Learn how to build and run a protective intelligence program for executives. Step-by-step guide covering the 6-phase PI cycle, POI monitoring, technology stack, and threat assessment frameworks used by Fortune 500 security teams.
Protective intelligence for executives is the discipline of proactively identifying, assessing, and mitigating threats to a company's leadership before those threats reach the principal. It combines open source research, behavioral analysis, and structured risk profiling to detect warning signals early enough for a security team to act, rather than react.
Protective intelligence (PI) differs from reactive security and executive protection (EP) staffing in a critical way: EP puts trained personnel between a principal and a threat that already exists. PI works upstream of that moment, looking for the indicators that precede a targeted attack so the threat never has to be physically intercepted at all.
The discipline gained new urgency after the December 2024 killing of UnitedHealthcare CEO Brian Thompson, which pushed corporate boards across every industry to ask whether their own executive protection programs included a real intelligence function, or just a security detail. The answer for most organizations was no. This guide covers what protective intelligence for executives looks like in practice: the six-phase operational cycle, how to build and manage a persons-of-interest program, the technology stack that supports it, and the mistakes that undermine even well-funded programs.
Executives face threats from five distinct actor types, each with different motivations and warning signs. Financially motivated criminals target executives for kidnapping, extortion, or ransom, a category that has grown sharply alongside the visibility of executive wealth; the 2025 kidnapping of a Ledger co-founder's family member in France illustrated how personal wealth signals, not just corporate role, now drive targeting decisions. Ideologically motivated actors treat an executive as a symbol of a company's policies, products, or industry, a dynamic that intensified in the wake of the UnitedHealthcare shooting, when online commentary framed the killing as a referendum on the health insurance industry rather than an isolated crime. Disgruntled current or former employees and litigants represent a third category, often the most detectable because their grievances surface in writing, in exit interviews, or in court filings before they escalate. Stalkers, whose fixation is personal rather than professional, form a fourth category that frequently intersects with an executive's family and residence. Nation-state actors, targeting executives for intelligence collection, coercion, or influence operations, round out the fifth category, particularly relevant for executives in defense, technology, and critical infrastructure sectors.
The 2024 attempted abduction of shipping executive Tim Heath outside his UK residence underscored a pattern security researchers have documented for decades: targeted attacks are predatory, not impulsive. The Pathway to Violence model, developed by researchers Fein and Vossekuil, holds that people who commit targeted violence do not "snap." They move through an observable progression, meaning there are detectable warning signals at nearly every stage of planning.
That predatory, observable nature is exactly why protective intelligence exists. It gives security teams a way to detect the pattern before it becomes an attack. But detection has gotten harder, not easier, as monitoring tools have proliferated. As one security leader described it during a product evaluation call, "We've been seeing a rise in this that we need to be concerned about. What is the year over year change? How do we quickly validate that to make sure we're not over indexing or under indexing on what we're seeing from our crisis management tools." Teams now generate more alerts than ever and extract less usable intelligence from them, a problem the rest of this guide addresses directly.
A protective intelligence program for executives runs on six phases: define intelligence requirements, build the executive risk profile, collect intelligence, analyze and assess threats, disseminate and act, and continuously reassess. The structure borrows from the classic government intelligence cycle (planning, collection, analysis, dissemination) but compresses its scope and tempo for the private sector. Corporate PI teams operate with fewer analysts, tighter timelines, and a narrower mandate: protect a defined set of principals and locations rather than a national interest. Every phase below has to produce something actionable, not just informative, because a corporate security director cannot act on a raw intelligence report the way a government analyst might file one for downstream use.
Priority Intelligence Requirements (PIRs) are the specific questions a protective intelligence program exists to answer, defined in advance so collection and analysis have a target. Critical Information Requirements (CIRs) are the specific, time-sensitive data points that would trigger an immediate response if detected. Without defined requirements, analysts default to collecting everything, which produces volume without focus.
Concrete CIR examples for an executive PI program include: any social media post containing the executive's name alongside violent language, any purchase of the executive's personal address data on dark web forums, any credible protest event within 500 meters of the principal's travel itinerary, any terminated employee who has made threats during the exit process, and any media coverage linking the CEO to a controversial policy decision. Each of these is written to be time-sensitive and immediately actionable: an analyst who detects one knows exactly what to do next, not just that something noteworthy happened.
Defining PIRs and CIRs correctly is what turns a vague geofenced risk assessment (comparing venue options before a public appearance, for example) into an operationalized collection plan with a clear trigger condition. Programs that skip this step and jump straight to collection often end up with automated change detection systems flagging dozens of low-relevance events a week, because nobody defined in advance what actually mattered.
The executive risk profile is a structured baseline covering public exposure mapping (what is publicly known about the executive and their family), lifestyle factor analysis (travel patterns, residence security, public appearances), and threat typology scoring against the five actor types described above. A widely used framework for structuring this profile is the 7 Ps: People, Places, Personality, Prejudices, Personal History, Political and Religious views, and Private Lifestyle.
The profile is not a one-time deliverable. It is a living document, updated after trigger events such as earnings calls, layoffs, public controversy, divorce filings, or an IPO announcement, any of which can shift the executive's threat exposure overnight. A useful proxy for why this matters: crime clusters within a half-mile radius of an executive's residence directly inform the physical security recommendations in the profile, and those clusters change over time.
Standardized profiling also solves a specific operational problem. One global travel company's security team found that its "medium risk" ratings were applied inconsistently across cities, because there was no shared methodology behind the label. A structured profile with defined scoring criteria prevents that inconsistency from creeping into decisions about executive travel and site selection.
Executive protective intelligence draws on six collection categories, each surfacing a different type of signal.
OSINT (Open Source Intelligence) refers to information gathered from publicly available sources: social media, news coverage, court filings, public records, SEC filings, and litigation databases. It is the broadest and most legally permissive collection category, and usually the starting point for any PIR.
SOCMINT (Social Media Intelligence) is platform-specific monitoring across X/Twitter, LinkedIn, Facebook, Telegram, Reddit, and TikTok, tracking mentions, sentiment, and direct threats aimed at the principal or the company.
Dark web and deep web intelligence covers forums, ransomware leak sites, illicit marketplaces, and doxxing repositories where personal data, addresses, or explicit threats against an executive can surface before they reach the surface web.
HUMINT (Human Intelligence) comes from advance team reports, venue staff interactions, insider tips, and law enforcement liaison relationships. It is the collection category most dependent on people rather than tools.
GEOINT (Geospatial Intelligence) refers to location-based threat activity: geofenced social media posts, route mapping, and crime pattern analysis tied to specific addresses, venues, and travel corridors. This is where street-level data does work OSINT alone cannot; a national crime average tells a security team little about the specific block where an executive's hotel sits.
Cyber-physical intelligence spans credential leaks, executive domain spoofing, and phishing campaigns targeting the principal or their family, threats that originate digitally but create physical-world exposure.
The value of combining these categories shows up directly in practice. One pharmacy retail chain's security team found that a centralized intelligence platform surfaced meaningful crime patterns near locations its prior process had missed entirely, a gap that pure OSINT monitoring would not have closed on its own.
Collection produces raw signal. Analysis turns it into a judgment about risk, and it is the phase that most separates a mature PI program from a data-aggregation exercise. The Capability-Intent-Opportunity (C-I-O) model is a standard analytical frame: does the person of interest have the capability to carry out a threat, the intent to do so, and the opportunity (access, proximity, timing) to act on it? A subject with high intent but no capability or opportunity scores differently than one with all three.
The Pathway to Violence model, developed by researchers Fein, Vossekuil, and Borum and used by the Association of Threat Assessment Professionals (ATAP), describes the observable progression most targeted attackers follow: grievance, ideation, research and planning, preparation, probing and breaching, and attack. Structured professional judgment tools, including the WAVR-21 and related behavioral threat assessment (BTA) frameworks, give analysts a consistent methodology for scoring where a subject sits on that pathway rather than relying on gut instinct.
This is also where the alert fatigue problem gets solved or made worse. As one security director put it, the operative question analysts have to answer is not "what's happening?" It's "is this normal?" A raw alert volume tells a team nothing about baseline behavior; only comparative analysis, backed by historical data, distinguishes a low-credibility complaint from a subject actively moving along the pathway to violence.
Intelligence that stays in an analyst's system produces zero protective value. Phase 5 routes findings through a defined escalation matrix, typically running from the Global Security Operations Center (GSOC) to the EP detail leader, then to General Counsel, and to law enforcement when a threat crosses a legal threshold.
The output of this phase is a finished intelligence product, and its format depends on urgency. A short-form alert supports an imminent decision (delay a public appearance, reroute a motorcade). A long-form threat dossier supports a strategic decision (whether to add close protection for a specific executive, whether to harden a residence). One executive residence security team demonstrated the short-form model in practice, sharing actionable intelligence with its security integrators within 30 minutes of identifying a risk, fast enough to inform a same-day decision.
Two failure modes dominate this phase. The first is intelligence that never leaves the analyst's system because there is no defined handoff process. The second, and more common, is over-alerting: when every finding gets escalated with equal urgency, decision-makers become desensitized and stop reading the alerts that actually matter.
Protective intelligence is an operating posture, not a one-time assessment. Programs sustain that posture through three mechanisms: an active persons-of-interest (POI) watchlist with case file management, trigger-based profile updates supplemented by a quarterly review at minimum, and a small set of program KPIs, typically time-to-detect, time-to-inform, and threats mitigated, tracked over time to demonstrate program value.
A useful operational scale for prioritizing attention is a three-tier framework: no immediate threats identified, some persons of interest at low-to-moderate risk requiring periodic review, and high-level threats requiring active intervention. One global AI company's security team applied this structure by tagging executive principal assets for ongoing monitoring, creating a systematic record instead of relying on individual analyst memory. A global consultancy's security operations center used automated change detection to flag month-over-month increases in crime near its offices, turning what had been a manual, periodic exercise into a repeatable review cycle. A separate travel company's security function used this same reassessment discipline to shift from a reactive posture, where threat assessments consistently lagged behind business decisions, to a proactive advisory function built into travel and site-selection planning from the start.
A person of interest (POI) is an individual who has exhibited behavior, made statements, or demonstrated intent that warrants documented, ongoing attention from a protective intelligence program, even if that behavior does not yet meet the threshold for law enforcement involvement.
Building a POI database starts with defined inclusion criteria: direct threats, concerning contact patterns, documented grievances, or behavior consistent with early stages of the Pathway to Violence model. Each POI is assigned a threat level classification, commonly a low-to-high scale tied to the C-I-O model, and monitored through lawful, ongoing review of social media and other open sources. Ontic, a widely used case management platform in the EP industry, frames POI tracking around four elements: behavioral assessment over time, litigation readiness, performance data, and trend identification, a structure that works whether a program uses dedicated POI software or a well-organized internal system.
Case file documentation matters for two reasons beyond situational awareness. First, a documented history of escalating behavior is what supports a restraining order or a criminal referral if a situation deteriorates. Second, it protects the organization if a POI later claims the company had no basis for its response. Programs should define in advance when a case gets escalated to law enforcement or legal counsel, rather than making that determination case by case under time pressure.
One recurring pattern in under-resourced programs: interns handling day-to-day POI monitoring, because the actual work, watching for name mentions and pattern changes across public sources, is systematizable but nobody has systematized it. That is a symptom of inadequate tooling, not a smart use of junior staff, and it is one of the clearest signals that a program has outgrown manual methods.
Protective intelligence performs three functions: threat identification, threat assessment, and threat mitigation. This framework originated with the U.S. Secret Service's National Threat Assessment Center (NTAC), whose research on targeted violence forms the basis for most modern corporate PI programs.
Threat identification is the detection function: surfacing a concerning social media post, a terminated employee's threatening exit-interview statement, or a subject purchasing an executive's home address on a dark web forum. Threat assessment is the analytical function: applying the C-I-O model and Pathway to Violence framework to determine how serious that identified threat actually is. Threat mitigation is the action function: the specific protective response, adding close protection coverage, notifying law enforcement, hardening a residence, that follows from the assessment. A program that only performs identification without assessment generates noise; one that assesses without mitigating produces reports nobody acts on.
An executive protection plan rests on three pillars: protective intelligence, physical security and close protection, and crisis management and response.
Protective intelligence identifies and assesses threats before they materialize. Physical security and close protection, the trained personnel, access control, and residential hardening, provides the physical barrier when a threat does reach the principal. Crisis management and response governs what happens after an incident occurs, from medical response to legal and communications coordination.
The three elements interlock. Protective intelligence feeds physical security, telling a close protection team where and when risk is elevated so they can allocate resources accordingly. Both feed crisis management, since a well-documented threat history speeds decision-making if a crisis does unfold. In practice, PI makes the other two elements more effective and resource-efficient: an EP detail that knows which specific threats are active can staff and posture accordingly, rather than applying uniform coverage regardless of actual risk.
The 7 Ps framework structures the executive risk profile described in Phase 2: People, Places, Personality, Prejudices, Personal History, Political and Religious views, and Private Lifestyle.
People covers the executive's known associates, family members, and staff, all of whom expand the attack surface. Places covers residences, offices, and frequently visited locations, each requiring its own site-specific risk assessment. Personality covers behavioral traits that affect risk exposure, such as an executive's public communication style or risk tolerance around personal security measures. Prejudices covers biases or strongly held positions the executive is publicly associated with, which can attract ideologically motivated threats. Personal History covers past controversies, litigation, or incidents that could resurface as a threat driver. Political and Religious views covers public positions that make an executive a target for ideologically motivated actors specifically. Private Lifestyle covers routines, habits, and personal activities that create predictable patterns an attacker could exploit.
Each of these categories feeds directly into the risk profile built in Phase 2 of the intelligence cycle. A profile that only captures professional exposure and ignores private lifestyle and personal history is incomplete, because targeted attackers frequently research all seven dimensions before acting.
The primary 3 Ps of threat intelligence are Predict, Prevent, and Protect. An alternate framing used in some programs is People, Process, and Platform, describing the operational components (staff, methodology, and technology) needed to run a program rather than its functional goals.
Predict-Prevent-Protect maps directly onto the proactive logic of protective intelligence: predict emerging risk by identifying patterns and early indicators, prevent an incident by acting on those indicators before they escalate, and protect the principal through physical security measures when prevention alone is not sufficient. This framing connects back to the six-phase PI cycle: prediction happens in Phases 3 and 4 (collection and analysis), prevention happens in Phase 5 (dissemination and escalation), and protection is the physical security layer the PI program supports rather than replaces.
Security teams building a protective intelligence function face three structural options: in-house, outsourced, and hybrid.
An in-house model requires dedicated analyst headcount, a technology stack, integration with an existing GSOC, and often ATAP certification for lead analysts. It offers full control over methodology but takes six to twelve months to stand up and carries the highest upfront cost. An outsourced or managed model provides 24/7 coverage and pre-built tools with a faster time to value, typically deployable in two to four weeks, but limits customization to the provider's existing methodology and scales with per-protectee fees rather than internal capacity. A hybrid model combines a lean in-house EP team with a technology platform and on-call analyst support, and increasingly represents the practical middle ground for mid-market corporate security teams that need more than a managed service but cannot justify a full in-house analyst bench.
The hybrid model is not theoretical. One global consultancy's security function runs its protective intelligence program with a Director of Security, a GSOC team, and a single dedicated analyst, covering more than 75 regional offices using a shared intelligence platform rather than a large internal team. That kind of lean staffing model is only viable when the technology layer does the collection and baseline analysis work that would otherwise require additional headcount.
The staffing reality behind the build decision is also worth naming directly. Security leaders report maintaining ongoing relationships with roughly 15 vendors at any given time, evaluating options for years before budget and timing align on a purchase, which means the in-house versus outsourced decision is rarely made in a single evaluation cycle. And the "interns as intelligence workforce" pattern described earlier in this guide is itself a symptom of the build decision made by default rather than deliberately: an under-tooled in-house model that nobody chose so much as backed into.
A 45-day pilot run by one pharmacy retail chain against 73 specific locations demonstrated how quickly a hybrid model can prove out: the trial alone saved the security team more than 37 hours of manual research time, evidence that speed to value does not require a full in-house buildout to materialize.
An effective PI technology stack is organized by function, not by vendor name. Each layer should do a specific job, and no single tool covers every layer.
Base Operations sits specifically in the geospatial intelligence layer, not the real-time alerting layer. It delivers street-level location intelligence covering the risk landscape around every address a principal visits, lives, or works, using regularly refreshed data (updated monthly, bi-weekly in many areas) across 25,000+ global sources. That is a different function from event-driven real-time alerting, and the two are complementary: a platform like Dataminr or Everbridge tells a team a specific event just happened nearby; a platform like Base Operations tells a team what the persistent risk baseline around a specific address looks like, which is what makes a real-time alert meaningful in the first place. Pair a real-time alerting tool with a geospatial threat-landscape platform, rather than treating either as a substitute for the other.
The value of combining a real-time alerting tool with persistent geospatial intelligence shows up in how teams actually use the data. One AI company's security team paired Base Operations' street-level intelligence data with Claude AI analysis to identify patterns that manual review had been missing, cutting executive protection assessment time by 75% and tripling the number of locations under active threat coverage. A global consultancy replaced a patchwork of spreadsheets and an unreliable business intelligence tool with a unified asset view, a change that drove a 35% efficiency lift across its GSOC.
Seven operational failures recur across otherwise well-resourced protective intelligence programs, each with a specific fix.
Two of the case studies referenced throughout this guide illustrate these failures directly. One travel company's security team found itself trapped in reactive mode for years, with threat assessments consistently lagging behind business decisions (Mistake #1) and data quality inconsistent across regions (Mistake #5), until it standardized its intelligence process. And the pattern of using interns as an intelligence-gathering workforce, described earlier, is Mistake #6 in practice: a signal that PI has not been resourced as seriously as physical security has.
Base Operations maps to four of the six phases in the protective intelligence cycle. In Phases 2 and 3, it provides street-level intelligence for building the executive risk profile and for GEOINT collection, covering 5,000+ global cities at sub-mile granularity. In Phase 4, it supplies historical baseline data that helps analysts separate genuine anomalies from normal background activity, directly addressing the "is this normal?" problem that drives alert fatigue. In Phase 5, its visualization tools support clear communication with stakeholders who need to understand a threat quickly, including non-security executives and legal counsel. In Phase 6, automated change detection and tagged asset monitoring support the continuous reassessment discipline that keeps a program from going stale between formal reviews.
In practice, this looks like location intelligence for site advance work ahead of executive travel, persistent threat landscape data across every residence and office an executive uses, and geospatial risk data that feeds directly into travel security planning. It is not a replacement for real-time alerting platforms and does not push event-driven notifications; it is the persistent, regularly refreshed threat landscape layer that makes the rest of a PI program's analysis and prioritization possible.
The results show up across programs of different sizes and maturity levels. One executive residence security team cut assessment time from 5 hours to 30 minutes per location while identifying crime clusters that led to zero security redesigns after the fact, evidence the proactive approach worked the first time. A global AI company's EP program achieved a 75% reduction in assessment time and tripled its threat coverage. A pharmacy retail chain completed assessments over three times faster during a 45-day pilot. A global consultancy's GSOC saw a 35% efficiency lift after consolidating its risk data into a single platform.
If your organization is building or maturing an executive protective intelligence program, take a look at the product to see how street-level threat intelligence fits into your existing PI cycle.
Protective intelligence is the investigative and analytical function that proactively identifies threats before they reach the principal, using open source research, behavioral analysis, and risk profiling. Executive protection is the physical security function: trained personnel who interpose themselves between a principal and a threat. The U.S. Secret Service captures the relationship well: if a protective detail has to draw a weapon, the intelligence function has already failed to detect and prevent the threat upstream. PI makes EP more effective and resource-efficient by giving detail leaders advance warning of where risk is concentrated.
Costs vary based on the number of protectees, the technology stack, and the delivery model chosen. Enterprise-grade PI platforms typically range from $50,000 to $500,000 or more annually depending on scope and features. Managed services generally charge per-protectee monthly fees rather than a flat platform cost. A hybrid model, combining a technology platform with a lean in-house analyst team, tends to offer the most cost-effective path for mid-market organizations that need more than a managed service but cannot justify a full in-house buildout.
A threat assessment for an executive follows five steps: collect available information on the threat actor or concerning behavior, apply the Capability-Intent-Opportunity (C-I-O) framework to evaluate seriousness, score the threat level using a defined classification scheme, determine the recommended protective action based on that score, and document the finding with a scheduled reassessment date. Programs following Association of Threat Assessment Professionals (ATAP) standards typically incorporate structured tools such as the WAVR-21 to keep scoring consistent across analysts and cases.
The Pathway to Violence model, developed by researchers Fein, Vossekuil, and Borum, describes the observable progression most targeted attackers follow: grievance, ideation, research and planning, preparation, probing and breaching, and attack. It matters for executive protective intelligence because it establishes that targeted attacks are rarely impulsive; they follow a detectable sequence with warning signals at nearly every stage. A PI program built around this model monitors for indicators at each stage, aiming to intervene well before a subject reaches the final stage.
Collecting OSINT from publicly available sources is generally legally permissible. Dark web monitoring requires authorized personnel operating within a defined legal framework, since some collection methods there carry higher legal risk. Location data and other more intrusive collection methods are subject to GDPR, CCPA, and various state surveillance laws depending on jurisdiction. Every protective intelligence program should operate under a written policy reviewed by legal counsel, and programs commonly reference Association of Threat Assessment Professionals (ATAP) guidelines when structuring that policy.
Building a POI database involves six steps: define inclusion criteria for what behavior warrants tracking, establish standardized data fields for each POI record, set a threat level classification scheme (commonly a low-to-high scale, sometimes framed as monitor, investigate, and intervene tiers), assign a specific analyst owner to each case, set defined review intervals rather than ad hoc check-ins, and document the data collection and handling policy in writing. Mature protective intelligence programs at large enterprises may track hundreds of active POI cases at once.
The Global Security Operations Center is the operational hub where protective intelligence findings, EP team activity, and incident management converge. A GSOC receives alerts and intelligence findings, triages them through a defined escalation matrix, and initiates protective actions when a finding crosses a defined threshold. Larger organizations typically run a 24/7 GSOC model; smaller ones often rely on a business-hours analyst model supplemented by a managed service provider for off-hours coverage. Organizations without a dedicated GSOC of any kind are usually the ones with the least consistent dissemination process, which is where intelligence findings most often stall before reaching a decision-maker.

Join 1100+ security leaders getting new ideas on how to better protect their people and assets.