At Black Hat USA 2026, the conversation around identity security has shifted from a technical afterthought to the industry’s central battleground. Attackers today rarely need to “break in” — they simply log in, using stolen credentials, hijacked sessions, or manipulated approvals that look entirely legitimate on the surface. Layer in the rise of deepfake impersonation and autonomous AI agents capable of executing consequential actions at machine speed, and it’s clear why security leaders are rethinking what it actually means to verify a human being. VMblog sat down with Kevin Surace, CEO of Token, ahead of the show to discuss how his company is addressing this shift.
Token positions itself as the biometric identity assurance company, built on a simple but consequential premise: proving someone possesses a credential is no longer enough — proving they are physically present is what matters now. Through its TokenCore platform and three form factors — the Wearable ring, the Portable security key, and the enterprise-grade Node — the company aims to close the gaps left by passkeys and conventional MFA, placing a biometric “hard gate” around privileged access, financial transactions, and even AI agent-initiated actions. In this pre-show Q&A, Surace unpacks why he believes video conferencing has become a new battleground for executive impersonation, why asking one AI agent to verify another is a flawed premise, and what he thinks should top every security leader’s priority list for the remainder of 2026.
++
VMblog: For readers who may not be familiar, give us the elevator pitch. Who are you, what do you do, and what genuinely sets you apart in today’s crowded cybersecurity market?
Kevin Surace: Token is the biometric identity assurance company. We make human identity provable and nontransferable by combining an on device fingerprint match, cryptographic authentication, and physical proximity. TokenCore strengthens the IAM, SSO, and PAM systems enterprises already use through three form factors: the Wearable biometric ring, the Portable security key, and the Node for enterprise, government, classified, and air gapped environments. The market is already moving away from passwords and codes toward passkeys and local user verification. Token completes that journey by requiring the authorized person, not merely a credential or device, to be present. Identity. Zero Doubt.
VMblog: The threat landscape heading into Black Hat 2026 looks very different from even 18 months ago. Which specific threat vectors, whether agentic AI attacks, identity based intrusions, critical infrastructure targeting, or something else, is your solution most directly built to address?
Surace: Attackers increasingly do not break in. They log in with credentials, sessions, and approvals that appear legitimate. TokenCore is built to stop identity based intrusions, phishing, credential sharing, remote relay, session misuse, deepfake impersonation, and unauthorized actions by AI agents. The Wearable is designed for continuous daily use, Portable brings biometric assurance across workstations and mobile workflows, and Node extends local cryptographic identity assurance into critical infrastructure, classified systems, and air gapped environments. Even when credentials are stolen or an agent is manipulated, access still requires the fingerprint and physical presence of the authorized individual.
VMblog: Agentic AI is reshaping both offense and defense. How is your company building security for and with autonomous AI systems, and what risks are you most concerned enterprises are underestimating right now?
Surace: Autonomous agents can now transfer money, delete records, change privileges, expose data, and deploy software. Token places a biometric hard gate around those consequential actions. The agent can work at full speed until it reaches a policy controlled boundary, where the actual transaction stops and the specifically authorized human must approve it with an on device fingerprint. This control sits outside the agent’s reasoning environment, which is critical. Asking another agent to approve an action is simply asking more software for another opinion, and that agent may be influenced by the same poisoned context or prompt injection. Token provides a deterministic outcome: no verified human, no execution.
VMblog: Identity has become the new perimeter, and attackers know it. How has your approach to identity security, authentication, or access management evolved, and what are organizations still getting dangerously wrong?
Surace: Identity security must evolve from verifying possession to proving the person. Passkeys are an important improvement because they eliminate passwords and resist conventional phishing, but passkey deployments can still be compromised around the edges through cloud synchronization, compromised devices, weak account recovery, PIN fallback, or stolen sessions. A passkey proves that a credential was available. Token proves who is using it by requiring a fingerprint on dedicated hardware with no PIN fallback, while domain binding and proximity confirm where the authentication is happening. Organizations are dangerously wrong when they treat one successful login as sufficient proof for an entire session. Identity should be reverified when access or an action carries real consequence.
VMblog: What is the most significant cybersecurity blind spot you are seeing across your customer base right now, and how does your technology address it?
Surace: The largest emerging blind spot is that organizations still trust what they see and hear on a video conference. Face and voice are now reproducible, making Zoom, Teams, and other collaboration platforms a new battlefield for executive impersonation, fraudulent payment requests, credential resets, and sensitive disclosures. Facial recognition and voice recognition cannot independently solve a threat built from cloned faces and voices. Organizations need an external proof of identity, such as TokenCore’s on device fingerprint verification, cryptographic authentication, and proximity assurance, before someone joins a sensitive meeting or authorizes a consequential action. In the deepfake era, seeing and hearing someone is no longer proof that the person is real.
VMblog: Security teams are being asked to do more with tighter budgets and leaner headcounts. How does your solution help security leaders justify ROI and actually reduce operational burden rather than add to it?
Surace: TokenCore produces measurable ROI while reducing work for both employees and security teams. Moving from a thirty second login to a two second biometric login saves twenty eight seconds every time. At twenty logins per employee per day, that returns more than nine minutes daily and over thirty four hours annually. At a fully loaded labor cost of sixty dollars per hour, that is approximately two thousand fifty dollars in recovered productivity per employee each year, before counting fewer password resets, fewer help desk tickets, and reduced breach exposure. Employees love the two second experience because there are no passwords, codes, phones, or approval prompts, so compliance becomes the easiest path. Wearable, Portable, and Node also let organizations match the form factor to the employee and environment.
VMblog: What should be sitting at the very top of every security leader’s priority list in the second half of 2026?
Surace: The top priority for every security leader in the second half of 2026 should be making biometric assured identity mandatory wherever the business cannot afford a false identity or unauthorized action. That includes privileged access, financial transactions, credential recovery, production changes, critical infrastructure, sensitive video conferences, and actions initiated by autonomous agents. Organizations should allow routine work to move quickly while placing biometric hard gates around the moments that can create irreversible damage. The winning security model will not ask whether a credential appears valid. It will prove that the correct human is physically present and intentionally authorizing the action.
##






