Featured Article : Fraud Fears Over New WhatsApp Usernames

WhatsApp’s plan to let people communicate without revealing their phone numbers has run into immediate regulatory opposition in India, turning what began as a new privacy feature into a much wider debate about online anonymity, fraud and how messaging platforms should balance privacy with security.

Give Your Username Instead Of Your Phone Number

WhatsApp has begun allowing users to reserve unique usernames ahead of a wider rollout planned for later this year. The idea is that, under a new system, WhatsApp users will be able to give someone a username instead of their mobile phone number, meaning they can communicate without revealing the number connected to their account.

WhatsApp explained the reason for the feature, saying: “Sometimes you just want to chat without handing over your digits.”

That could be particularly useful, for example, when joining community groups, meeting someone at an event, communicating with a business or speaking to someone online for the first time.

WhatsApp says the reservation process is being opened gradually because the platform has more than three billion users and many people will inevitably want similar names. Once the option becomes available, users can reserve a name through the Account section of the app’s settings.

How Will Usernames Work?

The feature is designed to provide greater privacy without making WhatsApp users publicly searchable.

It’s understood that there will be no directory of usernames and no suggestions showing people they might want to contact, and someone will need to know the exact username before they can start a conversation.

And A Key

Users will also be able to create an optional username key, providing another layer of protection against unwanted contact.

Once the full feature launches, people who have enabled a username will be able to message a new person or business without their phone number being displayed. However, a mobile number will still be required to create a WhatsApp account in the first place.

For creators, businesses and organisations that want a consistent identity, WhatsApp has also created a way to claim an existing Instagram or Facebook username.

Why Has India Intervened?

However, it seems the rollout quickly attracted regulatory attention in India, WhatsApp’s largest national market.

The Indian government has asked WhatsApp to pause the introduction of usernames in the country while consultations take place, amid concerns that the feature could make fraud, phishing and impersonation easier.

The main concern is that criminals could create usernames resembling those of banks, government departments, businesses or well-known individuals and then use them to contact potential victims without displaying a phone number.

This is particularly significant in India, where authorities have been trying to combat a growing problem with cyber fraud, including so-called digital arrest scams in which criminals impersonate police officers or government officials.

The government intervention came shortly after WhatsApp opened username reservations, transforming the launch from a straightforward product announcement into a test of how privacy features should be balanced against fraud prevention and law enforcement concerns.

What Does WhatsApp Say About The Risks?

WhatsApp argues that it has already built several layers of protection into the system.

High-profile usernames associated with public figures, government bodies, celebrities and verified Meta accounts have been reserved so that they can only be claimed by legitimate owners. The company says variations of well-known names are also being protected.

WhatsApp has also said it will limit the number of new people an account can contact, prevent repeated attempts to guess username keys and use its systems to identify common patterns associated with impersonation and abuse.

Recipients of messages from first-time contacts will also be given contextual information, such as whether the sender has a new account, shares mutual groups with them or is based in another country.

The company says: “We’re taking our time and listening to feedback so that when it rolls out later this year we get it right.”

A Genuine Privacy Benefit

Despite the controversy, there does seem to be quite a clear privacy argument for introducing usernames.

For example, phone numbers are increasingly used as identifiers across banking, online accounts, two-factor authentication and other digital services. Giving one to a stranger can therefore reveal more personal information than someone may realise.

Usernames provide a way to separate someone’s WhatsApp identity from their mobile number, making it easier to communicate with new contacts without immediately sharing that information.

This is particularly relevant for business networking, online marketplaces, community groups, customer enquiries and other situations where people may want to communicate without establishing a deeper personal connection.

WhatsApp summarises the thinking behind the feature by saying: “A phone number is personal and it’s tied to so many parts of your life.”

However, the challenge is that privacy features that protect genuine users can also potentially make life easier for criminals. The debate is therefore not simply about whether usernames are good or bad, but whether platforms can introduce stronger privacy without weakening trust and accountability.

What Does This Mean For Your Business?

For businesses, the introduction of WhatsApp usernames could make the platform more useful for customer communication. Employees may be able to speak with customers, suppliers or new contacts without sharing personal mobile numbers, while businesses could create a more consistent identity across WhatsApp, Facebook and Instagram.

However, the fraud concerns raised by the Indian government also highlight the growing importance of digital identity verification.

If usernames become widely used, businesses may need to be more careful about how customers identify genuine accounts. Criminals already impersonate banks, suppliers, senior executives and well-known brands, and convincing username variations could create another opportunity for social engineering.

Organisations using WhatsApp for customer service may therefore need to communicate clearly which accounts are genuine, while employees should be trained not to assume that a familiar-looking username proves someone’s identity.

The wider story here is really about the difficult balance between privacy and trust. Hiding phone numbers can protect users from unwanted exposure, but every new layer of anonymity can also create opportunities for abuse.

WhatsApp’s challenge is to prove that usernames can provide meaningful privacy without making impersonation and fraud easier. How that balance is achieved could influence not only the future of WhatsApp, but also how messaging platforms around the world design privacy features in the years ahead.

Security Stop-Press : Staff Increasingly Relaxed About Workplace Fraud

New research from Cifas suggests some UK employees are becoming increasingly comfortable with workplace fraud and insider threats.

The survey found that 24 per cent believed it was acceptable to secretly work for a competitor, while 13 per cent admitted selling, or knowing someone who had sold, company login details.

Cifas warned the findings point to “shifting norms, blurred boundaries, and rising risks to organisational integrity”, with insider threats becoming a growing concern for employers.

For businesses, the report reinforces the need for stronger access controls, staff training, and better monitoring of insider risks, as cybercriminals increasingly target employees as a route into company systems and sensitive data.

Security Stop-Press: Scam Ads Reported On YouTube As Fraudsters Exploit Ad Slots

Users in several countries say they are seeing a rise in misleading adverts on YouTube, including fake government schemes, miracle health claims, inappropriate content and AI-generated promotions that lead to suspicious websites.

Many of the ads redirect to imitation news pages or fake portals designed to collect personal information or small payments. Viewers say the scams often look polished, making them harder to spot at a glance.

Security researchers warn that criminals are using malvertising techniques to slip fraudulent ads into YouTube’s automated auction system. Cheap AI tools make it easy to generate endless scam variations that bypass basic checks, even as billions of harmful ads are removed each year.

Businesses can reduce exposure by training staff to recognise suspicious promotions, avoiding links in untrusted ads and using browser protections that block known malicious domains. Clear reporting routes and strong account security help limit the chances of employees being caught out.

Security Stop-Press: AI Deepfake Receipts Spark Expense Fraud Concerns

Experts are warning AI-generated receipts are now so convincing that they could be used to cheat company expense systems.

OpenAI’s latest image generator, part of its ChatGPT 4o model, allows users to create fake receipts in seconds, complete with logos, stains, and creases. Online examples show how easily these images can bypass expense software, raising concerns among security experts.

For example, AI researcher Raphael Chenol has reported demonstrating how altering dates and prices on realistic-looking receipts now takes just seconds, where once it required graphic design skills. He warned that without safeguards, companies could soon face a flood of fraudulent claims.

Other security commentators say the risk isn’t limited to employee expense claims. It seems there are growing concerns that criminals could impersonate staff, submit fake receipts, and trick finance teams into making payments, particularly when paired with email-based scams targeting company accounts.

Although OpenAI says its images contain metadata showing they’re AI-generated, this can be removed. The company has defended the tool’s flexibility, saying it can also be used for education and creative work.

To reduce the risk, experts recommend multi-step approval processes and secure digital verification methods. As deepfake receipts become harder to spot, companies will need to rely less on visual checks, and more on trusted, auditable systems.

Security Stop Press: Black Friday Scam Emails Surge to 77 per cent Fraudulent

Cybersecurity company Bitdefender’s Antispam Lab reports that 77 per cent of Black Friday-themed emails in 2024 are scams, up from 70 per cent in 2023.

Bitdefender reports that these scams target consumers worldwide, with the US and Europe receiving 38 per cent and 44 per cent of such emails respectively. Two-thirds of these messages originate from the US, with significant activity also traced to Europe and Asia.

Scammers are tailoring their attacks to diverse demographics. For example, tech enthusiasts in Spain were targeted with malware-laden emails impersonating Fnac, delivering the Grandoreiro banking Trojan. Fashion shoppers received phishing emails promoting fake Ray-Ban discounts, while survey scams exploiting brands like Tesco and Costco sought sensitive details from grocery shoppers.

The variety of tactics, from counterfeit luxury goods to phishing surveys, demonstrates how cybercriminals are now exploiting regional and consumer preferences to maximise their reach.

Businesses can reduce their exposure by employing robust email filtering systems, training staff to spot phishing attempts, and using advanced security tools to flag suspicious links and emails. Regular updates to security protocols and proactive awareness campaigns are essential to staying ahead of these evolving threats.

Featured Article : Musical Misconduct

In a first-of-its-kind case, a US musician has been charged with fraud for allegedly using thousands of automated bot accounts to stream AI-generated tracks from which he made more than $10m in royalty payments.

Which Tracks? 

The music tracks that 52-year-old Michael Smith from North Carolina in the US allegedly used came from a co-conspirator, a music promoter, and the CEO of an AI music company, who (from 2018) supplied him with hundreds of thousands of AI-generated songs – songs described as “instant music” by the alleged co-conspirator.

Uploaded To Music Streaming Platforms 

Smith then allegedly uploaded these tracks to music streaming platforms like Spotify, Apple Music, Amazon Music, and YouTube Music. Typically, when songs are uploaded to music streaming platforms, the artists earn royalties based on the number of streams their songs receive.

Then Used Automated Bots To Inflate The Number of Streams 

In the case of Mr Smith, the allegation is that he then used “bots” (automated programs) to stream the AI-generated songs billions of times. The indictment says that, at the height of his alleged fraudulent scheme, Mr Smith “used over a thousand bot accounts simultaneously to artificially boost streams of his music across the Streaming Platforms”. It’s alleged that by manipulating the streaming data in this way, Smith was able to fraudulently obtain “more than $10 million in royalty payments to which he was not entitled”.

How Royalties Work Via Music Streaming Platforms

Royalties paid to songwriters, composers, lyricists, and music publishers (“Songwriters”) are funded by streaming platforms like Spotify and Apple Music. These platforms allocate a percentage of their revenue (called the “Revenue Pool”) to performance rights organisations (PROs) and the Mechanical Licensing Collective (MLC). PROs manage performance royalties, while the MLC handles digital mechanical royalties for reproducing and distributing songs. The streaming platforms send both streaming data and revenue to these organisations, which then distribute royalties proportionally to the Songwriters based on the number of streams their songs received.

Similarly, performing artists and record companies (“Artists”) receive royalties from a separate pool, also funded by a percentage of streaming platform revenues. These funds are allocated based on the total number of streams each artist’s recordings receive, and the royalties are typically paid to Artists through record labels and distribution companies.

Why Fraud? 

Streaming fraud, using bots to inflate stream numbers, diverts royalties from legitimate creators to those engaging in fraudulent activity. In this case, the allegation is that Michael Smith committed fraud by making false and misleading statements to streaming platforms, the above-mentioned performance rights organisations (PROs), and music distribution companies. It’s been alleged that his intent was to conceal a massive streaming manipulation scheme, where he used bots to inflate the number of streams for AI-generated songs. By doing so, prosecutors say that Smith used deceptive practices, to fraudulently divert royalties meant for legitimate creators who earned their revenue through real consumer engagement / real listeners (not automated bots).

Technology Improved Over Time 

Emails obtained from Smith and other participants in the scheme, also appear to show how the technology used to create the tracks improved over time, thereby making his scheme more difficult for the streaming platforms to detect. For example, an email from February shows Mr Smith claiming that his “existing music has generated at this point over 4 billion streams and $12 million in royalties since 2019.”

Not The Only Case Of This Kind 

Although prosecutors in this case have described it as the first criminal case of its kind, it’s not the only music platform streaming fraud case of recent years. For example:

– The Danish executive case (2024) where a Danish executive got an 18-month prison sentence after using bots from 2013 to 2019 to inflate streams on platforms like Spotify and Tidal, earning around $635,000 in fraudulent royalties.

– The Boomy AI fraud incident (2023) where Boomy, an AI music startup, had millions of its tracks blocked by Spotify due to suspected bot-driven streaming fraud, leading to increased scrutiny of AI-generated music on platforms.

– The Tidal fake streams investigation (2019), where Norwegian authorities investigated Tidal (a global music streaming platform) for allegedly inflating streams for artists like Beyoncé and Kanye West by hundreds of millions, resulting in massive royalty payouts and one of the largest streaming fraud cases to date.

Other AI-Related Music Incidents of Note 

It’s not just using bots to inflate streams on platforms that have caused AI-driven problems in the music world. For example:

– In 2023, a song titled “Heart on My Sleeve” featuring AI-generated voices that mimicked ‘Drake and The Weeknd’ (a Canadian singer/songwriter) went viral on platforms like TikTok and Spotify. Created by a user named Ghostwriter977, the track accumulated millions of streams before being pulled from streaming services following a complaint from Universal Music Group (UMG). UMG argued that the AI technology used to clone the artists’ voices breached copyright law and harmed the rights of real artists. Despite its removal, the incident highlighted growing concerns over the use of AI in the music industry and its potential legal implications.

– In April this year, over 200 prominent artists including Billie Eilish, Chappell Roan, Elvis Costello, and Aerosmith, signed an open letter calling for an end to the “predatory” use of AI in the music industry. This letter, coordinated by the Artist Rights Alliance, highlighted concerns that AI technology is being used irresponsibly to mimic artists’ work without permission, undermining creativity, and devaluing musicians’ rights. The artists warned that AI models are being trained on their copyrighted work without consent, with the potential to replace human artistry and dilute the royalties that artists depend on. They called for developers and platforms to commit to avoiding AI usage which infringes on artists’ rights or denies them fair compensation.

Can Tech Firms Steal Your Voice? 

In an interesting AI-related case of a notable class action lawsuit filed in 2024, voice actors Paul Skye Lehrman and Linnea Sage accused AI startup Lovo of illegally cloning and selling their voices without consent. The pair were originally contacted via Fiverr in 2019 and 2020, where they were asked to record voiceover samples for what they were told were “academic research” or radio test scripts. Lehrman was paid $1,200, and Sage $400, with both assured that their recordings wouldn’t be used for anything beyond these stated purposes. However, they later discovered their voices had been cloned using AI and used in commercial content without permission.

However, much to Lehrman’s surprise and shock, he heard his voice on a YouTube video about the Russia-Ukraine conflict, discussing topics he had never recorded. The irony of his situation deepened when he heard his voice again on the podcast “Deadline Strike Talk,” where his AI-generated voice was used to discuss the impact of AI on Hollywood and the ongoing strikes, i.e. issues central to the lawsuit itself! Sage similarly discovered her voice in promotional materials for Lovo. The lawsuit claims that Lovo misappropriated their voices to market AI-generated versions under pseudonyms, “Kyle Snow” and “Sally Coleman,” which damaged their careers by reducing job opportunities and potentially replacing their work entirely with AI.

This lawsuit highlights a growing concern in the entertainment industry about AI’s unchecked use to clone voices and likenesses without authorisation, raising issues of intellectual property, consent, and fair compensation.

What Does This Mean For Your Business? 

The rise of AI in the music and entertainment industry introduces both exciting opportunities and serious risks for music streaming platforms, artists, and individuals whose voices or music may be used without consent. For streaming platforms, cases like Michael Smith’s alleged fraudulent streaming manipulation expose real vulnerabilities in royalty systems, which requires platforms to implement more robust detection methods. As AI-generated content becomes more sophisticated, distinguishing between real and artificial streams will be crucial to prevent fraudulent activity that undermines royalty distribution and trust.

For artists, AI’s ability to clone voices, styles, and entire songs presents an existential challenge to creativity and ownership. The growing number of cases, including the Heart on My Sleeve incident and the lawsuit against Lovo, highlight how AI can be used to replicate an artist’s voice or music without permission. This threatens not only their revenue but also their creative integrity. This illustrates why prominent artists, as seen in the open letter signed by Billie Eilish, Chappell Roan, and others, are calling for clearer protections and industry standards i.e., to prevent AI from being used in ways that exploit human artistry without proper compensation.

Voice actors and other professionals who rely on their vocal talents are particularly vulnerable to AI voice cloning. Lehrman and Sage’s experience with Lovo illustrates how voice recordings can be misappropriated and used commercially under false pretenses, damaging careers and reducing future opportunities. This case highlights the need for businesses, especially those in the tech and entertainment sectors, to perhaps develop transparent and ethical policies around AI-generated content, thereby ensuring that creators are properly informed, compensated, and protected.

Beyond the entertainment industry, AI misuse poses a potential risk for the rest of us, especially when it comes to the unauthorised use of voices or faces. AI technology, like voice cloning and deepfakes, can be used to imitate individuals without their consent, creating the potential for serious ethical and legal challenges. For businesses, this means increased vulnerability to fraud, such as the possibility of AI-generated voices being used to impersonate employees or executives in phishing scams. Without proper safeguards, AI can become weaponised to deceive customers or commit fraud against organisations by replicating voices or faces in ways that can bypass security measures, leading to financial and reputational damage.

In response to these growing concerns, industry experts and creators are calling for stronger regulations and protections. Clear consent processes, the development of intellectual property rights linked to a person’s voice and likeness, and technological solutions for detecting fraudulent AI usage now appear to be essential. Ideally, companies and platforms now need to collaborate with policymakers and rights organisations to try and ensure that AI is used ethically, protecting the creative economy and the rights of individuals.

Security Stop Press : Beware Summer Romance Scams

The latest ‘Barclays Scams Bulletin’ highlights how more romance scams took place in July last year than any other month, as Barclays warns those looking for love to remain vigilant to potential scams. It also highlights how men appear more likely to fall victim to romance scams, while women lose 2.5 times as much money as men in romance scams.

The research figures featured in the report from Barclays show that one in three singletons (34 per cent) is more open to dating in the summer months, which may account for why July accounted for 12 per cent of all romance scam claims last year.

Kirsty Adams, Fraud and Scams Expert at Barclays, also points out where these scams are most prevalent, saying: “Social media platforms and dating apps are by far the biggest sources of romance scams, which is no surprise considering how the dating landscape has changed over the years”. 

Barclays says the advice for anyone who has been targeted is to “report it to their bank and to open up to family and friends for emotional support”.

Featured Article : 3000% Increase in Deepfake Frauds

A new report from ID Verification Company Onfido shows that the availability of cheap generative AI tools has led to Deepfake fraud attempts increasing by 3,000 per cent (specifically, a factor of 31) in 2023.

Free And Cheap AI Tools 

Although deepfakes have now been around for several years, as the report points out, deepfake fraud has become significantly easier and more accessible due to the widespread availability of free and cheap generative AI tools. In simple terms, these tools have democratised the ability to create hyper-realistic fake images and videos, which were once only possible for those with advanced technical skills and access to expensive software.

Prior to the public availability of AI tools, for example, creating a convincing fake video or image required a deep understanding of computer graphics and access to high-end, often costly, software (a barrier to entry for would-be deep-fakers).

Document and Biometric Fraud – The New Frontier 

The Onfido data reveals a worrying trend in that while physical counterfeits are still prevalent, there’s a notable shift towards digital manipulation of documents and biometrics, facilitated by the availability and sophistication of AI tools. Fraudsters are not only altering documents digitally but also exploiting biometric verification systems through deepfakes and other AI-assisted methods. The Onfido report highlights a dramatic rise in the rate of biometric fraud, which doubled from 2022 to 2023.

Deepfakes – A Growing Threat 

As reinforced by the findings of the report, deepfakes pose an emerging and significant threat, particularly in biometric verification. The accessibility of generative AI and face-swap apps has made the creation of deepfakes easier and highly scalable, which is evidenced by a 31X increase in deepfake attempts in 2023 compared to the previous year!

Minimum Effort (And Cost) For Maximum Return

As the Onfido report points out, simple ‘face swapping’ apps (i.e. apps which leverage advanced AI algorithms to seamlessly superimpose one person’s face onto another in photos or videos) offer ease of use and effectiveness in creating convincing fake identities. They are part of an influx of readily available online AI assisted tools that are providing fraudsters with a new avenue into biometric fraud. For example, the Onfido data shows that Biometric fraud attempts are clearly higher this year than in previous years with fraudsters favouring tools like the face-swapping apps to target selfie biometric checks and create fake identities.

The kind of fakes these cheap, easy apps create have been dubbed “cheapfakes” and this conforms with something that’s long been known about online fraudsters and cyber criminals – they seek methods that require minimum effort, minimum expense and minimum personal risk, yet deliver maximum effect.

Sector-Specific Impact of Deepfakes 

The Identity Fraud Report shows that (perhaps obviously) the gambling and financial sectors in particular are facing the brunt of these sophisticated fraud attempts. The lure of cash rewards and high-value transactions in these sectors makes them attractive targets for deepfake-driven frauds. In the gambling industry, for example, fraudsters may be particularly attracted to the sign-up and referral bonuses. In the financial industry, where frauds tend to be based around money laundering and loan theft, Onfido reports that digital attacks are easy to scale, especially when incorporating AI tools.

Implications For UK Businesses In The Age of (AI) Deepfake-Driven Fraud 

The surge in deepfake-driven fraud highlighted by the somewhat startling statistics in Onfido’s 2024 Identity Fraud Report, suggest that UK businesses navigating this new landscape may require a multifaceted approach. This could be achieved by balancing the implementation of cutting-edge technologies with heightened awareness and strategic planning. In more detail, this could involve:

– UK businesses prioritising the reinforcement of their identity verification processes. The traditional methods may no longer suffice against the sophistication of deepfakes. Therefore, Adopting AI-powered solutions that are specifically designed to detect and counter deepfake attempts could be the way forward. This could work as long as such systems can keep up with the advancements in fraudulent techniques (more advanced techniques may emerge as more AI sophisticated AI tools emerge).

– The training of staff, i.e. educating them about the nature of deepfakes and how they can be used to perpetrate fraud. This could empower employees to better recognise potential threats and respond appropriately, particularly in sectors like customer service and security, where human judgment plays a key role.

– Maintaining customer trust. UK businesses must navigate the fine line between implementing robust security measures and ensuring a frictionless customer experience. Transparent communication about the security measures in place and how they protect customer data can help in maintaining and even enhancing customer trust.

– As the use of deepfakes in fraud rises, regulatory bodies may introduce new compliance requirements and UK businesses will need to ensure that they stay abreast of these changes both to protect customers and remain compliant with legal standards. This in turn could require more rigorous data protection protocols or mandatory reporting of deepfake-related breaches.

– Collaboration with industry peers and participation in broader discussions about combating deepfake fraud may also be a way to gain valuable insights. Sharing knowledge and strategies, for example, could help in developing industry-wide best practices. Also, partnerships with technology providers specialising in AI and fraud detection could offer access to the latest tools and expertise.

– Since deepfake fraud may be an ongoing threat, long-term strategic planning may be essential. This perspective could be integrated into long-term business strategies, thereby (hopefully) making sure that resources are available and allocated not just for immediate solutions but also for future-proofing against evolving digital threats.

What Else Can Businesses Do To Combat Threats Like AI-Generated Deepfakes? 

Other ways that businesses can contribute to the necessary comprehensive approach to tackling the AI-generated deepfake threat may also include:

– Implementing biometric verification technologies that require live interactions (so-called ‘liveness solutions’), such as head movements, which are difficult for deepfakes to replicate.

– The use of SDKs (platform-specific building tools for developers) over APIs. For example, SDKs provide better protection against fraudulent submissions as they incorporate live capture and device integrity checks.

The Dual Nature Of Generative AI 

Although, as you’d expect an ‘Identity Fraud Report’ to do, the Onfido report focuses solely on the threats posed by AI, it’s important to remember that AI tools can be used by all businesses to add value, save time, improve productivity, get more creative, and to defend against the AI threats. AI-driven verification tools, for example, are becoming more adept at detecting and preventing fraud, underscoring the technology’s dual nature as both a tool for fraudsters and a shield for businesses.

What Does This Mean For Your Business? 

Tempering the reading of the startling stats in the report with the knowledge that Onfido is selling its own deepfake (liveness) detection solution and SDKs, it still paints a rather worrying picture for businesses. That said, The Onfido 2024 Identity Fraud Report’s findings, highlighting a 3000 per cent increase in deepfake fraud attempts due to readily available generative AI tools, signal a pivotal shift in the landscape of online fraud. This shift could pose new challenges for UK businesses but also open avenues for innovative solutions.

For businesses, the immediate response may involve upgrading identity verification processes with AI-powered solutions tailored to detect and counter deepfakes. However, it’s not just about deploying advanced technology. It’s also about ensuring these systems evolve with the fraudsters’ tactics. Equally crucial is the role of employee training in recognising and responding to these sophisticated fraud attempts.

As regulatory landscapes adjust to these emerging threats, staying informed and compliant is also likely to become essential. The goal is not only to counter current threats but to build resilience and innovation for future challenges.