Kasparov Warning: Executive Protection Lessons
One of the hardest situations in executive protection is not the threat we completely understand.
It is the threat we know enough about to take seriously but not enough about to completely explain.
That is the protection question raised by recent warnings involving former world chess champion and Russian opposition figure Garry Kasparov and his longtime colleague Ivan Tyutrin.
On October 1, 2026, Kasparov said security services in the United States and Lithuania had warned both men that their lives were in danger and that they should take precautions. Reuters reported that the warnings came shortly after U.S. prosecutors announced charges involving an alleged Russian intelligence network accused of arranging surveillance and planned killings of Russian dissidents in the United States and Lithuania.
There is an important distinction.
Kasparov specifically said neither he nor Tyutrin had been explicitly told that they were the unnamed victims described in the U.S. indictment.
That means we have two things at the same time.
A serious warning from credible security authorities.
And incomplete public information about exactly what intelligence produced that warning.
That is not unusual in protection work.
Sometimes the protection team knows exactly who is causing concern, what that person has done and where the threat is coming from.
Sometimes law enforcement tells the principal that there is a credible reason to take precautions but cannot provide the complete picture.
Sometimes we receive information indicating possible surveillance but do not know who ordered it.
Sometimes an executive begins receiving increasingly concerning contact while motive remains unclear.
Sometimes a family office learns that a threat exists before investigators have determined the full scope of it.
In those situations, I do not need perfect certainty before taking reasonable protective action.
But I also do not want fear filling the gaps where facts should be.
The job is to separate what we know, what we do not know and what the new information changes.
Then we adjust the protection accordingly.

Key takeaways for executive protection and protective intelligence
- A credible warning changes the security picture. When a reliable government or law-enforcement source says the principal may be in danger, the existing protective posture should be reassessed immediately.
- Uncertainty does not mean inaction. The team can reduce vulnerability even when the identity, motive or exact plan behind a threat remains unclear.
- Do not turn allegations into facts. The protection team should distinguish official information, allegations, intelligence assessments, media reporting and internal observations.
- Look for preparation, not only explicit threats. Surveillance, information gathering, repeated approaches and attempts to understand the principal’s movements may matter even without a direct threat.
- The residence becomes part of the threat assessment. If locations associated with the principal are being observed, residential security, family movements and household procedures deserve immediate review.
- The family may become part of the exposure. Spouses, children, assistants, drivers and close associates can provide access or information even when they are not the original target.
- International protection requires coordination. A principal who operates in several countries may require communication among multiple security teams and government authorities.
- Information should be need-to-know. A heightened threat is not a reason to distribute sensitive intelligence broadly throughout the household or organization.
- Heightened protection should have reassessment points. Security should increase when risk changes and decrease when the intelligence picture genuinely supports doing so.
- The objective is options. Good protection should reduce exposure while preserving as much of the principal’s normal life and independence as the threat allows.
What happened in the Kasparov case
On September 15, 2026, the U.S. Department of Justice announced the unsealing of federal charges against five men whom prosecutors allege were working as part of a network connected to Russian intelligence services.
The defendants are Yuri Khrameev, Kirill Khrameev, Oemis Romagoza Durruthy, Yaidel Delgado Suarez and Angel Eduardo Castro.
All five were charged with conspiracy to finance terrorism. Yuri Khrameev, Suarez and Castro were additionally charged with conspiracy to commit murder for hire. The defendants remained at large when the charges were announced. The indictment contains allegations, and all defendants are presumed innocent unless proven guilty beyond a reasonable doubt.
The allegations are significant from a protective-intelligence standpoint.
The Justice Department says the network had operated since at least 2024 and had allegedly been involved in planning attacks and killings in multiple countries.
Most relevant to the current case, prosecutors allege that members of the network recruited a person in the United States to conduct surveillance against a prominent Russian dissident believed to be living in the United States.
According to the DOJ, that person was sent two locations associated with the intended victim and offered between $1,000 and $1,500 to conduct what prosecutors describe as pre-operational surveillance.
The recruited individual allegedly photographed and recorded video of locations associated with the intended target and returned that material to members of the network.
Prosecutors then allege that Suarez and Castro offered $40,000 to have the target “eliminated” or “disappeared.”
That sequence is important.
The allegation is not simply that somebody made a threat.
The alleged activity included identifying locations associated with a person, directing surveillance of those locations, receiving photographs and video and then allegedly attempting to arrange the killing.
That is why surveillance and information gathering matter in executive protection.
They may be part of a larger preparation process.
The alleged network was not limited to the United States
The DOJ also alleges that members of the network were involved in operations elsewhere in Europe.
According to prosecutors, Durruthy coordinated travel and logistics associated with a June 2024 attack in Prague and another operation in Lithuania later that year. The indictment also alleges that Durruthy obtained media of one of the U.S. victim’s dwellings before subsequent surveillance occurred.
For a protection team, that international element matters.
A principal may live primarily in one country and still face exposure in several.
Residences.
Hotels.
Offices.
Conferences.
Airports.
Public appearances.
Another jurisdiction may hold information that the local protective team does not have.
Kasparov then disclosed the security warnings
On October 1, Kasparov said security services in the United States and Lithuania had warned him and Ivan Tyutrin that their lives were in danger.
Kasparov said both men had been advised to take security precautions.
He also made the evidentiary limitation clear: neither man had been explicitly told that they were the unnamed individuals described as victims in the U.S. indictment.
That distinction should remain intact.
The warning is real according to Kasparov’s public statement and multiple news reports.
The DOJ indictment is real.
The allegations in that indictment are serious.
But the publicly available evidence does not establish that Kasparov and Tyutrin are the indictment’s unnamed targets.
A professional protection team should be able to hold those two thoughts simultaneously.
The Kremlin disputed the U.S. allegations
Reuters reported that the Kremlin said it saw no reason to comment on the U.S. allegations without what it regarded as credible evidence and facts. Russia has previously denied conducting assassination plots on foreign soil.
That competing position is part of the public record.
For the protection team, however, the political argument does not determine the immediate security decision.
If credible authorities responsible for security tell the principal that their life may be in danger, I am reassessing the protection program.
I do not need to settle an international attribution debate first.
This fits a broader category of transnational repression
The FBI uses the term transnational repression for situations in which foreign governments reach beyond their borders to intimidate, silence, coerce, harass or harm dissidents and diaspora communities.
The Bureau lists tactics including stalking, intimidation, cyberhacking, harassment, threats, attempted kidnapping and attempted murder. It also notes that family members and friends can become targets of pressure or intimidation.
The DOJ itself characterized the September indictment as an example of the threat posed by transnational repression to people who oppose authoritarian governments.
This is obviously a more specialized threat environment than the one facing most high-net-worth families.
Most UHNW principals are not dissidents targeted by foreign intelligence services.
But the protection problem created by incomplete intelligence is highly transferable.
Executives, celebrities, business owners and wealthy families can all receive warnings that are credible but incomplete.
The response discipline should be similar.
My first question after a credible warning: what changed?
A warning should change something.
Otherwise it is not being treated as meaningful information.
The question is what.
I want to establish:
Who provided the warning?
How directly?
Was the communication formal or informal?
What exactly was said?
Were specific precautions recommended?
Does the warning concern a known individual?
A group?
A location?
A period of time?
Travel?
A residence?
A public appearance?
Is there an indication that surveillance has already occurred?
Has family information been exposed?
Do authorities expect additional contact?
What information is still unknown?
Those answers determine what changes next.
I separate confirmed information, credible reporting and assumptions
This is critical during serious threat cases.
The protection environment becomes noisy very quickly.
Media reports appear.
Friends call.
Employees speculate.
Social media adds theories.
Different officials may communicate different pieces of information.
I want a clear distinction among:
- information directly provided by authorities;
- public allegations in court filings;
- reliable media reporting;
- observations made by the protection team;
- information reported by household or family-office personnel;
- and assumptions that have not been corroborated.
Mix those categories together and decision-making becomes much harder.
Uncertainty is not the same as low risk
This is one of the mistakes I see people make when information is incomplete.
“We don’t know enough yet.”
That can become an excuse to do nothing.
Sometimes incomplete intelligence should create more caution, not less.
If a reliable authority tells me there is a credible threat but cannot tell me exactly who is involved, I may not be able to target every protective measure precisely.
I can still reduce obvious exposure.
I can strengthen the residence.
I can review travel.
I can tighten information control.
I can increase protective coverage.
I can brief staff.
I can improve communication with authorities.
I can prepare alternatives.
Protection does not require certainty to begin.
Credibility and specificity are different
A warning can be highly credible while remaining relatively nonspecific.
For example:
A government security service may be highly credible.
But the service may not tell the protection team the exact timing, location or method of a possible attack.
That creates a different protection challenge from receiving a very specific direct threat from an unknown source.
I evaluate both dimensions.
How reliable is the source?
And how specific is the information?
A highly reliable but broad warning can justify substantial precaution.
A very specific message from an unknown source may also require investigation.
Different information.
Different response.
Existing exposure matters as much as the warning itself
The same warning can require completely different protection depending on the principal.
One principal lives behind a professionally managed residential-security program, has controlled travel information and uses experienced executive protection.
Another lives at a publicly identifiable residence with an open driveway, no protection personnel and highly predictable routines.
The threat information could be identical.
The vulnerability is not.
That is why I reassess the complete environment instead of simply saying:
“We received a threat. Add two guards.”
The DOJ allegations show why location surveillance deserves attention
The indictment’s alleged surveillance sequence should be particularly interesting to protection professionals.
Prosecutors allege that the recruited U.S. resident was given locations associated with the intended victim and specifically tasked with surveilling those locations.
Photos and videos were allegedly returned to the network.
That tells us something important from a protective standpoint.
A threat actor may be interested in the principal long before approaching the principal.
They may first be interested in:
Where does this person live?
Which entrance do they use?
What vehicles appear there?
When does the property look occupied?
Who else visits?
Where else does the person spend time?
What routine exists?
I do not need to assume that every unfamiliar vehicle outside a house is hostile surveillance.
But I do need the protection team capable of recognizing repeated observation when it occurs.
Surveillance is about behavior and pattern
One person standing near a residence may mean nothing.
One vehicle parked nearby may mean nothing.
Someone taking a photograph may have a completely innocent explanation.
I look for context.
Repeated appearances.
Unusual duration.
Appearance at several principal-related locations.
Interest in gates, vehicles or occupants.
Attempts to obtain information.
Behavior that changes when security appears.
Movement that tracks the principal’s movements.
Those details become more useful when they are documented over time.
The team needs a baseline before it can recognize an anomaly
A residential security team should know the environment.
Regular neighbors.
Delivery patterns.
Contractors.
Construction activity.
Routine street parking.
Dog walkers.
Staff vehicles.
If every unknown car is treated as surveillance, the program becomes overwhelmed with noise.
Understanding normal makes meaningful deviations easier to identify.
Factual documentation matters more than dramatic language
I prefer:
“Black Toyota SUV remained opposite the west entrance from 6:42 p.m. until 7:18 p.m. Driver remained inside. Vehicle departed approximately two minutes after the principal’s vehicle exited.”
over:
“Russian surveillance team outside the house.”
The first is useful.
The second is speculation unless the evidence supports it.
Security reporting should increase clarity.
Not anxiety.
Preserve potentially relevant video early
Patterns sometimes become obvious only later.
A vehicle appears today.
Two weeks later, the same vehicle appears at another location.
Now the team wants the earlier footage.
If normal retention has overwritten it, the information is gone.
When something may be relevant to a serious warning, preserve the appropriate video, access logs, messages and other records promptly.
The residence should be reviewed immediately after a serious warning
If the threat may involve physical violence, I want to revisit residential security.
How easy is it to identify the residence?
How can somebody approach?
Can the property be observed from public areas?
Is the perimeter meaningful?
Are gates actually controlled?
Do cameras provide useful detection?
Does nighttime coverage work?
What happens if someone crosses the boundary?
Who receives the alarm?
Where does the family move?
How quickly can outside help reach the property?
I do not necessarily rebuild the entire estate because of a warning.
I want to know whether existing weaknesses suddenly matter more.
A temporary staffing increase may be appropriate
A family that normally does not need continuous residential security may temporarily need it after a credible warning.
A principal who normally uses discreet mobile protection may temporarily require additional personnel.
That is not an admission that the original program failed.
The threat changed.
The posture changes with it.
Later, the situation can be reassessed.
Family members should be included in the exposure review
The FBI notes that transnational repression can extend to friends and family members, including threats or pressure against people close to the primary target.
Even outside a state-sponsored threat environment, the same practical concern exists.
The principal may have strong executive protection.
The spouse may not.
Children may travel predictable routes.
A parent may live elsewhere.
An assistant may be easier to approach than the principal.
A driver may know movements.
When a serious threat emerges, I want to review the people around the principal as well.
That does not mean surrounding the entire family with protectors
Security should remain proportionate.
The spouse may need a briefing rather than full-time protection.
Children may need pickup procedures reviewed.
A driver may need better communication.
An assistant may need guidance on unusual requests.
The residence may need stronger access control.
Use the measures that address the exposure.
Children should not carry the psychological burden
If children are involved, I do not want the entire adult threat picture transferred to them.
The adults and professionals manage it.
Maybe school pickup changes.
Maybe drivers receive additional instructions.
Maybe social-media exposure gets reviewed.
Maybe the executive protection team coordinates more closely with parents.
The child should receive only what is appropriate for their age and situation.
The family office becomes especially important during a threat increase
A family office often holds more actionable information about the principal than almost anybody else.
Calendars.
Travel.
Hotels.
Aircraft.
Addresses.
Meetings.
Family events.
Children’s schedules.
Medical appointments.
When risk increases, I want that information controlled more carefully.
Need-to-know matters more under heightened threat
A serious warning is not a reason to send the threat report to fifty people.
Information should go to people who need it for a protective function.
Security leadership needs more than a housekeeper does.
The driver needs information relevant to transportation.
The executive assistant may need instructions for unusual contacts.
The household staff may only need a procedural change.
The more sensitive the information, the more deliberate distribution should become.
The complete protection plan should remain private
I do not want the response to a threat creating another vulnerability.
Do not broadly circulate:
guard schedules;
protector positions;
routes;
backup routes;
safe locations;
security vehicle assignments;
residential procedures;
or law-enforcement liaison details.
People receive what they need to perform their role.
Public schedules deserve immediate review
A public figure may have upcoming:
speeches;
conferences;
fundraisers;
media events;
board meetings;
political events;
or public appearances.
A credible warning should trigger a review of those movements.
Which events are essential?
Which are public?
Which publish exact times and locations?
Which have controlled access?
Which require additional advance work?
Which can be modified without significantly affecting the principal’s objectives?
The answer is not automatically:
“Cancel everything.”
The purpose of protection is to preserve options where we responsibly can.
Sometimes cancelling an event is still the correct decision
There are situations where the team cannot adequately reduce the risk.
The venue may be too exposed.
The warning may be too specific.
The response capability may be insufficient.
Authorities may recommend against attendance.
Protection is not about proving we can protect somebody anywhere under any condition.
It is about making defensible decisions.
Travel deserves immediate reassessment
If the principal is subject to a serious international threat, travel security becomes particularly important.
What countries are coming up?
What is the local law-enforcement environment?
Who is providing protection?
Are teams communicating?
Where is the principal staying?
Who has the itinerary?
How predictable are airport movements?
Who handles transportation?
What happens if plans change?
International protection requires more than putting an agent on an airplane with the principal.
Different countries may hold different pieces of intelligence
That is clearly relevant to the Kasparov situation because he said both U.S. and Lithuanian security services had warned him.
A principal moving internationally may have:
one protection provider in the United States;
another in Europe;
local government protection somewhere else;
and separate residential teams at different properties.
If each receives different information and nobody coordinates it, gaps appear.
A designated security liaison helps reduce fragmentation
I prefer one person owning communication with relevant authorities on behalf of the protective program.
That does not mean only one person can communicate.
It means somebody is responsible for maintaining the record.
What was communicated?
When?
By whom?
What changed?
What is still outstanding?
What did authorities recommend?
What protection changes were approved?
That prevents important information from living in scattered phone calls and text messages.
Law enforcement and private security have different roles
Private executive protection is not a substitute for law enforcement or intelligence services.
Likewise, authorities are not usually managing the principal’s complete day-to-day protective operation.
The government may possess intelligence.
The private team understands the principal’s residence, schedule, family, vehicles and routines.
Both perspectives can matter.
The private team should use government information to inform the protective posture while respecting the limits of what authorities can or will share.
Do not interrogate authorities for intelligence they cannot provide
If an agency provides a warning, I want useful clarification.
But repeatedly pressuring an official for details they are not authorized to disclose is not a protection strategy.
I work with the information available.
What precautions do you recommend?
Does the concern apply to a particular jurisdiction?
Should specific travel be reconsidered?
Is the residence a concern?
Who should we contact if something changes?
Those answers may be more operationally useful than trying to learn the entire intelligence case.
Digital exposure should be reassessed too
A modern threat actor may not need physical surveillance to begin understanding the principal.
Calendars.
Email.
Public records.
Social media.
Staff profiles.
Hotel reservations.
Travel correspondence.
A cyber compromise can expose physical movements.
During a heightened threat period, the family office should review who can access sensitive schedules and whether unusual account activity has occurred.
The principal’s public online footprint deserves another look
What does a search reveal today?
Home address?
Other residences?
Family members?
Staff?
Upcoming events?
Vehicle photographs?
Regular travel?
Public calendars?
An old privacy review may no longer reflect what is publicly available now.
The protection team should review information collection against the principal
When authorities warn of a potentially sophisticated threat, I want to know whether there have been recent attempts to obtain information.
Strange calls.
Fake meeting requests.
Questions to staff.
Requests for travel details.
Unexpected media inquiries.
Impersonation.
Social-engineering attempts.
Those may be completely unrelated.
But they should be evaluated against the new information.
Household staff should receive a practical briefing
I do not want to frighten the entire household with information they cannot use.
I do want staff to know what changes operationally.
Do not confirm whether the principal is home.
Do not provide future travel information.
Do not discuss security staffing.
Report unusual calls.
Verify unexpected contractors.
Report unfamiliar people or repeated vehicles.
Those are practical instructions.
Executive assistants need a slightly different briefing
They may see:
meeting requests;
communications from people claiming government or media connections;
requests for interviews;
travel changes;
impersonation attempts;
gifts;
letters;
or persistent contact.
They should know what to preserve and where it goes.
Drivers should be part of the reporting structure
Drivers have an excellent view of repeated road activity.
They may notice the same vehicle.
The same person near multiple pickup points.
Someone photographing transportation.
A car departing immediately after the principal.
They should not have to decide whether any of that constitutes surveillance.
They should report it factually.
Protectors should be briefed on confirmed facts and unresolved questions
This is important for preventing speculation inside the team.
What do we know?
What has the government said?
What has not been confirmed?
What are the new procedures?
What are we looking for?
Who receives reports?
Who can authorize a change in posture?
A team that does not understand those boundaries can become either complacent or overly reactive.
I want escalation criteria defined
Once protection increases, determine what new developments would justify another increase.
For example:
- new official intelligence;
- confirmed surveillance;
- an attempted physical approach;
- direct threats containing nonpublic information;
- contact with family members;
- attempts to obtain residential or travel details;
- appearance of the same individual or vehicle across multiple locations;
- or a recommendation from authorities.
Those events do not all require the same response.
They require review.
The program also needs de-escalation criteria
Heightened security should not become permanent automatically.
Maybe investigators identify and neutralize the threat.
Maybe authorities advise that the immediate concern has changed.
Maybe a temporary event ends.
Maybe travel finishes.
Maybe additional information significantly narrows the exposure.
Then reassess.
The goal is not to keep the principal living under maximum restriction indefinitely.
Schedule reassessment instead of waiting for someone to remember
If protection increases today, set review points.
Maybe tomorrow.
Maybe weekly.
Maybe before each major movement.
The frequency should follow the seriousness and pace of the situation.
At each review:
What changed?
What new intelligence exists?
Did anything concerning occur?
Are current measures still appropriate?
Do we need more?
Can anything be reduced?
A serious warning does not automatically mean 24/7 executive protection
Sometimes it will.
Sometimes it will not.
I want to understand the complete protective environment.
If the principal has strong residential security and the exposure is primarily associated with specific public events, the correct response may be concentrated around those events and movements.
If the principal has an identifiable residence, predictable movements and a potentially sophisticated adversary, continuous coverage may be justified.
If the threat involves family members, the staffing model changes again.
There is no universal answer.
More people are not automatically more security
A large detail with poor intelligence, bad communication and exposed schedules can still be weak.
A smaller, disciplined detail supported by strong information and residential protection can be highly capable.
The question is:
What capability do we need?
Then staff for that capability.
The Kasparov case illustrates why preparation can be more important than the threat message
One of the most consequential allegations in the federal case is that individuals were allegedly recruited to conduct surveillance before a proposed killing.
That is a practical reminder that a protection team should not wait for someone to send a perfectly explicit threat.
Sometimes the more useful indicators involve preparation:
Who is trying to learn the principal’s routine?
Who is appearing near locations?
Who is asking questions?
Who is attempting to obtain access?
Who is photographing?
Who is contacting staff?
Those behaviors need context.
They should not automatically be labeled hostile.
But they deserve a reporting system capable of recognizing a pattern.
The principal’s freedom of action remains part of the mission
A serious threat can easily make a protection program overly restrictive.
No public events.
No travel.
No dinners.
No walking outside.
No family activities.
Sometimes temporary restrictions are absolutely justified.
But I do not use restriction as the default answer simply because it feels safe.
Protection should preserve the principal’s ability to work and live wherever we can responsibly do so.
High-profile public figures and UHNW families share one important problem
The source of threat may be completely different.
But both can face situations where:
the home address is identifiable;
travel is public;
staff hold sensitive information;
the principal moves through predictable transitions;
multiple residences are involved;
family members have separate routines;
and different teams control different pieces of the security picture.
That is why the lessons transfer.
What families and family offices can do before a serious warning ever arrives
Decide who receives threat information
Do not wait until a government agency calls.
Who owns security-related information?
Security director?
Chief of staff?
Family-office leader?
Executive protection provider?
Know now.
Create one reporting path
Unusual email.
Repeated caller.
Gate approach.
Unsolicited package.
Recurring vehicle.
Give people one clear place to report.
Know who can authorize additional protection
If something changes at midnight, who can add coverage?
Do not discover during the crisis that nobody has decision authority.
Review residential security
Understand approaches, perimeter, gates, surveillance, nighttime conditions, access procedures and response.
Review family exposure
Spouse.
Children.
Drivers.
Assistants.
Other residences.
Review calendar and itinerary access
Who can see complete future movements?
Who actually needs to?
Review public exposure
Search the family from an outsider’s perspective.
What is easily discoverable?
Establish law-enforcement contacts where appropriate
Especially when a principal’s profile or history suggests that future coordination may be necessary.
Preserve historical incident information
Old unwanted contacts can become relevant again.
Test surge capability
If the threat level changes tomorrow, can the protection program change tomorrow?
How MSB Protection approaches credible threats
At MSB Protection, I approach serious warnings through an intelligence-led, risk-based process.
I want the information first.
Then the exposure.
Then the measures.
I do not begin with:
“Add four agents.”
I begin with:
“What changed?”
“What do we know?”
“What remains unknown?”
“Where is the principal exposed?”
“What protective layers already exist?”
“What changes would materially reduce the risk?”
Depending on the answer, the program may involve:
- executive protection;
- residential security;
- protective intelligence;
- security assessments;
- travel security;
- law-enforcement liaison;
- family-office coordination;
- privacy and information controls;
- additional movement planning;
- and temporary increases in personnel.
The exact mix should follow the actual problem.
I do not want the protection team solving the intelligence case
This distinction matters.
Law enforcement and intelligence agencies investigate the underlying actors.
The private protection team’s responsibility is to reduce the principal’s vulnerability.
Those functions overlap through information.
They are not the same job.
I do not need to identify every person in a network before improving residential access.
I do not need to know the motive before reviewing travel.
I do not need to establish criminal liability before protecting the family.
Protect the principal.
Support the authorities.
Preserve information.
Do not create a parallel amateur investigation.
Frequently asked questions about credible threats and executive protection
What should an executive protection team do after receiving a credible government warning?
Immediately document exactly what was communicated, establish a liaison with the relevant authority, review the principal’s exposure and determine whether residential security, travel, public appearances, staffing or information controls need to change.
Does a security warning automatically mean an attack is imminent?
No. A warning may reflect different levels of threat and specificity. The protection team should take the source seriously while avoiding assumptions about timing or method that have not been established.
Does incomplete intelligence mean the team should wait for more information?
Not necessarily. The team can take proportionate precautions while additional information is developed. Uncertainty does not prevent reasonable risk reduction.
Does every serious warning require 24/7 executive protection?
No. Staffing depends on the credibility and specificity of the warning, existing security layers, principal exposure, family exposure, residences, movements and recommendations from authorities.
What is protective intelligence?
Protective intelligence is the organized collection and evaluation of information relevant to the safety of a principal or family. Its purpose is to identify developing concerns, patterns and changes that may require protective action.
How is protective intelligence different from executive protection?
Protective intelligence helps the team understand what may be developing. Executive protection provides operational protection around the principal’s movements and activities. Strong programs connect the two.
Why does surveillance matter?
Surveillance can help an adversary understand locations, routines, access and vulnerabilities. In the September 2026 federal indictment, prosecutors allege that a recruited individual conducted surveillance and returned photographs and video of locations associated with an intended victim before an alleged murder-for-hire offer was made.
Does an unfamiliar vehicle outside a residence mean surveillance?
No. There may be many innocent explanations. The important approach is factual documentation and comparison over time rather than immediate conclusions.
What makes suspected surveillance more concerning?
Repeated appearances, presence at multiple principal-related locations, attempts to gather information, behavior synchronized with the principal’s movements or other corroborating observations can increase concern.
Should security confront a suspected surveillance team?
Not automatically. The primary objective is protecting the principal. Depending on circumstances, observation, documentation, adjusting the principal’s exposure and coordinating with authorities may be more appropriate.
Why is the residence important after a threat warning?
A residence can provide both access to the principal and information about routines. The federal allegations in this case specifically include surveillance of locations associated with an intended target.
Should family members receive additional protection?
Sometimes. The decision should reflect their exposure. A spouse or child may require changed procedures, additional transportation support or temporary protection rather than the same detail assigned to the principal.
Can family members become targets in transnational repression cases?
Yes. The FBI says foreign governments may also threaten or harass family members and friends of individuals targeted by transnational repression.
What is transnational repression?
The FBI defines transnational repression as foreign-government activity reaching across borders to intimidate, silence, coerce, harass or harm members of diaspora and exile communities. The FBI lists tactics including stalking, threats, cyberhacking, assault, attempted kidnapping and attempted murder.
Are all high-net-worth families at risk of transnational repression?
No. It is a specialized threat particularly relevant to dissidents, political opponents, journalists and certain diaspora communities. The broader executive-protection lessons about credible but incomplete threat information can still apply to private clients facing other types of threats.
Were Garry Kasparov and Ivan Tyutrin confirmed as the targets in the DOJ indictment?
No. Kasparov said both men were warned by U.S. and Lithuanian security services that their lives were in danger, but he also said they had not been explicitly told that they were the unnamed individuals described in the federal indictment.
Who are the defendants in the September 2026 federal case?
The DOJ charged Yuri Khrameev, Kirill Khrameev, Oemis Romagoza Durruthy, Yaidel Delgado Suarez and Angel Eduardo Castro. All five were charged with conspiracy to finance terrorism, and Yuri Khrameev, Suarez and Castro were additionally charged with conspiracy to commit murder for hire. The charges are allegations and the defendants are presumed innocent unless proven guilty.
Were the defendants arrested?
The Justice Department said the five defendants remained at large when the charges were announced on September 15, 2026.
What did prosecutors allege happened in the United States?
Prosecutors allege that members of the network recruited a U.S.-based individual to surveil a prominent Russian dissident, supplied locations associated with the intended target, paid for surveillance and later offered $40,000 to have the target killed.
Does the indictment prove the Russian government ordered the alleged Kasparov plot?
The indictment contains U.S. government allegations involving individuals prosecutors say were working for Russian intelligence services. Kasparov and Tyutrin have not publicly been confirmed as the unnamed victims in that indictment. The Kremlin has disputed the U.S. allegations and Russia has denied involvement in similar overseas plots.
Should a principal cancel all public events after a warning?
Not automatically. Each event should be reassessed based on the available intelligence, venue, access, visibility and response capability. Some events may proceed with modified protection while others may need to be postponed or cancelled.
Should the principal stop traveling?
Again, not automatically. Travel should be reviewed based on destination, local protection, intelligence, itinerary exposure and government recommendations. Some travel may remain reasonable while other movements become inadvisable.
How should executive protection coordinate with government agencies?
Use a designated liaison, document communications and make sure relevant government information reaches authorized protective decision-makers. Private security should not attempt to replace the investigative role of law enforcement or intelligence services.
Should household staff know all details of the threat?
Usually not. Household employees should receive the information required to perform their role safely. Sensitive threat intelligence and protective procedures should remain need-to-know.
What should executive assistants do with unusual communications?
Preserve them and report them through the established security process. Assistants should not have to decide on their own whether a communication represents a credible threat.
Should previous threats be retained after the situation calms down?
Relevant historical information should remain available. A person or behavior that disappears for a period may become relevant again later, and future teams need continuity.
How often should the threat assessment be updated?
As often as the situation requires. A rapidly developing warning may require daily or even movement-by-movement review, while a more stable concern may be reassessed on a longer schedule.
What should trigger another increase in protection?
Examples include new official intelligence, confirmed surveillance, physical approaches, threats containing nonpublic information, contact with family members, information-gathering attempts or recommendations from authorities.
When can heightened protection be reduced?
When the intelligence picture materially changes and the existing measures are no longer justified at the same level. De-escalation should be deliberate and documented rather than based simply on time passing.
Why is a professional security assessment useful after a serious warning?
A security assessment identifies where the principal, family, residence, information and movements are most exposed so additional protection can be directed toward the vulnerabilities that actually matter.
Final thoughts: protection often has to act before certainty arrives
The Garry Kasparov warning illustrates one of the realities of professional executive protection.
Sometimes the intelligence is complete.
Sometimes it is not.
Sometimes you know exactly who is concerned, what they have done and where the exposure exists.
Sometimes a credible authority simply tells you:
The principal may be in danger.
Take precautions.
At that point, I do not have the luxury of pretending uncertainty means there is no problem.
I also do not want the protection team filling every information gap with the worst possible assumption.
We work with what we know.
We separate facts from allegations.
We identify the unknowns.
We review the residence.
We review family exposure.
We review movements.
We review travel.
We control sensitive information.
We establish communication with the authorities holding the intelligence.
We look for behavior that may indicate preparation.
We increase the protective posture where the risk justifies it.
And we keep reassessing as new information arrives.
The federal allegations announced in September are a particularly useful reminder because the alleged plot did not begin with somebody simply walking toward the intended victim.
According to prosecutors, locations were identified.
Surveillance was allegedly commissioned.
Photos and video were allegedly collected.
Then a murder-for-hire offer allegedly followed.
That sequence is exactly why protective intelligence matters.
The best opportunity to protect a principal is often before an incident becomes an incident.
Recognize changing behavior.
Recognize attempts to learn the environment.
Recognize surveillance when a pattern supports that conclusion.
Connect information from the residence, driver, assistant, family office and mobile detail.
Then act proportionately.
The objective is not to make the principal afraid.
It is not to make every unusual event sinister.
And it is not to maintain maximum security forever.
The objective is to make sure that when credible information says the risk has changed, the protection program is capable of changing with it.
That is what professional executive protection should do.
Sources
About Michael Braun
Michael Braun is a former Special Unit Operator, former Manager at Gavin de Becker & Associates, and Founder & CEO of MSB Protection, an executive protection and residential security firm serving high-net-worth and ultra-high-net-worth clients.
Braun has built his career at the intersection of specialized protective operations, executive protection, residential security, protective intelligence, and security risk management. His experience spans special-unit operations, leadership within Gavin de Becker & Associates, and the development and oversight of private protection programs within demanding UHNW environments.
He has been recognized by The Top 100 Magazine as a leading CEO in the private security field and is the subject of an upcoming Marquis Who’s Who feature highlighting his leadership and contributions to the profession.
Today, Braun is recognized for his work in executive protection, UHNW estate security, residential protection, protective intelligence, adversarial security assessments, and security auditing throughout Beverly Hills and Southern California.
His work focuses on moving private security beyond simply “providing a body” and toward intelligence-led, risk-based protection programs designed to identify vulnerabilities before an adversary can exploit them.
Looking for Executive Protection or Residential Security Services?
If you are a high-net-worth or ultra-high-net-worth individual, family office, estate manager, chief of staff, or executive in Beverly Hills, Los Angeles, Malibu or Southern California, MSB Protection provides executive protection, residential security, 24/7 protection, protective intelligence, medical-readiness planning, and security risk management.
We evaluate the complete security environment, from threat exposure and residential vulnerabilities to personnel, technology, procedures, protective intelligence, and emergency response, and build a program around the risks that actually exist.
Contact us for a confidential consultation or message us at +1 (805) 285-2807.