Intelligence Library
Executive Targeting

Board Briefings as Attack Surface: What Your Directors Are Leaking

Investor calls, conference presentations, and LinkedIn activity provide detailed intelligence to adversaries. Executive digital hygiene is a strategic concern, not a personal one.

The intelligence value of publicly available information about senior leaders and board members is systematically underestimated. Quarterly earnings calls are transcribed and analysed. Conference presentations are recorded and studied. LinkedIn profiles are updated in real time with information about responsibilities, projects, and relationships. Press releases announce leadership transitions, new business relationships, and strategic priorities. Taken in aggregate, this material provides a sophisticated adversary with an operational picture of an organisation's leadership structure, decision-making processes, and strategic vulnerabilities that would previously have required sustained intrusion activity to develop.

Open-source intelligence gathering against senior leaders is now a standard precursor to both social engineering attacks and executive impersonation fraud. The attacker who calls a financial controller impersonating the CFO has, in most cases, spent time reviewing the CFO's public communications to ensure the impersonation carries sufficient contextual authenticity. The contextual material is public and freely available. The effort required to weaponise it has decreased substantially.

Board meeting materials, analyst briefings, and investor presentations create a particularly concentrated intelligence risk. These documents often contain strategic information, personnel details, and forward-looking plans that, in the hands of an adversary, significantly improve the quality of subsequent targeting. The risk is compounded by distribution to parties, including external advisors and institutional investors, who operate outside the organisation's security architecture.

Personal digital footprint management for senior leaders requires treating their online presence as a strategic asset to be managed rather than a personal matter to be ignored. This includes: systematic reduction of unnecessary personal information in professional profiles; monitoring of the information landscape around key individuals for evidence of targeting; and regular review of the intersection between public communications and sensitive operational information.

The most significant changes are often procedural rather than technical. Establishing clear protocols for what categories of information are appropriate for inclusion in public-facing communications, and building review mechanisms for executive content before publication, can substantially reduce the intelligence value of an organisation's public information environment.

"Your adversary's OSINT operation starts before your security team knows there is an adversary. The material they are working from was published by your own communications function."

Custodia One Advisory Perspective

What Your Organisation Should Do

  • Conduct a structured OSINT assessment of your senior leadership to understand what an adversary already knows

  • Establish information classification protocols that apply to executive communications, not just internal documents

  • Implement a pre-publication review process for senior leader content that assesses operational security implications

  • Brief board members specifically on the intelligence value of their public profiles and the aggregation risk

Advisory Enquiries

Facing this issue in your organisation?

Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.