● The Shield · Protective Intelligence

Someone could already be building your profile. We map it first.

A structured threat assessment for active threats and high-exposure prevention — mapping what an adversary can already assemble about you, then reducing what can be reduced.

01 The exposurePrivacy

A public-facing person leaves a richer profile than they realise — a schedule, a home area, a set of relationships, the details an approach could exploit. The Shield maps it before someone uses it.

Who the Shield is for

The Shield serves two situations. The first is a documented or suspected active threat — someone monitoring your activity, sending targeted messages, attempting impersonation, or building a profile for harassment or social engineering. The Shield models what an adversary could realistically assemble, assesses the pattern, and reduces what can be reduced.

The second is prevention. High public exposure is a risk factor before any specific threat materialises. Executives and public figures, but also creators, professional gamers, models, streamers, and anyone whose name, face and location are known quantities — the threat does not have to have started for the exposure to be real. Whether that justifies protective work in a given case is a proportionality question, taken up in an assessment of when protective intelligence beats standard precautions.

The Shield is a digital investigation. Physical security, active stalking, and criminal matters fall outside it and are referred to law enforcement and specialist partners.

What the Shield's threat assessment covers, and what it does not

The Shield assesses external digital exposure: public records and people-search profiles, credential circulation, family and relationship links, location and routine disclosure, social-engineering pretexts, impersonation material and signs of coordinated targeting. It uses the full Mirror and Lockdown investigation as its foundation, then adds 30-day pattern-of-life analysis, social-engineering vulnerability profiling, and threat or targeting analysis.

It is not a penetration test, a network vulnerability assessment, a physical security service, an incident response engagement or a criminal investigation. Those needs are referred to law enforcement or specialist partners. The Shield is the executive-exposure layer that sits between physical protection and enterprise cybersecurity.

That boundary decides what the work can honestly promise. The UK's National Protective Security Authority separates threat — the intention and capability of hostile actors to cause harm — from vulnerability, the factors that make a person more susceptible to a given threat, and states the relationship plainly: you reduce your risk by lowering your vulnerability. The Shield works on vulnerability. It cannot change anyone's intent toward you, and nothing sold as an assessment can. What it can do is establish what an approach would have to work with, and then reduce it.

National Protective Security Authority, Understanding Your Level of Risk (updated 22 April 2026), sections 1–5. NPSA guidance addresses people facing heightened threats to their personal safety and security; it does not endorse Privacy Insight Solutions or define the scope of this service.

What the Shield addresses

Conference appearances, tagged photographs, location-enabled posts, historical forum activity, publicly connected family members — each is a data point. Assembled, they create a targeting profile: a schedule, a home area, a set of relationships, the details an approach could exploit. For an active threat, that profile is already being used. For a prevention case, it is being built passively and will be available when someone decides to use it. The Shield maps it first.

That sequence is documented rather than hypothetical. NPSA lists surveillance and information gathering — carried out to obtain detailed knowledge of a person's location, daily routines and close contacts — among the methods used against people at heightened risk, and names two of the resulting conditions as vulnerability factors in their own right: information about your home or work address being readily available online, and having predictable routines.

NPSA, Understanding Your Level of Risk, sections 2 and 4.

What digital executive protection means in practice

Digital executive protection sits between physical executive protection and generic enterprise cybersecurity. The discipline behind it is protective intelligence, which maps your own profile the way an adversary would before any threat declares itself. Physical protection models the principal as a body to be moved safely; generic cybersecurity models them as a user with an account. Neither addresses the principal as what an OSINT-driven adversary sees: a public name attached to a home address, a family circle, a routine, an old breach password, and a set of handles that link it all together. The Shield is the digital layer those services do not cover, across four practitioner habits:

  • Map the exposure surface — where the home address has propagated, which credential pairs sit in stealer-log corpora, which family members are usable as pretext, what public schedule the filings and appearances draw.
  • Close the openings that close cleanly — people-search opt-outs, broker removals scoped to the threat picture, social tightening, registry-data minimisation, password and recovery-channel hardening.
  • Watch what reappears — people-search hits regenerate and credentials resurface; ongoing monitoring carries the cycle forward and is discussed as part of post-engagement review.
  • Escalate when the threat model changes — a targeted impersonation or a fresh combolist hit is an event, not a finding, and the response routing is different.
02 The investigationInsights

A protective-intelligence assessment built on the full Mirror and Lockdown investigation — then three Shield-specific research layers on top.

What the investigation produces

The Shield runs the full Mirror and Lockdown investigation as its foundation — people-search platforms, breach databases, stealer-log corpora, dark-forum archives, social profiles and corporate leak databases — then adds three Shield-specific layers.

01
Investigation foundation

Full Mirror + Lockdown scope — public exposure and credential circulation mapped before the Shield-specific work begins.

02
30-day pattern-of-life

A 30-day window of your publicly visible activity is analysed to map what your routine, locations and relationships disclose. Where a threat is active, that baseline is then watched forward, under separate consent.

03
Social-engineering profile

The profile a social engineer would build before contact — the shared history, affiliations and relationships they would invoke to seem legitimate.

04
Harassment & targeting analysis

Cross-platform behaviour analysis of found accounts to assess whether coordinated activity is underway. Physical danger is escalated.

The reasoning behind that third layer is the adversary's own. MITRE ATT&CK documents the gathering of victim identity information — personal details, credentials and authentication data — as a reconnaissance technique, and separately documents the searching of social media for roles, locations and interests to support targeted phishing and impersonation. The NCSC, in guidance written for people who may be of interest to nation-state actors, states the same mechanism in a line: attackers may use the information you post to engineer a spear-phishing attack.

MITRE ATT&CK, Gather Victim Identity Information (T1589) and Search Open Websites/Domains: Social Media (T1593.001). National Cyber Security Centre, Guidance for high-risk individuals.

What we produce

A full exposure report covering the Mirror and Lockdown foundation plus the three Shield-specific outputs — the 30-day pattern-of-life assessment, the social-engineering vulnerability profile, and the threat or targeting analysis — delivered in a structured report with a 60-minute analyst consultation to walk through it directly. Dedicated analyst support throughout; all collected data deleted within 48 hours of delivery.

Add-on AI & Deepfake Impersonation Assessment · €900

Based on Shield findings, assesses the publicly available material that could enable synthetic impersonation, with mitigation recommendations. Quoted and scoped separately.

03 The path forwardSolutions

The Shield does not stop at mapping. Where the surface can be reduced, we reduce it — and where a threat is active, findings are documented for escalation.

What changes

People-search opt-outs, broker removals, social tightening and registry-data minimisation are executed as part of the engagement, scoped to what the threat picture makes urgent. Exposed credentials are flagged for rotation with per-platform instructions; risky recovery routes are closed. Where the objective is an exhaustive, verified removal campaign across both broker surfaces rather than threat-driven reduction, that is the Eraser.

Documented for escalation

For an active threat, findings are documented in a form suitable for law enforcement or legal proceedings. Escalation routing is discussed in the consultation.

After the engagement

A hardened surface is a baseline, not a permanent state. The Shield is protective intelligence run as a project; its retained form is Guardian Executive, which keeps the same posture — surface, impersonation and event-driven checks, analyst hours held open — under an ongoing retainer. Your analyst will discuss whether it fits.

Family exposure

Where family members extend the targeting surface, the Family Member Exposure Check (€750/person) runs a Mirror-level investigation on each person and reads it against yours — which of their traces point back to you, and which links rebuild what has just been removed — with that person's individual consent. Where the whole household needs scoping as one surface, that is the Family Office Privacy Pack.

Detail & positioning

Why this is not what your monitoring subscription already does

Most people who commission a Shield are already paying for something — a credential-monitoring service, an identity-protection subscription, an automated removal tool. Keep it. This does not replace it. But there are two things a subscription structurally cannot do, and they are the two the Shield exists for.

Monitoring is seeded. It watches the identifiers you handed it: the names, addresses and email accounts you could remember at sign-up. That list is your own recollection of your exposure, and what is missing from it is the problem. A home address on a directorship filed years ago. A username abandoned before the platform was archived. A relative's public post that names your street. A dormant mailbox that receives nothing but still answers an account-recovery challenge. None of it is on the list, so none of it is watched.

Someone researching you has no list. They begin with your name and follow whatever surfaces, which is rarely what you would have nominated as important. That asymmetry is the whole point: you monitor what you remember, and they work from what is findable. The two sets are never the same, and the gap between them is where an approach gets built.

The second gap is combination. A subscription reports items. An address here, a breach hit there, each judged alone and each looking harmless alone. It does not report that the employer, the commute, the named assistant and the venue behind a tagged photograph describe a routine when read together, or that four unremarkable facts are precisely the four a caller needs to sound like they already know you. Reading fragments as a set is analysis, not alerting.

So the Shield runs one authoritative investigation, unseeded, and reads the findings against each other. It is point-in-time by design — it establishes which approaches you are actually open to, at a moment. Continuous watching is a different job and a real one; carried forward, that is Guardian Executive.

How the Shield compares

The Lockdown vs The Shield

The Lockdown investigates credential leaks and what is circulating about you. The Shield starts from an active threat: it includes the full Mirror + Lockdown foundation, then adds deep social analysis, harassment pattern assessment, a 30-day pattern-of-life study, social-engineering profiling, and a 60-minute consultation. You do not need to have bought The Lockdown first.

Does the Shield provide physical security?

No. The Shield is a digital investigation service. We assess online harassment patterns and identify what information could enable physical targeting. If you face an active physical threat, that is a matter for law enforcement — we will say so clearly and help you understand which digital evidence is relevant to report.

What 30-day monitoring includes

We analyse a 30-day window of your publicly visible activity — posts, check-ins, tagged photos, replies — to map what your routine, locations and relationships disclose. That window has already happened, so it reads an existing record rather than watching you, and it does not delay your report. Where a threat is active, the baseline is then observed forward for deviation, under a separate and time-limited consent. Prevention engagements usually stop at the baseline.

If you think you're being stalked online

Document everything first — dated screenshots of messages, profiles and contact attempts — and report to the relevant platforms. If the pattern suggests a credible physical threat, contact police and victim support. A professional report maps what the individual can actually see and build about you, in a form useful to law enforcement.

Questions

Shield FAQs

Not in the broad enterprise sense. The Shield is a threat assessment of an individual's externally visible digital exposure and targeting risk. It does not test networks, applications or security controls. If you need a full security assessment of systems and controls, you need a different provider. Organisations can commission The Shield for a named executive, or a Corporate Audit across a leadership team.

It is designed for executives, public figures, founders, creators and families whose name, role, relationships or routine create elevated exposure, and for people already facing targeted messages, impersonation, harassment or suspected monitoring. Scope is confirmed before any work begins.

A monitoring product watches the identifiers you registered with it and alerts you when one matches. That is a different function, not a smaller version of this one. An investigation starts without a list: the analyst decides where to look, follows what surfaces, and reads the findings against each other instead of one at a time. Tooling covers known patterns at scale; an analyst covers what fits no pattern yet. Keep the monitoring you have — this is the layer above it.

The Lockdown is an investigation into credential leaks and what's circulating about you. The Shield starts from an active threat — it includes the full Mirror + Lockdown foundation, then layers on deep social analysis, harassment pattern assessment, a 30-day pattern-of-life study, social-engineering profiling, and a 60-minute consultation.

No. The Shield is a digital investigation service. We assess online harassment patterns and identify what could enable physical targeting. An active physical threat is a matter for law enforcement — we will say so clearly and help you understand what digital evidence is relevant to report.

We analyse a 30-day window of your publicly visible activity — posts, check-ins, tagged photos, replies — to map what your routine, locations and relationships disclose. That window has already happened, so it reads an existing record rather than watching you, and it does not delay your report. Where a threat is active, the baseline is then observed forward for deviation, under a separate and time-limited consent. Prevention engagements usually stop at the baseline.

Document everything first — dated screenshots of messages, profiles, posts and contact attempts, saved to multiple locations. Report to the relevant platforms. If the pattern suggests a credible physical threat, contact police and victim support. A professional assessment maps what the individual can see and build about you, so you can reduce it.

Courts and police look for a documented pattern — repeated contact or monitoring over time, not a single incident. Useful evidence includes timestamped screenshots with URLs, contact across multiple platforms, attempts to find your location, and direct threats. A professional report cross-references behaviour across platforms and documents the pattern in a form useful for law enforcement and legal proceedings.

Understand what someone could build from what you've already shared.

The Shield is scoped on intake — complex situations are quoted individually. We respond within 24 hours, and scope is confirmed before any work begins.

Scope confirmed before any work begins · all data purged within 48h of delivery