Martin Hinton (00:00) This is the Cyber Insurance News and Information Podcast. I'm Martin Hinton Executive Editor. Every week we talk to the underwriters, brokers, and security leaders shaping the market. Martin Hinton (00:11) Before we begin, a request that you take a few minutes and complete the Cyber Insurance News 2026 survey. There's a link in the show notes, and respondents get the results first. Thank you. Martin Hinton (00:25) All right then. Welcome to the Cyber Insurance News and Information Podcast. I'm the executive editor and your host today, Martin Hitten. And the topic on hand today is can you believe your eyes? And to help us walk through that in this age of deep fakes and AI and just digital evidence in general is Mike Nelson, field CTO. That's field CTO at Digicert. Mike, thanks so much for joining us today. How's your day going so far? Mike Nelson (00:47) It's great, Martin. It's fun to be on with you. I'm excited for this discussion today. Martin Hinton (00:52) So for those who don't know, maybe you didn't see the article we had featuring you, it starts with a case in Utah where prosecutors presented video evidence and it was a bit of a compilation, if I'm right. And there were elements of the video where they'd done things like zoom and highlight with circles, and the defense objected, and the judge ruled in the defense's favor because no one was quite sure. The person who had made those adjustments wasn't available to the defense to discuss. Now This opens up a huge can of worms. This isn't even in the deep fake world. But I wonder if you might tell me a bit about bit more about that case and and take me through some of the more specific the specifics of it. Mike Nelson (01:30) Yeah, it's really an interesting one. and it's it's fun to talk about because it really it it provides a real world example of what we're talking about today, which is can we trust digital content? And it's kind of fun for us here in Utah too, because it's happening the the case happened in our backyard. It's actually happening in in Utah, which is where I reside. but you know, many people are are aware, just over a year ago, Charlie Kirk was assassinated and the trial for Tyler Robinson's been going on, and the defense presented video, or the state, I should say, presented video evidence of someone climbing off Tyler Robinson climbing off a roof and doing things. And in the video, the defense had done some zooming and they also had highlighted some things in the video with red circles and green circles, clear manipulation of the original video. And it really interesting in the trial. The judge stopped them and said, Hey, I can tell that this is not the original video. It's been modified. and I'd like to see the original content. I'm like, how do I know what changes have been made? What's been added, what's been taken away, what's been altered in the video. And the state kind of was like, he said, Well, I'll give you 24 hours to provide the original content. Content, which the state did. But I think the question that the judge asked is the right question. I think it's what we're talking about today is like in this day and age where like so much digital content is available and the editing tools are so good. How do we know what has happened to digital content? And can it can it be trusted? And how do you know whether or not you can track the changes and know what modifications have been made to to content. Martin Hinton (03:31) One of the things that we discussed in preparing for this podcast was the idea that this isn't a new phenomenon. the there's a word in antiquity or antiques, pardon me, provenance, right? And this is the idea that the the existence of something is documented from its creation through the point you might buy it. And that's something that makes, in the case of antiques, the more valuable. And obviously, in the case of maybe evidence in this scenario, it makes it more reliable. The idea that it was recorded on this day by this person. And held in this fashion, and then it was moved into this place, and another copy was put here, and then one copy was made that these alterations were made to so that the original was preserved in its original form. All these iterations that exist when they're trackable, and in the case of antiques, again, who owns it can increase value if it was owned by someone famous or nefarious, that kind of thing, it makes it more legitimate. Is that you know, a simpler way to think about it and a way to maybe make it clear that this isn't some new issue or a new phenomenon that we're trying to struggle with as as a as human beings. Mike Nelson (04:33) I think it's a great analogy. you know, a a piece of art that has did that has documents of origination makes it more valuable on the market. With digital content, we're moving into an era where we need that same kind of documentation. And today it doesn't really exist. We have metadata, it it's starting to exist, but it's not widespread. We have metadata, but you can make edits to photographs and the metadata does not change. And so it's hard to chain custody to images and to know what's happened to them. And and so yes, I I think we need to, it's a good analogy and we need to get to a place where we can attach the right documentation to digital media so that we know where it came from and what modifications have been made. Martin Hinton (05:25) And in the in the broader sense of business, whether it's liability, you know, in a civil case or a criminal prosecution, or even even just being able to rely on something to be what people tell you it is, there's a broad implication here from the point of view of you know, companies and a bill that can occur. And that's sort of the space that you're in now with Digisert. So so tell me about how how you got to that spot and and and tell me what the solutions that you guys see are to To this problem. Mike Nelson (05:57) Yeah, well, I think, you know, establishing similar to, you know, it's like if you look at the physical world, a piece of art, knowing, you know, where it was originated, who who created it, what you know, who the owners have been, you want to have what we call a chain of custody. And that's a pretty common term that I I think is is understood. And so with digital media, the same thing needs to happen. And so when an image is captured at the Point of origination, you apply what's called a digital signature. And in the security world, that's a very common approach for ensuring integrity of digital content. So you do a digital signature on that. And what it does is it places a signature that says this is authentic and captured at this point in time on this camera. And then if modifications are made to it, so you take that image and you put it through Adobe photo photo editor. You would do another digital signature of that completed package. And it would say, All right, the photo was modified, and these are the changes that are made to it. And it would get another signature. But that chain of change stays with the photo. And so then, you know, if it shows up in a courtroom or an insurance adjuster is looking at it, you can then look and say, Hey, I can see the modifications that have made, I can see where it was manipulated, and it gives you more assurance that you know. What you're looking at and what has happened to that, to that photo or to that video. And so having that is is is so important. And that's where Digicert comes in. with cryptography, digital signatures are a fundamental component of what we do. And so we're one of the largest providers globally of digital signatures and digital cer certificates. Providing cryptographic evidence of these things and and that's where we come in is we help facilitate those signatures and make sure they're done in a way that's trusted and controlled. And so that you have trust of the whole process. Martin Hinton (08:01) Mike, I wonder if you could tell me a little bit about how you got to the space. I I know that that you've worked in the the federal government and health and human services, where, you know, we we we're talking about visual up to this point, but obviously h any record, whether they're medical records or research records, making sure that you maintain them and if they're changed, it becomes something that you're aware of. And when the change occurred, I mean it occurs to me saying that now, it's the whole premise of the book, nineteen eighty-four, where you have revisionist history is what we're talking about. If you alter the foundation of the information that creates understanding for any specific thing, whether it's a moment in a video that's presented in court or a document that's designed to help you argue that we should be funding this kind of research or this sort of medical stuff, you have to be able to rely on that. And that's the space you're in now with Digisert. But how did you get to that space? And what have you seen change over the course of your career in in that in in that realm? Mike Nelson (08:56) Yeah. yeah, thanks for the the question about my history. So I I started my career actually in Washington, DC at the US Department of Health and Human Services. And we were working on a project there. I was working for this the secretary, and we were working on a project that would spur the adoption of electronic health records in healthcare. At that time, you know, I mean, if you rewind the clock twenty-five years, Digital records were very they were not in wide distribution. We were using paper and and charts. And and so we believed that the promotion of technology throughout healthcare would improve the quality of care. And so we promoted a project, ended up being called Meaningful Use, and the Obama administration came in and threw $20 billion at it. And it really spurred the adoption of electronic health records nationwide. And today most systems are using digital records. But tw Twenty-five years ago, we were using paper charts. And so, you know, content authenticity and it it was not even thought about. We didn't the industry really didn't have to solve that problem. And now today, with images, all images are digital. after the Department of Health and Human Services, I went to GE Healthcare and worked on software and medical devices that were running on on on them and and saw the problem firsthand of you know we were trying to put at the US Department of Health and Human Services we were creating policies to spur the adoption of technology but then I went and started building software and medical devices that was using that software and I saw firsthand how hard it is to comply. And I also saw at that point, you know, that was you know ear about twenty ten Cybersecurity was not really thought about through the design. It was thought about as an afterthought. It was kind of a box that you would check in the QA process to say, hey, you know, is this going to cause any harm to patients and is it going to expose the networks and put hospitals at risk? But we really didn't design for cybersecurity. And I saw that for the first time. Cyber was was very premature. The FDA hadn't done anything at that time on cyber requirements. And so we really were still wild, wild west. I then went to a company called Levit Partners and I did a lot of IT consulting. Levit Partners is kind of a boutique healthcare consulting firm. And I helped with IT implementation and consulting and saw again firsthand just the unawareness of cybersecurity and the risks that come from digital systems. which then led me to Digicert, where I was asked first to start our healthcare practice. they had great technology for cybersecurity and they knew that healthcare was wildly insecure, which is why I I jumped at that opportunity because I saw firsthand the need in the market. And so I came and and we've done a tremendous amount in healthcare, but then we've expanded and have done a lot in all other critical infrastructure to really bring security to critical infrastructure, including. Digital content and making sure that the things that we're talking about today for content authenticity are in place. so you know, so your other question is how is it different? I mean, the world is just dramatically different today than it was 25 years ago when I started. digital content is everywhere. and the need for trust with that content and chain of custody and knowing provenance is so important. And and it will continue to become more important as you know that that content is used, like we saw in the the courtroom here in Utah, to prove certain actions. we need to know where content came from and the history of change. And so it's a really exciting time to be in this space and Digisearch really At the heart of a lot of this stuff. It's a great company and I've been here for eleven years and excited for for what's ahead. Martin Hinton (13:17) You you know, so twenty years of connected medicine, is there a material improvement in the sort of security that around it? I mean, you touched on something that I think's true Mike Nelson (13:28) For sure. Martin Hinton (13:28) broadly is that, you know, security was always an afterthought for to a large degree within tech, right? It was fast, cheap, effective, good UX, you know, the QA doesn't create liability, but keeping it secure was not something that was paramount. By any measure, healthcare being maybe the the the the biggest example of this because of the scale of of healthcare, and but also the the price of when it doesn't work and the and the the vulnerability that the the the problem with vulnerability in that space. What what about the the like a hospital imaging system and MRIs and those sorts of things? W what does that stand now? What what should people know about that space? Mike Nelson (14:08) Yeah, well, I would just say starting at a general level, the industry has gotten much better. You know, as of 2016, the Food and Drug Administration released guidance for medical device manufacturers of things that they needed to do from a cyber perspective to ensure the security of medical devices. medical device manufacturers at that point started acting with responsibility in the development, and they began building security into the workflow, the design, and how they built medical devices. as of several years ago, the food and drug went from guidance to actually regulatory, where they could deny submissions of medical devices that are coming through for approval that don't meet cyber resilience. And so today the FDA can actually say, sorry, this device can't go to market because it's not adequately secure. So significant progress has been made in healthcare. Around you know, around the Imaging systems, I think it's still a little bit of a mixed basket. And the reason for that, Martin, is that those devices are not short-lived devices. You know, I mean, those are big pieces of capital equipment that sit on a hospital floor for 15, sometimes 20 years. And the FDA's guidance is for new devices coming off the market off the manufacturing line. And so devices that are out there, legacy is how we refer to them. Are really where I see still significant challenges. And so what we see is manufacturers doing things around like network security, data in transmission, making sure encryption's being used, authenticating connections to the clouds, doing things around access controls. But the devices themselves still carry significant vulnerabilities. And you know, and I I I think the controls that they're putting around it are good, but there's still improvement that needs to be made. Martin Hinton (16:07) this is not, you know, we we single out hook here, but this is a problem that exists through a lot of legacy tech specs, right? I mean the Mike Nelson (16:13) Totally. Yep. Martin Hinton (16:14) you know, yeah, the the thing that jumps to mind, and as long as I've been doing this, I still b b become befuddled by the vulnerability the internet of things creates. All these internet connected devices that we have that we don't realize have passwords that we have to should change and all that sort of thing. That the you know, any device that might have sort of, you know, I mean the MRI machine might be hooked to the internet so they can update its software automatically, for example, right? And that connection is of doorway that if it's not secured properly creates a vulnerability that in likelihood makes i gets you into the entire network of a healthcare facility or any other organization with a similar type of device, a a a a copier, for example. so it's it it's it is one of those interesting things as we've sort of steadily and in in in our current era of apparently we are pumping the brakes on certain technologies, or Mike Nelson (17:00) Yeah. Martin Hinton (17:00) there's a big argument to do it being made, that that that is something that has not been the case. That's why the I mean, it it's it's worth noting now, all this slow down frontier AI conversation now. One of the reasons it's such a big conversation for people who've been paying attention is no one in that world ever talked about slowing anything down. Like that's just that that's that's for me the sort of you know canary in the coal mines. Like, okay, well, if these guys are saying slow down, if the go fast and break stuff crew is saying pump the brakes, you you you you might want to pay attention. So again, that that idea that maybe there's this reflective moment that people say, you know. That's a problem. But what about these little things already that we've got, these niggling little things that are around that that we should fix and deal with? There is, as it turns out, an idea or a solution to this that is C2PA, which stands for Coalition for Content, Provenance, and Authenticity. Tell me what that is. It's only about five years old or so. I think February 2021 is when it kicked off. But Mike Nelson (17:54) Yeah. Yeah. Martin Hinton (17:56) what is this coalition? Who who are these people and what are they trying to achieve? Mike Nelson (18:01) Yeah, so this coalition was formed, as you said, about five years ago. And it was it was based on the need to have provenance with digital content, specifically starting around photos and then they're evolving into video and other forms of of digital content. and C2PA was formed because of the need to have a chain of custody. members like You know, Adobe, Nikon, all of the big camera manufacturers, Photoshop editing tools, were all participating. Even a lot of the AI businesses are participating in in the coalition. And the objective was to create a standard that allowed individuals or organizations when they're looking at a digital photo, let's say, to see the origin, to see the chain of custody. And where it came from, where it was captured and what changes have been modified. And so they came up with a standard over the last five years that allows you to do that. So when you look at an image, you can see when it was captured. You can see the the camera that was used in capturing it, and you can see if any modifications have been made, and if they have, what tools were used, what changes were made. And it provides that chain of custody so that you know. you can look at it and have assurance to know, hey, this was not generated by AI. It was taken by this camera and it is has made these modifications. The whole intent of it is to increase the trustworthiness of those photos. So that if you're a media company or you're a judge or an insurance company, you can look at these and you can have certainty of where it came from and what changes have been made. So it's a really great standard that we believe is gonna help improve the trustworthiness of of photos and and videos to come. Martin Hinton (20:04) When we discussed this i in advance of the conversation today, there's a distinction between it proving something is real and proving where Mike Nelson (20:13) Yeah. Martin Hinton (20:14) it came from and what's happened to it since it was created. So this technology isn't about is this actually a photo of the King of England riding a horse in a skirt? It's more Mike Nelson (20:25) That's right. Martin Hinton (20:26) this happened to the this this was created here and since then it's gone through Adobe and had the contrast chusted and the coloring adjusted a little bit. originally it was cropped differently and now it's been cropped. All those sorts of things. It's not about proof that it's real. It's just proof of its of its lifespan or its i i its experiences through its existence. Is it do I have Mike Nelson (20:48) That's right. Martin Hinton (20:49) that right? Mike Nelson (20:49) Yeah, that's right. And I think in our previous conversation I had said, you know, to prove that it's real. And I was like, no, let me let me revoke that. It's not to prove that images are real. That's still for consumers and organizations to decide, but it's to show the history. It's to show where it came from, what modifications were made. and you know, the reality of it. I think that those help aid that discussion of is it real or not? But C two PA is very clear on saying it's not to help decide whether images are real or not, it's to show where they came from and what the history of modifications have been been applied to that. Martin Hinton (21:30) And how so Digisert provides or s sells is in the business of these certifications. You know, I one of the interesting things about this is that the people who are involved in this are the, if you will, the selling the shovels of the digital content age, like camera makers, right? The idea Mike Nelson (21:47) Yep. Yep. Martin Hinton (21:48) that they know that if their product is used to manipulate things, that could be bad for their brand or bad for the industry, j broadly. So the idea that their their interest in this is something that strikes me as a sort of very holistic approach to one of the issues we face now with us not being able to believe our eyes, if you will. I and I wonder whether or not you could tell me like plainly how how does that certif certification process go about? W w what occurs there that that leads someone to be certified? Mike Nelson (22:15) Yeah, well, I so before I answer that, I think it's important to distinguish that, you know, I don't nobody is saying that editing is bad. I think editing is something that all of us are used to doing. I mean, I think most kids today, before they post photos, they probably do some form of manipulation. I know my kids like to do that. And so it's not that editing is bad, it's knowing what has been edited. So you can have a better assessment of of of what's happened to the photo. And so, you know, so your question is, how does Martin Hinton (22:48) Why you I Mike, Mike, I just I I just I just y y I've been in the media business for over thirty years. Every image you put in a paper, every image you put on television, whether it's video or still, goes through some phase of editing. And what we're talking about now is the transparency that allows the consumer in some respects to be able to, or you know, maybe a legal entity, to be able to see that change as a way of increasing trust or and Mike Nelson (23:12) Yes. Martin Hinton (23:12) awareness. Right. And I just again I just in an age where there's a lot of doubt about journalism and media and Can you believe your own eyes? And, you know, all kinds of social media campaigns designed to manipulate public opinion. These are the sorts of things that are the big real reasons why this sort of thing matters. And I pardon me, I just wanted to interject that, but please p continue. Mike Nelson (23:30) Yeah. Yeah. But it but to double click on that, that trust has value in the world. Just like with old physical objects, having that documentation increases its value. Having documentation of that for digital content increases its value. If you look at it from like a if you're a media company and you're buying an image to use, knowing that it has integrity in a chain of Of custody helps. If you're an insurance company and you're trying to evaluate an image, having that documentation increases its value. Now, I'm I'm not here to say that we've decided or have a value matrix where we can provide monetary value to that, but it certainly increases its value. Having trustworthiness of those certainly has has a value. And and it's And it will become more and more important as that digital content is used in all corners of our lives. Martin Hinton (24:34) Yeah. Yeah. So how does it work? Mike Nelson (24:37) Yeah, so so C2PA has come up with a process for for providing these credentials to its members. there's something called a trust list. So C2PA has a trust list and credentials are issued. Right now there's really a two-layered approach. The first layer is for the I would say the technology that is being used. So the cameras, the editing technology. When an image is taken, let's say by a Nikon camera, they will have a mechanism that allows it to do a digital signature right when that image is captured. And that provides the first origin of documentation for an image. and so Nikon would be issued a credential that is signed by what's called a root of trust, and that's Digicert is in that business. A root of trust is kind of the anchor of trust. And anything that's signed by that root of trust inherits the trustworthiness of that. And so when Nikon goes and signs that image, it's signed by someone in the trust list. Digicert would be one of those other certificate authorities like Digicert would be in that trust list. And as long as you're in that trust list and you're providing a digital signature, it inherits the trustworthiness of those. In the trust list. And so those images will be digitally signed by certificate authorities like Digicert. And then if it goes to editing technology, Adobe will just keep using them, has that same digital signature. The changes would be made, they'd be documented. And then upon the end of that, that package would be signed again by a trusted certificate authority like Digicert. And it would then inherit that trustworthiness. From the trust list. And so they've come up with this process for before Nikon is issued a credential, we go in and validate that Nikon really is Nikon. And they get a trusted credential that allows them to sign with a certificate authority from a company like Digicert. So there's a very extensive process for validating identity, verifying that they are who they say they are, and providing trusted credentials and then keeping those credentials Safe and trusted. And that really is the business of why Digicert gets involved, because digital signatures can come from a lot of different places. But doing that in the right way, making sure that the keys are protected, making sure that the validation of those organizations and individuals is done in the right way is very important to the trustworthiness of those credentials. And that's why they bring companies like Digicert in, is to make sure that it's done in the right way. And so C2PA has come up with that. process for validating identities, facilitating digital signatures, and we're very much in the center of Martin Hinton (27:38) you know, we touched on this at the beginning. the digital space, I I think l largely because how it works and the way it exists around us, even for people who are maybe i technically minded, because it's not there and it's not tactile, it's hard to comprehend. We we we use the example of antique provenance and the train of custody of an antique helping increase its value potentially. But this idea of of documenting is not new for us. You've got certified copies of things, we notarize things. All those sorts of things have gone on for a a long, long, long time. And I wonder why do you think that the digital equivalent of that is was slow to adopt or the problem of it slow to be realized? Well what what what's gone on there that, you know, is makes it feel like it's plain catch up, I suppose. Mike Nelson (28:26) Yeah, I mean, I think it's a good question, Martin. I think that anytime I I I've seen this in a lot of different areas, but anytime technology, good technology comes out, we rush to adopt it. You look at like AI and what's happening right now, and now everybody's saying, hey, we need to slow this down because you know it's it's efficacy is is growing so quickly. IoT, you mentioned IoT, similar things. Everybody wanted the latest ring doorbell or smart thermostat or garage door opener. And they want that technology. And so the manufacturers of that push it quickly. Oftentimes in those rush, in that rush to get products to market, what we see is an oversight of cyber and not being thoughtful enough about security. And so, you know, I think that the same thing is happening here with digital content is that we were, you know, I think that, you know, when I was when I was a kid, we didn't have the ability to take pictures everywhere we went because we didn't walk around with phones that could do it. You had to you had to carry a a a camera and then you'd have to take it to a store and and have it processed for a couple of days and then get get the photo. But today, you know, we're we're capturing digital content everywhere we go. And we're now at a point where that digital content is being used for very important things, medical diagnosis, insurance claims, in courtrooms. And we're starting to realize that the integrity of that content is actually important. but it's taken a little while for us to realize the and to feel the pain of that and not being able to provide. And so similar to like IoT, when a lot of those devices were going to market, you know, several years after they're like, hey, now we're able to, we have people spying on homes. We have people going in and saying to Alexa, open the front door or unlock the front door and it would unlock. And we realized that there were a lot of security vulnerabilities that were not carefully thought through. And they then played catch-up. AI is doing the same thing. And I think we're doing the same thing with digital content right now and authenticity and being able to demonstrate where it came from and what changes have been made. And I think we're now just starting to feel the pain. And unfortunately, I think that the world has a history of like we don't pay attention to something until there's pain or until there's opportunity. And we're now just starting to feel the pain of that because it's so widespread in everything that we're doing. And so we are now, we are playing a little catch up. but I do think we're gonna get there. And I think in the next two to five years, we're gonna see significant evolution in this space to a po a point where consumers will will have will get used to seeing little icons that demonstrate content authenticity and maybe doing a little investigation to understand where it came from and and what changes have been made. Martin Hinton (31:37) So you you touched on it, the the the insurance angle of it, the the the the so we'll move it into the claims file, if you will. And w again in our in our pre-planning conversation for this, you discussed a little fender bender you had at the amusement park car Mike Nelson (31:52) Yeah. Martin Hinton (31:53) lot. And I wonder whether you might take me through that and and use that as a way to illustrate how in the insurance claim space this is becoming a real issue. Mike Nelson (32:05) Yeah. Yeah. And I'm I'm certainly not the only one who've ex who's experienced this. I mean, a quick Google search will help you see that insurance companies are scrambling on this topic right now and trying to figure out what to do because content is so easy to manipulate in really powerful ways. Yeah, so I was I was at an amusement park with my kids a couple months ago and I was on the phone with my mom. I got in the car and I was on the phone with my mom and I made a quick right hand turn. And you know, I heard I heard a sound that none of us love, which is car to car friction. And you know, I I scraped the side of the car that was was sitting next to me. and you know, in in the process of it, I the the person wasn't there, so I captured photos. I left a note on their on their windshield and said, Hey, you know, I'm I'm leaving the park, but happy to take accountability of of you know, the damage that has occurred to your car. And I I took photos of of that. now fortunately the car that I hit, I think it was like a 1975 Corolla or something like that. The car should not still be on the road. I probably the I I probably increased the value of the car. it it it was not in the best shape. But when the individual called me, he's like, hey look, I can't even tell where you hit my car. so don't worry about it. I'm not gonna do anything. but but I I started thinking about it because for me, the side of my my truck was actually pretty significantly damaged. There was a big streak that went, it damaged both the doors. a lot of paint was taken off. And you know, I I thought about submitting the photos to insurance and doing a claim and and getting it fixed. And it was right around the time we're doing all this work with C2PA. And I was like, how easy would it be for me to just throw that into an AI bot and enhance the damage that's been done, you know, and and and manipulate that. It it's way too easy today for consumers to do that. And that's why, you know, I started by saying insurance companies are really scrambling to figure out what to do because I do believe that that is happening wide scale today. I think, Martin Hinton (34:28) So Mike Nelson (34:28) yeah. Martin Hinton (34:29) I was gonna say, just to just just to interject, there was a study that that I think we we shared that came out in March of this year. And I'm just gonna read some of the findings. 36% of consumers would consider digitally altering an image or document in a claim. That rises to 55% among generation Z. Nine percent of insurers surveyed said they had already encountered manipulated or artificially altered documentation. And 66% were percent believe digital fraud goes undetected often or very often. So that's I mean, we're talk these are not outliers, right? You know, over half of a particular generation, 99%, which is as close to 100 as you get in any real world situation. of insurers say that they've encountered manipulator artificially altered documentation. And the the reality here is that this this is a drain, fraud, crime, and it's a huge problem. So I just wanted to interject those numbers to give us some framing for, you know, we're not making it up, I guess, be the i i point. Mike Nelson (35:39) Yeah, and the problem is like in society, we've normalized editing, right? And so I do think the upcoming generation just thinks that's part of what you do. Before you submit an image, you edit it and then you send it on, right? There's nothing wrong with that. but it it certainly introduces challenges with trust when you do. Martin Hinton (35:59) Yeah. I mean I I again the the the the the trust and the financial burden in that same research, sixty-nine percent of consumers believe that they're already paying more as a result of other people's fraudulent claims. So Mike Nelson (36:10) Yeah. Yep. Martin Hinton (36:12) that's the sort of thing, you know, we we've been using the word trust. It diminishes a sort of sense of society and civilization. I don't want to get too philosophical here, but but when you can't believe what is before your own eyes, it it it it's not a small thing. One of the areas that, you know, we we're talking about insurance claims and fender benders, but the idea of more sinister acts occurring with altering of you know, say MRI results or medical imagery, you you that's something that you dealt with specifically i i in in your career. Yeah, how do how does that how does that factor into this? You know, and those with the way those files move. Mike Nelson (36:45) Yeah. Yeah. The same, the same need, the same thing is needed there. and and as an industry, we're not we're we're still early in the adoption of this type of technology to say you know, this image was captured and it's been modified or it hasn't been. And so more advancements, I would say we still are very early in that. I think the healthcare industry has done a lot of good work around the protection of the infrastructure around the image. But the chain of custody of the image itself, there's still a lot of progress that needs to be made. Martin Hinton (37:22) Do you I mean, in the in the sort of underwriting space, if if I'm doing car insurance and I have a fender mender and I take a photograph with a C two PA you know, enabled authentication or certification part of me, do you think that's the sort of thing that should smooth a claim? Should it be something that gets considered? Or, you know, if even when you do your policy that that you have a you know, an element of it that you get a discount if any claim comes with a C two PA authorized documentation of photographs. How far far away do you think that sort of certification and authenticity falling into the routine of everyday claims like this is? Mike Nelson (38:00) Yeah. I think that C2PA certainly could be one of the approaches. And I I do think that it's not far away. I think that insurance companies in the coming years are gonna have that technology is gonna be adopted widespread. And it it will be approaches like C2PA or things like having their own application where you capture photos and not allowing you to capture photos outside of that, right? There are other approaches to ensure authenticity. and and lack of editing and preventing those types of manipulations from happening. But I do think that in the coming year, two years, we're gonna see significant adoption of technologies like that with insurance companies. Martin Hinton (38:43) I mean, like like you said, there's there's so little friction to to altering it. W when this sort of thing happens, you know, i if a business pays out in a fabricated image or a clone voice, I mean, is it crime, cybercrime, professional liability, or is it just a business squabble? you know, i is there any even any agreement about I mean I I I keep i one of the things that that occurred earlier in the year is this hugging face hack. And if people had been doing that, we're talking about a felony. Because it was machines, it seems to be just a a lot of you know, news coverage and and and that's a I mean, I'm being a little facetious, a little silly, but that's a real issue here where it's like, Well, where does the liability fall if this sort of thing is gonna be so widespread? And I guess I'm curious whether you have any thoughts about that. Mike Nelson (39:27) Yeah, I yeah, I I I don't know that I have a a a very strong opinion on that, but I I do think that there's liability that's associated. And I haven't seen or, you know, been I I I couldn't speak to a case where something like that it has happened, but I do think that it's a combination of, you know, fraud is fraud is certainly part of that. And you're trying to alter something for your benefit, that that, you know, f fraud is certainly involved in that. And so I do think that there will be some level of liability. I can't speak to you know, to what and I'm not gonna make any claims on that, but I I certainly think fraud is involved in that and consequences will will will follow. Martin Hinton (40:16) I mean, I I speaking for my myself and and this is my opinion now, I I think, you know, covering the insurance space, cyber insurance specifically but broadly, there is such a to put it politely, lukewarm feeling about insurance among the consumers that they feel like they're paying premiums and the worst thing they'd ever have to do is file a claim for a fender bender and they pay they have to the law requires insurance for your automobile. There's a real sense that there isn't a value that's two sided in that. And what but some of the research I've done and and certainly anecdotally talking to people because I've had a couple of fender benders lately having just aged out of some teenage drivers. The the idea is that that the there is it's fair. I'm getting back. And I and and again like like we've discussed it it making it so easy, I I I can't imagine across insurance policies they're looking at this. And we've seen anecdotal stories about it, but the scale of it from a financial point of view Is something you'll have to stay tuned for. I don't know off the top of my head of any any big numbers. We we talked a little a little bit earlier about the sort of security coming late and it it coming late and then, like you said, it coming in in a hurry when a crisis lands. And I don't know if we're in a crisis situation now, but what AI in the last couple of years has made possible from the point of view of creation of things and the content creation world to include the manipulation of things is significant. You know, you the internet of things, smart doorbells, thermostats, cameras shipped in the millions with no security framework and that sort of thing. I wonder if you could just sort of, you know, d delve a little deeper into this sort of the reality we face now that I've often likened to sort of coming to a middle-aged moment in your own human life, and the doctor sits you down and says, You can't live like you're twenty-five anymore. You need to sleep more, exercise more, lay off the red meat, you don't go out five nights a week, whatever it is. you know, get your cholesterol under control. We're sort of in this moment now where we've had that midlife crisis physical and there's a lot of scrambling to fix things while having to keep everything moving along at a pretty steady clip in the sense of progress. I guess I'm wondering whether you have any more thoughts about that part of all this. Mike Nelson (42:27) Yeah. So you look, I just don't think consumers or businesses are trained right now or have a part of their routines to check credentials, to check origin of a photo. And C2PA is trying to change that. You know, I mean, you know, one of the things I didn't mention about C2PA is that when an image is signed by C2PA, it actually inherits a little a credential, but it also has a watermark that will be on the image. So if it's posted on Platform like LinkedIn, you'll actually see a little C2PA. It's like a raindrop kind of thing in the corner of the image. And you can click on that and then you can investigate and you can see the documentation associated. Right now, consumers, we don't do that. We're not trained to do that. We don't have the history of knowing how to do that. But I would say that in two to five years, it'll be a much more common. Approach, especially in critical environments like medical imaging, courthouse, the the situations that we've talked about. But as consumers will become more accustomed to looking at it, it's kind of like when you see a Bluetooth symbol, you're like, I know what that does. in the smart IoT space, the industry actually did a similar thing to what C2PA did. as they were trying to catch up with security, they brought a collaboration together under the Connectivity Standard Alliance. So they came up And they developed a standard for interoperability and security. And now, if you go to any best buyer consumer electronics store and you're buying a smart IoT device, there's a matter logo on that box. And consumers are becoming more accustomed to look for that and say, hey, if I buy a matter endorsed device, it's actually going to work with all my other devices. No matter what, no matter what hub I'm using, it will have interoperability and it will have security. And so consumers are starting to learn to trust. smart IoT devices and to adopt ones that actually have that mark. And so I think your commentary is right that it's just not in our DNA today. We're not doing it. We're not accustomed to doing it. But I think in the coming years it's going to become more common. And I think certainly with some of those critical uses where you need to know that what you're looking at can be trusted, it certainly will be used in those environments more quickly. But I think in coming years even consumers will start to become used to seeing those watermarks and being able to click for the documentation to know where it came from. Martin Hinton (44:59) I mean I I think the the the phrase coming years sort of leads us into the next segment. And the idea is that C2PA is just the solution now. And that the it's really, really important to for people to comprehend and understand how organized this crime is. This isn't, you know, me faking a photo so that I get a better deal on my insurance or something like that. The scale of this from a a global crime point of view is is highly organized and highly profitable. So any solution that brings along greater security to make that business model, the criminal business model more difficult, is going to meet resistance and then a, if you will, a counterattack, right? The famous line is no plan survives first contact with the enemy. You know, metadata didn't survive. You know, you can alter that and that sort of thing. How do you see this evolving? I mean, I know we we we we discussed and I think we shared in the research that Nikon had shipped some credentials and there was a that there was a vulnerability found in them in a few days. But that's the nature of the conflict, right? There is there is a dynamic reality to this. It's not, you know, I I I ate a salad today, I'm gonna be healthy for the next five years. You you have to create a routine around this, which you sort of touched on. The consumer really needs to bring the energy to this and realize, wait, if I get a new IoT Internet of Things device, I should change the default password or I should make sure it integrates in a way that security is sort of, you know, not diminished but enhanced or at least maintained. That is a part of this that is you know, in some respects where the power lies with people like me and you and and you know, the public. How do you see this playing out going forward? And and the the fact that that is this reality is that there are really, really motivated, successful to date criminals who are now have the benefit of things like AI to help them be more efficient, just like every other corporation. Mike Nelson (46:47) Yeah. Well, I think the the good thing is we see C2PA is in its early deployment. but we do see a race to adoption by all the players that should be. the photo editors, the you know, AI companies and and the camera manufacturers are racing to adopt and they're all participating. And that's a really good sign that they are feeling enough pain to act. They see enough. They see the problem swelling and they're like, we need to get ahead of this or we need to catch up, is a better term. but we do see significant adoption, right? It's like a race to adoption. It's still early, but they're lining up to do it. I I'm even on LinkedIn today. I I told you, I think in our last conversation, I'm starting to see t C2PA watermarks on images that are there. Digicert today is starting to adopt just even our own use. Our communications team is only going to promote and use C2PA stamped images. And so the more momentum, to your point, the more momentum, the more awareness, the better these things do. I've seen plenty of industry standards that are created and would do great things, but nobody catches on, nobody adopts them, and they phase, they fade away. But I don't think that that's gonna happen in this space. And the reason is because the world needs it. we need this type of chain of custody and provenance with digital media. and because of that, I do think that in the coming years that even consumers, not just in those critical use cases that we've talked about, but even consumers are gonna become accustomed to seeing this, leveraging it. I mean, if there's a photo out there of your kid floating around, parents might care. to know where it came from and if it's been manipulated. I mean, there's a lot of use cases where consumers will want to know. And so I do think that we will become accustomed. It probably won't happen as fast as it will with the critical use cases we've discussed, but I do think it will become commonplace. Martin Hinton (48:59) You know, I mean I i i it it's maybe a a bit of a silly but I think about the idea of of the increasing awareness people have around, say, what they eat and particularly processed or heavily processed foods, not only being unhealthy for you physically, but also potentially having mental health impact and that sort of thing. And this idea, you know, you hear phrases like farm to table and organic, those all come at a premium, right? But th that that means you're paying more for what is perceived and and isn't quite likely to be a higher quality product. Do you see this sort of being a sort of two-tier reality to this in the short term where, you know, being able to pay for it or is to your to the point we made earlier, there are real value in it for the creators and distributors of at least the tools that allow all this content to be created to to to make sure that their business maintains the trust of the public. Mike Nelson (49:52) Yeah. Yeah, it's a good question. And I'm gonna I might I might take this a little bit of a different direction. So if I don't answer it how you want, you can bring me back to it. But it's an important Martin Hinton (50:01) That that's okay. They it it's the the we we're a free free speech though, and you can say whatever you like. Mike Nelson (50:05) Yeah, we are. But but this is, you know, an important distinction with C2PA, even is how they're starting and where they see it progressing to. The first iteration of C2PA is actually, unfortunately, not at the individual identity level or organizational identity level. It's at the technology level. So it will attest what camera took a photo, not who's standing behind the photo. It'll attest what photo editing technology has been used, but it's not going to attest to Martin being the editor behind it. It doesn't have that level of identity yet. And so the second iteration and the next, and they have a working group on this right now, is around identity attestation and being able to assign, because I just think that, yes, it's great to know that a camera was used, but it's like, Okay, well, you found the gun, but you still don't know who the shooter is, right? It's like you need to have identity associated with it as well. And they have fortunately they have a working group that is working on that in the right way to attest the organization and to attest an identity. So you can attach and say it was taken by this camera, and this was the individual standing behind it. But that level of adoption it does require a lot more process. Identity validation is. harder than just technology, you know, a a signature on on a piece of technology. And so, but, but we're gonna get there. And so, you know, I I think I took your question in a little different direction, but I but I think that that level of trust is is really important because it it enhances the trustworthiness. And I think the more you get to that level, I think adoption will will be spurred as well. It'll it'll accelerate. Martin Hinton (52:02) So on adoption, we did see some regulation arrived last month in the European Union in the form of what is called Article 50 what do you think about the regulation space broadly then? Do you think that, you know, we've been touching on the the product creators? you know, we've been talking about the consumers demanding something that they can trust and believe in and and and know it's what it says it is, or at least be able to tell to a degree what that is. Where does where does regulation and and the government fall into this space with regard to, you know, creating I mean we hip y listen, the government puts up guardrails on the highway, right? So we everyone uses guardrails Mike Nelson (52:38) Yeah. Martin Hinton (52:39) in in this digital world now, in this cyber world now. Who's putting up the guardrails there? And is it a collaborative private public partnership? Should the government be more involved? Does it require international cooperation? Which would seem to Mike Nelson (52:51) Yeah. Martin Hinton (52:51) to me, but but what do we think about all that? Mike Nelson (52:54) Yeah, I think regulation is certainly needed. And I think it is coming. And we see areas where it's emerging. I think there's some in Europe and and other other places. But not just, you know, I I think industry regulation is also important. And I think you'll start seeing it around you know, areas like DICOM and images in medical or insurance. I think you'll start to see more regulatory oversight and processes to ensure that these types of technologies exist to make sure that trustworthiness. is there. Martin Hinton (53:27) Yeah, I mean I I I again I it it feels like you you touched on this earlier, like to often takes a large event to trigger significant change and attention and and resources to something. And there is an element of that sort of again, sometimes I feel Mike Nelson (53:41) Sure. Martin Hinton (53:41) like I'm a little too close to the flame, but there is a you know, when you've got there's very f little Americans agree on politically, and data centers and AI seem to be one where they're not sure. And that that coalescing of sh if you will you know, everyday human power is is something that that does move the needle if if you get leaders that are willing to tap into that resource and that energy. You know, one of the things we we've sort of glazed over here is that if you take photos in this world, where they've been and how they existed is something that can be documented. Is there any downside to that? I mean I'm thinking go ahead, great. Mike Nelson (54:11) You know, I think yeah, it's a good it's a great question. you know, I think transparency, confidentiality is important for consumers. And so I think can you could see a situation where a consumer was like, hey, I don't want my identity disclosed. Let's say you're a photographer in a war zone and you've captured an image that you you know it's powerful, it's being distributed by media outlets, and you don't want your name everywhere associated with that. Confidentiality is important. But C2PA is dealing with that, with that identity, you know, it can be, it can be at the machine level or it can be at the identity level. And so I think it's important in these situations that if confidentiality wants to be maintained by an individual or by an organization, that it can. And the good thing is C2PA is accounting for that. And so, yeah, it could be a you know, confidentiality of of Confidentiality could be an issue. but I think that it's being accounted for. Yeah, I I don't know if I love how I answered that, but Martin Hinton (55:19) No, no, I I well yep so I'm again like th so I'm I'm the reality is we're trying to fix a very, very complicated problem while the ship is at sea at full speed. And anyone who thinks that that should be something that's easy to do is fooling themselves and no one else. Maybe they're fooling other people, I don't know. So again, I think that, you know, one of the things as a journalist in this space And as a journalist in general, it's very easy to see what's wrong, right? Like we we we tend not to talk about when planes land safely, right? That's not something that winds up on the cover of the paper. But I I think in particularly in this sort of professional business world of journalism that that I'm occupying now is the idea that there is a process ongoing here and that you know you don't launch a product and it's like, that's it. That's that's all we're ever gonna need to do. That's the greatest wrench ever. I mean, there are t hammers have changed over time and wrenches and all sorts of things have been added to cars to make them more successful from from the decades since the Model T and that sort of thing. So again, that idea that there is this very, very you know, important mindset to maintain when you're taking on a monumental challenge. And as we've touched on, there are other people who are trying to prevent you from succeeding. And the reason is they're making themselves incredibly wealthy, stealing things in the digital space and using these tools to manipulate information and inf ideas and and that sort of thing. And and You know, there's a there's a game afoot to to to paraphrase Sherlock Holmes. So yeah. so we've we've been talking about an hour and and as as as as we suspected, we didn't get to everything. But I wonder if there's anything we didn't get to that you'd you'd like to bring up and discuss? Mike Nelson (56:58) No, I think that yeah, I mean, I I love the conversation that we've had, Martin. We've talked, we've touched on a lot of of really good topics. I think that, you know, the the main takeaway that I hope your listeners will have is that, you know, provenance with digital media is very important. we're not saying that editing's bad. we're saying that we need to have chain of custody. We need to know where images were. captured and what modifications have been made. And that will increase the trustworthiness of that. And I think that it will it will help in all of the critical uses that we've discussed at length today. and you know I just I hope that even with this podcast we're raising awareness and that people will start thinking about this is why this type of technology is important. And when it comes out, start start utilizing and leveraging it. And You know, I I I think that The other thing I would say is, you know, when new technology comes actually I don't know, maybe I'll I'll pause on that. I was gonna talk about trust models and and and why it's important to build trust models, but Martin Hinton (58:10) It sounds like it's it's it sounds like we got a topic for another conversation. So I got one last question. If if if th there's an underwriter or broker or someone in the insurance space, e cyber insurance or otherwise listen to this, what's something that they should consider doing tomorrow morning? What what's something that they should sort of, you know, put on their radar right away? Mike Nelson (58:29) Yeah, I would start looking into how do you verify integrity of images? Are you gonna have, are you gonna rely on people sitting down and looking and saying, this looks like this has been digitally altered? Or do you have systems and technology in place that allows you to make the right decision and allows you to make a confident decision of trust? human eyes are no longer good enough to detect. modification and changes. You need the right technology. And I'm really excited the future and the things that are coming. Digisearch's right at the the heart of it. And we're excited about the opportunities to help organizations to deploy this level of trust to digital content and, you know, be interesting. We should revisit this conversation in a couple of years and and see where the world is. Martin Hinton (59:19) Sounds good. Sounds good. Well, listen, Mike Nelson, field CTO at Digicert. Thank you so very much for the time and attention today. Everyone else, thank you for listening and tuning in, if that's in case in fact how you watched. We mentioned a few things. There'll be some links in the show notes to some of those resources as well as links to to Mike and Digicert so you can find him. If you've got a question or a comment, please leave it below and we'll get an answer to you or we'll we'll pull Mike in and see whether he's got an answer for you. And that's it. Martin Hinton. Executive Editor Cyber Insurance News Information. Thanks so much for your time. Enjoy the rest of your day.