How to defend the full social engineering attack chain | Register for the webinar to learn more

Company

Get to Know Our VP of Sales, EMEA: Q&A with Stewart Gregory

Meet Stewart Gregory, Doppel's first VP of Sales for EMEA. Stewart shares what's really changed in the region's threat landscape, why deepfakes have made attacks personal for executives, and why fast followers are about to become fast adopters.

Get to Know Our VP of Sales, EMEA: Q&A with Stewart Gregory

Doppel is building the leading AI-native platform for social engineering defense, helping organizations detect and disrupt threats like phishing, brand impersonation, and executive deepfakes before they cause harm. As the company expands its footprint in Europe, the Middle East, and Africa, we brought on Stewart Gregory to lead that charge.

Stewart joins Doppel with 15 years in enterprise security sales, including senior roles at CrowdStrike and Tanium, where he watched the industry's "tip of the spear" shift from endpoint protection to identity and, now, social engineering.

We caught up with him a few weeks into the role to talk about what makes EMEA different, why the market's biggest brands have become case studies in what not to do, and what's holding some organizations back from acting.

Q: What's the one shift in EMEA's threat landscape over the last 12 months that most businesses haven't fully adjusted to yet?

It's AI, but it's specifically about how much AI has expanded what adversaries can do.

Enterprise customers used to think about phishing and email as the threat. Now, the way adversaries approach organizations has completely changed. It's WhatsApp, Signal, voice phishing, "quishing" via QR codes, deepfake videos, deepfake phone calls. And all of it is being coordinated by adversaries using agentic AI at scale, across multiple mediums simultaneously.

That's the shift. Point solutions that are still purely focused on email haven't caught up to that reality, and it's exactly the gap Doppel is built to close.

That's also why we're seeing investment follow, not just from VCs, but from customers. It's the same cat-and-mouse game security has always been, but adversary tactics have moved faster in the last two years than most defenses have.

Q: Do you see a gap between what leaders think they know about cyber threats and how prepared their organizations actually are?

Absolutely, and I think it comes down to a gap in the market's collective capability, not just any one company's.

Leaders sense that the technology to cope with deepfake phone calls and phishing isn't fully there yet, and recent events in the UK back that up. Recent high-profile supply chain disruptions demonstrate the scale of this vulnerability.

In one instance, a major global manufacturer suffered months of operational downtime and billions in supply-chain impact after threat actors exploited automated hiring processes using deepfake video technology. In another case, a major retail institution faced weeks of offline operations and massive revenue losses following a similar identity-based attack.

Those two incidents made the deepfake voice and video threat very real for people, and it's clearly on executives' minds.

What's newer, even in my first few weeks here, is how personal this has become for individual leaders. It's one thing when your company's brand is impersonated. It's another when it's a deepfake of you saying something you'd never say, tied to a political or religious stance that isn't true.

That's no longer a corporate problem. It's deeply personal, and I'm hearing that emotional weight from executives at companies of every size.

Q: Are you seeing specific industries or countries investing more heavily in this space right now? Is there urgency?

Security is usually the last place companies cut budget, and after last year, that's especially true in the UK. The two examples I mentioned earlier weren’t just costly incidents. They were headline, mainstream news for weeks. Events at that scale become a wake-up call for every other enterprise: you can’t stop investing in security, and it changes where you focus that investment.

I think about security in terms of "what's the tip of the spear this year." When I was at Tanium, and then CrowdStrike, endpoint detection and response was that tip of the spear, roughly 2015 through the start of COVID. If you weren't securing your laptops, servers, and points of entry, you were exposed. That technology has since matured and become widely adopted.

The next tip of the spear is social engineering. There's an old industry line: attacks have shifted from breaking in to logging in. Adversaries stopped trying to force their way past defenses and started simply finding valid credentials.

Now it's evolved again into impersonation: instead of stealing credentials outright, attackers manufacture trust so convincingly that someone hands the access over. The goal hasn't changed. It's still about logging in undetected. But the method keeps getting more sophisticated, and it increasingly runs through people rather than technology. That's the piece more and more customers are waking up to.

Q: On the flip side, where do you see hesitancy or resistance to adopting new security solutions?

People generally like to be fast followers, not first takers. That's true across most of my career, and it's especially true with something as new as deepfake defense.

Customers would rather let someone else figure it out first and then follow their lead, rather than take on the risk of being the first to adopt an unproven approach. But this space moves so fast that I think those fast followers will move quickly once the pattern is set.

The organizations most likely to go first are the larger, more resourced enterprises (the tier-one banks and tier-one players in their sectors) because they have the engineering depth to push a new technology to its limits and get it right. Once they do, everyone else tends to follow quickly. That's the pattern I've seen play out again and again over the years, and I expect deepfake and social engineering defense to follow the same curve.


Interested in learning more about how Doppel is helping organizations across EMEA defend against social engineering, deepfakes, and identity-based attacks? Get in touch with our team.

Learn how Doppel can protect your brand from social engineering attacks

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.