ForgeNEX

Camerfirma and the crossroads of digital identity: sovereignty, geopolitics and the challenge of usability in a world at war

Javier Bustillo, CEO of Camerfirma, breaks down the challenges of digital identity in a context of geopolitical tension, European regulation and the eternal battle between security and usability.

Javier Bustillo, CEO of Camerfirma, analyzes the present and future of digital trust in an environment marked by geopolitics, European regulation and cybersecurity pressure

At a time when digital identity has become the cornerstone of any transaction, from an online purchase to the signing of a corporate contract, the rules of the game are changing at breakneck speed. Javier Bustillo, CEO of Camerfirma, a company born under the umbrella of the Spanish Chambers of Commerce and now part of the Infocert group, speaks to ComputerWorld to break down the challenges facing the sector. His vision, loaded with historical perspective and technical realism, paints a picture where security, usability and technological sovereignty wage a constant battle.

Bustillo, who joined the company in the midst of the post-pandemic period, highlights the importance of understanding the legacy of two decades. "I hope I am laying the groundwork for whatever the group wants to do in the next four or five years," he says, stressing that the company was founded in 2000, when e-commerce was taking its first steps and the priority was "to convey security." Today, that e-commerce is a fundamental part of everyday life, and the concept of digital identity has been solidified thanks to regulations such as eIDAS. The pandemic, he recalls, "meant the sudden digitalization not only of the transactions that remained to be digitalized but also of a huge number of communications."

Latin America: a booming market with regulatory complexity

Expansion into Latin America is one of Camerfirma's strategic focuses. Bustillo describes the region as a market "at a moment of explosion in digitalization, with a few years of delay compared to what we have experienced in Europe and with greater legal and regulatory complexity." This regulatory fragmentation raises the cost of building tailored value propositions, but, according to him, "it is more than compensated for by that moment of high-growth market." The shared language is a vehicular advantage, but so is regulatory affinity: "Many of these geographies are more influenced at the regulatory level by what is being done in Europe than by what the Americans are doing." In a geopolitical context where the United States and its neighbors maintain tensions, the European approach to data protection, which places the person as the central owner of their information, aligns better with Latin American culture.

This approach to sovereignty and data protection resonates with broader debates in the technology sector, such as those we analyze in the new era of cyber risks unleashed by agentic AI, where the monitoring and control of autonomous systems become critical.

eIDAS 2 and the countdown for European companies

The eIDAS regulation is the axis on which the entire digital identity strategy in Europe pivots. Bustillo distinguishes two milestones: eIDAS 1 (2014), which established the foundations for the definition of digital identity, issuance of certificates and identification methods; and eIDAS 2 (2024), which introduces the concept of the EUDI Wallet. "The timelines have been compressed," he warns. By December of this year, governments must provide their citizens free of charge with a wallet with basic functionalities. In December of the following year, the obligation will extend to the private sector: banks, utilities and large platforms. In addition, the European Business Wallets, which transfer the same concept to the business sphere, including SMEs, will not take effect until 2028 or 2029. "A pre-notice has already been given because all companies will need to adhere to this type of identity management for legal entities," he explains.

Concern about the impact on SMEs is palpable. Bustillo mentions that institutional and financial support is being requested so that they are not left unprotected against the large resources of corporations. "The incorporation of all this type of regulation will be necessary, as we are now seeing with Verifactu and electronic invoicing," he adds. Precisely on Verifactu, he acknowledges that there is confusion: "We have learned a lot from the electronic invoicing issue. Many of the things that have generated friction with the end user will be simplified." However, there remain points of debate between the Council and the Commission, such as the mandatory nature of these tools, the cost for SMEs and, above all, data sovereignty: "Where will they be? In non-European hyperscalers with data centers outside Europe, in non-European hyperscalers with data centers in Europe? How do you control whether information flows or not when in the United States national security is used to do whatever they want?"

Cybersecurity and geopolitics: the tightrope between protection and usability

Growing geopolitical tension and the threat of cyberwar raise the bar for requirements. Bustillo is blunt: "That war environment increases even more the demands and requirements for any type of transaction or use of digital identity. Anything that means protection is not enough." However, he points out an inherent contradiction: "Usability clashes head-on with total protection. In a company you have the security manager pulling on one side of the rope and the salesperson on the other, with several departments in between trying to find the logical balance." Regulation, he says, comes to establish that line, to set the minimum. In Europe it is "tremendously advanced" and will become "more perfect" over time.

This balance between security and functionality is a recurring theme in current technology analysis, as we explore in the merger of Synack and Wiz to revolutionize vulnerability management, where the integration of solutions seeks to break down silos without sacrificing protection.

Camerfirma, aware of these demands, invests significant amounts solely in regulatory compliance. "We spend hundreds of thousands of euros just on complying with regulations in order to operate," reveals Bustillo. The company undergoes annual technological audits, both local and from the National Security Scheme. In bioidentification processes, they use algorithms certified by the National Cryptologic Center, with biometric technologies, liveness detection, document OCR and real-time consultation of the National Police database. "All this ensures that that person can exercise their rights and obligations through a digital tool as if they were physically present," he states.

The European Council has raised the security threshold and extended evaluation periods for many technologies. "With the Electronic Business Wallet, the aim is to raise the threshold even higher, which will mean that providers will have to spend even more money to comply with regulatory restrictions and prevent fraud. Eliminating it would be the ideal goal, especially now that technologies such as AI are used for identity impersonation," he stresses. This threat of impersonation through AI connects with concerns about the evolution of language models and their impact on security.

Competing against free services: usability as a differential advantage

In Spain, Camerfirma has competed since its beginnings with the National Mint and Stamp Factory (FNMT) and with the National Police, which by law is the only body capable of issuing identity for natural persons. Both offer certificate and signature services free of charge. "We have had to compete with that free universal service from our origins. The only way is by offering a service that is easier to consume," explains Bustillo. The advantage is based on usability, functionality, interoperability and integration with existing processes, as well as constant innovation.

The electronic DNI is the paradigmatic example of failure in usability. "Less than 5% of citizens who have it use it. It is perfectly functional if you know how to use it, but if you know how it is probably because you are a computer engineer or because you have made an effort to use it. It is not comfortable and it is not usable." Bustillo emphasizes that companies and individuals need things to be usable, especially when their use is occasional. "When you are going to use these technologies occasionally, you want it to be secure and easy."

This lesson is applicable to other technological fields. For example, in the development of cloud solutions, usability and integration are key, as analyzed in advanced solutions in Microsoft Azure: beyond the basic cloud. Likewise, migration to new versions of tools must consider the user experience, as detailed in the migration guide for DevOps after the price reduction of Opus 5.5.

The conversation with Bustillo suggests that the future of digital identity is not only played out in the regulatory offices of Brussels or in data centers, but in the ability to make security invisible and simple for the end user. A major challenge in a world where geopolitics and cybersecurity set the pace.


Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.

Keep reading