Digital Trust at the Crossroads of Technology and Security

Author: Ayom Mratita Purbandani
Editor: Achmed Faiz Siregar

The expeditious digital revolution has not only transformed the way things work, but has also rewritten the rules of cybersecurity. Entry points for cyberattacks have become increasingly complex and diverse. Something as simple as clicking a link or downloading a file can now turn anyone into a victim of cybercrime. Cybersecurity has evolved far beyond the issue of data breaches alone. It now directly affects public trust. When systems fail, the impact does not stop at devices or networks; it spills into everyday life, delayed transactions, disrupted services, and, ultimately, eroded trust.

For users, perception is often just as important as technical reality. Systems that appear “unsafe” are quickly abandoned, even if they have never experienced an actual breach. Goode Intelligence has described 2025 as a critical year for digital trust.[1] With the proliferation of social media platforms, digital payment systems, and essential digital services, most people struggle to keep track of where their personal information is stored online. The rapid expansion of artificial intelligence (AI) has further complicated the landscape, posing significant challenges for identity verification systems. Data from the UK’s fraud prevention services shows that in 2025 there was an increase in both the number of fraud cases and total financial losses, at least 17 percent higher than in 2024.[2]

For years, many organisations and electronic service providers relied on reactive security approaches. Vulnerabilities were patched after incidents occurred. Systems were updated only once problems surfaced. This approach is no longer sufficient. Threats move faster than security patches. In this context, users have become more mature and critical. The misuse of personal data can be just as damaging as direct financial loss. Once trust is broken, it is difficult to rebuild. Today’s cyber threats are volatile. Data and access move across devices, locations, and platforms. As a result, many organsations now recognize that security can no longer be treated as an afterthought. It must be designed from the outset and embedded throughout the technology supply chain.

Trust begins with security

Trust in the safety, reliability, and transparency of technology, platforms, and organsations is a foundational element of the digital ecosystem. As users become more deeply embedded in digital life, their ability to control data and navigate digital spaces without fear or hesitation becomes a precondition for meaningful participation. In identity-dependent digital ecosystems, digital identity functions as the primary gateway. The 17 percent increase in fraud cases is not merely a criminal statistic; it reflects systemic failures in protecting users’ digital identities.[3]

Systems that are technically secure but opaque in how they manage data are still perceived as risky. When users do not understand how their data is collected, used, or protected, trust weakens. In this sense, security is not only a technical matter, but also one of governance and accountability.

An important insight is captured in a 2025 YouGov report, which shows that 66 percent of consumers view the performance of digital transactions as a key indicator of digital trust.[4] Without trust, the potential of digital transformation will remain unexploited. Users will only engage actively in digital environments if they believe the benefits outweigh the risks. When security fails, the consequences are far-reaching: incident response costs rise, technology adoption slows, and organisational reputations suffer. These losses often far exceed the financial damage caused by a single security incident.

Trust is also closely linked to power. Security serves as a balancing mechanism for power in digital spaces. In many digital services, electronic service providers hold far greater information and control than users. Without adequate security, this imbalance creates opportunities for data misuse, unilateral decision-making, and practices that disadvantage users.[5] In this context, security is not merely technical protection, it is an institutional signal that providers recognise risks and take responsibility for their consequences.

IDV as the central pillar

The role of security becomes even more critical in the context of digital identity. Much like in the physical world, digital identity is the key to accessing services, conducting transactions, and participating in digital life. Without confidence that identities and data are properly protected, users tend to limit their digital interactions. Security, therefore, can no longer focus solely on defending systems from external attacks. It must also ensure that identities are verified accurately and continuously. Without strong identity mechanisms, fraud prevention efforts will always lag behind perpetrators.

Research consistently shows that most cybercrime incidents are not caused by technological failure alone, but by failures in identity verification (IDV).[6] Account takeovers and manipulated authentication processes are among the primary entry points for cybercrime. As a result, system security depends heavily on the ability to recognise legitimate users and deny access to unauthorised actors.

Several IDV mechanisms have been developed to address this challenge. Knowledge-based credentials, such as passwords and PINs, remain widely used but are highly vulnerable to theft and human error.[7] Possession-based factors, such as cards, tokens, or devices, offer additional layers of protection, yet they can still be lost or transferred.[8]

Biometric mechanisms have emerged as the most relevant solution in 2025, reaching the highest adoption levels in their history.[9] Unlike other methods, biometrics link identity directly to an individual’s physical or behavioral characteristics. Their implementation is driven not only by market demand but also by regulatory intervention. In the European Union, for example, the rollout of the European Digital Identity Wallet under the revised Electronic Identification, Authentication and Trust Services (eIDAS) framework allows citizens to securely store and use official identity credentials across borders.

Other jurisdictions have begun regulating biometric data protection and the use of digital identity in financial and public services. Big tech companies such as Google and Apple have also announced support for digital identity credentials in mobile wallets.[10] Their involvement promises mass adoption, although it also reshapes the identity ecosystem. Despite differing approaches, the direction is clear: digital identity is increasingly positioned as a critical trust infrastructure.

Nevertheless, biometrics are not a standalone solution. Due to their sensitive and irreplaceable nature, biometric systems must be combined with other safeguards, such as multi-factor authentication and robust data governance. Ultimately, cybersecurity is not about building the most advanced systems possible. It is about building trust that can endure amid digital uncertainty. This requires a shift in mindset. Security is not merely a cost center, it is a strategic asset. As 2026 approaches, the roles of states, regulators, and big tech in the digital identity ecosystem will be decisive in shaping the future of digital trust. Trust can only grow when security and rights protection are designed in an integrated and responsible manner.


  1. Biometric Update. (2025, November 16). 2025 Digital Identity Verification Market Report and Buyers Guide. BiometricUpdate.com. Retrieved from https://www.biometricupdate.com/2025-digital-identity-verification-market-report-and-buyers-guide ↑
  2. UK Finance. (2025, October 24). Half year fraud report 2025. UK Finance. https://www.ukfinance.org.uk/policy-and-guidance/reports-and-publications/half-year-fraud-report-2025 ↑
  3. Ibid. ↑
  4. YouGov (2025). Trust in the Digital Economy 2025. https://www.checkout.com/guides-and-reports/digital-economy-report ↑
  5. Christmann, Robin & Rösch, Jürgen, 2025. “Platforms, information asymmetry and leakage: why disintermediation may not hurt (so much) after all,” MPRA Paper 126803, University Library of Munich, Germany. ↑
  6. Shufti. (2025). The critical 1%: Closing systemic gaps in global identity verification [White paper]. ShuftiPro. ↑
  7. Jenkins, M. (2024, January 18). From KBA to MFA: Why knowledge-based authentication is out. Crowe Cyber Watch. ↑
  8. Liu, F. (2025, December 9). The Secure Sign-in Trends Report 2025: An inside look at MFA adoption and the authenticators that influence it [Report]. Okta. ↑
  9. Potential. (2025). EU Digital Identity Wallet. https://www.digital-identity-wallet.eu/ ↑
  10. Delitz, V. (2025, June 17). Digital credentials & payments: Apple vs. Google Wallet strategy. Corbado. ↑