A number has been circulating in our industry for the better part of a year. Forty-two percent (42%) of security chiefs report a significant increase in threats of violence against company executives. It comes from research covering more than 2,300 security leaders at global companies, and it turns up in board decks, vendor emails, and conference keynotes with reliable frequency.
The number does useful work. It starts budget conversations and it confirms something most protection teams already feel on the ground. What it does not do is help anyone on a Tuesday morning when a post naming your CEO has picked up 40,000 views overnight, the comms team is asking whether to respond, and someone on the executive floor wants to know whether the family should stay home today.
That morning is where an executive protection program actually gets tested. Here is a working sequence for it.
The instinct is to open the post and start reading. Reading matters, and it comes second.
The first thing worth establishing is the shape of the thing.
How many places is this appearing, how fast is it moving, and is the movement organic or pushed? A single angry post from a mid-size account behaves very differently from the same text copied across six platforms inside an hour. The second pattern suggests coordination, which changes both the threat picture and the response.
Continuous threat monitoring and alerting across social platforms and fringe forums is what turns this into a five minute question rather than a two hour one, because the collection has already happened before anyone thinks to ask for it.
The spread also tells you about timing. Content that peaked six hours ago and has gone flat is a different operational problem than content still climbing.
Content gets attention. Actors create risk. The questions that matter are about the human behind the account.
This is where investigations and identity resolution work earns its place. Proximity changes everything. In one biotech case, a team established that the person of interest did not live locally, which was reassuring for roughly a minute, until they determined that the original post had been made from a location very close to where the executive was staying at the time. That single detail moved the file from passive monitoring to active coordination with the protection detail.
Not every viral mention of an executive is a threat to that executive. Some of it is sector grievance using a recognizable name as shorthand. Some is a reputational attack aimed at the company, with the CEO serving as the nearest available face. Some is impersonation, where the account pretends to be the executive rather than targeting them.
These call for different responses, and blurring them together burns credibility quickly. A protection program that escalates every mention at the same volume trains leadership to stop listening.
Useful questions here are: what does the poster appear to want, do they reference capability or access, and has the language moved from complaint toward specificity. Specificity about location, schedule, or means is the signal that changes your forward action.
Notification order matters more than notification speed.
Inside security, the chain runs up before it runs out. The analyst who found it briefs the GSOC manager, the GSOC manager briefs the CSO, and the CSO owns the call on what goes to the business and when. Skipping that step to get word to the executive faster usually produces a briefing that nobody has assessed yet.
From there it runs outward. The executive's chief of staff generally needs to know before the executive does, so the principal hears it with context attached rather than as a forwarded screenshot. Comms needs to know early, because a response strategy built without security input can hand the post a much larger audience. Legal needs visibility if there is any prospect of a law enforcement referral. The detail needs to know before the next movement, not after it.
That order is worth writing down on an ordinary day. Rebuilding it at six in the morning produces gaps.
Every one of these events creates a record that somebody will ask for later. Sometimes months later, sometimes in a legal setting.
Timestamped captures, the assessment you made, the reasoning behind it, who was notified and when, and what changed as a result. Holding that in a case manager rather than across email threads and a shared drive folder means the next analyst who encounters this name already has the history in front of them.
Repeat contact is common. A second post from the same account carries much more weight when you can see the first one.
Most of the work that makes the morning after manageable happens on quiet days. Baseline monitoring on executive names and known variants. A current read on what personal information is publicly exposed. An agreed threshold for what escalates and what gets logged. An intelligence team and a protection team that have actually met.
None of that requires new budget. It requires deciding, in advance, who makes the call.