Skip to content

Biometrics and identity

The biometric security ecosystem: who's protecting your systems and who isn't.

Biometric identity systems don’t exist in isolation. They are shaped by a complex ecosystem of actors, each with different capabilities, different incentives, and different relationships to your security. Understanding who they are, what they do, and what they don’t do is the first step to making well-informed decisions about your systems.

Six actors. Related interests. Very different motivations.

The security and performance of any biometric is influenced by more than the technology itself. It is shaped by the organisations that build it, the bodies that regulate it, the institutions that certify it, the researchers who study it, the testers who challenge it, and the threat actors who are constantly trying to attack it.

Each of these actors operates with distinct motivations. Some are aligned with your outcomes. Some are not. Understanding the difference matters.

The six actors

1. Hackers and threat actors

What they do

Hackers continuously develop and refine methods to exploit vulnerabilities in biometric and identity systems. They synthesise fraudulent data, coordinate automated attacks, and share techniques across organised criminal networks. Their tools evolve in line with technology, including deepfakes, virtual cameras and AI-generated identity documents, and they do not wait for systems to catch up.

What they don’t do

Care about your reputation, your compliance status, or the downstream consequences of a breach. A compromised system is an opportunity.

Why this matters

The threat is not static. Hackers innovate when they fail. Every time a defence holds, they innovate. The question is not whether attacks will happen, but whether your systems are tested against the methods being used today, tomorrow and beyond.

2. Biometric technology vendors

What they do

Vendors design and develop the technical infrastructure that makes biometric identity systems possible, including the software, algorithms, and platforms that organisations deploy. The best vendors invest in security, continuously update their products, and take compliance seriously.

What they don’t do

Operate as a neutral, independent authority on their own products’ performance. Vendors have a commercial interest in the systems they sell. Their testing is done in conditions they control, against benchmarks they set, and reported in ways that serve their sales cycle. That is not a criticism, it is simply how commercial incentives work.

Why this matters

Vendor assurance and independent assurance are not the same thing. Knowing the difference, and insisting on both, is what separates organisations that manage risk from those that assume it.

3. Regulators, standards bodies, and policy makers

What they do

Regulators and standards bodies establish the frameworks within which identity systems must operate. They set minimum thresholds, define testing requirements, and create the policy environment that shapes the market. Standards such as CEN/TS 18099 and ISO/IEC 30107 provide the reference points against which systems and testing methodologies are evaluated.

What they don’t do

Actively protect individual organisations from attack, or account for threat vectors that emerge after a standard was written or revised. Whilst standards vary in what they define, in and of themselves they do not guarantee resilience against what hackers are doing today.

Why this matters

Regulatory compliance is necessary but on it’s own, may not be sufficient. The most consequential attacks exploit the gap between what standards mandate and what threat actors are currently capable of.

4. Auditors, certification and accreditation bodies

What they do

Auditors at Certification Bodies assess whether organisations and systems meet defined standards and frameworks. Accreditation bodies accredit laboratories and validate that testing methodologies conform to recognised criteria. Both play an important role in establishing market-wide benchmarks for quality and accountability.

What they don’t do

Conduct the kind of active, adversarial testing that reveals real-world vulnerabilities. Audits are typically process-based. They verify that procedures exist and are followed. They are not the same as putting a system under live attack conditions.

Why this matters

A successful audit confirms good practice. It does not confirm that your systems will hold under the methods a sophisticated attacker would use today. Auditing and testing by laboratories serve different purposes, and both are needed.

5. Academia and research institutions

What they do

Academic institutions and independent researchers advance the scientific understanding of biometric and identity security, developing new methodologies, studying emerging threats, and publishing findings that inform standards, testing practices, and technology development. Research communities are often the first to identify new classes of vulnerability, sometimes years before they appear in commercial attack tools.

What they don’t do

What academic institutions add in terms of deep research and advancing the scientific field is not necessarily matched in speed and deployment that buyers and vendors require for commercial scale testing that meet the needs of their stakeholders. They also require rapid deployment of new testing methods that keep pace with technological advances.

Why this matters

The gap between research and practice is where risks are born. Organisations that partner with academic institutions, and testing labs that invest in those relationships, access threat intelligence that is not yet visible in the commercial market, meaning emerging threats can be managed as early as possible.

6. Independent testing labs

What they do

Independent testing labs evaluate how biometric and identity systems actually perform: under real-world conditions, against current attack methods, using reproducible scientific methodology, based on standards and industry best practice. They sit outside the vendor relationship, separate to the certification process, and the standards-writing cycle. Their only function is to find out whether a system does what it is supposed to do.

What they don’t do

Have a commercial interest and therefore a conflict in the outcome of testing. Truly independent labs do not sell the technology they test. They derive no benefit from a system passing or failing. That independence is the source of its value.

Why this matters

In an ecosystem where every other actor has a stake in the outcome, independent testing is the mechanism through which objective evidence is produced. It is the difference between being told a system is secure and knowing it.

Ingenium – Independent and invested in protecting your objectives

Independent by design.

Ingenium is an independent biometric and identity testing laboratory. We do not build or sell identity technology. We do not certify systems or issue compliance documentation. We test.

That independence is structural, but staying ahead of the threat landscape requires more than neutrality. It requires active investment in the relationships and intelligence that keep testing methodologies current.

Invested in staying ahead. ​

Ingenium works in close partnership with public sector bodies, academic institutions, and international standards working groups. Those relationships give us access to emerging threat intelligence, including attack methods that are not yet reflected in published standards, and allow us to develop tests that mirror the capabilities of organised threat actors, not just the baselines mandated by regulation.
The result is testing that is both independently credible and genuinely current.

Regulators define a baseline. Vendors assure their own products. Auditors verify the process. None of these tell you whether your system would hold against the nefarious actors and the methods they  use against systems like yours, right now.

That is what independent testing is for.

Ready to find out where your systems actually stand?

Whether you’re evaluating a new system, preparing for regulatory scrutiny, or looking to build independent evidence into your product, Ingenium provides rigorous, impartial testing and reporting to give you a clear picture of where you are and what it takes to close the gaps.