UHNW Security Lessons From Former Bodyguard Case
A developing criminal case in Arizona involving a former bodyguard of former U.S. Senator Kyrsten Sinema raises a security issue I take very seriously in UHNW protection: what happens when someone who once had legitimate access, trusted information and intimate knowledge of the protective environment is no longer part of the team?
That question matters far beyond this particular case.
Protectors are often given access that very few people outside the family ever receive. We learn where the principal lives, how the residence operates, which entrances are routinely used, where vehicles are staged, how the family travels, who works at the estate, what the normal schedule looks like and how the protective team responds when something unusual happens.
Executive assistants, estate managers, drivers, household employees, technology vendors and certain contractors can accumulate similar knowledge.
When one of those relationships ends, we can revoke a credential.
We cannot revoke memory.
That is the part of offboarding that is too often missed.
According to court records reported by Arizona’s Family and KJZZ, Matthew Ammel, a former member of Sinema’s security detail and later her romantic partner, is accused of causing extensive damage at her Cave Creek, Arizona residence on August 30, 2026. Investigators allege that 22 paintings were thrown into a swimming pool, another painting was spray-painted, expensive bottles were broken and a large mirror was shattered. Authorities estimated approximately $123,015 in damage to artwork and more than $200,000 in total damage.
The case later developed further.
Arizona’s Family reported on October 1 that investigators alleged Ammel violated release conditions by attempting to contact Sinema indirectly through another person and by possessing a large hunting-style knife. Authorities also alleged that information was received suggesting he was attempting to obtain a firearm and tactical equipment and had made threatening statements. Those later allegations were part of the continuing court proceedings and had not been proven at trial.
By October 2, Arizona’s Family reported that a grand jury had indicted Ammel on a criminal-damage charge designated as a domestic-violence offense. His arraignment had been moved to October 15 after he declined transport for an earlier hearing. The additional allegations surrounding his release conditions remained part of the developing case.
I am not interested in diagnosing anybody involved in this case, speculating about motive or using an unresolved criminal proceeding to make broader claims about former employees.
The protection issue is more straightforward.
A person who once occupied a trusted protective position may retain detailed knowledge of the principal, the residence and the security program long after the formal relationship ends.
That changes how I think about offboarding.

Key takeaways for UHNW families and family offices
- Former insider knowledge does not disappear when employment ends. Keys and credentials can be returned. Knowledge of entrances, schedules, procedures, vehicles and family routines cannot.
- Offboarding is a security event, not merely an HR event. The protective team should understand who is leaving, what that person knew and what access or information remains useful.
- Different roles require different offboarding. A protector with intimate knowledge of the principal’s routines requires a different review from a vendor who serviced one exterior system.
- Behavior matters more than the label “former employee.” Most people who leave a household or protection team present no threat whatsoever. Concern should follow observable conduct, access and changes in circumstances, not assumptions.
- Access can be revoked; familiarity cannot. Sometimes the protective posture itself needs to change because old knowledge remains accurate.
- Residential security and executive protection have to operate together. A former insider may know both the estate and the principal’s movements outside it.
- Small incidents need to be collected. Unexpected calls, unwanted contact, unusual appearances near the property or attempts to obtain information may mean little individually. They become more useful when one person is responsible for seeing the complete picture.
- The protective team’s job is to reduce exposure and coordinate. Protectors should document concerning behavior and work with counsel and law enforcement where appropriate rather than improvising confrontations or amateur investigations.
What happened in the Kyrsten Sinema former-bodyguard case
Based on the publicly reported court records, the underlying Arizona incident occurred on August 30, 2026, at Sinema’s Cave Creek residence.
Investigators allege Ammel demanded that Sinema publish a video on social media and threatened to damage paintings if she did not comply. Court records cited by Arizona’s Family describe 22 paintings being removed from the residence and placed in the swimming pool. Investigators also reported another painting had been spray-painted, expensive bottles had been broken and a wall-mounted mirror had been shattered.
Authorities estimated the paintings alone were worth approximately $123,015, with total reported damage exceeding $200,000.
Investigators also said Sinema provided text messages, recordings and residential surveillance video that were reviewed as part of the investigation. Ammel was later arrested in connection with the alleged damage.
The case did not end with the initial arrest.
Later court records reported by Arizona’s Family alleged that Ammel attempted to circumvent a no-contact restriction by asking another person to communicate with Sinema. Investigators also alleged that his GPS monitor showed him at a firearms retailer and that he possessed a large hunting-style knife despite restrictions on possession. Prosecutors cited additional allegations involving attempts to acquire a firearm or tactical equipment and threatening statements when seeking stricter release conditions.
On October 2, reporting based on the continuing proceedings said a grand jury had indicted Ammel on the criminal-damage charge.
These facts remain part of an unresolved criminal case. An indictment is not a conviction, and allegations surrounding the later conduct also remain allegations unless established through the legal process.
For a protection professional, however, the case illustrates an operational problem that exists independently of the final legal outcome:
What happens when somebody who knows the protective environment becomes somebody the protective environment may now need to account for?
Former insiders start with something an outsider does not have
Familiarity.
That is the fundamental difference.
An unknown outsider who wants information about a protected family may first need to determine where the family lives.
A former protector may already know.
An outsider may need to determine which gate is normally used.
A former protector may have stood at that gate hundreds of times.
An outsider may need to determine what vehicle the principal normally uses.
A former driver or protector may know every vehicle in the fleet.
An outsider may need to learn when the principal normally leaves in the morning.
A former assistant, driver or residential protector may already understand the pattern.
An outsider may need to identify the household staff.
A former insider may know them personally.
An outsider may have to guess what happens when an alarm activates.
A former protector may know the response procedure.
This does not make the former employee dangerous.
That distinction is important.
The overwhelming majority of people who leave protective teams, family offices and private households go on with their lives and never present any concern to the family.
Security should never treat normal separation as evidence of malicious intent.
But from a risk-management standpoint, we also should not pretend that a person forgets everything they learned the moment employment ends.
Offboarding should be treated as part of the protective operation
In many private households, offboarding is divided among several people.
HR handles payroll and employment paperwork.
The estate manager retrieves a key.
IT disables an email account.
The office administrator removes access from a calendar.
Security may hear that the person left but never receive responsibility for reviewing the security implications.
That creates a gap.
I want somebody to step back and ask a larger question:
What did this person know, what could this person access and what remains relevant now?
Those are three different questions.
What did the person know?
A former protector may know:
- the principal’s primary residence;
- secondary residences;
- regular vehicle assignments;
- school locations;
- children’s recurring activities;
- frequently used routes;
- normal departure times;
- preferred airports or FBOs;
- common restaurants or clubs;
- the identity of household staff;
- where security personnel are normally positioned;
- which entrances receive less attention;
- what happens during an alarm;
- how travel movements are coordinated;
- and how the principal behaves when plans change.
An estate manager or executive assistant may know even more about the family’s schedule.
A technology contractor may know network architecture, camera locations or access-control systems.
A driver may understand vehicle movements and pickup locations.
A nanny may know children’s schedules.
The review should reflect the person’s actual exposure rather than simply the job title.
What could the person access?
Then I look at physical and digital access.
Keys.
Gate remotes.
Alarm codes.
Mobile access-control applications.
Vehicle credentials.
Garage-door transmitters.
Building badges.
Security-system accounts.
Email.
Calendars.
Cloud storage.
Messaging platforms.
Shared contact lists.
Travel systems.
Home-automation applications.
Password managers.
Company-issued phones or computers.
Even seemingly minor access can matter when it connects to something else.
What knowledge remains useful?
This is the part a simple access checklist does not answer.
Suppose every credential is disabled correctly.
The former protector still knows the normal route from the residence to the office.
Or where the principal’s vehicle waits every morning.
Or that a particular pedestrian gate receives little attention.
Or that the family normally leaves the estate unattended on certain weekends.
Or that the children always use the same pickup point.
That information cannot be deleted.
So I want to know whether it is still accurate.
You do not need to change every routine after somebody leaves
I am not a believer in security theater.
Changing everything simply because a protector resigned can create enormous disruption without reducing meaningful risk.
The response should be proportionate.
If somebody leaves under completely routine circumstances, there may be no reason to alter principal movements beyond normal credential revocation and administrative cleanup.
If the departing person had extremely deep access and the separation was contentious, I look more carefully.
If unwanted communication, fixation, boundary violations or other concerning conduct begins afterward, the analysis changes again.
The point is not to react dramatically.
The point is to understand what old knowledge could realistically still be used.
Different departures require different security reviews
I would not offboard every role the same way.
Former executive protector
A protector may have the most complete picture of the principal outside the residence.
They may understand:
- routes;
- travel patterns;
- vehicle procedures;
- hotel preferences;
- airports and aircraft arrangements;
- regular destinations;
- principal habits;
- protective formations;
- communication procedures;
- and response plans.
If that person also worked residential assignments, the exposure becomes broader.
Former residential protector
A residential protector may understand the estate in extraordinary detail.
Where cameras do and do not see.
How gates operate.
Which vendors arrive without much scrutiny.
When staffing is lighter.
Which family members follow predictable routines.
Where vehicles are parked.
How alarms are handled.
What happens during a power outage.
That knowledge deserves consideration during offboarding.
Former estate manager or executive assistant
These roles can have enormous visibility into the principal’s life.
Calendars.
Contacts.
Travel plans.
Household personnel.
Medical appointments.
Family events.
Vendors.
Property schedules.
They may know less about tactical security but more about the family’s actual movements.
Former driver
A driver can know vehicles, pickup locations, airport movements, school schedules, preferred routes and timing.
That is meaningful protective information.
Former contractor or security vendor
A contractor may have narrower access but extremely sensitive technical knowledge.
Someone who installed the gate system may understand how it operates.
A surveillance installer may know camera placement.
An alarm technician may understand sensors and zones.
A network provider may know where critical infrastructure is located.
The amount of time somebody worked for the household is not always the best measure of the sensitivity of their knowledge.
Credential revocation should be immediate and complete
The easiest part of offboarding is also the part that should never be missed.
Remove access that is no longer justified.
That sounds obvious.
In practice, private estates accumulate credentials constantly.
Someone has an old gate remote in a vehicle.
A temporary keypad code became permanent.
A mobile application is still installed on a former employee’s personal phone.
An old email account still forwards messages.
A shared password was never changed.
A security-system login is forgotten because nobody remembers that it was created.
A company phone is returned, but a cloud account remains logged into a personal device.
This is why I prefer an actual access inventory rather than relying on memory.
When somebody leaves, the question should not be, “Did we get the key?”
The question should be, “What could this person reach yesterday, and can they still reach any of it today?”
Shared credentials create unnecessary offboarding problems
One reason offboarding becomes difficult is that many estates still use shared credentials.
Everyone knows the same gate code.
Several staff members use one surveillance login.
The same alarm credential is passed between employees.
One password is used for a shared household account.
That may be convenient until one person leaves.
Now the household has to choose between leaving the former employee’s access intact or changing the credential for everybody.
Where practical, I prefer identifiable access tied to the individual.
That gives the estate control.
It also creates better accountability because we know which credential was used rather than merely knowing that somebody knew the code.
Former insiders also create a social-engineering consideration
Physical access is only one part of the issue.
A former employee may know the names of people inside the household.
They may know which assistant handles a particular issue.
They may know which vendor normally services a system.
They may know the terminology the team uses.
That makes an approach sound more credible.
“John told me to come by.”
“Sarah knows I’m here.”
“I’m working on the west gate again.”
“I just need five minutes with the estate manager.”
Those statements become more persuasive when the speaker genuinely knows John, Sarah, the west gate and the estate manager.
That is another reason verification should be based on current authorization rather than familiarity.
Concern should follow behavior, not former employment
I want to be very clear about this.
A person leaving a protection team is not a threat indicator.
A difficult personality is not a threat assessment.
A disagreement is not a threat.
A veteran is not inherently dangerous.
A former romantic relationship is not by itself evidence that violence will occur.
A protective program should focus on observable behavior and context.
What is the person doing?
Has unwanted contact begun?
Are boundaries being ignored?
Are attempts being made to obtain information from staff?
Has the person appeared unexpectedly at locations connected to the family?
Are communications escalating?
Are other people being used to reach the principal after direct contact has been refused?
Has there been damage, intimidation or other unlawful conduct?
Are there court orders or law-enforcement instructions that change what the team needs to do?
Those are much more useful questions.
Small pieces of information need one place to go
This is where residential security, executive protection and protective intelligence have to connect.
An assistant receives an unusual message.
A residential protector sees a familiar former employee’s vehicle near the property.
A driver hears from somebody asking about the principal’s travel.
An estate manager learns that a former contractor contacted another member of staff.
A family member receives an unwanted message through a third party.
Individually, each event may have an innocent explanation.
The problem arises when each person treats the incident as isolated.
The assistant deletes the message.
The protector mentions the vehicle casually at shift change.
The driver ignores the question.
The estate manager does not know about either event.
No one sees that three things happened in forty-eight hours.
That is a protective-intelligence failure.
Somebody has to own the picture
For a sophisticated family office or UHNW protection program, somebody should be responsible for collecting relevant security information.
Not gossip.
Not speculation.
Not rumors about former employees.
Observable facts.
Date.
Time.
Location.
What occurred.
Who observed it.
What supporting material exists.
Whether it connects with anything else.
This prevents the team from overreacting to a single event while also reducing the chance that a meaningful pattern is missed.
Preserve evidence instead of creating more conflict
When concerning contact begins, I do not want protectors improvising personal confrontations.
The team should understand its role.
Document what occurred.
Preserve relevant messages.
Preserve video.
Preserve access records.
Document unwanted appearances.
Make sure the information reaches the person responsible for the protective picture.
Then coordinate with counsel and law enforcement when the circumstances warrant it.
The objective is to reduce exposure and give the appropriate authorities good information.
The security team is not there to start an argument, negotiate a personal dispute or run an amateur criminal investigation.
No-contact restrictions have operational consequences for the security team
The later allegations in the Sinema case are important from a protection perspective because investigators alleged indirect attempts at contact after court restrictions had been imposed.
When a court order or law-enforcement instruction exists, the protective team needs to understand exactly what it means operationally.
Who should be contacted if the person appears?
What should staff do if a third party delivers a message?
Does the family want all indirect contact documented?
Who preserves evidence?
Who communicates with counsel?
Who communicates with law enforcement?
What should the residential team do if the person approaches the estate?
What should the executive protection team do if the person appears at an event or destination?
The worst time to invent these answers is during the encounter itself.
The residence and the executive protection detail are one protective system
A former protector may understand both environments.
That is what makes this particular category of insider knowledge different from many ordinary employment situations.
The person may know the residence.
They may also know the principal’s routes.
They may know the office.
They may know travel patterns.
They may know how the driver operates.
They may know where the principal enters a venue.
They may know how the family handles school movements.
If the residential team evaluates risk independently from the executive protection team, each side may be working with only half the information.
The protective program has to connect.
Transition points deserve another look after a concerning departure
I pay particular attention to predictable transitions.
The principal leaving the residence.
Entering a vehicle.
Walking from a parking location into an office.
School pickups.
Airport arrivals.
Regular exercise locations.
Recurring social events.
A former protector may know those points better than almost anyone.
Again, I would not automatically change every movement.
But if the risk picture changes, I want to know where old knowledge creates the greatest exposure.
A pattern that was perfectly acceptable yesterday may deserve adjustment tomorrow because somebody with detailed knowledge of it has become a legitimate security concern.
High-net-worth families should review predictability, not create chaos
There is a temptation after a concerning departure to start changing everything.
Different vehicles every day.
Different routes.
Different gates.
Different schedules.
That quickly becomes disruptive and usually unsustainable.
I prefer to identify the predictable behaviors that actually matter.
If a former employee knows that the principal walks alone through the same exposed motor court every morning at 7:10, that may matter.
If the former employee knows that the family’s gardener arrives every Tuesday at 11 a.m., that may not.
Security should make changes because they reduce a real vulnerability, not because visible activity makes everyone feel as though something is being done.
The principal’s children and family members should be considered separately
A former insider may know more than the principal’s schedule.
They may know where children attend school.
Which nanny drives them.
Which extracurricular activities are recurring.
Which family member is most approachable.
Which relatives visit frequently.
Which secondary residence the family uses on weekends.
That does not mean children should be frightened or suddenly subjected to dramatic changes.
The adults managing the protection program should quietly determine whether any retained knowledge creates unnecessary exposure.
Family protection works best when the security burden remains with the adults and the professional team rather than being transferred to children.
Household staff need a simple reporting procedure
After a concerning departure, everyone who works around the household should not be handed a complicated threat-assessment lecture.
They need to know what to do.
If the former person calls, who gets told?
If they show up, who gets told?
If they ask a staff member for the principal’s location, what should the employee say?
If a mutual acquaintance tries to pass along a message, does security need to know?
If somebody sees the person’s vehicle near the property, should it be documented?
Simple reporting works better than expecting every employee to decide whether something is serious enough.
Let the protection team make that assessment.
Offboarding should include devices and data, not just gates
Modern protection programs generate a tremendous amount of digital information.
Calendars.
Travel itineraries.
Shift logs.
Visitor records.
Incident reports.
Vehicle information.
Residential camera feeds.
Gate applications.
Cloud documents.
Group messages.
Contact lists.
A person may lose access to the physical property and still retain sensitive material on an old device.
Family offices should understand where protective information lives and which devices or accounts had access to it.
This is especially important when personal devices were permitted for work.
You cannot make a former employee forget what they saw.
But you can stop continuing to send new information to an account or device they should no longer control.
Relationships inside a protective team require professional boundaries
The publicly reported court filings in the Sinema matter identify Ammel not only as a former member of her security detail but also as a former romantic partner. Sinema acknowledged in a March 2026 court filing that the relationship became romantic and intimate during 2024.
I am not interested in commenting on the personal relationship itself.
There is, however, an operational issue whenever professional and deeply personal relationships overlap.
Protectors already occupy positions of unusual trust.
They may have access to the principal’s private life, vulnerabilities, travel, residence and family.
When another relationship becomes layered onto that professional access, lines of authority and information can become harder to manage.
From a security-management standpoint, the protective program should still know who has access, who supervises whom and who has authority to make decisions affecting the principal’s safety.
The more informal those boundaries become, the easier it is for access that originally existed for a professional reason to continue after the professional reason has disappeared.
Former insiders can expose weaknesses without intentionally attacking the family
Not every insider-related problem involves violence or deliberate malicious behavior.
A former employee can accidentally create exposure.
They may discuss a former principal with friends.
Post photographs that reveal part of a residence.
Keep old contacts.
Retain a group chat.
Mention travel patterns.
Use their past employment to impress somebody.
That information can migrate.
This is another reason the household should practice good information discipline during employment, not merely after the employee leaves.
The less unnecessary information everybody has, the less information walks out the door later.
Compartmentalization matters inside UHNW households
People should know what they need to perform their role.
Not because the family distrusts its employees.
Because unnecessary distribution creates unnecessary exposure.
The gardener does not need the principal’s international itinerary.
The delivery coordinator does not need the children’s school schedule.
A temporary contractor does not need access to the residential camera system.
A driver may need tomorrow’s pickup time but not a month of family travel.
Even inside the security team, there may be information that only certain people need.
Good compartmentalization makes the program more resilient during normal staff turnover.
When should a family conduct a post-departure security assessment?
I would consider a more detailed review when the departing person had substantial access to the principal or estate, when the departure was contentious, when the role exposed them to sensitive procedures or when concerning behavior emerges afterward.
The review might include:
- physical access credentials;
- digital accounts and devices;
- residential routines;
- vehicle and transportation patterns;
- children’s schedules;
- travel information;
- exposed access-control procedures;
- known weaknesses the person may have observed;
- information available through other staff members;
- and whether the person still has legitimate reasons to interact with the household.
The purpose is not to redesign the entire protective program every time somebody leaves.
The purpose is to determine whether old knowledge has created a vulnerability worth addressing.
What I would do after a normal protector departure
Most departures are routine.
The protector takes another job.
The assignment changes.
The family restructures the team.
There is no concerning behavior.
In that situation, I still want disciplined offboarding.
Recover issued property.
Revoke physical access.
Remove digital accounts.
Update distribution groups.
Confirm devices are returned.
Review any shared credentials that need changing.
Inform the relevant estate and protection personnel that the person’s authorization has ended.
Then move on.
Security does not need to manufacture suspicion where none exists.
What changes when the departure becomes concerning
If unwanted contact, repeated boundary violations, threats, unexplained appearances or other concerning behavior develops, the protective response becomes more deliberate.
I want to know:
What access has already been removed?
What does the person still know?
Which routines remain predictable?
Who inside the household is receiving contact?
Has everybody reported what they know?
Are there legal restrictions?
Has law enforcement been involved?
What evidence has been preserved?
Does the residential team know what to do?
Does the executive protection team know what to do?
Do staff know how to handle unexpected contact?
Does the family need a temporary change in staffing or coverage?
Those are operational questions.
They are far more useful than trying to decide what label to put on the person.
How MSB Protection approaches insider risk for HNW and UHNW families
At MSB Protection, I look at insider risk as part of the larger protective environment.
The residence.
Executive protection.
Family office.
Vehicles.
Staff.
Vendors.
Technology.
Travel.
Children.
Protective intelligence.
Those things overlap.
That means the offboarding of a high-access person should not happen in one department while everybody else assumes the issue belongs to somebody else.
Depending on the circumstances, a review may involve security assessment, residential-security adjustments, executive-protection changes, access-control review, protective-intelligence monitoring, staff briefing and coordination with legal counsel or law enforcement.
Sometimes the result is simple.
Change a credential.
Remove an account.
Update a gate list.
Sometimes the conclusion is that nothing further is necessary.
And sometimes retained knowledge combined with changing behavior means the protective posture genuinely needs to change.
The important part is that somebody actually makes that assessment.
What UHNW families and family offices can do now
Identify high-access roles
Start by identifying the people whose jobs give them substantial visibility into the principal’s life.
Protectors.
Estate managers.
Executive assistants.
Drivers.
Nannies.
Senior household staff.
Technology administrators.
Certain contractors.
That does not mean those people are risks.
It means their departure deserves a more complete process because of what they know.
Build an access inventory before you need it
Know what credentials exist.
Physical keys.
Gate remotes.
Access cards.
Mobile applications.
Alarm accounts.
Camera accounts.
Network accounts.
Shared folders.
Calendars.
Company devices.
If the household has to reconstruct that list after a contentious departure, the process is already harder than it should be.
Decide who owns security offboarding
Somebody should be responsible for asking the protective questions.
HR can handle HR.
IT can handle IT.
The estate manager can handle household property.
But somebody should look across all of those areas and determine whether anything has been missed.
Create a staff reporting channel
Employees should know who to contact if a former insider reaches out unexpectedly or appears at a location connected to the family.
Do not rely on everyone independently deciding whether an event is important.
Review predictable routines only when necessary
Do not create disruption for the sake of creating disruption.
Identify the routines that old knowledge makes genuinely vulnerable and change those if the risk justifies it.
Keep residential and executive-protection reporting connected
A concern observed at the residence may matter to the travel team.
A concern observed while the principal is away may matter to the residential team.
Both sides need an appropriate information-sharing process.
Preserve evidence
If concerning contact occurs, retain relevant messages, video, access logs and observations.
Good information allows counsel, law enforcement and the protection team to make better decisions.
The real lesson is not to distrust insiders
That would be the wrong conclusion.
UHNW protection depends on trusted people.
Families could not function otherwise.
The strongest residential and executive-protection programs I have seen are built on professional relationships, good communication and trust.
The lesson is that trust does not eliminate the need for structure.
People change roles.
Employees leave.
Relationships change.
Contractors finish projects.
Protectors move on.
Life changes.
The protective program should be designed so that those normal changes do not create unnecessary vulnerability.
Frequently asked questions about insider risk and security offboarding
Why are former employees relevant to UHNW security?
Some former employees retain detailed knowledge of residences, vehicles, schedules, family members, access procedures and security systems. That does not make them suspicious. It means their departure should account for the continuing value of what they learned while working around the principal.
Should every former protector be treated as a security concern?
No. Absolutely not. Most protector departures are routine and require nothing beyond professional offboarding. Security concerns should be based on access, circumstances and observable behavior rather than the mere fact that somebody used to work for the family.
What should happen when an executive protector leaves a detail?
Issued equipment should be recovered, physical and digital access should be removed, distribution groups and accounts should be updated and the team should determine whether the protector had knowledge that creates any continuing vulnerability. In a routine departure, that may be the end of the process.
Should gate codes be changed every time a household employee leaves?
It depends on how the access system is designed. Individually assigned credentials can often simply be disabled. If multiple people share one code and the departing employee knew it, changing that shared credential may be appropriate. This is one reason individualized access is generally easier to manage.
What security information can a former bodyguard retain?
A former bodyguard may remember routes, schedules, vehicles, residences, travel habits, protection procedures, family routines, access points and the behavior of the principal. The exact exposure depends on the assignment.
Can a family make a former employee forget security procedures?
No. That is exactly why offboarding cannot be limited to collecting keys. The team should determine whether the information the person retains is still accurate and whether any meaningful vulnerability should be changed.
Should routines automatically change after a protector leaves?
No. Routine changes should solve an identified problem. Constantly changing routes or schedules without a reason creates unnecessary friction and rarely lasts. If retained knowledge combined with concerning behavior creates a specific exposure, then targeted changes may make sense.
What is security offboarding?
Security offboarding is the process of ending a person’s physical and digital access while reviewing what protective information they had and whether their departure changes the risk environment. It should complement HR and IT offboarding rather than replace them.
Who should manage offboarding for a family office?
Responsibilities may be divided among HR, IT, estate management and security, but somebody should have responsibility for the complete security picture. Otherwise each department can complete its piece while an important gap remains between them.
What should household staff do if a former employee contacts them?
They should follow the household’s reporting procedure. The important thing is that potentially relevant contact reaches the person responsible for security rather than remaining only on an employee’s phone or in memory. Staff should not be expected to conduct their own threat assessment.
What should happen if a former employee appears at the estate?
The response depends on whether the person remains authorized and whether any legal restrictions or security concerns exist. Residential personnel should have clear instructions before such an event occurs, including who to contact and whether law enforcement should be notified.
Why is indirect contact important?
Indirect communication can matter when the principal has already declined contact or when legal restrictions exist. A third party delivering messages can still be relevant to the protective picture. In the Sinema case, investigators alleged that an attempt to communicate through another person violated release conditions.
What is protective intelligence in a private-family environment?
Protective intelligence is the disciplined collection and evaluation of information that may affect the safety of the principal or family. In this context, it means making sure separate observations and contacts are compared so decisions are based on the full pattern rather than isolated anecdotes.
Should security personnel confront a concerning former employee?
Generally, I want protectors focused on protecting the principal, controlling access, preserving evidence and coordinating with the appropriate authorities. Unnecessary confrontation can create additional risk. The specific response should follow the circumstances, legal guidance and law-enforcement direction.
How does insider risk affect residential security?
A former insider may understand gates, camera coverage, household routines, staff practices, vehicle movements and emergency procedures. Residential security should therefore be included in any meaningful review following a concerning high-access departure.
How does insider risk affect executive protection?
A former protector or driver may understand routes, pickups, recurring destinations, airports, vehicle procedures and principal habits. If a legitimate concern develops, executive protection should evaluate whether any of those predictable patterns create unnecessary exposure.
Should children’s routines be reviewed?
If the departing person had detailed knowledge of children’s schools, activities or transportation and the circumstances justify a security review, those routines should be considered. The goal should be targeted risk reduction without unnecessarily frightening or disrupting the children.
How often should access rights be audited?
Access should be reviewed whenever employment or responsibilities change, with periodic audits as a backstop. A former employee should not retain a working gate credential for months simply because nobody remembered it existed.
Why are shared passwords and gate codes a problem?
Shared credentials make it harder to revoke one person’s access without affecting everybody else. They also make it harder to determine who actually used the credential. Individual access provides cleaner control when the system supports it.
Does a contentious termination automatically mean somebody is dangerous?
No. A contentious departure may justify a more careful security review, but it is not itself evidence that the person intends harm. Protective decisions should follow observable behavior, access and specific circumstances.
What should a family office preserve after concerning contact?
Depending on the circumstances, that can include messages, emails, voicemails, surveillance video, access logs, photographs, dates and times of appearances and factual observations from staff. Preserve information rather than relying on memory.
When should law enforcement become involved?
That depends on the conduct and jurisdiction. Threats, unlawful entry, violence, property damage, stalking behavior, violations of court orders or other potential crimes may warrant law-enforcement involvement. Protective personnel should coordinate with counsel and the appropriate authorities rather than trying to adjudicate criminal behavior themselves.
Final thoughts: access ends faster than knowledge
The Arizona case involving Kyrsten Sinema and her former bodyguard is still moving through the courts, and the allegations should remain exactly that until the legal process resolves them.
But the security principle does not depend on the verdict.
Protectors and other trusted insiders can accumulate extraordinary knowledge about the people they serve.
That is part of the job.
We are trusted with residences.
Schedules.
Vehicles.
Children.
Travel.
Procedures.
Vulnerabilities.
Private information.
When the professional relationship ends, the family can recover the key.
It can disable the gate remote.
It can close the account.
It can collect the phone.
It cannot erase what the person learned.
That does not mean the former insider should be feared.
It means the protection program should be mature enough to recognize the difference between access and knowledge.
Most of the time, professional offboarding is enough.
When circumstances change, the team should be able to identify that change early, collect the relevant information and adjust the protective posture without panic and without security theater.
That is the standard I apply to executive protection, residential security and security programs for high-net-worth and ultra-high-net-worth families.
Trusted access is necessary.
Disciplined offboarding is what makes that trust sustainable.
Sources
About Michael Braun
Michael Braun is a former Special Unit Operator, former Manager at Gavin de Becker & Associates, and Founder & CEO of MSB Protection, an executive protection and residential security firm serving high-net-worth and ultra-high-net-worth clients.
Braun has built his career at the intersection of specialized protective operations, executive protection, residential security, protective intelligence, and security risk management. His experience spans special-unit operations, leadership within Gavin de Becker & Associates, and the development and oversight of private protection programs within demanding UHNW environments.
He has been recognized by The Top 100 Magazine as a leading CEO in the private security field and is the subject of an upcoming Marquis Who’s Who feature highlighting his leadership and contributions to the profession.
Today, Braun is recognized for his work in executive protection, UHNW estate security, residential protection, protective intelligence, adversarial security assessments, and security auditing throughout Beverly Hills and Southern California.
His work focuses on moving private security beyond simply “providing a body” and toward intelligence-led, risk-based protection programs designed to identify vulnerabilities before an adversary can exploit them.
Looking for Executive Protection or Residential Security Services?
If you are a high-net-worth or ultra-high-net-worth individual, family office, estate manager, chief of staff, or executive in Beverly Hills, Los Angeles, Malibu or Southern California, MSB Protection provides executive protection, residential security, 24/7 protection, protective intelligence, medical-readiness planning, and security risk management.
We evaluate the complete security environment, from threat exposure and residential vulnerabilities to personnel, technology, procedures, protective intelligence, and emergency response, and build a program around the risks that actually exist.
Contact us for a confidential consultation or message us at +1 (805) 285-2807.