On 28 April, teissTalk host Geoff White was joined by Matthew Lang, Chief Information Security Officer, SECU; JB Benjamin, Chief Information Security Officer, REAP Technologies Ltd; and David Mahdi, CSO and CISO Advisor, Sectigo.
The UK has announced plans to introduce legislation to improve the security of digital identity solutions. The new rules are designed to enhance trust in digital identities, reducing reliance on traditional physical documents such as passports and driving licenses. However, there are considerable privacy and security concerns relating to how the sensitive personal data collected will be stored and used. The Office for Digital Identities and Attribute (ODIA) will be given the power to issue an easily recognized trust mark to certified digital identity organizations, demonstrating that they can be trusted to handle personal data safely and consistently. The government believes this shift will have privacy and security benefits by reducing the amount of personal information that needs to be revealed online or in-person once they have created a digital identity with a trusted organization. The question that arises, though, is if it’s the government who should manage an individual’s digital identity or should it be the individuals themselves? In the US, attitudes towards digital identity are evolving, too. 5 years ago, it was unimaginable to sign a document digitally and use it for an application for a mortgage. Now it’s common practice. Digital identities do raise some security concerns. But so does the availability of certain bulk digital forgery tools that take an electricity bill template and when combined with a data base, can print out multitudes of fake electricity bills that look genuine. In this context, digital identities, if done securely, look like the better solution. Canada is now in the second phase of its digital identity programme, where a consortium of banks owns a Hyperledger blockchain – each of them a number of nodes – to store and verify identities. With verified.me you can verify your digital identity quickly and securely using personal information that you consent to share from your Connections, such as your financial institution – which can, in the long run, turn banks into brokers of identity. Although the concept of self-sovereign identity is a valid one, the jury is still out on who actually should be the custodian of digital identity: the individual who owns the data or the government, the bank etc as a third party.
It again boils down to trust, i.e., whether you trust a third party, and trust them with or without the government’s endorsement. Although you consent to the institution’s data privacy policy when you go and see a doctor, few people actually read or deliberate the terms of the policy. The question is whether companies can rely on external trust ecosystem for their internal IAM etc processes. BYOI (Bring your own identity) wallets will play a central role in digital identity management. When, for example, taking out a loan with a bank, the applicant can take data from their driver’s licence authority such as proof of address and age and attributes from their employer to prove that they work for them, as well as their pay range. All data supplied by various providers will be digitally signed by them. But are we opening Pandora’s box and create a digital world where SSL keys can be and are stolen?
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543