Organisations should treat liveness detection and facial biometrics as one control in a layered identity verification stack, not a standalone cure. Deepfakes can impersonate people convincingly, while passwords and OTPs are easy to steal or intercept. The practical goal is to bind the presented face to a trusted identity record in real time, then combine that check with risk-based monitoring and step-up controls.
How liveness and facial biometrics should fit into the authentication flow
Liveness detection is most effective when it is used to answer a narrow question, whether the person presenting the face is physically present and the capture is genuine. Facial biometrics then compare that live sample to a trusted reference, but they should be treated as an assurance step, not a complete trust decision. That means the organisation still needs device, session and transaction context around the biometric result.
The practical design choice is to use the face check to reduce impersonation risk at login or step-up moments, while keeping recovery paths, enrolment, and administrative changes under stronger controls. For identity programmes, the same principle applies to lifecycle and governance, not just initial verification, as shown in NHIMG’s Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs and the broader NHI Lifecycle Management Guide.
Biometrics also introduce a different failure profile from passwords. If a password is stolen, it can be rotated. If a biometric template or reference data is exposed, the organisation may have a long-lived trust problem, so the enrolment and storage model matters as much as the matching engine. That is why high-risk deployments should use biometric assurance in conjunction with explicit risk scoring, not as the sole gate for privileged access.
Why passwords and one-time codes are not enough against deepfake impersonation
Passwords and OTPs remain useful, but they are weak as a standalone answer to deepfake-driven social engineering. A convincing synthetic face, voice, or video can carry the conversation far enough to trigger a reset, enrol a new factor, or persuade an operator to bypass normal steps. OTPs are especially vulnerable when attackers can intercept them through phishing, SIM swap, session theft, or helpdesk manipulation.
The right response is to reduce the amount of trust placed in a single proof of possession or memorised secret. Organisations should prefer layered verification that combines the biometric signal with device binding, behavioural or transaction risk, and step-up review for sensitive actions. For deeper threat context, the attack paths and compromise patterns in The 52 NHI breaches Report, Microsoft Midnight Blizzard breach and MGM Resorts Breach 2023, Scattered Spider illustrate how trust in human-facing verification can be abused when stronger controls are missing.
Deepfake defence works best when the organisation assumes that a single factor may be imitated, intercepted, or socially engineered. The biometric result should therefore be one input to a policy decision, not the decision itself. In other words, the question is not whether the face matches, but whether this is the right person, on the right device, for the right action, at the right time.
Risk and Threat Considerations
Deepfake-enabled fraud creates two linked risks: false acceptance, where an impostor passes the face check, and control bypass, where the organisation over-trusts a successful biometric match and weakens the rest of the verification stack. The highest exposure is usually at account recovery, enrolment, and privilege escalation moments, because those flows often carry more trust than a normal sign-in.
Failure mechanism: An attacker uses synthetic media to defeat human judgment, then leverages passwords or OTPs only as a fallback path, or uses the biometric success to push the operator or system into granting a higher-trust session than the evidence supports.
Impact: The result can be account takeover, fraudulent enrolment of new factors, unauthorised access to sensitive systems, or an approval path that is difficult to unwind because the organisation treated a biometric match as proof of overall legitimacy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Biometric and OTP controls are part of authentication assurance. |
| Recommendation — Apply PR.AA to combine biometrics with layered authentication and step-up access decisions. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Facial biometrics and liveness affect identity proofing and binding assurance. |
| AAL — Authenticator Assurance Level | Passwords and OTPs are authenticators whose strength must be balanced with stronger checks. | |
| Recommendation — Set assurance levels that match enrolment, recovery, and sensitive access risk. Use higher authenticator assurance for sensitive actions instead of relying on OTPs alone. | ||
| CIS Controls v8 | 5 — Account Management | Deepfake-resistant verification must protect enrolment, recovery, and account changes. |
| 6 — Access Control Management | Biometric checks should feed access decisions rather than stand alone. | |
| Recommendation — Harden account lifecycle flows so biometric success cannot bypass recovery safeguards. Tie biometric results to access policy and step-up controls for high-risk sessions. | ||
| MITRE ATT&CK | T1656 — Impersonation | Deepfakes are an impersonation technique used to defeat trust decisions. |
| Recommendation — Model deepfake abuse as impersonation and test controls at the human verification boundary. | ||
Practitioner Guidance
What to prioritise: Put the strongest controls around enrolment, recovery, and step-up for high-risk transactions first. Those are the moments where deepfake attacks and social engineering usually convert a convincing presentation into lasting access.
What to verify: Confirm that the biometric system is tied to a trusted identity record, that liveness is tested under the same capture conditions users actually have, and that failed or borderline cases trigger a safer path rather than silent fallback to OTP-only verification.
Decision rule: If the action would change privilege, payout, account recovery state, or authentication assurance for an important session, require an additional contextual signal or human review. If it is a low-risk convenience flow, a biometric step may be acceptable on its own only when the downstream impact is limited.
Practitioner takeaway: The objective is not to make biometrics the new single factor, but to make deepfake success insufficient on its own by combining liveness, identity binding, and risk-based escalation.
Related resources from NHI Mgmt Group
- How should security teams reduce phishing, vishing, and smishing risk without relying only on passwords or one-time codes?
- Should organisations still use one-time passwords for MFA?
- How should healthcare organisations use facial biometrics without creating new privacy risk?
- Why do passwords and one-time codes still leave organisations exposed to identity fraud?