NCSC Annual Review 2025
Looking back at the National Cyber Security Centre's ninth year and its key developments and highlights, between 1 September 2024 and 31 August 2025.
Pages
Page 26 of 32
The future of digital identity

Why digital identity is fundamental to supporting the transformation of the UK’s ‘digital-first’ services.
Many aspects of our lives are increasingly conducted digitally to benefit from the speed and convenience this can provide. Everything from keeping in touch with friends and family, to shopping and banking, to renting or buying a property, to enrolling in university or starting a job, to managing long‑term pension and healthcare choices.
Adding to this, the COVID‑19 pandemic triggered a rapid acceleration of digitisation across many sectors, proving that previously in‑person and paper‑based services could be moved online to get these same benefits. In the years since, this continued digitisation of services has only increased the importance of having an effective ‘digital identity’ architecture that underpins them. This architecture needs to be easy enough to use whilst also strong enough to protect the privacy and provide the security that’s required for people accessing all these services.
The future of digital identity is developing rapidly, but it is already clear that usability, privacy, and security will need to be balanced at the heart of it.
Before we go any further, it’s useful to clarify what we mean by ‘digital identity’. It can be described as a digital representation of a set of verified attributes, derived attributes and properties. With this representation, digital systems can use necessary attributes and properties during their decision-making. For example, a business being able to check if someone is over the age of 18 according to a mutually trusted source:
Date of Birth/Age
- attribute - Date of Birth: 2008-Feb-29
- derived attributes - Over 13: True; Over 15: True; Over 16: True; Over 18: False
- properties - Issued by: General Register Office, (HMPO) Issue date: 2024-Mar-04
Whilst the most common form of digital identity that we talk about is for a person, an identity can also apply to other entities, such as:
- a group, such as ‘Occupier(s) of 32 Windsor Gardens’ for proof‑of‑address, e.g. registering for the Electoral Register and accessing household streaming services
- an organisation, such as ‘The Winchester’ for proof‑of‑certification, e.g. VAT registration and business licence
- a device, such as ‘Personal smartphone’, ‘Family tablet’ and ‘Work laptop’ to help establish trust and feed into a decision, e.g. making repeated payments from the same device
- a place, such as ‘Home’, ‘School’, and Work’ to help feed into a decision, e.g. making a request from a recognised or explicitly trusted location.
Note that a digital identity should uniquely represent one entity, allowing a digital system to differentiate and address this entity from all others of its kind. A digital identity will be as complex as required, from a simple set that only comprises a unique username or account ID (such as on a personal membership), to a comprehensive set containing enough personal data to match an individual physical, natural‑world identity (such as for meeting ‘Know Your Customer’ requirements).
Digital identities are already improving lives worldwide. Countries like Estonia, Sweden, and Singapore are already using them to improve access to public and private services. However, not all digital identities are equal; one may let you buy something from a shop, another may let you open a bank account, and another may help you vote or access healthcare. What is clear is that digital identities can work, and their benefits are already apparent.
Digital identity: underpinning the UK’s digital services
Across a number of sectors, digital identity is a foundational building block in the ‘digital‑first’ transformation that promises a faster, smoother, and more secure future, including:
-
Defence:
The Strategic Defence Review 2025 highlights that ‘data and digital systems are the fundamental underpinnings of all modern military capabilities’.
-
Government:
DSIT’s Blueprint for modern digital government defines ‘a digital‑first operating model’, including the One Login and Digital Wallet services that can support the Digital ID scheme that will be mandatory for Right to Work checks and enable more personalised interactions with public services through the GOV.UK app.
-
Healthcare:
NHS Digital has set out a ‘nationally agreed approach to identity management’ to encourage greater use of digitised health and care services accessible through NHS login and the NHS App.
-
Education:
some universities such as Sheffield are beginning to issue signed transcripts to allow graduates to prove their qualifications.
As this pace of change continues, the ability of digital systems to make accurate decisions - for example, confirming the coordinates of an entity so supplies can be airdropped - is more important than ever. In such scenarios, gathering enough confidence and trust in a digital identity is crucial. Looking ahead, further transformations including artificial intelligence and digital assistants are promising to make decisions at line‑speed on behalf of its user.
Digital identity systems have the potential to be more difficult for attackers to compromise than traditional identity systems, if they are designed and implemented correctly. Naturally the increased use of digital identities attracts increased interest from threat actors, looking to take advantage of weaknesses for their own gains. Attackers of all capabilities are pivoting away from targeting individual devices in favour of targeting user identity. For example, impersonating a user on helpdesk calls to reset an identity’s access credentials , or phishing for valid access credentials from an online identity provider to access its connected services.
Attackers are also quick in adopting novel technology to aid them, including the use of AI in the creation of ‘deepfake’ video and audio that be used for impersonation attacks, or to falsify identity documents that can pass weak examination and identity checks. Adding to this, the continuing trend in data breaches means the amount of ‘secret answer’ information that can be used to securely verify an identity (such as previous addresses, schools, and personal reference numbers) is diminishing.
All this to say that robust digital identity underpins the fundamental aspects of a modern and future‑looking society.
The fundamentals of future‑ready digital identities
At a high level, the challenges and problems of building a robust digital identity ecosystem breaks down into four core areas:
- registration
- authentication
- management
- secure channels
When building such a system, it must be determined what attributes and properties must be collected and verified to meet current and projected future requirements. However, it must be noted that only the necessary and sufficient information for the current usage is gathered and stored securely to meet privacy and data protection requirements.
Registration
When a new entity ‘enrols in’ or is ‘onboarded onto’ a system, the system must create an identity that it can assign to that entity. This assignment is built and registered by the system in a data store such as a User Directory or Device Management database.
The registration phase is the most security critical since it establishes the initial trust relationship and sets the foundation for all future trust between the system and the entity. It is not possible to add trust in an entity after registration, without relying on trust established during registration. When designing registration mechanisms, the following are important to consider:
- How effectively must and can we verify these attributes and properties? How might this change in the future?
- How long should these attributes and properties be treated as valid for, before they must/should be re‑verified?
Modern solutions for authentication rely on the assumption that everyone owns a device capable of supporting modern cryptography.
A digital identity is most commonly used to represent a user of a system, either one ‘natural person’ or a group of people that are safe to appear as one to the system. When registering a personal digital identity, such as an employee or customer, a system needs to perform the necessary verification of the identity’s properties and attributes. Knowing what exactly constitutes ‘necessary’ is a significant challenge, as it depends on the needs and sensitivity of the system. Unfortunately, this means that there isn’t one universal digital identity architecture that can work out‑of‑the‑box for all systems.
A digital identity future will include the challenge of sufficiently strengthening the processes for verifying digital sources of trust where we currently use physical (i.e. natural‑world) ones. For example, building and scaling the processes that can provide the digital equivalent of checking the holograms and photographs of a UK passport or driving licence documents to detect the presentation of falsified identity attributes.
With digital identity, cryptographic verification and a digital web of trust can be used to meet this, and unlock even more opportunities. However, this must all be done without also infringing on privacy protections and unacceptably increasing the risk of fraudulent registration. One architecture for this is already being built out in the UK digital identity and attributes trust framework.
An important challenge in personal digital identity is making sure the ways we request and verify identity are as inclusive as possible. For example, an estimated one in twenty UK adults don’t own a personal smartphone, and some people with disabilities are unable to use them. In any registration process, it is critical that the identity verification methods used are fit for all users that will be required to use them. This often means offering multiple methods and allowing users to opt in to that which is most agreeable to them.
Recall, digital identities are not only for people; there are also systems where registration of other kinds of entities or assets is needed. Depending on the system, this can be anything from registering the identity of an aircraft carrier to avoid friendly fire, down to the identity of a wearable device like a smartwatch or pair of smart glasses that is trying to access personal data. Whilst registering a Royal Navy aircraft carrier seems relatively easy (there’s two of them and they’re quite distinctive), this process gets much more challenging for the likes of cars and drones and phones that have much greater numbers and whose ownership and integrity are much harder to verify.
Authentication
When an entity returns to a system claiming to be already registered, the system must discern if it is the same entity that was previously onboarded. In this workflow, we don’t want to completely re‑verify the identity every time they knock on the system’s virtual front‑door, so we try to prove (‘authenticate’) to a high‑enough level of assurance that it really is the same entity, using a digital, often remote, challenge. This challenge uses a combination of digitised attributes and their properties, captured during registration, that only the ‘authentic’ entity should be able to complete. If the challenge of authentication is not strong enough, it provides a weakness that an attacker can exploit to gain unauthorised access.
In digital systems, this authentication needs to provide strong enough assurance to the service for it to accept the risk of allowing access. Increasingly, modern solutions for strong authentication are available that make better use of modern device hardware that includes secure elements with cryptographic modules.
These modern solutions use the capabilities of digital technology to handle a digital problem. A perfect example of this is passkeys and their use of a trusted device’s secure element and local authentication hardware to handle the complex cryptography and digital exchanges, providing a more secure and easier authentication process by only placing burden on the user when their choice and approval is required.
Modern, digital solutions for authentication can offer speed and security over traditional means, but they often rely on the assumption that everyone owns a device capable of supporting modern cryptography. If this assumption is not actively addressed or resolved, we risk people being left behind, or being unfairly placed at greater risk than those who do.
Management of a digital identity
As with a physical, natural‑world identity, while some aspects of a digital identity are not expected to change (such as a person’s confirmed Date of Birth), some aspects may change to a significant extent. For example:
- change of legal name or chosen username
- change of a contact and/or residence address
- change of payment details or financial account information
- change in biometric features
- reset of a forgotten password or replacement of lost passkey
This means that digital identities need management and maintenance to remain accurate and useful. Digital identities provide the benefit that the records of their attributes and properties are comparably easier and faster to create and update than paper‑based records. For example, being able to confirm your address using an existing digital contract agreement, avoiding the need to wait for a letter to arrive in the post. However, this relies on strongly authenticating the request to change an identity record to verify its legitimacy, and then verifying the accuracy of the requested change before completing this process. With the relative ease and speed of changes also comes the drawback that mismanagement (accidental or intentional) can also cause greater harm. This must be risk managed in the future digital identity architecture being built.
This includes making it known, where beneficial, that one or more attributes or properties of an identity have changed. This requires a communication framework that makes it secure and easy enough for a person to tell a service about a change. This can also include the option for this service to tell other related services of the change to inform their security decision making. A good demonstration of this is the UK government’s ‘Tell Us Once’ service, which can simultaneously notify relevant services of a change in an identity’s circumstances after it has been verified.
Secure channels
Registration, authentication, and management of digital identities require trusted digital communication channels. These cover communication between the entity and the verifier, and in modern systems, between a verifier and other verifiers. For example, a job applicant sharing necessary identity attributes with a prospective employer, and the prospective employer who is verifying these attributes to confirm the applicant’s right to work and authenticity/validity of their claimed qualifications.
For the vast majority of people and public services, the communication protocols used in commodity devices and services are ‘secure enough’ against today’s threats, and they have demonstrated that they can develop quickly enough to keep up with the latest best practices.
In spaces like military and critical national infrastructure systems, many use cases are more complex, and the effort attackers might use to undermine the security of these communications is significantly higher. This requires commensurately stronger confidence around the identity of each entity involved in these communications and their attributes, including how securely they can create, process, and store the communications that they will receive and transmit as part of these systems.
What is the NCSC doing
Robust digital identity is a long‑term problem with a lot of moving parts. Within the defence sector, this is a multi‑decade problem where systems and platforms commissioned now will be in service in 2050 and beyond. The NCSC’s Crypt‑Key mission is providing solutions to defence now, and is working in partnership to understand and meet the perceived future needs of these systems.
In wider UK public sector applications, the NCSC is working with DSIT on supporting better registration and on‑boarding processes, through the issuing and use of digital credentials from the GOV.UK Wallet. This is part of a longer‑term strategy to demonstrate the value that digital identities and trust verification can unlock in solving challenges across UK society.
To improve the security of authentication, the NCSC are working with DSIT and the FIDO Alliance on improving the adoption of passkeys across the public and private sectors. Accelerating the UK adoption of passkeys means we can migrate people off passwords and weak MFA methods, onto something that is more secure and makes interacting with companies and government more seamless.
And finally, the NCSC’s work on advanced cryptography makes us the expert on where novel cryptography can help solve a problem within digital identity, such as by being able to securely enough prove that a person is eligible for a service without unnecessarily revealing other attributes about themselves.