Malik Haidar has spent over two decades at the intersection of high-stakes intelligence and corporate resilience, navigating the complex digital battlefields where multinational corporations face off against increasingly sophisticated adversaries. As a cybersecurity expert with a deep background in analytics and security intelligence, he has pioneered strategies that move beyond technical patches to integrate a holistic business perspective into defensive architectures. As we navigate the complexities of 2026, the lines between digital and physical threats have blurred entirely, making his insights into identity and trust more critical than ever. In this conversation, we explore the erosion of traditional recognition, the systemic vulnerabilities in modern security handoffs, and the urgent need for a continuous identity lifecycle that can withstand the era of industrial-scale impersonation.
The interview explores how the rise of synthetic media has transformed fraud from a localized nuisance into a scalable business model, rendering traditional visual and auditory confirmation obsolete. It delves into the limitations of human intuition in the face of professional-grade deepfakes and the necessity of shifting toward a decentralized biometric framework that prioritizes user privacy. Furthermore, it examines the regulatory landscape of the mid-2020s and the emerging challenge of managing non-human identities as AI agents become standard participants in corporate workflows.
The professionalization of synthetic voices and faces has turned impersonation into a scalable business model. How does this shift the fundamental way we think about daily recognition in a corporate environment?
In the past, everyday life depended on simple recognition where a photograph was evidence, a voice on the phone provided confirmation, and a familiar face on a video call meant your colleague was actually there. These assumptions were so deeply embedded in our corporate culture that we stopped noticing them, but in 2026, they no longer hold any weight. AI has made it incredibly easy to manufacture a convincing face saying convincing things in someone else’s voice, effectively turning identities into attack tools that can be sold and deployed with the efficiency of modern software. Every process built on the assumption of visual or auditory recognition, from hiring interviews to payment approvals and password resets, is now resting on ground that has shifted. The defining challenge today is no longer just about building a stronger lock; it is about establishing with absolute certainty if the person is genuine, if they are the right person, and if they are authorized to act in that specific moment.
The story of a high-level executive foiling a deepfake attempt by asking about a specific book recommendation is often cited as a win for human intuition. What does this incident actually reveal about the systemic vulnerabilities in our current organizational defenses?
While that executive’s quick thinking saved the company, it highlights a terrifying reality: the organization was protected only by a single memory shared between two people. That defense worked for one person, in one company, during one specific call, but you simply cannot run a global airline, a hospital system, or a national border on a foundation of trivia. When the final line of corporate defense is reduced to a book recommendation, it is a clear signal that recognition has stopped being a reliable form of verification. Relying on an alert employee to detect a voice that perfectly reproduces a CEO’s accent is a gamble that most organizations will eventually lose. We need a systematic, automated way to establish identity, presence, and authority that does not rely on the variable “gut feeling” of individuals.
Identity fraud has been a constant in the industry, but why do you argue that deepfakes represent a deeper shift than the traditional stolen credentials we have managed for years?
A stolen password or a phished credential is essentially a tool used to circumvent a security control, which the system can eventually recognize as a breach. However, a convincing deepfake is fundamentally different because it appears to satisfy the security control rather than bypassing it. From the system’s perspective, nothing has malfunctioned because it receives exactly the evidence it was designed to assess—a valid-looking face or voice—and it reaches the wrong conclusion based on that “correct” data. This means a valid-looking credential is no longer enough to ensure security in our current environment. We must move toward a model that determines whether the evidence is physically connected to a real person, whether that identity is trusted, and whether they have the specific authorization for the action they are attempting.
For many years, the industry’s goal was to make verification “invisible” to reduce friction for the user. In retrospect, how did this ambition contribute to the vulnerabilities we are seeing today?
The ambition to reduce friction was well-intentioned because security doesn’t actually improve when employees spend their entire morning struggling with complex authentication screens. However, in our rush to make the experience seamless, we sometimes removed the very evidence that connects an access decision to a genuine person. We created systems where tokens are passed between applications and credentials are replayed automatically, often leaving the organization with zero assurance about who was actually behind the decision. This mistake is now being exposed by synthetic identities and deepfakes that thrive in those invisible gaps. Our challenge in 2026 is to restore that verifiable evidence and link it back to a human being without reintroducing the complexity that originally drove the push for invisible security.
Biometrics are central to your proposed solution, yet they frequently cause concern among privacy advocates. How can organizations implement these systems while addressing the fear of centralized biometric databases?
The fear is entirely justified because a centralized database containing poorly protected biometric data creates a massive “honeypot” for hackers and increases the risk of permanent identity misuse. Unlike a password, biometrics cannot be replaced once they are compromised, which is why we must move toward a decentralized model. In this architecture, an individual’s biometric reference remains securely stored on their own phone, and the matching process takes place locally under the user’s control. The organization never receives or retains a copy of the person’s face; instead, it receives a secure confirmation that the authorized user has authenticated using a trusted device. This approach, combined with selective disclosure, allows people to prove who they are without repeatedly sharing their complete identity record with every system they touch.
Europe has introduced significant regulations like the AI Act, NIS2, and eIDAS 2.0 to reshape cybersecurity. How effective will these be in resolving the impersonation crisis on their own?
These regulations are a significant step in the right direction because they move us toward accountable systems and verifiable identity, but they are not a silver bullet. The Cyber Resilience Act and NIS2 reinforce risk management and lifecycle obligations, while eIDAS 2.0 advances identity that can be used across services. However, the danger lies in organizations treating compliance as a simple checklist to be completed for an audit. A security program can pass every regulatory audit while still leaving massive architectural weaknesses unresolved if the systems remain isolated. Regulation can establish the expectations of society and the law, but it cannot design a company’s specific identity architecture or ensure that their internal systems are properly connected.
As we look at the immediate future of access management, what is the next major category of identities that security leaders are currently unprepared to handle?
The next major wave of identities requesting access to our corporate systems will not always be human, as AI agents are already beginning to interact with software and complete transactions on behalf of users. Almost every security protocol we have built over the last five decades assumes that a person is directly operating the device or the application at the other end. We urgently need frameworks that use verifiable digital credentials to connect these AI agents to a trusted person or organization. These credentials must provide clear evidence of the specific authority the agent has been granted to act on a human’s behalf. AI agents are arriving in the workplace much faster than the governance frameworks needed to control them, creating a new and dangerous gap in our defense.
You’ve pointed out that attackers often target the “seams” between otherwise strong security controls. Where are these gaps most commonly found in a typical corporate structure?
Fraud frequently succeeds at the handoffs where one system enrolls a person, another verifies their identity, and a third controls their physical or digital access. These seams are most visible during the “identity reconstruction” process—when a credential is lost and the system falls back on weaker evidence than what was initially required to set up the account. Attackers look specifically for these moments of transition because that is where the chain of trust is most likely to be broken. The only real answer is continuity, where a person’s identity is established once with a high level of assurance and then bound to secure credentials that are used across all environments. We need to move away from fragmented systems and toward a continuous identity lifecycle where trust is maintained rather than repeatedly re-proven.
In many organizations, physical security and cybersecurity are still treated as entirely separate departments. Why is this division no longer tenable in the face of modern threats?
Attackers do not recognize the arbitrary division between physical and digital access; they see one unified attack surface. A compromised digital identity can have immediate physical consequences, just as a poorly controlled physical recovery process can be used to undermine digital security across the entire network. If these systems do not share a coherent and interoperable view of the user, an adversary will simply target the weakest point in the disconnected chain. The goal shouldn’t necessarily be to put every single system on one platform, but to create a continuous chain of trust where physical security, cybersecurity, and fraud teams are all part of the same conversation. Organizations that continue to divide these responsibilities are essentially providing their adversaries with easy gaps to exploit.
What is your forecast for the evolution of trust in the digital workplace?
In the coming years, we will see identity move from being a peripheral security concern to becoming the core infrastructure upon which all digital and physical actions are built. We will transition away from static authentication toward a model of continuous assurance, where the distinction between proving who you are and performing a task begins to disappear. I expect that by 2028, the most resilient organizations will have completely eliminated “trivia-based” recovery methods, replacing them with decentralized biometrics that protect privacy while providing absolute certainty. The companies that survive the next wave of AI-driven attacks will be those that have successfully unified their view of identity, ensuring that every action—whether performed by a human or an AI agent—is genuine, trusted, and authorized. The era of “seeing is believing” is over, and the era of “verifiable trust” is just beginning.

