When you leave the house in the morning. Which route you take to the office. On which days you’re at the main office. Which conferences you attend. Where your next business trip will take you. All of this is known not only to you, your assistant, and a few colleagues, but possibly also to other people.

For most executives, this does not initially pose a security problem. However, in companies that, due to their strategic importance, are more likely to be targeted by sabotage, espionage, or politically motivated actions, this predictability can become part of a changed risk profile.

 

How predictable is your daily routine as an executive?

This issue has become particularly significant in the context of critical infrastructure (KRITIS). The Federal Office for the Protection of the Constitution assesses the threat posed by sabotage activities and related preparatory acts in Germany as elevated. However, not all industries and companies are equally vulnerable.

In addition to protecting locations, facilities, and processes, corporate security has another task: it must determine whether the threat to a company extends to individual executives and what protective measures this entails.

This article from RH Security focuses on board members, managing directors, and other executives whose role, visibility, or decision-making responsibility can lead to increased personal exposure.

Cybersecurity and NIS2 play a central role in the KRITIS debate. This article deliberately focuses on physical and personal security, as well as on the organizational structures relevant to executive protection.

 

1. Sabotage and espionage pose a potential threat to critical infrastructure

For several years now, the Federal Office for the Protection of the Constitution has been highlighting the increased risks to critical infrastructure and companies closely associated with KRITIS. Sabotage can be carried out by foreign states, their supporters, or extremist actors. The agency assumes that publicly available information can be used to gather intelligence and prepare for such activities.

In May 2025, the Federal Office for the Protection of the Constitution published an overview of Russian espionage, sabotage, and disinformation activities. The report lists numerous incidents and suspected cases in European countries, including arson attacks, preparations for sabotage, and the use of individuals recruited through low-threshold methods for espionage or sabotage.

The European Union classifies Russian hybrid activities as an ongoing threat. In 2025, the European Council explicitly condemned sabotage, damage to critical infrastructure, cyberattacks, and other forms of hybrid influence operations.
However, the threat is not distributed evenly across all sectors. An increased intelligence focus on the security and defense industry is particularly well documented.

The Office for the Protection of the Constitution classifies the defense sector as a traditional target of foreign intelligence services and recognizes an heightened threat stemming from geopolitical rivalries and Russia’s war of aggression. Physical attacks and extremist activities have also been documented in the energy sector.
This situational intelligence initially covers the risk to companies, locations, facilities, information, and processes. An additional assessment is required for the protection of individual executives.

 

2. Corporate risk and personal threat require separate assessments

The industry alone does not allow for a reliable assessment of the protection needs for an executive board or managing director position.

For example, an energy company may have high strategic relevance due to its importance for security of supply. In the case of a defense industry company, however, certain technologies, products, or supply relationships may attract significant intelligence interest.

In both cases, the threat is initially directed against the company and its operational capabilities. Additional factors come into play for personal risk assessment. Relevant factors may include a person’s specific role, decision-making authority, public visibility, travel patterns, accessible personal information, specific threats, or a prominent role in a current dispute.

A threat assessment brings these levels together. It examines threats, exposure, and vulnerability and relates them to the individual in question. This approach aligns with the fundamental preventive logic of the Federal Office for the Protection of the Constitution. Companies should analyze who might launch attacks, which assets are particularly worthy of protection, and through which channels an attack could occur.

In close protection, a person’s role, specific situation, and individual exposure determine whether and to what extent personalized protective measures are necessary.

 

3. Role, visibility, and routines shape the risk profile of executives

he risk profile of a position on the executive board or as a managing director can change depending on the company’s situation. Strategic decisions, a public controversy, an acquisition, a major defense contract, labor disputes, protests, or changes in the international security situation can influence the exposure of a company and its executives.
The individual’s role is also relevant. A managing director who rarely appears in public and attends only a few public events has a different exposure profile than a board member whose name regularly appears in the media, who speaks at international events, and whose travel itinerary is frequently publicized.

Recurring routines also play a role. Start times, commutes, preferred modes of transportation, restaurants visited regularly, sports activities, airports, or recurring events can, over time, reveal a relatively precise pattern of movement.
None of these factors, taken on its own, constitutes a concrete threat. However, when combined with an existing threat situation, they can increase a person’s vulnerability. A risk assessment therefore begins by defining the relevant scenarios. From these scenarios, the nature and scope of the necessary protective measures can be derived.

 

4. Publicly available information can get executives into trouble

Companies publish a large amount of information that, when viewed individually, seems unproblematic. However, the Office for the Protection of the Constitution points out that websites, internal documents, job postings, and social media can provide information relevant for investigative purposes. This includes contact information, organizational relationships, and references to operational processes.

For executives, such corporate information may be combined with personal details. Conferences publish programs and the names of speakers. Company posts reveal locations. Press releases list dates. Photos can sometimes provide clues about vehicles or buildings. Personal social media profiles can reveal travel plans or private habits.

An announced conference appearance initially specifies only the location and time. Combined with details on travel arrangements, hotels, vehicles, or private posts, this can paint a much more precise picture of a person’s movements.
For physical security, it is therefore also important to determine which insights can be linked together from multiple sources. Information management thus becomes an integral part of personal security planning.

 

5. Business trips and public engagements alter personal exposure

Business trips take executives out of the controlled environment of the company. Trade shows, conferences, political engagements, plant visits, trips abroad, or meetings with business partners each entail different security conditions. Hotels, event venues, vehicles, transfers, and local service providers become part of the travel arrangements.

At the same time, the number of people and organizations receiving information about the itinerary increases. Travel itineraries are sent to assistant teams, event organizers, drivers, hotels, business partners, or local contacts. Last-minute changes must be coordinated among multiple parties.

From an executive protection perspective, situational assessment and travel preparation go hand in hand. Depending on the risk profile, the destination, routes, event venues, vehicles, and local conditions can be assessed in advance. Coordination with corporate security and the deployment of personal security guards can also be part of the protection strategy.

The nature and scope depend on the specific threat. For many business trips, no operational close protection is required. However, if the company’s situation changes, concrete intelligence is received, or personal exposure increases significantly, the same trip may require a different assessment.

 

6. Corporate Security combines company security and close protection

Many large KRITIS operators have professional security departments. These departments are familiar with the company’s internal processes, locations, responsibilities, and existing security measures, providing a crucial foundation for assessing personal risks.

Indications of changes can arise from various sources. For example, plant security and crisis management have different information than the communications, legal, human resources, or executive management departments. For a robust threat assessment, the relevant insights must be consolidated in an appropriate location.

Corporate Security often assumes this coordinating role. Security officials assess whether the changes affect only the general corporate situation or whether individual persons are more highly exposed. This may lead to adjustments to existing protective measures, the provision of additional resources, or the utilization of specialized external support.
The European Commission also attaches importance to the personnel security dimension. In its guidelines on the resilience of critical infrastructure, it stipulates that personnel with critical functions must be identified, including employees of external service providers.

This results in a shared organizational responsibility for close protection. Internal security structures, executive management, support staff, and operational protection teams require clearly defined responsibilities and reliable information channels for this purpose.

 

7. External close protection guards complement internal security structures

Companies organize close protection in various ways. Some have their own close protection guards. Others manage protection through corporate security and outsource operational tasks to specialized external service providers. During business trips, events, or periods of heightened risk, external personnel can supplement existing teams. In other models, an external provider assumes full operational responsibility for close protection.

None of these organizational models is inherently superior. The quality of protection depends crucially on the qualifications of the personnel deployed, clear responsibilities, a shared situational awareness, defined reporting channels, and effective operational leadership.

The interface between internal and external stakeholders deserves special attention. close protection officers need all the information required to assess the situation, plan, and carry out their assignment. At the same time, sensitive information must be restricted to the necessary audience.

A clear division of tasks reduces friction and ensures that relevant changes can be quickly incorporated into operational planning.

 

8. Executive Assistants (EAs) and Personal Assistants (PAs) serve as a crucial source of information in executive protection

Mostly, EAs and PAs are not part of the protection team. Nevertheless, they fulfill a central information function for the security organization. They usually manage calendars, travel arrangements, hotels, drivers, event venues, contacts, and last-minute changes. As a result, they possess a wealth of information from which an executive’s movement patterns can be deduced.

EAs and PAs also often know early when a schedule changes: an additional public event is added; an executive decides on a different mode of travel; a meeting takes place at a new location; or a trip is extended or shortened.
Such changes are not automatically security-critical. However, in the event of an existing or heightened threat, they can have an impact on a protection plan.

Assistance teams should therefore know which information is relevant to Corporate Security or the operational protection team and how changes are communicated. While they do not make security decisions, they provide part of the information on which those decisions are based.

This makes the assistance team one of the key interfaces in a functioning executive protection program.

 

9. In case of a specific threat, the private sphere must be included in the risk assessment

Professional exposure and private life cannot always be clearly separated in the case of a specific, person-specific threat.

For KRITIS executives, there is no solid basis for the blanket assumption that their families or their private sphere are regularly threatened. However, as part of an individual threat assessment, it must be determined which information and routines could be relevant to a specific threat.

This may include place of residence, vehicles, private travel patterns, frequently visited locations, or publicly visible family information. The social media activities of family members can also unintentionally provide clues about whereabouts or habits.

Whether this results in additional protective measures for other individuals depends on the specific situation. In the case of a specific, person-targeted threat, the potential exposure within the private sphere must therefore also be factored into the assessment. The scope and limits of the protection plan are then derived from this analysis.

 

10. Changes within the company may necessitate a new risk assessment

A risk profile that has been assessed once is not valid indefinitely. Certain changes within the company, in its environment, or in an executive’s daily routine may warrant a review of the existing assessment.

These include, for example, specific threats or suspicious observations, a significant increase in public attention, new strategic initiatives by the company, particularly sensitive projects, political or social conflicts, recurring protests, or high-profile trips abroad. Changes in a person’s private life may also become relevant if they result in additional information about whereabouts or routines becoming public.

Similarly, a changed geopolitical situation may justify a reassessment, provided it directly affects the company, its industry, or specific functions within the company. None of these factors necessarily leads to a greater need for protection. They are reasons to review existing assumptions and reassess the current level of exposure.

 

11. The threat assessment forms the basis for executive protection

Executive protection is one possible measure within a broader security concept. As part of a structured threat assessment, the relevant threats, potential targets, their exposure, and existing protective measures are examined. This results in a reliable picture of the actual situation.

The resulting measures can vary widely. Travel information can be shared more selectively. Routines can be adjusted. Event venues can be inspected in advance. A security driver can be included in the planning. Advance work may be necessary. In the event of a higher personal threat, the protected individual may be accompanied by bodyguards.
Similarly, the analysis may conclude that no operational close protection is currently necessary. A professional assessment should align measures transparently with the existing risk and allow for readjustment in the event of changes.

 

12. Conclusion: Close protection for KRITIS executives is based on their individual risk profile

The heightened geopolitical security situation increases the pressure on numerous operators of critical infrastructure to take action. However, an increased corporate threat does not automatically imply a need for close protection for individual executives.

In executive protection, the individual situation is what matters. Role, exposure, available information, movement patterns, and specific threat intelligence collectively determine the risk profile. A robust threat assessment provides the foundation for reviewing existing measures and adjusting close protection as needed.

Companies with established corporate security structures can manage this process internally and, if necessary, bring in external expertise or operational bodyguards. Clear responsibilities and effective communication channels should already be in place before a specific threat emerges.

Ivo Schendel

Ivo Schendel

Owner and CEO

Former police chief inspector with 20 years of experience in the North Rhine-Westphalia police force, including 10 years with the special forces. Today, he advises companies and private individuals on all security matters.