Skip to main content
Annual Review

NCSC Annual Review 2025

Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.

Page 26 of 32

The future of digital identity

Why digital identity is fundamental to supporting the transformation of the UK’s ‘digital-first’ services.

Many aspects of our lives are increasingly conducted digitally to benefit from the speed and convenience this can provide. Everything from keeping in touch with friends and family, to shopping and banking, to renting or buying a property, to enrolling in university or starting a job, to managing long‑term pension and healthcare choices.

Adding to this, the COVID‑19 pandemic triggered a rapid acceleration of digitisation across many sectors, proving that previously in‑person and paper‑based services could be moved online to get these same benefits. In the years since, this continued digitisation of services has only increased the importance of having an effective ‘digital identity’ architecture that underpins them. This architecture needs to be easy enough to use whilst also strong enough to protect the privacy and provide the security that’s required for people accessing all these services.

The future of digital identity is developing rapidly, but it is already clear that usability, privacy, and security will need to be balanced at the heart of it.

Before we go any further, it’s useful to clarify what we mean by ‘digital identity’. It can be described as a digital representation of a set of verified attributes, derived attributes and properties. With this representation, digital systems can use necessary attributes and properties during their decision-making. For example, a business being able to check if someone is over the age of 18 according to a mutually trusted source:

Date of Birth/Age

  • attribute - Date of Birth: 2008-Feb-29 
  • derived attributes - Over 13: True; Over 15: True; Over 16: True; Over 18: False 
  • properties - Issued by: General Register Office, (HMPO) Issue date: 2024-Mar-04

Whilst the most common form of digital identity that we talk about is for a person, an identity can also apply to other entities, such as:

  • a group, such as ‘Occupier(s) of 32 Windsor Gardens’ for proof‑of‑address, e.g. registering for the Electoral Register and accessing household streaming services
  • an organisation, such as ‘The Winchester’ for proof‑of‑certification, e.g. VAT registration and business licence
  • a device, such as ‘Personal smartphone’, ‘Family tablet’ and ‘Work laptop’ to help establish trust and feed into a decision, e.g. making repeated payments from the same device
  • a place, such as ‘Home’, ‘School’, and Work’ to help feed into a decision, e.g. making a request from a recognised or explicitly trusted location.

Note that a digital identity should uniquely represent one entity, allowing a digital system to differentiate and address this entity from all others of its kind. A digital identity will be as complex as required, from a simple set that only comprises a unique username or account ID (such as on a personal membership), to a comprehensive set containing enough personal data to match an individual physical, natural‑world identity (such as for meeting ‘Know Your Customer’ requirements).

Digital identities are already improving lives worldwide. Countries like Estonia, Sweden, and Singapore are already using them to improve access to public and private services. However, not all digital identities are equal; one may let you buy something from a shop, another may let you open a bank account, and another may help you vote or access healthcare. What is clear is that digital identities can work, and their benefits are already apparent.


As this pace of change continues, the ability of digital systems to make accurate decisions - for example, confirming the coordinates of an entity so supplies can be airdropped - is more important than ever. In such scenarios, gathering enough confidence and trust in a digital identity is crucial. Looking ahead, further transformations including artificial intelligence and digital assistants are promising to make decisions at line‑speed on behalf of its user.

Digital identity systems have the potential to be more difficult for attackers to compromise than traditional identity systems, if they are designed and implemented correctly. Naturally the increased use of digital identities attracts increased interest from threat actors, looking to take advantage of weaknesses for their own gains. Attackers of all capabilities are pivoting away from targeting individual devices in favour of targeting user identity. For example, impersonating a user on helpdesk calls to reset an identity’s access credentials , or phishing for valid access credentials from an online identity provider to access its connected services.

Attackers are also quick in adopting novel technology to aid them, including the use of AI in the creation of ‘deepfake’ video and audio that be used for impersonation attacks, or to falsify identity documents that can pass weak examination and identity checks. Adding to this, the continuing trend in data breaches means the amount of ‘secret answer’ information that can be used to securely verify an identity (such as previous addresses, schools, and personal reference numbers) is diminishing.

All this to say that robust digital identity underpins the fundamental aspects of a modern and future‑looking society.



Published

Reviewed

Version

1.0