Why Are Executives the Soft Target?
Because the organisation hardens systems while its leaders publish themselves: property records and society directories expose homes; family social accounts broadcast school runs and travel; conference bios and podcasts supply voice and mannerism samples for deepfakes; breached credentials from personal accounts unlock corporate ones. Whaling, extortion and physical-approach risks all begin as OSINT anyone can gather.
What Does the Audit Actually Map?
The assessment reproduces an attacker's file:
- Residence and movement exposure (addresses, vehicles, gym-and-golf routines visible online
- Family surface) spouses' and children's accounts, tagged locations, school identifiers
- Credential exposure (executive emails in breach dumps, password-reuse indicators
- Impersonation material) voice, video and writing samples; lookalike social handles already registered
- Aggregator and data-broker listings quietly compiling the above
What Does Reduction Look Like?
A prioritised scrub-and-harden program: takedowns and opt-outs where removal is possible; privacy-setting overhauls across family accounts; credential resets and passkey migration; registration of lookalike handles; and briefing the executive assistant, the perennial soft entry point. Reassessment on a cadence keeps the surface small as new data leaks. This is a standing service within Garuda's cyber intelligence practice.