Protective Intelligence Lessons From Brazil
When threats, surveillance concerns and intimidation begin affecting not only the original target but also the people around them, the protection problem changes.
The principal is no longer the only person I am thinking about.
I am thinking about the spouse.
The children.
The driver.
The executive assistant.
The estate manager.
The household staff.
The people who work with the principal every day.
And I am thinking about whether seemingly unrelated events are actually beginning to form a pattern.
That is what makes the recent case involving Brazilian news outlet Tapajós de Fato worth examining from a protective-intelligence standpoint.
The independent outlet, based in Santarém in Brazil’s northern state of Pará, decided not to conduct the systematic election coverage it had been preparing for Brazil’s 2026 elections after years of reported threats, intimidation and violence involving members of its team.
Agência Pública reported on September 14 that the newsroom had spent part of 2026 planning the coverage and seeking funding before deciding the risk was too great. Abraji, the Brazilian Association of Investigative Journalism, subsequently reported that the decision was driven by fear of retaliation and persecution following recurring incidents dating back several years.
The reported incidents were serious.
Abraji said team members had faced episodes including a decapitated cat’s head, slashed tires and an attack in which a journalist was stabbed approximately 30 meters from the newsroom. The organization also reported that some professionals had changed residences or cities and spent months away from their families because of safety concerns.
The Guardian later reported that Tapajós de Fato co-founder Marcos Wesley Pedroso described suspicious surveillance near his home followed by an incident involving his vehicle. The outlet ultimately decided not to systematically cover the election because, in Pedroso’s description, the safety concern extended to journalists and their families.
Folha de S.Paulo separately reported the stabbing and the delivery of a cat’s head while covering threats affecting regional news organizations during the 2026 election period.
There is an important limitation to all of this.
The available reporting does not establish who was responsible for all of these incidents.
It does not establish that they all came from the same person or organization.
It does not establish that every event was related.
And there is no responsible basis for me to attribute the reported intimidation to a political party, candidate, business interest, criminal organization or other actor without evidence.
From a protection standpoint, however, that uncertainty does not prevent us from doing our job.
You do not have to solve the mystery before you begin protecting the people involved.
You have to understand what is happening.
You have to document it.
You have to determine whether repetition, escalation or proximity is developing.
And you have to make sure the information reaches somebody capable of seeing the whole picture.

Key takeaways for protective intelligence and executive protection
- Look for patterns, not dramatic individual incidents. One ambiguous event may mean nothing. Several events involving the same people, locations or behaviors can create a very different picture.
- The family can become part of the threat environment. Attention focused on one person may create exposure for spouses, children, assistants, drivers and household staff.
- Unknown attribution does not mean no action. You can reduce vulnerability and preserve evidence without knowing who is responsible or why.
- Information needs one place to go. A driver, assistant, residential protector and estate manager may each see one piece of the same developing situation.
- Stay behavior-based. Document what happened, when, where and how. Do not turn suspicion into fact.
- Reporting has to be easy. Staff should not have to prove that something is dangerous before telling security about it.
- Protective intelligence includes the residence. Surveillance, repeated appearances, unusual questions and unwanted contact around a home can matter even if the principal is never directly approached.
- Privacy and physical security are connected. Public routines, addresses, photographs, staff identities and schedules can make unwanted observation significantly easier.
- Good protection preserves options. The objective is to reduce the ability of intimidation to dictate where the principal or family can go, work or live.
What happened to Tapajós de Fato
Tapajós de Fato was founded in 2020 and covers issues in western Pará, particularly environmental, Indigenous and social issues affecting communities in the Brazilian Amazon. Abraji describes the outlet as an independent publication recognized for its Amazon coverage.
For the 2026 election cycle, the newsroom had intended to systematically follow candidates and election issues.
That plan changed.
Agência Pública reported that the organization had already been developing its editorial plans and looking for funding when it decided that continuing the project would expose staff to unacceptable danger.
FENAJ, Brazil’s National Federation of Journalists, and the Pará journalists’ union publicly expressed solidarity with Tapajós de Fato on September 16. Their statement said journalists and contributors had faced threats of death, persecution and violence over several years, and that members of the team had restricted their professional activity for safety reasons.
Abraji reported that the problems dated at least to 2021 and included both physical and psychological intimidation.
Among the events described publicly were:
- a decapitated cat’s head being left in circumstances understood by the journalists as intimidation;
- vehicle tires being slashed;
- a journalist being stabbed near the newsroom;
- threats against members of the team;
- reported surveillance around a co-founder’s home;
- and staff members changing where they lived or spending extended periods away from their families because of security concerns.
Abraji and FENAJ have called for investigation of the incidents and protection for the journalists.
The Guardian reported on September 30 that the cumulative effect was serious enough that the outlet decided not to systematically cover the national election.
That decision itself tells us something important about intimidation.
The objective of intimidation does not have to be physical injury.
If enough pressure causes somebody to stop working, stop traveling, leave a residence, alter a public role or abandon an activity they otherwise would have continued, the intimidation has already affected behavior.
From a protective standpoint, I am trying to prevent the adversary—whoever that adversary may be—from acquiring that kind of control over the protected person’s life.
The larger Amazon context matters, but it does not establish attribution
Tapajós de Fato’s experience is not occurring in an environment where threats to journalists are unheard of.
Reporters Without Borders reported in 2025 that its research had documented 66 attacks against journalists in the Brazilian Amazon between July 2022 and July 2023. RSF has also described local journalists in parts of the Amazon as facing surveillance, physical intimidation and difficult operating environments while reporting on environmental and territorial issues.
In Pará specifically, RSF reported that radio journalist Luis Augusto Carneiro da Costa was shot and killed while broadcasting in Abaetetuba in May 2025. RSF called on authorities to investigate whether his journalistic work was connected to the killing. That connection had not been established when RSF issued its statement.
That broader context can inform situational awareness.
It still does not tell us who was responsible for the incidents involving Tapajós de Fato.
This distinction is critical in protective intelligence.
Context helps me understand the operating environment.
It does not give me permission to invent attribution.
You do not need attribution before you begin protecting someone
This is one of the biggest misconceptions about protective intelligence.
People think we have to answer:
Who is doing this?
Why?
What do they want?
Are they dangerous?
Sometimes we can answer those questions quickly.
Sometimes we cannot.
But protection cannot stop while everyone waits for certainty.
If somebody is repeatedly observing a residence, I can address the exposure without knowing who they are.
If a family member begins receiving unwanted contact, I can document and manage it without understanding the motive.
If somebody repeatedly asks employees about the principal’s schedule, I can tighten information control before I know what that person intends to do with the information.
If an unknown vehicle repeatedly appears near the property, I can establish a factual record and determine whether it is appearing elsewhere.
Protect first.
Attribute when evidence allows it.
Pattern recognition is not the same as assuming everything is connected
That distinction matters just as much.
I do not want a security team turning three unrelated events into a conspiracy because everybody has become nervous.
Protective intelligence should make the program more disciplined, not more paranoid.
Suppose an unfamiliar SUV is parked near the residence on Monday.
That alone may mean almost nothing.
Maybe the driver is visiting a neighbor.
Maybe someone is waiting for a contractor.
Maybe the person is lost.
Now suppose the same vehicle appears again Thursday.
Still not proof of anything.
Then an assistant receives a message asking whether the principal will attend an event Friday.
A driver later notices an individual photographing vehicles at another location associated with the family.
A member of household staff mentions that somebody asked which gate the principal normally uses.
Now I have several observations.
I still do not automatically conclude they are connected.
But I absolutely want them in the same place so somebody can determine whether they are.
That is the difference between pattern recognition and storytelling.
The biggest protective-intelligence failure is often fragmentation
In UHNW environments, the information is frequently already there.
The problem is that it is scattered.
The residential protector sees something outside the gate.
The driver notices something during a movement.
The executive assistant receives a message.
The estate manager hears a strange question from a contractor.
The nanny notices someone near a school pickup.
The principal mentions an uncomfortable encounter but does not think it is important.
Each observation lives with a different person.
Everyone sees one small piece.
Nobody sees the entire picture.
That is why protective intelligence has to be integrated into the protection program rather than treated as a separate analytical exercise.
Information has to move.
A household needs one place for security-relevant information
I want a clear reporting channel.
It can be managed through a security director.
A family-office security lead.
An operations center.
A properly designed digital reporting system.
The exact tool is less important than the process.
Relevant information needs to reach somebody who can compare today’s event with yesterday’s event.
The report should answer basic questions.
What happened?
When?
Where?
Who observed it?
What exactly was said or done?
Was a vehicle involved?
Was a photograph or video captured?
Did the person appear anywhere else?
Has anything similar happened previously?
That is useful information.
“There was a suspicious guy” is much less useful.
Factual reporting is critical
I train people to separate observation from interpretation.
Observation:
“A white SUV with California plate 123ABC remained across from the driveway from 7:12 a.m. until 7:38 a.m. The driver remained inside.”
Interpretation:
“Someone was surveilling the house.”
Those are not the same statement.
The first gives me information I can compare later.
The second gives me somebody’s conclusion.
Maybe surveillance was occurring.
Maybe it was not.
I want the facts first.
Descriptions should be specific enough to compare later
The same goes for people.
“A weird guy was outside.”
That does not help much.
What did the person look like?
Approximate age?
Clothing?
Vehicle?
Location?
Direction of travel?
What exactly did the person do?
Did they interact with anyone?
Did they use a camera or phone?
What time?
Was there anything distinctive?
These details matter because another protector may see the same person somewhere else three days later.
Staff should not have to decide whether something is dangerous before reporting it
This is one of the most important cultural issues in protective intelligence.
If the driver thinks, “It’s probably nothing,” the information may disappear.
If the executive assistant thinks, “I don’t want to bother security,” the information may disappear.
If the housekeeper assumes, “Security probably already knows,” the information may disappear.
I want a lower threshold.
If something seems sufficiently unusual that the employee remembers it, tell us.
Let the protection team decide what it means.
That does not mean every report becomes a major threat investigation.
Most reports will probably lead nowhere.
That is fine.
The value comes from having the information available if another piece appears later.
A reporting system should not punish people for being wrong
If employees are embarrassed every time they report something that turns out to be harmless, they will stop reporting.
That is the opposite of what I want.
I would rather receive ten factual reports that turn out to mean nothing than miss the eleventh because somebody was afraid of looking foolish.
The quality standard should be accuracy.
Not clairvoyance.
Staff are not expected to know whether someone is dangerous.
They are expected to communicate relevant observations.
The family is part of the protective environment
The Tapajós de Fato reporting is especially relevant because the journalists said the concern extended beyond the newsroom to their families.
That changes the protection problem.
If somebody wants to intimidate a principal, they may decide the principal is difficult to reach.
The spouse may be easier.
A child may follow a predictable school routine.
An assistant may answer an unexpected message.
A driver may be approachable.
A household employee may be willing to answer what seems like an innocent question.
A relative may post more publicly on social media.
This does not mean I automatically assume family members will be targeted.
It means I do not design the protective program as though the principal exists in isolation.
Spouses can have a completely different exposure profile
A spouse may not have executive protection.
They may drive themselves.
Attend routine activities.
Shop at predictable locations.
Exercise at the same time every day.
Use social media differently.
Interact with schools, service providers and household employees.
If the threat picture changes around the principal, I want to consider whether any of those routines create unnecessary exposure.
That does not automatically mean assigning a protector.
It means including the spouse in the assessment.
Children require protection without transferring fear to them
Children create another challenge.
I do not want a threat situation turned into a constant source of fear for them.
The adults and the professional protection team should carry that burden.
But the program still needs to understand:
school;
pickup and drop-off;
sports;
friends’ homes;
drivers;
nannies;
social media;
and what information about the children is publicly available.
As threat concerns increase, the question becomes whether any predictable routine creates an exposure worth changing.
Targeted adjustments are much better than turning a child’s entire life upside down.
Household employees may be approached because they appear easier to access
This happens in many forms.
“Does Mr. Smith still live here?”
“What time does he normally leave?”
“Is the family traveling?”
“Which entrance should I use?”
“I’m trying to deliver something directly to him.”
“Do you know whether he will be at the event tonight?”
Each question can sound harmless.
That is why staff need simple information-security rules.
Do not confirm the principal’s location to unknown people.
Do not confirm travel.
Do not provide schedules.
Do not explain security procedures.
Route unusual requests through the established channel.
That does not require making employees suspicious of everybody.
It requires professional boundaries.
Surveillance concerns should be assessed behaviorally
The word surveillance gets used too easily.
A vehicle near a residence is not automatically surveillance.
A person looking at a house is not automatically surveillance.
Someone taking photographs may be photographing architecture, scenery or something completely unrelated.
The question is what behavior occurs over time.
Repetition matters.
Location matters.
Timing matters.
Whether the person appears at multiple locations matters.
Whether they are attempting to conceal their behavior may matter.
Whether they are asking questions may matter.
Whether they move when the principal moves may matter.
Whether the behavior is escalating matters.
I am looking for a pattern, not trying to label the first ambiguous event.
The baseline matters before you can recognize the anomaly
A good residential security team understands normal activity around the property.
Which neighbors park nearby?
Which gardeners arrive on which days?
Where do delivery drivers stop?
What construction projects are active?
Which vehicles regularly belong on the street?
Who walks dogs?
Which utility companies are working nearby?
If you do not understand normal, everything unfamiliar looks suspicious.
That produces noise.
And when everything is suspicious, nothing is suspicious.
Baseline knowledge allows the protection team to focus attention where it belongs.
Do not unnecessarily confront somebody you think may be watching the principal
If an unknown person may be conducting surveillance, my default objective is not to walk over and start an argument.
There are circumstances where direct intervention may be appropriate.
But confrontation should not be the automatic response to uncertainty.
Unnecessary confrontation can:
- alert someone that they have been detected;
- escalate an otherwise ambiguous encounter;
- create legal or safety problems;
- interfere with evidence collection;
- or unnecessarily expose the protector.
I want the team focused on the principal.
Document.
Communicate.
Reduce exposure.
Coordinate with law enforcement where appropriate.
You do not have to personally solve who the person is in order to protect the family.
Preserving evidence matters more than remembering it later
Memory changes quickly.
A staff member who remembers a license plate clearly today may be unsure tomorrow.
The exact wording of a message becomes fuzzy.
People forget times.
They merge events.
That is why evidence should be preserved when appropriate.
Screenshots.
Emails.
Voicemails.
Video.
Access logs.
Photographs.
Dates.
Times.
Vehicle descriptions.
Exact wording.
The purpose is not to build a private criminal case.
The purpose is to retain accurate information that can support better decisions and, when appropriate, be provided to law enforcement.
Video retention becomes important when patterns develop slowly
This is something estates frequently overlook.
A camera system may record continuously but retain footage for only a short period.
By the time somebody realizes the same person appeared three weeks earlier, the earlier footage is gone.
If a protective-intelligence concern is developing, relevant video should be preserved before normal retention cycles overwrite it.
The same applies to visitor logs and access records.
Information can be technically collected and still become useless if nobody preserves it.
Time and location allow separate events to be compared
A useful reporting program makes correlation possible.
Maybe an unknown vehicle appears near the residence at 8:15 a.m.
Three days later, another protector records the same vehicle near an office at 5:40 p.m.
A week later, the principal attends a public event and someone sees the same plate.
Without dates, times and locations, those events may never connect.
This is why good reporting is operational, not bureaucratic.
Historical information should remain available
Not every concern develops quickly.
Some disappear.
Some reappear months later.
Some change location.
Some change communication method.
That means relevant historical information cannot live only in one protector’s memory.
If somebody repeatedly approached a residence two years ago and the same individual appears again today, I want the current team to know.
People change assignments.
Employees leave.
New security managers arrive.
The information has to survive those changes.
Protective intelligence is not a collection contest
More data is not automatically better.
I do not want a family office collecting everything about everyone simply because it can.
That creates privacy, legal and operational problems of its own.
Collect information that is relevant to the protective mission.
Preserve it appropriately.
Restrict access.
Review it intelligently.
And dispose of information according to the organization’s legal and retention requirements when it is no longer needed.
The objective is decision-quality information.
Not a giant database nobody can use.
Privacy is one of the first things I review when unwanted attention develops
If somebody appears interested in a principal or family, I want to know how difficult the family is to understand from outside.
Can someone identify the residence easily?
Are family travel plans posted publicly?
Do social-media photographs reveal vehicles?
Do posts reveal school locations?
Can someone identify household employees through professional profiles?
Do family members post their location in real time?
Can an observer identify normal departure times?
Can public calendars reveal future events?
Do vendors publicly identify the family as a client?
I am not trying to erase the family from the internet.
I am trying to remove information that makes unwanted attention easier to operationalize.
Predictability is often more important than secrecy
A family can be extremely private and still highly predictable.
Same departure time.
Same coffee shop.
Same gym.
Same school route.
Same vehicle.
Same restaurant every Friday.
Same dog walk.
Same gate.
Routine is normal.
People need routine.
I do not advocate randomizing life merely to make the protection program look sophisticated.
I want to identify predictable behaviors that create unnecessary exposure under the current threat picture.
If a routine does not create a meaningful vulnerability, leave it alone.
If circumstances change and that routine becomes useful to someone conducting unwanted observation, then we consider adjusting it.
Good protection should reduce disruption, not multiply it
One of the risks during a threat situation is that the protection program itself begins controlling the principal’s life.
Don’t go there.
Don’t attend that.
Don’t travel.
Don’t walk outside.
Don’t post anything.
Don’t let the children go anywhere.
Sometimes restrictions are necessary.
But the goal of protection is not to imprison the person we are protecting.
The objective is to reduce the risk enough that the principal can continue making choices.
That is an important part of what the Tapajós de Fato case illustrates.
When people become afraid to perform their normal work because they believe doing so may expose themselves or their families to violence, intimidation has affected their freedom of action.
For a protective professional, maintaining options is one of the central objectives.
Protective decisions should distinguish probability from consequence
Suppose we have an ambiguous observation that may have only a small probability of representing hostile surveillance.
That does not automatically mean we ignore it.
I also consider consequence.
If the observation relates to a highly exposed transition point involving the principal’s children, even relatively uncertain information may justify a modest precaution.
Maybe we improve observation.
Maybe we adjust pickup procedures temporarily.
Maybe we brief the driver.
That is very different from declaring an active threat.
Professional protection allows for proportionate action under uncertainty.
Escalation matters more than drama
I pay close attention to whether behavior is moving closer to the protected person.
An anonymous online comment is one thing.
Repeated direct messages are different.
Contacting the principal’s staff is different again.
Appearing near the residence changes the picture.
Appearing at multiple locations changes it further.
Attempting to gain access creates another level.
I do not need one spectacular event to recognize that the pattern is becoming more concerning.
The direction of travel matters.
Frequency matters, but so does specificity
Ten generic hostile messages may concern me less than one communication containing accurate nonpublic information about where the principal will be tomorrow.
Volume is easy to count.
Protective value comes from context.
Does the person know the residence?
Do they know family members?
Do they know an itinerary?
Have they demonstrated physical proximity?
Have they attempted to contact employees?
Have they identified vulnerabilities?
Specificity can change the assessment very quickly.
Movement across environments is especially important
A potential pattern becomes more significant when the same person, vehicle or behavior appears in environments that should not naturally overlap.
The residence.
The office.
A school.
A public event.
A hotel.
An airport.
A second residence.
If the same subject appears across multiple locations associated with the principal, that deserves immediate attention.
This is why executive protection, residential security and travel security cannot maintain separate information silos.
The residential team may have the earliest warning
Residential protectors spend long periods in one environment.
That gives them something valuable.
Baseline.
They know the street.
The neighbors.
The delivery patterns.
The service vehicles.
The dog walkers.
The normal traffic.
When something changes, they may notice before anyone else.
That makes residential reporting an important part of protective intelligence, not merely a record of visitors and packages.
The mobile detail sees a different part of the picture
The executive protection team may see things the residential team never encounters.
Repeated people at events.
Vehicles along movement routes.
Individuals near offices.
Unusual attempts to approach the principal.
Changes in crowd behavior.
Questions asked at hotels.
Activity around private aviation.
That information needs to come back into the same protective picture.
Executive assistants often receive early indicators nobody else sees
An assistant may receive:
unwanted emails;
strange meeting requests;
repeated calls;
unusual gifts;
messages from people claiming to know the principal;
requests for private contact information;
questions about travel;
or communications that gradually become more personal.
Those may be the earliest indicators of developing unwanted interest.
Assistants should know how to preserve and report them.
Drivers are often overlooked as intelligence collectors
Drivers spend substantial time observing the same routes and transition points.
They know what normally belongs there.
They may recognize a vehicle before a protector does.
They may see the same person near a pickup location.
They may be approached by somebody asking about the principal.
A good protection program treats that information as valuable.
Estate managers can see the vendor side of the picture
An estate manager may notice:
unexpected contractors;
unusual vendor questions;
attempts to obtain schedules;
repeat service calls that do not make sense;
or someone attempting to use the name of an employee to gain credibility.
Again, none of those observations automatically establishes hostile intent.
But they can contribute to the broader picture.
Digital and physical indicators increasingly overlap
Protective intelligence can no longer be limited to what happens physically around the principal.
An online message can reveal physical knowledge.
A compromised account can expose travel.
A social-media follower can begin appearing at events.
Someone may move from comments to direct messages to contacting staff to physical approaches.
The progression can cross digital and physical environments.
That means the people handling cyber, social-media and physical-security concerns need a way to communicate.
Public information can support unwanted observation
A person interested in a principal may not need sophisticated surveillance if the family tells the world where it will be.
Real-time social media.
Event announcements.
Flight tracking where applicable.
Public staff biographies.
Property records.
Tagged locations.
Photographs showing vehicle plates or entrances.
School information.
Foundation schedules.
Business calendars.
Each piece may be harmless alone.
Together, they can make the principal easier to understand.
Protective intelligence should influence the security posture
Information is not useful if it never changes anything.
If the pattern becomes more concerning, the program should be capable of scaling.
Additional residential coverage.
Additional executive protection.
More controlled arrivals.
Adjustments to public appearances.
Better privacy around schedules.
Law-enforcement liaison.
Temporary changes to routines.
Additional monitoring.
The response should match the behavior and vulnerability.
Not every concern requires every measure.
The team should also know when to step back down
Protection should not remain at crisis level indefinitely simply because a concerning event happened once.
Reassess.
What changed?
Has the behavior stopped?
Do we understand why?
Has the exposure been reduced?
Has law enforcement developed new information?
Did a temporary event end?
Can some measures now be relaxed?
A mature protection program can escalate and de-escalate without losing the underlying intelligence picture.
Law enforcement should receive useful information, not speculation
If circumstances justify reporting to law enforcement, factual documentation becomes extremely valuable.
Dates.
Times.
Messages.
Videos.
Vehicle information.
Repeated locations.
Specific statements.
That is far more useful than:
“We think somebody is after us.”
Protective personnel should help organize information so authorities can understand what actually occurred.
Do not turn the protective team into private detectives
There is a line.
The purpose of the protection team is to protect.
We document what occurs around the principal.
We evaluate relevance.
We preserve evidence.
We reduce vulnerability.
We coordinate with appropriate specialists and authorities.
We do not need to start following people around the city, confronting suspected observers or trying to prove criminal intent ourselves.
That can increase risk and create legal problems.
Good protective intelligence protects decision-making freedom
This is the part I think is most important.
The objective is not simply to collect information about threats.
The objective is to preserve the principal’s ability to make decisions.
Can the executive attend the meeting?
Can the family remain at the residence?
Can the children continue school normally?
Can the principal travel?
Can the journalist continue reporting?
Can the family appear publicly?
Can the household continue functioning?
A strong protection program should create options.
It should not automatically answer every risk with “stay home.”
The Tapajós de Fato decision shows what intimidation can ultimately accomplish
Tapajós de Fato’s decision not to conduct the election coverage it had planned is significant because the newsroom said the decision was driven by concern for the safety of journalists and their families.
I am not making a political judgment about the Brazilian election, the outlet’s reporting or the people it has covered.
From a protection standpoint, the case demonstrates the endpoint we are trying to avoid whenever possible:
the threat environment begins making decisions for the protected person.
Sometimes cancelling an activity is absolutely the correct security decision.
There are situations where the risk cannot be responsibly mitigated.
But a professional protection program should always ask whether there are practical ways to preserve the person’s freedom of action rather than simply surrendering it.
The broader pressure on journalists provides useful context
Current Brazilian press organizations have also reported substantial online hostility during the 2026 election period.
Abraji’s election monitoring reported approximately 4,400 online attacks against journalists between August 30 and September 12, a 67.3% increase from the previous monitored period. The project is monitoring online hostility toward journalists during the campaign; those online attacks are a different category from the physical incidents reported by Tapajós de Fato and should not be treated as evidence that the same actors are involved.
That distinction matters.
A hostile information environment can increase the number of concerning communications a protection team has to process.
It can create enormous noise.
Our job is to identify what, within that noise, has protective significance.
High volume makes triage more important, not less
A public figure may receive hundreds or thousands of negative messages.
Security cannot treat every one as equally significant.
I am looking for indicators that differentiate ordinary hostility from behavior that may require closer attention.
Specific knowledge.
Repeated direct contact.
Attempts to identify private locations.
Movement from online interaction to physical approach.
Contact with employees or family.
Attempts to bypass access controls.
Escalating persistence.
Those are the kinds of changes that deserve a more serious review.
What HNW families and family offices can do now
Create one reporting channel
Determine exactly where unusual contacts, sightings, questions and approaches should be reported.
Do not make employees guess.
Teach factual reporting
Train staff to describe what they observed rather than labeling what they think occurred.
Dates, times, locations, descriptions and exact statements are valuable.
Include the entire family in the assessment
If unwanted attention develops around the principal, consider whether the spouse, children or other family members have different vulnerabilities.
Include household staff
Household employees should know what information they should not disclose and where to report unusual questions or encounters.
Connect residential and executive protection reporting
A vehicle seen near the residence may matter when the same vehicle appears near an office.
Those observations have to meet somewhere.
Include executive assistants
Assistants often receive the first unusual communication.
Give them a simple reporting path.
Review privacy exposure
Look at what public information reveals about residences, schedules, family members, vehicles, staff and future travel.
Review predictable transition points
Arrivals and departures, school pickup, regular exercise, airports and recurring events may deserve additional attention when a threat picture changes.
Preserve relevant evidence
Messages, screenshots, video, access logs and factual observations may become important later.
Review camera retention
If an incident may be relevant, preserve footage before it is automatically overwritten.
Know when law enforcement becomes involved
Establish the reporting path before an urgent situation occurs.
Do not unnecessarily confront possible observers
Focus on protecting the principal, preserving information and coordinating appropriately.
Reassess periodically
A developing concern may increase or decrease over time.
The protection posture should be capable of doing the same.
How MSB Protection approaches protective intelligence
At MSB Protection, I consider protective intelligence part of the core protection operation.
It is not a separate product sitting in a report somewhere.
It informs executive protection.
It informs residential security.
It informs travel security.
It informs security assessments.
And it informs decisions about whether the protection posture needs to change.
I want to understand:
- what normal looks like;
- what has changed;
- what behavior has occurred;
- whether the behavior is repeating;
- whether it is becoming more specific;
- whether it is moving closer to the principal;
- whether family members or staff are being included;
- whether someone is attempting to obtain information;
- whether multiple locations are involved;
- and what vulnerabilities could be exploited if the behavior continues.
Then we make a decision.
Sometimes the answer is simply documentation.
Sometimes additional awareness.
Sometimes stronger residential measures.
Sometimes additional executive protection.
Sometimes privacy changes.
Sometimes law-enforcement coordination.
The measure follows the information.
That is what intelligence-led protection means to me.
Protective intelligence should never become paranoia
This deserves emphasis.
Protection professionals can do enormous damage when they begin interpreting every unusual event as hostile.
A person can look at a house without being a threat.
A vehicle can appear twice by coincidence.
Someone can ask an awkward question without malicious intent.
A social-media message can be unpleasant without presenting a physical-security concern.
The goal is disciplined awareness.
Not fear.
I want the team curious enough to notice.
Disciplined enough to document.
Analytical enough to compare.
And restrained enough not to invent conclusions unsupported by evidence.
Protective intelligence should also never become complacency
The opposite failure is equally dangerous.
“It is probably nothing.”
“That person has been around before.”
“The principal gets weird emails all the time.”
“Someone else probably reported it.”
“We don’t want to overreact.”
Each statement can sound reasonable.
Used repeatedly, they create a culture where important information disappears.
Professional protection occupies the space between paranoia and complacency.
Observe.
Document.
Assess.
Respond proportionately.
Frequently asked questions about protective intelligence
What is protective intelligence in executive protection?
Protective intelligence is the organized collection, comparison and assessment of information that may affect the safety of a protected person or family. In practical terms, it helps a protection team determine whether separate contacts, observations or incidents may be forming a meaningful pattern.
Does protective intelligence mean investigating people?
Not necessarily. Much of protective intelligence consists of organizing information already encountered through normal protective operations: messages, unusual approaches, repeated sightings, access attempts, reports from staff and changes in the environment. More specialized investigative work should be handled appropriately and lawfully by qualified personnel.
Does seeing the same vehicle twice mean somebody is conducting surveillance?
No. There can be many innocent explanations. I would document the observations and look for context, repetition and other related behavior before drawing conclusions.
What makes possible surveillance more concerning?
Repetition across multiple locations, attempts to conceal observation, unusual interest in the principal’s movements, questions about schedules, contact with staff, increasing proximity or other related behavior can change the assessment.
Should a protector confront someone suspected of surveillance?
Not automatically. The priority is the principal’s safety. Depending on the circumstances, documenting the activity, reducing exposure and coordinating with law enforcement may be more appropriate than direct confrontation.
Why should a driver report an unusual vehicle?
Because the driver may be seeing one part of a larger pattern. The same vehicle may have been noticed at the residence, office or another location. Security cannot make that connection if the observation is never reported.
Why should executive assistants be included in protective intelligence?
Assistants often receive unusual emails, calls, meeting requests, gifts or attempts to contact the principal. Those communications may contain early indicators that the physical-security team never sees directly.
Why should household staff report unusual questions?
Household employees may be approached because they appear easier to access than the principal. Questions about travel, occupancy, gates, schedules or family members can become relevant when viewed with other information.
Should every strange message be treated as a threat?
No. Most unusual messages will not represent a meaningful threat. The purpose of reporting is to make the information available for assessment, not to automatically classify the sender as dangerous.
What information should be recorded after a suspicious encounter?
Record the date, time, location, factual description of the person or vehicle, exactly what occurred, what was said and any available supporting information such as photographs, video or messages.
Why is exact wording important?
People naturally summarize or reinterpret conversations over time. Preserving the actual words used gives the protection team and, if necessary, law enforcement better information.
How long should security retain incident information?
That depends on the organization’s legal requirements, privacy obligations and protective needs. Relevant information should be retained long enough to allow patterns to be identified, but protective intelligence should not become uncontrolled collection with no retention policy.
What should happen to surveillance video after a potentially relevant incident?
If the video may be important, preserve it before the normal recording system overwrites it. The same principle applies to access logs, visitor records and other time-limited data.
Can online behavior become a physical-security concern?
Yes. Online communications may reveal knowledge of private information, attempts to contact employees, increasing fixation or a progression toward physical locations associated with the principal. Digital and physical reporting should therefore not operate in complete isolation.
Should families vary their routes and schedules?
Only where it solves a real problem. I do not believe in randomizing life for appearance’s sake. If a specific routine creates unnecessary exposure under the current threat picture, targeted changes may be appropriate.
Should a high-net-worth family stop posting on social media after receiving unwanted attention?
Not necessarily. The better question is what the posts reveal. Real-time location, travel plans, residence details, school information and predictable routines may deserve greater control without requiring the entire family to disappear from public life.
How does protective intelligence connect with residential security?
Residential personnel often have excellent baseline knowledge of the environment around an estate. Repeated vehicles, unusual pedestrian activity, gate inquiries and vendor behavior can provide early information that becomes more meaningful when combined with reports from elsewhere.
How does protective intelligence connect with executive protection?
The mobile detail sees the principal across offices, events, travel and public environments. Information from those locations should be compared with what residential personnel and the family office are seeing.
How does protective intelligence affect the level of protection?
Changes in behavior, proximity, specificity or exposure can justify increasing protection. If a concern later resolves or changes, the posture can also be reduced. Intelligence should inform the measures rather than measures remaining static forever.
Does an unknown threat actor mean the family cannot be protected effectively?
No. Attribution is useful, but many protective steps can be taken before identity or motive is known. The team can reduce exposure, strengthen access control, adjust vulnerable routines, preserve information and coordinate with law enforcement.
Why does family exposure matter if the principal is the person receiving threats?
Because a spouse, child or employee may have different routines and less protection. Someone seeking access to or leverage over the principal may attempt to reach the people around them instead.
Should children be told about every threat?
No universal answer applies, but I generally want the adults and professionals carrying as much of the protective burden as possible. Children should receive only the information and guidance appropriate to their age and circumstances.
When should law enforcement be contacted?
Threats, stalking, unlawful entry, violence, property damage, suspicious approaches or other potential criminal behavior may warrant law-enforcement involvement depending on the circumstances and jurisdiction. The protection team should have an established liaison and reporting process rather than inventing one in the middle of an incident.
What happened to Tapajós de Fato?
Tapajós de Fato is an independent outlet in Santarém, Pará. In 2026 it decided not to conduct the systematic election coverage it had been planning because members of its team said years of threats and violence had created unacceptable risks to journalists and their families. Agência Pública, Abraji, FENAJ, Folha de S.Paulo and The Guardian have all reported on the decision and associated incidents.
Who was responsible for the threats against Tapajós de Fato?
The public reporting reviewed for this article does not establish a single person, political party, business, criminal organization or other actor as responsible for all of the reported incidents. It would therefore be inappropriate to attribute them beyond what investigators or credible reporting establishes.
Were all of the reported incidents connected?
That has not been publicly established. The incidents form part of the outlet’s reported history of intimidation, but similarity or timing does not prove that the same actor was responsible for each event.
Why is the Tapajós de Fato case relevant to UHNW security?
The relevance is the protective problem rather than the profession of the people involved. Repeated unwanted attention, ambiguous surveillance concerns, intimidation affecting family members and fragmented information can occur around executives, public figures and wealthy families as well. The same disciplined approach to documentation, pattern recognition, privacy and proportional protection applies.
Final thoughts: somebody has to connect the pieces
The most important lesson I take from the Tapajós de Fato case is not about Brazilian politics.
It is not about assigning blame.
And it is not about assuming every ambiguous incident is part of a coordinated threat.
It is about what happens when concerning events accumulate around a person and the people close to them.
One event can be dismissed.
One strange vehicle.
One unusual message.
One person asking questions.
One uncomfortable encounter.
Each may have an innocent explanation.
Sometimes they do.
But a professional protection program cannot evaluate every event in isolation forever.
The residential protector sees one piece.
The driver sees another.
The assistant receives another.
The spouse experiences another.
The estate manager hears something else.
The executive protection team notices someone at an event.
If all of that information remains in separate people’s heads, there is no protective-intelligence program.
There are only observations.
Somebody has to connect them.
That is what protective intelligence does.
It does not turn uncertainty into certainty.
It does not turn suspicious behavior into guilt.
It does not replace law enforcement.
It does not require paranoia.
It gives the protection team a disciplined way to understand whether the environment around the principal is changing.
And when it is changing, it gives us the opportunity to act before the family loses options.
That is why I consider protective intelligence inseparable from executive protection, residential security, travel security and security assessment.
The objective is not to treat everything as a threat.
The objective is to make sure a real threat does not disappear in plain sight because every person around the principal saw only one piece of it.
Sources
About Michael Braun
Michael Braun is a former Special Unit Operator, former Manager at Gavin de Becker & Associates, and Founder & CEO of MSB Protection, an executive protection and residential security firm serving high-net-worth and ultra-high-net-worth clients.
Braun has built his career at the intersection of specialized protective operations, executive protection, residential security, protective intelligence, and security risk management. His experience spans special-unit operations, leadership within Gavin de Becker & Associates, and the development and oversight of private protection programs within demanding UHNW environments.
He has been recognized by The Top 100 Magazine as a leading CEO in the private security field and is the subject of an upcoming Marquis Who’s Who feature highlighting his leadership and contributions to the profession.
Today, Braun is recognized for his work in executive protection, UHNW estate security, residential protection, protective intelligence, adversarial security assessments, and security auditing throughout Beverly Hills and Southern California.
His work focuses on moving private security beyond simply “providing a body” and toward intelligence-led, risk-based protection programs designed to identify vulnerabilities before an adversary can exploit them.
Looking for Executive Protection or Residential Security Services?
If you are a high-net-worth or ultra-high-net-worth individual, family office, estate manager, chief of staff, or executive in Beverly Hills, Los Angeles, Malibu or Southern California, MSB Protection provides executive protection, residential security, 24/7 protection, protective intelligence, medical-readiness planning, and security risk management.
We evaluate the complete security environment, from threat exposure and residential vulnerabilities to personnel, technology, procedures, protective intelligence, and emergency response, and build a program around the risks that actually exist.
Contact us for a confidential consultation or message us at +1 (805) 285-2807.