In Conversation With... Bobby Ford
In Conversation With... Bobby Ford
In Conversation With... Bobby Ford
In Conversation with ... Bobby Ford on the Impact of emerging technologies on social engineering attacks
Social engineering has always relied on one constant: human trust. But as emerging technologies accelerate, from generative AI and voice cloning to deepfakes and automated impersonation, that trust is being exploited at a scale and sophistication never seen before. What were once crude phishing attempts have evolved into highly believable, multi-channel deception campaigns that blur the line between what is real and what is synthetic.
At the same time, the internet itself is undergoing a fundamental shift. Identity, authenticity, and intent are no longer things humans can reliably verify with their own senses. In this new environment, organisations are being forced to rethink how they protect not just their systems, but their people, their brands, and their customers from manipulation and fraud.
In this edition of In Conversation with…, we speak with Bobby Ford, Chief Strategy and Experience Officer at Doppel, about how emerging technologies are reshaping the social engineering threat landscape. Drawing on his experience across cybersecurity leadership and digital trust, Bobby shares his perspective on how attackers are evolving, why traditional defences are no longer enough, and what organisations must do to stay ahead in an era of AI-driven deception.
Setting the Scene
Q1: Bobby, social engineering has always been about exploiting human trust. How do you see that dynamic evolving as technologies like generative AI and deepfakes become mainstream?
[Bobby Response:]
Social engineering has always exploited trust, but generative AI and deepfakes dramatically raise the level of realism. It’s now far easier for attackers to convincingly impersonate colleagues, executives, or trusted brands — with far less effort and far greater scale.
What’s really changed is how personalised these attacks have become. Messages can reference real people, real work, and real context, making them feel authentic rather than suspicious. Social engineering is no longer limited to email, we’re seeing multi-channel attacks that play out across email, social media, messaging platforms, and even voice — mirroring exactly how we work day to day.
When deception looks real, feels personal, and shows up in trusted channels, trust itself becomes the attack surface.
Q2: What’s the biggest misconception organisations still have about social engineering in 2026?
[Bobby Response:]
The biggest misconception is that social engineering is an email problem. Many organisations still believe that if email is well protected, they’re largely covered, but as I said previously these attacks now span across multiple channels, email is just one entry point.
There’s also an overreliance on training as a silver bullet. Awareness training is important, but it can’t keep pace with highly realistic, AI-driven attacks that are designed to bypass human judgment in moments of pressure or urgency. When organisations treat training as “job done,” they shift responsibility onto individuals rather than fixing systemic gaps.
Ultimately, social engineering isn’t a people problem — it’s a trust and identity problem. Expecting employees to always spot deception in an increasingly synthetic world is unrealistic. Defence has to move beyond education and into continuous detection, protection, and support for the humans in the loop.
The Tech Shift
Q3: How are emerging technologies, such as AI-driven voice synthesis to large-scale language models, changing the scale and precision of social engineering campaigns?
[Bobby Response:]
Emerging technologies are changing social engineering in two fundamental ways: scale and precision. On the scale side, the volume of attacks is increasing dramatically. AI removes many of the time and resource constraints attackers once faced, allowing campaigns to be launched at a speed and breadth that simply wasn’t possible before.
When it comes to precision, these attacks are no longer generic. Large language models and automated data gathering enable hyper-personalisation at scale. What once required days or weeks of researching a target, understanding their role, relationships, and behaviour, can now be done in seconds. Attackers can focus on very specific details about an individual, making each interaction feel legitimate and highly relevant.
The result is a dangerous shift: more attacks, delivered faster, and tailored to exploit exactly who someone is and how they work. Making modern social engineering so effective and so difficult to detect.
AI-fueled activity has exploded: estimates suggest AI‑enabled cyberattacks have increased by more than 4,000% over the past three years, and recent analyses indicate that more than four out of five phishing emails sent in late 2024 and early 2025 showed clear signs of AI involvement.
Q4: Doppel’s technology focuses on digital identity and trust. How does that translate into defending against these modern, AI-powered deception tactics?
[Bobby Response:]
At its core, Doppel is focused on helping organisations understand and differentiate digital identities, determining which identities are legitimate and which are being used deceptively. In a world where AI makes impersonation easy, that distinction becomes critical.
Rather than putting the burden on individuals to spot deception, we focus on identifying malicious identities and activity across the digital landscape. Once those threats are detected, we work to disrupt, dismantle, and take down impersonation campaigns before they can be used to deceive employees, customers, or partners.
By restoring clarity around digital identity and trust, we help organisations move from reacting to social engineering attacks to proactively preventing them, even when those attacks are powered by AI and designed to look authentic.
The Human Factor
Q5: Even as tools get more advanced, people remain the entry point. What do you believe is the future of security awareness and behaviour change in this new environment?
[Bobby Response:]
I think it’s time to be honest: traditional security awareness, as we know it, is dead. It’s built on the assumption that individuals can reliably tell what’s malicious and what isn’t. That assumption no longer holds in a world of generative AI.
When AI can produce emails, voices, images, and even videos that are indistinguishable from reality — look at tools like Sora and the quality of videos it's creating — asking people to “spot the fake” is unrealistic. We’re moving into an environment where even highly trained professionals won’t be able to trust their own judgment consistently.
So the future isn’t about forcing more behaviour change or putting more pressure on individuals. It’s about putting the right controls in place, controls that can detect deception, verify identity, and reduce risk before a human ever has to make a decision. People will always be part of the process, but they shouldn’t be the last line of defence in an increasingly synthetic world.
Q6: How can organisations foster a culture of digital skepticism without creating fear or friction?
[Bobby Response:]
It starts with giving people confidence, not fear. And I know I keep coming back to this, but it’s important to drive it home: the right controls around individuals change everything. When employees know they’re protected, they’re far more likely to engage thoughtfully rather than operate in a constant state of suspicion.
The most critical part of trust is knowing that the technology has already done the hard work. Checks have been run, identities validated, and signals filtered, so the end product that reaches an employee is legitimate. When a tool takes on that responsibility, people don’t have to second-guess every interaction and can get on with their jobs.
That’s how you foster a culture of digital skepticism without friction: by shifting from “don’t trust anything” to “trust, but verify and verification happens by default.” The goal isn’t to make people paranoid, it’s to create a culture of confidence where employees can focus on their work, knowing the organisation has put the right protections in place around them.
The Business and Strategy Lens
Q7: How does Doppel connect the dots between user experience, trust, and security resilience?
At Doppel, our vision for social engineering defense is to create a platform that shields users, so most attacks are prevented before they even become a decision point for a human. Instead of asking employees to become full-time threat analysts, we unify signals across domains, social, messaging, and collaboration tools to spot impersonation and fraud patterns early and neutralize them upstream, before they land in an inbox, a DM, or a call queue. By combining AI-native detection, intelligent takedowns, and realistic simulations in one experience, we turn social engineering defense into an ambient safety net that strengthens trust and resilience without adding friction to how people actually work.
Q8: Are we entering a stage where identity verification will need to move beyond human senses, for example, detecting synthetic media or validating authenticity at machine speed?
Yes. Identity verification is already moving beyond what humans can reliably see, hear, or “feel,” and it has to if we want to keep pace with AI-generated attacks. As deepfakes and synthetic voices become indistinguishable from real people to the naked eye and ear, you need machine-speed signals, like synthetic media detection, behavioral patterns, and channel-level authenticity checks, to validate who or what you’re dealing with. At Doppel, we think of this as augmenting human judgment rather than replacing it: machines handle the pixel-level and signal-level authenticity questions in real time, so your people can focus on intent, context, and decision-making where human intuition still has the edge.
Looking Ahead
Q9: What role do you see for regulation or industry standards in managing AI-driven impersonation and disinformation risks?
[Bobby Response:]
Regulation and industry standards will play one of the biggest roles in managing AI-driven impersonation and disinformation — particularly at the platform and creator level. We can’t put the entire burden on individuals or organisations to detect synthetic content after it’s already in the wild.
Some progress has been made, like watermarking AI-generated content, but that’s not enough. Watermarks can be removed, blurred, or bypassed, which means we need stronger, more resilient ways to label, identify, and trace synthetic media by default. Transparency has to be built into the creation and distribution of this content.
The most logical places to start are high-impact sectors like healthcare and elections, where the consequences of impersonation and disinformation are severe and immediate. Getting standards right there can set the foundation for broader adoption across industries — and help restore trust as AI-generated content becomes ubiquitous.
Q10: Finally, what excites you most about where technology is heading and what keeps you up at night?
[Bobby Response:]
What excites me most is that we’re finally reaching a point many of us envisioned twenty years ago. The technology is here, the capabilities are real, and we’re genuinely about to step into a future we’ve been talking about for decades. There’s an incredible sense of momentum right now and it feels like the beginning of something transformative rather than incremental.
What keeps me up at night is the scale of this next wave. We’ve seen this before. Mobile, cloud, and the internet fundamentally changed how we live and work, and entire industries were built almost overnight. The convergence of generative AI and robotics has the potential to be even more disruptive. The opportunity is enormous, but so is the responsibility to make sure trust, safety, and guardrails evolve just as quickly as the technology itself.
Closing Statement
The key takeaway from Bobby Ford’s perspective is clear: the future of defending against social engineering lies in rethinking trust, not simply reinforcing old habits. Email security alone is no longer enough. Awareness training, while still valuable, cannot carry the full weight of defence in a world where AI-generated deception is increasingly indistinguishable from reality.
Instead, organisations must shift toward systems and controls that can validate digital identity, operate at machine speed, and remove malicious activity before it ever reaches a human decision point. Protecting people means designing security that works around them, not against them.
What’s exciting is that we’re entering a moment where technology can finally meet that challenge. The same advances that have empowered attackers — generative AI, automation, scale — are also enabling defenders to restore confidence and clarity in the digital world. As Bobby highlights, this isn’t just a period of increased risk; it’s an opportunity to build a safer, more trusted future, powered by the very technologies shaping it.
In Conversation with ... Bobby Ford on the Impact of emerging technologies on social engineering attacks
Social engineering has always relied on one constant: human trust. But as emerging technologies accelerate, from generative AI and voice cloning to deepfakes and automated impersonation, that trust is being exploited at a scale and sophistication never seen before. What were once crude phishing attempts have evolved into highly believable, multi-channel deception campaigns that blur the line between what is real and what is synthetic.
At the same time, the internet itself is undergoing a fundamental shift. Identity, authenticity, and intent are no longer things humans can reliably verify with their own senses. In this new environment, organisations are being forced to rethink how they protect not just their systems, but their people, their brands, and their customers from manipulation and fraud.
In this edition of In Conversation with…, we speak with Bobby Ford, Chief Strategy and Experience Officer at Doppel, about how emerging technologies are reshaping the social engineering threat landscape. Drawing on his experience across cybersecurity leadership and digital trust, Bobby shares his perspective on how attackers are evolving, why traditional defences are no longer enough, and what organisations must do to stay ahead in an era of AI-driven deception.
Setting the Scene
Q1: Bobby, social engineering has always been about exploiting human trust. How do you see that dynamic evolving as technologies like generative AI and deepfakes become mainstream?
[Bobby Response:]
Social engineering has always exploited trust, but generative AI and deepfakes dramatically raise the level of realism. It’s now far easier for attackers to convincingly impersonate colleagues, executives, or trusted brands — with far less effort and far greater scale.
What’s really changed is how personalised these attacks have become. Messages can reference real people, real work, and real context, making them feel authentic rather than suspicious. Social engineering is no longer limited to email, we’re seeing multi-channel attacks that play out across email, social media, messaging platforms, and even voice — mirroring exactly how we work day to day.
When deception looks real, feels personal, and shows up in trusted channels, trust itself becomes the attack surface.
Q2: What’s the biggest misconception organisations still have about social engineering in 2026?
[Bobby Response:]
The biggest misconception is that social engineering is an email problem. Many organisations still believe that if email is well protected, they’re largely covered, but as I said previously these attacks now span across multiple channels, email is just one entry point.
There’s also an overreliance on training as a silver bullet. Awareness training is important, but it can’t keep pace with highly realistic, AI-driven attacks that are designed to bypass human judgment in moments of pressure or urgency. When organisations treat training as “job done,” they shift responsibility onto individuals rather than fixing systemic gaps.
Ultimately, social engineering isn’t a people problem — it’s a trust and identity problem. Expecting employees to always spot deception in an increasingly synthetic world is unrealistic. Defence has to move beyond education and into continuous detection, protection, and support for the humans in the loop.
The Tech Shift
Q3: How are emerging technologies, such as AI-driven voice synthesis to large-scale language models, changing the scale and precision of social engineering campaigns?
[Bobby Response:]
Emerging technologies are changing social engineering in two fundamental ways: scale and precision. On the scale side, the volume of attacks is increasing dramatically. AI removes many of the time and resource constraints attackers once faced, allowing campaigns to be launched at a speed and breadth that simply wasn’t possible before.
When it comes to precision, these attacks are no longer generic. Large language models and automated data gathering enable hyper-personalisation at scale. What once required days or weeks of researching a target, understanding their role, relationships, and behaviour, can now be done in seconds. Attackers can focus on very specific details about an individual, making each interaction feel legitimate and highly relevant.
The result is a dangerous shift: more attacks, delivered faster, and tailored to exploit exactly who someone is and how they work. Making modern social engineering so effective and so difficult to detect.
AI-fueled activity has exploded: estimates suggest AI‑enabled cyberattacks have increased by more than 4,000% over the past three years, and recent analyses indicate that more than four out of five phishing emails sent in late 2024 and early 2025 showed clear signs of AI involvement.
Q4: Doppel’s technology focuses on digital identity and trust. How does that translate into defending against these modern, AI-powered deception tactics?
[Bobby Response:]
At its core, Doppel is focused on helping organisations understand and differentiate digital identities, determining which identities are legitimate and which are being used deceptively. In a world where AI makes impersonation easy, that distinction becomes critical.
Rather than putting the burden on individuals to spot deception, we focus on identifying malicious identities and activity across the digital landscape. Once those threats are detected, we work to disrupt, dismantle, and take down impersonation campaigns before they can be used to deceive employees, customers, or partners.
By restoring clarity around digital identity and trust, we help organisations move from reacting to social engineering attacks to proactively preventing them, even when those attacks are powered by AI and designed to look authentic.
The Human Factor
Q5: Even as tools get more advanced, people remain the entry point. What do you believe is the future of security awareness and behaviour change in this new environment?
[Bobby Response:]
I think it’s time to be honest: traditional security awareness, as we know it, is dead. It’s built on the assumption that individuals can reliably tell what’s malicious and what isn’t. That assumption no longer holds in a world of generative AI.
When AI can produce emails, voices, images, and even videos that are indistinguishable from reality — look at tools like Sora and the quality of videos it's creating — asking people to “spot the fake” is unrealistic. We’re moving into an environment where even highly trained professionals won’t be able to trust their own judgment consistently.
So the future isn’t about forcing more behaviour change or putting more pressure on individuals. It’s about putting the right controls in place, controls that can detect deception, verify identity, and reduce risk before a human ever has to make a decision. People will always be part of the process, but they shouldn’t be the last line of defence in an increasingly synthetic world.
Q6: How can organisations foster a culture of digital skepticism without creating fear or friction?
[Bobby Response:]
It starts with giving people confidence, not fear. And I know I keep coming back to this, but it’s important to drive it home: the right controls around individuals change everything. When employees know they’re protected, they’re far more likely to engage thoughtfully rather than operate in a constant state of suspicion.
The most critical part of trust is knowing that the technology has already done the hard work. Checks have been run, identities validated, and signals filtered, so the end product that reaches an employee is legitimate. When a tool takes on that responsibility, people don’t have to second-guess every interaction and can get on with their jobs.
That’s how you foster a culture of digital skepticism without friction: by shifting from “don’t trust anything” to “trust, but verify and verification happens by default.” The goal isn’t to make people paranoid, it’s to create a culture of confidence where employees can focus on their work, knowing the organisation has put the right protections in place around them.
The Business and Strategy Lens
Q7: How does Doppel connect the dots between user experience, trust, and security resilience?
At Doppel, our vision for social engineering defense is to create a platform that shields users, so most attacks are prevented before they even become a decision point for a human. Instead of asking employees to become full-time threat analysts, we unify signals across domains, social, messaging, and collaboration tools to spot impersonation and fraud patterns early and neutralize them upstream, before they land in an inbox, a DM, or a call queue. By combining AI-native detection, intelligent takedowns, and realistic simulations in one experience, we turn social engineering defense into an ambient safety net that strengthens trust and resilience without adding friction to how people actually work.
Q8: Are we entering a stage where identity verification will need to move beyond human senses, for example, detecting synthetic media or validating authenticity at machine speed?
Yes. Identity verification is already moving beyond what humans can reliably see, hear, or “feel,” and it has to if we want to keep pace with AI-generated attacks. As deepfakes and synthetic voices become indistinguishable from real people to the naked eye and ear, you need machine-speed signals, like synthetic media detection, behavioral patterns, and channel-level authenticity checks, to validate who or what you’re dealing with. At Doppel, we think of this as augmenting human judgment rather than replacing it: machines handle the pixel-level and signal-level authenticity questions in real time, so your people can focus on intent, context, and decision-making where human intuition still has the edge.
Looking Ahead
Q9: What role do you see for regulation or industry standards in managing AI-driven impersonation and disinformation risks?
[Bobby Response:]
Regulation and industry standards will play one of the biggest roles in managing AI-driven impersonation and disinformation — particularly at the platform and creator level. We can’t put the entire burden on individuals or organisations to detect synthetic content after it’s already in the wild.
Some progress has been made, like watermarking AI-generated content, but that’s not enough. Watermarks can be removed, blurred, or bypassed, which means we need stronger, more resilient ways to label, identify, and trace synthetic media by default. Transparency has to be built into the creation and distribution of this content.
The most logical places to start are high-impact sectors like healthcare and elections, where the consequences of impersonation and disinformation are severe and immediate. Getting standards right there can set the foundation for broader adoption across industries — and help restore trust as AI-generated content becomes ubiquitous.
Q10: Finally, what excites you most about where technology is heading and what keeps you up at night?
[Bobby Response:]
What excites me most is that we’re finally reaching a point many of us envisioned twenty years ago. The technology is here, the capabilities are real, and we’re genuinely about to step into a future we’ve been talking about for decades. There’s an incredible sense of momentum right now and it feels like the beginning of something transformative rather than incremental.
What keeps me up at night is the scale of this next wave. We’ve seen this before. Mobile, cloud, and the internet fundamentally changed how we live and work, and entire industries were built almost overnight. The convergence of generative AI and robotics has the potential to be even more disruptive. The opportunity is enormous, but so is the responsibility to make sure trust, safety, and guardrails evolve just as quickly as the technology itself.
Closing Statement
The key takeaway from Bobby Ford’s perspective is clear: the future of defending against social engineering lies in rethinking trust, not simply reinforcing old habits. Email security alone is no longer enough. Awareness training, while still valuable, cannot carry the full weight of defence in a world where AI-generated deception is increasingly indistinguishable from reality.
Instead, organisations must shift toward systems and controls that can validate digital identity, operate at machine speed, and remove malicious activity before it ever reaches a human decision point. Protecting people means designing security that works around them, not against them.
What’s exciting is that we’re entering a moment where technology can finally meet that challenge. The same advances that have empowered attackers — generative AI, automation, scale — are also enabling defenders to restore confidence and clarity in the digital world. As Bobby highlights, this isn’t just a period of increased risk; it’s an opportunity to build a safer, more trusted future, powered by the very technologies shaping it.
In Conversation with ... Bobby Ford on the Impact of emerging technologies on social engineering attacks
Social engineering has always relied on one constant: human trust. But as emerging technologies accelerate, from generative AI and voice cloning to deepfakes and automated impersonation, that trust is being exploited at a scale and sophistication never seen before. What were once crude phishing attempts have evolved into highly believable, multi-channel deception campaigns that blur the line between what is real and what is synthetic.
At the same time, the internet itself is undergoing a fundamental shift. Identity, authenticity, and intent are no longer things humans can reliably verify with their own senses. In this new environment, organisations are being forced to rethink how they protect not just their systems, but their people, their brands, and their customers from manipulation and fraud.
In this edition of In Conversation with…, we speak with Bobby Ford, Chief Strategy and Experience Officer at Doppel, about how emerging technologies are reshaping the social engineering threat landscape. Drawing on his experience across cybersecurity leadership and digital trust, Bobby shares his perspective on how attackers are evolving, why traditional defences are no longer enough, and what organisations must do to stay ahead in an era of AI-driven deception.
Setting the Scene
Q1: Bobby, social engineering has always been about exploiting human trust. How do you see that dynamic evolving as technologies like generative AI and deepfakes become mainstream?
[Bobby Response:]
Social engineering has always exploited trust, but generative AI and deepfakes dramatically raise the level of realism. It’s now far easier for attackers to convincingly impersonate colleagues, executives, or trusted brands — with far less effort and far greater scale.
What’s really changed is how personalised these attacks have become. Messages can reference real people, real work, and real context, making them feel authentic rather than suspicious. Social engineering is no longer limited to email, we’re seeing multi-channel attacks that play out across email, social media, messaging platforms, and even voice — mirroring exactly how we work day to day.
When deception looks real, feels personal, and shows up in trusted channels, trust itself becomes the attack surface.
Q2: What’s the biggest misconception organisations still have about social engineering in 2026?
[Bobby Response:]
The biggest misconception is that social engineering is an email problem. Many organisations still believe that if email is well protected, they’re largely covered, but as I said previously these attacks now span across multiple channels, email is just one entry point.
There’s also an overreliance on training as a silver bullet. Awareness training is important, but it can’t keep pace with highly realistic, AI-driven attacks that are designed to bypass human judgment in moments of pressure or urgency. When organisations treat training as “job done,” they shift responsibility onto individuals rather than fixing systemic gaps.
Ultimately, social engineering isn’t a people problem — it’s a trust and identity problem. Expecting employees to always spot deception in an increasingly synthetic world is unrealistic. Defence has to move beyond education and into continuous detection, protection, and support for the humans in the loop.
The Tech Shift
Q3: How are emerging technologies, such as AI-driven voice synthesis to large-scale language models, changing the scale and precision of social engineering campaigns?
[Bobby Response:]
Emerging technologies are changing social engineering in two fundamental ways: scale and precision. On the scale side, the volume of attacks is increasing dramatically. AI removes many of the time and resource constraints attackers once faced, allowing campaigns to be launched at a speed and breadth that simply wasn’t possible before.
When it comes to precision, these attacks are no longer generic. Large language models and automated data gathering enable hyper-personalisation at scale. What once required days or weeks of researching a target, understanding their role, relationships, and behaviour, can now be done in seconds. Attackers can focus on very specific details about an individual, making each interaction feel legitimate and highly relevant.
The result is a dangerous shift: more attacks, delivered faster, and tailored to exploit exactly who someone is and how they work. Making modern social engineering so effective and so difficult to detect.
AI-fueled activity has exploded: estimates suggest AI‑enabled cyberattacks have increased by more than 4,000% over the past three years, and recent analyses indicate that more than four out of five phishing emails sent in late 2024 and early 2025 showed clear signs of AI involvement.
Q4: Doppel’s technology focuses on digital identity and trust. How does that translate into defending against these modern, AI-powered deception tactics?
[Bobby Response:]
At its core, Doppel is focused on helping organisations understand and differentiate digital identities, determining which identities are legitimate and which are being used deceptively. In a world where AI makes impersonation easy, that distinction becomes critical.
Rather than putting the burden on individuals to spot deception, we focus on identifying malicious identities and activity across the digital landscape. Once those threats are detected, we work to disrupt, dismantle, and take down impersonation campaigns before they can be used to deceive employees, customers, or partners.
By restoring clarity around digital identity and trust, we help organisations move from reacting to social engineering attacks to proactively preventing them, even when those attacks are powered by AI and designed to look authentic.
The Human Factor
Q5: Even as tools get more advanced, people remain the entry point. What do you believe is the future of security awareness and behaviour change in this new environment?
[Bobby Response:]
I think it’s time to be honest: traditional security awareness, as we know it, is dead. It’s built on the assumption that individuals can reliably tell what’s malicious and what isn’t. That assumption no longer holds in a world of generative AI.
When AI can produce emails, voices, images, and even videos that are indistinguishable from reality — look at tools like Sora and the quality of videos it's creating — asking people to “spot the fake” is unrealistic. We’re moving into an environment where even highly trained professionals won’t be able to trust their own judgment consistently.
So the future isn’t about forcing more behaviour change or putting more pressure on individuals. It’s about putting the right controls in place, controls that can detect deception, verify identity, and reduce risk before a human ever has to make a decision. People will always be part of the process, but they shouldn’t be the last line of defence in an increasingly synthetic world.
Q6: How can organisations foster a culture of digital skepticism without creating fear or friction?
[Bobby Response:]
It starts with giving people confidence, not fear. And I know I keep coming back to this, but it’s important to drive it home: the right controls around individuals change everything. When employees know they’re protected, they’re far more likely to engage thoughtfully rather than operate in a constant state of suspicion.
The most critical part of trust is knowing that the technology has already done the hard work. Checks have been run, identities validated, and signals filtered, so the end product that reaches an employee is legitimate. When a tool takes on that responsibility, people don’t have to second-guess every interaction and can get on with their jobs.
That’s how you foster a culture of digital skepticism without friction: by shifting from “don’t trust anything” to “trust, but verify and verification happens by default.” The goal isn’t to make people paranoid, it’s to create a culture of confidence where employees can focus on their work, knowing the organisation has put the right protections in place around them.
The Business and Strategy Lens
Q7: How does Doppel connect the dots between user experience, trust, and security resilience?
At Doppel, our vision for social engineering defense is to create a platform that shields users, so most attacks are prevented before they even become a decision point for a human. Instead of asking employees to become full-time threat analysts, we unify signals across domains, social, messaging, and collaboration tools to spot impersonation and fraud patterns early and neutralize them upstream, before they land in an inbox, a DM, or a call queue. By combining AI-native detection, intelligent takedowns, and realistic simulations in one experience, we turn social engineering defense into an ambient safety net that strengthens trust and resilience without adding friction to how people actually work.
Q8: Are we entering a stage where identity verification will need to move beyond human senses, for example, detecting synthetic media or validating authenticity at machine speed?
Yes. Identity verification is already moving beyond what humans can reliably see, hear, or “feel,” and it has to if we want to keep pace with AI-generated attacks. As deepfakes and synthetic voices become indistinguishable from real people to the naked eye and ear, you need machine-speed signals, like synthetic media detection, behavioral patterns, and channel-level authenticity checks, to validate who or what you’re dealing with. At Doppel, we think of this as augmenting human judgment rather than replacing it: machines handle the pixel-level and signal-level authenticity questions in real time, so your people can focus on intent, context, and decision-making where human intuition still has the edge.
Looking Ahead
Q9: What role do you see for regulation or industry standards in managing AI-driven impersonation and disinformation risks?
[Bobby Response:]
Regulation and industry standards will play one of the biggest roles in managing AI-driven impersonation and disinformation — particularly at the platform and creator level. We can’t put the entire burden on individuals or organisations to detect synthetic content after it’s already in the wild.
Some progress has been made, like watermarking AI-generated content, but that’s not enough. Watermarks can be removed, blurred, or bypassed, which means we need stronger, more resilient ways to label, identify, and trace synthetic media by default. Transparency has to be built into the creation and distribution of this content.
The most logical places to start are high-impact sectors like healthcare and elections, where the consequences of impersonation and disinformation are severe and immediate. Getting standards right there can set the foundation for broader adoption across industries — and help restore trust as AI-generated content becomes ubiquitous.
Q10: Finally, what excites you most about where technology is heading and what keeps you up at night?
[Bobby Response:]
What excites me most is that we’re finally reaching a point many of us envisioned twenty years ago. The technology is here, the capabilities are real, and we’re genuinely about to step into a future we’ve been talking about for decades. There’s an incredible sense of momentum right now and it feels like the beginning of something transformative rather than incremental.
What keeps me up at night is the scale of this next wave. We’ve seen this before. Mobile, cloud, and the internet fundamentally changed how we live and work, and entire industries were built almost overnight. The convergence of generative AI and robotics has the potential to be even more disruptive. The opportunity is enormous, but so is the responsibility to make sure trust, safety, and guardrails evolve just as quickly as the technology itself.
Closing Statement
The key takeaway from Bobby Ford’s perspective is clear: the future of defending against social engineering lies in rethinking trust, not simply reinforcing old habits. Email security alone is no longer enough. Awareness training, while still valuable, cannot carry the full weight of defence in a world where AI-generated deception is increasingly indistinguishable from reality.
Instead, organisations must shift toward systems and controls that can validate digital identity, operate at machine speed, and remove malicious activity before it ever reaches a human decision point. Protecting people means designing security that works around them, not against them.
What’s exciting is that we’re entering a moment where technology can finally meet that challenge. The same advances that have empowered attackers — generative AI, automation, scale — are also enabling defenders to restore confidence and clarity in the digital world. As Bobby highlights, this isn’t just a period of increased risk; it’s an opportunity to build a safer, more trusted future, powered by the very technologies shaping it.