RSS Amplifier

Black Widow Security · May 27, 2026

From Battleground to Boardroom: How Geopolitics Is Rewriting Executive Security

0
Sign in to vote or save

Black Widow Security · Black Widow Security

At 06:46 in the morning on 4 December 2024, Brian Thompson, Chief Executive Officer of UnitedHealthcare, was shot three times outside the Midtown Hilton Hotel in Manhattan. He was heading to his company’s annual investor conference, and he had no security detail with him.1 The conference itself had been publicly disclosed in advance under Securities and Exchange Commission (SEC) filing requirements, which meant his location, the time of his arrival and his identity as the attending executive were matters of public record before he left his hotel room.2

This was not random. Bullet casings recovered at the scene carried the words “deny,” “defend” and “depose,” echoing widespread and long-standing public anger at UnitedHealthcare’s claim denial practices.3 The sentiment that motivated the attack had been building visibly across online platforms for years before it materialised physically, accessible to anyone monitoring the information environment around executives in the health insurance sector. His wife later confirmed that there had been prior threats.4 The attack was not an intelligence failure in the sense of missing something obscure or technical, it was a failure to look at what was already available.

Following the killing, executive security firms reported a significant surge in enquiries from corporate clients who had never previously considered protective measures. 5The Thompson incident did not create a new threat environment, it made an existing one impossible to ignore.

In our experience working on protective details, the Thompson case illustrates failures that are not uncommon in corporate security architecture and that are, individually, entirely addressable. There can be an attitude across the C-Suite of “it will never happen to me”, the data often says otherwise.

The investor conference created a fixed, publicly known location and time in advance. From a preventative perspective, prior threat indicators had been noted but not actioned. From a reactive perspective, the absence of any close protection presence meant there was no protective buffer between the principal and an uncontrolled approach route.

The broader digital environment, in which hostility toward health insurance executives had been a persistent and escalating feature for several years, had not been subject to any systematic monitoring. Each of these failures is correctable. Together, in the absence of an intelligence-led protective framework, they proved fatal.

Most close protection work looks nothing like the version people imagine. There is rarely dramatic intervention, no visible tension and, on a well-run detail, very little that the principal notices at all. The job is to make the environment safe enough that the person you are protecting can focus entirely on the work they came to do, whether that is a board meeting, a series of back-to-back client engagements or a multi-city trip through environments that carry different risks in different ways.

I have worked on protection details with senior corporate leaders across a broad range of industries, primarily financial services, and almost always as part of a team rather than as a single operator. That distinction matters, because a single body on the ground with no intelligence support is not a protection detail. It is a physical presence, and a physical presence alone is reactive by definition.

Before any principal moved, we ran advance recces on every location they were scheduled to visit. Those recces were not box-ticking exercises. They produced structured reports on the environment, covering approach routes, access points, vulnerabilities, crowd dynamics where relevant and the specific conditions that would require us to adjust the plan. Simultaneously, another operator was running continuous open-source intelligence collection to build a risk score for each leg of the day, drawing on everything publicly available about the environment, the context and any relevant threat indicators. That intelligence fed directly into how we moved, when we moved and the decisions we made on the ground in real time.

The principal was always briefed. Not with everything, and not in a way designed to create anxiety, because an anxious principal changes their behaviour and changed behaviour creates its own vulnerabilities. Our role was to be facilitators, not restrictors. The aim was always to allow the person we were protecting to do their job as normally as possible, with the risk managed around them rather than imposed on them. There is, however, a line, and when the intelligence picture demanded a different approach, that conversation happened clearly and without ambiguity.

The protest intelligence work I have undertaken is a direct extension of the same philosophy. On several occasions I have been contracted to embed within protest activity surrounding a client’s operations and report in real time to the team managing the protective operation from the outside. The principle is identical: understand the threat environment from the inside, feed that understanding into the intelligence picture and give the people making protective decisions the information they need before the situation forces their hand rather than after it already has. A team watching from outside a protest can observe behaviour. They cannot hear what is being planned, identify who is making decisions or know the difference between a crowd that is venting and a crowd that is organising. That intelligence shaped building access decisions, route planning, executive entry and exit timing and the specific windows during which it was safe to move senior leadership. Not as a replacement for the external operation, but as the dimension of it that the external operation could not generate itself.

The gap that the Thompson case exposed is not just a gap in physical capability but also a gap in intelligence architecture. The protective detail that could have made a difference that morning was not one that was bigger or more visible. It was one that had already mapped the environment, scored the risk, briefed the principal and positioned itself accordingly before Brian Thompson stepped outside.

Subscribe to Black Widow Security

Senior executives have become visible pressure points for activism, protest mobilisation and hybrid information operations, rather than insulated decision makers operating behind institutional brands. Traditional executive protection models focused on venues, travel and event security are increasingly misaligned with threat vectors that now develop across interconnected digital, geopolitical and personal domains.

It is likely that organisations which fail to adopt intelligence-led protective security and structured due diligence around executive exposure will face avoidable operational disruption, reputational damage and heightened duty-of-care scrutiny over the medium term. Executive targeting incidents reached their highest recorded levels in 2025, doubling year-on-year across 424 documented incidents worldwide.678

Physical activity accounts for 85 percent of those incidents, including assaults, kidnappings, stalking and protest-related actions, and one third of all incidents resulted in injury or death.9 The executive protection industry, valued at $427.8 million in 2024, is projected to nearly double to $853.7 million by 2032, with 72 percent of security professionals citing an increase in public threats against executives as the primary driver of enhanced protective measures.10

This shift matters because most executive protection architectures were designed for an earlier era, one in which threats were slower, more geographically bounded and primarily physical. Today, hostility often incubates first in the information environment before manifesting in the real world, compressing warning timelines and expanding the number of actors capable of generating disruption. The Thompson case is the most visible recent illustration of this dynamic, but it is not an isolated event. It is a data point in an accelerating trend.

Subscribe to St James Briefing Room

KJ1 - It is likely that targeted pressure on senior executives will increase over the near to medium term as wars, sanctions and domestic protest cycles continue to drive anger toward political and corporate elites. Recent socio-political pressures linked to pro-Palestine demonstrations, climate activism and anti-billionaire sentiment have already illustrated how geopolitical grievances translate rapidly into executive-level risk.1112

KJ2 - It is highly likely that an executive’s digital shadow, including historical statements, political donations, social media activity, publicly accessible records and family affiliations, will increasingly serve as the initial access point for harassment, protest mobilisation and reputational targeting over the near term. The Thompson case illustrates what happens when this dimension of threat intelligence is not monitored, as grievance hardened into action without generating any organisational warning.1314

KJ3 - Traditional static executive protection models are highly likely to fail against decentralised, flash-mob style protests and doxxing campaigns, as these threats bypass physical perimeters by targeting the principal’s psychological safety and private reputation. Targeting increasingly occurs at workplaces and residential addresses rather than solely at managed corporate events, with residential incidents rising sharply since 2020.1516

KJ4 - There is a realistic possibility that corporate duty-of-care expectations will expand over the medium term to include continuous digital exposure monitoring, geopolitical threat briefings and family risk assessments as standard components of executive protection programmes rather than discretionary enhancements. Boards and general counsels are increasingly exposed to personal liability where foreseeable risks to executives were not adequately addressed.17

Geopolitics and the politicisation of leaders

The central claim of this assessment is straightforward: as geopolitics becomes more volatile, chief executives who once operated in the background are increasingly pulled into the foreground of political and social contention. Conflicts, sanctions and great-power competition are reshaping trade, finance and technology in ways that force visible, value-laden choices onto boards and executive teams.

Since the COVID-19 period, protest mobilisation has become more decentralised, digitally coordinated and personalised, narrowing the distinction between political and corporate authority figures where executives are perceived to influence socially contentious outcomes. In many jurisdictions domestic politics is more polarised, with sharper narratives about inequality, corporate power and the perceived capture of government by business interests. Executives making decisions in that environment are no longer treated as neutral technicians but are framed, fairly or not, as political actors.

It is likely that this politicisation of executive decision making will persist over the near to medium term. Decisions about health-care reform, energy transition, cost-of-living measures, sensitive technologies or financial stability are now routinely framed in moral terms, where who pays, who benefits and who decided carry as much weight as the technical details of the policy or strategy itself. Once those questions are personalised, senior leaders become natural focal points for public anger and organised campaigns, moving executive risk from a narrow concern of physical security teams into a wider strategic issue for boards and resilience leaders.

The contemporary information environment amplifies this trend. Social media, partisan commentary and loosely organised online communities make it easier than ever to attach a name and face to complex grievances, and a handful of viral posts is often sufficient to recast an unknown executive as the perceived architect of an unpopular decision. For hostile or disaffected actors, the operative question becomes less how do we challenge this institution and more which person can we pressure to get a reaction, making senior leaders attractive pressure points even when they are several steps removed from the front line.

Executives were not designed for this role. The legacy model assumed leaders operated in relatively closed spaces, shielded by institutional brands, controlled communications and physical security, with visibility largely limited to investor calls, conferences and managed media engagements. Everyday life was separate, home addresses were functionally private, and family members were rarely part of the public story unless by deliberate choice.

That separation has thinned considerably. Many executives now maintain a deliberate public profile online, engaging with staff, customers and peers under their own name, while corporate and property records are searchable at scale and conference appearances live indefinitely on video platforms. Friends, family and routines appear inadvertently in social media posts, creating a composite picture of the individual that is far richer than anything most organisations systematically map for security purposes. In effect, executives have become open-source individuals to a degree that would have been unthinkable a generation ago.

From a protective security standpoint, this openness is one of the most significant and underappreciated shifts in the executive risk environment. What an operator or a threat actor can learn about a principal’s movements, preferences, family, home location and professional schedule through open-source research alone would, in many cases, be sufficient to plan and execute a targeted approach without any specialist capability whatsoever. The Thompson investor conference is the clearest available illustration of this principle: the time, location and identity of the attending executive were matters of public record before the event took place, and no protective framework existed to account for what that public knowledge created.

For actors seeking influence, this openness is an opportunity. Targeting a named individual generates more attention and emotional energy than challenging a faceless entity, and it is considerably easier to tell a story about what this person did than to explain complex institutional processes. There is also a widespread belief, sometimes justified, that senior leaders respond more quickly to discomfort directed at them and their families than to more abstract reputational risk aimed at the organisation. These perceptions make executives an appealing route for applying pressure when other channels feel blocked or too slow, and the data reflects this clearly: residential and workplace targeting of executives has risen significantly since 2020, with activists demonstrating a consistent preference for predictable, high-visibility locations that maximise both disruption and media coverage.

Share

Every executive carries a digital shadow, which is the accumulated and publicly accessible record of their professional and personal life as it exists across the internet. This includes their own posts, media appearances, conference schedules, company filings, property records, political donations, family members’ social media accounts and the secondary sources that reference them. For most executives, this shadow is larger, more detailed and less well understood than they realise.

The intelligence value of a digital shadow to a motivated actor is considerable. A thorough open-source profile of a senior executive can reveal predictable daily routines, residential locations, family vulnerabilities, ideological exposures, reputational weaknesses and the specific grievances most likely to be used to frame them as a target. This is not a theoretical concern. It is precisely what occurred in the period before the Thompson shooting, when online communities were actively aggregating information about executives in the health insurance sector and the sentiment environment around them had been deteriorating visibly for years.

From an operational perspective, the digital shadow is simultaneously an intelligence source and a risk surface that requires active management. As an intelligence source, systematic monitoring of a principal’s digital footprint provides early warning of emerging threats, including escalating sentiment, the appearance of personal details in activist forums, specific threats or the identification of an executive as a campaign target. As a risk surface, an unmanaged digital shadow increases the probability that a motivated actor can plan and execute a targeted approach with minimal operational effort and no specialist resources.

What we find consistently in practice is that most organisations have not yet operationalised digital shadow management as a routine component of their executive protection programme. It is typically treated as a communications or reputational function rather than a security one, which means the threat intelligence value is lost entirely and the risk surface remains unmonitored. The gap between what is visible about a principal in the open-source environment and what their security team knows about that visibility is, in most cases, significant and, in some cases, dangerous.

The shift from background manager to visible pressure point has generated a broader and faster-moving risk surface around executives than most organisations currently acknowledge. At least four dimensions stand out.

Physical and protest-related risk. Demonstrations have moved beyond traditional sites of power to include corporate offices, shareholder meetings, private venues and, in some cases, residential areas. The home has emerged as the most common single location for targeting incidents, a shift that reflects activist groups’ preference for environments where executives are less likely to have any protective presence. It is likely that protests targeting locations associated with executives will remain a feature of contentious issues in the near term, with consequences for the safety of families, staff and neighbours alongside operational and reputational impacts.

Digital and information risk. Executives are increasingly named, discussed and targeted online in ways once reserved for senior politicians, with doxxing, harassment campaigns and manipulated content now accompanying conventional criticism. Cyber incidents now account for fourteen percent of documented executive targeting incidents, including death threats, impersonation, swatting and account compromise, and hybrid cases that begin online before transitioning to physical behaviour represent an emerging and concerning pattern.

Travel and geopolitical exposure. Senior leaders who travel to or operate in countries involved in conflicts, sanctions regimes or sharp diplomatic disputes carry a materially different risk profile from those whose work remains domestic. Their presence can be framed by local actors as endorsement, complicity or provocation regardless of nuance, and without robust geopolitical context and protective intelligence support it is more likely than not that routine trips will intersect with unanticipated flashpoints.

Legal and reputational risk. Executives are increasingly named personally in litigation, regulatory actions, shareholder activism and public inquiries. In these cases activist materials and media coverage often move rapidly from criticising an institution to focusing on the statements, personal associations and perceived moral responsibility of specific executives, with organisations facing growing scrutiny over whether foreseeable risks to their senior leaders were adequately addressed.

Taken together, these dimensions describe an executive risk landscape that has outpaced the assumptions built into many existing protection programmes. The case for a more explicitly intelligence-led approach lies precisely in this gap between a static, logistics-centric model and a set of threats that are dynamic, narrative-driven and increasingly personalised.

R1 - Adopt intelligence-led protection as the operating standard.

Organisations should transition from reactive, logistics-focused executive protection to a continuous intelligence-led model in which threat assessment, digital monitoring and geopolitical context inform protective decisions in real time. The distinction between security and intelligence functions should be dissolved at the executive protection level. A security posture that does not include systematic collection and analysis of threat indicators is not a protection programme in any meaningful sense: it is logistics management dressed as security, and the Thompson case illustrates exactly where that distinction leads. S&P 500 companies have already recognised this shift, with median executive security spending rising from $47,643 in 2021 to $98,069 in 2023, a trajectory that will continue to accelerate in the current environment.

R2 - Conduct a digital shadow audit for every principal.

Each organisation should commission a structured open-source assessment of every senior executive’s digital footprint, covering professional and personal exposure across all publicly accessible sources. The output should identify the most significant risk surfaces, including predictable routines, family vulnerabilities and reputational exposures, and should inform both the protective programme and any recommended reductions in digital exposure. This should be treated as a standing intelligence requirement that is reviewed at regular intervals rather than a one-time exercise conducted at onboarding.

R3 - Establish a geopolitical briefing cadence tied to executive activity.

Senior executives operating in sectors or geographies with elevated political sensitivity should receive regular structured briefings on the geopolitical context relevant to their specific profile, decisions and travel. These briefings should be forward-looking and calibrated to the individual rather than generic country risk summaries: the relevant question is not what is happening in a given region but how current events and activist dynamics interact with that executive’s specific public statements, corporate decisions and personal associations.

R4 - Extend formal risk assessment to family members and residential environments.

The growing pattern of protest and targeting activity directed at executives at their homes and through their families requires that residential security and family risk are treated as formal components of the protection programme rather than peripheral considerations. This should include a structured assessment of the family’s own digital footprint and a residential security review conducted by a qualified practitioner, with recommendations implemented proportionate to the threat level identified. Female executive targeting reached record levels in 2025, and the targeting of family members as an extension of pressure on the principal is a documented and growing feature of the current threat landscape.

R5 - Eliminate predictability in public-facing executive schedules.

Organisations should systematically review the degree to which executive schedules, travel patterns and public appearances are predictable and pre-disclosed. Where regulatory or commercial obligations require advance disclosure of executive locations or events, a structured approach to approach route management, venue security and close protection presence should be considered a standard requirement rather than an exceptional one. The principle here is straightforward: a publicly known location and a senior executive with no protective presence is not an oversight. It is an invitation.

R6 - Consider covert intelligence and covert protective capability as components of a 360 degree protection programme.

For executives operating in sustained or organised threat environments, conventional close protection represents only one layer of a genuinely comprehensive protective approach. Covert intelligence collection from within the threat environment itself (be it digitally or physically), and covert protective presence in the surrounding area, offer dimensions of coverage that visible security cannot replicate and that the current threat landscape increasingly demands. The ability to understand intent before it becomes action, and to maintain a protective presence that is invisible to those generating the threat, gives the wider security operation the time and information it needs to make the right decisions before the situation forces a reactive response. These capabilities are not reserved for heads of state or public figures operating at the highest levels of exposure. They are appropriate, available and proportionate for senior corporate executives whose threat picture has reached the level described in this assessment, and organisations that do not consider them are leaving a meaningful gap in the coverage they believe they have.

If you would like to discuss what an intelligence-led executive protection programme looks like in practice, contact Black Widow Security. For geopolitical intelligence assessments, strategic briefings Country analysis, visit St James Briefing Room.

Subscribe to Black Widow Security

Subscribe to St James Briefing Room

9

Executive Targeting Report: Analysis of Attacks on Corporate Executives from 2003–2025. 2026.

10

Executive Protection Trends in 2025. 2025.

11

Executive Targeting Report: Analysis of Attacks on Corporate Executives from 2003–2025. 2026.

12

Executive Targeting Incidents Doubled in 2025, Report Finds. 2026.

13

Corporate America’s Fears Billow After UnitedHealthcare CEO Brian Thompson’s Killing. 2024.

14

UnitedHealthcare CEO Brian Thompson Killing Prompts Deluge of Calls to Security Firms. 2024.

15

Executive Targeting Report: Analysis of Attacks on Corporate Executives from 2003–2025. 2026.

17

Executive Protection Trends in 2025. 2025.

No posts

Read the original on blackwidowsecurity.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.