ANALYSIS

Threat Hunting Stops at the Company Edge

A large organisation with a mature internal security programme will sometimes reach outside it for a single job: looking at one executive’s private digital footprint. The security team is not admitting failure when it does this. It has reached a boundary.

The boundary is not the network perimeter. Modern security work crosses that routinely. The boundary is a limit on a method. Threat hunting, the discipline of chasing an adversary through data rather than waiting for an alert, is built to run inside the organisation. When the work that needs doing is on the private life of a named individual, the method does not travel with it. What crosses the edge to the executive is monitoring. What stays behind is the hunt.

This is about that gap: why it exists, and what it means for a security function that has an executive at real risk.

What the lock does not cover

The comparison people reach for is a lock on a door. Good security controls are the lock. They raise the cost of forced entry. They work because the door and its frame belong to you. An attacker studying an executive rarely starts at the door. They start with what is lying around outside it: the home address on a property record, the relatives named in a local news story, the running route posted to a fitness app, the personal email reused across a decade of accounts. None of that sits behind the lock. It sits in public, where no control mounted on the company’s door reaches it.

Boundary one: mandate

The first reason the method stops at the edge is authority. A computer security incident response team operates under a defined mandate and a defined constituency. Mandate and constituency are not loose words. Both are defined formally, in the charter documents that establish the team: the RFC 2350 profile, the ENISA maturity model, the SIM3 standard used to assess teams across Europe. The constituency is the population the team is authorised to act for. It is the company’s systems, accounts and staff in their working capacity.

An executive’s private life falls outside that constituency by definition. The home network, the personal phone, the spouse’s social media, the children’s schools: none of it is a company asset. The incident response team holds no charter to investigate any of it. Nothing about this is timidity. The team was chartered for the company’s estate, not the executive’s private life.

Boundary two: lawful basis

The second reason is legal, and it runs deeper than most security teams have cause to examine. Under European data protection law, an employer cannot simply decide to build a file on an employee’s private life. The Article 29 Working Party, whose guidance the European Data Protection Board carried forward, was explicit in its 2017 opinion on data processing at work. Employee consent is almost never a valid basis for processing, because an employee cannot refuse an employer freely. The power imbalance makes the consent hollow.

That leaves legitimate interest, and legitimate interest is not a blank cheque. It requires the processing to be necessary and proportionate, weighed against the employee’s own right to a private life. An employer systematically compiling an executive’s home address, family details and personal accounts would struggle to clear that bar. The exercise would carry formal impact-assessment duties of its own. The conclusion is an awkward one. The employer is often the wrong party to hold this map, even where it has the skill to draw it.

Boundary three: the method itself

The third reason is the method. Threat hunting, as the discipline is actually defined, is proactive, human-led and hypothesis-driven. A hunter assumes an adversary is already inside, forms a hypothesis about how, and searches the organisation’s own telemetry for the traces. The material it works on is endpoint data, network logs, authentication records. It faces inward by construction.

There is an outward form too. External threat hunting maps the adversary’s infrastructure: the domains, servers and tooling an attacker assembles before a campaign. It points at the threat actor, not at the defender’s own people. So neither form of the discipline is aimed at the question that matters here, which is what a stranger could assemble about your chief executive from open sources this afternoon.

The stack against one question

Set the whole stack against one question. What can each control actually see of an executive’s personal exposure, and does it hunt or merely enumerate?

A two-by-two grid mapping the security stack by direction (inward at the estate versus outward at the person) and method (enumerates a fixed list versus follows leads). SIEM, EDR, ASM and CSIRT sit in inward-enumerate; internal threat hunting is inward-follows-leads; dark-web monitoring, DEP/DRP and identity protection are outward-enumerate; only a consented, analyst-led investigation of the person is outward-follows-leads, highlighted in gold as the gap the corporate stack does not contain.
Control or functionWhat it works onPoints atHunts or enumeratesBlind to, for an executive
SIEM / SOCLog and event data from company systemsThe estateEnumerates alertsAnything outside corporate logs
EDREndpoint process and memory activityThe estateEnumerates detectionsPersonal devices, home network
ASM / EASMInternet-facing company assetsThe estateEnumerates assetsThe person, who is not an asset
Dark-web / credential monitoringBreach and leak dumpsKnown leaked dataEnumerates against inputsExposure never breached: public records, brokers
Digital executive protection / DRPBroker, social and dark-web sourcesThe personEnumerates against a source listThe lead a fixed list does not contain
Consumer identity protectionCredit and identity signalsThe personEnumerates against inputsEverything that is not a monitored identifier
Awareness trainingThe employee’s judgementBehaviourNeitherThe data an attacker already holds
CSIRT incident responseDeclared incidents on company assetsThe estateResponds to eventsPrivate exposure, where there is no incident to respond to
Internal threat huntingCompany telemetryThe estateFollows leads, inwardThe person’s life outside the estate
Consented investigation of a personOpen sources, with the subject’s authorisationThe personFollows leads, outwardBounded by consent; does not scale

Two rows carry the argument. Internal threat hunting is the one established discipline that follows leads rather than enumerating. It is aimed inward. Digital executive protection is the row that reaches the person. It does so by enumeration alone. The last row, the outward hunt of an individual, is the one thing the stack does not otherwise contain.

Enumeration is not a hunt

Security teams reasonably push back here. There are products aimed at exactly this problem. A digital executive protection service will scan hundreds of sources for a principal’s exposed data, then flag or remove what it finds. The objection deserves a precise answer, because the difference is mechanical rather than a matter of quality.

A monitoring product enumerates. You give it a fixed set of inputs: a name, some email addresses, a phone number. It checks them against a fixed set of sources, then reports the matches. It does this continuously and at scale, which is its real strength. But it is complete only relative to what you gave it. It finds you where you already knew to look.

A hunt follows leads. A finding becomes the next question. An alias turns up on one platform and becomes the search term that surfaces a forum account. The forum account carries a photograph whose caption names a town nobody entered as an input. Each step is a judgement about which thread to pull, the kind of judgement that does not automate. That is also what makes it expensive: analyst time, which does not compress. That is why a subscription and a manual engagement are priced an order of magnitude apart. The point is reach, not quality: what each method can actually get to.

None of this makes monitoring the lesser tool. The two do different jobs. They are strongest together. A subscription watches a broad set of known sources continuously and cheaply, which is the right way to catch routine re-listing and the slow drift of data back onto broker sites. A hunt goes deep on one person at one moment and finds what a fixed list was never going to hold. The sensible order is to hunt first, so the exposure is mapped and cleared, then keep monitoring running to hold the line afterwards. Neither replaces the other. An executive at real risk is best served by both.

Why scale is the wrong goal

There is a further point, and it inverts the usual sales logic. “It does not scale” is offered as the weakness of manual work. Scale is offered as the virtue of automation. For a principal at genuine exposure, scale is the wrong objective.

The exposed executive does not need every platform swept generically. They need the specific threads that lead to them run down to the end. That calls for depth, not breadth. A broad automated sweep cannot deliver it.

There is a quieter problem underneath it. A continuous automated service assembles the principal’s complete exposure profile and holds it, in a vendor’s systems, reachable through an app, on shared infrastructure. For most people that trade-off is sensible. For someone whose entire difficulty is that too much about them is already gathered in too few places, adding one more standing collection of the whole picture runs against the grain of the problem. A scoped engagement that does its work and then purges leaves no such store behind.

Investigation also leaves its own traces. Manual work can be done quietly. The queries and integrations of a mass-market platform are not built for discretion, because they were never meant to be quiet. For the executive who most needs the work, private, precise and low-footprint is worth more than broad and automatic. What the vendor sells as its strength is, for this particular job, the wrong optimisation. None of that is a fault in the product. It is doing a different job. Both have their place, side by side rather than in competition.

Reconnaissance is a stage of the attack

It would be easy to file all of this under privacy, a matter of taste rather than corporate risk. The threat data says otherwise. Reconnaissance is a formal stage of an attack, not a vague preamble to it. The MITRE ATT&CK framework, the reference taxonomy the industry shares, lists Reconnaissance as its own tactic, the phase in which an adversary gathers information on the target before any intrusion. The material for that phase is precisely the open-source exposure no corporate control is watching.

The 2026 Verizon Data Breach Investigations Report gives the stage its weight. The human element featured in 62 per cent of breaches. This year the report added pretexting to its tracked initial-access vectors, on the strength of the ransomware cases that now open with it. Pretexting is impersonation built on research: a convincing false scenario, delivered by someone who has done the reading. The more an attacker knows about a target’s relationships, habits and language, the more credible the approach. That advantage is measurable. In field experiments, generic phishing email is clicked by around a fifth of recipients, while a message that appears to come from a known contact or a real internal figure has been clicked by 62 to 72 per cent. A controlled trial of close to twenty thousand employees showed the pattern from the other side: the choice of lure moved the failure rate from under 2 per cent to over 30 per cent, a wider swing than any training in the study produced. What decides success is how well the message is tailored. That tailoring is assembled from exposure. The reconnaissance and the pretext are the same material seen from two sides. Remove the exposure and you remove the raw material for the pretext.

Why the work has to sit outside

This is where the three boundaries resolve into a single point. The reason an outside firm can do this work is the same reason the employer cannot. An individual can give free, informed consent to have their own exposure investigated on their behalf. An employer cannot manufacture that consent from an employee, because the relationship makes it unfree. So the work does not merely happen to sit outside the company. It has to. The only lawful, legitimate shape for it is an engagement between the investigator and the individual, with the individual’s authorisation, outside the employment relationship.

The separation a security team notices when it reaches for the phone is built into the problem, not a quirk of the market.

What a security function can still do

None of this leaves the organisation without options. It changes what the option is.

The organisation cannot build the executive’s personal exposure map itself. It can sponsor the executive to have it built, by a firm the executive authorises directly. It can treat the finding as the executive’s to hold rather than the company’s. It can fold the result into the threat model it already maintains for the business, without ever taking custody of the underlying personal data. And it can recognise that a monitoring subscription and an investigation are different instruments for different jobs, and stop asking the first to do the work of the second.

A security team that commissions outside help for a named executive has understood something correct about its own boundaries. The exposure is real. The risk is a corporate risk. The method that addresses it is one the company cannot run from the inside. Knowing where your own edge sits may be the most useful thing a mature security function can know.

Sources

  1. CrowdStrike. “What Is Cyber Threat Hunting?” (threat hunting as proactive, human-led, hypothesis-driven, conducted within the organisation’s own environment).
  2. MITRE ATT&CK. “Reconnaissance, Tactic TA0043 — Enterprise.”
  3. Verizon. “2026 Data Breach Investigations Report” (human element in 62% of breaches; pretexting added as a tracked initial-access vector).
  4. Article 29 Working Party. “Opinion 2/2017 on data processing at work” (WP249): consent generally invalid in the employment relationship; legitimate interest requires necessity and proportionality.
  5. ENISA CSIRT Maturity Framework; RFC 2350; SIM3 (constituency and mandate as formally defined).
  6. Lin et al. “Susceptibility to Spear-Phishing Emails.” ACM TOCHI, 2019 (reporting Jagatic et al. 2007, 72%, and Halevi et al. 2015, 62%, familiarity effects against roughly 20% for generic email).
  7. Ho et al. “Understanding the Efficacy of Phishing Training in Practice.” IEEE Symposium on Security and Privacy, 2025 (lure choice moved failure from 1.82% to 30.80%; lure realism outweighs training).

If this is your situation

If this kind of exposure affects your organisation, a Corporate Audit maps the full surface.

Assess organisational exposure Book a confidential scoping call

Share this briefing

If this was useful, sharing it helps others protect themselves. It also helps keep the intelligence briefings free.

Or get the quarterly intelligence brief — significant breaches, OSINT technique shifts, and executive privacy risks, once a quarter. Read the briefing →