602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

When Does an Executive Need Close Protection?

Concept of a board decision framework for executive close protection showing threat-trigger nodes, a scoring matrix, and a rising escalation ladder in navy and gold

A company should authorize close protection when a documented threat assessment shows credible, escalating risk to an executive that ordinary security cannot mitigate — a specific threat, a pattern of surveillance or fixation, a controversial decision driving public hostility, or travel into a high-risk jurisdiction. The decision should follow a structured framework, not a single frightening email, and should scale through defined escalation tiers rather than jumping straight to a full-time detail or, worse, doing nothing until an incident forces the issue.

Every general counsel and board member who has sat through a security briefing knows the uncomfortable middle ground this question occupies. On one side sits the executive who wants to believe nothing will happen to them, or who worries that a detail signals fear, weakness, or corporate excess. On the other sits the security director or outside consultant who, having seen what happens when protection arrives too late, would rather over-protect every principal than risk under-protecting one. Between those two positions is where boards actually have to decide — and too many of them decide badly, either ignoring a credible threat until it becomes a headline or authorizing an expensive standing detail with no evidentiary basis at all. This guide lays out the decision framework a well-governed company actually uses: the threat triggers that should start the conversation, the risk-assessment discipline that turns a vague worry into a defensible finding, the escalation tiers that let a response scale with the evidence, and who inside the organization should be making the call.

Why do so many boards get this decision wrong?

Because the decision is almost always made under one of two bad conditions: too much emotion, or too little information. A threatening message, a viral controversy, or a competitor’s headline-making incident produces a reactive spike in appetite for protection that fades within weeks if nothing happens — and the program that gets stood up in a panic is rarely the program the actual risk warrants. Conversely, absent a triggering event, protection rarely reaches the board agenda at all, even when an executive’s public exposure, wealth visibility, or role in a contentious transaction has quietly become substantial. Both failure modes share the same root cause: there is no standing framework that converts observable facts into a decision, so the decision only gets made in crisis, and crisis is a poor time to reason clearly.

There is also a governance dimension that is easy to underweight until litigation makes it unavoidable. Companies owe a duty of care to senior executives that scales with foreseeable risk, and directors carry fiduciary exposure if a foreseeable, well-documented threat was known and no reasonable response was authorized. A framework that produces a written record — threat identified, risk assessed, response scaled to the finding — is not just better security practice; it is the paper trail that later demonstrates the board acted reasonably. ASIS International and other professional security bodies have long argued that documented risk assessment, not instinct, is what separates defensible corporate security programs from ones that only look good until they are examined after the fact.

What is the decision framework, in outline?

The framework has three moving parts, and the order matters. Threat triggers are the observable facts that should place the question on the table — a specific message, a pattern of unwanted contact, a change in the executive’s public profile, or elevated travel risk. A risk assessment then converts those triggers into a measured finding by weighing the credibility and capability of the threat against the executive’s actual vulnerability and the severity of the consequence if the threat materializes. Only then does the response get sized, through a set of escalation tiers that range from heightened awareness and monitoring at the low end to a full standing detail at the high end — with the tier justified by the assessment, not by who is loudest in the room.

Skipping any of the three steps produces the same predictable failures. Acting on a trigger without an assessment produces protection sized to fear rather than fact. Assessing risk without defined escalation tiers produces an accurate finding with no mechanism to translate it into action. And building escalation tiers without first doing the assessment produces a menu of options with no principled way to choose among them. The sections below take each part in turn.

What threat triggers should put close protection on the board’s agenda?

Not every uncomfortable email warrants a security detail, and not every credible threat announces itself with an explicit statement of intent. A working list of triggers — the facts that should prompt a formal risk assessment, not an automatic deployment — typically includes the following:

  • Direct or implied threats of harm received by the executive, the company, or family members, whether by email, letter, social media, or a third party.
  • A pattern of fixation or unwanted contact — repeated communications from the same individual, attempts to locate the executive’s home or family, or escalating boundary-testing behavior at events or the workplace.
  • A controversial corporate decision likely to generate sustained public anger directed at a named individual — a plant closure, a mass layoff, a product-safety failure, a contentious merger, or litigation naming the executive personally.
  • A sudden increase in public profile — a high-visibility media cycle, an IPO, a leadership transition into public view, or viral attention, especially where it is paired with wealth visibility.
  • Travel into an elevated-risk jurisdiction, particularly regions flagged by the U.S. Department of State’s Overseas Security Advisory Council for kidnap-for-ransom activity, civil unrest, or targeted crime against foreign business travelers.
  • A workplace-violence indicator connected to a termination, a labor dispute, or a disgruntled former employee with knowledge of the executive’s routine.
  • A data breach or leak exposing the executive’s home address, family details, daily schedule, or financial information — particularly when paired with any of the triggers above.
  • A peer or industry incident — an attack, kidnapping, or serious threat against an executive at a comparable company, which should prompt a proportional review even absent a direct threat to your own principal.

The presence of a trigger is a reason to assess, not a reason to deploy. Treating every trigger as an automatic deployment decision is how companies end up with protection programs that are expensive, resented by the executives they cover, and disconnected from the actual risk — which is precisely the failure mode the next step exists to prevent.

How does a risk assessment turn a trigger into a defensible decision?

A professional risk assessment measures three variables and multiplies them, conceptually, into a single finding: threat (who, and how credible and capable are they), vulnerability (how exposed is the executive — a published home address, a predictable commute, a public calendar), and consequence (how severe is the outcome if the threat succeeds — physical harm, kidnapping, loss of leadership continuity, litigation, reputational damage). A high-threat, low-vulnerability, low-consequence scenario is treated very differently from a moderate-threat, high-vulnerability, high-consequence one, even though both might arrive at the board’s attention looking equally alarming in the moment.

In practice, the assessment draws on open-source intelligence to map the executive’s digital footprint and address exposure exactly as a hostile actor would see it, a review of any direct communications or behavioral indicators from the specific person or group of concern, a physical vulnerability survey of the residence, workplace, and habitual routes, and a structured evaluation of the executive’s public profile and the current controversy, if any, driving attention toward them. This is intelligence and analysis work, and at Honeybadger it is handled in-house and delivered nationwide — the same command that would later run any protective detail also builds the assessment that determines whether one is warranted, which keeps the finding honest rather than shaped by whoever stands to profit from a larger deployment. The output is not a single word like “safe” or “unsafe”; it is a scored, prioritized finding that plugs directly into the escalation-tier decision below.

Concept of an executive protection escalation ladder rising from monitoring through advisory, part-time coverage, and a full standing detail, with a threat indicator line climbing beside it in navy and gold

What are the escalation tiers, and how does a response scale with the finding?

A defensible program does not have two settings — nothing, and a full-time armed detail. It has a ladder, and the assessed risk determines which rung the executive sits on today, with a clear description of what would move them up or down. A representative escalation structure looks like this:

TierAssessed riskRepresentative responseTypical authorization level
Tier 0 — BaselineNo specific threat; standard executive exposureDigital-footprint hygiene, address suppression, periodic OSINT sweep, security awareness briefingSecurity team, no board involvement required
Tier 1 — Elevated awarenessA trigger has surfaced but is unassessed or preliminaryFormal risk assessment initiated, protective-intelligence monitoring stood up, no physical detail yetSecurity director, GC notified
Tier 2 — Advisory / event-basedAssessment finds moderate, defined riskPart-time or event-based coverage, secure transport for high-exposure movements, residential hardeningGC or security committee approval
Tier 3 — Active protectionAssessment finds a credible, active threatStanding protective detail, secure transport, residential security, continuous intelligence monitoringBoard or security-committee approval, budget authorization
Tier 4 — Severe / crisisImminent threat, kidnap-and-ransom exposure, or active incidentFull multi-agent detail, family coverage, travel-risk operations, law-enforcement liaison, crisis-management activationFull board notification, crisis team activated

The tiers exist to be moved through in both directions. A Tier 3 detail that has run for six months with no further threat activity and a stable intelligence picture should be reviewed for step-down, not left in place indefinitely out of institutional inertia. Equally, a Tier 1 monitoring posture should escalate immediately if the intelligence picture worsens. The discipline of the framework is precisely that movement between tiers is evidence-driven and documented, not a one-way ratchet toward maximum coverage or a permanent freeze at whatever level was authorized during the original panic.

Who inside the company should actually make the call?

Authority should sit above the executive being protected, for an obvious but frequently ignored reason: the person most at risk is the worst-positioned person to judge their own risk objectively. Executives systematically underestimate threats directed at them — normalizing hostile contact, dismissing warning behavior as harmless, or resisting protection out of pride, denial, or a genuine dislike of having their autonomy curtailed. A framework where the principal effectively vetoes their own protection defeats the purpose of having a framework at all.

The workable model places initial trigger evaluation with the security director or CSO, formal risk-assessment authorization with general counsel, and Tier 3 and Tier 4 decisions — the ones carrying real budget and real disruption to the executive’s life — with a board security committee or the full board, informed by the written assessment rather than by anecdote. Larger organizations formalize this as a standing security or risk committee with a defined charter; smaller and closely held companies typically route it through general counsel and the CEO or founder directly. Whatever the structure, the decisive feature is that it exists before the crisis, with defined roles, so that the first hostile email of the year does not become an improvised committee meeting under pressure.

The board authorization framework, step by step

The following sequence converts the framework above into a repeatable process a security or risk committee can adopt directly:

  1. Establish standing triggers. Document, in advance, the categories of event that require a risk assessment to be opened — direct threats, fixation patterns, controversial decisions, profile spikes, high-risk travel, workplace-violence indicators, data exposure, and peer incidents.
  2. Assign an intake owner. Name who receives and logs a triggering event — typically the security director or CSO — so nothing depends on an executive remembering to mention it.
  3. Commission the risk assessment. Route every trigger to a formal threat-vulnerability-consequence assessment rather than an ad hoc judgment call, with a defined turnaround time for urgent situations.
  4. Score the finding. Require the assessment to produce a rated, prioritized finding — not a narrative alone — so the escalation-tier decision has a number to point to.
  5. Match the finding to a tier. Use the escalation table as the default mapping from finding to response, departing from it only with documented, specific justification.
  6. Route authorization to the right level. Tier 0–1 stays with the security function; Tier 2 goes to general counsel or the security committee; Tier 3–4 goes to the board or security committee with budget authority.
  7. Document the decision and the rationale. Record the trigger, the assessment, the tier selected, and who authorized it — the record that later demonstrates reasonable care.
  8. Set a review date. Every tier above baseline gets a scheduled reassessment, not an indefinite default, so the program can step down as risk recedes and step up before it escalates unmonitored.

What mistakes do companies make even after adopting a framework?

The most common failure is treating the framework as a one-time decision rather than a living process. A board authorizes a Tier 3 detail after a serious incident, the detail runs, nothing further happens, and eighteen months later no one has revisited whether the original threat is still live — the program simply continues by inertia until someone questions the line item, at which point it is cut without a new assessment either. Both directions of that failure — freezing at a stale tier and abandoning coverage without reassessing — stem from skipping the review-date discipline built into the framework.

A second common mistake is letting the executive’s comfort override the assessment in either direction. Some principals resist any visible protection regardless of what the finding shows, quietly undermining a Tier 3 program by refusing secure transport or disclosing their schedule publicly; others, once accustomed to a detail, resist stepping down even after the threat has demonstrably resolved. A well-run program treats executive cooperation as an input to be managed — through education, discretion, and a protective posture designed to minimize friction with the executive’s actual life — not as a veto over what the evidence shows.

A third mistake is confusing physical protection with the whole of the response. A meaningful share of executive risk today is digital before it is physical — a leaked home address, a data-broker listing, a geotagged photograph, a compromised account. CISA and other authorities have repeatedly flagged the convergence of cyber-enabled reconnaissance with physical targeting of executives. A framework that authorizes a detail but never addresses the digital exposure that made the executive findable in the first place has solved only half the problem, and often the cheaper half to fix.

How does Honeybadger support this decision for boards and general counsel?

Honeybadger Solutions builds the assessment that this framework depends on, and we build it as a neutral finding rather than a sales document. Threat and vulnerability analysis, OSINT and digital-footprint mapping, protective-intelligence monitoring, and background investigations supporting the assessment are handled in-house and delivered nationwide and internationally — this intelligence work is our core strength. We commonly work directly with general counsel and security committees to stand up the standing framework itself — the trigger list, the intake process, the authorization chain — so the next threatening email does not require reinventing the process from scratch.

Where an assessment concludes that physical executive protection is warranted, delivery follows the honest structure of our model. In Arizona, protection is executed by our own in-house, AZ-licensed agents, supervised under direct command from our Casa Grande, Phoenix, and Oro Valley offices. Outside Arizona, protective coverage is delivered through a commanded vetted-partner network, with established theaters in California, Texas, and Florida and coverage elsewhere coordinated as the assessment requires — so a company gets a licensed, accountable response scaled precisely to the tier the assessment supports, not an oversold standing detail or a dangerously thin one.

Frequently asked questions

Does a single threatening email automatically justify a security detail?

No. A single message is a trigger that should open a formal risk assessment, not an automatic deployment. Most single, isolated threats resolve at Tier 1 monitoring once assessed — a pattern of escalation, a credible and capable sender, or corroborating vulnerability is what moves a case toward an active protective response.

Who pays for close protection when it is authorized — the company or the executive?

For threats arising from the executive’s role, decisions, or public profile connected to the business, the company typically funds the response as a business security expense, and many public companies disclose this cost in proxy statements. Purely personal threats unconnected to the role are handled case by case, though boards increasingly recognize that the line between the two is thin for highly visible executives.

How quickly can a risk assessment be completed if the situation feels urgent?

A focused assessment on a single credible trigger can often be completed within days, with interim monitoring or advisory measures standing up immediately while the full assessment proceeds. Urgent situations are triaged first for immediate safety, with the complete threat-vulnerability-consequence analysis following close behind rather than being skipped.

Can the framework be applied to family members and not just the executive?

Yes, and it should be. Spouses, children, and household staff are frequently the actual vulnerability a threat actor exploits, and a mature framework scopes the assessment to include them from the outset rather than treating the executive as the only person at risk.

About Honeybadger Solutions

Honeybadger Solutions is an Arizona-licensed security and investigations firm delivering intelligence-led executive protection, investigations, and cyber services to executives, boards, general counsel, and organizations nationwide and internationally. Threat and vulnerability assessment, protective intelligence, background intelligence, and digital forensics are handled in-house and delivered globally. In Arizona, physical and executive protection is delivered by our own in-house, AZ-licensed agents; outside Arizona it is delivered through a commanded vetted-partner network with established theaters in California, Texas, and Florida, directed from Arizona home command — so every protective decision is scoped honestly, sized to the assessed tier, and backed by a single accountable chain of command.

Offices: Casa Grande (HQ), Phoenix, and Oro Valley, Arizona.
Phone: 602-725-2818
Confidential consultation: discuss a threat trigger or authorization framework with our command team.