Identity is not failing because attackers are smarter.
It is failing because we built it in pieces.
Identity spans security, risk, product, compliance, operations, and customer experience. In most organizations, no one owns it end to end.
Onboarding is optimized in one place. Authentication in another. Fraud, recovery, help desks, and operational workflows somewhere else entirely. Each layer is locally optimized. The system as a whole is fragile.
That fragmentation is no longer survivable.
The problem is accelerating
Fraud and scams are no longer episodic. They are continuous, adaptive, and increasingly coordinated. Attackers iterate faster than organizations can redesign identity systems, exploiting gaps between teams, tools, and controls rather than any single weakness.
At the same time, defenders are navigating multiple shifts at once:
- Industrialized fraud and scam operations that adapt in near real time
- Agentic AI increasing the speed, scale, and coordination of attacks
- Rapid adoption of digital credentials and wallets
- New authentication models that reduce some risks while exposing others
- Expanding regulatory and compliance expectations across jurisdictions
- Increased reliance on agents, automation, and outsourced operations
Most identity programs were not designed for this pace or this level of concurrency.
The result is predictable. Organizations harden visible flows like onboarding and login, while attackers exploit recovery paths, help desks, operational exceptions, and agent-driven workflows.
The front door improves. Side doors multiply.
This is not a technology failure. It is a system failing under pressure.
Where my perspective comes from
I work across identity, fraud, security, and fintech as an independent advisor, operator, and ecosystem builder, with experience on both the vendor and deployment sides.
- Nearly three decades ago Visionics Became involved with one of the first facial recognition companies and helped grow it into what is today one of the largest identity companies in the world.
- Since then Building and advising identity & biometric technologies Used in real-world, high-stakes environments, where tradeoffs between risk, usability, privacy, and governance are unavoidable. Helped shape some of the early responsible-use guidelines for biometrics, and has advocated for privacy-first identity strategies since the earliest days of commercial deployment.
- More recently — five years Anonybit — co-founded and led Pioneering privacy-preserving biometric architectures.
- Senior leadership roles BioCatch · MyCheck (now Shiji Group) · L-1 Identity Solutions (now Idemia) Across the identity, payments, and fraud ecosystem.
- Along the way Governments and multilateral organizations Advised on national-scale biometric and digital identity deployments, supported the growth of mobile payments and digital financial services, and led strategic partnerships that moved identity technologies from pilots into sustained commercial adoption.
Being independent allows for honest conversations and sometimes uncomfortable conclusions.
Sometimes the problem is not the tool, but how identity is organized. Sometimes the right answer is not a new product, but treating identity as infrastructure rather than as a feature and designing a better way for how existing tools can work together. Sometimes, the biggest risks sit in the flows organizations believe are secure.
I do not believe there is a silver bullet or a one size fits all in identity. However, I do believe most organizations underestimate how deeply identity touches their operations and overestimate how much control they actually have.
Who Identity Strategies is for
My work will resonate with those who are accountable for identity and fraud outcomes, including:
- 01Banks
Confronting relentless fraud, scams, and recovery abuse, trying to distinguish between vendors making increasingly similar claims.
- 02Fintechs
Seeking growth without opening new attack surfaces or inviting fraud at scale.
- 03Enterprises
Managing expanding identity risk across employees, agents, and help desks, without clear ownership or a starting point.
- 04Solution providers
Attempting to cut through market noise while navigating customers' real-world deployment, operational, and regulatory constraints.
- 05Executive boards and C-level teams
Accountable for identity and fraud risk that is opaque, or poorly understood.
If this framing resonates, the next step is not a pitch
It is a conversation about where identity is failing under pressure and what meaningful change actually requires.