iProov provides biometric solutions that enable the world’s most security-conscious organizations to streamline secure remote onboarding and authentication for digital and physical access. Its award-winning liveness technology and iSOC offer unmatched resilience against deepfakes and generative AI threats while ensuring effortless, scalable user experiences. Trusted by leading governments and enterprises, including the U.S. Department of Homeland Security, U.K. Home Office, GovTech Singapore, ING, and UBS, iProov sets the standard in biometric identity assurance.
Can you share the most interesting story that happened to you since you started your career, especially one that shaped your leadership approach at your current company?
One of the most interesting, instructive, and also brutal experiences in my career was also the formative moment for iProov. In 2008, I was chairman of a previous company I had founded, the world’s largest processor of mobile payments.
The year before, I had bragged to the press about the low level of fraud we were experiencing, without really understanding why or hearing the growing concerns some staff had about it. Suddenly, in 2008, we found ourselves at the heart of a massive fraud which involved the theft of money from millions of people. I was hauled up in front of the press and asked, ‘Mr. Bud, the role of you and your company in this scandal: were you complicit or just recklessly incompetent?’
To deal with the situation, I corralled every employee in the company to undertake forensic analysis over a long weekend, to understand how bad the situation was. It was very bad: about 30% of our mobile payments originated from fraud, and as soon as we discovered that, we put a stop to it.
Subsequently, the regulator determined that our behavior had been exemplary. But it was a deeply traumatic and shaming experience for me. I learned some very important lessons which have contributed to the success of iProov today.
It taught me that risk management is not a performing art, but when you are protecting the security of others, it is a vital and existential responsibility. It taught me that with strong direction and motivation, teams of people can accomplish extraordinary outcomes.
It taught me the importance of listening carefully to all staff, especially if they want to share bad news. And it taught me that bragging about things you don’t fully understand is foolish.
What initially brought you to this specific career path, and how did it lead to your role in this company?
I’m an engineer by training, expertise, and inclination, and an entrepreneur by temperament. I had the extraordinary good fortune to be involved in three technological revolutions in a row. In the 1980s, I was there when product design and manufacturing were transformed from electromechanical to microprocessor-based. In the 1990s, I was one of a small band of pioneers building digital mobile communications and, later, the mobile internet. Now I’m in the middle of the digital identity revolution, and it is perhaps the most interesting thing I have ever done.
To secure mobile payments against the kind of fraud I’d experienced, I needed to figure out how you could be certain that a real, live human being was physically in front of any mobile device at the precise moment a transaction was authorized, without making any demands on them. I asked consultants.
They told me it couldn’t be done. So I spent a year working on it myself, and when I had the answer, I realized I hadn’t just solved a mobile payments problem. I had accidentally solved one of the fundamental problems of the online ecosystem: how to establish trust remotely, over the internet. What else could I do but find a company to deliver that?
What makes your company stand out from competitors in the market? Can you share an example that highlights this?
Two things set iProov apart. The first is our science. Most vendors try to catch deepfakes by staring harder at the picture. I believe that is a losing race and, in the long run, an impossible one. So instead of analyzing the image passively, we change the physics of the capture itself. We use the screen of the user’s device to illuminate their face with an unpredictable sequence of colors, then stream the video back to our servers, where we analyze the reflection.
The color combinations run into the millions, which means the sequence cannot be copied, and we remain a billion data points ahead of the attacker. It’s a difficult technology, which took us five years to perfect to today’s level of reliability – we verify about 1.5m people a day with industry-leading success rates.
Second, we run our own global Security Operations Center (iSOC). We triage every transaction in our global ecosystem, watch attackers as they experiment against us, and modify our classifiers and defenses continuously. Think of the shift from the first-generation antivirus disks that came in the post to today’s continuously updating cloud protection.
That is the model we run for biometrics, and we are the only company in the world doing it this way. It is difficult, expensive, and legally quite painful, which is why no one has copied it. The result: in our last 200+ million Dynamic verifications in the field, there has been no evidence of a single successful spoof.
Are you working on any exciting new products or projects? How do you think this innovation will positively impact your customers?
We are launching a full suite of solutions aimed at a set of problems keeping CISOs awake at night: enterprise workforce identity. Existing identity and access management infrastructures have done the job well for a long time, but are showing some critical limitations.
Almost every major enterprise breach of the last two years has come through the same door, which is compromised account recovery and credential reset. It brought MGM and Caesars to their knees. It took down Co-op and Marks & Spencer here in the UK. It hit Alaska Airlines. It is believed to have nearly bankrupted one of the world’s largest automotive manufacturers. The same attack works time and again, because account recovery is the moment when a legitimate user has no other credential left to prove themselves with.
Well, they do have one credential: their face. Faces protected by proof of human presence cannot be stolen, cannot be shared, and cannot be phished. Our new enterprise products apply reusable, liveness-assured biometrics across the workforce identity lifecycle, from onboarding through helpdesk verification and account recovery, and they address the shared-credential problem and the North Korean remote-worker problem along the way. For our customers, the impact is straightforward: they keep their jobs and stay off the front page.
What was the tipping point for your company’s recent success? Was there a change in strategy or approach that others might learn from?
The tipping point was allowing the market to tell us what problem we had actually solved. When I invented the technology, I was convinced we were going to replace passwords. So off we went, kissing frogs across the industry, only to find that customers kept saying: “Authentication is not our biggest problem. But if you can do remote identity proofing, that would be genuinely exciting.”
So we followed them there, and we built almost the entire business for five years on identity proofing, a use case we had originally discounted. Our patents covered it, but we had not taken seriously the thought it might be our primary market.
The lesson for other founders is to hold your conviction about the technology tightly, and your conviction about the use case loosely. Invest with a fierce belief that the fundamental thing works, and be prepared to be surprised about exactly who needs it and what for. If we had stubbornly kept banging on the authentication door ten years ago, iProov would not exist today.
Can you share a significant challenge your company faced and how you overcame it? What key lesson did that experience provide?
The hardest challenge in the early years was not commercial; it was existential. Could the physics actually work? The core idea, illuminating a face with a random sequence of colors from an ordinary mobile screen and reading the reflection back through the camera, was alluring but, from a signal-to-noise perspective, dubious. We were operating with a Samsung Galaxy S3 in whatever ambient lighting a real user happened to be in. The vision at the end was enticing, but it was not at all obvious the technology could deliver.
It is very easy for an entrepreneur to fall so in love with an idea that they become a victim of confirmation bias, building castles on foundations they have never really stress-tested. So discipline and realism were essential. A very small group of us spent nearly two years building enough prototypes to prove there was a detectable signal in the reflection, before we allowed ourselves to say, “Yes, we can build a business on this.” Only then did we bring more people in and start investing properly to develop the product.
The lesson: conviction is essential, but conviction is not the same thing as delusion. Identify the fundamental unproven assumptions your business rests on, and prove or disprove them as quickly and as cheaply as you can, before you commit the rest of your life to them.
In just a few words, what differentiates your leadership role from others in the company? What impact does this have on company culture or product success?
My role as a leader is to set the objectives, affirm our values, drive change, and take the blame. Yes, you read that right. A piece of wisdom I picked up along the way is that “a fish stinks from the head,” so when things fail or go wrong, I take ultimate responsibility – what information could have been shared better, what processes or controls should I have demanded, what questions should I have asked, what decisions were a mistake?
Let’s learn and do better. My experience and success give me the confidence to create that psychologically safe space for my team, without compromising their accountability. I am proud that with clear values and a set of collective objectives, allowing the maximum initiative by staff to make their contribution, we’ve created a high-performance, supportive, inclusive, high-trust culture.
We are in a live contest with sophisticated adversaries, and in live competition with skilled competitors. We update our defenses constantly and have to ensure excellent quality in everything we do, at every level. Complete and safe staff engagement throughout the business is essential to ensure we move nimbly and intelligently enough to stay at the top of this game.
I was inspired by my years at Olivetti in Italy, a community and a culture as much as the world’s second-largest IT technology company at one time, famed for its innovation and quality; even today, former staff are very proud to talk of their affiliation with the firm. That’s also one of my ambitions for iProov.
Learn more at www.iproov.com.
Related News:
Malwarebytes Scam Link Check Helps Verify Links Before Clicking
Cloudflare Basin Launched: Open Data Platform for Developers