Key Insights
- There has been a substantial increase in targeted cyber and physical threats over the past two years for public-facing leaders and executives.
- Publicly available personal details and routines can be weaponized into phishing, extortion, or physical attacks.
- Institutions should inventory executive and leader exposure, scrub public data broker records, and restrict sensitive information sharing.
We willingly hand over small pieces of personal information all day long. A pizza order requires a home address. A new contact gets a cell phone number. A social-media post can reveal a vacation date, a child’s school event, or the route taken on a Saturday run. Each detail seems harmless in isolation — until someone assembles them into a useful profile.
For community financial institutions (CFIs) under $1B in assets, cybersecurity investments can run from the low six figures to well above $1MM annually, depending on the institution’s size, technology environment, third-party relationships, staffing model, and other variables. Those dollars help protect networks, branches, offices, and customer data. But even a well-funded security program can overlook a critical exposure: the people most visibly associated with the institution.
That includes CEOs, presidents, board members, chief information security officers, and other public-facing employees. Threats and incidents involving public figures, broadly defined, have risen 400% over the past two years, according to ProSight’s analysis.
For an executive at a financial institution, the risk may begin with a trail of ordinary digital breadcrumbs: a home address in a people-search database, a spouse’s name in a charitable-event program, a child’s school mentioned in a local-news article, or a predictable workday routine visible through social media. On their own, these details may seem insignificant. Combined, they can help a bad actor impersonate, phish, coerce, dox, swat, or physically target an individual and potentially gain a route into the institution itself.
The security perimeter, in other words, does not stop at the branch door or the network firewall. It can extend to the front doorstep of the people entrusted to lead the bank.
How to Protect Executives and Sensitive Information
The following are several steps to help CFIs be more proactive in protecting executive vulnerabilities.
1. Inventory Executive Exposure
Identifying leadership data that’s publicly accessible and easily assembled should be the first step. Your list might include personal email addresses, mobile phone numbers, home addresses, family members’ names and contact details, social media accounts, property records, real estate listings that show home layout, daily routines, public speaking calendars, and organizational charts.
Consider which of these details you’re legally required to disclose and which are merely customary or a means to a desirable end. For instance, you probably aren’t legally required to publicize where your leadership team will give talks, but your CEO might have bigger audiences at her public speaking engagements if you publicize her calendar. Is that uptick in attendance worth the attendant risk? That’s a judgment call your leadership should make deliberately. Don’t decide by default by never considering the question.
2. Demonstrate How Information Can Be Weaponized
People in leadership can dismiss efforts at protection because they don’t see the need. They may see exposed data as harmless. Because they don’t plan to do harm, they’re not accustomed to thinking like a potential criminal. An explanation of how information leads to vulnerability can help open their eyes. Point out that stray information doesn’t just open them to attack, but that their families and coworkers could also potential targets.
In the wrong hands, a cell number could lead to social media, which could in turn reveal the existence and ages of someone’s children, as well as where they go to school. A real estate listing from an earlier home sale might show a house layout, allowing a viewer to find entry and exit points and navigate the interior. Posts of athletic accomplishments could point to regular visits at a particular gym.
Even routine publicity surrounding an otherwise peaceful business event can create security considerations. Luigi Mangione, who pleaded guilty in federal court in connection with the killing of UnitedHealthcare CEO Brian Thompson, reportedly identified Thompson’s planned appearance at an investor conference and used a false pretext to obtain details about the event’s location and timing.
3. Build Protection into Existing Controls
Bank leaders should regularly run executive-specific phishing simulations. Consider making these simulations routine for employees to use multi-factor and phishing-resistant authentication, secure communication channels, payment and wire-verification protocols, escalation procedures around impersonation, and coordinated responses to cyber or physical incidents. You could also include the board and leaders’ spouses and families in awareness training.
You could also search for sensitive information online that you can routinely protect or remove. Consider taking executive home addresses and personal email addresses off data broker sites and public records. It may be wise to list CFI office addresses as the contact point for public filings and either avoid sharing or restrict access to CFI organizational charts.
4. Decide How You’ll Share Sensitive Information
In July 2026, the FDIC, Federal Reserve, and OCC set out a coordinated approach to managing sensitive data during bank examinations. The guidelines can help in other situations as well. The standards include releasing information on a need-to-know basis; controlling access; creating summaries rather than detailed or individually identifiable information; giving samples or excerpts instead of complete data; or redacting sensitive details.
When it isn’t possible to remove sensitive information, the next best move might involve making it more difficult to locate. That’s still helpful. “Time is a tool, and a powerful tool, when it comes to violence,” says Kelsi Strutton, a workplace security expert at Ironwall. A delay can give a bank’s security time to see a threat or for an angry person’s better nature to prevail.
We all give away personal information casually, but that data can turn into harm when it falls into the wrong hands. CFIs should be thoughtful about how they share and protect leaders’ information, doing their best to remove information from databases, share on a need-to-know basis, teach leaders about the importance of information security, and even make information harder and more time-consuming to find.