Identity and authentication

SMART Access & Identity 2025 Access Control & Identity Management, Information Security, Security Services & Risk Management

Identity authentication is a crucial aspect of both physical and cybersecurity. In this feature, SMART Security Solutions asks three companies for insight into the latest developments.

Identity management and authentication have always played a crucial role in security, ensuring that only authorised individuals can enter a building or access digital assets. Adding the myriad cloud computing and general internet services available to businesses and individuals today, only serves to exacerbate the challenge of knowing who you are dealing with and transacting with.

The importance of identity management (IDM) and identity authentication (IDA) has further escalated due to the rise in crime in both physical and digital realms, as well as the increasing use of artificial intelligence (AI) to bypass the security measures that companies implement.

IDA is not only a business issue, as individuals are victims of fraud and various crimes when they, or the companies they trust, lose sensitive information. The POPIA Act in South Africa was developed to safeguard sensitive information. Still, the Information Regulator only gets involved once the damage is done, and no matter how steep the sanctions may be, the information that should have been protected is out in the wild and accounts and identities are compromised.

Everyone has been and is subjected to some form of identity authentication, especially those who bank online or set up passwords for other online or mobile services. Put simply, IDA is similar to a digital handshake that confirms you are who you say you are – and this is where the risk comes into play.

The most common IDA mechanism is the much-abused password. Some (old) measures to improve security involved asking preset questions that only the real user would supposedly know (your dog’s name, for example). Naturally the additional security provided by a set of questions is, to be polite, questionable.

More recently, biometrics became popular as they combine convenience with additional security, especially when transacting on mobile devices. But there are still security and user issues with biometrics, which led to the introduction of two-factor authentication (2FA) and multi-factor authentication (MFA), combining something you know (like a password) with something you have (like a phone) and/or something you are (biometrics).

In this year’s handbook, SMART Security Solutions asked three companies involved in the identity market to expand on the progress and challenges of IDM and IDA, and how they are addressing the market. To avoid including all the responses in an excessively long and complex article, we split the answers into separate articles which follow this introduction, one of which will be online due to space restrictions.

The FIDO Alliance

This feature refers to the FIDO Alliance. We include this brief explanation for anyone unfamiliar with the organisation’s work.

The FIDO Alliance is an open industry association focused on reducing the world’s reliance on passwords. To accomplish this, the FIDO Alliance promotes developing, using, and complying with authentication and device attestation standards.

The FIDO Alliance aims to change the nature of authentication with open standards for phishing-resistant sign-ins with passkeys that are more secure than passwords and SMS OTPs, simpler for consumers and employees to use, and easier for service providers to deploy and manage. The alliance also provides standards for secure device onboarding to ensure the security and efficiency of connected devices operating in cloud and IoT environments.

The FIDO Alliance currently has published three sets of user authentication specifications for simpler, stronger authentication: FIDO Universal Second Factor (FIDO U2F), FIDO Universal Authentication Framework (FIDO UAF) and FIDO2, which includes the W3C’s Web Authentication (WebAuthn) specification and FIDO Client to Authenticator Protocol (CTAP). The alliance also has a specification for secure onboarding of edge and IoT devices (FDO). The specifications are open and free

for global use. Find out more about the FIDO Alliance at https://fidoalliance.org/

Links to the articles

Federated identity orchestration.

Managing identities for 20 years.

Balancing security and ease-of-use.


Credit(s)





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Corporate and academic teams can register for Kaspersky contest
Kaspersky News & Events Information Security
Kaspersky has announced the registration opening for its new Kaspersky{CTF} (Capture the Flag) competition, inviting academic and corporate teams from around the globe to compete in a battle of skill, strategy and innovation.

Read more...
Secure, touchless access control
Access Control & Identity Management Products & Solutions Commercial (Industry)
Invixium has joined forces with SAP to deliver a touchless access control experience for the S.Mart Store, SAP’s first fully automated, 24/7 self-service retail outlet, located at its global headquarters in Walldorf, Germany.

Read more...
Continuous security optimisation.
News & Events Information Security
Cymulate has announced its partnership with SentinelOne, a threat exposure validation and AI-powered cybersecurity platform. The collaboration delivers self-healing endpoint security that empowers businesses to increase protection for every endpoint on their network.

Read more...
Protect your smart home devices
Kaspersky IoT & Automation Information Security Smart Home Automation
Voice assistants, kitchen robots, smart lights and many other intelligent devices have become part of our everyday life. However, with the rise of smart technology comes the need for robust protection against potential vulnerabilities.

Read more...
ISPA’s take-down process protects from local scams
News & Events Information Security
During the recent school holidays, parents could rest a little easier knowing that ISPA, SA’s official internet industry representative body, is removing an average of three to four problematic websites from the local internet every week.

Read more...
The power of PKI and private sector innovation
Access Control & Identity Management News & Events Government and Parastatal (Industry)
At the recent ID4Africa 2025 Summit in Addis Ababa, the spotlight was firmly on building secure, inclusive, and scalable digital identity ecosystems for the African continent.

Read more...
Biometric security key for phishing-resistant MFA
Products & Solutions Access Control & Identity Management
New FIDO-compliant USB, Bluetooth, and NFC BioKeys with biometric login and centralised management for phishing-resistant, passwordless multifactor authentication (MFA) for enterprise users.

Read more...
SA’s strained, loadshedding-prone grid faces cyberthreats
Power Management Information Security
South Africa’s energy sector, already battered by decades of underinvestment and loadshedding, faces another escalating crisis; a wave of cyberthreats that could turn disruptions into catastrophic failures. Attacks are already happening internationally.

Read more...
Almost 50% of companies choose to pay the ransom
News & Events Information Security
This year’s Sophos State of Ransomware 2025 report found that nearly 50% of companies paid the ransom to get their data back, the second-highest rate of ransom payment for ransom demands in six years.

Read more...
Gallagher Security releases OneLink
Gallagher Animal Management Products & Solutions Access Control & Identity Management
Gallagher Security has announced OneLink, a cloud-based solution that makes it faster, easier and more cost-effective to deploy security anywhere in the world, transforming how security can be delivered to remote sites and distributed infrastructure.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.