Naveena Balam, VP of Technology, Risk & Strategy at Entrust: “Cybersecurity is a field where trust is both the goal and the product”

Naveena Balam’s route into cybersecurity was shaped by curiosity. Beginning her career in enterprise antivirus software sales, she quickly developed an interest in understanding more about how organisations manage risk and protect their most important assets. That journey has taken her through consulting roles across industries before arriving as VP of Tech Risk and Security at Entrust, where she works today helping organisations adopt emerging technologies responsibly.

For Naveena, the most fundamental change to digital fraud has been the rise of generative AI. While AI allows attackers to produce more convincing phishing and social engineering attacks, deepfakes pose a greater challenge through the eroding of digital identity itself. According to Entrust’s latest research, deepfakes now account for “one in five biometric fraud attempts,” making them a threat that can no longer be avoided. As Naveena warns, deepfakes are now “no longer experimental. They are industrialised, accessible, and integrated into broader fraud ecosystems.”

Combating these attacks, Naveena argues, requires organisations to move beyond single control point security measures to a “multi-layered, lifecycle-based approach,” including liveness detection and motion analysis. Alongside technical safeguards, regular staff training is essential to maintain, creating what Naveena describes as a strategy built upon “advanced biometrics, layered analytics, lifecycle protection and human awareness”.

Looking to the future, Naveena believes that the next generation of cybersecurity professionals will need far more than technical expertise. As AI continues to reshape the industry for both attackers and defenders, business strategy and human behaviour must advance alongside it. Ultimately, she argues, “the most effective professionals are not those who identify the most risks, but those who help the organisation make better decisions”.

With AI, identity and trust now sitting firmly at the centre of cybersecurity, the professionals best positioned to lead the next era will be those who continue to learn, adapt and challenge assumptions. Fortunately, few careers reflect that more clearly than Naveena’s, so we started by asking for more details on how she entered the field and her journey to where she is today.

(And it’s an impressive journey, including work with the UK Information Commissioner’s Office!)

Could you please introduce yourself to our audience and share how you ended up working in cybersecurity?

I’m Naveena Balam, VP of Tech Risk and Security at Entrust, where I lead initiatives spanning cybersecurity, data protection, and emerging technology risks, with a focus on artificial intelligence and its safe and responsible adoption.

My route into cybersecurity was not a perfectly designed career plan, which is probably

true for many people in this field. After completing my graduate degree in Information Systems, my first role was selling enterprise antivirus software to organisations. On paper, I was there to develop the business, build partner relationships and work with resellers. However, I found myself far more interested in why customers needed it, and what risks it was really solving. 

I wanted to understand not just the tools, but the business impact of risk, how organisations make decisions, how they protect what matters, and how security can enable rather than slow down progress. That led me to complete a master’s degree in Corporate Risk and Security Management, before moving into working for the Big Four firms, where I had the opportunity to work across different industries, regulatory environments and risk cultures.

What has kept me in cybersecurity is that it is never static. It forces you to keep learning, to think commercially and technically, and to stay close to how people, businesses and attackers behave. It is a field where trust is both the goal and the product.

What are some cases of deepfakes being used that particularly concern you?

One of the most concerning developments in fraud is the normalisation and scaling of deepfakes within biometric fraud systems, particularly during identity verification. The Entrust 2026 Identity Report revealed that deepfakes now account for one in five biometric fraud attempts, and the number of deepfake selfies increased by 58% in 2025, indicating both rapid adoption and increasing effectiveness of these techniques.

What is particularly alarming is not the prevalence of deepfakes alone, but the combination of them with injection attacks. Fraudsters are bypassing live capture processes by injecting synthetic video or images directly into verification systems, effectively simulating a real user interaction. This removes one of the last “human trust” barriers in digital identity, enabling fraudsters to convincingly impersonate legitimate users at scale. The sophistication of these attacks is such that they can replicate full biometric workflows, making them extremely difficult to detect without layered defences. 

Another concerning scenario is the use of deepfakes across the entire customer lifecycle, not just at onboarding. While onboarding fraud remains high in sectors like cryptocurrency, account takeover (ATO) fraud dominates in payments and digital banking, where long-term account value is high. Deepfake-enabled impersonation, combined with phishing or social engineering, suggests attackers are looking to gain control of legitimate accounts and conduct fraudulent transactions long after identity verification is completed.

And they’re popping up in several use cases, including impersonation of political and celebrity figures, romance scams, education examination and increasingly, candidate interviews and workforce hiring.

Overall, the most concerning aspect is that deepfakes are no longer experimental. They are industrialised, accessible, and integrated into broader fraud ecosystems, making them a persistent and scalable threat to digital identity systems.

What do you think are the best approaches to combating deepfakes?

Combating deepfakes requires a multi-layered, lifecycle-based approach, rather than relying on any single control point. Because deepfakes are increasingly used in combination with other techniques, such as injection attacks and social engineering, defences must address both technical vulnerabilities and human factors.

One of the most critical defences is the implementation of advanced biometric verification techniques, particularly liveness detection and motion analysis. Deepfakes often exploit static or low-sophistication verification systems. Without robust liveness controls, synthetic media can easily pass as genuine. Strengthening these mechanisms helps ensure that the biometric being presented is tied to a real, live person rather than a manipulated input.

Organisations must deploy multi-layered fraud prevention systems that combine biometrics with device intelligence, behavioural analytics, and risk-based authentication. Deepfake and injection attack combinations are especially difficult to detect, and only layered defences can identify inconsistencies across channels or signals. For example, even if a deepfake passes facial verification, anomalies in device behaviour or interaction patterns may still reveal fraud.

A large portion of fraud occurs after onboarding, particularly through account takeover. Continuous authentication, step-up verification, and transaction monitoring are therefore critical to ensuring that a verified identity remains trusted over time. 

Since deepfakes are increasingly used in social engineering, employees and customers need to be trained to verify unusual requests – especially those involving urgency or sensitive actions. Simple protocols, such as secondary verification channels or pre-agreed authentication steps, can significantly reduce risk.

Finally, combating deepfakes requires ongoing adaptation and intelligence sharing. Fraud is becoming more organised and commercially driven, with attackers rapidly evolving their tactics. Organisations therefore need continuous updates to detection models, threat intelligence integration, and collaboration across industry ecosystems.

The most effective approach is not a single solution, but a defence-in-depth strategy that combines advanced biometrics, layered analytics, lifecycle protection, and human awareness – reflecting the increasingly sophisticated and hybrid nature of deepfake-driven fraud.

What are the biggest cybersecurity challenges those in leadership roles are facing?

The biggest challenge for security leaders today is speed. Technology, like AI, is evolving faster than many traditional security models were designed to support.

IBM’s 2025 Cost of a Data Breach Report highlights the gap. Many organisations are still in the early stages of AI governance: 97% of organisations that reported an AI-related breach lacked proper AI access controls. AI adoption is accelerating faster than the governance, accountability, and control frameworks needed to manage it.

But AI is only one part of a much broader challenge. Organisations are navigating increasingly complex digital environments, including expanding cloud estates, identity sprawl, third-party dependencies, regulatory pressure, and more capable threat actors. The real test for security leaders is managing that complexity and translating it into clear, actionable decisions the business can understand and act on.

This is why cybersecurity has become a leadership issue, not just a technical one. Boards and executive teams expect risk to be framed in terms of business impact, including operational disruption, customer trust, regulatory exposure, and long-term resilience.

At the same time, there is an important balance to strike. Security cannot be the function that simply says no. The most effective leaders enable the business to move faster, not slower, by embedding security, identity, and governance into innovation from the outset, particularly as AI adoption accelerates. 

Ultimately, the systems are just the mechanisms. Cybersecurity leaders are actually defending the confidence of their customers and partners by protecting trust at scale. 

What is it about generative AI that makes it so prone to exploitation by threat actors? Conversely, how can it be used for good?

Generative AI is attractive to threat actors because it lowers the barrier to entry. It helps them move faster, produce more convincing content and scale activity that previously required more time, skill or resources.

A phishing email, for example, no longer needs to contain obvious spelling mistakes or awkward phrasing. It can be well written, localised, personalised and adapted for different audiences. Social engineering becomes more convincing. Reconnaissance can be accelerated. Malicious code can be iterated more quickly. Deepfakes and synthetic content make it harder for people to trust what they see and hear.

Generative AI increases the speed, scale and believability of attacks. That powerful combination is the real issue. 

But the same qualities can also be used for good. Defenders can use AI to analyse large volumes of data, identify patterns, support threat detection, accelerate incident response, improve security awareness and help overstretched teams prioritise what matters most. In a world where security teams are often dealing with too much noise and not enough time, that is extremely valuable.

The important point is that AI should augment human judgement, not replace it. Used well, it can give security teams more context, more speed and better decision support. Used poorly, it can automate confusion.

My view is that the organisations that get the most value from AI in cybersecurity will be those that pair innovation with governance. AI needs guardrails, accountability and good data. Without that, it becomes another risk surface. With it, it becomes a force multiplier.

What advice do you have for aspiring professionals wanting to work in cybersecurity?

Cybersecurity is often seen as a purely technical field, but it demands a much broader perspective. Organisations need people who can understand technology, but also those who can navigate risk, regulation, human behaviour, and business decision-making.

Early in your career, focus on building range. Develop a strong grounding in areas such as identity and access management, cloud security, data protection, governance and incident response. But technical capability alone is not enough. The ability to communicate risk clearly, influence decisions, and engage senior stakeholders is what sets leaders apart.

It is also a field where judgement is tested. You will be working with sensitive information, making decisions under pressure, and managing competing priorities. Good judgement in cybersecurity requires developing the discipline to think clearly when the stakes are high.

Adaptability is also important. The landscape is shifting continuously, and those who succeed are not simply keeping pace with change, they are anticipating it and shaping how their organisations respond.

Above all, learn to connect security to business value. The most effective professionals are not those who identify the most risks, but those who help the organisation make better decisions.

In cybersecurity, your impact is measured by how effectively you enable the business to move forward with confidence.

Rowan Campbell TechFinitive
Rowan Campbell

Rowan is a writer for TechFinitive focusing on technology companies doing interesting things all around the globe. He is currently studying philosophy at university.