High-Risk Operations  ·  OSINT Methodology
· 5 min read

What Executive OSINT Reveals in 48 Hours

The question is not whether your exposure exists. It does. The question is whether you have seen it before someone with adverse intent has.

What the assessment covers

An executive OSINT assessment is not a background check. It is a systematic mapping of everything that is publicly knowable about a specific individual — and an assessment of what that information enables in the hands of an adversary.

The scope covers six primary vectors: digital identity (email addresses, usernames, registered domains), professional network exposure (LinkedIn, conference listings, board memberships, alumni directories), document trail (PDFs containing the subject's name indexed by search engines), credential exposure (breach databases, dark web monitoring), physical pattern indicators (EXIF metadata in photographs, venue check-ins, event schedules), and social graph vulnerabilities (family members, assistants and staff who create indirect exposure).

Each vector is assessed not for its existence — most executives have exposure across all six — but for what it enables. The question is not "can someone find your name?" but "can someone find your home address, your travel schedule and your access credentials from your name alone?" The answer, for most senior executives, is yes.

The two-layer report

The finished product follows the same format as all OF-PRO intelligence products. An executive summary of no more than one page, with the key findings, the highest-priority risks, and a recommended action for each. The supporting analytical report documents every finding with its source, collection date and reliability rating on the NATO Admiralty scale.

The report does not list everything that is publicly available about the subject. It lists what is operationally significant — what an adversary could use, and what it would enable. A finding that is technically public but practically inaccessible without specialist knowledge is assessed differently from a finding that surfaces in the first three search results.

What a remediation roadmap looks like

Every finding that represents an active risk comes with specific remediation guidance. Not generic advice — specific instructions for the specific exposure. For an EXIF-tagged photograph: the exact file, the exact metadata, the exact removal method. For a data broker listing: the specific opt-out procedure for that broker, and a realistic assessment of how long it takes.

Remediation is prioritised by operational risk. Physical access risks — home address reconstructability, predictable movement patterns — are addressed first. Credential risks second. Reputational and competitive risks third.

When to request an assessment

The most common trigger is a change in public profile: a new board appointment, a significant press mention, a new deal. The second most common trigger is a specific incident — a targeted social engineering attempt, a suspicious connection request, an anomalous enquiry.

The right time is before the incident, not after. An assessment takes 48 hours. An incident takes longer to recover from.

Next step

See your own exposure before someone else does.

Request an Executive Protection Risk Assessment. Delivered in 48 hours.

Request assessment
← Back to all briefings