Map accounts and recovery paths
Identify business and personal accounts that support important activities. Review authentication, recovery addresses, trusted devices, and who can assist with access. An overlooked recovery account can undermine stronger protection elsewhere. Prioritise the accounts with the greatest potential impact.
Review communication and delegated access
Understand how assistants, family members, advisers, and colleagues exchange sensitive information. Establish verification steps for unusual requests and changes to payment instructions. Choose communication tools and settings according to the information and participants involved.
Assess public exposure and impersonation
Review relevant public information and signs of impersonation within a lawful scope. Document sources and distinguish verified evidence from speculation. Removal or correction requests depend on the platform and process, so the plan should include escalation and follow-up.
Keep the plan practical
The result should be a short set of priorities, configuration actions, and response contacts. Revisit it after travel, role changes, new devices, or significant exposure. A discreet, usable process is easier to maintain than a long list of controls that nobody follows.
Put the guidance to work
Strengthen access controls, secure communications, and digital protection for organisations and executives.
Identity & executive security