Identity, IAM Technologies, Data Security, Encryption

San Francisco’s ‘Waymo Freeze’ last month uncovered the next identity challenge

Waymo autonomous Jaguar electric SUV equipped with roof and side sensors parked roadside, representing self-driving vehicle technology and transportation innovation

COMMENTARY: In December 2025, San Francisco became the stage for a modern technological paradox: Responding to a local power outage, a fleet of Waymo autonomous vehicles came to a grinding halt, creating a freeze that rippled through the city.

On paper, the system worked perfectly. The vehicles were digitally secure, they weren’t compromised by a malicious actor and they followed their programmed safety protocols to the letter. Yet, in the physical world, they created a massive infrastructure failure, blocking emergency responders and paralyzing public transit.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

The incident serves as a wake-up call for the cybersecurity industry, revealing that we have reached a tipping point of cryptographic debt. For the last decade, we have focused almost exclusively on securing the identity of devices – ensuring we know exactly who or what machines are. But in doing so, we have dangerously neglected their operational continuity. To prevent the next freeze, we must move beyond static identity and toward a more resilient, dynamic continuum of trust. 

The trap of static identity

Traditionally, we have relied on public key infrastructure (PKI) to deliver a "digital handshake." This handshake establishes a foundation of trust, but it’s inherently static. Once a device gets authenticated and "trusted," the industry has largely assumed it will continue to behave correctly. 

The San Francisco outage exposed the flaw in this logic: traditional PKI doesn't offer instructions for when that handshake gets broken. When these vehicles encountered a variable they couldn't process, such as traffic signals that shut down, they defaulted to a "fail-safe" mode. In a vacuum, stopping is safe. In an urban ecosystem, a fleet of unmovable objects becomes a hazard.

We need to evolve toward systems that don't just ask: "Who are you?" We need architectures that constantly evaluate, "What are you authorized to do right now in this specific context?" This shift from static identity to dynamic, context-aware authorization is the only way to ensure safety in environments where human lives are on the line. 

High stakes of operational continuity

The lessons learned in San Francisco extend far beyond the automotive sector. As we integrate autonomous systems into the backbone of our society, the identity-only model creates systemic risks across other high-stakes verticals. Consider situations such as:

  • Remote surgical robotics: In a telesurgery environment, a momentary loss of cloud connectivity cannot result in a "freeze" of the instrument. The system must have the local cryptographic authority to continue the procedure safely without a continuous back-end handshake.
  • Smart grid infrastructure: Automated distribution switches must balance load-leveling with emergency overrides. If an outage occurs, these devices cannot wait for a centralized "all-clear" if the communication lines are down; they must have pre-validated, local trust protocols to prevent a total grid collapse.
  • Automated logistics and warehousing: In massive fulfillment centers, dozens of heavy machines coordinate movements in high-speed choreography. If the facility’s local network dips, these machines must have the intelligence to avoid collisions and find a safe egress without a central "brain" to guide them.

Solving for cryptographic debt and visibility

The San Francisco incident also highlighted the burgeoning issue of cryptographic debt: the accumulated burden of unmanaged keys, certificates and secrets that organizations have ignored in favor of rapid deployment. Many organizations today suffer from "hidden secrets" buried deep within their firmware or legacy systems. During the San Francisco outage, the inability to quickly reroute or re-authorize those vehicles was likely hampered by a lack of visibility into the cryptographic assets governing those machines.

When we have opaque security, we inevitably get a sluggish response. Today, operators require a “single pane of glass” view of their entire security posture. For cyber pros, this means moving away from siloed certificate management and toward integrated platforms that offer real-time visibility from the semiconductor level to the operational field. If we cannot see the expiration, origin or permission set of a key, we cannot pivot when the physical environment fails.

In other words, we must adopt a Secure-by-Design philosophy that creates a continuum of trust. It’s security that travels seamlessly from the silicon chip to the cloud – rather than existing only at the endpoints. 

The goal of our industry must shift as we move into 2026. It’s no longer enough to build connected products; we must build resilient ones. True leadership in this era of autonomous technology means ensuring that our mission-critical systems have the autonomy to act wisely when they are most alone.

By paying down our cryptographic debt and moving toward a dynamic continuum of trust, we can ensure that when the world goes dark, our machines have the baked-in intelligence to keep the world moving.

David Sequino, chief executive officer, Integrity Security Services

SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

You can skip this ad in 5 seconds