Connect with us

Hi, what are you looking for?

GEO

Beyond Login: Why CISOs Are Moving Towards Continuous Identity Assurance

Identity verification remains a necessary defence against cybercrime, but it addresses only one stage of the user journey. It confirms identity when a person is onboarded or authenticated; it does not prove that the same person controls the session afterwards.

For CISOs, this creates a clear security gap: authentication may be valid while the person using the authenticated account is not.

What South African cybersecurity data shows

Preliminary findings from the 2026 ITWeb Brainstorm CISO Survey place unauthorised access and hacking among the leading risks facing South African organisations.

The published findings report that:

  • 51% of respondents identified unauthorised access or hacking as a leading cyber risk.
  • 28.3% reported identity-theft incidents during the preceding year.
  • 75% rated their maturity in managing machine identities at three out of five or lower.
  • Phishing and social engineering were the two most frequently reported security incidents.

These figures do not mean that authentication has failed as a security control. They show that identity risk extends beyond a single login event and involves people, credentials, devices, sessions and non-human identities.

The limitation of point-in-time authentication

Multi-factor authentication, biometric login, document verification and passwordless authentication can make unauthorised login more difficult. Their limitation is temporal: they establish trust at a particular point.

Once access has been granted, many systems continue to trust the session until it expires or suspicious behaviour is detected.

During that period, an attacker may obtain a session token, take control of an authenticated device, persuade a user to share access or exploit stolen credentials. An internal user may also give another person access to an approved session.

In each case, the authentication event can be legitimate while the subsequent activity is not.

Continuous identity assurance closes part of the gap

Continuous identity assurance is the ongoing evaluation of whether the authenticated individual remains present and in control.

Continuous Facial Recognition with Liveness provides one way of adding this assurance. Facial comparison helps verify that the present user matches the enrolled identity, while liveness detection helps distinguish a live participant from certain presentation attacks.

Through the partnership between Datanamix and YEO Messaging, organisations can integrate Continuous Facial Recognition with Liveness using YEO Messaging’s Continuous Facial Recognition SDK.

The technology should be understood as an additional security layer. It does not remove the need for secure onboarding, multi-factor authentication, device security, behavioural monitoring or incident response.

Where continuous assurance may be most useful

Continuous verification is unlikely to be necessary for every user action. A risk-based implementation can prioritise situations in which an account takeover would cause substantial harm.

Examples include:

  • Access to privileged administrative systems
  • Approval of sensitive financial transactions
  • Viewing or exporting confidential information
  • Remote access to regulated systems
  • High-trust messaging, voice and video communications
  • Sessions involving personal or customer data

Organisations should also evaluate privacy, consent, data governance, accessibility, retention and user-experience requirements before deploying biometric technology.

Supporting Zero Trust principles

Zero Trust security is based on continually evaluating access rather than assuming that trust persists after authentication.

Continuous identity assurance supports this principle by adding evidence about the person currently using the session. It allows existing identity providers and authentication technologies to remain in place while strengthening assurance during higher-risk interactions.

Secure Enterprise Messaging can extend the same principle to business communications by combining continuously verified identities with enterprise-grade encryption across messaging, voice and video.

The practical conclusion for CISOs

Identity verification is necessary, but it is not sufficient on its own to address every form of unauthorised access.

A more resilient strategy combines identity verification at onboarding, strong authentication at login, ongoing session assurance and additional controls for high-risk actions.

Datanamix combines identity verification, Continuous Facial Recognition with Liveness and Secure Enterprise Messaging to support this layered approach. The objective is not to replace existing authentication investments, but to maintain stronger confidence in identity after login.

Contact Datanamix to discuss continuous identity assurance for your organisation.

You May Also Like

Datanamix News

How to improve right-party contact rates in debt collection in South Africa  Right-party contact is one of the most important performance indicators in debt...

Datanamix News

How to find updated debtor contact details in South Africa  One of the biggest operational challenges facing South African debt collectors today is outdated debtor...

Datanamix News

Datanamix brings Continuous Facial Recognition with Liveness to South Africa through YEO Messaging Digital fraud is evolving. As organisations continue to expand digital onboarding,...

Datanamix News

Is manual verification slowing your digital retail business down?  Manual verification is one of the biggest hidden risks in digital retail today. As digital...

Datanamix News

How can businesses prevent commercial fraud in South Africa?  Commercial fraud is no longer a distant risk. Commercial fraud is a daily reality for...

Datanamix News

How do you verify a Trust in South Africa?    Verifying a Trust in South Africa is one of the most misunderstood and risk-heavy parts of...

Datanamix News

Why do Trusts create so much uncertainty for compliance teams in South Africa?  Trusts are widely used in South Africa to protect assets, manage...

Datanamix News

The Digital Compliance Gap in Debt Review: Why Identity Assurance Matters More Than Ever  The debt review industry in South Africa has embraced digital...

Datanamix News

How do you verify a business and its directors in South Africa?  Verifying a business in South Africa is no longer just about confirming registration details. It...

Datanamix News

Unauthorised Access Is A Growing Concern For CISOs: Is Identity Verification Enough? For many organisations, identity verification has long been considered the first line...

Copyright © 2026 - Datanamix
Disclaimer: The information in this BLOG is provided for general informational purposes only and is the opinion of the author only. No information contained in this blog should be construed as legal advice from Datanamix or the individual author, nor is it intended to be a substitute for legal counsel on any subject matter. No reader of this blog should act or refrain from acting on the basis of any information included in, or accessible through, this blog without seeking the appropriate legal or other professional advice on the particular facts and circumstances at issue.