Internet is led by people, powered by words, and inspired by technology. She has been involved in leadership roles with some of the most technical, volunteer-driven organisations on the Internet, including IDPro as Principal Editor, the IETF, the IAB, and the IRTF as RFC Series Editor, ICANN as Technical Writer, and REFEDS as Coordinator, just to name a few. If there is work going on to develop new Internet standards, or discussions around the future of digital identity, she is interested in engaging in that work.

Connect with Heather on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining us. Today, we are going to hear from an expert in identity about - how from the perspective of, let's say regular people, most of the people, who are not involved in the identity industry, how much they understand the identity, the methods, the technology and everything that we in this industry are building. So, we're going to talk about how we can make identity easy for everyone.

For that, our guest is Heather Flanagan. She is Principal at Spherical Cow Consulting, and Choreographer for Identity Flash Mob. She comes from a position that the Internet is led by people powered by words and inspired by technology. She has been involved in leadership roles with some of the most technical, volunteer-driven organisations on the internet, including IDPro as Principal Editor, the IETF, the IAB as RFC Series Editor, ICANN as Technical Writer just to name a few. Hello, Heather.

Heather Flanagan: Hello, Oscar.

Oscar: Nice having you.

Heather: Thank you. It's great to be here.

Oscar: Excellent. This is going to be super fun talking about how to make identity easy for everyone. Let's see how our conversation goes. So yeah, let's get started, let's talk about digital identity. First, I would like to hear a bit more about yourself, please tell us your journey to this world of identity.

Heather: Oh, you know, very few people actually decide that "You know, digital identity, that's going to be my career." In my case, I have a liberal arts degree as a history major, and a library science degree for my master's degree. I mean, I was supposed to be a librarian when I grew up. But as is often the case, once the person falls into tech, everything ends up touching on digital identity.

So immediately after university, I ended up working for the public research division of a newspaper that was just starting up an ISP. So, this was the mid '90s, there weren't a lot of experienced tech people to hire. And that ISP started hiring people who, you know, are you smart? Are you logical? Can you learn from a book? And there, as a sysadmin, I had to worry about creating user accounts and making sure that those users were able to access what they were allowed to on a system and only what they were allowed to on a system.

When I left the ISP, I went to work for a large software company where again, the fundamental reason for even having an infrastructure IT team was to make sure that people could access wh...

View Details

Let's talk about digital identity with Ann Cavoukian, Executive Director of the Global Privacy and Security by Design Centre. In our series opener, Ann Cavoukian discusses Privacy by Design – the 7 foundational principles, the issues that it aims to solve and how Privacy by Design has evolved and is being used in today’s tech products.

[Transcript below] "You want to prevent the privacy harms from arising, not just resolve them after the fact, you want to prevent them." Dr. Ann Cavoukian is recognised as one of the world’s leading privacy experts. Dr. Cavoukian served an unprecedented three terms as the Information & Privacy Commissioner of Ontario, Canada. There she created Privacy by Design, a framework that seeks to proactively embed privacy into the design specifications of information technologies, networked infrastructure and business practices, thereby achieving the strongest protection possible. In 2010, International Privacy Regulators unanimously passed a Resolution recognising Privacy by Design as an International Standard. Since then, PbD has been translated into 40 languages! In 2018, PbD was included in a sweeping new law in the EU: the General Data Protection Regulation.

Dr. Cavoukian is now the Executive Director of the Global Privacy & Security by Design Centre. She is also a Senior Fellow of the Ted Rogers Leadership Centre at Ryerson University, and a Faculty Fellow of the Center for Law, Science & Innovation at the Sandra Day O’Connor College of Law at Arizona State University.

Connect with Ann on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and welcome to join us a new episode of Let’s Talk About Digital Identity. And you might have heard about Privacy by Design before all the influence that has had in products and regulations, et cetera. And today, we'll hear about that from its own creator. So, our guest today is Dr. Ann Cavoukian. She is recognised as one of the world's leading privacy experts.

Dr. Cavoukian served an unprecedented three terms as the Information and Privacy Commissioner of Ontario, Canada. There she created Privacy by Design, a framework that seeks to proactively embed privacy into the design specifications of information technologies, network infrastructure, and business practices, thereby achieving the strongest protection possible. Today, Dr. Cavoukian is the Executive Director of the Global Privacy and Security by Design Centre. Good morning.

Dr. Ann Cavoukian: Good morning, Oscar.

Oscar: Good morning. And it's fantastic having the pleasure of having this conversation with you.

Ann: Thank you. It's my pleasure.

Oscar: Please tell us shortly how, yeah, your journey to this word of privacy and digital identity?

Ann: Well, you know, it's interesting. When I became Privacy Commissioner, for the first term in '97, I think, I joined the office and it was full of brilliant lawyers who wanted to apply the law to data breach or privacy infraction and get a good resolution, which is great. But I wanted something earlier than that. I wanted something that was proactive. That by design could be embedded into the operations that you have, bake it into the code, make it a presence, so that you could prevent the privacy harms from arising. I wanted a model of proactive protection. And it took a while to sell this to my staff, to my lawyers. But I literally created Privacy by Design at my kitchen table over three nights. It was all about being proactive. That's how it came about.

Oscar: OK, super interesting. If you can tell us, what is that concept for the ones who are not so completely familiar.

Ann: So, Privacy by Design is all about being proactive. You want to prevent the privacy harms from arising,

View Details

Let's talk about digital identity with Simon Moffatt, CEO and Analyst at The Cyber Hut. In episode 72, Simon Moffatt from The Cyber Hut discusses what is next for identity and access management – what his recent research has shown regarding passwordless authentication and next generation authorisation, alongside what trends are emerging in IAM and how he sees the IAM landscape evolving in the future.

[Transcript below] "I think the technology is there today, I think there are numerous different solutions, whether it's based on sort of biometrics, or perhaps standards, like FIDO and WebAuthn that provide us with the tools and techniques to rid ourselves of passwords." Simon is Founder and Analyst at The Cyber Hut - a leading boutique industry research, analysis and advisory firm focused on identity, access and cyber security technology. He has a 20+ year career within the identity and access management space having worked for consultancies, startups and global software vendors.  He is a published author and contributor to identity standards at the likes of NIST and the IETF.  He is also a Fellow of the Chartered Institute of Information Security.

His long running research is focused upon next generation authorisation and emerging authentication technologies as well as having an interest in the history of code breaking, signals intelligence and cyber warfare operations.

Find Simon on LinkedIn.

Find out more about The Cyber Hut.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Let's Talk About Digital Identity will be returning for Series 4 on Wednesday 17th August 2022.

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining. Today, we are going to hear now what is next for identity and access management. And we have a guest who really does a lot of research and training and consultancy about specifically identity and access management. Our guest today is Simon Moffatt. He is Founder and Analyst at The Cyber Hut, a leading boutique industry research, analysis, and advisory firm focused on identity, access, and cybersecurity technology.

He has more than 20-year career experience within the identity and access management space, having worked for consultancies, start-ups, and global software vendors. He is a published author and contributor to identity standards as the likes of NIST and the IETF. He's also fellow of the Chartered Institute of Information Security. His long running research is focused upon next generation authorisation and emerging authentication technologies, as well as having an interest in the history of code breaking, signals intelligence, and cyber warfare operations.

Hello, Simon.

Simon Moffatt: Hi, Oscar. How are we doing? It’s great to be here today.

Oscar: Pretty good. It's a pleasure talking with you, Simon. So definitely, we want to hear what's coming in identity and access management. So yeah, let's get started. Let's talk about digital identity. And first, we would like to hear a bit more about yourself, especially what was your journey to the world of identity.

Simon: Yeah, thanks. It's such a fascinating area, identity. I've been fortunate to have been in it for just over 20 years, which is a little bit scary when I say that out loud. But I guess like any technology in any sort of technology trend, 20 years is an absolute lifetime. And there's been so many changes in actual products that are available, the standards, how technology is used, it seems an absolute world away.

But I started my career back in 2001, working in industry, like most people probably do when they when they start their careers. And I was working for a large insurance company in the UK for three or four years. And I was essentially doing identity by hand. I was creating accounts on RACF mainframe,

View Details

Let's talk about digital identity with John Wunderlich, Information Privacy and Security Expert. Join Oscar and John Wunderlich in this week’s podcast episode, 71, as they discuss mobile credentials – what are the challenges and solutions surrounding mobile credentials, what is IAM's role in this and how systems need to be developed around trust.

[Transcript below] "So, you have different levels of assurance in the physical world, just as you do in the digital world. So, anybody can issue a credential, the question is what level of authority you give to the credential."

John Wunderlich is an information privacy & security expert with extensive experience in information privacy, identity management and data security. He has designed, built, operated and assess systems for operations and compliance in the private and public sectors for over 25 years. This included working or consulting for Fortune 500 corporations, government ministries, small companies, volunteer organisations, regulators and health system organisations of all sizes.

Connect with John on LinkedIn and Twitter or email him at john@wunderlich.ca.

This is the Report on mobile Driving License Privacy:

https://kantarainitiative.org/download/pimdl-v1-final/

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: In the recent years, there have been organisations across the world creating, for instance, mobile credentials, and specifically mobile driving licenses. So, we're going to discuss about this topic, and also the privacy side of this super interesting system that has been around. So, for that, we have an expert who is joining us today. My guest today is John Wunderlich. He is an information privacy and security expert with extensive experience in information privacy, identity management, and data security.

He has designed, built, operated, and assessed system for operations and compliance in the private and public sectors for over 25 years. These includes working or consulting for Fortune 500 corporations, government ministries, small companies, volunteer organisations, regulators, and health system organisations of all sizes.

Hello, John.

John Wunderlich: Hi, Oscar, how are you doing?

Oscar: Very good. It's a pleasure talking with you.

John: Likewise.

Oscar: Fantastic. That's a super interesting topic we're going to discuss today about mobile credentials, so yeah, let's talk about digital identity. But first, of course, we want to hear something a bit more about you as a guest. So please tell us your journey to the world of digital identity.

John: Long story short, I used to be Corporate Systems Administrator, Network Administrator, Operations Manager, and the Federal Privacy Law in Canada was introduced, I took that as a project at my company, and it turned into a career. When I moved from the corporate side to working for a regulator, I first met Kim Cameron, a name that most of your listeners will know, working with the Privacy Commissioner of Ontario, shortly after he introduced the Seven Laws of Identity. And around the same time, my former boss introduced the idea of Privacy by Design.

So, for me going back 15, 16 years privacy and identity have been in lockstep. There's a very large Venn diagram overlap between the two. And I've been consulting and working on standards and volunteer areas in that joint area since then.

Oscar: Excellent. Yes, just a few years ago, maybe almost two, a bit more than two years ago, we met in Kantara Initiative, in one of the working groups, and you are super involved there. And I know that recently, you and other authors have released one document called Privacy and Identity Protection in Mobile Driving License Ecosystem. So first of all, kudos for that very good report.

View Details

Let's talk about digital identity with Rachel O’Connell, Founder & CEO, and Nicky Hickman, Product Innovation Manager, at TrustElevate. In episode 70, Nicky Hickman and Rachel O’Connell of TrustElevate discuss children’s digital identity – why this is so important, what challenges are currently being faced and what solutions need to be put in place to help protect children within the digital landscape.

[Transcript below] "There is a clear and present need for regulatory drivers to enhance children's safety online to ensure the companies are held accountable and are transparent in terms of the measures that they take to keep kids safe online. And critical and central to that is digital identity." Nicky Hickman

Nicky Hickman is a freelance product & innovation manager based in the UK with international experience in APAC, Europe and Africa.  With a background in telecoms she has worked with digital identity and personal data markets for ~20 years researching, designing and delivering multi-channel large scale CIAM services and strategies for clients including Vodafone, O2, GSMA, Barclays, Sky and Verizon.  In the last 5 years she has been a contributor to open-source communities at the Sovrin Foundation, where she served as a Trustee and Chair of the Identity for All Council,  and at Trust over IP Foundation where she is a co-chair of the Human Experience Working Group.  Nicky is also an active researcher and is an industry contributor and guest lecturer at the University of Jyväskylä’s Blockchain & Digital Identity Start-Up Lab in Finland.

Find Nicky on LinkedIn.

Dr. Rachel O'Connell

Dr Rachel O’Connell is a leading expert on online child safety. Her PhD examined paedophile activity online and  the implications for investigative strategies. Rachel set up the first UK Internet safety centre in 2000; she was Chief Security office for Bebo a social networking platform 2006-2010. Rachel is the founder of TrustElevate, author of a technical standard published by the British Standards Institution that describes how to verify the age band a person belongs in a privacy-preserving, secure manner.

Find Rachel on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and welcome to this new episode. And today, we'll talk about enabling and protecting children's digital identity. And for that, we have two guests who are working together in this very important issue.

Let me introduce my first guest, it’s Nicky Hickman. She is a Freelance Product and Innovation Manager based in the UK with international experience in the Asia Pacific, Europe and Africa. With a background in telecoms, she has worked with digital identity and personal data markets for 20 years researching, designing and delivering multichannel, large-scale CIAM services and strategies for clients including Vodafone, O2, the GSMA, Barclays, Sky, and Verizon.

All of Nicky's recent work focuses on using digital identity to promote socio-economic inclusion, and impact against the United Nations Sustainable Development Goals with an underlying commercial business model that is sustainable for the long-term. For the last year, Nicky has focused on youth and child identity through work with a UNICEF YOMA programme, and with TrustElevate as a Product and Innovation Manager.

Our second guest is Dr. Rachel O’Connell. She is a leading expert on online child safety. Her PhD examined paedophile activity online and the implications for investigative strategies. Rachel set up the first UK Internet Safety Centre in 2000. She was Chief Security Officer for Bebo, a social networking platform between 2006 and 2010. Rachel is the founder of TrustElevate. She's an author of a technical standard published by the British Standards Institution that describes...

View Details

Let's talk about digital identity with Aaron Painter, CEO at Nametag. In episode 69, Oscar and Aaron discuss identity in the metaverse - including Aaron's vision for how both people and organisations can prove their identity in the metaverse, and what virtual platforms can do to make their communities safer/more trustworthy.

[Transcript below] "I'm deeply optimistic that we can create this metaverse environment, or the next generation of the internet or Web 3.0, with a greater sense of authenticity behind people to create safer and more trusted spaces." Aaron Painter is the CEO of Nametag Inc, the company who invented "Sign in with ID" as a more secure alternative to passwords. He is the former Vice President and General Manager of Microsoft China, Hong Kong, and Brazil as well as best-selling author of LOYAL, where he describes his key to leadership: fostering a culture of listening.

Find Aaron on LinkedIn.

Nametag is the fast, safe, everywhere ID with a mission to bring authenticity to the internet and enable people to build more trusted relationships. Through sophisticated, proprietary AI-technology, Nametag verifies people, not passwords, creating the next generation of digital security. The app uses multi-factor authentication, government ID verification, and biometric recognition to ensure only users have access to their own data. Nametag never stores, sells, or mines a user's data. By putting privacy first, Nametag gives the consumer control over sharing your personal information, and the power to choose when it's shared, where it's shared, and for how long.

Find out more about Nametag at www.getnametag.com.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello. And today, our guest is a very special guest - it's Aaron Painter, and he is the CEO of Nametag, the company who invented "Sign in with ID" as a more secure alternative to passwords. He is the former Vice President and General Manager of Microsoft China, Hong Kong, and Brazil as well as best-selling author of LOYAL, where he describes his key to leadership: fostering a culture of listening.

Hello, Aaron.

Aaron Painter: Hello, Oscar.

Oscar: Welcome. It's a pleasure talking with you.

Aaron: Thank you. It's an honour to be here. I love the show. I learn so much from each episode so it's really a privilege to be on.

Oscar: Fantastic. Definitely, super interesting, the conversation we're going to have actually about a topic we have not talked before in this show is the metaverse. So, let's get started. Let's talk about digital identity. And of course, we first want to hear about our guest, so what was your journey to come to this world of identity?

Aaron: My journey was really growing up in technology. I spent about 14 years at Microsoft, started in Redmond near Seattle. And then the rest of my career was outside the US. I spent four years in France, two-and-a-half years in Brazil, five-and-a-half years in China, mostly doing international development, working with large customers of Microsoft's, partnerships, helping Microsoft expand into new geographies. I loved it. I got to experience so many different people and cultures around the world.

I left and then went to run a cloud computing consultancy firm based in the UK called Cloudreach for a couple of years. And I left in December of 2019, just before the pandemic. That's where it all started.

Oscar: Since when you started in identity, already in your work in Microsoft, you start entering, immersing yourself in this world of identity, or it came much, much more recently?

Aaron: Identity came to me much more recently. And it was because so many customers that I was working with at Microsoft and later at Cloudreach were fascinated with security. Increasingly,

View Details

Let's talk about digital identity with Bo Harald, Founding Member at MyData Global Network. In episode 68, Bo discusses all things eIDAS 2.0 – what eIDAS 2.0 is and how it differs from eIDAS 1.0; the opportunities with Self-Sovereign Identity (SSI) and eReceipts; public and private sector involvement; what the world can learn from the Nordics for projects like eIDAS and GAIN; and how smaller players can influence the Commission’s decisions.

[Transcript below] "Some people say that this is more important than the Internet, I agree… During 40 years of digital work, I've seen a lot of important things, but this is the biggest by far." Bo Harald has been named as one of the most influential technologists of the 20th century by Institutional Investor, and has been awarded for advancing the Information Society by the Finnish Ministry of Transport and Communications. He currently works as an independent advisor at Findy.fi, a Senior Advisor at the Finnish Council of Regulatory Impact Analysis, a Founder and Steering Committee member at MyData.org, and with the publicly funded Real Time Economy programme. He also has an active role in the Finnish eIDAS 2.0 workgroups.

Connect with Bo on LinkedIn.

Find Bo's open letter to the EU Commission posted in Finextra -https://www.finextra.com/blogposting/22017/open-letter-to-the-eu-commission

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: You might have heard of eIDAS before, especially if you are in the payment industry. But now in the recent years, the European Commission is working on a new version, eIDAS 2.0. We're going to talk about that and especially from the perspective of Finland. We have a special guest who has been working in Finland. And our special guest today is Bo Harald.

He started his career in banking in the 1970s by promoting and building electronic banking, payments, and e-business services. He developed Nordea's Electronic Banking and payments operation for 30 years, after which he started working with TietoEvry as the Head of Executive Advisors.

He has also served as the Chairman of the EU Expert Group on Electronic Invoicing, the Chairman of Mobey, Mobile Financial Services Forum, and has held and holds directorships in various companies and associations. He has been named as one of the most influential technologists of the 20th century by Institutional Investor, and has been awarded for advancing the Information Society by the Finnish Ministry of Transport and Communications.

Bo currently works as an independent advisor at Findy.fi, a Senior Advisor at the Finnish Council of Regulatory Impact Analysis, a Founder and Steering Committee member at MyData.org, and with the publicly funded, Real Time Economy programme.

Hello, Bo.

Bo Harald: Hello, and thank you for having me.

Oscar: It's a pleasure, Bo. Thanks for joining us. And definitely, I want to hear all these very interesting things about eIDAS 2.0. So let's start, let's get started. Let's talk about digital identity. We'd like to hear from your very extensive and varied background in banking and technology. Please tell us a bit more about your career journey - how everything until today working in the Finnish eIDAS 2.0 workgroups.

Bo: Yeah, it's a long ladder, and I want to call it a ladder. It started back in the late '70s, when we developed the first versions of home banking, the PC banking in the very early 1980s for private customers at Union Bank of Finland, and nowadays Nordea. And also for SMEs long before internet. And the first step was obviously with payments, invoice payments, typically, bill payments. And then we moved on to put all banking services actually into e-banking before internet already. And so that was the first phase.

View Details

Let's talk about digital identity with Schehrezade Davidson, CEO of Tricerion, Sarah Walton, Code of Conduct Programme Manager at Women in Identity, and Amit Sharma, Founder and CEO at FinClusive. Episode 67 explores inclusive identity. Making identity solutions inclusive for everyone wanting (or needing) to use them is a topic that's coming more and more to the forefront of the identity industry. From logging into apps, to accessing essential services; to how barriers to organisation identity is impacting individuals - in this episode, we speak to three guests from the identity industry on what they're doing to help solve these issues.

[Transcript below]

Schehrezade Davidson

Schehrezade Davidson is the CEO of Tricerion Limited, a company that owns novel patented mutual authentication software using image passwords. Find Schehrezade on LinkedIn. Find out more about Tricerion at tricerion.com. Schehrezade has appeared on the podcast twice before, talking about: neurographic passwords (episode 26) and immunity passports (episode 41). "If the onus is on the individual to authenticate themselves, those in the industry need to make it truly inclusive with alternative ways, depending on a customer’s needs." Sarah Walton

Dr Sarah Walton is a digital consultant, author, coach and public speaker. She founded Counterpoint in 2003 to support organisations become digital, innovate and grow. Most recently she led the UK Open Finance programme and is Women in Identity’s ID Code of Conduct Programme Manager, as well as being commissioned by the Open Identity Exchange to author ID Inclusion reports. Find Sarah on Twitter @sarahlwalton and on LinkedIn. Find out more about Women in Identity at www.womeninidentity.org. "This is very much something that is very commercially important but it’s also extremely important to people’s lives and livelihoods on an individual basis." Amit Sharma

Amit Sharma has engaged in a myriad of roles that intersect financial markets, risk management, regulatory compliance, and international development. He is the Founder and CEO of FinClusive, a hybrid FinTech and RegTech company dedicated to financial inclusion. Connect with Amit on Twitter @ASharma_VT and on LinkedIn. Find out more about FinClusive at finclusive.com. Amit has featured on the podcast before, discussing the role of identity in financial inclusion (episode 51). "From a macroeconomic perspective, it’s important to note that identity challenges are often seen as just at the individual level, but these at the institutional or entity level are equally important." We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Welcome to the Let's Talk About Digital Identity podcast. I'm Francesca Hobson and I'll be guest hosting this episode of the podcast all around inclusive identity.

Francesca: When I say I work in Identity, my friends and family usually don't know what I'm talking about. To explain, I'll often give the example of signing up to an app and logging in – which really doesn't begin to cover the myriad of use cases that identity enables (some of which we’ve explored on this podcast), but it's such a common experience that it's often the easiest for them to relate to. They're touching our industry several times a day, many of them without really thinking of Identity as the key to so many processes.

Of course, that's not the case for everyone. Some people, often the more vulnerable in society, are only too aware of how important identity is to accessing and using services. Security is clearly high priority for service providers when it comes to identity, as is regulatory compliance. But when these aspects aren't correctly balanced with user experience - or when users with varying abilities, technical proficiency, or access to resources are not fully catered for – there is a very real risk that the intended users will be excluded from, or have trouble,

View Details

Let's talk about digital identity with Keiron Dalton, VP and UK Country Manager at Prove. In episode 66, Keiron talks to Oscar about mobile/phone-centric identity, and what it offers to users and organisations that other types of identity/security measures can't. They also explore the key challenges when it comes to mobile identity and how to mitigate against those, particularly when it comes vulnerable people.

[Transcript below] "Mobile is obviously the most relevant future-proofed method of verification." Keiron Dalton is currently UK Country Manager and VP for International market development at Prove. Prior to Prove, Keiron has had roles within the GSMA’s mobile connect programme, BT’s mobile identity division and successfully helped to establish the UK mobile identity eco system as it stands today.

Connect with Keiron on LinkedIn.

Find out more about Prove at prove.com.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Welcome to a new episode of Let’s Talk About Digital Identity. And as you know pretty well, from experience and hearing from others, mobile phones are super important for identity, already they are having a leading role into that. So that's what we're going to discuss today.

And our guest today is Keiron Dalton. He's currently UK Country Manager, and VP for International Market Development at Prove. Prior to Prove, Keiron has had roles within the GSMA's Mobile Connect programme, BT's mobile identity division, and has successfully helped to establish the UK mobile identity ecosystem as it stands today.

Hello, Keiron. Welcome.

Keiron Dalton: Hi, thanks for having me.

Oscar: It's a pleasure talking with you, Keiron. Definitely, it's going to be a super interesting conversation. And of course, we first would like to hear more about you, our guest today, and how you came to this world of digital identity.

Keiron: Yeah, sure. So, it's probably been about a 10-year journey now. So prior to that I was kind of in a product management role working in a number of different areas. But then I joined a start-up that was based in the north of the UK. And what we did was we recognised the opportunity around mobile, when it comes to identity, authentication, and fundamentally verifying who the user is. And what we did was we accessed, at that time, data from mobile networks to establish account takeovers, things like that.

So that was, like I say, probably about 10 years ago. So over the last 10 years, it's been really a focus of mine to get that concept to be kind of recognised more legitimately. So working with a number of the, in particular, banks, working with telcos and that's globally. And that led me to joining, for example, the GSMA, working with their Mobile Connect programme, helping BT with their mobile identity proposition.

And then now I'm in Prove, where really, it's taking that kind of 10 years of insight and 10 years of kind of understanding of value, and helping Prove bring that to market, both in the UK and anywhere really outside of the US. So it's been an interesting ride. But yeah, I think it's probably, in terms of momentum, it's probably as fast paced as it's ever been. So yeah, it's quite an exciting time.

Oscar: Excellent. So if you can tell us very shortly what Prove does, if it's more into the mobile authentication or to identity verification, what would you say?

Keiron: And so we have a very kind of short sentence to explain what we do, which is it's phone-centric identity. So what we do is, if you think of it as being - and obviously, it can get more complicated than this - but it's basic as leveraging the phone number as a mechanism to understand if you can trust the device, the number, the person, et cetera at the other end.

View Details

Let's talk about digital identity with Ubisecure IAM Academy hosts and Vinay Sawarkar. In this shorter bonus episode, Oscar discusses IAM Academy – Ubisecure's free training on Identity and Access Management (IAM) and our Identity Platform for our partners and customers. Listen to the episode to find out why we launched the courses, how they've evolved over the years, a clip from the training, and why it's so important to keep up to date on IAM.

[Transcript below] "Understanding IAM well is crucial for professionals across companies, not only for the IT folks as it used to be in the beginning of the century." We'll be back to the usual schedule next week! In the meantime, catch up on episodes with guests featured in this episode:

Creating an open-source IAM wiki with Open-Measure Founder, David Doret – Podcast Episode 45 Digital transformation and identity compliance in India with Vinay Sawarkar, Claidroid – Podcast Episode 47 Identity management in Mergers & Acquisitions with Keith Uber, Ubisecure – Podcast Episode 53

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: It was the early 1960s when Identity was introduced to the digital world, way before computers became an essential part of our everyday life. Computer scientist, Fernando Corbató, introduced passwords into the computing world as a method to secure access to files. Yes, identity is much older than what we normally think. 

David Doret: I think my oldest bibliographic reference in IAM dates back to 1967. That sounds absolutely amazing, no?

Oscar: Indeed! That was David Doret who created Open Measure, a wiki that has built and maintains a dictionary of accurate definitions of Identity and Access Management terms. 

Another word that is in everyone’s vocabulary today, the Internet, only appeared in the late 80s. The 90s saw how Internet became commercial and global. The original Internet’s Identity and Access Management infrastructure was based on RADIUS, a protocol that did authentication, authorisation, and accounting.  As more and more companies built web applications that allowed access to outside users, companies opted for developing their own identity solutions to handle their own needs. Such in-house solutions were easy at first, (such as a web form plus a SQL database) but later they became complex, and expensive and difficult to maintain.  

Later, in the 2000s, a massive number of people got online, reaching the billion mark. However, the world was not yet familiar with the term Identity and Access Management.

What did IAM really mean? What were the business benefits? During those years, Finland was one of the pioneering countries building the IAM that the Internet needed. That’s how Ubisecure was founded in 2002. After years solving problems and developing a mature IAM platform, one thing was noticed: the lack of knowledge and understanding of the key concepts around the Identity and Access Management world. Let’s hear Keith Uber, who experienced those days working for Ubisecure. 

Keith Uber: When I joined the company in 2009 a training system was in place for our partners and for our customers, and we would use that for providing custom training together with the implementation projects on a one-one basis. Around that time, we started to think about productising that training and making it more generic. What we found in the sales process was many of the buyers, or even partners at that stage, were unfamiliar with many of the new concepts in this rapidly changing Identity and Access Management world. A lot of the terms were unfamiliar, a lot of the ideas and concepts were new.

Around that time, the then CEO, Juha Remmes, had the idea to productise the training and create a separate brand around the training called ...

View Details

Let's talk about digital identity with Jessica Figueras, Founder at Hither Strategy. In episode 64, Oscar and Jessica explore the ethical issues surrounding digital identity, and what's happening to ensure ethical use of identity in the UK and globally. Plus, how organisations can continue to protect themselves while staying on the right side of this ethical minefield.

[Transcript below] "These issues are just too important to leave to business as usual. These issues are everyone's responsibility to fix." Jessica is a strategist specialising in trust and security, governance, and the role of tech in civil society. She works with start-ups and scale-ups on commercial strategy, and advises UK Government on technology and policy issues relating to cyber crime and online harms. Previously Jessica led multi-million pound research and data programmes for companies including Dods, GlobalData and Ovum, and has advised senior executives in large established tech companies as well as many VC-backed scaleups.

She is currently Vice Chair of the UK Cyber Security Council, and was previously Chair of the Board at NCT, the UK's largest charity for parents. She is a sought-after speaker and commentator, and has published extensive research on the application of emerging technologies across government, telecoms and other regulated industries.

Find Jessica online at jessicafigueras.com, on Twitter @JessicaFigueras and on LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: The emerging ethics of digital identity is what we're going to discuss today. And our guest today is Jessica Figueras, founder at Hither Strategy. Jessica is a strategist specialising in trust and security governance, and the role of tech in civil society. She works with start-ups and scale-ups on commercial strategy, and advises the UK Government on technology and policy issues relating to cybercrime in online harms.

Previously, Jessica led multimillion pound research and data programmes for companies including Dods, GlobalData and Ovum, and has advised senior executives in large established tech companies, as well as many venture capital-backed scale-ups.

She is currently Vice Chair of the UK Cyber Security Council, and was previously Chair of the Board at NCT, the UK is largest charity for parents. She is a sought-after speaker and commentator and has published extensive research on the application of emerging technologies across government, telecoms, and other regulated industries.

Hello, Jessica.

Jessica Figueras: Hi, thank you so much for inviting me.

Oscar: It's great having you, Jessica. It's super interesting, the conversation that we're going to have now. So let's talk about digital identity. And first of all, I would like to hear a bit more about yourself, if you can tell us about yourself and your journey to the world of identity.

Jessica: Sure. So in fact, I mean many people I found to work in the field of digital identity, it's interesting, actually how many have a background in the telecoms industry, which is my background as well, originally. So around 20 years ago, I worked at a company called Ovum, which was at that time, the leading European tech analyst firm. And I was really focusing on how you had, for the first time, the telecoms industry converging with the mainstream IT industry. And as mobile telecoms operators started to get to grips with the consumer web, it was really clear that one interesting asset they had, mobile telcos had, was identity. And so you know, I became very interested in ways in which telcos might be able to use their knowledge of the identity of the user in different ways. And in those kinds of use case.

So after that, I moved away from telecoms and for the past eight years,

View Details

Let's talk about digital identity with Richard Slater, Head of Managed Services at Amido. In episode 63, Richard fills us in on the latest developments in the UK Government’s Identity strategy; how the public sector should be approaching IAM in 2022; how organisations can ensure IAM implementations are successful/top mistakes to avoid; and creating a successful identity user experience (UX).

[Transcript below] "There is absolutely no reason in 2022 to be looking at on-prem environments for hosting IAM." Richard Slater started writing code on a second hand ZX Spectrum before he was 10. Today, Richard works as Head of Managed Services at Amido, a London-based start-up working on identity and microservices projects for some of the largest companies in the UK. He lives and breathes DevOps which means he is a vocal proponent of best practices for their software development teams, focusing on continuous-deployment, systems thinking, reducing feedback cycles, configuration-management, infrastructure-as-a-code and cybersecurity.

Find Richard on Twitter @richardslater and LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and today, in this episode, we're going to talk about identity and also identity and access management, what is happening in the UK government and also in the public sector of this part of the world. So, for that, we have a very special guest.

Richard Slater started writing code on a second hand ZX Spectrum before he was 10. Today, Richard works as Head of Managed Services at Amido, a London-based start-up working on identity and microservices projects for some of the largest companies in the UK. He lives and breathes DevOps, which means he is a vocal proponent of best practices for software development teams focusing on continuous-deployment, systems thinking, reducing feedback cycles, configuration-management, infrastructure-as-a-code and of course, cyber security.

Hello, Richard.

Richard Slater: Hello, Oscar. Thank you for inviting me on.

Oscar: It's a pleasure having you Richard and well, let's start talking about, let's talk about digital identity. So first of all, I would like to hear a bit more about yourself, if you can tell us about yourself, and especially your journey to this world of identity.

Richard: Sure, yeah. So, over the course of the last, I don’t know, 20 odd years in the IT industry, I've kind of written my fair share of login pages. At one point in time, I was a dotnet developer, before that, I was a systems administrator. So that kind of gave me interaction with enterprise IdAM solutions, like Active Directory. But then also, as a developer, you know, consumer IdAM, from the point of view of login pages are required for the vast majority of applications that I've ever written in my time.

And then about 10 years ago, I joined Amido, and had the opportunity to deliver over that time, about half a dozen identity platforms for kind of big and small companies, both public and private sector. And then I started to move my career over time much more towards the cybersecurity side, and really enjoy the kind of IdAM side of it. And that kind of led me into cybersecurity.

However, I then really realised that cybersecurity was the thing that kind of got left behind in DevOps. And actually, that's the area where the innovation needs to happen to really kind of change the world, change the way that we approach IT, including IdAM, including cybersecurity in general, and kind of shift left on that thinking. And IdAM is a huge part of that.

Oscar: Yeah, absolutely, absolutely. Yes, as I read from your bio I found on Stack Overflow, yeah, you said, you live and breathe DevOps. And of course, yes, security, cybersecurity is something that is super important t...

View Details

Let's talk about digital identity with Olly Brough, Managing Director of EMEA at Trusona. In episode 62, Olly discusses all things WebAuthN – including what it is exactly, when and why you would use it, cost savings enabled by WebAuthN, how secure it is compared to other standards, and how easy it is to use and deploy.

[Transcript below] "WebAuthN is the most exciting development that I've seen over the last four and a half years working with Trusona" Olly Brough is Managing Director of EMEA at Trusona Inc. Olly has built his career delivering best in class payments, anti-fraud and identity solutions to leading retail, financial services and public sector clients working with a variety of high growth technology companies in Europe and overseas. Prior to joining Trusona Olly led European sales and marketing functions of privately-owned technology businesses through to successful exit including QAS; an identity and data quality business, Eiger Systems; a consumer payment collection platform, Cambridge Global Payments and cross border bank payments service and 41st Parameter; the online device intelligence platform where Olly previously worked with Ori Eisen.

Find Olly on LinkedIn.

Find out more about Trusona at trusona.com.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Authentication without passwords is the goal that many businesses have already set, but very few have delivered. Now, WebAuthN is one of the standards that we hear the most lately. So today we'll have a critical assessment of WebAuthN. And we'll see, is it ready to deliver its promise? And for that we have a special guest who is Olly Brough.

He's Managing Director of EMEA at Trusona. Olly has built his career delivering best in class payments, anti-fraud, and identity solutions to leading retail, financial services and public sector clients working with a variety of high growth technology companies in Europe and overseas. Prior to joining Trusona, Olly led European sales and marketing functions of privately-owned technology businesses to successful exit including QAS; an identity and data quality business, Eiger Systems; a consumer payment collection platform, Cambridge Global Payments; a cross border bank payments service, and 41st Parameter; the online device intelligence platform.

Hello, Olly.

Olly Brough: Hello, Oscar. Good morning to you.

Oscar: Good morning. And welcome, let's talk about data identity. But as always, I want to hear more about our guests. So please, Olly, tell us a bit more about yourself and how was your journey to this world of identity.

Olly: Thank you, Oscar. So yeah, my name is Olly. I'm based here in the UK. My focus is, as you said, has been very much around growing technology companies across Europe. I think I somewhat stumbled into the world of identity. I first joined, over 25 years ago, a data verification business that was at the time flexed on helping organisations increase the integrity of their name and address data for old style mailing campaigns, just before the internet was a big thing.

But of course, that morphed into identity verification, because once you have names and addresses and date of birth, you can then start to verify identities. And that business was acquired by Experian, the big PLC. Then really through that, my experience sort of morphed into identity verification. And then I got into the whole area of online security, which is where I am now initially through 41st Parameter, but now focusing on Trusona.

And then finally I dipped into payments along the way. But then payments, as you know, is also very heavily associated with the world of online authentication because payments can't happen unless they've been authenticated in the right way. So yeah,

View Details

Let's talk about digital identity with Aran Khanna, Co-Founder & CEO of Archera. In episode 61, Oscar talks to Aran about how social media companies handle identity management and data privacy, and considerations for businesses offering social media identity providers for login to their online services.

[Transcript below] "Identity plays a different role in different places around the social ecosystem today that is really dependent on what the goal of that underlying social platform is and sort of what regulatory regime it operates under." Aran Khanna has been labelled many things. Thought leader. Innovator. And (at times) troublemaker. Now, in his search to give technological control back to developers and business leaders, he’s added cloud management entrepreneur to that list as the Co-Founder & CEO of Archera, a company that helps organisations find cloud solutions that fit their companies.

Find Aran on Twitter @arankhanna.

Find out more about Archera at archera.ai.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thank you for joining. Today, we'll have now a conversation with an entrepreneur in the tech industry that is not directly connected in the identity industry, but they are very innovative company and the CEO has a very interesting story to tell us.

So let's welcome Aran Khanna. He has been labelled many things. A thought leader, an innovator and at times, a troublemaker. Now, in his search to give technological control back to the developers and business leaders, he has added cloud management entrepreneur to that list, as being the co-founder and CEO of Archera, a company that helps organisations find cloud solutions that fit their companies.

Hello, Aran.

Aran Khanna: Hi, Oscar. Thanks so much for having me.

Oscar: Welcome to the show. Let's talk about digital identity. But of course, first of all, we want to hear your story, a bit of your journey, how, since the beginning of your career, you end up in this world of – you tell us about your company, and also about identity, please tell us.

Aran: I can tell the short version here, I don't want to bore you guys with a 30-minute background. But in short, I was born and raised in Seattle, I've really grown up all my life around technology. Both my folks worked at Amazon and Microsoft in the early days. And my first foray into technology was actually working at, funnily enough full circle, at the cloud provider that was soon to become Azure, it was called something different back then. But essentially started in that world. Really, from there, I started to get really interested in digital privacy as myself and all of my friends at college and high school were migrating all of our communications, all of our financial activity on to platforms like Facebook, Venmo, Twitter, etc., Instagram, right?

And I started to think a little bit about particularly the data leakage that was coming out of that sort of migration of really society, and started my journey as a privacy researcher in college working with the former FTC CTO Latanya Sweeney on a number of projects, including one very well-known one that actually got me fired from Facebook for revealing some pretty invasive defaults that they had in their platform around location sharing.

From there, I actually went into machine learning research, there was very interesting story behind that, but really started working on fundamental deep learning research, and actually then got pulled right back into the cloud world when AWS acquired that team that was working on to become their internal deep learning team. We launched a number of products at Amazon. And I started again, to start seeing this disconnect between platform users and the platforms themselves and the rules they wer...

View Details

Let's talk about digital identity with Nick Mothershaw, Chief Identity Strategist at the Open Identity Exchange. In episode 61, Oscar speaks to Nick about the Open Identity Exchange (OIX)'s role in the Global Assured Identity Network (GAIN), plus the OIX Trust Framework 2022. Nick discusses what makes a trust framework work for its intended users, and how to make it interoperable with other frameworks.

[Transcript below] "When things work for users, they get adopted." Nick is Chief Identity Strategist at the Open Identity Exchange, a community for all those involved in the ID sector to connect and collaborate. Together they develop the guidance needed for interoperable, trusted identities on a global basis. Through OIX’s definition of, and education on, Trust Frameworks it creates the rules, tools, and confidence to allow every individual a trusted, universally accepted, identity.

Find out more about the Open Identity Exchange at openidentityexchange.org.

Nick has expert knowledge of Identity and Fraud techniques, solutions, and standards across a wide variety of different sectors and jurisdictions. He was previously Director of ID and Fraud at Experian where he was responsible for the development of Experian’s fraud and identity solutions for both the public and private sectors. Nick led Experian’s development, launch and operation of a full “Identity as a Service” solution which was the first live example of a Digital ID being seamlessly interoperable across public and private sector.

Find Nick on Twitter @OIX_Nick and on LinkedIn. Follow OIX on Twitter @OpenIDExchange.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and welcome to a new episode of Let’s Talk About Digital Identity in this new year, 2022. And we have, after some time, again, our friends of the Open Identity Exchange. And today, our guest is Nick Mothershaw. He is the Chief Identity Strategist at the Open Identity Exchange, a community for all those involved in the identity sector to connect and collaborate.

Nick has expert knowledge of Identity and Fraud techniques, solutions and standards across a wide variety of different sectors and jurisdictions. Nick was previously Director of Identity and Fraud at Experian, where he was responsible for the development of Experian's fraud and identity solutions for both the public and private sectors. Nick led Experian's development, launch and operation of a full "Identity as a Service" solution, which was the first live example of a digital identity being seamlessly interoperable across public and private sector.

Hello, Nick.

Nick Mothershaw: Hello, Oscar. Hello.

Oscar: Welcome. It's great having you, Nick.

Nick: It's a pleasure to be here. And yeah, Happy New Year to you and all your listeners, very exciting to be at the start of 2022, which I think it's going to be an amazing and transformational year for digital identity. So this is a really timely conversation.

Oscar: Yeah. And I know you have new things to tell us. So yeah, Nick, let's talk about digital identity. But I'd like to start hearing a bit more about yourself, so please tell us about your journey to the world of digital identity.

Nick: Yeah, it's been a long journey now. So I was originally involved in, I guess, in identity when I worked with law enforcement, providing crime management and intelligence management systems. And after that, we started looking at biometrics. So around the year 2000, we were using biometrics to help identify criminals from group photographs and also using facial mapping to look at, where we used to use these E-FITs, these faces that were being drawn by computer that were put out on things like crime watch programmes, so we're using facial biometrics to match those two datab...

View Details

Let's talk about digital identity with Nat Sakimura, Chairman at the OpenID Foundation. In episode 59, Nat returns to the podcast to explore Financial-Grade API (FAPI), the base security protocol for UK Open Banking, Australian Consumer Data Standard, and Brazil's Open Banking. He discusses why and how FAPI was formed; what exactly FAPI is – including technical characteristics; how FAPI is used today; and future plans for the specification - as well as how it connects to GAIN.

[Transcript below] "The data economy needs a secure and interoperable data network. And we are finally getting there with FAPI and eKYC standards. So, you guys need to get ready for the ride. It’s the time. You need to start acting, start preparing for that." Nat Sakimura is a well-known identity and privacy standardisation architect and the representative partner of NAT Consulting. Besides being an author/editor of such widely used standards as OpenID Connect, FAPI, JWT (RFC7519), JWS (RFC7515), OAuth PKCE (RFC7636) ISO/IEC 29184, ISO/IEC 29100 Amd.1, he helps communities to organise themselves to realise the ideas around identity and privacy.

As the chairman of the board of the OpenID Foundation, he streamlined the process, bolstered the IPR management, and greatly expanded the breadth of the Foundation spanning over 10 working groups whose members include large internet services, mobile operators, financial institutions, governments, etc. He is also active in the public policy space. He has been serving in various committees in the Japanese government, including the Study Group on the Platform Services of the Ministry of Internal Affairs and Communications and the Study Group on the competition in Digital Market of the Fair Trade Commission of Japan.

Find Nat on Twitter @_nat_en and LinkedIn.

Nat also appeared in episode 54 of Let's Talk About Digital Identity, discussing how OpenID Connect took over the world.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and welcome to the first episode of Let’s Talk About Digital Identity for this New Year 2022. And we have a very special guest who has been in very short clips in an episode we had in October, very recently in October. A very special episode, a storytelling episode called How OpenID Connect took over the World, and today’s guest was there. We are talking about our super special guest called Nat Sakimura, one of the creators of the OpenID Connect standard.

Nat Sakimura is a well-known identity and privacy standardisation architect and a representative partner of NAT Consulting. Besides being an author and editor of such widely standards such as the OpenID Connect, FAPI, JWT, OAuth PKCE among others, he helps communities to organise themselves to realise the ideas around identity and privacy. As the chairman of the board of the OpenID Foundation, he streamlined the process, bolstered the IPR management, and greatly expanded the breadth of the Foundation spanning over 10 working groups whose members included large internet services, mobile operators, financial institutions, government, etc. He has been serving in various committees in the Japanese government, including a Study Group on the Platform Services of the Ministry of Internal Affairs and Communications and a Study Group on the competition in Digital Market of the Fair-Trade Commission of Japan.

Hello, Nat.

Nat Sakimura: Hi, Oscar. Thanks for inviting me.

Oscar: Welcome. It’s a great pleasure talking with you, Nat. And well, Happy New Year. And let’s talk about digital identity.

Nat: Likewise, yeah.

Oscar: Fantastic. And I think we know a lot of your involvement, of course, you are leading one of the most important standardisation organisations in the digital space.

View Details

Let's talk about digital identity with Ian Yoxall, CEO at Intragen. In episode 58, Oscar talks to Ian about how far a tighter budget can get you on your Identity and Access Management (IAM) journey. Ian discusses the best approaches to steps prioritisation, avoiding scope creep when it comes to time constraints, how to preserve budget whilst maximising time-to-value, and considerations for a gated funding approach.

[Transcript below] "It can't be words. It's got to be metrics." Originally from New Zealand, Ian started Intragen in 2006 after working for several companies in the US and London. As Principal Consultant of Intragen, Ian has worked on many of the largest projects in the Netherlands and throughout Western Europe. With a broad experience with small and large-scale implementations, both in the private and public sector, he brings a pragmatic approach to problems that arise around identity & access management projects. Prior to joining Intragen, Ian worked for global infrastructure and security vendors and consultancies.

Connect with Ian on LinkedIn.

Find out more about Intragen at www.intragen.com. Intragen is a Ubisecure partner.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thank you for [joining] the last episode of this year 2021 for Let’s Talk About Digital Identity. We are now talking about how to budget projects, identity and access management projects, and we have very a interesting guest for that.

Originally from New Zealand, Ian Yoxall started Intragen in 2006 after working for several companies in the US and in London. As Principal Consultant and CEO of Intragen, Ian has worked on many of the largest projects in the Netherlands and throughout Western Europe. With a broad experience with small and large scale implementations, both in the private and public sector, he brings a pragmatic approach to problems that arise around identity and access management projects. Prior to joining Intragen, Ian worked for global infrastructure and security vendors and consultancies.

Hello, Ian.

Ian Yoxall: Good morning. Hello. And how are you Oscar?

Oscar: Very good. Nice having you here, Ian.

Ian: It’s great to be here. Thank you for the invitation.

Oscar: Our pleasure. And please tell us a bit more how your career, your life led you to this world of digital identity.

Ian: Right. Well, yeah, that’s a long train wreck of a story. So let’s start off. Originally, I started in consulting as a DBA working for the various database vendors in infrastructure, and then moved across into business consulting, still with an infrastructural angle and infrastructural projects. And one day I arrived in London and sort of fell into banking security. And after that, I dropped into the gravity well that became identity and access management. And once you start down the career of identity and access management, you can’t escape. That’s it. That’s the end. Yeah, you can’t go anywhere else.

I think one of the things that attracts people to stay in it is it’s got a high failure rate. I have a personal hobby of flying, and when you fly a plane, nobody expects you to do everything perfectly, but it’s about making fewer mistakes and reducing your risks. And with the rapidly evolving industry that we’re in, it attracts plenty of bad actors. We’ve seen just recently the Log4j issues that have come up. And already that’s been weaponised and deployed very, very quickly. So when you’ve got bad actors who are so willing to try and make a profit here and attract businesses it’s an interesting field to work in.

Oscar: Yeah, it is definitely. It’s an exciting place to be working in these days, right? There are so many things happening, good and bad, of course,

View Details

Let's talk about digital identity with Titi Akinsanmi. In episode 57, Oscar talks to Titi about the various trust frameworks being developed across the world. Titi also explores how the frameworks could interact with each other across borders, how important the frameworks are to ensuring data privacy is upheld, and about the Good ID movement.

[Transcript below] "Digital identity is very much at the core of a lot of the adoption of technology that’s happening." Titi Akinsanmi is a Public Policy thought leader on the digital economy focused on shaping an enabling environment for innovation. A thought leader, coach and mentor, Titi has served as a Berkman Klein Fellow (Faculty of Law, Harvard University from 2018 – 2020); an advisory and steering committee Board member at GoodID, with the World Economic Forum’s Global Future Council on the Digital Economy and on the strategy and advisory team on Digital Identity.

Titi is a member of the Technical Advisory Group (TAG) on the 4th Industrial Revolution of the UNDP (Africa) and serves on the Presidential Advisory Committee on the Digital Economy (StartUpBill.NG) for Nigeria. She sits on the board of nonprofits like the Alliance for Affordable Internet, Yemi Shyllon Museum of Arts and Junior Achievement amongst others.

She has spent the last two decades – globally – advising, speaking and delivering on laws and policies connecting the public, civil and private sectors. Her expertise is discerning which, where, and how regulations and policies help harness digital opportunities while mediating its emerging tensions, addressing gaps and building sustainable allies. She is the Global Policy team lead for Google Assistant and Hardware having previously led the cluster for the global tech giant as the Government affairs and Public policy lead for West & Francophone Africa.

She holds a master's degree in Law specialising in Privacy and Cybersecurity (Osgoode Law) and a master's in Public Policy & Development Management (Uni. of Witwatersrand).

Find out more about Titi at www.titiakinsanmi.com.

Connect with Titi on Twitter @titiakinsanmi and LinkedIn.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and welcome to a new episode of Let’s Talk About Digital Identity and the focus of today, this conversation, is going to be about trust frameworks. For that we have an amazing guest who knows a lot about this, who is Titi Akinsanmi.

She is a Public Policy thought leader on the digital economy focused on shaping an enabling environment for innovation. A thought leader, coach and mentor, Titi has served as a Berkman Klein Fellow, the Faculty of Law at Harvard University from 2018 to 2020; an advisory and a steering committee Board member at GoodID, with the World Economic Forum’s Global Future Council on the Digital Economy and on the strategy and advisory team on Digital Identity.

Titi is a member of the Technical Advisory Group (TAG) on the 4th Industrial Revolution of the UNDP (Africa) and serves on the Presidential Advisory Committee on the Digital Economy (StartUpBill.NG) for Nigeria.

She has spent the last two decades globally advising, speaking and delivering on laws and policies connecting the public, civil and private sectors. Her expertise is discerning which, where, and how regulations and policies help harness digital opportunities while mediating its emerging tensions, addressing gaps and building sustainable allies. She is the Global Policy team lead for Google Assistant and Hardware and having previously led the cluster for the global tech giant as the Government Affairs and Public Policy Lead for West & Francophone Africa.

She is a Mama of three and a wifey to one. Hello Titi.

Titi Akinsanmi: Hello.

Oscar: Very welcome.

View Details

Let's talk about digital identity with Linus Kvarnhammar, Cyber Security Consultant at Syneptic. Following his Swedish TV series, Hackad, professional hacker Linus discusses the biggest risks that insufficient identity management can create for individuals and organisations. Oscar and Linus explore the pitfalls of authentication, authorization (including MFA), and more – and how these lead to security incidents.

[Transcript below] "We have a standard way of identifying a person in real life – passport, driver’s license, national identity card. But as far as I’m aware, we don’t have one that is universally accepted both by the individual and companies" Linus is an independent cyber security consultant and professional hacker. He is also one of the hackers in the TV series “Hackad” on SVT. He has more than 20 years of experience working in the IT industry where the last 10 years have been spent exclusively doing penetration tests of applications and networks with a few social engineering assignments every now and then.

Find Linus on Twitter @lkvarnhammar and on LinkedIn.

Watch Hackad at www.svtplay.se/hackad. You can also find the English subtitles at hackad-english.blogspot.com/2021/11/hackad-tv-2021-english-subtitles.html.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. And today, we’ll hear insights from the world of hackers. Of course, ethical hacking is what we’re talking about. And we have a very special guest with Linus Kvarnhammar. Linus is an independent cybersecurity consultant and professional hacker. He’s also one of the hackers in the TV series Hackad on the Swedish TV SVT. He has more than 20 years of experience working in the IT industry, where the last 10 years have been spent exclusively doing penetration tests of applications and networks with a few social engineering assignments every now and then.

Hello, Linus.

Linus Kvarnhammar: Hello.

Oscar: Very welcome. It’s nice being with you, Linus. And well, good to hear more about the interesting work you are doing there. So…

Linus: Oh, thank you.

Oscar: Please tell us a bit more about yourself and how was your journey to this world of cybersecurity and hackers.

Linus: Yeah. I- the last 10 years or so, I’ve been doing penetration testing as a security consultant. And yeah, my interest in computers started when I got my Commodore 64, I think it was 1987. And then I had an Amiga. And then I started working with computers directly after school and I’ve been doing that since. I also spent some time, some years doing development work, being a .NET programmer. So a quick bit about my background.

Oscar: You also worked as a developer at some point?

Linus: Yeah, yeah. I think my background as a developer, and an IT pro back in the early days, was a good way of getting into security. Because I think, for me, cybersecurity is about knowing how a computer system works and trying to break it, right. So if you know how the application is built, and if you know how operating systems and networks work, then I think you have a good chance of being good at cybersecurity, I think.

Oscar: Yeah. And I can imagine if you have had, since a child you had a computer at home, not many of the ones who are listening to this had that. And yeah, I’m sure you understand. You have time to understand quite well how the computer works exactly as you said and also in your perspective as a developer. So when you were, for instance, a developer, during time you were a developer, you had also this interest in trying to find the vulnerabilities or something that doesn’t work well, you had already this curiosity?

Linus: No, I don’t… Nah, not really, actually. I think I was mostly focused on – focusing on like writing good cod...

View Details

Let's talk about digital identity with Kristofer von Beetzen, Chief Product Officer at Freja eID. In episode 55, Oscar speaks to Kristofer about Swedish verified identity provider, Freja eID. They discuss why Freja was created; how it works; where it can be used; how it compares with BankID; how it ties in with European identity schemes; the importance of organisation identity and Freja's plans for the future.

[Scroll down for transcript] "Everything becomes related to your identity as things become digital." Kristofer von Beetzen is the Chief Product Officer at Freja eID. He joined the company in 2012 and was part of the transformation from a technology-centric IT security company to the cloud-based, user-oriented identity service that is offered with Freja eID today. Kristofer previously worked in media production and advertising and studied marketing at the University of Växjö. His interest, aside from bringing Freja to the world, is writing and he has published several books and columns, among them a crime novel and a book on poker strategy.

Find Kristofer on LinkedIn and Twitter @KvonBeetzen.

Find out more about Freja at frejaeid.com.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining for a new episode of Let’s Talk About Digital Identity. As you may have heard before that Sweden is one of the countries that has one of the best electronic identifications in the world. And we are going to hear specifically one of these systems, which is Freja eID.

So our guest today is Kristofer von Beetzen. He is the Chief Product Officer at Freja eID. He joined the company in 2012 and was part of the transformation from a technology-centric IT security company to the cloud-based user-oriented identity service that is offered with Freja eID today. Kristofer was previously working with media production and advertising, and has studied marketing at the University of Vaxjo. His interest aside from bringing Freja to the world is writing, and he has published several books and columns - among them are a crime novel and a book on poker strategy.

Hello, Kristofer.

Kristofer von Beetzen: Hello. Thanks for inviting me.

Oscar: It’s a pleasure, super interested in hearing about Freja eID, which a few years ago- Ubisecure started work more and more in Sweden, and then I start hearing this name Freja eID. So you will tell us for everybody how exactly this system works, this service. But please, first, we would like to hear from you a bit your personal side. Tell us about yourself, and how was your journey to this world of digital identity.

Kristofer: Yes. So, I started out in the industry, actually, as I said, I came from media production and advertising. I was working with this company, back then was called Verisec. And I was working with their communication and PR and so on. And they were working a lot with the traditional digital identity things like hardware tokens for banks, establishing trust on a pretty high level so that banks could migrate from bank offices to online banking. So this company was actually started already in 2002. And then they also started with some initial product development with an authentication server, and had some plans of going international with this product. So I actually went from being a consultant to the company to joining them in 2012, as a part of their expansion.

And along the way, we kind of figured out that the proprietary solutions, that was kind of the name of the game back then, where you had an authentication server placed in your server room, and then issuing identities from your own organisations to your customers. We saw that, particularly in Sweden, and in the Nordic countries, the use of these kind of communities,

View Details

Let's talk about digital identity with Oscar Santolalla, Nat Sakimura and Petteri Stenius. In this week's special episode, Oscar explores the history of OpenID Connect and how it became so prevalent, with special guests Nat Sakimura, Chairman at the OpenID Foundation, and Petteri Stenius, Principal Scientist at Ubisecure. Listen to the episode wherever you get your podcasts, or read the transcript below. "New technology seldomly completely replaces the older technologies. They will form additional layers, and slowly start replacing it." Podcast transcript Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

It was February 2014, already hundreds of millions of people worldwide had a smartphone in their pockets, with dozens of apps installed, apps like: Snapchat, Spotify, Vine, Skype, and games like Angry Birds and Minecraft. Mobile apps had been booming for a few years, and users were eager to install every app that resonated with them out of a seemingly unlimited stream of new apps. Indeed, the Apple’s App Store had recently reached the 1 million mobile apps milestone.

Not only mobile, but also in web services, for every new app I wanted to use, I needed to create a new user account, which was OK when I could count them with my own fingers. But what if I had 20, 30, 40 apps on my phone. This was becoming a headache for people, but especially it was clear to become a security concern.

Identity professionals had seen this challenge even in their own lives. And there were combined efforts from big tech, mobile operators, identity software vendors, to architect a solution. An early effort was the OpenID standard, which gained promising interaction at the start of the 2010s. With my OpenID user account, I could log into Yahoo, Google MySpace, and dozens of thousands of web services. However, the lack of a uniform user experience didn’t help people and not a massive audience got hooked with the standard.

So, what happened after the setback? A new solution had been cooked by identity professionals, and finally solved this long living problem. OpenID Connect not only solved that problem for the big tech and social networks, but created a modern way of user authentication, especially for mobile.

Today, if you are listening to this podcast, you have definitely used OpenID Connect before, with or without knowing it. To hear a story from the brilliant minds that designed this standard, let’s hear from Nat Sakimura, one of the creators of the OpenID Connect 1.0 Standard, and today, Chairman of the OpenID Foundation. How was the world just before OpenID connect appeared?


Nat Sakimura

Nat Sakimura: So you know, the creation of OpenID Connect actually started in 2009. And contemplation on that was actually done from 2007. Even before OpenID 2.0 was published, right? There were things like XRI, XDI, SAML. And SAML was becoming pretty strong in the market, but at the same time, because of the XMLD Signature problems, people are starting to complain about that.

And the OpenID Connect just started off with three people: Me, John Bradley, and Breno De Medeiros at the corner of the Internet Identity Workshop. And we were just sketching out a protocol, which is really dead simple to implement in the simple cases but at the same time, something that could be extended to a very high security, integrity protected federation protocol. And the years between 2010 and 2013 was spent on drafting it and implementing it.

Actually, a lot of people started implementing OpenID Connect back in 2011 or something like that. And we had multiple rounds of interop tests as well as you know, they were actually deployed in the wild and was tested. So OpenID Connect was actually quite well-implemented by service providers like Google before it was published in 2014.

Oscar: Yes, so that was my understanding that before the standard was published,

View Details

Let's talk about digital identity with Keith Uber, VP Customer Success at Ubisecure. In episode 53, Oscar and Keith explore the role of Identity and Access Management (IAM) in Mergers and Acquisitions (M&A). With the importance of customer experience at the centre, Keith and Oscar discuss standards considerations, available options and practical steps for successful consolidation of IAM systems.

[Scroll down for transcript] "The most important part of mergers and acquisitions is that the customer is the value of the company."

"Take advantage of the opportunities that moving to a new identity and access management system can provide for customers." Keith is VP Customer Success at Ubisecure. As an Identity and Access Management product expert, he leads the Sales Engineering team and is involved in many stages in the planning and design of demanding customer implementation projects. Keith is active in various industry organisations and has a keen interest particularly in government mandated digital identity systems. He holds a bachelor's degree in I.T. and a master's degree in Economics, specialising in software business.

Check out Keith's blog and comprehensive white paper on the topic of IAM in M&A:

Blog - The critical role of Customer IAM in M&A White Paper - Mergers & Acquisitions: Enabling identity integration and opportunities with IAM

Connect with Keith on LinkedIn and follow him on Twitter @keithuber.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. After some time we are having a guest from the house, from Ubisecure, and he is a guest who has been in Ubisecure for 12 years. So let me introduce to you, Keith Uber.

He is the VP Customer Success at Ubisecure. As an identity and access management product expert, he leads the Sales Engineering team and is involved in many stages in the planning and design of demanding customer implementation projects. Keith is active in various industry organisations, and has a keen interest particularly in government mandated digital identity systems. Having been involved in dozens of IAM implementation projects, he is quick to identify organisation’s needs, and provide suitable configuration, integration and roadmap guidance.

Hello Keith and welcome.

Keith Uber: Hello, Oscar. And thank you very much for having me. It’s a pleasure to be here.

Oscar: It is really great talking with you. You had really long experience in Ubisecure and in the industry so have super interesting things to tell us. We will talk about mergers and acquisitions today. But before that, we'd like to hear a bit more about yourself, so please tell us your journey to this world of digital identity.

Keith: For me, digital identity became part of my career when I moved to Finland in 2000. So this was the height of the .com boom. I got a job working for Sonera, which is now Telia, one of the largest Telco operators in the Nordic countries. As part of that role, one of my jobs was to help Telia to combine the login systems for various small start-up companies, various small projects that they had acquired during the .com phase. They acted as a kind of a technology incubator for many small companies too so they had a huge portfolio of disparate services, all with different ways to sign in and authenticate. That’s where my journey started.

So I have a background as a software engineer. I have a Bachelor of IT and previously worked in logistics field as a software developer. But after moving to Finland, I later studied software business then continued after graduation joined Ubisecure and I’ve been working with identity and access management, particularly customer identity and access management ever since then.

View Details

Let's talk about digital identity with Elizabeth Garber, Editor of GAIN. In episode 52, Elizabeth explores the recently announced Global Assured Identity Network (GAIN) initiative. She fills us in on what the GAIN project is, explaining how it's different from other trust networks and why GAIN is good for financial institutions. She also discusses the role of the Global Legal Entity Identifier Foundation (GLEIF) in the project, and what's next for GAIN. "This is really going to unleash creativity and expand access to individuals and communities and sellers all around the world." Elizabeth Garber is a customer and product strategist who started her career in telecommunications and honed her craft in six different industries before joining one of the world’s largest retail banks. She is an expert in designing experiences and delivering transformational change based on a deep understanding of people. This interest has underpinned her graduate studies of the psychology of cross functional teams as well as how customers define value in relation to services they use.

In 2015, she was named one of the top 3 marketers under 30 by the UK Marketing Society and was recognised by Energy UK and EY for her work building Trust across the UK energy industry. In 2017 she won the Financial Times/30% club ‘Women in Leadership’ award.

Find Elizabeth on LinkedIn.

Elizabeth recently played a leading role editing the paper published by more than 150 Identity experts - GAIN: How Financial Institutions are taking a leadership role in the Digital Economy by establishing a Global Assured Identity Network. It was announced at the European Identity and Cloud Conference on 13 September by Nat Sakimura, chairman of the OpenID Foundation, and Gottfried Leibbrandt, former CEO of Swift, and then published by, among others, the Institute of International Finance.

To get involved, email digitaltrust@iif.com or join the LinkedIn group.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining. Our guest today played a leading role editing a paper published by more than 150 identity experts. The paper is called GAIN: How Financial Institutions are taking a leadership role in the Digital Economy by establishing a Global Assured Identity Network. It was announced at the European Identity and Cloud Conference last 13th of September by Nat Sakimura, who is the Chairman of the OpenID Foundation, and Gottfried Leibbrandt, former CEO of Swift, and then was published by, among others, the Institute of International Finance.

Our guest today is Elizabeth Garber. She is a customer and product strategist who started her career in telecommunications and honed her craft in six different industries before joining one of the world’s largest retail banks. She is an expert in designing experiences and delivering transformational change based on a deep understanding of people. This interest has underpinned her graduate studies of the psychology of cross functional teams, as well as how customers define value in relation to the services they use.

In 2015, she was named one of the top three marketers under 30 by the UK Marketing Society, and was recognised by Energy UK and EY for her work building trust across the UK energy industry. In 2017, she won the Financial Times 30% club Women in Leadership Award.

Hello, Elizabeth.

Elizabeth Garber: Hello, thanks for having me.

Oscar: It’s a pleasure. Welcome to our show. And let’s talk about digital identity. And certainly, we always like to start hearing a little bit more about our guest, especially how was your journey into this world of digital identity. Please tell us a bit about yourself.

Elizabeth: Sure. So my name is Elizabeth Garber. As you said, I’m a customer strategist,

View Details

Let's talk about digital identity with Amit Sharma, Founder and CEO at FinClusive. In episode 51, Amit discusses how to address financial inclusion for individuals and organisations – and how identity can both prohibit and enable this. He explores the solutions that are available to facilitate secure Know Your Customer (KYC) and Know Your Business (KYB) processes whilst enabling economic empowerment globally – such as the Legal Entity Identifier (LEI).

[Scroll down for transcript] "Legal entity digital identities are equally as important as the individual identities because they form the gateway to be able to access essential and critical financial services." Amit Sharma has engaged in a myriad of roles that intersect financial markets, risk management, regulatory compliance, and international development. He is the Founder and CEO of FinClusive, a hybrid FinTech and RegTech company dedicated to financial inclusion. FinClusive serves the growing fintech, virtual asset/crypto and other non-bank/alternative financial services sector by providing them the ability to establish insured accounts for themselves and their clients through its growing U.S. based bank partners and conduct cross border transactions over crypto/blockchain and traditional bank payment rails—with an embedded full-stack global-standard financial crimes compliance (FCC) platform. Prior to FinClusive, Amit worked in both the public and private sectors, including with Empowerment Capital, Mitsubishi UFJ, and at the US Treasury Department, first at the inception of the Office of Terrorism and Financial Intelligence (TFI), and later as COS to the Deputy Secretary and Advisor to Treasury’s senior team under Secretary Henry Paulson.

Connect with Amit on Twitter @ASharma_VT and on LinkedIn.

Find out more about FinClusive at finclusive.com.

FinClusive is a Ubisecure/RapidLEI partner. Read more about the partnership in our press release: www.ubisecure.com/news-events/finclusive-validation-agent-gleis/

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining. Today, we talk about the role of identity in financial inclusion. And for that our special guest is Amit Sharma. He has engaged in a myriad of roles that intersect financial markets, risk management, regulatory compliance, and international development. He is the Founder and CEO of FinClusive, a hybrid financial technology and regulatory technology FinTech, RegTech company dedicated to financial inclusion.

Prior to FinClusive, Amit worked on both the public and the private sectors, including the empowerment capital, Mitsubishi UFJ, and at the US Treasury Department first, at the inception of the Office of Terrorism and Financial Intelligence, TFI, and later as a Chief of Staff to the Deputy Secretary and advisor to Treasury’s Senior Team Under Secretary Henry Paulson.

Hello, Amit.

Amit Sharma: Hello, how are you today?

Oscar: Very good. It’s a pleasure talking with you, Amit.

Amit: It’s great to be here. Thank you for having me.

Oscar: Great. So Amit, let’s talk about digital identity. And of course, the first thing we want to hear from our guests is the journey. Please tell us your journey to this world of digital identity and also FinTech.

Amit: Sure. Thank you for that. You listed a little bit on the intro of my bio. I have had the good fortune of being in the development sector. I was a Peace Corps volunteer in Asia. I did development work in Asia as well as in South America. After the tragic events of September 2001, I had the opportunity to join the US Treasury Department, at the time at the inception of what became really a third of the department’s efforts to combat illicit finance, both the US and the global anti-money laundering financial c...

View Details

Let's talk about digital identity with Margus Pala, Founder and CEO at eID Easy, and Johan Nyman, Project Coordinator at Åbo Akademi University. In our 50th episode, Margus and Johan discuss eSignatures. Coming from Estonia and Finland, they explore the use (and potential future use) of simple, advanced and qualified eSignatures in two of the world's most digitally advanced countries. They also delve into how we can standardise the use of eSignatures in Europe, and advice for business owners on what to ask from an eSignature provider.

[Scroll down for transcript]

Margus Pala

Margus is from the world's most digitally advanced country, Estonia, and has seen the future many years ahead of most other countries. He started his professional career as a programming teacher before being part of multiple start-ups, including one unicorn - Playtech. He is also an officer in the Estonian army's National Guard Cyber Unit and has a master's degree in Cyber Security. For the last 5 years he has been running eID Easy, whose mission is to help everyone benefit from the future of digital identity and electronic signatures - not by breeding faster horses, but going to a whole new level.

Find Margus on Twitter @MargusPala @e_id_easy and on LinkedIn.

Johan Nyman

Johan's interest in digital identity, and specifically electronic signatures, is manifested in two areas: 1) the citizens’ perspective; how citizens can take advantage of national PKI (public key infrastructure) available on their ID cards to produce and use qualified electronic signatures, and 2) the public sector; how organisations working within the public realm, e.g. universities, can use national PKI for issuing e-signed documents, and also how they can raise their awareness and knowledge to handle qualified e-signatures in incoming correspondence from persons using e-signatures. He works as a project manager in university administration at Åbo Akademi, in Turku/Åbo, Finland.

Find Johan on Twitter @Johan_Nym and on LinkedIn.

Margus refers to the Finnish Trust Network. Find out more about the FTN here - https://www.ubisecure.com/authentication/finnish-trust-network-ftn/

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining into a new episode of Let’s Talk About Digital Identity. And today, we are coming back with a fireside chat format in which we have two guests. And this time, two guests are going to talk about electronic signatures. For that, let me introduce them. We will have Johan Nyman, who is Project Coordinator, Research and Education Services at Abo Academy University in Turku.

His interest in digital identity and specifically electronic signatures is manifested in two areas. First, the citizens’ perspective, how citizens can take advantage of national PKI, public key infrastructure, available on their ID cards to produce and use qualified electronic signatures. And the second is the public sector, how organisations working within the public realm such as universities can use PKI for issuing electronic signed documents and also how they can raise their awareness and knowledge to handle qualified eSignatures in incoming correspondence from persons using electronic signatures.

And our second guest is Margus Pala, who is founder and CEO of eID Easy. Margus come from Estonia. He proudly says that it is the world’s most digitally advanced country, country which has seen the futures many years ahead of most other countries. He started his professional career as a programming teacher before being part of multiple start-ups, including one unicorn, Playtech. He’s also an officer in Estonian army, the National Guard Cyber Unit and has a master’s degree in Cyber Security. In the last five years Margus has been running the c...

View Details

Let's talk about digital identity with Kay Chopard, Executive Director at Kantara Initiative. In this first episode of series 3, we put your burning questions to Kantara's newly appointed Executive Director, Kay Chopard. Kay explores why identity is so critical in so many applications; her hope for more promotion of Kantara's great work and to advance opportunities for collaboration; Kantara's new mobile drivers licenses (mDLs) work group; Women in Identity and the problem of lack of diversity in standards working groups; and why access and inclusion is one of the biggest challenges facing identity today.

[Scroll down for transcript] "Digital identity is going to be one of the most critical issues going forward, for the world." Kay Chopard is the newly appointed Executive Director of the Kantara Initiative, a non-profit corporation. She is the former President and CEO of Chopard Consulting based in the Washington, DC metro area and is the founder of the Women’s Leadership Institute. Kay has more than 30 years’ experience in executive leadership in government, non-profit, and business organisations, with leadership positions in several organisations including: Identity Ecosystem Steering Group (IDESG), National District Attorneys Association (NDAA), National Criminal Justice Association (NCJA) and the National Highway Traffic Safety Administration (NHTSA). She is an attorney and has served as a prosecutor and maintained a private practice. Ms. Chopard also serves on the Board of Directors of Women in Identity US and volunteers in the leadership of the Women in Identity UK.

Find Kay on Twitter @KayChopardCohen and on LinkedIn.

The Kantara Initiative is a unique global ‘commons’ that operates conformity assessment, assurance and grant of Trust Marks against de-jure standards under its Trust Framework programme, while at the same time nurturing ‘beyond-the-state-of-the-art’ ideas and developing specifications to transform the state of digital identity and personal data agency domains.

Find out more about Kantara at kantarainitiative.org.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. We are after our summer break in 2021. We are coming back with amazing conversations, episodes talking about digital identity from many aspects. And now we have a great pleasure to start this new third season with a person who is the leader of an organisation in the identity industry that is very close to my heart. So let’s introduce her.

Mrs. Kay Chopard is the newly appointed Executive Director of the Kantara Initiative, a non-profit organisation. The Kantara Initiative is a unique global ‘commons’ that operates conformity assessment assurance and grant of Trust Marks against de-jure standards under its Trust Framework programme, while at the same time nurturing beyond the state-of-the-art ideas and developing specifications to transform the state of digital identity and personal data agency domains.

Kay has more than 30 years' experience in executive leadership in government, non-profit, and business organisations in the DC area. She has led several organisations but in identity especially, I would like to mention she was Executive Director of the Identity Ecosystem Steering Group, IDESG, a non-profit organisation developed in a public-private partnership to implement the national strategy for trusted identities in cyberspace, in partnership with the National Institute of Standards and Technology, NIST.

She is an attorney and has served as a prosecutor and maintains a private practice. Kay also serves on the Board of Directors of the Women in Identity US and volunteers in the leadership of the Women in Identity UK. She lectures internationally and has authored several articles an...

View Details

The wait is almost over... series three of the Let's Talk About Digital Identity podcast will return on 25th August - and we've got more fantastic guests lined up!

We're on all the major podcast platforms, so please like/rate (to help others like you find the podcast) and subscribe to get notified of new episodes.

Podcast trailer transcript and links to episodes: [René Seifert, Co-Founder & Co-Head at TrueProfile.io] Please let me just add, I think it's really interesting because I listened to some 80% of your podcast and I think what you're doing - you're doing a great service of building this industry of digital identity.

[Oscar Santolalla] Hi, this is Oscar Santolalla, host of Let's Talk About Digital Identity - a podcast brought to you by Ubisecure. In each episode, I interview bright minds in the digital identity space, focusing on hot topics and stories from the industry.

[Katryna Dow, Founder and CEO of Meeco] It was the film minority report and I don't know if you remember that, or you know super futuristic technologies... I just remember being in the cinema and staring at the screen and thinking "is this really the future?" And in some ways it may look like a marketer's dream.

[Bengt Berg, Head of Compliance Management Services at Cybercom] The most common system or platform to get hacked is the system you didn’t even know that you had.

[Lisa Forte, Partner at Red Goat Cyber Security] Researchers had discovered that goats were able to identify intruders into their herd, just hearing their voice.

[Oscar Santolalla] Subscribe on your favourite podcast platform, to join me and my special guests as we discuss what's current and what's next for digital identity.

View Details

Let's talk about digital identity with Jim Pasquale, EVP Interoperability at digi.me. In the final episode of series 2, Oscar and Jim discuss the problem of "digital exhaust" – the data trail (including identity data) that consumers leave as they go about life online, which they often have little control over. Jim fills us in on why this data needs to be better managed – and how. He also explores the importance of interoperability, given his role as Chair of Kantara's Information Sharing Interoperability working group.

[Scroll down for transcript] "Businesses need to use mechanisms to give data back to the individual - because if you give data, you’ll get better data back" Jim Pasquale is a veteran innovator with a passion for disruption. He has deployed large and complex software systems with the world’s largest telcos and communications companies to improve engagement, conversion and customer experience. Jim is currently EVP Interoperability at digi.me.

Find Jim on LinkedIn and Twitter @jpasquale.

Find out more about the organisations Jim's involved with: digi.me, kantarainitiative.org/groups/isi-work-group and me2ba.org.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

That's a wrap on series 2, but don't worry - we'll be back soon with series 3 of Let's Talk About Digital Identity, the podcast connecting identity and business. Subscribe to get new episodes in your feed, wherever you get your podcasts.

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining this episode at the end of the season for Let’s Talk About Digital Identity. And one of the things we haven’t talked too much is about sharing data - particularly there are scenarios when it’s a definitely a good idea to share data. And for that, we are going to have a special guest who is Jim Pasquale. He is a veteran innovator with a passion for disruption. Jim has deployed large and complex software systems with the world’s largest telcos and communication companies to improve engagement, conversion and customer experience. Jim is also Executive Vice President Interoperability at digi.me.

Hello, Jim.

Jim Pasquale: Good morning, Oscar. And thank you for the opportunity to have this conversation this morning about the importance of providing real-time or near real-time data and being able to share.

Oscar: Yeah, thank you. It’s a pleasure talking with you, Jim. So, I would like to hear more, we would like to hear more about how life led you to this world, working at digi.me and in digital identity.

Jim: Sure. So, I’ve been in the computer industry for over 35 years, predominantly in software and mostly in data communication software infrastructure. What really led me to much of the digital identity work that we do today was my 15-year experience at a company called Novell who had deployed probably one of the very first PC-based or LAN-based X.500 identity programme. And really, when we talk about the idea of identity it goes beyond a person, so it includes people, places and things. And not only how to identify them but how to structurally place them in a directory so that they’re easily accessible and able to be found.

Oscar: Excellent. So from the time at Novell, you were working already on the very early days of identity as we know it today. We have been discussing because we have been collaborating for a couple of years at least in Kantara Initiative in the workgroup related to information sharing. So, we know that today in this fast-paced digital world we are living, there is a lot of what is called the digital exhaust, everywhere, everything we do we are – some data is leaking. Well, we are letting some data, personal data go and of course some companies are taking that advantage. So, tell me from your perspective why this is a serious problem and why we...

View Details

Let's talk about digital identity with Vinay Sawarkar, Founder and CEO at Claidroid. In episode 47, Oscar talks to Vinay about digital identity in India, and its key role in the country's digital transformation and privacy regulation evolution (with the upcoming Personal Data Protection Bill). They also discuss identity in a wider regulatory compliance, security and user experience context, noting Identity and Access Management (IAM) – and particularly Customer IAM (CIAM) – as a core component of success in all three areas.

[Scroll down for transcript] "India is on a very exciting journey of digitalisation." Vinay has over 35 years of varied experience. Over the years, he successfully held numerous roles with increasing responsibilities. He established and managed the global practices in e-Security and Service Management in partnership with global technology leaders. Vinay also led software development centre and corporate IT group earlier. The Oracle E-Business Suite R12 was deployed globally under him, as were set up various quality systems such as ISO 27001 (for IT security), ISO 20000 (for IT services), and CMMi Level 5 (for Software Maturity).

Vinay started his career with VLSI R&D and technology transfer of 68000 based workstations and servers in the initial days of his career. Vinay holds a Bachelor of Engineering from Jabalpur Engineering College and Master of Technology from Indian Institute of Technology, Banaras Hindu University. He is also a Senior Member of Institute of Electrical and Electronics Engineers (IEEE).

Find Vinay on LinkedIn, and find out more about Claidroid at www.claidroid.com.

Claidroid is a Ubisecure partner. Read more about the partnership at www.ubisecure.com/news-events/claidroid-partnership-pr/.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, a podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining a new episode of Let’s Talk About Digital Identity. And today, we are going to have an imaginary trip to India and we are going to hear about digital transformation and identity compliance, among other things. And for that, we are inviting here one guest from our partners who is Vinay Sawarkar. He is the founder and CEO of Claidroid Technologies. With over 35 years of experience, Vinay has successfully held numerous roles with increasing responsibilities. He established and managed the global practices in e-Security and Service Management in partnership with global technology leaders.

Vinay also led software development centre and corporate IT groups earlier. The Oracle E-Business Suite Release 12 was developed globally under him as well as setting up various quality systems such ISO 27001, ISO 20000 and CMMi Level 5 for Software Maturity.

Vinay started his career with VLSI, a very large scale integrated circuits research and development and technology transfer of Motorola 68000 based workstations and servers in the initial days of his career.

Vinay holds a Bachelor of Engineering from Jabalpur Engineering College and a Master of Technology from Indian Institute of Technology, Banaras Hindu University. He is also a senior member of the Institute of Electrical and Electronic Engineers, IEEE.

Hello, Vinay.

Vinay Sawarkar: Hi, Oscar. It’s an absolute pleasure and privilege to be with you in this podcast.

Oscar: Thank you. It’s great having you. I’m really happy to have this conversation with you. And as always, we want to hear a bit more about the guest we talk. So please tell us about yourself and your journey to this world of digital identity.

Vinay: Of course. Very interestingly, I have had the passion for technologies from the early days, so after completing my course and specialisation in Integrated Circuits, I joined a company who was a pioneer in the semiconductor field in India...

View Details

Let's talk about digital identity with Richard Bird, Chief Customer Information Officer at Ping Identity. In episode 46, Oscar and Richard discuss how the Decentralized Identity Foundation is helping people gain control of their online identities and why an open-standards based approach to identity management is the key to better privacy, lower fraud, and a more ethical user experience.

[Scroll down for the transcript] "Decentralised identity will create an empowerment framework for people to have a part to play in their digital identity." Richard Bird is the Chief Customer Information Officer for Ping Identity, a leading identity solution and access management platform. An internationally recognised data privacy and identity-centric security expert, Richard leverages his diverse experiences as a strategic advisor, solutions provider and former global head of identity for JP Morgan Chase’s consumer businesses to challenge current notions about cybersecurity. He is a Forbes Tech council member and has been interviewed by the Wall Street Journal, Bloomberg, The Financial Times, Business Insider, and the NYSE on topics ranging from data protection regulations to cybersecurity enabled consumer protection.

The Decentralized Identity Foundation aims to develop an open ecosystem for decentralised management of digital identities and ensure interoperability between all participants. Find out more at identity.foundation.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for listening. Today we are going to have a discussion about a group of companies, individuals and organisations who are joining forces for solving very important problems today and particularly we’re going to talk about the Decentralized Identity Foundation and for that we have a guest who is from one of these members. The guest today is Richard Bird who is Chief Customer Information Officer at Ping Identity.

An internationally recognised data privacy and identity-centric security expert, Richard leverages his diverse experiences as a strategic advisor and solutions provider to challenge current notions about cybersecurity and identity. He is a Forbes Tech council member and has been interviewed by the Wall Street Journal, Bloomberg, The Financial Times, Business Insider, and the New York Stock Exchange on topics ranging from data protection regulations to cybersecurity-enabled consumer protection.

Hello Richard.

Richard Bird: Oscar, how are you?

Oscar: Very good. It's great having you.

Richard: I appreciate the opportunity to be with you.

Oscar: Yeah, fantastic. It’s great having this conversation. I’m really intrigued to hear more about the Decentralized Identity Foundation. But before that, I would like to hear a little bit about you. So please tell us about yourself and how you joined this world of digital identity.

Richard: Absolutely. It’s a – I think it’s really interesting. It’s always strange to hear anybody read my bio. I feel like, you know, a bit of imposter syndrome. All these opportunities in the last couple of years to talk with all of these different media outlets and one thing that’s interesting, the consistent theme there is just – it’s all business side media outlets.

You know, the journal and CNBC and all of those different organisations and I think a lot of that is because my experience and background has given me the opportunity to be able to translate the complexities, the challenges, the issues in digital identity in a way that the business side of the house can consume and understand.

I spent 20 plus years in corporate and I worked at companies like JP Morgan Chase for many years, Accenture, smaller banks in the Midwest. I also held a Chief Information Officer position and gravitated i...

View Details

Let's talk about digital identity with David Doret, Deputy CISO and IAM Manager at BNP Paribas and Founder of Open-Measure. In episode 45, Oscar talks to David Doret about Open-Measure – the comprehensive, open-source Identity and Access Management (IAM) resource that he created as a not-for-profit initiative. The conversation explores how and why Open Measure came to be – and how anyone working with IAM, in any capacity, can get involved.

[Scroll down for the transcript] "IAM is so transversal within the organisation – we need to work with HR, IT, security, the full workforce, top management, customers – with everyone, basically." David Doret is a cybersecurity and IAM veteran. He worked in advisory services helping numerous organisations strengthen their security posture, held twice the position of CISO and specialised in IAM and risk management. He founded and runs the Open-Measure wiki for IAM professionals. He holds an MSc in Information Security, is certified GRCP, PMP, Lean 6 Sigma Green Belt, CISSP, ISO 27001 Lead Auditor and loves studying MOOCs as a hobby. He is currently Deputy CISO and IAM Manager at BNP Paribas.

Find David on LinkedIn and on Twitter @DavidDoret.

Contribute or provide feedback to Open-Measure at www.open-measure.org, or follow the LinkedIn feed at www.linkedin.com/company/open-measure/. The Open-Measure wiki can be found at open-measure.atlassian.net/wiki.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello. Today’s guest is going to tell us about I would say to me is the most comprehensive IAM, so identity and access management, resource I’ve ever seen and the good thing of this is that it’s open source.

So my guest today is David Doret. David is a cybersecurity and IAM, identity and access management, veteran. He worked in advisory services helping numerous organisations strengthen their security posture. He held twice the position of CISO and specialised in IAM and risk management.

David founded and runs the Open-Measure wiki for IAM professionals. He holds a masters in Information Security, is certified GRCP, PMP, Lean 6 Sigma Green Belt, CISSP, ISO 27001 Lead Auditor and he loves studying MOOCs as a hobby. He is currently Deputy CISO and IAM Manager at BNP Paribas.

Hello David.

David Doret: Hi Oscar. Thank you very much for having me here.

Oscar: You are very welcome. It’s really interesting to hear about Open-Measure and of course about yourself. You have quite a long, comprehensive experience in cybersecurity and especially in IAM. That’s going to be the main discussion point today.

So we would like to hear, before hearing about Open-Measure, a bit more about yourself and how life led you to the world of digital identity.

David: Yes. I think my initial experience with IAM comes back to the early 1990s. So that’s too far away for me to properly collect my memories unfortunately. But yeah, I’m in the business for ages. I’m a dinosaur I would say.

Oscar: OK, OK. So it has been for – probably since the beginning of your career, I guess.

David: Yeah. During quite a long period of time, software development. Also I more or less held nearly all possible positions within an IT department that are possible to hold. My first job was in support. I was doing help desk support. Then I moved into system engineering. But that was decades ago.

From there, I moved into software development and then into cybersecurity. Then I specialised into IAM eventually.

Oscar: Excellent. So now that you are very into IAM, so I’m thinking – as far as I know, less than two years ago you created Open-Measure. So please tell us, what is Open-Measure?

David: The Open-Measure is a wiki. Actually it is first to fall a non-profit association that owns the content that is...

View Details

Let's talk about digital identity with Colin Wallis, Executive Director of Kantara Initiative, and Charlie Harry Smith, Political Theorist at the Oxford Internet Institute. In episode 44, we shake things up with a fireside chat format. Colin and Charlie begin by discussing: "Is digital identity for citizens a commodity?". From their different backgrounds in identity – Colin's tenure as Kantara's Executive Director, and Charlie's work as a political theorist – they explore multiple considerations, including user experience, the role of private organisations in shaping citizen (or resident) identity and how to ensure adoption. As both are currently UK-based, they use the UK government's historical and future plans around digital identity for context, as well as examples from other countries like New Zealand and the US.

[Scroll down for transcript] "[Digital identity] can be delivered effectively, securely, and in a way that's lovely to look at as well. That's an exciting thing and it's an exciting time to be in this industry." Colin Wallis

Colin Wallis is the Executive Director of the Kantara Initiative – the international industry association globally acknowledged for its ethos of no barriers to participation. Kantara is most recognised as a Trust Framework Operator of conformity assessment and Trust Marked schemes for digital Identity, Credential and Consent Management Service Providers.

Colin develops and executes the Kantara Initiative’s strategic plan in concert with the Board and Leadership Council, driving the organisation forward on a broad front with the financial support of private, public sector and individual members from every region of the world and the assistance of a dedicated band of expert volunteers. Colin’s work has been recognised by being named one of the Top 100 Influencers in Identity by independent research company One World Identity.

Find Colin on LinkedIn and on Twitter @KantaraColin. Find out more about Kantara at kantarainitiative.org and www.kantarainitiative.eu. This is Colin's second appearance on LTADI – find his first episode at www.ubisecure.com/podcast/kantara-colin-wallis/.

Charlie Harry Smith

Charlie Harry Smith is a political theorist pursuing a doctoral degree at the Oxford Internet Institute, part of the University of Oxford. In particular, his research considers the normative and theoretical issues surrounding digital governments and the ongoing development of federated identity systems in the UK.

Alongside his research, Charlie regularly consults on digital identity projects. He handles social media monitoring for the Open Identity Exchange and, most recently, has worked with the Digital Equity Association to bring the SMART Africa Trust Alliance – an ambitious cross-continental federated identity scheme – to the pilot project stage.

Find Charlie on LinkedIn, Twitter @charliehrysmith, and on his website - www.chsmith.co.uk.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining this episode which is going to be quite a different format. First of all, we’ll have two guests. Both are based in the UK, but also the format is going to be more free, so there’s going to be a sort of fireside chat. And so, let me introduce you my guests today.

My first guest today is coming for the second time - Colin Wallis. He is the Executive Director of the Kantara Initiative – the international industry association globally acknowledged for its ethos of no barriers to participation. Kantara is most recognised as a Trust Framework Operator of conformity assessment, and Trust Marked schemes for digital Identity, credential, and Consent Management Service Providers.

Colin develops and executes the Kantara Initiative’s strategic plan in concert w...

View Details

Let's talk about digital identity with Erdoo Yongo, Policy and Advocacy Manager at GSMA. In episode 43, Oscar and Erdoo explore the importance of mobile technology to digital identity, and what that means for inclusion in schemes that rely on identification of individuals. From her background in policy and advocacy at GSMA, Erdoo gives specific examples of mobile playing a role in the development of identity – identity enrolment in Nigeria, birth registration in Pakistan, health records in Kenya, and cash value assistance in Zambia. She also explores the challenges preventing mobile from playing a role in the development of digital identity ecosystems.

[Scroll down for transcript] "There are a range of opportunities for mobile technology and mobile operators to play a pivotal role in the development of digital identity ecosystems." Erdoo joined GSMA in 2017. She is a Policy and Advocacy Manager across the Digital Identity (DI) and Mobile for Humanitarian Innovation (M4H) teams. As part of the advocacy and policy team, she is working to create an enabling policy environment for mobile operators to ensure that mobile can be used to support identification of underserved populations and as a platform to deliver humanitarian assistance. Erdoo is thus working with mobile operators, development partners and humanitarian organisations to uncover and resolve policy and regulatory barriers they face in providing mobile services to users.

She also leads GSMA’s research on mandatory SIM registration, exploring its relation to other key indicators in order to establish key trends that inform the work of the DI and M4H advocacy and policy streams.

Erdoo delivers the ‘Digital identity for the underserved and the role of mobile’ Capacity Building course to regulators and policymakers and represents GSMA at a broad range of events.

Find Erdoo on LinkedIn and Twitter @YErdoo.

Find out more about GSMA's Mobile for Development team at www.gsma.com/mobilefordevelopment.

Find the reports that Erdoo refers to at the end of the episode at www.gsma.com/mobilefordevelopment/resources/access-to-mobile-services-and-proof-of-identity-2021/, www.gsma.com/mobilefordevelopment/resources/digital-identity-accelerating-financial-inclusion-during-a-crisis/ and www.gsma.com/mobilefordevelopment/resources/commercially-sustainable-roles-for-mobile-operators-in-digital-id-ecosystems/.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining. Today, we are going to talk about the world of mobile. And for that we have for the second time a guest from the GSMA. So let me introduce you today to Erdoo Yongo. She is a Policy and Advocate Manager across the Digital Identity and Mobile for Humanitarian Innovation teams. As part of the advocacy and policy team, she’s working to create an enabling policy environment for mobile operators to ensure that mobile can be used to support identification of underserved populations and as a platform to deliver humanitarian assistance.

Erdoo is thus working with mobile operators, development partners and humanitarian organisations to uncover and resolve policy and regulatory barriers that they face in providing mobile services to users. Erdoo delivers the digital identity for the underserved and the role of mobile capacity building course to regulators and policymakers, and represents GSMA at a broad range of events.

Hello, Erdoo.

Erdoo Yongo: Hi, Oscar. How are you doing?

Oscar: Very good. It’s a pleasure talking with you Erdoo and I’m very intrigued to hear what GSMA is doing, in particular your work.

Erdoo: It’s a pleasure to be a guest on this show. Thank you for having me, Oscar, as well as Francesca.

Oscar: Thank you. So please,

View Details

Let's talk about digital identity with Mei Ngan, Scientist at the National Institute of Standards and Technology (NIST). In episode 42, we explore Mei's work at NIST evaluating face recognition biometrics with the Face Recognition Vendor Test (FRVT), how accurate facial recognition actually is, and the effects of different variables on the FRVT – face masks (motivated by the pandemic), face morphing as a current FR vulnerability for identity credentials, demographic differentials, and twins – “the forgotten demographic”.

[Scroll down for transcript] "[Face recognition] technology really has come a long way, especially when you only have half the face available to do recognition with. But with that said though, there still remains certain limitations to the technology – such as being able to differentiate between identical twins, demographic differentials and extremely poor-quality photos." Mei Ngan is a scientist at the National Institute of Standards and Technology (NIST).  Her research focus includes evaluation of face recognition and tattoo recognition technologies.  Mei has authored and co-authored a number of technical publications, including the accuracy of face recognition with face masks, evaluation of face morphing detection algorithms, demographic effects in face recognition, performance of facial age and gender estimation algorithms, and publication of a seminal open tattoo database for developing tattoo recognition research, which she received the Special Contribution Award for at the 2015 IEEE International Conference on Identity, Security and Behavior Analysis (ISBA).

Mei was awarded the Department of Commerce Gold Medal Award in 2020 and was a recipient of the 2020 Women in Biometrics Award, a globally recognised award honouring innovative women in the biometrics field.

Find out more about Mei's work at nist.gov/programs-projects/face-recognition-vendor-test-frvt

Find the FRVT leaderboards at pages.nist.gov/frvt/html/frvt11.html (1:1) and pages.nist.gov/frvt/html/frvt1N.html (1:N).

View Women in Identity's webinar with Mei exploring demographic effects in facial recognition here: https://youtu.be/Lni4Pe8dYuk

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining to this episode of Let’s Talk about Digital Identity. And one aspect that is connected to identity and has been like that for many years is face recognition. You have heard a lot in the past years. But also there are new challenges in these recent years, for instance, by the use of face masks, as you can imagine. And for having a deeper conversation about face recognition biometrics, we’ll have a special guest today who is Mei Ngan.

Mei is a scientist at the National Institute of Standards and Technology, NIST. Her research focus includes evaluation of face recognition and tattoo recognition technologies. Mei have authored and co-authored a number of technical publications, including the accuracy of face recognition with face masks, evaluation of face morphing detection algorithms, demographic effects in face recognition, performance of facial age, and gender estimation algorithms and publication of a seminal open tattoo database for developing tattoo recognition research.

And for this, she received a Special Contribution Award at the 2015 IEEE International Conference on Identity, Security and Behavior Analysis. Mei was awarded the Department of Commerce Gold Medal Award in 2020, and was the recipient of the 2020 Women in Biometrics Award.

Hello, Mei.

Mei Ngan: Hello, Oscar. How are you?

Oscar: Oh, very good and really pleased to have you on this conversation with you.

Mei: Yeah, I’m quite happy to be here. Thanks for having me.

Oscar: Fantastic.

View Details

Let's Talk About Digital Identity with Schehrezade Davidson, CEO of Tricerion. In episode 41, Oscar and Schehrezade explore Tricerion's immunity passport – ImmucheX. They discuss the challenges that immunity passports present – including privacy, trust and regulatory compliance - and how Tricerion is responding to those challenges.

[Scroll down for transcript] "Fundamentally it's about trust, it's about accuracy. It's complicated but there is a way forward." Schehrezade Davidson is the CEO of Tricerion Limited, a company that owns novel patented mutual authentication software using image passwords. Find Schehrezade on LinkedIn.

This is Schehrezade's second LTADI podcast appearance. Listen to her previous episode (26), describing Tricerion's neurographic passwords solution, here - www.ubisecure.com/podcast/neurographic-passwords-tricerion-schehrezade-davidson/

Find out more about Tricerion's ImmucheX solution at www.tricerion.com/immuchex.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining another episode of Let’s Talk About Digital Identity and in these days, if one goes to a newspaper or in some other media, we hear, we read about vaccination passports, immunity passports and similar terms and things that are already coming. But today we’re going to have a discussion specifically about these with one of our partners, a company that has been before here in the podcast and they are working on that, an immunity passport.

We’re going to hear what has been their experience and what type of solutions they are bringing. So let me welcome back again to Schehrezade Davidson. She is the CEO of Tricerion Limited, a company that owns novel patented mutual authentication software using image passwords. Hi Schehrezade.

Schehrezade Davidson: Hi Oscar. Lovely to be back again.

Oscar: Yes. A few months ago, a bit more than one year ago, we were having a conversation. We talked about a very innovative product, original product you have had for the last years that are neurographic passwords. So that’s a super interesting conversation we had. So we would like to hear first what happened on Tricerion, on the team, on the labs that you have there and since this month – since the last time we talked. So tell us a bit.

Schehrezade: Yeah, yeah. So really, I think for all of us who are working remotely, it’s about making connections with potential partners and end users. It’s about refining our message and positioning the company to leverage hopefully what will be a better 2021 compared to 2020. So yeah, we’re feeling very positive about our solution and obviously our other exciting projects, which we’re going to talk about today.

Oscar: Yeah, exactly. Then I didn’t know too much at that time when we talked last year but now I know that you have been working on this immunity passport even before that conversation. So that’s one of the main things we talk today. Please to make it go – start from the very, very basic. So what is an immunity passport?

Schehrezade: Yes. I think immunity passports, as people probably know, have been around for a long time whether it was to prove that you'd a disease and recovered from it, for example like smallpox, or whether you can prove that you’ve had a vaccine. So for example like yellow fever.

So the idea and concept of an immunity passport is not really new as we know. Where I think the stakes are slightly different to do with COVID is because we’re looking at something that is a global pandemic. So yeah, very happy to sort of talk a little bit about what we’ve been doing at Tricerion in this area. But just to make it perfectly clear, I think the world is only just beginning to talk about how an immunity passport for COVID would really ...

View Details

Let's Talk About Digital Identity with Roland Adrian, Managing Director at Verimi. In episode 40, Roland fills us in on how Verimi works and its privacy-by-design cornerstones, including data minimisation. Oscar and Roland also discuss the digital identity landscape in Germany and how it's been affected by the pandemic, plus the future of identity in Germany and what needs to happen next.

[Scroll down for transcript] "Customer experience is king at digital identity. And really, technology, security, privacy, whatever it is - it's important, but in a sense it’s a commodity." Roland Adrian has been Managing Director and Spokesman of the Management Board at Verimi since January 2019. Previously, he was Managing Director and Spokesman of the Executive Board at Lufthansa Miles & More GmbH for four years. The business degree holder started his career in 1996 at Roland Berger Strategy Consultants in Munich. After holding leading positions in the KarstadtQuelle Group, he built up the HappyDigits bonus programme from 2002 as a joint venture between Arcandor AG and of Deutsche Telekom AG. In 2009, he moved to PAYBACK in Munich and from 2010 focused on the launch of the programme in India. As Vice President, he led PAYBACK's expansion into various markets worldwide.

Find Roland on LinkedIn or email him at roland.adrian@verimi.com.

Verimi is the European cross industry identity and trusted platform. Verimi combines a convenient central login (Single Sign On), the highest data security and protection standards in line with European law and the self-determination of users regarding the use of their personal data. Verimi was founded in spring of 2017. The identity and trusted platform is supported by a network of thirteen international corporations. The shareholder network includes Allianz, Axel Springer, Bundesdruckerei, Core, Daimler, Deutsche Bahn, Deutsche Bank and Postbank, Deutsche Telekom, Giesecke+Devrient, Here Technologies, Lufthansa, Samsung and Volkswagen.

Verimi is a Ubisecure partner. Read more about the partnership in the press release: https://www.ubisecure.com/news-events/verimi-partnership/

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hi, and thanks for joining. Today, we are going to hear about the digital landscape in Germany. And for that our special guest is Roland Adrian. He is Managing Director and Spokesman of the Management Board at Verimi since January 2019. Previously, he was Managing Director and Spokesman of the Executive Board at Lufthansa Miles and More for four years. He built up the HappyDigits bonus programme from 2002 as a joint venture of Deutsche Telekom. In 2009, he moved to PAYBACK. And as Vice President, he led PAYBACK’s expansion into various markets worldwide.

Hi, Roland.

Roland Adrian: Hi Oscar.

Oscar: Nice talking with you Roland and really happy to hear what is going on in Germany in terms of digital identity and everything related to that. And happy to know more about Verimi. I’ve been hearing 'Verimi' already for the last years and definitely need to hear more details. What are the products you are building and offering today? So please, tell us a bit of your journey how you became the managing director at Verimi.

Roland: Yes. Thank you, Oscar. And many thanks for the invitation. Glad to be here and talk to you a little bit about the market in Germany. So yeah, what was my journey becoming Managing Director of Verimi. Actually, my journey, professional journey, started 25 years ago when I started my career in consulting. Then some stations at Karstadt which is a department store group. And then I founded multi partner loyalty scheme together with Deutsche Telekom. And from there, I moved to PAYBACK which actually is Germany’s leading multi par...

View Details

Let's Talk About Digital Identity with Ben Cronin, Managing Director at UBO Service. In episode 39 of LTADI, Oscar talks to Ben about UBO Service and the challenges it solves around verifying Ultimate Beneficiary Owners, how UBO Service is leveraging Legal Entity Identifiers (LEIs) for KYC and enhanced CDD, and the Global LEI Foundation's validation agent (VA) framework.

[Scroll down for transcript] "It was very obvious to us that adding the LEI to that identification piece was very powerful because you're really identifying and verifying the entity to a very high standard. By using data that we get from official government registries – adding that to an LEI just makes complete perfect sense to us." Serial entrepreneur Ben Cronin founded GBR (Global Business Register) in 2008. GBR morphed into Kyckr over the following years and Kyckr listed on the Sydney Stock Exchange in 2016, providing commercially proven products for the authentication of businesses globally. His roles at Kyckr included Managing Director and Chief Data Officer. Ben is a supporter of Max Schrem’s organisation, NOYB - European Centre for Digital Rights; the fight for data privacy is important for all citizens. Ben played professional rugby with Munster and Ireland in the 90’s. His other interests include tennis, whisky, science and family!

Find Ben on LinkedIn and on Twitter @Ben_Cronin.

Ben Cronin is currently Managing Director at UBO Service. UBO Service offers an innovative new solution for obliged entities to capture accurate Ultimate Beneficial Owner (UBO) declarations in real-time.

Find out more about UBO Service at www.uboservice.com.

UBO Service is in partnership with Ubisecure's Legal Entity Identifier service, RapidLEI. Read more about the partnership in the press release: https://www.ubisecure.com/news-events/ubo-service-lei-validation-agent/

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. We have been in the last months talking once about the LEI, the Legal Entity Identifiers. And today, we’re going to hear very innovative business models that combine some of the solutions to the challenges with LEIs. And for that, we have a very interesting guest today who is Ben Cronin. Ben is Managing Director at UBO Service.

Serial entrepreneur Ben Cronin founded Global Business Register in 2008. Global Business Register morphed into Kyckr over the following years and Kyckr listed on the Sydney Stock Exchange in 2016. Kyckr provided award-winning, commercially proven products for the authentication of businesses globally. Kyckr developed APIs and cloud-based decision engines for best-in-class KYC (Know Your Customer), due diligence and customer on-boarding.

Ben is a supporter of Max Schrem’s organisation, NOYB – European Center for Digital Rights; the fight for data privacy is important for all citizens. Ben has played professional rugby with Munster and Ireland in the ‘90s. Other of his personal interests include tennis, whisky, science and family!

Hi Ben.

Ben Cronin: Hello, Oscar. How are you?

Oscar: Very good. It’s a pleasure having you today to hear about very innovative services and business models that UBO Service is offering today. So, before talking on that, I would like to hear even a bit more about you. Please tell us how your career led you to this world of digital identity.

Ben: Thank you Oscar. And as you mentioned, I was fortunate enough to play professional rugby. So in the ‘90s, the game rugby went professional in 1995 and I was fortunate enough to be I suppose playing at a level that I played. It came when I was amateur and then when it went professional I started getting paid to something that I loved which was fantastic.

View Details

Let's Talk About Digital Identity with Lisa LeVasseur, Executive Director at Me2B Alliance. In episode 38, Lisa and Oscar discuss the Me2B Alliance and how it aims to make technology better for humans, plus the businesses (B-s) which are shining a light on privacy issues and giving the Me-s more control.

[Scroll down for transcript] "We used to call ourselves something like the 'organic food label'. But that's actually not right. We're more like independent automobile crash testing." Lisa LeVasseur is Executive Director at Me2B Alliance, a non-profit organisation that is setting the standard for respectful technology. An MBA technologist with a background in Computer Science and Philosophy, Lisa began strategic work in cellular telecom industry standards in the late ‘90s while at Motorola. Since then, she has participated in 3GPP, 3GPP2, MEIF, WAP Forum, IETF, W3C, IEEE and Kantara Initiative.

Find out more about Me2B Alliance at me2ba.org. Join as a 'Me' or a 'B' at me2ba.org/membership.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. We are going to discuss today something pretty different about the ethical aspects of technology. A lot of technology we are already using. We are using a lot of technologies brought by big tech, by many organisations around the world and we are going to hear what could be a better vision for how the technology treats people in a more respectful way.

For that, I have a very special guest who is Lisa LeVasseur. She is the Executive Director at Me2B Alliance, a non-profit organisation that is setting the standard for respectful technology. An MBA technologist with a background in Computer Science and Philosophy, Lisa began strategic work in cellular telecom industry standards in the late ‘90s while working at Motorola. Since then, she has participated in several other standards organisations such as 3GPP, 3GPP2, MEIF, WAP Forum, IETF, W3C, IEEE and Kantara Initiative. Hi Lisa.

Lisa LeVasseur: Morning. Or evening!

Oscar: Yes, exactly. We’re in the opposite. Quite early for you. The night is falling here in Helsinki. So it’s a pleasure talking with you Lisa. Welcome and let’s talk about digital identity and this very interesting concept and project you are embarking on, Me2B. But I would like to hear more about your beginnings and how things led to the world of digital identity and this latest project you have.

Lisa: Sure. Thanks Oscar. Thanks for having me. I’m really honoured to be here talking with you. So how I got involved in this world was back in 2009, I started working on a product that was designed to put families really in control of their information and the services that they use, whether those services were in the brick-and-mortar world or online services.

And it was through research in that project where I really became aware of – I think it was initially Doc Searls and I maybe became aware of some trust framework stuff and then I sort of unlocked the door to this whole world of people working on identity management and identity standards and realised that there was a whole world of people sort of on the leading edge of this work. That’s how I kind of stumbled in. It was probably around 2012 or so.

Oscar: At that time you were the product manager, building software, building product? That was your role at the time?

Lisa: That’s right.

Oscar: And how did that evolve to today, Me2B, which is relatively new, right?

Lisa: Yeah. Well, interestingly enough, having this sort of long experience in industry standards and being one of four people on the planet who actually like industry standards work, as back – as far as 2009, I actually had this idea when I started to define this product because I had...

View Details

Let's Talk About Digital Identity with René Seifert, Co-Founder & Co-Head at TrueProfile.io. In episode 37, René Seifert talks about the current status of identity in the UK; the government's recent call for evidence and DIU (digital identity unit); the resultant six guiding principles – including privacy and inclusivity; the potential of self-sovereign identity to solve some of these issues; TrueProfile.io and the importance of verified credentials in an HR context; plus the ethical, political and technical challenges of ‘immunity passports’.

[Scroll down for transcript] "I think it's interesting if we overlay this utopia of a self-sovereign identity that sounds maybe like science fiction today, and where these UK digital initiatives are geared, and my best guess is we can and will land somewhere in the middle." René Seifert is a serial entrepreneur and co-head of TrueProfile.io, a credential verification solution provider. Powered by the DataFlow Group, TrueProfile.io provides these services in a modern environment via the adoption of Ethereum blockchain. Prior to this, René was the co-founder and co-CEO of Venturate AG, a crowdfunding platform allowing regular people to invest side-by- side with experienced business angels.

In addition, he has been involved in founding several internet, tech and media companies, among the Holtzbrinck eLab. René, half German and half Croatian, began his career hosting radio shows and running an advertising agency parallel to his studies. He was head of marketing and presenter at the radio station Bayern 3. During the "new economy" he headed the entertainment department at Lycos Europe.

Find René on Twitter @reneseifert and on LinkedIn.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining today, an episode in this New Year 2021 and we are going to discuss, especially now, the digital identity in the UK for this New Year 2021. I have a super special guest today who is René Seifert. He is a serial entrepreneur and co-head of TrueProfile.io, the industry leader in document verification. Powered by the DataFlow Group, TrueProfile.io provides these services in a modern environment via the adoption of Ethereum blockchain. Prior to this, René was the co-founder and co-CEO of Venturate AG, a crowdfunding platform allowing regular people to invest side-by-side with experienced business angels.

In addition, he has been involved in founding several internet, tech and media companies among the Holtzbrinck eLab. René, half German and half Croatian, began his career hosting radio shows and running an advertising agency parallel to his studies. He was head of marketing and presenter at the radio station Bayern 3. During the “new economy” he headed the entertainment department at Lycos Europe.

Hello René. Welcome.

René Seifert: Hi, Oscar. And Happy New Year! My pleasure for this podcast.

Oscar: It’s great talking with you. Thank you. Hope you are having a great start of the New Year 2021. First, we would like to hear more about you particularly, how you have been doing in media and other very interesting things about technology, how your life ended in this world of digital identity?

René: If I knew that myself… I think it’s a quite unlikely scenario that panned out. And maybe you also heard that famous commencement speech from Steve Jobs in Harvard that you only can connect the dots in hindsight, you can’t connect them living your life forward. And let me maybe try to connect these dots. And you mentioned a couple of already things how they evolved in my life.

Indeed, in my first life, as I tend to say, I was sitting on the other side of our conversation, I was a radio presenter, I was a journalist,

View Details

Let's Talk About Digital Identity with Kaliya Young – consultant, conference organiser, author, activist. In episode 36, Kaliya and Oscar discuss the long-running Internet Identity Workshop (IIW) that she co-founded, the effects of moving to virtual identity conferences in 2020, insights from Kaliya's books - 'The Domains of Identity', newly published in 2020, and 'A Comprehensive Guide to Self Sovereign Identity' – plus some great tips for all business leaders on how to view the role of identity in their organisation.

[Scroll down for transcript] "I think we may be selling self-sovereign identity all wrong. It should be infinitely scalable, low-cost federation. That's really powerful!" Kaliya Young is the author of two books “The Domains of Identity” and “A Comprehensive Guide to Self Sovereign Identity”.

For the past 15 years, she has been working to catalyse the creation of a layer of identity for people based on open standards. She co-founded the Internet Identity Workshop (IIW) in 2005 to bring together technologists who want to see decentralised identity come into being. In the fifteen years their community has been meeting, they have created standards being used all over the internet, like OpenID Connect and OAuth. In 2012 she was recognised as a Young Global Leader by the World Economic Forum.

The next IIW is in April. Sign up on Eventbrite.

Kaliya is widely recognised for her community leadership. She travels to Africa and Asia at least once a year to ensure the development of person-centric identity is truly global and inclusive. Most recently, she co-founded HumanFirst.Tech with Shireen Mitchell, a project focused on creating space for diverse voices and building a more inclusive industry.

In 2009, she was named one of Fast Company’s Most Influential Women in Technology.

Find Kaliya on Twitter @IdentityWoman and LinkedIn.

Check out Kaliya's website at identitywoman.net and her podcast with Seth Goldstein, PSA Today (Privacy, Surveillance, Anonymity).

Regular listeners of Let's Talk About Digital Identity will know that Oscar asks every guest for their top tips on how to protect our digital identities. For 2021, Oscar has a new burning question for all LTADI guests – "for all business leaders listening to us now, what is the one actionable idea that they should write on their agendas today?"

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining another episode of Let’s Talk About Digital Identity. Now, that we are starting the New Year 2021 and we are very excited to present a fantastic guest today. She has many interesting things. She’s an author, a speaker, of course an identity expert and she has done so many interesting projects. You are going to hear more about that. So let me introduce you Kaliya Young.

She is the author of two books: The Domains of Identity and A Comprehensive Guide to Self-Sovereign Identity. For the past 15 years, she has been working to catalyse the creation of a layer of identity for people based on open standards. She co-founded the Internet Identity Workshop in 2005 to bring together technologists who want to see decentralised identity come into being. In the 15 years, their community has been meeting, they have created standards being used all over the internet like OpenID Connect and OAuth. In 2012, she was recognised as a young Global Leader by the World Economic Forum.

Kaliya is widely recognised for her community leadership. She travels to Africa and Asia at least once a year to ensure the development of person-centric identity is truly global and inclusive. Most recently, she co-founded HumanFirst.Tech with Shireen Mitchell, a project focused on creating space for diverse voices and building a more inclus...

View Details

Let's Talk About Digital Identity with Khalid Maliki, Co-Founder & Managing Director, and Jimmy J.P. Snoek, Co-Founder & CEO at Tykn. Khalid and Jimmy join Oscar for episode 35 of the podcast, discussing everything Self-Sovereign Identity (SSI) and the SSI company they co-founded, Tykn. The conversation details the 'three pillars of SSI' (verifiable credentials, decentralised identifiers and blockchain), how SSI fits with existing processes, what it should appear as to end users (and what level of education they need around the technology), the importance of accessibility for inclusivity, and what's next for Tykn.

[Scroll down for transcript] "In 5 years, people should take [SSI] for granted" Khalid Maliki

After many years working in UX at the Dutch Ministry of the Interior, Khalid’s keen product design knowledge combined with a passion for social impact led him to put all his time and efforts into co-founding the award-winning digital ID company Tykn. Khalid believes Self-Sovereign Identity will positively impact billions of people’s lives and has advocated for its adoption on the most important stages, from the Economic Forum in Africa to the United Nations in NYC. He considers one of his biggest achievements to have co-founded a happy family.

Find Khalid on LinkedIn and on Twitter @Khalidworks.

Jimmy J.P. Snoek

Jimmy J.P. is a musician, business developer and entrepreneur, currently residing in The Hague, The Netherlands. After having worked as a professional musician in Spain and having started his first company in The Netherlands before the age of 20, Jimmy was accepted into the prestigious McGill University in Montréal, Canada and co-founded the now award-winning digital ID company Tykn. As an evangelist of data privacy and an early adopter of crypto, Jimmy has spoken about the merits of blockchain and self-sovereign identity at conferences and institutions worldwide since 2017, and has been featured in multiple publications, including The Guardian.

Find Jimmy J.P. on LinkedIn and Twitter @idforgood.

Tykn leverages blockchain technology to bring trust, privacy, and interoperability to identity. Tykn’s Ana platform allows organisations to issue tamper-proof digital credentials which are verifiable anywhere, at any time. Users can prove their ID to access services while remaining in full control of what personal data is viewed, shared & stored.

Find out more at tykn.tech.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining this new episode of Let’s Talk About Digital Identity. “A future of opportunity through digital identity” - so that’s what I read in the page of the guests we will have today, which is a young but very promising company called Tykn. They are working on a very interesting project and very interesting stories you are going to hear today from two guests. We have two guests today. So let me introduce to you my guests today.

First of all, Khalid Maliki. After many years working on user experience at the Dutch Ministry of the Interior, Khalid’s keen product design knowledge combined with a passion for social impact led him to put all his time and efforts into co-founding the award-winning digital ID company, Tykn. Khalid believes self-sovereign identity will positively impact billions of people’s lives and has advocated for its adoption on the most important stages, from the Economic Forum in Africa to the United Nations in New York.

And my second guest is Jimmy Snoek. Jimmy is a musician, business developer and entrepreneur, currently residing in The Hague, in The Netherlands. After having worked as a professional musician in Spain and having started his first company in The Netherlands before the age of 20,

View Details

Let's Talk About Digital Identity with Ilkka Hyvönen, Head of Cyber Security at Sogeti Finland. In episode 34, Oscar talks to Ilkka about the challenges that financial services face with digital identity, how CIAM helps with those challenges, the Zero Trust model and its applications for remote working, security in digital payments today, and his predictions for the near future of FS.

[Scroll down for transcript] "Customer Identity and Access Management can enable financial services to do business in this digital world, especially now that people are not able to go to their branch." Ilkka Hyvönen works as the Head of Cyber Security at Sogeti Finland and has ten years of experience in security consulting. In his free time, he likes to do sports such as running, biking and swimming. Find Ilkka on LinkedIn.

Sogeti is a part of the Capgemini group and offers advisory, implementation and managed services in 15 countries. In addition to digital identity, Sogeti’s cybersecurity services cover cyber security strategy, application security and detection & response. Find out more at www.sogeti.fi.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. Today, it’s time to talk about financial services and what are the implications for digital identity. For that, let me introduce you to my guest today. Ilkka Hyvönen works as the Head of Cyber Security at Sogeti Finland and has 10 years of experience in security consulting. In his free time, he likes to do sports such as running, biking and swimming.

For the ones who are not familiar with Sogeti, Sogeti is part of Capgemini group and offers advisory, implementation and managed services in 15 countries. In addition to digital identity, Sogeti’s cyber security services cover cyber security strategy, application security and detection and response services.

Hello, Ilkka.

Ilkka Hyvönen: Hello.

Oscar: Very welcome to have you here, Ilkka.

Ilkka: My pleasure.

Oscar: Nice. I hope you’re having a good day and you told me, we are both in Finland and we have a sunny day. You’re in Helsinki, correct? Somewhere…

Ilkka: Yes, correct.

Oscar: Yes, so we can see the same almost sunny, autumn morning.

Ilkka: Yes, it is very nice weather for Finnish autumn.

Oscar: Exactly. Excellent. It’s really great having you here. So, Ilkka, let’s talk about digital identity and the first thing I would like to hear is what was your journey to this world of digital identity.

Ilkka: Yes. So, I have a background actually in telecommunications so not a security background originally. And after I graduated, I went to work for a big technology consulting company. And I got assigned to a digital identity project as one of my first projects. And I guess I sort of got hooked into the world of security and digital identity. I like security and digital identity because you get to work with a lot of different things, like you have to understand the technology such as protocols and applications that you are securing, you have to understand the business drivers and the sort of assets that you are protecting, because it’s really important to understand those as well.

And then especially in digital identity, you have to understand the human aspects such as usability and how the users are behaving. Because if you, for example, had to enforce too strict rules the users can find some clever workarounds for things such as using the same passwords everywhere. So, I have been working in security for about 10 years now and I work a lot with digital identity especially in the financial services industry. So that’s my journey so far in digital identity.

Oscar: Yeah, excellent. So, you started in telecommunication, but you got somehow enchanted,

View Details

Let's Talk About Digital Identity with Petteri Ihalainen, Senior Specialist at the National Cyber Security Centre, Finland (part of Traficom - Finnish Transport and Communications Agency). In episode 33, Oscar's on home turf talking to Petteri Ihalainen about the identity landscape in Finland and all about the Finnish Trust Network (FTN) – what it is, why it came about and what the benefits are for Finland's population. They also discuss Katso, Finland's business-to-government national delegation solution (read more about Katso here), and eIDAS, a regulation that Petteri is deeply involved in.

[Scroll down for transcript] "You get basically the whole population of Finnish people through a single contract." Petteri Ihalainen has an extensive information security background, having worked for organisations like SSH, Ubisecure, the EU Commission, Gemalto and GlobalSign. During his career he has participated in advanced initiatives and digital identity programmes in various roles. He's currently working as a senior specialist at the National Cyber Security Centre of Finland (part of Traficom – the Finnish Transport and Communications Agency) in a team that supervises and advises organisations deploying digital identity solutions. Petteri also acts as one of the country's representatives at the EU-level in eIDAS related tasks and programmes.

Find Petteri on LinkedIn and on Twitter @Ihalain.

Read more about 'What is the Finnish Trust Network' in our blog.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. In Finland, people are used to accessing many services completely online and authenticate using verified identity, I would say almost on a daily basis. So this has been the norm for already many, many years. But recently, there have been some changes and as a result, we have something called the Finnish Trust Network. So, if you haven’t heard about that, you are going to hear from an expert in this matter who – let me introduce you today, is with me, Petteri Ihalainen.

He has an extensive information security background having worked for organisations like SSH, Ubisecure, the European Commission, Gemalto and GlobalSign. During his career, he has participated in advanced initiatives and digital identity programmes in various roles. He’s currently working as a Senior Specialist at the National Cyber Security Centre in Finland which is part of the Finnish Transport and Communication Agency, Traficom, in a team that supervises and advises organisations deploying digital identity solutions. Petteri also acts as one of the country representatives at the European Union-level in eIDAS related tasks and programmes.

Hello, Petteri.

Petteri Ihalainen: Hello, Oscar. How are you doing?

Oscar: Very good. It’s great talking with you after some time. So, as I said in your bio, you’ve been part of Ubisecure some time ago and it’s great to talk with you again and see what you are doing now in Traficom.

Petteri: Yeah, thanks for inviting me over.

Oscar: Fantastic. So, we’d like to hear a bit more from your own words what was your journey to this world of digital identity?

Petteri: Digital identity is kind of a long story. So, I have been interested in information security in general for ages, even in my first job at the healthcare sector had an aspect of information security. But it really got start information security career at SSH Communications Security in 2000. And I was then hired as a product manager for the PKI product family that was still being developed at SSH. And it was supposed to be the year of the PKI, but it didn’t happen and then we kind of like went, “OK, 2001 has to be the year of PKI and so on and so forth” which never happened.

View Details

Let's Talk About Digital Identity with Andrew Weaver, Executive Director of Digital Identity New Zealand (DINZ). In episode 32, Andrew fills us in on the main trends and challenges for digital identity in New Zealand, its national Digital Identity Trust Framework and the importance of interoperability between identity systems. He also gives us an excellent tip for individuals and organisations on reframing identity, inspired by Maori identity validations - trusting and respecting identities as a precious gift.

[Scroll down for transcript] "The strange thing with digital identity is most of the technology that's needed is already there – we're not really inventing anything new. The key to digital identity working is actually in collaboration." Andrew Weaver is the Executive Director of Digital Identity New Zealand, an organisation whose mission is to create a digital identity ecosystem that enhances privacy, trust and improves access for all people in New Zealand.

Andrew is a strategic specialist with over 30 years hands-on management, consultancy and systems development experience built throughout New Zealand, Australia, Asia and the Middle East.  He is also an active and passionate supporter of social enterprises and charities working in New Zealand and overseas.

Connect with Andrew on LinkedIn.

Digital Identity NZ is a purpose driven, inclusive, membership funded organisation, whose members have a shared passion for the opportunities that digital identity can offer. Digital Identity NZ supports a sustainable, inclusive and trustworthy digital future for all New Zealanders.

Find out more about Digital Identity NZ at digitalidentity.nz.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hi and thanks for joining today. We always are very interested in learning what are the digital identity initiatives around the world. And today, we have a location that is geographically a bit far from where we are in Finland, it’s 10 hours ahead. And today we’re going to talk about New Zealand. And for that, we have a very special guest who is Andrew Weaver. He is the Executive Director of Digital Identity New Zealand, an organisation whose mission is to create a digital identity ecosystem that enhances privacy, trust and improves access for all people in New Zealand.

Andrew is a strategic specialist with over 30 years hands-on management, consultancy and systems development experience built throughout New Zealand, Australia, Asia and the Middle East. He is also an active and passionate supporter of social enterprises and charities working in New Zealand and overseas.

Hello, Andrew.

Andrew Weaver: Kia Ora. [Introduces himself in Māori]

That is just a very brief introduction of me. I’ve just told you my identity. That’s the Māori language, the indigenous people of New Zealand and that’s a traditional greeting. They’ve had that for hundreds if not thousands of years to describe the place that they call home. So, I talked about my mountain, I talked about my river, I talked about the geographic location, then I talked about my family and finally, talked about myself. So, it’s always a good way to start a conversation around identity.

Oscar: Fantastic. Kia Ora, Andrew. Definitely it’s very fascinating talking with you. You started in a very special way. And we want to hear more about you, please tell us a bit more about you how you came to this world of digital identity.

Andrew: OK. My personal background - and I have been working in payments, cards, banking, fraud prevention for too many years to count. And on a couple of occasions I’ve been asked to facilitate some discussions at a conference, banking conference primarily. And then last time I did that, the topic was digital identity.

View Details

Let's Talk About Digital Identity with Miikka Sainio, CTO, and Rami Raulas, Vice President EMEA, at SSH.com. In episode 31, Oscar talks to Miikka and Rami about expanding identity beyond IAM and CIAM to Privileged Access Management. Listen for: what exactly Privileged Access Management (PAM) is; PAM benefits and use cases; the complexity and challenges with cloud, hybrid, and multi-cloud environments; ephemeral certificates; the principle and application of zero trust; and SSH's PAM product – PrivX.

[Scroll down for transcript] "Ideally you want to have a single pane of glass through which you control access to your whole estate." Miikka Sainio

Miikka Sainio is CTO at SSH.com. He has been successfully building services and products for over 20 years as a coder, architect and product owner. Find Miikka on LinkedIn.

Rami Raulas

Rami Raulas is Vice President EMEA at SSH.com. He has a wealth of experience in IT, working at Fujitsu prior to joining SSH. His specialist area is in building successful customer experiences. Find Rami on LinkedIn.

SSH.COM (SSH Communications Security Oy) is an encryption specialist for safe data communications and a pioneer in data and internet security since its incarnation, when founder Tatu Ylönen invented the SSH Secure Shell Protocol in 1995. It is a global company with headquarters in Helsinki, Finland.

Find out more about SSH at www.ssh.com. SSH.com is a Ubisecure partner; view more information in this press release.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. Now, the organisations and the projects in the organisations are getting more and more complex, there is more complexity in these environments and there is a topic that is completely linked to that: it's Privileged Access Management. So, we are going to hear from experts in this matter from the company called SSH.com. We have today two guests. They are Miikka Sainio. He’s CTO at SSH.com. He’s been building beautiful services and products for over 20 years as a coder, architect and product owner.

And our second guest is Rami Raulas. He is Vice President EMEA at SSH.com. He has long experience in IT from Fujitsu before SSH. His special area is in successful customer experiences. Hello Miikka. Hello Rami.

Miikka Sainio: Hello, nice to be here.

Rami Raulas: Hi, Oscar. Pleased to join.

Oscar: Yeah, very welcome and it’s nice talking with you and great to talk after some time from some company in Finland here where we are, so it’s great to hear. Let’s see what SSH, a Finnish company, is having for solving these very complicated problems for some organisations. We’ll hear more. But I would like to hear now a bit more about yourselves. So please could you tell me, each of you, what was your journey to this world of digital identity?

Miikka: For me, it goes way back. So, I’ve been in IT for over 20 years now and even before that in the ‘90s, I used to run dial-in bulletin board systems which of course already had user accounts and user identities, which you logged in to the systems. And from those I graduated to different textual multi-user online games, again with accounts and so forth. And from that to our first start-up and building social web experiences. So, building and having a digital identity has always been a part of who I am as long as I can remember.

Rami: Yeah, and for me, I’ve been working with the identity and authentication actually with different technologies like biometrics and user certificates or tokens. I’ve actually been putting, in the early ‘90s so a long time ago, smartcard readers and biometric readers into laptops. But now, the focus of course from our side is less so on the identification and authentication of the user.

View Details

Let's Talk About Digital Identity with Katryna Dow, founder and CEO of Meeco. Katryna talks to Oscar about her career (including inspiration from Minority Report), Meeco's personal data & distributed ledger platform, the importance of data minimisation to inspire trust in organisations, and cultural differences in attitudes towards digital identity.

[Scroll down for transcript] "The greatest way to overcome this privacy paradox is transparency."

"Where regulators have moved to increase the data transparency and data rights of individuals, these need to actually be part of the solution architecture." Katryna Dow is the founder and CEO of Meeco; a personal data & distributed ledger platform that enables people to securely exchange data via the API-of-Me with the people and organisations they trust. Katryna has been pioneering personal data rights since 2002, when she envisioned a time when personal sovereignty, identity and contextual privacy would be as important as being connected. Now within the context of GDPR and Open Banking, distributed ledger, cloud, AI and IoT have converged to make Meeco both possible and necessary.

Find out more about Meeco at meeco.me.

For the past three years, Katryna has been named as one of the Top 100 Identity Influencers. She is the co-author of the blockchain identity paper ‘Immutable Me’ and co-author/co-architect of Meeco’s distributed ledger solution and technical White Paper on Zero Knowledge Proofs for Access, Control, Delegation and Consent of Identity and Personal Data. Katryna speaks globally on digital rights, privacy and data innovation.

Follow Katryna on her blog at katrynadow.me, on LinkedIn and on Twitter @katrynadow.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hi and thanks for joining today. Today, we’re going to have a very interesting conversation about how many technologies and business ideas converge into products that help people directly to protect their data and their identity. For that we have a very special guest. Our guest today is Katryna Dow.

She is the founder and CEO of Meeco, a personal data and distributed ledger platform that enables people to securely exchange data via the API-of-Me with the people and organisations they trust. Katryna has been pioneering personal data rights since 2002, when she envisioned a time when personal sovereignty, identity and contextual privacy would be as important as being connected. Now within the context of GDPR and Open Banking, Distributed Ledger, Cloud, Artificial Intelligence and the Internet of Things have converged to make Meeco both possible and necessary. For the past three years, Katryna has been named as one of the Top 100 Identity Influencers.

Hello, Katryna.

Katryna Dow: Hello, Oscar. That introduction makes me feel I’m going backwards and forwards in time at the same time.

Oscar: Very nice talking with you now Katryna. It’s super interesting having this conversation with you. I know there are so many things we can talk about. And so, I would like to hear from you what was your journey to this world of digital identity?

Katryna: So, I don’t know where to start because I’m not sure it’s something that I ever consciously woke up one day and went, “Oh, you know, I really want to work in the identity space.” And I think that maybe true for a lot of people that maybe you’ve even interviewed previously. It actually unfolds out of something that is either driven by something you’re trying to do in society or related to commerce or related to access to services.

And then all of a sudden you have this question of who or what are you? Are you supposed to be here? Are you allowed to have access to this place or this thing? And now you have access,

View Details

Let's Talk About Digital Identity with Lisa Forte, Partner at Red Goat Cyber Security and Host of the Rebooting YouTube Channel. In episode 29, Oscar talks to Lisa about her fascinating journey to cybersecurity, the lucrative schemes that hackers and scammers have been employing since the start of the pandemic, the group of volunteers (CV19) she co-founded to help protect hospitals against cyber-attacks with the onset of COVID19 in Europe, and top tips for individuals and organisations on cybersecurity and identity.

They also discuss a new Tomorrow Unlocked documentary that Lisa appears in - Ha(CK)c1ne: Healthcare on the Edge. It explores the shocking cyber-attacks that have hit vulnerable hospitals, healthcare supply chains and vaccine labs since the COVID-19 pandemic. Released on 25th September, watch Ha(CK)c1ne on YouTube now.

[Scroll down for transcript] "The pandemic is a crisis, but security has to continue. Even though we're fighting a biological virus at the moment, security still has massive ramifications If you ignore it." Lisa Forte is a social engineering and insider threat expert. She is a partner at Red Goat Cyber Security and Host of the Rebooting YouTube Channel. Lisa is a regular on TV shows, documentary films and news broadcasts. Her career started in a very unlikely place, working to stop pirates off the coast of Somalia! She worked in one of the UK Police Cyber Crime Units before starting Red Goat Cyber Security. Lisa is also one of the very proud co-founders of the Cyber Volunteers 19 (CV19) initiative providing free help and intelligence to healthcare providers in Europe during the pandemic, an organisation that has been recognised and praised by Governments around Europe.

Find Lisa on Twitter @LisaForteUK and LinkedIn.

Find out more about Red Goat Cyber Security at red-goat.com.

Watch Ha(CK)c1ne here, embedded from YouTube:



We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host Oscar Santolalla.

Oscar Santolalla: Hi and thank you for joining today. Already in the second week of March, I started hearing on social media news about ransomware gangs that were targeting hospitals in the very beginning of the pandemic and that was really horrible to hear and hard to believe. Today, we’re going to discuss what has happened since then until now because our guest will tell us how we can also protect ourselves, both as individuals and as organisations.

Our special guest today is Lisa Forte. She is a social engineering and insider threat expert. She is a partner at Red Goat Cyber Security and Host of the Rebooting YouTube Channel. Lisa is a regular on TV shows, documentary films and news broadcasts. Her career started in a very unlikely place, working to stop pirates off the coast of Somalia! She worked in one of the UK Police Cyber Crime Units before starting Red Goat Cyber Security. Lisa is also one of the very proud co-founders of the Cyber Volunteers 19 (CV 19) initiative providing free help and intelligence to healthcare providers in Europe during the pandemic, an organisation that has been recognised and praised by governments around Europe.

Hello Lisa.

Lisa Forte: Hello, it’s wonderful to be here.

Oscar: It’s a pleasure having you Lisa and super interesting what we’re going to discuss. But first, I would like to hear how you started, what was your journey to this world of cyber security.

Lisa: So, it was a bit weird because I actually studied Law at university, and I thought I was going to become a lawyer for many years. And then I got a job working for a private armed security company that put armed guards onboard commercial ships to protect them from pirates. I started working there and I started getting more interested in security and more specifically how pirates were targeting ships because...

View Details

Let's talk about digital identity with Jurgita Sarkovaite, Innovation and Strategy Manager at NEO Consulting. In episode 28, Jurgita and Oscar discuss digital transformation, particularly in light of COVID19, and the critical role of identity in any digital transformation project. The conversation also explores the importance of digital identity in customer experience and how companies are approaching digital identity in light of that, including who has ultimate influence over digital identity projects within the organisation and the popularity of Identity-as-a-Service (IDaaS, SaaS-delivered IAM).

[Scroll down for transcript] "Digital identity is part of every digital transformation project because it would be impossible to do without it" Jurgita Sarkovaite is Innovation and Strategy Manager at NEO Consulting. She’s also Professor of Digital Marketing and Digital Transformation courses at Pacífico Business School, Peru. Jurgita has 8+ years of project management experience in digital strategy consulting, technology and software development. Her research covers digital culture, entrepreneurship and innovation. She has a passion for education.

You can contact Jurgita on LinkedIn or email jurgita.sarkovaite@neoconsulting.ai.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining today. Digital transformation is a term that we have been hearing and reading about in the last recent years, but I will say has never been as important as today. That’s why in this interview, we’ll dig into that. And also, we’d like to hear about the role of identity in digital transformation. And for that let me introduce you to today’s guest.

Jurgita Sarkovaite is Innovation and Strategy Manager at NEO Consulting. She’s Professor of Digital Marketing and Digital Transformation courses at Pacifico Business School in Peru. Sarkovaite has more than eight years of project management experience in digital strategy consulting, technology and software development. Her research covers digital culture, entrepreneurship and innovation. And she has a passion for education. Hi, Jurgita.

Jurgita Sarkovaite: Hi, Oscar. Nice to be here and delighted to share this time with you.

Oscar: Yeah, it’s very nice. Thanks for joining. It’s very nice talking with you and I’m really intrigued about hearing more about digital transformation that as I say is becoming more and more important in these circumstances that we are living. But I would like to hear a bit more about yourself, so please tell us what is your journey to be in this world of digital transformation and digital identity, et cetera?

Jurgita: Definitely, yes. So, I think as most professionals who are working in digital these days you know, my journey began a bit random. So, I kind of stumbled upon the digital at the beginning of my career, so I was freshly graduating from the university for my bachelor’s degree and I was looking for internships, for international internships. And so I started exploring around the globe and luckily I found this company, NEO Consulting, located in Lima, Peru, which was working in digital marketing at the time.

So yeah, knowing absolutely nothing about digital marketing, I joined the company and it started straight ahead. So, I was working there developing the digital marketing strategies for companies in different industries. And after that I found myself very interested in the field, so I continued my journey, went on to working for a time for a specialised software development company in Lithuania which was working for clients in Europe or in Switzerland and in the United Kingdom. And I think just somehow you know rolled over from there.

So, digital kind of became part of what I am,

View Details

Let's talk about digital identity with Josselyne Abarca, Gerente General y socia fundadora de Seguridad América. A note for our English-speaking listeners: this week's episode is in Spanish, talking about the challenges of digital identity in Latin America with Josselyne Abarca, CEO and founding partner of Seguridad América. You can read the transcript in English - scroll down to below the subscription links. [En español] “Las empresas y organizaciones están migrando todos sus servicios al ámbito digital y uno de los desafíos con los que se encuentran es certificar o ratificar la identidad de las personas que ingresan en sus sistemas y servicios.” Josselyne Abarca es Gerente General y socia fundadora de Seguridad América. Josselyne se encuentra ligada a la seguridad y autenticación digital desde los tiempos de VeriSign, donde comienza su carrera comercial.

Para Josselyne, uno de los mayores retos en América Latina es la necesidad de proveer a los usuarios con una identidad global, robusta, flexible y verificada tanto en el ámbito público como privado para que puedan acceder con total seguridad y confianza a aquellos sistemas más susceptibles de sufrir ataques cibernéticos.

Seguridad América es una organización con sede en América Latina con una cartera de soluciones destinadas a ayudar a las organizaciones con requisitos crecientes para la gestión de la seguridad cibernética y permitir a las empresas expandirse de manera eficiente y segura. Su compromiso es facilitar el acceso de la empresa privada y los organismos públicos a soluciones digitales robustas y seguras, así como entregar a sus clientes soluciones flexibles que permitan el fácil ingreso a los portales y manejo de las identidades para que el entorno sea productivo.

Seguridad América es partner de Ubisecure y RapidLEI. Puedes leer más sobre asociación aquí. [In English] Challenges of digital identity in Latin America with Josselyne Abarca, Seguridad América – Podcast Episode 27 [Scroll down for English transcript] “Companies and organisations are migrating all their services to digital solutions and one of the challenges they face is to certify or verify the identity of the people who access their systems and services.” Josselyne Abarca is General Manager and founding partner of Seguridad América. Josselyne has been involved in digital authentication and security since the days of VeriSign, where she began her business career.

For Josselyne, one of the greatest challenges in Latin America is the need to provide users with a global, robust, flexible and verified identity, both in the public and private sector, so that they can access the most susceptible systems with total security and confidence.

Seguridad América is a Latin American-based organisation with a portfolio of solutions aimed at helping organisations with increasing requirements for cybersecurity management and enabling businesses to expand efficiently and securely. Its commitment is to facilitate the access of private companies and public organisations to robust and secure digital solutions, as well as to provide its clients with flexible solutions that allow easy access to portals and management of identities.

Find Josselyne on LinkedIn.

Find out more about Seguridad America at www.seguridadamerica.com.

Seguridad America is a Ubisecure and RapidLEI partner. Read more about the partnership here.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

­

Podcast transcript (translated to English) OSCAR: Hello and welcome to the show, this time and for the first time we are going to speak in Spanish and what we are going to touch on today are the challenges of digital identity in Latin America, and for this I have a special guest who is Josselyne Abarca. Josselyne is CEO and Founding Partner of Seguridad América. Josselyne has been involved in digital authentication and security since VeriSign where she began her ...

View Details

Let's talk about digital identity with Schehrezade Davidson, CEO of Tricerion. In episode 26, Oscar talks to Schehrezade about Tricerion's neurographic authentication solution – picture-based passwords. They discuss how neurographic authentication solves the risks of alphanumeric passwords and spoof phishing, the benefits for users who find it hard to remember and input alphanumeric passwords, and its use cases.

[Scroll down for transcript] "None of us like passwords, we want something simple. But individuals understand they need something secure." Schehrezade Davidson is the CEO of Tricerion, whose innovative SafeLogin product provides strong mutual authentication with picture-based passwords.

Find out more about Tricerion and watch videos of how it works at tricerion.com.

Schehrezade has 30 years' experience in financial services and equity fund management, where her expertise covered investing in large and small cap companies. She has over 10 years' experience in early stage technology investing, especially in companies on the cusp of commercialisation. Schehrezade was an early stage investor in Tricerion.

Find Schehrezade on LinkedIn.

Schehrezade also joins LTADI for a second podcast episode, discussing immunity passports. Listen to that conversation in episode 41.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Thanks for joining again to a new episode of Let’s Talk About Digital Identity. And happy to discuss a very interesting, very innovative way of protecting our digital identity. And if you haven’t heard before, we’ll talk about neurographic passwords. And for that we have a special guest so let me introduce to you, Scheherazade Davidson. She is the CEO of Tricerion Limited, a company that owns novel patented mutual authentication software. Before Tricerion, she worked in finance and fund management where she had a special interest in investing in innovative technology businesses. This experience has given her the understanding of what is needed to commercialise technology. Timing is all.

Hello, Scheherazade.

Scheherazade Davidson: Hello, Oscar. Great to meet you.

Oscar: Nice meeting you. It’s great talking with you. I’m really curious about hearing what Tricerion is doing so it sounds very, very interesting. But first, let’s hear something more about yourself, so please walk us through your journey to the world of digital identity.

Scheherazade: Yeah, sure, happy to give a little bit of background. So, originally, I was an investor in Tricerion. I came across it when the original founders came to present the idea to me. And it’s one of those things, in my investment career, I’ve seen a lot of amazing ideas and solutions in a whole range of industries. But when I heard the story of what the guys are trying to do, I just thought it was amazing. And when I left finance - that’s a long, long convoluted story - but in the end, I ended up joining the business and have become the CEO. Because I think our solution for authentication is simple, easy and visual. And it’s one of these stories where I have to admit I fell in love with the solution, and I really want to spread the idea far and wide.

Oscar: Oh, fantastic. Yes, we have been talking, not in all the episodes but I was thinking nearly all of the episodes in these conversations, we’ve been talking about one way or another about passwords. And people have differing opinions. But from your perspective of being in this company, Tricerion, having already been for several years and you have a very different perspective/way of solving this problem, what would you say is the main problem with traditional passwords?

Scheherazade: Well, I think one of the main issues is that everywhere that you log in with an alphanume...

View Details

Let's talk about digital identity with Debbie Reynolds, Founder, CEO, and Chief Data Privacy Officer at Debbie Reynolds Consulting LLC. And we're back with series 2! Kicking us off is Debbie Reynolds, looking at privacy in contact tracing apps around the world. Debbie walks us through the potential issues with contact tracing apps with regard to regional laws, security risks which must be mitigated against and the practical effectiveness of the apps themselves. Debbie and Oscar also dive into the world of facial recognition – including the importance of accuracy and transparency around public practices and relevant regulations (GDPR, CCPA, BIPA etc.).

[Scroll down for transcript] "For me, contact tracing is a profession, not an app" Debbie Reynolds, “The Data Diva,” is a world-renowned technologist, thought-leader, and advisor to Multinational Corporations for handling global data privacy, cyber data breach response, and complex cross-functional data-driven projects. Ms. Reynolds is an internationally published author, highly sought speaker, and top media presence about global data privacy, data protection, and technology issues. Ms. Reynolds has also been recognised as a Technology Visionary and as a top leader in the Data Privacy industry worldwide.

Find out more about Debbie at www.debbiereynoldsconsulting.com and connect with her on LinkedIn.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. 'Facial recognition', 'contact tracing apps' are terms that we have been hearing and reading very often in the last months. And we are going to discuss what are the implications in privacy and in the digital identity, and of course also opportunities related to that. And for that, we have a very special guest, an expert in that matter.

Let me introduce to you, Debbie Reynolds. She is “The Data Diva,” is a world-renowned technologist, thought-leader, an advisor to multinational corporations for handling global data privacy, cyber data breach response, and complex cross-functional in data-driven projects. Ms. Reynolds is an internationally published author, highly sought speaker, and top media presence about global data privacy, data protection and technology issues. Ms. Reynolds has also been recognised as a technology visionary and as a top leader in the data privacy industry worldwide.

Hello, Debbie.

Debbie Reynolds: Hello, Oscar. Thank you. That’s such a wonderful introduction. Thank you so much.

Oscar: It’s a pleasure talking with you. I really want to hear your opinion on some of these topics that I mentioned. But first of all, I want to hear a little bit more about you. So let us know how your journey to this world of privacy and digital identity was.

Debbie: Sure. So, I have been a 'data junkie' or a 'data geek' for many, many years. My first start in technology was working with library systems at times when they were trying to move from card catalogues to digital systems and databases. So, I started my technology career as a database administrator and I fell in love with data. And this was around the time a little bit before kind of internet became so commercially available to people.

So, at that time, I became very interested in privacy. This is like in the ‘90s actually, I read a book called The Right to Privacy that came out in 1997. And I was fascinated by the concept. So, I sort of had this parallel journey where I was working more in the data space in terms of helping– I ended working with multinational corporations, helping them do data movements for legal cases. So, moving data around the world and understanding how to do so legally, so I’ve been doing that for over 25 years. But as I kept keeping tabs on privacy,

View Details

Let's talk about digital identity with Clare Rowley, Head of Business Operations at the Global Legal Entity Identifier Foundation (GLEIF). In episode 24, Clare and Oscar delve into the world of the Legal Entity Identifier (LEI) – what exactly is an LEI; the GLEIF's role in ensuring the operation of the Global LEI System and promoting LEI engagement; and the specific, quantifiable benefits that the LEI can bring to the banking sector.

[Scroll down for transcript] "Consumer protection, greater transparency in the supply chain, and the detection and prevention of fraud can be achieved only through full transparency of counterparties." Clare Rowley is the Head of Business Operations at the Global Legal Entity Identifier Foundation (GLEIF). Prior to working with GLEIF, Ms. Rowley worked at the United States Federal Deposit Insurance Corporation where she led technology initiatives improving bank resolution programs and contributed to research on subprime mortgages.

Find Clare on LinkedIn.

Established by the Financial Stability Board in June 2014, the Global Legal Entity Identifier Foundation (GLEIF) is a not-for-profit organisation created to support the implementation and use of the Legal Entity Identifier (LEI). GLEIF is headquartered in Basel, Switzerland. GLEIF services ensure the operational integrity of the Global LEI System. GLEIF also makes available the technical infrastructure to provide, via an open data license, access to the full global LEI repository free of charge to users. GLEIF is overseen by the LEI Regulatory Oversight Committee, which is made up of representatives of public authorities from across the globe. GLEIF has obtained the ISO/IEC 20000-1:2011 certification in October 2019 for its Partnership Program Services to the LEI issuing organisations (LOUs).

For more information, visit the GLEIF website at https://www.gleif.org/en

Ubisecure is a Local Operating Unit (LOU) for the GLEIF through its RapidLEI service and is the number one issuer of LEIs worldwide. Find out about becoming a RapidLEI partner at rapidlei.com/partners.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining today. We usually talk about digital identity of individual people from many perspectives, but today we are going to talk about the identity of organisations.

The first question would be, do we have any universal way of identifying organisations in a way that can be electronically verified? The answer is yes, we have that and it’s called the Legal Entity Identifier or LEI. Today we are going to talk about that, and for that we have a representative from the organisation that works on the promotion of the LEI which is the GLEIF.

So let me introduce to you my guest today: Clare Rowley. Clare is Head of Business Operations at the Global Legal Entity Identifier Foundation or GLEIF. Prior to working with GLEIF, Ms. Rowley worked at the United States Federal Deposit Insurance Corporation where she led technology initiatives improving bank resolution programmes and contributed to research on subprime mortgages.

Hello Clare.

Clare Rowley: Hello Oscar, it’s lovely to be with you today.

Oscar: My pleasure Clare, it’s very nice talking with you and hearing what more about what GLEIF is doing. So, Clare let’s talk more about digital identity. The first thing I would like to ask you is: What is GLEIF?

Clare: Certainly. I will mention again, as Oscar said in the intro, I will use two acronyms throughout this discussion. The first is GLEIF, for Global Legal Entity Identifier Foundation and then LEI for the identifier itself, for Legal Entity Identifier. So, we at GLEIF, we are a non-profit Swiss foundation inaugurated in June 2014 and founded by the Financial Stabil...

View Details

Let's talk about digital identity with Susana Lopes, Director of Product at Onfido. In episode 23, Oscar talks to Susana about what biometrics enable that other identifiers can’t; the importance of anti-spoofing (liveness); privacy concerns around biometrics and regulatory impact; algorithmic bias in biometrics (including race, age, gender and other demographic differentials) and Onfido's work with the ICO in this regard.

[Scroll down for transcript] "Biometrics protect users against themselves in situations where they might not realise they're under attack" Susana has a varied background in product management in the B2B space. She has a breadth of platform experience, from web front and backend, iOS, Android and Machine learning infrastructure. Her current role is director of product at Onfido, specifically focusing on their biometric product offering.

Connect with Susana on Twitter @susanavlopes and on LinkedIn.

Onfido is building the new identity standard for the internet. Its AI-based technology assesses whether a user’s government-issued ID is genuine or fraudulent, and then compares it against their facial biometrics. Its mission is to create a more open world, where identity is the key to access.

For more information, visit: onfido.com or follow Onfido on social media: Facebook, Twitter @Onfido and LinkedIn. As referenced in the episode, you can also find Onfido's tech blog on Medium here: https://medium.com/onfido-tech.

Onfido is a Ubisecure partner. Find out more about the partnership here - https://www.ubisecure.com/partner-directory/onfido/.

Susana also refers to a NIST study on demographic differentials of biometric facial recognition accuracy, which can be found here: https://nvlpubs.nist.gov/nistpubs/ir/2019/NIST.IR.8280.pdf. Mei Ngan, Scientist at the National Institute of Standards and Technology (NIST), discusses evaluating face recognition biometrics in episode 42 of the podcast: https://www.ubisecure.com/podcast/face-recognition-biometrics-nist-mei-ngan/.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Hello and thanks for joining today. I will ask you: have you already used biometrics for authentication? Do you like it? Do you use it often? Well, today we are going to have a guest who will discuss with us the world of biometrics and what other things are happening today. So let me introduce to you our guest today: Susana Lopes.

Susana has a varied background in product management in the B2B space. She has a breadth of platform experience, from web front and backend, iOS, Android and Machine Learning infrastructure. Her current role is Director of Product at Onfido, specifically focusing on their biometric product offering. Hi Susana.

Susana Lopes: Hi Oscar. How are you?

Oscar: Oh, very good. I’m really happy to talk with you and learn more about biometrics and what you are doing in Onfido. So first of all, I would like to hear more about your journey to the world of digital identity.

Susana: Sure. So about three years ago, I joined Onfido and we are an identity verification business. So we want to help people prove who they claim to be, prove that they are who they claim to be when they’re trying to rent a car or when they’re trying to open a bank account so that they can do that without having to go to a store or to a bank front, particularly useful in pandemics.

So when I joined Onfido, I originally was looking after our identity databases product. So making sure that your name, your date of birth, your address are known in say credit rating agencies or in government databases. So that was my first introduction to the world of identity and then later on I actually was one of the founding members of the biometrics team and we started looking at - wh...

View Details

Let's talk about digital identity with Simon Wood, CEO of Ubisecure. In episode 22, we're featuring a bonus lockdown episode in which Oscar talks to Simon about how the current pandemic has changed, and is still changing, the digital identity landscape.

[Scroll down for transcript] "Now is the time for the digital identity industry to practice what we preach - security, efficiency, user experience, regulatory compliance." The conversation covers the key issues surrounding remote working and digital-first strategies, exploring both the commercial and governmental sides of the situation we all find ourselves in. Simon touches on the privacy aspects of contact tracing, the now 'blurred lines' of internal and external users from an identity and access management perspective, and the key role of SaaS to enable fast routes to digitalisation.

As Group CEO at Ubisecure, Simon Wood is responsible for planning, communicating and delivering Ubisecure’s overall vision and corporate strategy to enable the true potential of digital business through modern identity management solutions. 

Connect with Simon on LinkedIn.

As mentioned in the episode, Simon joined a previous episode of Let's Talk About Digital Identity. Catch up here: https://www.ubisecure.com/podcast/simon-wood/.

Ubisecure provides feature rich customer identity management software and services to help companies reduce identity data breach risk, improve operational efficiencies, and improve user experience.

Find out more at ubisecure.com.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

Podcast transcript Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Hello and thank you for joining today to a new episode of Let’s Talk About Digital Identity. And I am sure many of you, if not all of you, are remote workers right now, so we are going to talk about some of the implications of remote working and what other things have happened because of COVID-19 in this area of digital identity.

And for that, I’m going to introduce for the second time, our guest who has been on exactly 11 months ago, Ubisecure CEO, Simon Wood who was here talking about many aspects about what happened in digital identity in Ubisecure and giving some predictions. And let’s see what happened not only in these 11 past months, but especially in the very recent weeks.

So, let’s welcome Simon Wood. Hello, Simon.

Simon: Hi, Oscar and thank you for having me back again.

Oscar: Yeah, it’s great having you here now. We’re going to discuss a bit different topics because we are living in quite different times, given what happened last year. So let’s jump directly into this. So now that COVID-19 has affected every single industry, how do you see it has affected particularly the digital identity industry?

Simon: Yes. So I mean obviously right now, we are in quite an unprecedented time for all industries. We see a landscape where businesses are having to adapt quickly to this new unfolding situation, start planning for what the situation will become. And we don’t know that yet, but there's fairly wide acceptance that we will arrive at some new normal as we go forward. Certainly, how interactions have taken place, the default models I think will shift as we go forwards. Priorities will have to be slightly different as well.

Right now as employers, we’re looking after employees as the first priority. We've got to serve our customers and make sure that they can continue receiving services that they need. And then kind of the core business itself.

In the general sense, it’s interesting to see how businesses are behaving relative to their stated values, that a number of businesses published. And these are complex times and for all industries, we have to kind of practice what we preach and I think for the digital identity industry that...

View Details

Let's talk about digital identity with Bengt Berg, Head of Compliance Management Services at Cybercom. We all know the importance of regulatory compliance in any Identity and Access Management (IAM) scenario. What we don't always know is how to make colleagues engage with compliance, to ensure they sit up, listen and remember to always keep compliance front of mind.

In episode 21, Bengt Berg fills us in on the new alternatives to the dreaded compliance management handbook that sits on the office shelf collecting dust, taking inspiration from the finance industry. Oscar and Berg also cover other key topics such as how to convince the board that IT security is important with easily accessible metrics, specific cases of IT security compliance in IAM and Cybercom's approach to compliance management.

[Scroll down for transcript] "The most common system or platform to get hacked is the system you didn't even know you had." Bengt has been in the IT security industry since 1994, when building encryption systems for people in uniforms, have been a manager in an American big firm, has taken some time in the finance industry and today works as a do-all guy at Cybercom. Some sales, some consulting, some business strategy, and is also a member of the steering group of Cybercom Secure. He is also the proud father and protector of Cybercom’s products and services in the Compliance Management area.

Connect with Bengt on LinkedIn or at bengt.berg@cybercom.com.

Enjoyed this episode? Listen to episode 10 with Bengt's colleague, Cybercom’s Head of IAM Solutions, Robin von Post.

Find out more about Cybercom at www.cybercom.com.

Cybercom is a Ubisecure partner. Get the details here: ubisecure.com/news-events/cybercom-partnership.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. Imagine you have joined a new company and among the very first things, you are meeting the IT manager, giving you some training about security and then they hand you a 40-page guideline that you have to follow and that can be a nightmare for everybody - some stress how I’m going to make sure that I will follow that.

On the other side of the story, of course there are the compliance managers who really want that a company complies with these regulations or guidelines, security-based practices, and how they make sure that everybody is contributing to that, to the common goal. So for that, we will have a conversation about compliance management. For that we have an expert who is Bengt Berg who is a head of compliance management services at Cybercom.

Bengt has been in the IT security industry since 1994, when building encryption systems for people in uniforms. He has been also a manager in an American big firm, has taken some time in the finance industry and today works as a do-all guy at Cybercom. Some sales, some consulting, some business strategy, and he is also a member of the steering group at Cybercom Secure. He is also the proud father and protector of Cybercom’s products and services in the Compliance Management area. Hello Bengt.

Bengt Berg: Hello. Good to meet you, Oscar. How are you doing?

Oscar: Oh, very good. I’m really happy to talk with you and talk about this very interesting topic - compliance management. So let’s get started Bengt. Let’s talk about digital identity. And the very first things I would like to know is a bit more than I said everything in your bio. But tell us a bit more about your journey into this world of compliance and digital identity.

Bengt: I would like to start with thanking you for telling us, saying that compliance management sounds very interesting. In fact it sounds really, really boring. Most of the people who got these PDF documents with all the r...

View Details

Let's talk about digital identity with Marjukka Niinioja, co-author of API Economy 101 and Founding Partner at Osaango. Why are APIs not just a technical issue, but a business issue as well? In episode 20, Oscar chats to API guru Marjukka Niinioja about the opportunities APIs can create, how COVID-19 has highlighted the need for digitalisation, the role of identity in API security and the importance of standards like OpenID Connect.

[Scroll down for transcript] "You don't need to have an army of coders, you just need to buy the capabilities as APIs" Marjukka Niinioja is co-author of API Economy 101 book and founding partner and leading consultant at Osaango, a company specialising in API and Platform economy. Osaango has worked with several companies in Finland and abroad as well as public organisations to help them not only learn about the possibilities of API and Platform business models but also define their API and platform strategies and guide them in the implementations.

For links and more information visit www.osaango.com

Marjukka is also the "mother" of the lean, business-oriented and open APIOps Cycles method, creator of the open course about API Economy with Tampere University and the local organiser of APIdays Finland conferences.

Visit APIOps Cycles at www.apiopscycles.com and check out the API Economy open course at Tampere University at www.osaango.academy/courses/intro-to-api-economy.

For a roundup of APIdays Finland 2019, read Oscar's blog - www.ubisecure.com/api/apidays-finland-2019/

Find Marjukka on Twitter @MNiinioja and on LinkedIn.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Hello and thanks for joining today. We will have now for the first time talking about APIs and the API economy and what is the relationship with identity. For that, our guest is Marjukka Niinioja.

She is co-author of the API Economy 101 book and founding partner and leading consultant at Osaango, a company specialising in API and Platform economy. Osaango has worked with several companies in Finland and abroad as well as public organisations to help them not only learn about the possibilities of API and Platform business models but also define their API and platform strategies and guide them in the implementations.

Marjukka is also the “mother” of the lean business-oriented and open APIOps Cycles method, creator of the open course about API Economy with Tampere University and the local organiser of APIDays Finland conferences.

Hi Marjukka.

Marjukka Niinioja: Hi. Nice to be here.

Oscar: Welcome. It’s very nice talking with you. So Marjukka, let’s talk about digital identity. And the very first thing I want to hear from you is what was your journey to this world of APIs and digital identity?

Marjukka: It’s an interesting question because it started actually about 20 years ago. I will never be older than 25 but still 20 years ago. Finland joined the European Union, and we were basically pulled as students from the university to build the European Union Agricultural Benefit Systems in Finland.

And one of the key things there was, of course, identity and we started - very ambitiously because we were young and stupid, we didn’t know that it was very difficult to do. So we started building a web services-based architecture and one of the key things for that was how to handle identities and it was a really tough school because we had to handle the public sector people, like the people in municipalities who made the decisions about the benefits and also the farmers and everybody else who were somehow delivering or handling the agriculture goods and supplies and everything else, and the animals.

So we even had to find out ways to handle digital identity for animals.

View Details

Let's talk about digital identity with Sid Desai, Director at Remme. In episode 19, Oscar talks to Sid about what exactly a decentralised ID is, its benefits, use cases and open standards such as the Decentralized Identifiers (DIDs) specification from W3C. They also discuss how decentralised identity will develop in the coming years, and why Remme is building a decentralised model of Public Key Infrastructure (PKI).

[Scroll down for transcript] "Decentralised IDs give control of digital identity back to the user." Sid Desai is a Boston (USA) based IT security professional who’s passionate about user/machine identities, security & PKI. Sid has led the distributed identity front in his work at Remme, helping work with the platform, engineering and partner teams to massively extend the impact of decentralised identity & authentication solutions for the modern enterprise. He consults with Remme’s customers around the world on how to transform their identity & authentication ecosystems thus helping them increase their business integrity & efficiency while lowering costs. Recognised as a well-rounded advocate for identity, digital transformation and blockchain-enabled solutions, Sid is also a regular speaker, contributing author and media commentator. Find Sid on LinkedIn or email sid@remme.io.

Founded in 2015, Remme is building the distributed Public Key Infrastructure protocol and PKI-enabled apps to address the challenges of Web 3.0. Remme Auth is a 2-click authentication solution that allows users to securely access a website without passwords. Instead, the solution uses X.509 self-signed certificates and blockchain technology. Find out more at remme.io.

Remme is a Ubisecure partner, with the companies collaborating to create identity solutions using blockchain technology. Read the press release here - https://www.ubisecure.com/news-events/remme-ubisecure-blockchain-identity-management/

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. Today, we will hear our guest talking about Decentralised ID. So for that, I would like to welcome Sid Desai. Sid is a Boston-based IT security professional who’s passionate about user and machine identities, security, and PKI. Sid has led the distributed identity front in his work at Remme, helping work with the platform, engineering, and partner teams to massively extend the impact of decentralised identity and authentication solutions for the modern enterprise. He consults with Remme’s customers around the world on how to transform their identity and authentication ecosystems, thus helping them increase their business integrity and efficiency while lowering costs. Recognised as a well-rounded advocate for identity, digital transformation and blockchain-enabled solutions, Sid is also a regular speaker, contributing author and media commentator.

Hi, Sid.

Sid Desai: Hey, Oscar. How is it going?

Oscar: Very good. It’s nice talking with you. Welcome to the show.

Sid: Thank you for having me.

Oscar: A pleasure. Sid, let’s talk about digital identity and I would like to start hearing how was your journey to this world of digital identity?

Sid: I think it began around 2011. I was working on some energy smart grid projects for a large US-based smart metering company. And it was during that time where I was exposed to concepts of identity, especially something that’s got to do with Active Directory. I was also exposed to things like PKI and very early versions of single sign-on. And this applied not just for users at the company but also for machines, for the smart meters. So, concepts of machine identities were very early on at that time and was very much exposed to machine identities.

So,

View Details

Let's talk about digital identity with Dean Coclin, Senior Director, Business Development at DigiCert. In episode 18, Oscar is joined by Dean Coclin, representing the world's largest public Certificate Authority (CA) – DigiCert. The conversation decodes exactly what a CA does and its critical role in Public Key Infrastructure (PKI).

Listen in on DigiCert's view of, and role in, digital identity with relation to Transport Layer Security (TLS) and Extended Validation (EV) certificates, the Internet of Things (IoT) and Legal Entity Identifiers (LEIs).

LEIs are the 20-digit alphanumeric codes identifying unique global legal entities. Ubisecure is the fastest growing LEI issuer globally through its RapidLEI service. DigiCert announced a partnership with Ubisecure in December 2019, collaborating to extend the use of LEIs for multiple types of digital certificate-based use cases. Read the press release here - ubisecure.com/news-events/digicert-ubisecure-partnership-legal-entity-identifier-organization-identity-solutions.

Dean also fills us in on the CA/Browser Forum and the ASC X9 PKI Study Group, which he chairs.

[Scroll down for transcript] "What good is encryption if we don't know who we are encrypting to?" Dean Coclin brings more than 30 years of business development and product management experience in software, security and telecommunications.  As Senior Director of Business Development at DigiCert, he is responsible for representing the company in industry consortia and driving the company's strategic alliances with technology partners. Mr. Coclin is also the past Chair of the CA/Browser Forum and the CA Security Council. Currently he chairs the ASC X9 PKI Study Group.

Previously Mr. Coclin worked at Symantec’s Website Security business unit before it was sold to DigiCert and was one of the founders of ChosenSecurity, an Internet security firm which was sold to PGP Corporation in February 2010. PGP was subsequently acquired by Symantec in June 2010. Prior to this, Mr. Coclin was Director of Business Development at GeoTrust which was sold to Verisign in 2006. He holds a BSEE and MS from The George Washington University and an MBA from Babson College.

Follow Dean on Twitter @chosensecurity and find his articles on the DigiCert blog at digicert.com/blog.

For more information on DigiCert, visit its website - digicert.com – and follow the CA/Browser Forum at cabforum.org.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining today. Today, we will hear how certification authorities contribute to securing the internet but also what is their role in digital identity. And for that, I have a very special guest. Dean Coclin brings more than 30 years of business development and product management experience in software security and telecommunications.  As Senior Director of Business Development at DigiCert, he is responsible for representing the company in industry consortia and driving the company’s strategic alliances with technology partners.

Mr. Coclin is also the past Chair of the CA/Browser Forum and the CA Security Council. Currently, he chairs the ASC X9 PKI Study Group. He holds a BSEE and MS from the George Washington University and an MBA from Babson College.

Hello, Dean.

Dean Coclin: Hello, Oscar! Thank you for having me today.

Oscar: You're very welcome. It’s great talking with you, Dean. I’m really very excited to talk about your career and what you are doing today in this world of Certification Authorities, particularly in DigiCert. So, I would like to hear first, what was your journey to this world of digital identity?

Dean: Well, I’ve been involved with Public Key Infrastructure and Certificate Authorities since 1996 actually,

View Details

Let's Talk About Digital Identity with Grace Mutung'u, internet policy advocate and research fellow at CIPIT. This week, Oscar chats to Grace Mutung'u about challenges for digital identity in Kenya and the various considerations for inclusive national identification, including historical, social and economic issues. She fills us in on the court case against Huduma Namba (Kenya's national ID platform) that she has been involved in and its recent judgement to rule out unnecessary DNA and GPS data collection, and the framework that must be in place before being fully rolled out.

[Scroll down for transcript] "We need to think about identities before thinking about applications of digital technologies." Grace is a research fellow at the Centre for IP and IT Law (CIPIT) at Strathmore University, studying digital ID and society in Kenya. She has been involved in ICT policy advocacy for over 10 years and was most recently providing support during litigation in Kenya's digital ID case.

Find Grace on Twitter @bomu.

Find out more about the Centre for Intellectual Property and Information Technology Law (CIPIT) - a think tank and training centre established under Strathmore Law School at cipit.org.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] [Intro] Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. Today we’ll hear for the first time how is digital identity in the African continent. So, for that we have a special guest who is Grace Mutung’u. Grace is a research fellow at the Centre for IP and IT Law at Strathmore University in Nairobi studying digital identity and society in Kenya. She has been involved in ICT policy advocacy for over 10 years and was most recently providing support during litigation in Kenya’s digital ID case.

Hello Grace.

Grace Mutung’u: Hi, Oscar. Thanks for having me.

Oscar: It’s a pleasure. I’m happy to have you today on the show. So the first thing I would like to hear from you is how you entered in the world of digital identity? What was your journey?

Grace: I just kind of stumbled upon it. I have been working in ICT policy work here in Kenya. And in 2017, we had the general elections and - something about Kenya is that people take their politics very seriously. For us in the ICT space we were observing use of technology in the elections. And we observed that there was a lot of use of digital identity from two spaces.

One is that the politicians were using identity data from the voters register to target voters, to vote for them. And then at the same time there was also use of social media for political discourse for political mobilisation. And later on, the news came out that one of the political parties had actually engaged the firm Cambridge Analytica for voter targeting and some sort of political manipulation. So after that we really got into the work of advocating for our rights based digital identity for data protection and for political accountability for use of digital identity data.

Oscar: And what would you say are today the main challenges in digital identity that Kenya is facing?

Grace: I’d say one big challenge is that there has been a lot of importation of ideas, technology and hardware. So for example, Kenya is one of the countries in Africa that has always had a legal identity. In Kenya, it’s the normal thing to walk around with a card, a national identity card. It’s very normal to be asked for your card in order to access a building. This just started from a long time ago during the colonial period and then over time it’s become normalised because of the security challenges that we’ve had, the terrorism issues that we’ve had, so it’s very normal to walk around with the paper identity.

But there have been a lot of problems with the paper identity because that iden...

View Details

Let's talk about digital identity with Niklas Bergvall, Chair of the Mobile Connect Interest Group at GSMA. In episode 16, Niklas fills us in on how mobile operators around the world have joined forces to build a standard for strong authentication and other services to help protect our digital identity – Mobile Connect.

[Scroll down for transcript] "It may be that you and I, and some of the listeners of the podcast, are interested in identity. For the rest of the world its a necessary evil." Niklas and Oscar discuss Mobile Connect (a mobile identity-based service), its proven global use cases (such as China Mobile), why digital identity became a strategic priority for GSMA and the unique insights of MNOs to improve digital identity.

Niklas Bergvall

Niklas Bergvall, Chair of the Mobile Connect Interest Group at GSMA, leads the international Mobile Connect community developing and commercialising new identity capabilities using Mobile Connect. The Mobile Connect community engages over 70 mobile operators in over 30 countries, countless service providers, reaching over half a billion people worldwide.

With over 20 years of experience in the mobile ecosystem, Niklas has an exceptional understanding of the key challenges being faced when launching products and services internationally. Prior to the GSMA, Niklas launched and managed a number of global business-to-business products and services in various roles at Vodafone, Oxford Instruments and Europolitan.

Find Niklas on LinkedIn.

Find out more about GSMA at www.gsma.com and Mobile Connect at www.gsma.com/identity/mobile-connect.

Ubisecure also has a useful blog on 'What is Mobile Connect?' - check it out here: https://www.ubisecure.com/mobile-connect/what-is-mobile-connect/ - and an overview page on the Mobile Connect solution - read it here: https://www.ubisecure.com/mobile-connect-telecom/.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] [Intro] Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. Today we are going to hear how mobile operators around the world have joined forces to build a standard which brings not only strong authentication but also other services that help us to protect our digital identity.

So my guest today is Niklas Bergvall. He is Chair of the Mobile Connect Interest Group at GSMA. He leads the international Mobile Connect community developing and commercialising new identity capabilities using Mobile Connect. The Mobile Connect community engages over 70 mobile operators in over 30 countries, countless service providers, reaching over half a billion people worldwide.

With over 20 years of experience in the mobile ecosystem, Niklas has an exceptional understanding of the key challenges being faced when launching products and services internationally. Prior to the GSMA, Niklas launched and managed a number of global business-to-business products and services in various roles at Vodafone, Oxford Instruments and Europolitan.

Hi, Niklas.

Niklas Bergvall: Hi, Oscar. Very nice to be here on this podcast and thank you for inviting me to talk a little bit more about the identity and Mobile Connect specifically.

Oscar: Thanks to you. It’s really great talking with you. We really want to know more about how Mobile Connect is doing right now, what are the things coming during this New Year and ahead. But first, I would like to hear from you, how did you join, or your journey to come to, this world of digital identity?

Niklas: From the GSMA, it was really looking at our members. And our members’ networks as you know really underpin and have drive the– of the digital economy and its associated services. I mean as we see these services bring new challenges for businesses to protect customer identities and customer data which is both complex...

View Details

Let's talk about digital identity with Andy Milton, Head of Channels at Hitachi Digital Security. In episode 15, Oscar talks to Andy about Hitachi's pioneering finger-vein biometrics – VeinID Five. Hear about its use cases (present and future), the evolution of the product to its current form, comparison with other biometric and non-biometric authentication methods and, importantly, the relevant privacy and security risk mitigations.

[Scroll down for transcript] "I think it’s going to be an interesting time in the biometric world. I think we will start to see that one biometric is not necessarily the best at everything. So we are going to see lots of different applications of different technology and at different times. And what we will potentially start to see is also some of them start to become blended together as well." Andy Milton is Head of Channels and Marketing for Hitachi Security Business Group. He joined Hitachi in November 2018 to lead and develop the channel strategy for the Hitachi Security Business Group in EMEA and North America. With over 30 years in IT and 20 years in cybersecurity, Andy's experience in working for both vendors and channel partners has given him a unique insight into the workings and drivers for aspects of the channel. He brings experience across a wide range of products and solutions including SIEM, device management, WAFs, network devices and a specific interest in identity management and biometrics.

Get in touch with Andy on LinkedIn.

Hitachi Europe Ltd., a wholly owned subsidiary of Hitachi, Ltd. (TSE: 6501, "Hitachi") is headquartered in Maidenhead, UK. The company is focused on its Social Innovation Business - delivering innovations that answer society’s challenges. Hitachi Europe and its subsidiary companies offer a broad range of information & telecommunication systems; rail systems, power and industrial systems; industrial components & equipment; automotive systems, digital media & consumer products and others with operations and research & development laboratories across EMEA.

For more information, visit www.hitachi.eu.

To find out more about Hitachi's Finger Vein products visit digitalsecurity.hitachi.eu.

Hitachi is a Ubisecure partner. Find out more about the partnership, including further resources on VeinID Five, here: www.ubisecure.com/partner-directory/hitachi.

We’ll be continuing this conversation on Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Intro: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello, and thanks for joining. Today, we will hear about a very novel authentication method, multi-factor authentication method based on biometrics that you might not have heard before. My guest today is Andy Milton from Hitachi.

Andy Milton is Head of Channels and Marketing for Hitachi Security Business Group. He has more than 20 years of experience in cybersecurity across many companies.

Hello, Andy!

Andy Milton: Hello, Oscar. How are you?

Oscar: Very good and very happy to talk with you today about what Hitachi is doing with this very interesting new authentication method. So I would like to hear first from you how your career, how life led you to this world of digital identity.

Andy: OK. So just over 20 years ago now, I made a decision to move from engineering IT into security as it looked like it was becoming interesting and a hot market space, and that has proved to be very successful and a very good choice. So after working for several different vendors and partners and resellers, I've now found myself with the opportunity to join Hitachi with the addition of their new VeinID product, Five, which is very exciting for us all. I joined just over a year ago.

Oscar: OK. Fabulous. So you joined cybersecurity really many years ago and you have been in this industry since then. And very recently as you said,

View Details

Let's talk about digital identity with Rainer Hörbe, Senior Manager at KPMG Austria. In episode 14, Oscar and Rainer discuss identity management and eGovernment, including views on challenges in real eGovernment projects - India's Aadhar, Austria's smart ID card and China's residents' card. They also talk about Kantara's eGovernment work group, of which Rainer is the chair, and the annual TIIME conference, which he organises.

[Scroll down for transcript]

Rainer graduated in Computer Science from the University of Vienna. Working as a software developer for some years, he then specialised in identity and access management starting in 2001. In roles as a security and identity architect he contributed to projects like the Austrian eGovernment identity federation and European framework projects (epSOS, MAPPING). He is chair of the eGovernment WG at Kantara Initiative and contributor to standardisation activities in standards developing organisations like ISO SC27. He started the TIIME event – an annual identity conference - in 2013. Currently he has the position of Senior Manager at KPMG Austria, consulting clients in different sectors on enterprise IAM topics.

Find Rainer on Twitter @rhoerbe1 and on LinkedIn.

Find out more about the annual TIIME (Trust and Internet Identity Meeting Europe) event in Vienna at tiimeworkshop.eu. The event facilitates the cooperation between the innovative communities in various fields of trans-organisational trust and identity matters.

Check out Kantara's eGovernment Work Group here - kantarainitiative.org/confluence/display/eGov/Home.

We'll be continuing this conversation on Twitter using #LTADI - join us @ubisecure!

[Podcast transcript] Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Hello! Thanks for joining today. We will have a conversation about eGovernment, a very interesting conference coming now in February, and many more things. So let me introduce to you our guest today, Rainer Hörbe. He graduated in Computer Science at the University of Vienna. Working as a software developer for some years, he then specialised in identity and access management starting in 2001. In roles as security and identity architect, he contributed to projects like the Austrian eGovernment identity federation and European framework projects, epSOS and MAPPING.

He is chair of the eGovernment Work Group at Kantara Initiative and contributor to standardisation activities in standards developing organisations like ISO SC27. He started the TIIME event, an annual identity conference in 2013.

Currently, he has the position of a Senior Manager at KPMG Austria, consulting clients in different sectors on the enterprise IAM topics.

Hi, Rainer.

Rainer Hörbe: Hi, Oscar.

Oscar: Welcome. Very nice talking with you. So it’s starting now- just talking that we are in the middle of winter there, a little bit minus on your side, a little bit of sun.

Rainer: Yeah. Thank you for having me. It’s a good opportunity to start the year with identity management and eGovernment.

Oscar: Exactly. So let’s get started. Let’s talk about digital identity. So I would like to hear first from you how you entered this world of digital identity.

Rainer: So well, I think in 2020, a 40-year professional anniversary. And around half of that time, so almost 20 years ago, after working mostly as a software engineer, I came into identity and access management. So before that, I was exposed to topics like PKI and the host mainframe identity management tool, RACF, Lotus Notes, directories, etc. And I obviously as a developer had to do authentication, etc.

But I would say from today’s point of view, I was living in blissful ignorance because I didn’t understand identity management. Well, today still, if I could cite a Game of Thrones character, Ygritte, she was always saying to Jon Snow, “You know nothing.

View Details

Let's talk about digital identity with Monique Morrow, President and Co-Founder of the Humanized Internet and President at the VETRI Foundation. We're very excited to kick off #LTADI 2020 with Monique Morrow, multi-hyphen technology innovator and a Forbes Magazine's top 50 women globally in tech.

[Scroll down for transcript] "2020 is going to be the year for digital identity and, even more so, self-sovereign identity" In episode 13, Oscar and Monique discuss her route to digital identity, ethics in technology and credentialing, self-sovereign identity (SSI), and the various interesting projects that she is involved with.

Monique Morrow is President and Co-Founder of the Humanized Internet, a non-profit organisation focused on addressing the need to control our identities as well as providing digital identity for those individuals most underserved. The belief in the social good of technology with embedded ethics has guided Monique’s extensive work with blockchain, especially its applicability to education and credentialing as well as other industries including healthcare, insurance, and Internet of things.

Find out more about the Humanized Internet at www.thehumanizedinternet.org.

Monique is also President of the VETRI Foundation in Switzerland. The main purpose of the Foundation is to manage a platform presently known as VETRI and the funding, establishment and execution of initiatives that are focused on the management and control of data and privacy. The Foundation abides by the key tenets of "Trust and Transparency". The vision is to enable individuals to self-determine over their data. This alignment translates to assessing possible investments and activities towards secure self-sovereignty and secure e-vault mechanisms for the management and storage of data.

Find out more about the VETRI Foundation at vetri.global/the-vetri-foundation-is-here.

Much of Monique’s work operates at the intersection between blockchain technology, security-privacy issues, questions of legal jurisdiction, and portfolio development. She has had the opportunity to engage with and explore these issues in her capacity as a member of the procivis.ch and VETRI ’Global advisory boards based in Switzerland . Furthermore, she is also an active member of the IEEE Ethics in Action Executive Committee as well as Co-Chair of the IEEE Ethics in Action Extended Reality Committee.

More about Monique can be found on LinkedIn and at www.moniquemorrow.com.

We'll be continuing this conversation on Twitter using #LTADI - join us @ubisecure!

[Podcast transcript] Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host Oscar Santolalla.

Hello and thanks for joining today. We are starting the New Year 2020 and I hope you had a nice time in 2019. Now we are back and we have a fabulous guest to start this year - a guest who has an amazing career in technology, in cybersecurity and today she has embarked a lot on projects for combined technology with social impact, and a lot of that is also related to digital identity.

Monique Morrow is President and Co-Founder of the Humanized Internet, a non-profit organisation focused on addressing the need to control our identities as well as providing digital identity for those individuals most underserved. The belief in the social good of technology with embedded ethics has guided Monique’s extensive work with blockchain, especially its applicability to education and credentialing as well as other industries including healthcare, insurance, and Internet of Things.

Monique is also President of the VETRI Foundation in Switzerland. Among other accolades, Monique has been recognised in the industry for her tireless focus on social good. Monique was selected as one of the Top Digital Shapers 2018 in Switzerland. In this year, One World Identity recognised Monique as one of the top 100 influencers in identity for 2019.

View Details

Let’s talk about digital identity with Diane Joyce, Identity Evangelist and Executive at Women in Identity. In episode 12, Diane and Oscar explore all manner of digital identity topics - including self-sovereign identity, digital wallets, GDPR, CIAM and, importantly, what organisations should be doing to protect consumer identities. She also fills us in on her work with Women in Identity – a not-for-profit organisation promoting diversity in the identity industry.

[Scroll down for transcript] "I want to use technology as the enabler to make a safe and frictionless journey – I don't want to put technology in 'because it's fun'." Diane has provided thought leadership, vision and innovation in the digital transformation of financial institutions. She has worked with blue chip corporations to implement the technology and service architectures required to become certified identity providers as part of the GOV.UK Verify identity scheme. Diane has also worked with government departments setting up a pan government identity community and worked with leading IDAM vendors to address the need for secure and scalable identity federation to enable collaboration between public and private sector organisations. She champions technology innovation to provide users with a frictionless and safe digital experience.

Find Diane on Twitter @kiwiIDgal and on LinkedIn.

Find out more about Women in Identity at womeninidentity.org or on social media - Twitter @womeninid, LinkedIn and Instagram.

We'll be continuing this conversation on Twitter using #LTADI - join us @ubisecure!

[Podcast transcript] Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Hello. More and more we hear phrases like “reclaim your identity”. Some people care, some people don’t, but reclaiming identity from who? Who owns my identity today? And there are better ways we can do this. For that, we have a very special guest today, Diane Joyce.

Diane has provided thought leadership, vision and innovation in the digital transformation of financial institutions. Diane has worked with blue chip corporations to implement the technology and service architectures required to become certified identity providers as part of the GOV.UK Verify identity scheme. Diane has worked with government departments setting up a pan government identity community and work with leading IDAM vendors to address the need for secure and scalable identity federation to enable collaboration between public and private sector organisations. Diane champions technology innovation to provide users with a frictionless and safe digital experience.

Hello Diane.

Diane Joyce: Hi Oscar.

Oscar: It’s great talking with you, Diane.

Diane: Thank you.

Oscar: I know you do many things and you have done many things, very interesting things. But I would like to hear first from you, what was your journey, your personal journey, to this work of digital identity?

Diane: I’ve worked in technology, I started as a programmer many, many years ago. I’ve worked in identity for some time now but I started out in integration and security. And I saw two catalysts that I thought were going to change the technology world. And alongside those, the problem with identity needed solving.

So the first was the internet. Suddenly we could connect to anyone, anywhere, but we didn’t really know who we were connected to and how do we know it’s them the next time we connected. And when you added to that the .com boom and the subsequent e-commerce boom it has become even more important to understand who it is we’re speaking to.

And second thing is cloud computing. Following the internet and e-commerce, cloud computing solved a problem that I don’t think most organisations knew that they had. Their identity model was within the walled fortress of the data centre and so therefore they control all the identity there.

View Details

Let's talk about digital identity with Rachelle Sellung and Alberto Miranda García, representing the LIGHTest Project. As the successful three-year LIGHTest project draws to a close, Oscar talks to two key team members – project lead, Rachelle Sellung, also of the IAT University of Stuttgart, and project partner Atos representative, Alberto Miranda García. They discuss the idea behind LIGHTest, what it's all about, specific use cases of the infrastructure, and the project's achievements at its completion.

[Scroll down for transcript] "Are you sure you're doing the transaction with that person? Is that person a trustworthy counterpart in that transaction?" Find out more about the LIGHTest project at lightest.eu or visit the community website at lightest-community.org. LIGHTest are also on Twitter @LIGHTest_trust and on LinkedIn.

LIGHT est = Lightweight Infrastructure for Global Heterogeneous Trust management in support of an open Ecosystem of Stakeholders and Trust schemes.

Rachelle Sellung

Rachelle Sellung is a Senior Scientist in the competence team of Identity Management at the IAT University of Stuttgart. Within this interdisciplinary team with an array of skill sets, she provides the Economic perspective for not only Identity Management, but a variety of IT Security related technologies. She contributed a socio-economic perspective in the large-scale EU FP7 project FutureID, which developed an identity management infrastructure for Europe. Currently, she is the lead for the University of Stuttgart in the EU Horizon2020 project, LIGHTest. Find Rachelle on Twitter @rachellesellung and on LinkedIn.

Alberto Miranda García

Alberto Miranda García is Senior Business Consultant at Atos. Coming from the financial industry sector (Barclays Bank UK) he joined Atos in the Financial Services of Consulting Division. Later in 2017 Alberto joined the Financial Services sector of the Atos Research and Innovation unit, committed to business consultancy and exploitation management for European level projects, mainly related to Cybersecurity and Identity.  Find Alberto on LinkedIn.

This podcast is produced by Ubisecure who, among other respected identity players, has been one of the cooperating partners of the LIGHTest project, in its capacity as a provider of Customer IAM interactions. Ubisecure has contributed by giving insights into current best-of-breed principles in service provisioning in IAM globally; and by reviewing and contributing to the LIGHTest specifications and design from that perspective.

We'll be continuing this conversation on Twitter using #LTADI - join us @ubisecure!

[Podcast transcript] Oscar Santolalla: Let’s Talk About Digital Identity, the podcast connecting identity and business. I am your host, Oscar Santolalla.

Hi and thanks for joining. Today you can virtually make business with companies that are from any continent. But how would you know without this face-to-face contact that you can trust the person that is behind this digital service?

Today we are going to hear about a European project that has built a global trust infrastructure and for that today, we have two guests. So let’s introduce you.

My first guest is Rachelle Sellung. She’s a Senior Scientist in the competence team of Identity Management at the IAT University of Stuttgart. Within this interdisciplinary team with an array of skill sets, she provides the Economic perspective for not only Identity Management, but a variety of IT Security related technologies.

She contributed a socio-economic perspective in the large-scale EU FP7 project, FutureID, which developed an identity management infrastructure for Europe. Currently, she is the lead for the University of Stuttgart in the EU Horizon2020 project, LIGHTest.

Hello Rachelle.

Rachelle Sellung: Hi. Thank you for having me.

Oscar: And our second guest is Alberto Miranda García. He is a Senior Business Consultant at Atos.

View Details

Let's talk about digital identity with Robin von Post, Head of IAM Solutions at Cybercom. In episode 10, Oscar talks to Robin about digital signatures - what are they, what challenges do they solve/pose, and why businesses should be taking advantage of their benefits now. They also talk about the issue of trust between organisations and internationally - particularly from Swedish (where Robin is based) and pan-European perspectives.

[Scroll down for transcript] "Digital identities and digital signatures are one of the basic building blocks of making the transition to pure digital."

Robin has a deep interest and experience in the IT-security domain. He has for the last 20 years been involved in the development and deployment of high assurance encryption systems for European government and defense customers, with the last year's focus on securing national civilian critical infrastructure.

Last year, Robin took on a role at Cybercom Secure as the Head of IAM Solutions, including advanced electronic signature services, directory administration and governance, and other IAM and security related services.

On a private note, he weekly curates a newsletter – 'The von Post' - covering IT-security related events. He supports the Swedish “Säkerhetspodcasten” as a freelance reporter. He is also a private pilot & passionate photographer.

Find Robin on Twitter @rvonpost and on LinkedIn. 

Cybercom is an innovative consulting firm that enables leading companies and organisations to benefit from the opportunities of digitalisation. It provides innovative, secure and sustainable solutions in IT and communications technology by combining technical edge and strong business insight. This applies whether the issue is transforming products into services, developing new business models or helping the public sector get closer to citizens.

It is a highly diverse company, with a large age range, 45 nationalities and assignments in 20 countries. Cybercom’s domestic markets are the Nordic region and Poland, and in addition the company offers global delivery capacity for local and international business. Find out more at cybercom.com.

Read about Ubisecure and Cybercom's recent partnership announcement at ubisecure.com/news-events/cybercom-partnership.

Listen to episode 21 with Robin's colleague, Bengt Berg - Head of Compliance Management Services at Cybercom, here: www.ubisecure.com/podcast/bengt-berg-cybercom-iam-compliance/

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. Today we’re going to discuss a situation in which many people who have to sign documents and are given a digital version of signing might be aware that is this really safer, more secure than the old way? Or, if you are one of these persons who are signing documents not occasionally but many times per day and you think there will be a more modern way to do this. So we’re going to talk about digital signatures. And for that we have our guest today.

Let me introduce you to Robin von Post. He has a deep interest and experience in the IT-security domain. He has for the last 20 years been involved in the development and deployment of high assurance encryption systems for European government and defence customers, with the last year’s focus on securing national civilian critical infrastructure.

Last year, Robin took on a role at Cybercom Secure as the Head of IAM Solutions, including advanced electronic signature services, directory administration and governance, and other IAM and security related services.

On a private note, he weekly curates a newsletter called The von Post covering IT-security related events. He is also a private pilot and a passionate photographer.

Hello Robin.

View Details

Let's talk about digital identity with Don Thibeau, Executive Director of the OpenID Foundation. In episode 9, Oscar talks to Don about his career so far; his work with the OpenID Foundation (including FAPI and CIBA standards) and the Open Identity Exchange (OIX); and what he calls the 'Holy Trinity' driving the identity industry. Throughout the conversation Don highlights cultural differences in attitudes towards digital identity, and how we should be taking a more global approach.

[Scroll down for transcript] "We have to work locally, but we have to think globally" Don Thibeau is the Executive Director of the OpenID Foundation, a non-profit international standards development organisation of individuals and companies committed to enabling, promoting and protecting OpenID technologies. The Foundation’s membership includes leaders from across industry sectors and governments that collaborate on the development, adoption and deployment of open identity standards. Formed in June 2007, the Foundation serves as a public trust organisation representing the open community of developers, vendors, and users while providing needed infrastructure and leadership in promoting and supporting expanded adoption of OpenID. Find more information at openid.net/foundation/.

Don is also the Co-Chair of the OASIS Electronic Identity Credential Trust Elevation Methods (Trust Elevation) Technical Committee. He founded and now serves on the board of the Open Identity Exchange (OIX) - a non-profit, technology agnostic, collaborative cross sector membership organisation with the purpose of accelerating the adoption of digital identity services based on open standards. As Don mentions in the episode, you can find the OIX's extensive whitepaper library at openidentityexchange.org.

Find Don on Twitter @4thibeau, on LinkedIn, or email don(at)oidf.org.

Don also refers to previous episodes of Let's Talk About Digital Identity with DIACC President, Joni Brennan - ubisecure.com/podcast/joni-brennan-diacc - and with One World Identity’s Cameron D’Ambrosi - ubisecure.com/podcast/cameron-dambrosi-one-world-identity/.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. Today we will have a conversation with a man who has led, and today leads, very influential organisations in this realm of digital identity.

Don Thibeau is Executive Director of the OpenID Foundation, a non-profit international standards development organisation of individuals and companies committed to enabling, promoting and protecting OpenID technologies.

The foundation’s membership includes leaders from across industry sectors and governments that collaborate on the development, adoption and deployment of open identity standards.

Don is also the Co-Chair of the OASIS Electronic Identity Credential Trust Elevation Methods (Trust Elevation) Technical Committee and Don was the founder of the Open Identity Exchange and serves on its board.

Hello Don.

Don Thibeau: Hello Oscar. I’ve been looking forward to this conversation for some time.

Oscar: Same on our side. It’s great talking with you today. So let’s talk about digital identity. I would like to ask you first, what was your journey to this world of digital identity?

Don: Yes. Most of my career has been involved in the identity data business. The companies that I’ve been part of and the companies that I’ve founded have all in one form or fashion been concerned with how identity is expressed online, both in code and in governance.

So the work that I’ve been doing for the last 10 years has really been focused on digital identity on a global basis. I’ve had an opportunity to lead two organisations in the space and if I can,

View Details

Let’s talk about digital identity with Cameron D'Ambrosi, Principal at One World Identity. It's a crossover episode! Host of One World Identity's State of Identity podcast, Cameron D'Ambrosi, joins Oscar on the Let's Talk About Digital Identity podcast, to talk about the benefits of collaboration in the industry, how identity trends and behaviours are changing (particularly with Gen Z, aka 'zoomers') and global identity challenges. "Digital identity has ceased to be a technology problem – it's a people problem." Make sure you check out the State of Identity podcast with Ubisecure CEO, Simon Wood! Listen here - oneworldidentity.com/podcast/ubisecure.

Cameron D’Ambrosi is a Principal at One World Identity, and host of the State of Identity podcast. In his role, Cameron is responsible for supporting OWI’s advisory services platform by offering clients key insights into the companies and technologies shaping digital identity today. Prior to joining OWI Cameron was a Manager with Deloitte, focused on helping financial services clients complete digital transformations of their AML and KYC programs. Cameron is a graduate of Fordham University, with a degree in History. A long-time resident of New York City, in his spare time Cameron can be found in the somewhere in the five boros hunting down something delicious, or in his apartment tinkering with gadgets.

Follow Cameron on Twitter @dambrosi.

One World Identity (‘OWI’) is a market intelligence and strategy firm focused on identity, trust, and the data economy. It helps business leaders, governments, and investors stay ahead of market trends so they can build sustainable, forward-looking products. Follow OWI on Twitter @1worldidentity.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. Today we will hear about the work of One World Identity and also we will hear the voice of another podcast host in the digital identity industry.

Cameron D’Ambrosi is a Principal at One World Identity, and host of the State of Identity podcast. In his role, Cameron is responsible for supporting One World Identity’s advisory services platform by offering clients key insights into the companies and technologies shaping digital identity today.

Prior to joining One World Identity, Cameron was a Manager with Deloitte, focused on helping financial services clients complete digital transformations of their AML and KYC programs.

A long-time resident of New York City, in his spare time Cameron can be found somewhere in the five boroughs hunting down something delicious, or in his apartment tinkering with gadgets.

Hello Cameron.

Cameron D’Ambrosi: Hey Oscar. Thanks for inviting me. This is great and I’m very excited to be here.

Oscar: Same. It’s very nice talking with you today Cameron and please, the first thing I want to know is how was your journey to this world of digital identity.

Cameron: That’s a great question. So I’ve kind of danced around the topic of digital identity for a large part of my career. Even before I was with Deloitte, I actually started my career with the New York Stock Exchange’s regulatory arm, NYSE Regulation, which is now defunct. It’s part of FINRA still I believe but that’s neither here nor there.

But I started off at the New York Stock Exchange in trade surveillance looking at how the specialists at the time were conducting themselves and if they were comporting with New York Stock Exchange rules, specifically around the time stamping and audit trail of orders, which at that point had basically become automated as well. There was a man in the loop but it was largely computer systems making those decisions. And in hindsight, that was kind of my first exposure to digital identity because a lot of...

View Details

Let’s talk about digital identity with Julian Hayes, CEO of Veneto Privacy. In episode 7, Oscar talks to Julian Hayes about data privacy in the days of Brexit chaos and why a penalty fine shouldn't be your biggest concern when it comes to GDPR.

[Scroll down for transcript] “GDPR is 40% security and 60% privacy" Julian is a highly experienced Data Privacy and Security consultant with more than 18 years working in the telecommunications and IT industry. As Managing Director of Veneto Privacy Services, Julian and his team provide in-depth data protection consultancy services to clients in diverse industries, from telecommunications, consumer goods and educational providers throughout Europe and the United States. Find Julian on LinkedIn or email julian@venetoprivacy.ie.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. Today we will hear about a very important aspect of our digital lives, which is privacy, and for that we have an expert in the topic. So let me introduce you Julian Hayes. He’s an expert in data privacy with more than 20 years of experience, which includes working for telecommunications big players, such as Vodafone and Nokia.

Today he’s the Managing Director of Veneto Privacy Services, a consulting company based in Dublin, Ireland. Hello, Julian.

Julian Hayes: Hello Oscar, thank you for having me.

Oscar: Yeah, it’s a pleasure having you and talking with you Julian and yeah, please tell us a bit more what is – has been your journey until today. You have your own consulting company Veneto.

Julian: Great. It’s a pleasure to talk to you and I know that today’s subject on Brexit, GDPR and digital privacy generally should be an interesting discussion and listening material for your subscribers.

So Veneto Privacy is in business now three years. So prior to its establishment, I was a Data Protection Officer for Vodafone in the UK and in Ireland predominantly. So really I guess I was working in data privacy before it became such an issue of concern in terms of how personal information is obtained and processed. So it’s kind of – it grew – from my own kind of professional experience, it grew from about 2004 and then in 2010 it reached off as a major issue.

So data protection laws have been in place for decades, so it’s not that there was any type of new realisation. But there has been an increased focus I think from 2010 on data privacy and the importance of respecting personal information from a customer perspective.

So yeah, so we’re based in Dublin and we service companies in Europe and the US and we work basically a 24/7 type of operation, working in multiple time zones. Still a small consultancy business and we’re very much specialised in commerce-related personal data processing and GDPR obligations. As we’ve seen, there are many regions within the world that are implementing similar types of data protection law in the style of GDPR which is seen as kind of the best in practice operation.

Oscar: Yeah, very interesting. You have a 24/7 operation it sounds like. Pretty challenging. And tell us a bit the experience you have today with working in Veneto, your own company. What are the main challenges customers you have today have?

Julian: With the anticipation of the 25th of May 2018, there was a huge focus from companies to get compliant with GDPR and I remember often there were customers who would say, “Well, you know, is it just another Y2K? Is it just another type of hype situation?”

But the difference between Y2K and GDPR is that GDPR is actually law – and Y2K was a theory in the world. So I think that’s the major kind of challenge is, you know, preparations for establishing the basics of good e-processing operations,

View Details

Let’s talk about digital identity with Joni Brennan, President of DIACC (Digital ID & Authentication Council of Canada). In episode 6, Oscar talks to Joni about Canada's strategic collaboration for securing identity that builds economic 'good growth'. They also discuss Joni's journey to joining the identity space, challenges for digital identity from a Canadian point of view, and DIACC's vision for the future.

[Scroll down for transcript] "The way that we will grow the economy is through interoperability of identity solutions and services." Find out more about DIACC at diacc.ca or follow it on Twitter @mydiacc.

Joni Brennan is President of the Digital ID & Authentication Council of Canada (DIACC).  Building on over 15 years of hands on experience in Identity Access Management innovation, adoption, and industry standards development, Joni helps the DIACC to fulfill its vision delivering the resources needed to establish a digital identity ecosystem that accelerates the digital economy, grows Canada's GDP and benefits all Canadians.  Joni builds diplomatic and impactful collaborative relationships and formalizes strategic partnerships. She has participated in international committees from organizations including: OECD ITAC, ISOC, IEEE, OASIS, ISO, and ITU-T.

Before joining DIACC Joni was Kantara Initiative's Executive Director driving programs for business, legal, and technology interoperability to connect entities and individuals in a more trustworthy environment. Joni lead Kantara Initiative as the United States premiere trust framework provider delivering value to multiple industry sectors. Joni helped to ensure that Kantara Initiative program is aligned with multiple eGovernment strategies from economic regions including: Canada, New Zealand, Sweden, and the United Kingdom.

Joni Brennan previously served as the first-ever IEEE-SA Technology Evangelist for Internet Identity and Trust focusing on issues of governance, policy, and technology development that touch digital Identity, personally identifiable information, and trust services.

When not connecting the digital identity world for the better Joni can be found skiing in beautiful British Columbia, Canada. She can also be found playing flute or synthesizers in future thinking musical collaborations.

Follow Joni on Twitter @jonibrennan.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let's talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thank you for joining. Today we will talk about Canada, Canada’s strategic collaboration for securing identity and build economic good growth. And for that, we have a very special guest who is Joni Brennan.

Joni Brennan is President of the Digital ID & Authentication Council of Canada (DIACC). Building on over 15 years of hands-on experience in Identity and Access Management innovation, adoption, and industry standards development, Joni helps the DIACC to fulfil its vision delivering the resources needed to establish a digital identity ecosystem that accelerates the digital economy, grows Canada's GDP and benefits all Canadians.

Joni builds diplomatic and impactful collaborative relationships and formalises strategic partnerships. She has participated in international committees from organisations including OECD ITAC, ISOC, IEEE, OASIS, ISO, and ITU-T.

Before joining DIACC, Joni was Kantara Initiative's Executive Director driving programmes for business, legal, and technology interoperability to connect entities and individuals in a more trustworthy environment. Joni led Kantara Initiative as the United States premiere trust framework provider delivering value to multiple industry sectors. Joni helped to ensure that Kantara Initiative Program is aligned with multiple eGovernment strategies from economic regions including Canada,

View Details

Let’s talk about digital identity with Emma Lindley, Co-Founder of Women in Identity. In episode 5, Oscar talks to Emma Lindley about her background in digital identity, the challenges for digital identity (both for society and for the identity industry) and the Women in Identity community, which she co-founded. "Digital identity solutions built for everyone are built by everyone.“ [Scroll down for transcript]

Emma has over 16 years of experience in the identity industry, most recently as Head of Identity and Risk for Visa, and has a passion for diversity and inclusion. She has a strong track record of helping banks, fintechs, airlines, retailers and online gambling companies weave digital identity, security and privacy into their customer journeys, and works on creating compelling user experiences at the intersection of identity, security and privacy. Find Emma on Twitter @EmLindley or on LinkedIn.

Emma is also co-founder of Women in Identity, a not-for-profit bringing the topic of diversity and inclusion to the identity space. Anyone can, and is encouraged to, become a member for free and benefit from networking events and forums, conference discount codes, newsletter updates, mentor programmes and internships (coming soon). Sign up at www.womeninidentity.org. Women in Identity is funded by sponsorship and run by volunteers from the identity industry. If you're interested in those opportunities, email info@womeninidentity.org. Women in Identity also on Twitter @womeninid, Instagram @womeninid, and LinkedIn.

If you're following Emma's top tip at the end of the episode for keeping your data safe online, check out haveibeenpwned.com.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let’s talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. Today we are going to hear about the importance of Women in Identity and for that, I would like to introduce Emma Lindley. She’s an adviser on digital identity and co-founder of Women in Identity, a not for profit organisation focused on developing diversity in the identity industry.

Over her career of 16 years in identity, Emma has held various roles, most recently as Head of Identity and Risk at Visa, with previous board level roles at Confyrm, Innovate Identity and The Open Identity Exchange, and was instrumental in the commercial development of GB Group’s position in the identity market back in 2003.

She has been recognised in the KNOW Identity Top 100 leaders in Identity in 2017, 2018 and 2019, the Innovate Finance Powerlist for Women 2016 and 2017, and was voted CEO of the year at the KNOW Identity Awards. She has an MBA from Manchester Business School and completed her thesis in Competitive Strategy in the Identity Market.

Hello Emma.

Emma Lindley: Hi Oscar.

Oscar: It’s very nice talking with you Emma and I really want to hear more about Women in Identity and what you have been doing there. So let’s start. Let’s talk about digital identity.

Emma: For sure.

Oscar: So please tell me a bit about your journey, how you entered into this world of digital identity.

Emma: Sure. So I mean I started in the identity industry back in 2003 and it’s interesting actually, I kind of didn’t intentionally move into this industry. I was working at a company based in the UK and we had some data about kind of UK citizens, things like the electoral roll and some telephone records.

And the CEO at the time had quite a lot of kind of, you know, foresight into the future and he said I think this problem with kind of online identity is – it’s going to become a thing and he asked a small team of us to get together. There were six of us at the time, asked to get together and develop a product proposition around using some of the data that we had about UK people to help with this ...

View Details

Let’s talk about digital identity with Telia Company's Lauri Immonen - Head of Security & Identity - and Joni Rapanen - Global Product Manager. In episode 4, Oscar talks to Lauri and Joni about why the Telia Identification Broker Service (TIBS) came about and the challenges of creating an award-winning cross-border service.

The TIBS offers several strong authentication methods with just one service agreement and integration. It relays strong identification events and data between identification service providers and customer services used by end users. The strong authentication methods offered today are TUPAS and Mobile ID. Additional authentication methods will be added and they will be immediately available to all TIBS customers – including methods from multiple countries, to enable a global solution.

Read this case study to find out more about the Telia Identification Broker Service, including how and why it was built, plus the benefits for all parties - https://www.ubisecure.com/wp-content/uploads/2019/10/Telia-Identification-Broker-Service-Ubisecure-Case-Study.pdf

[Scroll down for the transcript of this podcast episode]

Lauri Immonen

Lauri Immonen has held various positions within Telia Company for the last 17 years and now leads the Commercial Security & Digital Identity portfolio on a group level. He is an experienced speaker on Digital Identity, Privacy and Cyber Security. 

Joni Rapanen

Joni Rapanen is the Global Product Manager for Identity Services at Telia Company. He has 15 years of experience in the identity & digital signing area - from national ID cards to private b2b identity - and drives strong authentication, attributes and identity federation to support more secure overall digitalisation of thousands of different services.

Telia Company is a telecommunications service provider offering mobile, broadband, television, and fixed-line services to both individuals and organisations. It also provides business services from the Internet of Things (IoT) to system integration services and financing solutions. Headquartered in Stockholm, a hub for innovation and technology, Telia Company serves millions of customers every day throughout the Nordics and Baltics - one of the world’s most connected regions.

You can find information about Telia Company's B2B identity services here - www.telia.fi/yrityksille/infrapalvelut/tietoturva/tunnistuspalvelu - and about their B2C mobile ID here - www.telia.fi/kauppa/palvelut/mobiilivarmenne (both links in Finnish).

Read more about the European Identity and Cloud award for the Telia Identification Broker Service at ubisecure.com/telia-award.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let's talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining today. Today we’re going to hear about Telia, what Telia is doing specifically in identification, as a broker service.

For that, we have two guests today. So let me introduce you to them. Lauri Immonen has held various positions within Telia Company for the last 17 years and now leads the commercial security and digital identity portfolio on a group level.

Then we have Joni Rapanen. He’s a global product manager for identity services in Telia Company. He has 15 years of experience in the identity and digital signing area, from national ID cards to private B2B identity, and he’s driving strong authentication attributes in identity federation to support more secure overall digitalisation of thousands of different services.

Hi Lauri and Joni. Welcome.

Lauri Immonen: Hello. Thanks for having us.

Joni Rapanen: Yeah, thanks.

Oscar: It’s great talking with you. So Lauri and Joni, let’s talk about digital identity and I would like to hear first how you entered into this world of digital identity.

View Details

Let’s talk about digital identity with Max van de Poll, Product Manager for SplitKey at Cybernetica. In episode 3, Oscar and Max discuss how Estonia is leading the way with an advanced digital government and what other countries can learn from them. Max also educates us on SplitKey – Cybernetica’s authentication and digital signature solution, which provides secure two-factor authentication and legally binding signatures. Find out more here - cyber.ee/products/digital-identity.

[Scroll down for transcript]

Max is the Product Manager for SplitKey at Cybernetica. Cybernetica is a research and development intensive ICT company, based in Estonia, that develops mission-critical software systems and products, maritime surveillance, and radio communications solutions. cyber.ee.

Max’s focus, beyond his product, is in digital identity in the real world, promoting Estonia as one of the best examples of where a long term, national digital identity has enabled massive efficiencies in both the public and private sector, with many lessons ready to be learnt by those that might follow.

Prior to joining Cybernetica, Max worked in consulting as a digital transformation project manager in London, working on large scale, business critical programmes.

Reach Max on Twitter - @MaxCvdP – or LinkedIn - www.linkedin.com/in/maxvdp.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let's talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for joining. You might have heard of Estonia as one of the most advanced digital societies in the world. And this success has been led by government initiatives. And there was a company that has played a major role in developing and maintaining much of Estonia’s digital government technology over the last 20 years, such as internet voting, the X-Road platform, tax and customs. We’re talking about Cybernetica. And from this company today, we are going to talk with Max van de Poll.

Max currently works in Cybernetica in Estonia as a SplitKey Product Lead. SplitKey is their mobile authentication technology for digital identity and signing. Prior to Cybernetica, Max was a Digital Project Management Consultant for large scale digital transformations. Besides his actual role in Cybernetica today, he has a strong focus on digital identity in the real world looking at Estonia from the inside with an outsider’s perspective, and other countries that have successfully implemented high penetration digital identities like its Scandinavian neighbours. Hello, Max.

Max van de Poll: Good morning.

Oscar: Good morning and it’s great talking with you.

Max: It’s fantastic to be on. Thank you very much for inviting me.

Oscar: Yeah, it’s going to be pretty fun. And I’m really interested in hearing about Cybernetica. And actually to give more background to people who are not so familiar with how Estonia is today, could you start telling us briefly what are the main achievements of Estonia in e-government? So what citizens can do in Estonia today that in other countries they cannot.

Max: Absolutely. Well, Estonia is an incredibly interesting country, much of it coming from the digital government. And like you mentioned there, it’s seen as one of the most advanced digital governments in the world. If you Google “most advanced digital government”, Estonia is what comes up most of the time. And like you explained, Cybernetica has been at the heart of that.

But what that means for the individuals, the citizens here, is much better interaction with not only the public sector and the government services they use for tax and for medical and for healthcare and things like that, but also the private sector - how they can interact with the public but also utilise the other government offerings to make the service as a whole much,

View Details

Let's talk about digital identity with Simon Wood, CEO of Ubisecure. In episode 2, Oscar interviews Simon Wood about his passion for digital identity and touches on some of the ways that Ubisecure is tackling challenges in the industry.

Also hear about Right to Represent [previously 'Right to X'] - the brand new, pioneering Ubisecure service enabling advanced delegation between all combinations of individuals and organisations - and its value for organisations. Read more about Right to Represent here - www.ubisecure.com/right-to-represent/.

[Scroll down for transcript] "Right to X is an evolution of where Ubisecure has come from and is going to over the last 10 years. At one level, it's not new at all. At another level, it's groundbreakingly new." As Group CEO at Ubisecure, Simon is responsible for planning, communicating and delivering Ubisecure’s overall vision and corporate strategy to enable the true potential of digital business through modern identity management solutions. 

Simon is a dedicated and uncompromising technology business leader, grounded in sophisticated high performance solutions. Previously, at GlobalSign, Simon led the strategic and technical growth of the company and during his tenure has overseen, from inception, the transition to high volume operations, providing world record performance, both technically and commercially.

At QuantumWave Capital Simon led the Venture Building practice, engaging, signing and working with deep technology early stage companies, preparing them for exit to large acquirers. Responsible for top-line performance Simon transformed the engagement model delivering a stable pipeline with predictable recurring revenue.

Prior to this Simon held a number of development leadership roles for software companies specialising in high-performance, real-time communications capture, analysis, and distribution, including highly secure military radio, aircraft black box analysis, Formula 1 telemetry and ECU management systems.

Simon graduated with a Bachelor of Engineering in Electronic Engineering from Southampton University. He holds multiple patents in the field of mobile internet software systems design. 

Find Simon on LinkedIn.

Ubisecure provides feature rich customer identity management software and services. The company provides a powerful Identity Platform and Identity Cloud to connect customer and citizen digital identities with customer-facing applications. The platform consists of productised Customer Identity & Access (CIAM) middleware and API tooling to enable single digital identity benefits across multiple applications. Features include single sign-on (SSO), multifactor authentication (MFA), authorisation workflows, user identity management, and pre-established connections to dozens of third-party identity providers (social, mobile, and verified).

Find out more about Ubisecure at www.ubisecure.com.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let's talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Hello and thanks for listening. If you're asking yourself what Ubisecure is doing nowadays, well, today we'll know more about that, with some insights from Ubisecure in house. And for that we will have Ubisecure CEO, Simon Wood, to talk about what are the challenges that our customers have and how, with our innovations, are having solutions for these challenges. As Group CEO, Simon Wood is responsible for planning, communicating, and delivering Ubisecure's overall vision and corporate strategy to enable the true potential of digital business through modern identity management solutions. Prior to joining Ubisecure, Simon was the CTO at GMO GlobalSign, a leading global certification authority, where he led the technical and strategic growth of the company.

View Details

Let's talk about digital identity with Colin Wallis, Executive Director of Kantara Initiative. Welcome to the very first episode of Let’s Talk About Digital Identity! Today we’re keeping up with the Kantarians, as they celebrate Kantara’s 10th anniversary.

Join Oscar as he chats with Colin Wallis, Executive Director, about the Kantara Initiative, how they’re different to other associations, their consent receipt project, and the main challenges in digital identity – present & future.

[Scroll down for transcript] "You can't really have good privacy without good identity, which relies on good security." Watch a short demo of the Kantara Consent Receipt on YouTube - www.youtube.com/watch?v=BW578dJRNCI&t=1s

Colin leads the Kantara Initiative Inc. a globally acknowledged ethics based, mission-led Trust Framework Operator of conformity assessment and Trust Marked schemes for Identity, Credential and Consent Management Service Providers, and the only 3rd party assessor of services seeking conformance with NIST 800-63-3 IAL2/AAL2. Kantara's open and inclusive philosophy to community development attracts the leading edge of identity and privacy innovation in its Working Groups that in turn attract R&D and sponsored funding. Colin develops and executes the strategic plan in concert with the Board and Leadership Council, driving the organisation forward with the help of a dedicated band of expert volunteers. Colin's combined public and private sector background in online identity and privacy continues to ensure that the Kantara Initiative program is aligned with multiple eGovernment strategies in Australia, Canada, New Zealand, Sweden and the US while influencing others in Europe and around the world.

Building on 15 years of contribution to international standards and consortia, Colin maintains other leadership positions across the consortium space in Information Security, Privacy and Trusted Identity. He represents Kantara on the OECD's ITAC (Internet technical Advisory Committee) and is a Board Director of the US NSTIC IDESG. He resigned his role as NZ's HoD in ISO JTC1 SC27, his Board post on the Cloud Security Alliance's (CSA) NZ Chapter and his positions in OASIS all linked to his public service employment in New Zealand before moving to the UK early in 2016 to run Kantara. Colin was named in OWI's Top 100 Influencers in Identity in 2018.

Find Colin on LinkedIn and on Twitter @KantaraColin.

Kantara Initiative operates conformity assessment, assurance and grant if Trust Marks against de-jure standards under its Trust Framework program whilst in parallel nurturing ‘beyond-the-state-of-the-art’ ideas and developing specifications to transform the state of digital identity and personal data agency domains.

Find out more at kantarainitiative.org and www.kantarainitiative.eu. You can also find Kantara on LinkedIn.

And here's the link to Standard Label, as mentioned in the episode: standardlabel.org.

We’ll be continuing this conversation on LinkedIn and Twitter using #LTADI – join us @ubisecure!

[Podcast transcript] Let's talk about digital identity. The podcast connecting identity and business. I am your host, Oscar Santolalla.

Oscar Santolalla: Welcome to the first episode of Let's Talk About Digital Identity. Digital identity is a challenge for everybody; people, businesses, government. Thanks to open standards, we can navigate securely on the Internet. And this is a product of hard work by organisations such as Kantara Initiative, which this year celebrates 10 years. And we are going to hear more about Kantara Initiative and who could be the best person to tell us about it than our guest today.

Colin Wallis is the executive director of Kantara Initiative, the global non-profit trade association dedicated to improving trustworthy use of identity and personal data through innovation, standardisation and good practice.

Kantara operates trust frameworks to assure digital identity in...