Executive Exposure Checklist
A structured self-diagnostic tool covering the ten public and semi-public surfaces an adversary uses to assemble an executive target profile. Work through it on screen, print it for a board binder, or use it to scope where a deeper audit is needed. Each category is tagged with the response its findings usually need, because what you can do about a finding matters as much as what it exposes.
Who this is for
Executives, board members, senior professionals, HNW individuals, and anyone who wants a clear picture of what a targeted adversary can assemble about them from public and semi-public sources. No technical background is required — each check is something you can run yourself, and most take only a few minutes.
What you gain from working through it
- Visibility into your own exposure. The ten categories below mirror the order a professional reconnaissance workflow follows in practice — brokers first, then breaches, filings, family, dark-web credentials, social-engineering surface.
- Lower personal discoverability. Each listed action removes a pretext ingredient an attacker would otherwise build on. Fewer ingredients mean fewer usable attack paths against you and the people around you.
- A harder target for targeted fraud. Whaling, CEO fraud, SIM-swap, and vishing all depend on cheap background research. Remove the raw material and the economic return on targeting you drops sharply.
- A repeatable baseline. Exposure drifts — new breaches, new people-search hits, new filings. Re-run the checklist every six to twelve months to catch drift before it turns into an incident.
How to judge what you find
Three questions decide what a finding is worth, and they matter more than how alarming it looks. Work them in this order.
The first question is the hardest to ask about yourself. You know why a detail exists and what it meant at the time, so it reads as ordinary. Someone assembling a profile has none of that context and reads the same detail for what it gives them. The gap is structural rather than a matter of effort, and a self-audit reaches the visible layer but not the outside judgement of it. Where that judgement matters more than the inventory, an Online Reputation Analysis is the outside read of what your findings say about you.
Two decisions, then a follow-up
A useful review ends with a next step, not a severity label. First decide whether a finding can be removed or reduced, or whether it has to be controlled around. Then decide whether it needs watching because it can return, or revisiting only if it connects to something else. The tag on each category below is the response its findings usually need — the individual finding still decides.
Remove or reduce
The publisher has discretion, the account can be secured, or the public detail can be generalised. Broker listings, exposed numbers, live credentials, and calendar detail usually sit here.
Control around it
The record is official, archived, or required by law. The work is to reduce the corroborating exposure around it rather than to delete it.
Watch after action
Use this after a removal or reduction when the source repopulates. People-search profiles, broker copies, breach indexes, and image results all drift back.
Revisit if it connects
Low-value details do little on their own. They matter when they connect to an address, a family member, a credential, travel, or timing.
Why removability drives the order: removal reduces exposure, but it needs verification and recurrence checks rather than trust. Gueorguieva, King, Panidapu, and Ho’s 2026 assessment of 522 registered data brokers found that only 9% were fully compliant with transparency requirements; in an audit of 250 request processes, 43% made it impossible to exercise all privacy rights and 64% introduced substantial friction. Consumer Reports’ 2024 Data Defense field test followed 32 volunteers in California and New York across 13 people-search sites and found that manual opt-outs removed about 70% of listings after four months, while paid services varied widely. Sources: Privacy Without Remedy; Consumer Reports, Data Defense, Yael Grauer, 8 August 2024. PI analysis: Best data broker removal services in the US.
Category 1: Data Broker Presence
Go deeper Data broker opt-out guideService The Eraser
Category 2: Breach Database Exposure
Go deeper Why breaches without passwords still put you at riskService The Lockdown
Category 3: Social Media Privacy Exposure
Go deeper How to protect your digital footprint
Category 4: Corporate Filings and Public Registers
Go deeper The structural doxing problem for European executives
Category 5: Property and Land Registry Records
Category 6: Family Member Discoverability
Go deeper Why social engineers target the executive’s familyService The Shield · Family Member Exposure Check
Category 7: Photo and Reverse-Image Searchability
Category 8: Domain and WHOIS Leakage
Go deeper What traces do you leave online
Category 9: Dark-Web Credential Exposure
Go deeper How modern infostealers workService The Lockdown
Category 10: Social-Engineering Surface
Go deeper How your footprint tells an attacker when to strike
This checklist is for informational and self-diagnostic purposes only. It does not constitute legal or security advice. The name, role, organisation, and date you enter, along with your notes and checklist progress, are stored locally in your browser and are never transmitted to our servers.
← Library