Executive Exposure

Less attack surface around your key people.

A confidential, manual outside-in review of public traces around visible decision makers. You learn which signals enable social engineering and account takeover — and receive a prioritized protection plan for the person, assistant, and IT.

ScopePersonNamed people and roles — not domain packages.
MethodManualPassive OSINT, authorized, no private-system access.
Briefing60–90 minHandoff to person, assistant, and IT.
Entryfrom €5,9001 person · additional people added transparently.
Outcomes

Three concrete outcomes for leaders and their circle.

The engagement ends with actions person, assistant, and IT can execute together — not a sensational list.

Social engineering

Fewer usable pretexts.

Public role and contact traces are prioritized so attackers find fewer credible entry points.

Less social-engineering context
Accounts

Less takeover surface.

Leaks, old identities, and login surfaces become a concrete hardening sequence.

Harder accounts
Response

Safer handling of sensitive requests.

Person, assistant, and IT share the same warning signs and escalation rules.

Clearer escalation
Review approach

Personal attack surface where role, visibility, and risk meet.

Many executive risks are not in a server log. They come from combinable public details: roles, appearances, old accounts, data leaks, assistants, travel and communication patterns. Billing and scope run on named people — domains appear only as context.

Executive ExposureAuthorized · Person scope

We apply the same care as in company CASP analysis (manual, passive, validated, with countermeasures), but strictly person-centered. This is not private curiosity — it is about which public signals open realistic attack paths and which measures close them.

Only named, approved people and roles Manual OSINT and leak assessment — no scanner dump Protection briefing, not sensational or doxing output
1 · MandateB2B client commissions the review in writing for the named people.
2 · Scope listNames and roles, boundaries, and what is explicitly out of scope.
3 · NDA & recipientsMutual NDA, fixed recipient group, secure delivery channel.
4 · Internal clearanceClient confirms affected people and internal rules (e.g. notice/HR) are handled.
5 · vs. domain CASPHere the people mandate is primary. Domain verification (DNS TXT) applies to company CASP analysis.
What we do not do
Identity signalsLeak contextSocial vectorsBriefing

No doxing

You get risks and protections — not a reusable collection of private details.

B2B mandate only

Business clients only, named people with authorization. No consumer orders, no third-party VIPs without a mandate.

Not a domain CASP substitute

Personal and company attack surface are complementary. Bundle available in a scope meeting.

No company risk score

There is no 1–10 firm score. Success = fewer attack signals + a prioritized protection plan.

No legal advice

Privacy and compliance references are operational, not legal opinions.

Personal risk dossier · no doxing
Review areas

Which personal risk indicators we examine.

Focus on information attackers combine to fake trust, target accounts, or abuse communication paths — around the person.

Identity and role footprint

Public profiles, responsibilities, contact paths, and details that enable credible pretexts.

Leak and account context

Breach signals, email patterns, old accounts, and account-takeover indicators.

Social-engineering vectors

Relationship patterns, public schedules, assistants, vendor and partner context.

Communication and approval surfaces

Channels and workflows through which sensitive requests reach the person and assistant.

Deliverables

Four artifacts. One clear handoff.

Signal, risk, recipients, and next step stay separated. The goal is actionable reduction of personal attack surface — not another report in the archive.

01

Executive Exposure Dossier

Prioritized personal exposures, attack paths, recipient group, and protection priorities.

Person scopePriorityConfidential
02

Exposure Map

Role, relationship, and account signals by abuse path; domain only as context.

SignalsContextAbuse path
03

Social-Engineering Briefing

60–90 minutes: scenarios, warning signs, and approval rules for person, assistant, and escalation.

BriefingAssistantApproval
04

Personal Remediation Plan

Sequence for trace reduction, account hardening, communication rules, and follow-up.

Quick winsAccountsFollow-up
Investment

Clear pricing by people scope.

Fixed net prices. Start with one person; add more transparently. Optional: domain CASP (Lite from EUR 7,500 · Full EUR 19,900) in the same program — complementary, not a substitute.

PeopleScopePrice (net)Duration
1 personStandard review · 4 artifacts · briefing 60–90 minEUR 5,9005–8 working days
2 peopleTwo person scopes, joint prioritizationEUR 8,8007–10 working days
3 peopleLeadership set (e.g. CEO + 2 key roles)EUR 11,7008–12 working days
Additional personExtra named scope in the same engagement+ EUR 2,900+2–3 working days
Process

Four steps from scope to protection briefing.

Tight and confidential. Work starts only after mandate, scope list, NDA, and recipients are set.

  1. 01

    Scope & mandate

    B2B mandate, named scope list, NDA, recipient group, and boundaries — in writing before start.

  2. 02

    Exposure mapping

    Manually correlate public signals, leak context, and social-engineering vectors — passive, no system access.

  3. 03

    Risk assessment

    Separate irrelevant traces from realistically usable attack paths around the person.

  4. 04

    Briefing & protection plan

    Confidential handoff (60–90 min) and concrete measures for person, assistant, and IT.

Next step

Ready to review attack surface around your key people?

Entry from EUR 5,900 for one named person. In the scope meeting we fix people, mandate, and recipients — domain CASP on request.

Scope first, action after.
from EUR 5,900 · 1 personNext step
Request scope meeting