Executive Exposure Checklist

A structured self-diagnostic tool covering the ten public and semi-public surfaces an adversary uses to assemble an executive target profile. Work through it on screen, print it for a board binder, or use it to scope where a deeper audit is needed. Each category is tagged with the response its findings usually need, because what you can do about a finding matters as much as what it exposes.

Last updated: July 2026 Designed for: executives, board members, privacy-conscious professionals See also: NIS2 Risk Vector

Who this is for

Executives, board members, senior professionals, HNW individuals, and anyone who wants a clear picture of what a targeted adversary can assemble about them from public and semi-public sources. No technical background is required — each check is something you can run yourself, and most take only a few minutes.

What you gain from working through it

  • Visibility into your own exposure. The ten categories below mirror the order a professional reconnaissance workflow follows in practice — brokers first, then breaches, filings, family, dark-web credentials, social-engineering surface.
  • Lower personal discoverability. Each listed action removes a pretext ingredient an attacker would otherwise build on. Fewer ingredients mean fewer usable attack paths against you and the people around you.
  • A harder target for targeted fraud. Whaling, CEO fraud, SIM-swap, and vishing all depend on cheap background research. Remove the raw material and the economic return on targeting you drops sharply.
  • A repeatable baseline. Exposure drifts — new breaches, new people-search hits, new filings. Re-run the checklist every six to twelve months to catch drift before it turns into an incident.

How to judge what you find

Three questions decide what a finding is worth, and they matter more than how alarming it looks. Work them in this order.

What it enables in practice Does it let someone contact you, locate your home, impersonate you, time an approach, or reach your family? A page-one search result is more usable than a stale archive record that takes specialist searching to find.
Whether it can be changed Some records can be deleted. Others can only be reduced, substituted, or made less useful.
Whether it comes back Broker profiles, breach indexes, and image results drift. A clean result today is not always a clean result later.

The first question is the hardest to ask about yourself. You know why a detail exists and what it meant at the time, so it reads as ordinary. Someone assembling a profile has none of that context and reads the same detail for what it gives them. The gap is structural rather than a matter of effort, and a self-audit reaches the visible layer but not the outside judgement of it. Where that judgement matters more than the inventory, an Online Reputation Analysis is the outside read of what your findings say about you.

Two decisions, then a follow-up

A useful review ends with a next step, not a severity label. First decide whether a finding can be removed or reduced, or whether it has to be controlled around. Then decide whether it needs watching because it can return, or revisiting only if it connects to something else. The tag on each category below is the response its findings usually need — the individual finding still decides.

Remove or reduce

The publisher has discretion, the account can be secured, or the public detail can be generalised. Broker listings, exposed numbers, live credentials, and calendar detail usually sit here.

Control around it

The record is official, archived, or required by law. The work is to reduce the corroborating exposure around it rather than to delete it.

Watch after action

Use this after a removal or reduction when the source repopulates. People-search profiles, broker copies, breach indexes, and image results all drift back.

Revisit if it connects

Low-value details do little on their own. They matter when they connect to an address, a family member, a credential, travel, or timing.

Why removability drives the order: removal reduces exposure, but it needs verification and recurrence checks rather than trust. Gueorguieva, King, Panidapu, and Ho’s 2026 assessment of 522 registered data brokers found that only 9% were fully compliant with transparency requirements; in an audit of 250 request processes, 43% made it impossible to exercise all privacy rights and 64% introduced substantial friction. Consumer Reports’ 2024 Data Defense field test followed 32 volunteers in California and New York across 13 people-search sites and found that manual opt-outs removed about 70% of listings after four months, while paid services varied widely. Sources: Privacy Without Remedy; Consumer Reports, Data Defense, Yael Grauer, 8 August 2024. PI analysis: Best data broker removal services in the US.

0 of 23 checks completed 0%

Category 1: Data Broker Presence

01 Data Broker Presence Remove, then watch

Category 2: Breach Database Exposure

02 Breach Database Exposure Reduce

Category 3: Social Media Privacy Exposure

03 Social Media Privacy Exposure Remove

Category 4: Corporate Filings and Public Registers

04 Corporate Filings & Public Registers Control around

Category 5: Property and Land Registry Records

05 Property & Land Registry Records Control around

Category 6: Family Member Discoverability

06 Family Member Discoverability Depends on publisher

Category 7: Photo and Reverse-Image Searchability

07 Photo & Reverse-Image Searchability Remove, then watch

Category 8: Domain and WHOIS Leakage

08 Domain & WHOIS Leakage Depends on record age

Category 9: Dark-Web Credential Exposure

09 Dark-Web Credential Exposure Reduce

Category 10: Social-Engineering Surface

10 Social-Engineering Surface Remove
Notes

What to do with the result

Unchecked boxes tell you where you have not looked yet. The findings tell you what to do. Several findings that enable direct contact, location, impersonation, timing, or family mapping mean the reconnaissance surface is already assembled against you, and the response needs structuring rather than piecemeal fixes.

Most of the actions above are yours to run. Where a finding needs work you would rather not do yourself, the route depends on the outcome it landed in.

For a named executive or a defined leadership cohort, a Corporate Audit runs this assessment end-to-end: surface mapping across the ten categories above, documented findings, and a prioritised remediation plan you can hand to legal, HR, or security. No client details are published; the deliverable is a bound report plus a debrief.

Where the subject is a family rather than an individual, the same work scopes differently. A Family Member Exposure Check maps what is findable about each person connected to the principal. A Family Office Privacy Pack scopes the household and its staff as a single surface rather than a collection of individuals, and does not require a core service first.

Assess organisational exposure

This checklist is for informational and self-diagnostic purposes only. It does not constitute legal or security advice. The name, role, organisation, and date you enter, along with your notes and checklist progress, are stored locally in your browser and are never transmitted to our servers.

← Library