Intelligence Library
Blackmail & Sextortion

When Silence Is Compliance: Corporate Liability in Employee Blackmail Cases

Organisations that fail to respond to blackmail attempts against their people expose themselves to reputational, legal, and operational risk. Here is what duty of care looks like in practice.

The legal landscape around employer duty of care in digital safety contexts is evolving rapidly. Courts in multiple jurisdictions have begun to address cases where employee harm arising from workplace-connected digital threats was foreseeable and unaddressed. The question is no longer academic: when an employee is targeted using information obtained from their professional role, and the employer knew the risk environment they operated in, the absence of a structured response carries legal weight.

This is not primarily a legal argument. It is an operational one. Organisations that create the conditions in which blackmail is concealed, that punish disclosure, or that treat digital threat to employees as a private matter, invariably discover that private matters become organisational ones. The blackmailed employee makes decisions under duress that affect systems, data, and colleagues.

Silence, in this context, is not neutral. When an employee discloses a blackmail situation and the organisation responds with indifference, administrative process, or dismissal rather than structured intervention, two things happen simultaneously: the employee's vulnerability deepens, and the organisation forfeits its window to manage the exposure.

Effective duty of care in this space requires three things: a published policy that treats digital threat and blackmail as matters warranting organisational support rather than employee discipline; a named, trained point of contact outside the standard HR chain; and a response protocol that has been rehearsed before it is needed.

The organisations that handle these situations well are not the ones with the largest security budgets. They are the ones that have normalised the conversation. Employees in those environments disclose faster. That speed is the most valuable risk management tool available.

"The organisation that punishes disclosure teaches its employees to manage these situations alone. The consequences of that lesson fall on the organisation."

Custodia One Advisory Perspective

What Your Organisation Should Do

  • Review your current blackmail and digital threat policy: if one does not exist, that is your first finding

  • Identify a trained, confidential point of contact who sits outside normal HR reporting lines

  • Audit your disclosure culture by asking whether employees would actually use the channels available to them

  • Conduct a legal review of current duty-of-care obligations in each jurisdiction you operate in

Advisory Enquiries

Facing this issue in your organisation?

Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.