Intelligence Library
Online Grooming

State Actors and Criminal Networks: The Executive Grooming Playbook

Intelligence agencies and organised crime networks run deliberate, long-horizon relationship operations against executives, defence personnel, and policymakers. This is not accidental contact. It is methodology.

The term 'grooming' carries an almost exclusive association with child safety. That association, while justified, has had an unintended consequence: it has blinded corporate security thinking to one of the most prevalent and effective attack methodologies used against adult professionals. State-linked intelligence operations, corporate espionage networks, and organised crime groups all use long-horizon relationship development to cultivate access to targets who would never respond to a conventional intrusion attempt.

The mechanics are identical regardless of target. A relationship is established through a channel the target perceives as low-risk: a professional network, a conference connection, a shared-interest community. The relationship is developed slowly, over weeks or months, until a degree of trust is established. Then the relationship is used. The exploit may be an information request that appears innocuous, an introduction to a compromised third party, or a request for access framed as a professional favour.

What makes corporate grooming particularly difficult to detect is that the target's perception throughout the process is of a legitimate, positive relationship. They are not being deceived in ways they recognise as deception. They are experiencing what feels like professional good fortune. Reframing only becomes possible in retrospect, and often not at all unless the organisation has investigative capacity to connect events after the fact.

The sectors most exposed are those where professional relationship-building is both normal and necessary: defence contracting, financial services, government affairs, energy, and advanced manufacturing. In these sectors, the line between a legitimate professional contact and a cultivated access vector requires active intelligence work to establish.

Custodia One's corporate grooming advisory focuses on three elements: recognition training calibrated to specific roles and sectors; due diligence protocols for relationships that reach defined access thresholds; and incident analysis capability that can reconstruct timelines when a compromise is suspected.

"The playbook used against a teenager on a gaming platform and the playbook used against a defence procurement officer on LinkedIn differ only in vocabulary. The psychological architecture is the same."

Custodia One Advisory Perspective

What Your Organisation Should Do

  • Assess which roles are most exposed to cultivated access attempts based on their access level and external visibility

  • Implement relationship due diligence for contacts that reach defined sensitivity thresholds

  • Provide recognition training covering the specific channels and approaches used in your sector

  • Build an incident analysis capability that can reconstruct relationship timelines after a suspected compromise

Advisory Enquiries

Facing this issue in your organisation?

Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.