BLACK HAT AUTHOR Q&A: The adversary doesn’t care which department owns the data

By Byron V. Acohido

The line between physical security, cybersecurity, privacy and reputation management is dissolving. A data leak can surface a home address.

Related: Defending the CEO attack vector

A breached account can put an executive’s family in physical danger. The threats don’t stay in their lanes.

That’s the terrain Chuck Randolph, Jonathan Wackrow and Fred Burton map in The Protector’s Edge: Leadership Through Strategy and Action. Their argument: executive protection has outgrown the old picture of bodyguards, travel logistics and perimeter walls. Today’s protector has to read digital exposure, business continuity and reputation risk, and the pressures bearing down on the C-suite.

Doxxing, deepfakes, AI-enabled impersonation and online radicalization are forcing boards to rethink what protection means. CISOs, CSOs, legal, communications and privacy teams each watch a different dashboard. Adversaries see one target.

I asked Randolph, chief strategy officer at 360 Privacy and a co-author, to lay out what executive protection means now, and why the modern protector works as a strategic risk advisor.

LW: You write that the physical and digital are inseparable. What does that mean for the teams protecting executives?

Randolph: A physical security problem may start online. Someone finds an executive’s home address through a data broker, the spouse and children through social media, travel patterns from posts, breached accounts or public records.

None of it may look especially dangerous on its own. Put it together and it starts to look like targeting. The person planning to harass, threaten or approach an executive does not care which department owns the information. They are looking for a way in.

The job is no longer limited to vehicles, routes, hotels and access control. You still have to do those well, but you also need to know what is exposed online, what the family is sharing, which devices and accounts are vulnerable and whether online activity points toward physical action.

The divide between physical and digital security may still exist on the org chart. It does not exist for the adversary.

LW: Why should CISOs, CSOs and privacy leaders care about executive protection?

Randolph: Because the executive is often one of the most valuable and exposed parts of the organization.

A senior leader has access, authority and visibility. They may have privileged accounts, sensitive communications and the ability to move the company during a crisis. They may also be the public face of a decision people are angry about.

That creates both personal and business risk. A compromised personal email account can expose travel or internal discussions. A family member can become a route for social engineering. A threat against the CEO can disrupt operations, delay decisions and pull several departments into a crisis.

This is where duty of care and business continuity meet. Protecting the executive is not just about keeping one person safe. It is also about protecting the organization’s ability to function.

Treating executive protection as separate from cyber, privacy and continuity planning is a mistake. In a real incident, those lines disappear.

LW: How should teams read weak signals without drowning in noise?

Randolph: You have to stop collecting information just because you can. The first question: what are we actually trying to understand?

That may be whether a grievance is becoming more personal, whether someone is trying to locate the executive or whether online anger is starting to move toward action. Once you know the question, you can look for the indicators that matter.

Technology helps with the volume. It can find patterns and surface things a person might miss, but someone still has to understand the context.

Good protective intelligence is not about reporting everything. It is about knowing what deserves attention, what needs watching and what requires a decision, or enabling a decision.

LW: You call the information environment a protective domain. What does that mean during doxxing, leaks or deepfakes?

Randolph: Information itself can change the threat. A leak can expose a home address. A deepfake can create confusion during an active incident. A false story can put an executive at the center of a grievance and drive people toward action.

The issue is not only whether the information is true. The issue is what people believe, how quickly it spreads and what they may do because of it.

Most companies break these incidents into pieces. Cyber looks at how the information got out. Legal looks at exposure. Communications looks at the public response. Physical security looks at whether someone might show up. All reasonable concerns, but someone has to connect them.

The shared questions are simple: What happened? Who is pushing it? Who is reacting to it? Does it change the executive’s exposure? What do we need to do now?

LW: Protectors have to translate risk into business terms. What does that sound like in a board conversation?

Randolph: Telling leaders what they need to know without turning the conversation into a security briefing.

“The threat level is elevated” does not help. Elevated compared with what? What changed? What decision needs to be made?

A better version: “We are seeing the CEO’s home address and family information circulate in a group that has encouraged people to confront company leaders. We have no evidence of a specific plan, but activity is increasing ahead of Tuesday’s event. Our recommendation is to keep the event on, change the arrival plan, increase monitoring and tighten coverage around the residence for the next several days.”

That gives the executive something to work with.

The protector’s job is not to make everything sound dangerous. It is to explain what is happening, what could happen and what the organization can do. Sometimes the right advice is to increase security. Sometimes it is to keep moving.

That judgment is what makes someone a trusted advisor.

LW: As AI and automation reshape targeting, what must remain human?

Randolph: The decision has to remain human. AI can help teams work faster. It can process large volumes, identify patterns and show us things we might otherwise miss. We should use it for that.

What it cannot do is take responsibility. It does not fully understand the executive, the family, the company culture or the cost of getting a call wrong. It can flag language or behavior, but a person still has to decide whether someone is angry, unstable, threatening or moving toward action.

Protection decisions affect real people. They can restrict movement, damage reputations and pull law enforcement or security resources into someone’s life.

The human part is judgment, ethics and the ability to stay calm when the information is incomplete. It is also trust. An executive has to believe the person advising them understands both the threat and the consequences of the recommendation.

AI can support the protector. It should not replace the protector’s judgment.

LW: What should organizations start on now?

Randolph: Find out what is exposed. The executive’s home address, family information, personal accounts, devices, travel habits and public profile. Do not assume you know what is online. Check it.

Then get the right people in the same room. Cyber, physical security, privacy, legal, communications and business continuity should agree on who owns what, what gets shared and when an issue gets escalated.

Then run an exercise. A scenario where an executive is doxxed, a fake recording begins circulating and people start talking about showing up at the executive’s home or a company event. See how the team responds. You will find the gaps quickly.

Companies cannot keep managing these as separate problems. The threat is already converged. The organization has to catch up.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

Share on FacebookShare on Google+Tweet about this on TwitterShare on LinkedInEmail this to someone