“In the incidents we handle, the executive is often the starting point for a wider attack. When strong technical controls are in place, attackers may go after people instead — they treat senior executives as a way into the whole organisation, find an opening, and scale from there.”
Jan Kaastrup, Chief Cybersecurity Advisor, CSIS Security Group
Companies are spending more than ever on executive protection. Among S&P 500 firms, the share reporting executive security spending rose from 24% in 2021 to 38% in 2025. Typical spending is now around $130,000 a year, up from around $55,000.1
Those investments have traditionally gone almost entirely to physical protection: drivers, residential security, private travel. Recently, companies have started extending that protection to their executives' online exposure. Personal data removal, online privacy services and identity theft protection are increasingly part of the package, sometimes extending to executives' families. 2
This checklist follows our webinar on executive protection. It sets out 18 practical actions in sequence, with the reason for each and who you need to involve. Watch the recording for the threat landscape and case studies behind them.
Stage 1 — Establish ownership
|
# |
Action |
Reason |
Who you need |
|
1 |
Agree who decides on executive protection and who coordinates across teams |
Executive protection spans cybersecurity, physical security, legal, HR, comms and the executive office. Gaps appear without coordination |
You, plus a decision from leadership |
|
2 |
Decide who is in scope: executives, assistants, immediate family, drivers, protection staff, heads of IT |
Threat actors go for the weakest point, and that is not always the executive themselves |
You |
Stage 2 — See the exposure
|
# |
Action |
Reason |
Who you need |
|
3 |
Run an exposure scan on everyone in scope, starting with no inside information |
An exposure review built from what you already know will miss what a stranger can assemble from scratch |
The executive's agreement, plus budget or a vendor |
|
4 |
Review the findings with the executive in person |
Executives act on their own exposure when they are shown it directly. A written report rarely produces the same response |
30 minutes with the executive |
Stage 3 — Reduce the exposure
|
# |
Action |
Reason |
Who you need |
|
5 |
Remove data broker listings for everyone in scope |
Data brokers are an easy and legal starting point for anyone building a profile of an executive |
Budget or a vendor |
|
6 |
Separate public and private contact details |
Private numbers and home addresses should never appear in external material, event listings or company filings |
Comms, HR |
|
7 |
Set up a password manager for executives, assistants and family |
Credentials from old breaches are reused for years. A password manager removes most of that risk in an afternoon |
The executive and their household |
|
8 |
Review social media privacy settings and fitness app sharing across everyone in scope |
Fitness apps and geotagged posts can reveal home locations and daily routines. A single running route, repeated, can reveal the movements of a whole team |
Each individual |
|
9 |
Ask for walkthroughs, not alerts |
An exposure finding changes nothing until someone opens the setting and changes it. That work sits with the individual |
Whoever produces your findings |
Stage 4 — Control what is visible
|
# |
Action |
Reason |
Who you need |
|
10 |
Review social media account privacy settings for the executive and direct familial network |
There is no greater source of information for threat actors to build a physical pattern of life than social media leakage of PII, contextual photos and hobbies and life events. |
You, the executive |
|
11 |
Review property listings and real estate sites for interior photos and floor plans of executives' homes |
Listings often stay online long after a sale, showing entrances, layouts and sightlines |
You, the executive |
|
12 |
Check for impersonation accounts using executives' names and photos across social platforms |
Fake profiles are used to approach staff, partners and family, and to run financial scams |
You, comms |
|
13 |
Publish the event, hold back the schedule |
A published start time lets anyone estimate an arrival window. The event needs publicity; the timing does not |
Marketing, comms |
Stage 5 — Detect and respond
|
# |
Action |
Reason |
Who you need |
|
14 |
Create one reporting channel for threats, suspicious contacts, possible surveillance and online exposure |
People report unusual things when there is one obvious place to send them, and stay quiet when there isn't |
You, plus an all-staff note |
|
15 |
Write a verification rule for unexpected recruiter, investor, board and partnership approaches |
Malicious approaches are designed to look completely normal, so the check has to happen every time |
You, the executive |
|
16 |
Run one tabletop exercise on doxing or swatting |
These scenarios cut across security, legal, comms and the executive office, and the confusion is usually about who decides |
Legal, comms, the executive office |
|
17 |
Add a physical and human risk review to your breach response playbook |
Password resets and credit monitoring do not address a leaked home address, a family member's name or a household routine |
Incident response, HR |
|
18 |
Set a re-scan cadence and the triggers: layoffs, litigation, transactions, earnings, any controversial public decision |
New leaks appear constantly, and threat context changes with company events |
You |
Implementation tips
Where programmes stall
Digital protection programmes can stall at Stage 2, because the executive does not believe the risk is real. The scan itself is straightforward. Getting executives to agree to action can be more challenging. It can therefore be helpful to show an executive what a stranger can find about their home, their family and their online accounts, and explain how that information can be used.
Who belongs in scope
Start with the C-suite, then go one level down. In our experience, the more useful findings often come from executive assistants and heads of IT. They hold comparable access with less scrutiny, and they are rarely told they are a target. Family members belong in scope too. A spouse's public profile or a child's school can complete a picture that the executive's own accounts do not.
How often to repeat this
Keep monitoring on an ongoing basis, with a full review at least annually and a fresh scan before any event that changes your threat context.
This is not only a large-company problem
Executive protection is often assumed to be a concern for banks and multinationals. The size of the company matters less than what a threat actor stands to gain from reaching the person at the top, and smaller organisations frequently have less protection around that person.
Get started: exposure assessment
Request an exposure review for one executive. We start with no inside information and build the picture the way a threat actor would, using the same data brokers and breach repositories they use. You get the findings, the mitigations attached to each one, and a walkthrough the executive can follow themselves.
Request an executive exposure review
References
- Equilar, Early Look: Executive Security Perks on the Rise, 10 April 2026. Based on S&P 500 proxy filings through 7 April 2026.
https://www.equilar.com/blogs/626-early-look-at-security-perks.html - Pay Governance, Executive Security and Protection Continues to Expand, 27 August 2026.
https://www.paygovernance.com/resource/executive-security-and-protection-continues-to-expand/
Stay updated
Sign up for our newsletter and get the latest cybersecurity analysis, reports and events from CSIS delivered straight to your inbox.
CSIS Newsletter