Multi-factor authentication (MFA) has long been treated as a critical defense for enterprise systems. But as attackers become more effective at stealing credentials, hijacking sessions, and manipulating users, adding another prompt to the login process may no longer provide the assurance organizations expect.
For Jose Bolanos, MD, Founder and CEO of Nimbus-T Global and inventor of Nimbus-Key® ID, the problem comes down to a fundamental question: Does authentication actually prove who is accessing the system? “MFA confirms that someone possesses an additional device, code, or token,” Bolanos says. “It does not necessarily confirm that the person requesting access is the true authorized user.”
That distinction is becoming increasingly important as organizations adopt passwordless authentication, Zero Trust architectures, artificial intelligence, and biometric systems. Zero Trust is based on “never trust, always verify.” But what is being verified—the credential, the device, the session, or the human being? If the identity layer cannot establish that the authorized person is behind the access request, Zero Trust begins with an unresolved vulnerability.
2FA / MFA Authenticates Something, Not the User.
Traditional MFA typically combines a username and password with a second factor, such as a six-digit code, authentication application, security key, or push notification. These mechanisms make unauthorized access more difficult, but they still rely on credentials, devices, and tokens that can be stolen, intercepted, or compromised.
Attackers have learned to target the authentication process itself. Phishing, malware, credential breaches, push fatigue, SIM swapping, help-desk manipulation, and adversary-in-the-middle attacks can all create pathways around conventional controls.
Another vulnerability arises after authentication: the session token generated when access is granted. If an attacker steals a valid session token or hijacks an authenticated browser session, the attacker may be able to operate as the employee without completing MFA again.
The system sees a valid session and assumes it is interacting with a trusted user. Yet the authorized person may no longer be in control. This is the critical difference between authenticating a credential and verifying a human identity.
Moving to True User Verification™
The next identity layer must go beyond possession-based authentication and establish a trusted digital identity before granting access. Nimbus-Key® ID, developed by Nimbus-T Global, uses a mobile-first registration process that combines government-issued identity evidence, facial images, biometric analysis, a unique device identifier, and a user-controlled Master PIN. These independent signals are connected to establish that the person creating the account is the person represented by the identity evidence. “Biometrics alone are still not enough,” Bolanos says. True User Verification™ requires more than one static characteristic or point of trust. A face, fingerprint, voice, or iris pattern is persistent and cannot easily be replaced if compromised. Deepfakes, synthetic media, copied biometric images, and replay attacks also mean organizations can no longer assume that seeing or hearing someone is sufficient proof of identity. A stronger approach creates a chain of trust around the person, the registered device, and the access attempt. It should incorporate strong identity enrollment, liveness detection, resistance to deepfakes and replay attacks, device binding, independent identity evidence, secure recovery, and continuous security testing.
Advancing From MFA to DE-MFA®
Nimbus-T Global calls its authentication model Dynamically Encrypted Multi-Factor Authentication, or DE-MFA®. The objective is not simply to add more factors. It is to protect the authentication event dynamically while verifying that the authorized human is actively participating. Instead of depending on passwords or reusable static tokens, Nimbus-Key® ID combines dynamically encrypted authentication information, a trusted mobile device, biometric verification, and a user-controlled Master PIN.
The principle is straightforward: stolen credentials should not be enough. Possession of a code should not be enough. Access to an email account should not be enough. A copied biometric image should not be enough. The verified user, registered device, and correct authorization factors must come together during the access event. DE-MFA® dynamically protects that authentication event, while True User Verification™ establishes the identity of the person behind it.
Deepfakes Are Raising the Stakes
AI-generated voices, images, and video are expanding the credibility and scale of identity fraud. A voice clone can impersonate an executive during a financial request. Synthetic video can create the appearance that a trusted leader is participating in a meeting. AI-generated communications can make fraudulent instructions appear legitimate. These capabilities weaken a longstanding assumption: that seeing or hearing someone is sufficient proof of identity. They also create serious risks for organizations that approve sensitive actions through email, telephone calls, video conferences, or messaging platforms. A request may appear to come from an executive, physician, administrator, or financial officer while actually originating from an attacker—or an AI system operating on the attacker’s behalf.
For high-risk actions, identity and authority should be verified independently from the communication channel where the request originated. The approval should also be connected to the specific action or transaction being authorized. The same verified identity layer used for login can therefore help protect financial approvals, administrative changes, sensitive records, security policies, and AI-agent permissions.
Zero Trust Is Only as Strong as Its Identity Foundation
Zero Trust assumes that no user, device, application, or network connection should be trusted automatically. Each access request should be evaluated according to identity, device condition, context, policy, and risk. But this model depends on the reliability of its identity foundation.
If an attacker uses stolen credentials, compromises a device, manipulates account recovery, or hijacks an authenticated session, a Zero Trust system may still receive signals that appear valid. It can continuously evaluate the wrong person with great technical precision. True User Verification™ is intended to provide the missing human identity layer. It asks whether the person requesting access is the individual originally verified, whether the request involves an authorized device, and whether that person is actively participating in the access decision. “You cannot depend on static tokens, keys, or passwords,” Bolanos says. “The world is advancing at a very fast pace.”
As cyberattacks become more automated, organizations must distinguish among a verified human, a compromised account, and an autonomous digital agent. Identity can no longer be inferred merely from possession of a valid credential.
Healthcare Shows Why Identity Matters
Bolanos’s perspective is shaped by 25 years as an obstetrician and gynecologist. In healthcare, identity errors can have serious consequences for patients, clinicians, and care delivery.
Healthcare environments are especially complex. Employees, physicians, contractors, patients, insurers, laboratories, and administrators interact with multiple systems around the clock. A patient may have records across hospitals, clinics, laboratories, pharmacies, and specialized systems, creating opportunities for identity mismatches.
Dr Bolanos encountered this problem while developing electronic medical record, billing, and laboratory systems. Multiple patients could share the same or similar names while holding different identifiers across disconnected systems. Establishing which information belongs to which person is fundamental to safe care.
Healthcare cybersecurity is therefore not simply about protecting data. It must also ensure that the right person accesses the right information, for the right purpose, and takes the right action. The same principle applies throughout enterprise security: identity is the foundation for access, authorization, accountability, and trust.
What Comes After MFA?
The next step is not necessarily to abandon every existing MFA system overnight. Enterprise leaders should identify where conventional authentication creates unacceptable risk and strengthen those entry points first.
Priority areas include administrator access, financial transactions, healthcare records, critical infrastructure, account recovery, security-policy changes, intellectual property, and AI-agent authorization. The target should be passwordless, phishing-resistant authentication that verifies the authorized human, binds identity to a trusted device, and protects the resulting session.
Rather than requiring separate biometric identities across every application, Bolanos envisions a user-controlled digital identity that connects securely to multiple enterprise systems. Nimbus-Key® ID is designed to operate as an identity layer in front of existing identity providers and applications, strengthening verification before access is granted.
As credential theft, deepfakes, session hijacking, and AI-enabled identity fraud become more sophisticated, True User Verification™ may become less of an enhancement and more of an enterprise requirement.
MFA verifies factors. DE-MFA® dynamically protects the authentication event. True User Verification™ establishes the human identity behind it.
Zero Trust cannot deliver its intended protection unless it begins with confidence in who is actually being verified.
Follow Jose Bolanos, MD, on LinkedIn or learn more about Nimbus-Key® ID at Nimbus-T Global.