enterprisesecuritymag

Veriff Persists Worldwide Expansion with the Establishment of a New Technology Hub in Barcelona

Enterprise Security Magazine | Monday, October 25, 2021

A new European technology center will enable the company to expand its product and engineering teams and its global customer reach.

FREMONT, CA: "We're thrilled to call Barcelona our next home, not only because it's a strong European tech hub, but also because it has some of the best product and engineering talent in the world," says Steblyna. "This is another critical step in our global expansion as we protect customers around the world from identity fraud, and I look forward to building another strong team in our new Veriff location." Veriff, a global identity verification company, establishes a tech hub in Barcelona for its product and technical teams. This follows on the heels of the company launching a new office in New York City in late 2019 and strengthening its presence in London earlier this year. The company continues to develop globally, now employing over 300 people from 35 different countries. Veriff, which is well on its way to meeting its goal of 500 employees by Q2 next year, will tap into Barcelona's impressive talent pool and be an active participant in the city's expanding digital scene.

Veriff is looking to expand its workforce with several new hires, including DevOps engineers, machine learning engineers, senior information security engineers, senior software engineers, ahead of design, and a senior product manager, to reach 50 workers by early next year.

Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.

Barcelona has a thriving startup environment and has received more private equity investment than Madrid, Dublin, or Amsterdam in recent years, making it Europe's fifth-largest source of venture capital. Duncan Steblyna, Veriff's VP of Product, will manage the hub, which will be staffed by several team members from the company's Estonia headquarters who will act as ambassadors for the company's ethos.

More in News

Integrated security services are gaining stronger relevance as organizations look for a single operating model for people, sites, systems and incident response. The category is no longer limited to guarding contracts or isolated surveillance installations. It is becoming a coordinated service model that links physical security, cyber exposure, access governance and risk management. The global security services market was valued at USD 412.7 billion in 2025 and is projected to grow from USD 437.9 billion in 2026 to USD 679.2 billion by 2033, according to Grand View Research. The report includes managed security services and security consulting services across sectors such as BFSI, government and defense, energy and utilities, manufacturing and retail. This matters because many organizations still run security in disconnected layers. A facilities team may manage guards and cameras, while IT manages cyber monitoring, and business leaders handle crisis response separately. That separation can slow decisions when a real incident affects offices, data systems, employees and customers at the same time. Integrated security providers are trying to close that gap. Morgan Reed Insights describes integrated security services as the delivery of interconnected physical security, cybersecurity and risk-management solutions through a unified operating framework. Its 2026-2035 market coverage includes managed security services, consulting and advisory, system integration and remote monitoring. The demand is also visible in physical security modernization. Mordor Intelligence estimates the physical security services market will grow from USD 124.82 billion in 2026 to USD 156.88 billion by 2031, with services covering areas such as access control, video surveillance, fire and life safety, professional services and managed services. For buyers, the value is not just fewer vendors. An integrated provider can help coordinate site risk assessment, visitor management, alarm handling, cybersecurity needs and emergency communications. The better integrated system provides a more informed perspective for the leadership on what is going on, who is accountable, and what actions need to be taken. This makes sense, especially in industries that have decentralized assets. Retail, manufacturers, logistics firms, hospitals and utility companies may have multiple sites. In such cases, an uncoordinated security approach may lead to inconsistent responses and different approaches to gathering evidence. What will be a problem is governance. The lack of integration will occur if the service provider simply bundles services but does not provide common procedures and reporting standards. The next phase of integrated security will likely favor providers that combine workforce, monitoring, technology and advisory support into one accountable model. Buyers need coordination, not only coverage. Integrated security services are becoming an enterprise risk-control infrastructure. Their value will be measured by whether they help organizations detect threats earlier, coordinate response faster and reduce the blind spots that come from disconnected security functions. ...Read more
Organizations are still adapting to an ever-changing security landscape and are not only faced with new challenges in terms of traditional access control methods but also with the need to operate in a digital world. Loss or theft of a password, keycard or PIN-based system could create an opportunity for unauthorized access. In response to these worries, many companies are implementing biometric control technology as a component of their enterprise safety measures. Biometric systems are more reliable at verifying identity due to the unique physical attributes they use, like fingerprints, facial recognition, iris scans or voice patterns. Biometric solutions are being used to beef up access control, secure sensitive information and enhance operational efficiency, and enterprise security leaders are investing in them. Why Is Biometric Control Technology Becoming Essential for Enterprise Security? One of the main benefits of biometric control technology is that it can be used to identify a person by a physical attribute or characteristic, such as a fingerprint, that is hard to duplicate or share with another person. Biometric systems are typically used to secure restricted spaces, such as offices, data centers, research facilities, etc. Businesses can better safeguard valuable assets and confidential information by confining access to sensitive areas to authorized users only. Biometric authentication also promotes accountability. Access events are associated with specific users, making it possible for an organization to keep an eye on when a person enters a facility and how much they use a system. This sort of traceability can help meet compliance needs and boost internal security measures. Employees no longer have to use more than one password or carry a physical access card. Quick authentication can mean quick transactions, but still a high level of security. The convenience and security that biometric technology offers make it attractive for organizations looking for an efficient security solution. The precision and reliability of biometric systems have been enhanced with the progress of artificial intelligence and sensor technology. Modern solutions can be used to achieve rapid identity verification with low false acceptance and false rejection rates. How Can Businesses Maximize the Value of Biometric Security Systems? The first step in the successful implementation is determining what type of biometric technology will meet the needs of the organization. Security requirements, number of users and the way the system will be used can vary from one environment to another and thus affect the type of authentication used. One of the other key advantages of modern biometric solutions is scalability. Many business needs grow, including more users, more locations, more levels of security, and more. And with biometric platforms, they can seamlessly add users, locations, levels of security and more. The flexibility enables businesses to adjust their security strategies without causing significant disruption to systems. Staff training can be a factor in successful adoption as well. Offering transparent information on the functioning of biometric systems and the measures taken to guarantee the protection of personal data can contribute to acceptance and alleviate privacy concerns. ...Read more
Cyber risk assessment in Canada is moving beyond periodic checklists and static vulnerability scans. As digital systems become more connected across cloud platforms, remote work environments and third-party ecosystems, the old approach to testing no longer provides enough visibility. Organizations need to understand not only where weaknesses exist but also how those weaknesses could be exploited in realistic attack scenarios. This shift is one reason AI-powered penetration testing solutions are becoming an important part of modern security strategies. Traditional penetration testing has always played a key role in uncovering exploitable gaps across networks, applications and infrastructure. However, it has often been limited by time scope and manual effort. A test may provide a useful snapshot of risk at one moment, but cyber threats do not stand still. Attack methods change quickly, and new exposures appear as systems evolve. In the Canadian business environment, where financial institutions, public sector bodies, healthcare organizations and critical infrastructure operators all face rising cyber pressure, risk assessments must become more adaptive and continuous. Why are cyber risk assessments changing in the AI era? Modern risk assessments are no longer focused only on identifying known vulnerabilities. They are increasingly designed to understand how threat actors move through an environment, which assets are most exposed, and where business disruption could occur. AI is accelerating this transition by helping penetration testing teams simulate attacks with greater speed, depth and context. AI tools can analyze large environments faster than a manual team working alone. They can map attack surfaces, identify likely paths of exploitation, and prioritize weaknesses based on how an attacker would actually use them. This changes the value of a penetration test. Instead of producing a long list of findings with equal weight, the assessment becomes more focused on business impact and real-world exploitability. In Canada, this matters because cyber risk management is becoming more closely tied to operational resilience, privacy obligations and third-party oversight. Organizations are expected to understand the risks that compromise their systems and supply chains, rather than only at the perimeter. How are AI-Powered Penetration Testing Solutions Improving Decision-Making? The biggest advantage of AI-powered penetration testing solutions is not simply automation. It is the ability to turn testing into an ongoing intelligence function rather than a one-time exercise. AI can help correlate findings across applications, endpoints, identities and cloud assets, so teams gain a clearer picture of how multiple weaknesses combine into a single meaningful threat path. This improves cyber risk assessments in practical ways. Security leaders can prioritize remediation based on attack feasibility rather than guesswork. Boards and executives receive clearer insight into exposure. Internal teams can validate whether security investments are actually reducing risk in the areas that matter most. As Canadian organizations continue to strengthen cyber resilience, the role of penetration testing is expanding. It is no longer just a technical checkpoint before an audit or compliance review. With AI in the process, it becomes a more dynamic way to measure resilience, anticipate attacker behavior and make cyber risk assessment a living part of business decision-making. ...Read more
Cybersecurity buying in Latin America becomes difficult when security coverage expands faster than internal staffing. A provider may offer a broad service catalog yet still leave gaps between detection and remediation. Executives comparing defensive cybersecurity services should look for a model that can connect those stages without creating more handoffs for an already stretched internal team. Coverage depth matters most when it maps to the attack surface actually in use. Endpoint protection alone does not address cloud applications, mobile access, identity exposure or unmanaged devices. Buyers should examine how a provider assesses the environment before proposing controls, then how it determines where EDR, patch management, DLP, cloud access controls and identity protections belong. The distinction is practical. Buying isolated tools can create duplicate alerts and weak ownership, while a risk-led design makes it easier to assign controls to specific exposure points. Continuous monitoring also needs scrutiny. A security operations center is useful only when monitoring leads to an action path. Executives should verify whether the provider can correlate events, investigate suspicious behavior, support threat hunting and escalate incidents around the clock. The service model should also make clear who owns containment and what information reaches the customer during an incident. A monitoring contract that stops at alert generation can shift the hardest part of the response back to the buyer. That distinction should be visible in escalation procedures. Contract scope deserves close reading when multiple security functions sit under one agreement. Response hours, escalation paths, reporting frequency and responsibility for remediation should be explicit before purchase. Otherwise, buyers can discover during an incident that monitoring coverage is broader than the provider’s authority to contain or correct the underlying problem. Implementation discipline can be as important as the technology itself. Defensive programs often touch workstations, servers, cloud platforms and user activity, which means weak scoping can disrupt business systems or leave controls partially deployed. Buyers should expect an initial assessment, defined objectives, implementation requirements and a work plan that can be refined before execution. Deliverables should also show what changed in the environment rather than simply confirm that a tool was installed. Clear ownership during rollout also reduces delays when technical dependencies or access requirements surface. Specialized areas can narrow the field further. Mobile application security, forensic analysis, continuous exposure management and AI-related security testing require different skills from routine device monitoring. Buyers with these requirements should determine whether expertise is available within the provider or depends on outside escalation. The same applies to incident response. A provider that can move from detection into investigation and remediation support can reduce the number of parties involved when an attack is already underway. Shield Force begins engagements by assessing the customer environment and defining the controls required before implementation. Its defensive services include EDR, DLP, patch management, cloud access security controls and identity-related protections, supported by 24/7 monitoring through its cybersecurity operations center. It also provides threat hunting, threat intelligence, forensic analysis and incident response support, while extending coverage to mobile application security and continuous exposure management. This breadth is most relevant for buyers that need one provider to handle prevention and monitoring through investigation and response without handing each stage to a separate specialist. For organizations in Latin America with limited internal security staffing, Shield Force warrants evaluation where execution depth matters as much as tool coverage. ...Read more

Weekly Brief