The Executive Threat Model: Four Surfaces, One Person
Key Intel / TL;DR
  • An executive is one person carrying concentrated authority, a public identity, and a household, which makes them a different threat model than an employee.
  • The four surfaces are physical, digital, cognitive, and household, and an attacker moves between them freely while most companies defend them in separate silos.
  • The cognitive surface is the one nobody owns, and it is where fatigue, isolation, and time pressure turn a competent leader into the fastest route in.
  • Household exposure sits almost entirely outside corporate authority, which is a scoping problem rather than a reason to ignore it.
  • Build the model before buying anything: name the person, list what only they can authorize, then map who would want it and which surface is cheapest for them.

A client called us about a residence in the hills above the valley. An intruder had come onto the property, and by the time law enforcement arrived and moved through it, the man had evaded them on the grounds for 36 minutes.

The property had cameras. It had a monitored alarm. At the back of the lot it had a gate with a latch and no lock, no sensor, and no light, opening onto a wash that ran up from the road below. Nobody had walked the perimeter and asked how a person on foot would come in, because the security conversation had been about the house.

That is the executive threat model in one image. Every organization I have worked with defends the front of the house.

Why an Executive Is a Different Threat Model

An employee is a route into a system. An executive is a route into a decision.

Three properties make the difference, and they compound.

Concentrated authority. A small number of people can move money, sign a binding commitment, approve an exception, or release material information without a second signature. The organization built that concentration deliberately, because leadership that needs consensus for everything cannot lead. The same design makes one person’s compromised judgment worth more than a hundred employees’ credentials.

Public identifiability. The executive’s name, face, employer, and calendar are marketing assets. The team page, the conference keynote, the earnings call, the LinkedIn post about the new office. All of that is deliberate, most of it is necessary, and all of it is also targeting data that an employee two levels down does not generate.

A household. The executive comes with a spouse, children, a home address, a routine, and a set of people who are reachable, worth pressuring, and outside every control the company owns.

Put those together and you get a target whose value is high, whose location and habits are discoverable, and whose most exposed surfaces belong to somebody other than your security team.

The Four Surfaces

An attacker does not think in departments. They pick the cheapest way to the outcome. These are the four ways in, and the useful exercise is noticing that your organization probably assigns them to four different owners, or to nobody.

Surface one: physical

The building, the residence, the vehicle, the hotel, the parking structure, the venue. Access control, perimeter, surveillance, travel routing, and the people who stand between a stranger and the principal.

This is the surface most people picture when they hear executive protection, and it is the one with the most mature vendor market. It is also the surface where the failure is almost never the technology. I have walked past $200,000 of working cameras and into a secure facility in under 90 seconds. Every camera caught me. Not one policy stopped me. The gap was the human being between the alarm and the decision to act on it.

If you want the depth here, our physical security guide covers the fundamentals and modern executive protection covers how the physical detail work now depends on digital intelligence to be effective at all.

Surface two: digital

Devices, accounts, communications, and the data trail. The laptop, the phone, the personal email that predates the job, the cloud storage nobody provisioned, and the sessions those devices hold open.

The executive’s digital surface differs from an employee’s in one specific way: much of it is personal, which means your mobile device management may not touch it, your endpoint detection does not see it, and your logging captures nothing. That is where mercenary spyware lands, and it is why an Apple threat notification is an incident nobody has a runbook for.

It is also where the credential story has moved past passwords. An attacker with code on the machine inherits sessions that already authenticated, which is why resetting the password does not kill the session and why travel exposure is now about what the device carries rather than what the person says. What your phone carries across the border and hotel Wi-Fi as an attacker’s network are both this surface on the road.

Surface three: cognitive

Attention, judgment, and the conditions under which decisions get made. Fatigue, time pressure, isolation, urgency, and the emotional levers a competent social engineer pulls.

This is the surface nobody owns. Physical security has a director. Information security has a director. The question of whether your chief executive is making authorization decisions at 11pm on the fourth night of a trip, on four hours of sleep, from a phone, belongs to no department at all.

The mechanism is physiology rather than character. Under acute stress, catecholamines degrade prefrontal function, and the executive who had four options at noon has two at 3 AM. That is Thermal Throttling, and the Human Zero-Day is the vulnerability it opens. An attacker who understands it does not need an exploit. They need to reach a tired person with a plausible urgent request, which is exactly what deepfake vishing and the psychology of CEO fraud describe from two different angles.

Allostatic Load is the version that builds over quarters rather than hours. A leader running at capacity for eight months is not the same decision-maker they were in month one, and nothing in your security program measures that.

Surface four: household

The spouse, the children, the home, the domestic staff, the family’s social media, and the routines that make a person findable.

This surface produces the attacks that work when the other three hold. Virtual kidnapping does not require touching the company at all. Neither does a threat delivered to a family member, and neither does the reconnaissance that oversharing on social media hands over for free, usually posted by somebody who does not work for you and never agreed to a policy.

It is also the surface where corporate authority runs out. You cannot order an executive’s teenager to lock down an account. That is a real constraint and it is not a reason to leave the surface unmapped.

Where Attackers Actually Move Between Them

The reason to hold all four in one model is that the attack path crosses them and your defenses do not.

Run one path through. Reconnaissance starts on the household surface, from a family member’s public posts: the neighborhood, the school, the recurring Thursday. That produces a physical routine and a set of names. The names go into a pretext, which gets delivered on the cognitive surface at the end of a travel week. The pretext produces one click or one approval on the digital surface. The digital access produces a document that makes the next pretext credible.

Four surfaces, one campaign, and at no point did the attacker care which of your directors owned the step they were on.

Now run your defense against that. The physical team saw nothing, because nothing physical happened. The security operations center saw a successful authentication from a known device. The awareness training covered phishing, and this was a phone call. Nobody was watching the household surface because it is not in scope.

Every control worked. The path went between them.

Building the Model

You cannot buy this. It starts as an hour of thinking, and the output is a document.

Step one: name the people

Skip the org chart and write the list of individuals who can move money, sign a binding commitment, approve a control exception, access the deal data room, or speak for the company. In most organizations this is between four and twelve people, and it always includes at least one person nobody thought of, usually an executive assistant or a finance manager with delegated authority.

Step two: write down what only they can do

For each person, the specific irreversible actions available to them. Be concrete. “Approves wires above $50,000.” “Can reset any employee’s multi-factor enrolment.” “Holds the only signature on the credit facility.”

This list is the reason an attacker would spend money on that individual, and it separates the high-value targets from the merely senior.

Step three: map each person against the four surfaces

For each name, ask what an attacker can learn and reach on each surface today. Where do they travel and how are those trips booked. What devices do they carry that you do not manage. What is publicly discoverable about their home and family. When are they routinely exhausted.

Most of this is an afternoon of open-source research, and you should have someone do that research rather than guess at it. The gap between what you assume is public and what turns out to be public will be the useful finding.

Step four: decide what you are accepting

You will not close all of it. The household surface in particular will stay partly open, because it belongs to people who did not sign your acceptable use policy.

Write down what you are accepting and why. A documented accepted risk is a decision. An undocumented one is an oversight, and the difference matters enormously when somebody asks afterward what you knew.

The Controls That Actually Move the Needle

Ranked by what we see produce results, rather than by what is easiest to buy.

Out-of-band verification for irreversible actions

One rule, applied without exception to the people in step one: any instruction to move money, change payment details, or release sensitive data gets verified through a second channel initiated by the recipient, using a number they already had. Not a number in the message.

This single control defeats the majority of the cognitive-surface attacks, because it removes the time pressure that makes them work. It costs nothing and it fails only when somebody makes an exception for the boss, which is precisely when it matters.

A named decision about the personal device

Decide, in writing, what your position is on the phones your executives carry every day. Managed, partially managed, or explicitly out of scope with a documented reason. Any of the three is defensible. Not having decided is not.

Session revocation on the incident checklist

Covered in depth here, and it belongs in this model because the executive’s session is the one worth stealing.

A quiet conversation about the household

Offer it rather than requiring it: we will do the same open-source review of your family’s public footprint that an adversary would, and give you the findings privately, and you decide what to do with them.

Framed as a mandate this gets refused. Framed as a service to a person whose family is exposed, it gets accepted more often than security teams expect.

Protecting the schedule as a security control

The calendar is the input to almost every physical and cognitive attack. Who can see it, how far ahead, and how much detail it carries are security questions that currently get answered by an administrator optimizing for convenience.

What This Costs You to Ignore

The executive threat model is unusual in that its failures are rarely partial. An employee’s compromised account produces an incident. A compromised executive produces a wire that cannot be recalled, a disclosure that cannot be retracted, a negotiating position that is already known, or a family in genuine danger.

Meanwhile the industry spends on the technical controls and close to nothing on the operator, which is a strange allocation given how many breaches route through a human decision.

The organizations that get this right sat down once, listed the people, mapped the four surfaces, and made an explicit decision about each one. Buying more protection came after that, if at all.

Go walk the back of your property.


Want the four-surface map built for your leadership team? Contact Grab The Axe for an executive threat assessment, or start with our free Human Attack Surface Score.

Distribute Intel
Jeff Welch
Chief Executive Officer
Jeff Welch
Architect of the 'Cognitive Firewall.'

A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.

View Author Page →