In the interview with Markus Soppa, Managing Director of filancore

The Internet of Things (IoT) is growing rapidly, but with increasing connectivity comes a rising risk of cyberattacks. Traditional security models are reaching their limits, while innovative approaches like Self-Sovereign Identity (SSI) herald a new era of digital identity security.
In an exclusive interview with Silicon Valley Europe, Markus Soppa, Managing Director at filancore and an expert in IoT security and identity management, discusses the challenges and opportunities of this development. He explains how decentralized identities (SSI) not only revolutionize control over digital identities but also strengthen security and trust in IoT environments. He also addresses why traditional security models are no longer sufficient for IoT and how filancore provides new solutions.
Another key topic is the importance of open standards for the scalability and interoperability of IoT systems. Soppa explains how filancore helps companies meet regulatory requirements such as the Cyber Resilience Act and ensure compliance. Additionally, the role of data integrity and immutability for trustworthy IoT interactions is highlighted. The interview offers fascinating insights into the strategies and technologies filancore is developing to make the IoT ecosystem safer and more efficient.
Silicon Valley Europe: Mr. Soppa, filancore places strong emphasis on the concept of Self-Sovereign Identity (SSI). Could you explain how this approach works and why it is so crucial for IoT environments?
Markus Soppa: I’d be happy to. Self-Sovereign Identity – or SSI for short – takes the approach of no longer managing identities centrally but instead anchoring them decentrally and sovereignly with the respective entity. This means that a device, a vehicle, or even a machine can have its own digital identity and communicate securely with other actors – independently of central security platforms or cloud services.
Especially in IoT, where millions – or even billions – of devices interact with each other, security is a key success factor. Traditional solutions and models reach their limits in these scenarios: they are not designed for these dimensions and come with dependencies and security risks that simply cannot be reconciled with modern, data-driven business models.
Self-Sovereign Identity (SSI) enables the establishment of trust relationships directly between machines—scalable, secure, and data-sovereign. This creates the foundation for an autonomous and interoperable IoT ecosystem that benefits both businesses and consumers alike.
Silicon Valley Europe: Why do conventional security models reach their limits in IoT? What specific vulnerabilities exist, and how can SSI provide a solution?
Markus Soppa: Conventional security models in IoT often rely on centralized trust anchors—such as individual certificate authorities or security services. These approaches are not only susceptible to single points of failure but are also difficult to scale and highly resource-intensive. Additionally, interoperable access controls are frequently lacking, which poses a significant challenge in highly networked systems operating in complex environments with numerous actors and third-party devices.
SSI addresses these issues on multiple levels. First, we eliminate central dependencies by ensuring that each device has its own unique identity, cryptographically secured and publicly verifiable. Second, based on this, essential mechanisms such as authentication and permission assignment can be implemented, which also function across ecosystems and contextually—e.g., granting access only to specific services, individuals, purposes, or for defined time periods. Third, SSI enables devices to audit the data they send. Anyone, even without our platform, can verify the data’s origin, generation time, and integrity. This not only enhances security but also increases flexibility in industrial applications and partner exchanges.
Silicon Valley Europe: Trust in connected systems is a critical factor. How does filancore ensure with its solutions that companies can create secure and reliable IoT environments?
Markus Soppa: Trust is established when systems behave as expected and their processes are traceable. Self-sovereign identities enable exactly this: We create the foundation to reliably verify in the digital world whether someone—or something—is truly what it claims to be. Interactions are clearly regulated, and shared data remains verifiable and transparent for all parties involved.
That’s precisely what we’re working on at filancore. Our solutions enable companies to create tamper-proof identities for each IoT device and make these usable in the form of so-called Verifiable Credentials. These digital attestations are standardized statements from one identity about another—interoperable and verifiable at any time—that are exchanged bidirectionally between participants, for example, between two machines.
We provide tools that allow companies to easily integrate these new identity technologies and standards into their IoT use cases and manage them automatically—including lifecycle, infrastructure, role, and rights management. This not only ensures security and future viability but also helps comply with various regulatory requirements. Our goal is to make IoT secure and open to unlock its full potential for businesses.
Silicon Valley Europe: Many companies struggle with integrating and connecting different IoT systems. How important are open standards for the interoperability of IoT devices and data, and how is filancore involved in this area?
Markus Soppa: Open standards are key to the future viability of IoT. In an environment where devices and data from a wide range of manufacturers must communicate with each other, interoperability is not an option but a necessity. We already support numerous customers with questions about autonomous systems based on AI agents. Proprietary solutions lead to siloed systems, high integration complexity, and ultimately security gaps.
We deliberately build our solutions on open protocols such as DID (Decentralized Identifiers) and Verifiable Credentials – both of which comply with W3C standards. This allows seamless integration into existing ecosystems and gives our customers the assurance that their systems remain future-proof and scalable.
Silicon Valley Europe: With the Cyber Resilience Act, the EU is setting new standards for cybersecurity. How is filancore supporting companies in meeting these regulatory requirements?
Markus Soppa: The Cyber Resilience Act is an important step toward a secure digital single market for internet-enabled products. It requires manufacturers and operators to ensure comprehensive protection of their products throughout their lifecycle – from development to end-of-life – a requirement that many products have only minimally addressed in terms of security design until now.
Our SSI-based solutions enable companies to easily implement identity and access management according to the principle of “Privacy and Security by Design.” By uniquely identifying and managing the lifecycle of devices, manufacturers can define who is allowed to do what and when. In addition, we support both data authenticity and integrity as well as a secure software update process for these devices. This allows our solutions to implement both preventive and reactive security measures technically – a real added value for CRA compliance and resilience.
Silicon Valley Europe: Can you give us specific examples from practice where companies are already successfully using filancore’s solutions?
Markus Soppa: A concrete example is our collaboration with ETO GRUPPE – a leading German automotive supplier and IoT system provider. ETO uses Self-Sovereign Identity to secure its products – completely dispensing with a classic Public Key Infrastructure.
Smart healthcare products are already equipped with a digital identity at the end of the production line. This creates a digital basis of trust right from delivery and initial commissioning. Customers and partners of ETO GRUPPE can thus ensure that they are dealing with an original product. When switched on for the first time, the product identifies itself clearly and registers itself, so that in the next step, ownership, access rights and necessary firmware updates can be clearly assigned and controlled via our platform.
Most of these processes run fully autonomously. By using SSI, we were able to significantly shorten integration times, increase security and considerably reduce the administrative workload for the security department.
Relieving the security department was just one aspect. In a very short time – and already with the first product integration – ETO GRUPPE’s decision to use SSI has clearly paid off. This was particularly evident at the financial level: the savings achieved compared to classic Public Key Infrastructures exceeded the initial investment many times over. In addition, the open, interoperable approach of SSI opens up new business potential – for example through expandable services, seamless integration with partner ecosystems or the ability to develop new data-based business models.
Silicon Valley Europe: How do you see the future of IoT security and identity management? What developments do you expect in the coming years, and what role will filancore play?
Markus Soppa: We are at a turning point: the digital infrastructure of the future will require distributed, dynamic and autonomous systems – and this calls for a rethink in identity and security management. I am convinced that decentralized identities will establish themselves as the new standard in IoT.
At the same time, it will become increasingly important not only to authenticate machines, but also to dynamically assign them roles, rights and trust contexts – automated, standardized and compliant. This is exactly where our role at filancore comes in: we want to provide the backbone for a secure, self-sovereign and interoperable machine economy in Europe and beyond. Our focus is not only on technology, but also on actively shaping industrial standards, regulatory processes and ecosystems.