If Nobody Can Prove What Happened To A File, Somebody Still Pays For It

Estimated reading time: 9 minutes

Photos, MRIs, X-rays, contracts. Every business decision now rests on digital records, and anyone can alter them in seconds. DigiCert’s Mike Nelson explains how provenance technology tracks where a file came from and every change made to it. The liability for what it can’t yet show is still unassigned.

A record is only as good as its history. Mike Nelson, Field CTO at DigiCert, joined the Cyber Insurance News and Information Podcast to talk about a question that sits under every claim, every court case, and every medical decision: can you prove that a digital file is what it claims to be, and that it hasn’t been changed without anyone knowing?

The conversation covers a lot of ground:

  • A Utah judge who stopped a hearing to ask what had been done to a video.
  • The antique dealer’s idea of provenance, and why digital records lack it.
  • A parking-lot fender-bender that turned into a thought experiment about claims fraud.
  • Why hospital imaging machines bought fifteen years ago are still a weak point.

It starts in a courtroom.

The Question That Creates The Liability

At the July preliminary hearing of Tyler Robinson, prosecutors tried to show surveillance footage that had been zoomed and marked with colored circles. The judge stopped them and asked for the original. He needed to know what had been added, what had been removed, and what had been changed.

“I think the question that the judge asked is the right question,” Nelson said. “How do we know what has happened to digital content? And can it be trusted?”

CINI covered that exchange in August. Nobody said the footage was fake. Nobody could document its history.

That gap is where liability starts. A court that can’t confirm a record may exclude it. An insurer that can’t confirm a claim photo may pay for damage that never happened. A hospital that can’t confirm an image hasn’t been altered is making clinical decisions on faith. In each case, the loss lands on someone, and the only real defense is a documented history.

Content Provenance, Borrowed From The Antiques Trade

The antiques trade solved this long ago. A painting with documented provenance, meaning a record of where it came from and who has owned it, is worth more because it can be trusted. Digital files have mostly lacked that.

“We have metadata, but you can make edits to photographs and the metadata does not change,” Nelson said. “So it’s hard to chain custody to images and to know what’s happened to them.”

His fix is a chain of digital signatures. A file is signed when it’s created, and every change after that is recorded and signed again. “That chain of change stays with the photo,” he said. “If it shows up in a courtroom or an insurance adjuster is looking at it, you can see the modifications that have been made.”

See also  Insurers Filed Deepfakes Under Cybersecurity. The Risk Walked Into The Claims File.

Editing isn’t the problem. “Nobody is saying that editing is bad,” Nelson said. “It’s knowing what has been edited.”

Paper Charts To Digital Records

Nelson began his career at the U.S. Department of Health and Human Services, working on the program that moved American hospitals from paper charts to electronic health records. When records were on paper, he said, nobody had to think about content authenticity. Now nearly everything is digital.

On the podcast, I put it to him that this is the premise of 1984: change the underlying record, and you change what people believe happened. A medical record, a research file, or a contract that can be altered without a trace is a liability for everyone who relies on it.

Nelson went on to GE Healthcare, building software for medical devices. Around 2010, he said, security was “a box that you would check in the QA process.” The Food and Drug Administration can now block insecure devices from reaching the market. But imaging systems stay on hospital floors for 15 to 20 years, and “the devices themselves still carry significant vulnerabilities,” he said.

Tracking the history of the images those machines produce is further behind. “The chain of custody of the image itself, there’s still a lot of progress that needs to be made.”

A Fender-Bender And An AI Bot

Nelson scraped a car in an amusement park lot. The other car, an ancient Corolla by his account, barely showed a mark. His truck lost paint down both doors. He took photos and thought about filing a claim. Then he had a second thought.

“How easy would it be for me to just throw that into an AI bot and enhance the damage that’s been done?” he said. “It’s way too easy today for consumers to do that.”

The Verisk research CINI reported on this month suggests plenty of people have had the same thought. More than half of Gen Z respondents said they’d consider editing a claim photo. Nelson thinks the cause is cultural. “We’ve normalized editing,” he said.

Take The Cyber Insurance News Survey

Respondents get the results first.

Cyber insurance survey graphic from Cyber Insurance News asking what the market actually sees and whether loss data is good enough, with an eight minute completion time

How The Signing Works, And Who Ships It

The Coalition for Content Provenance and Authenticity (C2PA) publishes the standard. A manufacturer or software maker gets a signing credential only after a certificate authority on C2PA’s trust list has verified its identity. DigiCert is one of those authorities, which is its commercial interest here. “Making sure that the keys are protected, making sure that the validation of those organizations and individuals is done in the right way is very important to the trustworthiness of those credentials,” Nelson said.

See also  Shareholder Lawsuit on Way for Sinclair Broadcast Group After Ransomware Attack? Significant Losses Expected from Hack Even After Cyber Insurance Reimbursements

The hardware is arriving unevenly:

  • Cameras. Leica shipped the first C2PA camera in 2023. Sony and Canon now have models that sign at capture.
  • Phones. Google’s Pixel 10 signs every photo by default. Samsung’s Galaxy S25 adds credentials only to AI-edited images.
  • Platforms. Most still strip embedded metadata on upload, so a signed file can reach the person relying on it with nothing attached.

Nelson says he’s started seeing the Content Credentials icon on LinkedIn. He expects consumers to learn to look for it within two to five years, the way they learned to look for the Matter logo on smart-home devices.

No Plan Survives First Contact

A standard that makes fraud harder will be attacked by people who profit from fraud. I put that to Nelson with a live example. Nikon added C2PA to its Z6 III camera in August 2025. Within days, a photographer found a way to make the camera sign an image it never took. Nikon suspended the service and revoked every certificate it had issued.

Nelson’s answer was about momentum rather than any single implementation. Camera makers, editing software companies and AI firms are “racing to adopt,” he said. “I’ve seen plenty of industry standards that are created and would do great things, but nobody catches on. I don’t think that’s gonna happen in this space. And the reason is that the world needs it.”

The Nikon episode also shows the system doing what it’s designed to do. A compromised credential can be canceled. For anyone relying on a signed record, that means checking whether a credential is still valid, not just whether it exists.

You Found The Gun. You Still Don’t Know The Shooter.

The limitation Nelson spent the most time on isn’t a flaw. It’s the stage the standard has reached.

Today, C2PA vouches for the device, not the person. “It will attest what camera took a photo, not who’s standing behind the photo,” he said. “Okay, well, you found the gun, but you still don’t know who the shooter is.”

Get The Cyber Insurance News Weekly Upload
Subscribe to our newsletter!

For liability, that matters. Knowing a file came from a particular camera or editing tool is useful. Knowing who created or changed it is what assigns responsibility. A C2PA working group is building identity attestation, meaning credentials tied to a person or organization. That raises privacy concerns: a photographer in a war zone may need to remain anonymous. Nelson says the standard is being built to allow credentials at either level.

See also  How Cyber Risk Is Turning Into A Credit Threat For Global Carmakers

For insurers, he expects change within a year or two, through C2PA or through carriers requiring claim photos to be taken inside their own apps.

Full Transcript

Download the full transcript of this episode. Transcripts are machine-generated and lightly edited. Accuracy is not guaranteed. Please refer to the audio for the record.

FAQ – Digital Record Authenticity And Liability

Why does digital record authenticity matter for liability?

Courts, insurers and hospitals all make decisions based on digital files. If nobody can confirm a record is authentic and unchanged, a court may exclude it, an insurer may pay a fraudulent claim, and a clinician may act on an altered image. The loss falls on whoever relied on it.

What is C2PA?

The Coalition for Content Provenance and Authenticity is an industry group formed in 2021. Its standard attaches a signed record to a file showing where it was created and every change made since. It documents history. It does not prove the content is true.

Can C2PA prove a photo is real?

No. Mike Nelson of DigiCert says the standard shows where content came from and how it was modified. Deciding whether an image is real remains a judgment for the people and organizations relying on it.

Does a C2PA credential identify who took or edited a photo?

Not yet. The current standard attests to the device and software, not the person. A C2PA working group is developing identity attestation, with options that let photographers stay anonymous.

What happens when a signing credential is compromised?

It can be revoked. After a flaw in Nikon’s implementation in 2025, the company canceled every certificate it had issued. Anyone relying on signed files needs to check that a credential is still valid, not just that one is present.

Leave a Comment

×