CSIS Tech Blog

Executive Protection Checklist: 18 Actions | CSIS

Written by CSIS | Sep 14, 2026, 9:14:21 AM

“In the incidents we handle, the executive is often the starting point for a wider attack. When strong technical controls are in place, attackers may go after people instead — they treat senior executives as a way into the whole organisation, find an opening, and scale from there.”

Jan Kaastrup, Chief Cybersecurity Advisor, CSIS Security Group

 

Companies are spending more than ever on executive protection. Among S&P 500 firms, the share reporting executive security spending rose from 24% in 2021 to 38% in 2025. Typical spending is now around $130,000 a year, up from around $55,000.1

Those investments have traditionally gone almost entirely to physical protection: drivers, residential security, private travel. Recently, companies have started extending that protection to their executives' online exposure. Personal data removal, online privacy services and identity theft protection are increasingly part of the package, sometimes extending to executives' families. 2

This checklist follows our webinar on executive protection. It sets out 18 practical actions in sequence, with the reason for each and who you need to involve. Watch the recording for the threat landscape and case studies behind them.

 

Stage 1 — Establish ownership

#

Action

Reason

Who you need

1

Agree who decides on executive protection and who coordinates across teams

Executive protection spans cybersecurity, physical security, legal, HR, comms and the executive office. Gaps appear without coordination

You, plus a decision from leadership

2

Decide who is in scope: executives, assistants, immediate family, drivers, protection staff, heads of IT

Threat actors go for the weakest point, and that is not always the executive themselves

You

 

Stage 2 — See the exposure

#

Action

Reason

Who you need

3

Run an exposure scan on everyone in scope, starting with no inside information

An exposure review built from what you already know will miss what a stranger can assemble from scratch

The executive's agreement, plus budget or a vendor

4

Review the findings with the executive in person

Executives act on their own exposure when they are shown it directly. A written report rarely produces the same response

30 minutes with the executive

 

Stage 3 — Reduce the exposure

#

Action

Reason

Who you need

5

Remove data broker listings for everyone in scope

Data brokers are an easy and legal starting point for anyone building a profile of an executive

Budget or a vendor

6

Separate public and private contact details

Private numbers and home addresses should never appear in external material, event listings or company filings

Comms, HR

7

Set up a password manager for executives, assistants and family

Credentials from old breaches are reused for years. A password manager removes most of that risk in an afternoon

The executive and their household

8

Review social media privacy settings and fitness app sharing across everyone in scope

Fitness apps and geotagged posts can reveal home locations and daily routines. A single running route, repeated, can reveal the movements of a whole team

Each individual

9

Ask for walkthroughs, not alerts

An exposure finding changes nothing until someone opens the setting and changes it. That work sits with the individual

Whoever produces your findings

 

 

Stage 4 — Control what is visible

#

Action

Reason

Who you need

10

Review social media account privacy settings for the executive and direct familial network

There is no greater source of information for threat actors to build a physical pattern of life than social media leakage of PII, contextual photos and hobbies and life events.

You, the executive

11

Review property listings and real estate sites for interior photos and floor plans of executives' homes

Listings often stay online long after a sale, showing entrances, layouts and sightlines

You, the executive

12

Check for impersonation accounts using executives' names and photos across social platforms

Fake profiles are used to approach staff, partners and family, and to run financial scams

You, comms

13

Publish the event, hold back the schedule

A published start time lets anyone estimate an arrival window. The event needs publicity; the timing does not

Marketing, comms

 

Stage 5 — Detect and respond

#

Action

Reason

Who you need

14

Create one reporting channel for threats, suspicious contacts, possible surveillance and online exposure

People report unusual things when there is one obvious place to send them, and stay quiet when there isn't

You, plus an all-staff note

15

Write a verification rule for unexpected recruiter, investor, board and partnership approaches

Malicious approaches are designed to look completely normal, so the check has to happen every time

You, the executive

16

Run one tabletop exercise on doxing or swatting

These scenarios cut across security, legal, comms and the executive office, and the confusion is usually about who decides

Legal, comms, the executive office

17

Add a physical and human risk review to your breach response playbook

Password resets and credit monitoring do not address a leaked home address, a family member's name or a household routine

Incident response, HR

18

Set a re-scan cadence and the triggers: layoffs, litigation, transactions, earnings, any controversial public decision

New leaks appear constantly, and threat context changes with company events

You

 

Implementation tips

Where programmes stall

Digital protection programmes can stall at Stage 2, because the executive does not believe the risk is real. The scan itself is straightforward. Getting executives to agree to action can be more challenging. It can therefore be helpful to show an executive what a stranger can find about their home, their family and their online accounts, and explain how that information can be used.

Who belongs in scope

Start with the C-suite, then go one level down. In our experience, the more useful findings often come from executive assistants and heads of IT. They hold comparable access with less scrutiny, and they are rarely told they are a target. Family members belong in scope too. A spouse's public profile or a child's school can complete a picture that the executive's own accounts do not.

How often to repeat this

Keep monitoring on an ongoing basis, with a full review at least annually and a fresh scan before any event that changes your threat context.

This is not only a large-company problem

Executive protection is often assumed to be a concern for banks and multinationals. The size of the company matters less than what a threat actor stands to gain from reaching the person at the top, and smaller organisations frequently have less protection around that person.

 

Get started: exposure assessment

Request an exposure review for one executive. We start with no inside information and build the picture the way a threat actor would, using the same data brokers and breach repositories they use. You get the findings, the mitigations attached to each one, and a walkthrough the executive can follow themselves.

Request an executive exposure review

References

Stay updated

Sign up for our newsletter and get the latest cybersecurity analysis, reports and events from CSIS delivered straight to your inbox.