An adversary can assemble a targeting profile of a senior executive and their family from open sources, fast. It is a physical-security problem, not a privacy one, and it can be shrunk.
Give me an hour & open sources. I'll map your CEO's life, down to their Sunday routine.
Here is the home address, & the second one at the lake. Here is the make & plate of the car in the driveway. Here is the gym, the 6 a.m. slot, the same three mornings a week. Here is the spouse's employer, the kids' school, the coffee shop after drop-off. Here is the charity gala next month, seat assignment & all. I never made a phone call. I never left my desk.
That is not a party trick, & the "I" in it is not me. It is the reach that a threat actor now has before they have done anything that would draw attention. A grievance-holder, a stalker, an activist willing to cross a line, a professional working for someone else. Automated collection tools & the data-broker economy have turned a name into a dossier: home, routine, family, finances, movement. The point of this edition is to move that fact out of the "privacy" column, where it gets ignored, & into the column where it belongs. This is a targeting problem. Targeting problems get people hurt.
Privacy language makes exposure sound like an inconvenience, something between you & an advertiser. Reframe it as a protective analyst would. A published home address plus an observable routine is the raw material of surveillance & unwanted approach. The gap between "someone knows where you live" & "someone is waiting when you get there" is smaller than most executives assume, & it is measurable.
The federal numbers are blunt. In 2019, about 1.3 percent of U.S. residents age 16 & older, roughly 3.4 million people, were stalking victims, per the Justice Department's Bureau of Justice Statistics. Among victims who were stalked both in person & through technology, 67 percent feared being killed or physically harmed; across all stalking victims, fewer than a third, 29 percent, reported it to police. Read those figures together & the argument makes itself: this is not about embarrassment, it is about people who reasonably believe they may be killed, & who mostly stay silent.
Family exposure widens the attack surface. A protectee may travel with a detail; the spouse driving to work & the child walking to class almost never do. And when exposure meets grievance, the two combine into a targeting package. The clearest proof is a case the protection field does not forget. In July 2020, a gunman posing as a delivery driver came to the New Jersey home of U.S. District Judge Esther Salas & opened fire, murdering her 20-year-old son, Daniel Anderl, & wounding her husband. The attacker had found the family's address online. New Jersey's legislative response, Daniel's Law, signed in November 2020, now bars the publication of home addresses & unlisted phone numbers for judges, prosecutors, law enforcement, & their immediate household family. An online address became a route to a front door, & a front door became a killing. The statute exists because the pathway is real, not theoretical.
For a long time, assembling that kind of profile took time, tradecraft, & money. That barrier is gone, & its collapse is the reason exposure that was acceptable five years ago is now a standing liability.
The mechanism is documented. In its May 2014 report, the Federal Trade Commission examined nine data brokers & found a scale that is hard to picture: one broker held information on 1.4 billion consumer transactions & more than 700 billion aggregated data elements; another was adding over 3 billion new data points every month; a third maintained more than 3,000 data segments on nearly every U.S. consumer. That was a decade ago. The machinery has only grown since. Regulators are still chasing it: the FTC brought 2024 enforcement actions against location-data brokers such as X-Mode & InMarket, & the Consumer Financial Protection Bureau moved in 2024 to bring data brokers under fair-credit rules. Now, layer automated open-source collection tools on top of that inventory. The cost, time, & skill that profiling used to require simply fall away.
The exposure curve is bending in the same direction as the tooling. In its January 2021 study, Pew Research Center found that 25 percent of all U.S. adults reported severe online harassment, including physical threats, stalking, & sustained abuse, up from 15 percent in 2014. That is a threat surface widening on a clear trajectory, not noise. The Anti-Defamation League's 2024 survey corroborates it, & notably now counts doxxing & swatting among the recognized harms.
A note on the hour in the headline. "Under an hour" is our professional assessment, not a lab result. It reflects what a trained analyst using commercial tools & broker aggregators can assemble in practice. What is documented is not the stopwatch, it is why the stopwatch keeps shrinking: the data-broker economy & automated collection have collapsed the cost, time, & skill that this work once demanded.
Here is the turn, & it is the whole point. If an adversary can run that hour against your principal, so can you, first, on your own terms. The discipline already exists. It is a vulnerability assessment, pointed at the digital footprint instead of the perimeter.
Audit first. Map what an outside collector can actually assemble on the executive & the household from open sources & brokers. Not a checklist of accounts, the real picture: home, second home, vehicles, routine, family, movement. Then prioritize by risk the way you would prioritize a site survey. Home address, family members, & a predictable routine are the exposures that convert into physical approach. Rank them above the ones that merely annoy.
From there, pursue systematic removal from data-broker & people-search sites, paired with privacy hardening on the accounts & habits that keep re-seeding the data. And be honest about what removal buys you. In its August 2024 evaluation, Consumer Reports found that paid removal services took down only about 35 percent of listings on average over four months, which means roughly two-thirds of the exposure stayed up even after people paid to erase it. Every participant still appeared on some people-search sites at one week, one month, & four months. Its verdict was plain: these services are "largely ineffective."
That finding is not a reason to skip removal. It is the reason to calibrate what removal can do: it is not fire-and-forget, it is one tool among several for reducing exposure, & it earns its keep only when it runs continuously. Brokers refresh their inventories on their own cycle, so any scrub is partial & leaky & starts going stale the moment it is done. Treat it as one layer, run continuously alongside hardening & monitoring, the same way you never audit the building once & call it safe for a decade.
Right now, for most organizations, the executive digital footprint is an unmanaged risk surface no one has ever formally assessed. It sits outside the security program, in the "privacy" column, quietly generating the exact intelligence an adversary needs. Companies understand this well enough to spend on it once it becomes visible; in its 2025 proxy statement, Meta disclosed that Mark Zuckerberg's security program cost more than $24 million in 2024 (closer to $27 million once protective travel is folded in), the largest such program among major U.S. companies, while Alphabet, Nvidia, Apple, & Amazon each disclosed their own seven-figure programs. The footprint is the upstream side of that same problem, & it is far cheaper to manage than to ignore or to react after the fact.
Reducing it is not a novelty service. It is protective intelligence doing its actual job, moved to where the threat now originates. The adversary's hour is real. The difference is whether someone on your side runs it first, finds the gap, & closes it, on a schedule, before anyone else goes looking. That is the work we do at Scopos Strategies, & it is what executive protection looks like when it is done upstream.
This article was produced with AI assistance. The perspective and security expertise are the author's own.