UHNW Protective Intelligence From Online to Physical
Protective intelligence is not just monitoring what people say about a principal online.
The part I care about is what happens next.
Does somebody remain an anonymous account posting criticism?
Do they begin contacting the principal directly?
Do they start messaging employees?
Do they identify the family?
Do they locate the residence?
Do they ask questions about travel?
Do they show up at an event?
Do they appear at the gate?
That movement from digital interest toward physical access is where protective intelligence becomes especially important.
For a UHNW principal, public figure or highly visible executive, the internet can reduce the amount of work required to move from a name to a real-world location.
A person may find a business biography in one place, relatives through a people-search service, property history somewhere else, photographs on social media, an event appearance on another website and an employee profile on LinkedIn.
No single piece needs to be especially sensitive.
Combined, the information may reveal:
where the principal lives;
which properties are connected to the family;
who works for them;
which vehicles appear regularly;
where the family travels;
which charities or events they attend;
and where an interested person might have an opportunity to approach them.
That is why I separate privacy from protective intelligence.
Privacy tries to reduce unnecessary exposure.
Protective intelligence assumes some exposure will remain and looks for behavior around it.
You need both.
In California, there is also a significant new tool available in 2026.
The California Privacy Protection Agency launched the Delete Request and Opt-out Platform, or DROP, on January 1. California residents can now submit one deletion request covering more than 600 registered data brokers. Beginning August 1, 2026, data brokers became required to retrieve and process those requests at least once every 45 days. CalPrivacy reported in July that more than 325,000 consumers had already submitted requests.
That is useful.
It is not a complete security solution.
A principal can reduce the amount of information circulating through data brokers and still remain identifiable through public records, social media, company websites, relatives, employees, event publicity and old information that has already been copied elsewhere.
The real protective problem is therefore not:
“Can we make the principal disappear?”
Usually we cannot.
The better question is:
Can we reduce unnecessary exposure and recognize quickly when someone is using the remaining information to move closer to the principal?

Key takeaways
- Protective intelligence should track movement from information to access. The important change is often not what somebody says online but whether their behavior begins moving closer to the principal.
- Privacy reduction and threat detection are different functions. Removing personal data can reduce exposure, but it does not replace monitoring and case management.
- California residents now have a significant data-broker removal tool. DROP sends one deletion request to more than 600 registered data brokers, which must process requests on a recurring cycle.
- Data removal does not erase public records. Property records, relatives, business records and other public information may remain available.
- Third parties expand the principal’s exposure. Family members, assistants, staff, vendors, charities and event organizers can unintentionally reveal information the principal never posted.
- Behavior matters more than anger. Persistent information seeking, boundary violations, repeated approaches and movement toward physical proximity usually matter more than whether a social-media post sounds hostile.
- One reporting system is critical. Online messages, gate incidents, event approaches and staff contacts should be capable of being connected to the same person or case.
- Preserve original evidence. The FBI advises recipients of electronic threats not to delete them and to preserve message details and electronic evidence.
- Doxxing should trigger a physical-security review. Once home or family information is deliberately circulated, the residence, travel and upcoming public exposure may need reassessment.
- Historical records matter. A person who reappears six months later should not look like a brand-new contact because earlier reports were discarded.
- Not every unusual contact is a threat. Protective intelligence needs context, corroboration and professional judgment rather than automatically escalating every critic or fan.
- The response should remain proportionate. Good intelligence reduces unnecessary protective measures as well as identifying when more protection is justified.
The internet creates an exposure chain
I do not think about online exposure as one giant database containing the family’s entire life.
Usually it is fragmented.
One source provides an address.
Another provides a spouse’s name.
Another identifies an assistant.
Another shows a vehicle.
Another shows where the family spent last weekend.
Another lists a charity event next Thursday.
Another identifies a company office.
The person collecting the information connects it.
A name can become a location faster than people realize
The Federal Trade Commission explains that people-search services can combine information purchased from other data brokers, public social-media information and government records.
A search beginning with one item such as a name or telephone number may return current and previous addresses, property history, employment information and names and addresses of relatives.
For a protection team, that changes how I think about the principal’s exposure.
The home address may not be posted on Instagram.
It may not need to be.
The exposure map should start with the principal
I want to understand what a normal person using ordinary public resources can establish.
Full name.
Aliases or prior names.
Professional entities.
Properties.
Telephone numbers.
Email addresses.
Family connections.
Public boards.
Charities.
Aircraft or vehicle associations where publicly available.
Upcoming appearances.
Social accounts.
Then I look outward.
The principal is only the center of the exposure map
Spouse.
Children, with very strict limits on unnecessary collection.
Executive assistant.
Chief of staff.
Family office.
Estate manager.
Public-facing employees.
Business entities.
Charitable organizations.
Other people who publicly connect themselves to the principal.
The point is not to build dossiers on everyone around the family.
The point is to understand obvious paths through which information about the principal becomes visible.
Employees can unintentionally identify a residence
A household employee posts:
“Another beautiful day at work.”
The photograph shows:
a distinctive house;
street geography;
a gate;
vehicle;
or recognizable view.
The principal never posted anything.
The residence may still be identifiable.
Vendors create the same issue
Pool company.
Interior designer.
Architect.
Landscape contractor.
Luxury-car detailer.
Caterer.
Photographer.
Real-estate agent.
A vendor may legitimately want to showcase its work.
The family may not want the property publicly associated with the principal.
That should be addressed contractually and operationally before content appears online.
Event organizers can publish future location information
“Join us Thursday evening with our special guest.”
For marketing, that may be valuable.
For protective planning, it means the location and timing are no longer private.
The executive protection team should know.
Exposure reviews should ask what is actionable
I am not interested in producing a hundred-page list of everything ever written about the principal.
I want to know what somebody could use.
Current residence?
Current phone?
Children’s recurring location?
Upcoming event?
Travel pattern?
Private employee contact information?
Vehicle association?
Home layout?
Security detail?
That helps prioritize removal and mitigation.
California DROP changed the data-broker landscape in 2026
For California-based UHNW families, this deserves specific attention.
The Delete Act created a statewide mechanism allowing consumers to submit one request directing registered data brokers to delete covered personal information.
DROP opened to consumers January 1, 2026.
Starting August 1, registered brokers became required to access the system and process deletion requests at least once every 45 days.
As of October 2026, that processing requirement is active.
Consumers can also check the status of their request through the system, although CalPrivacy warns that updates can take up to 90 days depending on data-broker workflows.
DROP is much broader than manually opting out site by site
CalPrivacy says one DROP request currently goes to more than 600 active registered data brokers.
That is important because manually removing a principal from individual brokers can become a permanent game of whack-a-mole.
CalPrivacy’s system is specifically designed to make the deletion request persistent.
If a data broker cannot match a consumer initially, it still has ongoing obligations around the request rather than requiring the consumer to start over every time new information appears.
A DROP request should now be part of a California exposure-reduction program
For eligible California principals, I would consider it a basic administrative privacy step.
It is free.
It is centralized.
It addresses a category of commercial data aggregation that previously required many separate opt-out requests.
But I would still continue exposure reviews.
DROP does not delete government public records
This distinction is important.
The FTC notes that opting out of people-search services does not remove information from government public records.
Information can also remain visible through relatives, neighbors or associates and may reappear if underlying public records change.
Privacy reduction is therefore maintenance.
Not disappearance.
A family should review what is actually deleted
Do not simply submit a request and assume the problem is solved.
Search again later.
Look at major people-search results.
Check old telephone numbers.
Check prior addresses.
Check relatives.
Check entities connected to the residence.
The California system can reduce exposure significantly without eliminating every route back to the principal.
New identifiers should be added when appropriate
CalPrivacy says consumers can update a DROP profile with changes such as a new email address, telephone number, vehicle identification number or other identifiers that may improve matching with broker records.
That makes privacy reduction an ongoing process rather than a one-time project.
Do not provide more personal information to random removal sites than necessary
This is another practical consideration.
People sometimes become so focused on removal that they begin sending identification documents and personal data to dozens of questionable websites.
Use legitimate processes.
Understand what a service is requesting.
Do not create a new privacy problem while trying to solve the old one.
Social media creates a different type of exposure
Data brokers tell somebody who you are.
Social media may tell them what you are doing right now.
That difference matters.
Real-time posting is especially useful to someone trying to locate a principal
“Dinner at…”
“Headed to…”
“Back in Malibu.”
“Vacation starts now.”
“Kids first day at…”
Those posts may seem completely normal.
They can also remove uncertainty.
Delayed posting reduces real-time value
A family does not necessarily need to stop using social media.
Posting photographs after leaving a location can reduce the immediate operational value of the information.
That is a simple adjustment.
Location data can be embedded indirectly
Landmark.
Restaurant.
Hotel pool.
Distinctive mountain view.
Vehicle registration sticker.
School logo.
Street sign.
House number reflected in a window.
A photograph can disclose location without a geotag.
CISA specifically treats doxxing as a personal-safety issue
CISA defines doxxing as gathering personally identifiable or sensitive information from open or compromised sources and publicly releasing or using it for malicious purposes.
Its personal-security guidance warns that online information can be used to build a picture of relationships and locations and specifically recommends limiting unnecessary personal information, reviewing app permissions and considering data-broker opt-outs.
That is exactly how I view it operationally.
Doxxing changes the protective picture when actionable information appears
There is a difference between:
someone posting the principal’s corporate biography
and
someone publishing the home address together with the spouse’s name, telephone number and photographs of the gate.
The second scenario deserves an immediate security review.
The first question is what was exposed
Capture exactly what was published.
Address?
Phone?
Email?
Children?
Family?
Employee information?
Gate photograph?
Travel?
Vehicle?
Security procedure?
Do not simply write:
“Principal was doxxed.”
That is not enough information to manage the risk.
The second question is how widely it is spreading
One obscure post.
Large social account.
Multiple reposts.
Forum discussion.
News coverage.
Direct calls for people to go to the property.
Those are different conditions.
The third question is whether anybody is acting on it
Increase in drive-bys?
Unknown visitors?
Deliveries the family did not order?
Harassing calls?
People photographing the property?
Attempts to contact employees?
Threats?
That is where online exposure begins crossing into physical protective intelligence.
Doxxing response should connect four functions
Privacy.
Protective intelligence.
Residential security.
Executive protection.
Removing the post but failing to notify the gate is incomplete.
Putting an extra guard at the residence but never trying to remove the exposed data is also incomplete.
Document the doxxing before removal
CISA recommends documenting the incident, taking screenshots, determining what information was exploited and working with the relevant platforms or site administrators to remove it.
That sequence matters.
Capture evidence.
Then work on removal.
Do not accidentally amplify the information internally
This happens easily.
Someone screenshots the doxxing page.
Sends it to twenty employees.
Now twenty more devices contain the family’s private information.
Need-to-know still applies during an incident.
Protective intelligence should focus on behavior, not vocabulary
I do not automatically treat the angriest person online as the biggest concern.
Language matters.
Behavior matters more.
A person can write something offensive every day and never attempt physical contact.
Another person may write politely while steadily trying to get closer to the principal.
The second person may deserve more attention.
What I look for is change
Frequency changes.
Channel changes.
Content changes.
Proximity changes.
Information-seeking changes.
Boundary behavior changes.
That tells me whether the situation is moving.
Repeated direct contact matters differently from general public commentary
A person posts about a CEO on X.
That may be ordinary public discussion.
The same person then:
messages the CEO;
emails the assistant;
calls the office;
contacts the spouse;
and sends something to the residence.
Now I am looking at a contact pattern.
Third-party contact is important
Someone cannot reach the principal.
They contact:
assistant;
employee;
spouse;
friend;
charity;
event organizer;
security officer;
or family office.
That can indicate persistence.
It may also create a new information path.
Information seeking is more important when it becomes specific
“Where does she live?”
“What entrance does he use?”
“What time does he normally arrive?”
“Which school do the kids attend?”
“Who is his driver?”
“Is the family home?”
“Which hotel are they at?”
The context matters.
Repeated attempts to obtain operational information deserve documentation.
Boundary violations matter
The principal does not respond.
The person continues.
An assistant asks them to stop.
They continue.
Security denies access at an event.
They attempt another entrance.
That tells me more than one unpleasant social-media comment.
Claims of a nonexistent relationship deserve context
“He knows me.”
“She is expecting me.”
“We communicate privately.”
“I am part of the family.”
Sometimes it is confusion.
Sometimes it is deception.
The claim itself is not enough to determine risk.
Repeated behavior built around an invented relationship is more relevant.
Movement from online to physical is a major change
This is the central point of the article.
A person exists only online.
Then they appear at a public event.
Then near the office.
Then at the residence.
That geographic movement should change the assessment.
The content of their posts may be exactly the same.
The behavior is not.
Repeated appearances require context
A public figure may legitimately see the same fan at several public events.
A business executive may see the same activist at several demonstrations.
That alone does not establish hostile intent.
But repeated appearances combined with attempts to bypass access, obtain personal information or contact the family create a different picture.
Do not make security personnel amateur psychologists
I do not need a residential protector diagnosing someone at the gate.
I want facts.
Person arrived at 2:14 p.m.
Asked for principal by name.
Stated principal was expecting them.
Could not provide appointment.
Asked whether principal was home.
Left when denied entry.
Vehicle description.
Direction of departure.
That is useful.
Facts survive handovers better than labels
“Crazy guy came to gate.”
Not useful.
“Suspicious female.”
Not enough.
“Stalker.”
That may be legally and operationally premature.
Describe what happened.
One central case record changes everything
The assistant should not have an email folder.
The gate should not have a separate notebook.
The executive protection team should not have another independent group chat.
And the family office should not have a spreadsheet nobody else knows exists.
Relevant incidents need a path into one protected case system.
What should be captured?
Date and time.
Channel.
Recipient.
Username or identifier.
Email or phone where relevant.
Exact wording where important.
Screenshot or original message.
Physical location if an approach occurred.
What the person asked for.
What staff did.
Whether prior incidents may involve the same person.
Law-enforcement information if a report was made.
Do not overcollect irrelevant personal information
The point is protection.
Not curiosity.
Collect information legitimately relevant to:
identity;
behavior;
contact;
threat;
and access.
Do not turn protective intelligence into an excuse for unnecessary intrusion.
Identifiers help connect incidents
Username.
Email.
Telephone number.
Vehicle.
Repeated phrase.
Photograph.
Address used for mailed items.
Those may show that several apparently unrelated contacts involve the same person.
Historical reports should remain searchable
Person stops contacting the principal for nine months.
Then returns.
I want the analyst or protection lead to see the history.
Not treat the new email as first contact.
The FBI has seen the value of pattern information in cyberstalking cases
In one FBI cyberstalking case, investigators found that other victims had previously filed similar police complaints involving the same person. Those earlier reports helped reveal a broader behavioral pattern.
That is one reason disciplined historical reporting matters.
Preserve electronic threats correctly
If a concerning message crosses into an actual threat, evidence handling matters.
The FBI advises recipients of electronic threats not to delete the message, to preserve the original electronic evidence, and to capture details including sender, subject line, date and time.
That is simple guidance worth building into family-office procedure.
A screenshot is helpful but should not automatically replace the original
Keep the original message where possible.
Screenshot the visible content.
Record the account or number.
Preserve any relevant link or platform information internally.
Do not forward the threat around unnecessarily.
Do not engage an unknown threatening person just to obtain more intelligence
This is an important boundary.
Protective staff should not bait, provoke or unnecessarily continue contact with somebody who may represent a threat.
If engagement is necessary, that decision should be deliberate and coordinated with qualified professionals or law enforcement when appropriate.
Blocking should be coordinated with evidence preservation
Sometimes blocking is the correct step.
Capture what you need first.
Then make the decision.
Do not delete the entire history in the process.
Law enforcement should not first hear about the case after a physical incident
Not every concerning contact needs a police report.
A credible threat, serious harassment, repeated unwanted physical approach or other significant conduct may justify early liaison.
That decision depends on the circumstances.
Immediate danger is different
If there is an immediate threat to life or an active emergency, call 911.
The FBI’s threat guidance likewise directs people facing threats to local law enforcement and emphasizes preserving evidence.
Protective intelligence needs escalation criteria
I do not like simplistic scoring systems that imply human behavior can be reduced to one number.
I do want defined triggers for review.
For example:
Ordinary attention
Public comments.
Normal criticism.
Fan mail.
Routine media attention.
No security change.
Persistent unwanted contact
Repeated direct messages.
Multiple channels.
Continued contact after boundaries are established.
Document and assess.
Information-seeking behavior
Questions about residence.
Children.
Travel.
Drivers.
Security.
Increase attention and correlate reports.
Third-party expansion
Contact shifts toward assistants, family, vendors or employees.
Review the broader exposure picture.
Physical approach
Appearance at residence, workplace, hotel, private event or another relevant location.
Reassess immediately.
Repeated or escalating physical behavior
Multiple appearances.
Attempts to bypass access.
Following movements.
Surveillance concerns.
Escalate protection and law-enforcement coordination as circumstances justify.
Threat or immediate danger
Preserve evidence.
Notify law enforcement.
Adjust physical protection immediately based on the actual circumstances.
The categories are not a mechanical formula
A single communication can be serious.
Twenty communications can be harmless.
Context always matters.
The purpose of escalation criteria is to prevent important behavioral changes from being dismissed because nobody made an explicit threat.
The residential team should receive actionable intelligence
Not the entire online case file.
If a person may approach the residence, the residential security team may need:
name;
photograph where lawfully available;
known vehicle;
known behavior;
and clear instructions.
For example:
Do not provide information.
Do not confirm whether principal is home.
Deny unauthorized access.
Notify supervisor.
Document the encounter.
Contact law enforcement if specified behavior occurs.
Do not dump raw intelligence on gate personnel
A forty-page analyst report does not help an officer working an entrance.
Give them what changes their action.
The executive protection team needs the same case picture
If the person has appeared at:
office;
public event;
hotel;
or residence,
the mobile team should know before the next movement.
An upcoming event can change the significance of online activity
Someone has spent weeks posting about the principal.
Tomorrow, the principal attends a publicly advertised event.
The protection team should examine whether there is any evidence the individual knows about the event or intends to attend.
Do not wait for the person to arrive at the door.
Travel changes the physical environment
A person knows the principal is staying at a particular hotel.
The home detail may be irrelevant for that period.
The travel security team now needs the information.
Protective intelligence should follow the principal.
Family exposure needs its own review
If somebody cannot reach the principal, they may shift attention.
Spouse.
Children.
Assistant.
Sibling.
Business partner.
That does not mean every associated person requires a protection detail.
It means the team should notice target broadening when it occurs.
Children should not be unnecessarily drawn into intelligence operations
Protect their information.
Give schools or caregivers appropriate instructions when a legitimate concern exists.
Do not frighten children with adult threat information they do not need.
Security should support normal life.
Staff should receive need-to-know information too
A nanny may need to know:
do not release information;
call this number if approached;
report photographs or repeated contact.
They may not need the entire history of the subject.
Protective intelligence can reduce security as well as increase it
This is important.
Suppose a principal receives one disturbing message.
The team assesses it.
No repetition.
No identified subject.
No approach behavior.
No continued interest.
Months pass.
The protective posture may remain normal.
Good intelligence should prevent fear-driven overreaction.
Do not confuse visibility with threat
A CEO becomes controversial.
Thousands of negative posts appear.
Volume alone does not tell me whether one person is moving toward harmful action.
I want to separate noise from behavior.
Protective intelligence should identify the small number of contacts that deserve attention
That is where automation and structured reporting can help.
But human review still matters.
Keyword counts do not understand context well enough to make final protective decisions by themselves.
AI tools can assist triage without becoming the decision-maker
A large public figure may receive thousands of mentions.
Technology can help identify:
repeated usernames;
direct mentions;
address references;
family references;
certain threat language;
or sudden increases in activity.
Then a qualified person reviews the underlying information.
False positives need to be expected
Sarcasm.
Quoting news.
Song lyrics.
Political rhetoric.
Common names.
AI-generated content.
Automation will get things wrong.
That is why protective intelligence cannot simply become:
“Software flagged it, therefore threat.”
Identity correlation also requires caution
The same username may belong to different people across platforms.
Names can be duplicated.
Profile photos can be stolen.
People impersonate others.
Do not label somebody as a person of concern based on weak identity matching.
Confidence should be stated
Confirmed same person.
Likely.
Possible.
Unknown.
That is much better than pretending certainty.
Protective intelligence should remain lawful
Use legitimate information sources.
Do not hack accounts.
Do not obtain restricted data through deception.
Do not harass people.
Do not manufacture contact simply to see what somebody will do.
The objective is protection.
Protective intelligence is not counter-harassment
Someone criticizes the principal.
Security does not attack them online.
Someone posts an offensive opinion.
Security does not try to intimidate them.
Focus on relevant conduct.
The principal’s critics are not automatically security subjects
This matters especially for:
politicians;
public executives;
media personalities;
activists;
and controversial business leaders.
Legitimate speech can be aggressive.
Protective intelligence should not become a mechanism for monitoring lawful opposition merely because somebody dislikes the principal.
Privacy reviews should include staff social media
Not by secretly policing employees’ personal lives.
By setting clear expectations around confidential family information.
Do not post:
family location;
children;
residence interiors;
gate codes;
principal schedule;
security procedures;
or identifiable travel information obtained through work.
Vendor contracts can address publicity
Photography.
Portfolio use.
Social posts.
Property name.
Client identity.
Location.
The expectations should be clear.
Family members need practical rules rather than impossible secrecy
I would rather have three rules everybody follows than thirty nobody remembers.
For example:
- avoid real-time location posting when privacy matters;
- do not publish private residential information;
- report unusual direct contact rather than engaging with it repeatedly.
Build an online-exposure baseline before a crisis
Search the principal now.
Not after a doxxing incident.
Document what is already public.
Then when something new appears, you can identify the change.
Baseline matters for social behavior too
A well-known principal always receives hundreds of negative messages.
That is baseline.
A sudden cluster naming the home address is not.
A previously unknown account begins sending family photographs.
Not baseline.
Someone publishes an upcoming private itinerary.
Not baseline.
Protective intelligence is ultimately change detection
What is normal?
What changed?
Does the change affect access?
That is the practical logic.
How MSB Protection approaches online protective intelligence
At MSB Protection, I do not view protective intelligence as collecting as much information as possible.
I want information that changes a protective decision.
I start with the principal’s real exposure.
What is already online?
What can be removed?
What cannot realistically be removed?
Who around the family increases that exposure?
Then I look at behavior.
Who is contacting the principal?
Is contact persistent?
Is somebody trying to obtain information?
Are they contacting third parties?
Have they moved from digital contact toward physical proximity?
Have they violated established boundaries?
Has their behavior changed?
Then I connect those findings to the actual protection program.
If the issue affects the residence, residential security needs relevant information.
If it affects movement, the executive protection team needs it.
If it affects travel, travel security needs it.
If family-office information is leaking, that process needs review.
A broader security assessment can then examine how the digital and physical layers connect.
I do not want intelligence sitting in a report nobody operationalizes.
The protective decision should always be explicit
After reviewing concerning information, ask:
What changes?
Nothing?
Continue monitoring?
Notify residential security?
Brief the mobile team?
Adjust an upcoming event?
Remove exposed information?
Contact law enforcement?
Temporarily increase coverage?
If the assessment produces no decision, it may simply be information collection.
What families and family offices can do now
Submit a California DROP request where eligible
California residents can now use one request to seek deletion across more than 600 registered data brokers. Processing has been mandatory for brokers since August 1, 2026.
Save the DROP identification information
CalPrivacy allows consumers to return and check the status of requests.
Understand the limits of DROP
It does not erase government public records or information published by unrelated third parties.
Search major people-search results
Look at what appears for:
principal;
spouse;
phone number;
current address;
prior addresses.
Repeat the review periodically
The FTC warns that information can reappear even after individual people-search opt-outs.
Review principal social media
Current location.
Family details.
Residences.
Vehicles.
Upcoming events.
Review family-member exposure
Do not focus only on the principal.
Set household social-media expectations
Simple, practical and realistic.
Address staff confidentiality
Especially residential location, travel and family schedules.
Address vendor photography and publicity
Particularly designers, builders, event companies and household vendors.
Establish one reporting channel
Email.
Gate contact.
Unusual direct message.
Repeated event appearance.
All should have somewhere to go.
Preserve historical reports
Do not erase them just because contact stops temporarily.
Preserve electronic threats
Do not delete original messages. Capture identifying details and preserve evidence consistent with FBI guidance.
Document doxxing before seeking removal
Take screenshots and identify exactly what information was exposed.
Notify residential security when a home address is exposed
Give actionable information, not internet gossip.
Review upcoming public appearances
Especially if concerning online behavior references the event.
Look for movement between channels
Public comment to direct message.
Direct message to staff contact.
Staff contact to physical appearance.
Look for repeated information seeking
Home.
Schedule.
Family.
Driver.
Hotel.
Record facts rather than labels
Behavior is more useful than opinions about the person.
Define escalation criteria
Persistent contact.
Boundary violations.
Physical appearance.
Threats.
Make law-enforcement liaison available before a crisis
Know who the protection lead should call when circumstances justify it.
Do not let raw intelligence spread unnecessarily
Sensitive reports should remain need-to-know.
Frequently asked questions
What is protective intelligence for a UHNW principal?
Protective intelligence is the process of collecting, connecting and assessing information that may affect the safety of a protected individual. The important part is not simply monitoring information but determining whether behavior or exposure changes the protection requirement.
How is protective intelligence different from OSINT?
OSINT refers broadly to information gathered from publicly available sources. Protective intelligence uses relevant information, including but not limited to open sources, to support decisions about a specific person’s safety.
Does protective intelligence mean monitoring everyone who criticizes the principal?
No. Criticism, protest and negative commentary are not automatically security matters. Protective intelligence should focus on relevant conduct such as persistent unwanted contact, information seeking, boundary violations, threats and movement toward physical access.
What is the most important online-to-physical warning sign?
There is no single universal indicator, but movement from online contact into real-world proximity is a significant change that should normally trigger reassessment.
Does somebody need to make a direct threat before security should act?
No. A direct threat may be important, but repeated approaches, information seeking, boundary violations or physical appearances can justify review even without an explicit threat.
What is doxxing?
CISA describes doxxing as gathering personally identifiable or sensitive information from open or compromised sources and publishing or using it maliciously.
What should happen when a principal is doxxed?
Document what was published, determine how widely it is spreading, preserve evidence, pursue appropriate removal, assess whether people are acting on the information and notify relevant physical-protection personnel.
Should a doxxing incident automatically result in 24/7 security?
No. The response depends on what information was exposed, the principal’s existing risk profile, the reach of the disclosure and whether there is concerning behavior connected to it.
What is California DROP?
DROP is the California Privacy Protection Agency’s Delete Request and Opt-out Platform. It allows California residents to submit one request asking registered data brokers to delete and stop selling covered personal information.
How many data brokers does DROP cover?
CalPrivacy states that a DROP request currently goes to more than 600 active registered data brokers.
When did DROP begin?
California consumers were able to begin submitting requests on January 1, 2026. Data brokers became required to process requests starting August 1, 2026.
How often must data brokers process DROP requests?
Registered brokers must access and process the system at least once every 45 days.
Does DROP immediately remove everything online?
No. Status updates can take time, and DROP applies to covered data-broker information rather than every public record, website or social-media post.
Does opting out of people-search sites remove property records?
No. The FTC specifically notes that people-search opt-outs do not delete underlying government public records.
Can information return after removal?
Yes. The FTC warns that people-search information may reappear as public records change or through information associated with relatives, neighbors and other sources.
Should data-broker removal be done once or repeatedly?
Treat it as maintenance. California DROP adds ongoing deletion obligations for participating registered brokers, but broader exposure reviews should still be repeated because other sources can change.
Should a principal stop using social media?
Not necessarily. The appropriate approach depends on the family. Delayed posting, limiting unnecessary location information and avoiding publication of sensitive residential details can reduce exposure without eliminating normal use.
Should family members also be reviewed?
Yes where appropriate, because relatives can unintentionally reveal residences, travel or relationships that connect back to the principal. The review should remain proportionate and respectful of privacy.
Should household staff be monitored online?
The goal should not be intrusive surveillance of employees’ personal lives. Staff should have clear confidentiality expectations regarding private information learned through employment.
Should vendors be allowed to photograph a UHNW residence?
That should be a deliberate client decision. Contractors, designers, photographers and event companies may want portfolio or promotional content, but the family’s privacy expectations should be established before publication.
What should a security officer write after an unusual gate encounter?
Record objective facts: time, appearance, stated reason for being there, questions asked, actions taken, vehicle information where relevant and how the encounter ended. Avoid unsupported labels or diagnoses.
Why is a central incident log important?
Because different parts of the protection system may encounter the same person at different times. Centralized reporting allows apparently unrelated incidents to be compared.
How long should protective-intelligence reports be retained?
There is no universal retention period. Retention should reflect legitimate security needs, applicable privacy and legal requirements and organizational policy. The important point is not to delete relevant historical information so quickly that recurring behavior cannot be recognized.
Should every strange message become a protective-intelligence case?
No. Programs can triage routine noise while ensuring unusual or concerning behavior can be elevated and preserved.
Should security respond directly to someone making concerning online posts?
Usually not casually. Unnecessary engagement can complicate the situation. If contact is required, it should be a deliberate decision made by the appropriate security, legal or law-enforcement function.
What should staff do with an electronic threat?
The FBI advises not deleting the message, preserving the electronic evidence and recording details such as sender, date, time and subject information before notifying appropriate law enforcement.
Should screenshots be taken?
Yes, especially for content that might be deleted or changed, but preserve the original message or content where possible as well.
Should a threatening post be forwarded around the family office?
No more than necessary. Preserve and route it to the people responsible for assessing it without unnecessarily expanding distribution of threatening or private material.
What makes repeated contact more concerning?
Factors can include increasing frequency, movement across communication channels, repeated boundary violations, attempts to contact third parties, specific information seeking and physical approaches.
Is a person who attends several public events automatically stalking the principal?
No. Public figures can have repeat fans, activists, journalists and critics. Context matters, including what the person does, whether boundaries are respected and whether behavior expands toward private locations or information.
Why does third-party contact matter?
Someone unable to reach the principal directly may contact employees, relatives, vendors or event personnel. Repeated attempts through those alternate channels can reveal persistence and may also expose additional information.
Should residential security receive online intelligence?
Only when it is operationally relevant. If a person may approach the residence, the team should receive enough information to identify the concern and respond correctly without receiving unnecessary case details.
Should executive protection receive the same information?
When the behavior may affect the principal during travel, events or daily movements, yes. Intelligence should follow the principal instead of remaining trapped at the residence.
How should online exposure be handled before a public appearance?
Review whether concerning individuals have referenced the event, venue, timing or travel and brief the protection team on any relevant changes before the principal arrives.
Can automated tools identify threats?
They can assist with triage, pattern detection and large-volume monitoring. Final assessments still require context and professional judgment because automated systems can misinterpret sarcasm, quotations, common names and other benign content.
Should security attempt to identify anonymous users?
Only through lawful, appropriate methods. Weak or speculative identity matching should not be treated as fact.
What is the role of a family office in protective intelligence?
The family office often receives communications, controls travel information and coordinates staff and vendors. It should have a clear process for routing relevant unusual contacts to the protection function.
How does this fit into an estate security assessment?
A comprehensive security assessment should examine not only physical barriers but also what information reveals the residence, how concerning contacts are reported and how intelligence reaches the residential and mobile protection teams.
Final thoughts: watch the distance between the screen and the principal
There will always be information about visible people online.
A wealthy family cannot remove every reference.
A CEO cannot eliminate every biography.
A public figure cannot stop every photograph.
A property owner cannot necessarily erase every public record.
That is not the objective.
I want to reduce unnecessary exposure.
California’s new DROP system now gives residents a meaningful way to reduce one large category of commercial data-broker exposure.
Use it.
Continue checking what remains.
Then pay attention to behavior around the information that cannot be removed.
Someone sees a name online.
That is nothing unusual.
They repeatedly contact the principal.
Now we document it.
They contact an assistant after the principal does not respond.
That adds context.
They begin asking where the principal lives.
That matters more.
They identify the residence.
The residential team may need to know.
They appear at a public event.
Now the digital behavior has a physical component.
They later appear near the residence.
That is another material change.
Protective intelligence is the discipline that connects those events.
Without it, every encounter can look isolated.
The assistant sees an email.
The driver sees a vehicle.
The event team sees an attendee.
The gate officer sees a visitor.
Nobody realizes they are looking at the same person.
That is the failure I want to prevent.
The answer is not to treat every stranger as hostile.
It is not to monitor every critic.
It is not to turn the family’s life into a constant threat investigation.
It is to build enough structure that meaningful changes stand out.
Know what is exposed.
Reduce what does not need to be exposed.
Create one reporting path.
Preserve important history.
Document facts.
Watch for persistence.
Watch for information seeking.
Watch for boundary violations.
Watch for third-party contact.
And, above all, watch for movement from online attention toward physical access.
That is where protective intelligence stops being an internet problem and starts directly supporting executive protection.
That is the line I want the team to recognize early.
About Michael Braun
Michael Braun is a former Special Unit Operator, former Manager at Gavin de Becker & Associates, and Founder & CEO of MSB Protection, an executive protection and residential security firm serving high-net-worth and ultra-high-net-worth clients.
Braun has built his career at the intersection of specialized protective operations, executive protection, residential security, protective intelligence, and security risk management. His experience spans special-unit operations, leadership within Gavin de Becker & Associates, and the development and oversight of private protection programs within demanding UHNW environments.
He has been recognized by The Top 100 Magazine as a leading CEO in the private security field and is the subject of an upcoming Marquis Who’s Who feature highlighting his leadership and contributions to the profession.
Today, Braun is recognized for his work in executive protection, UHNW estate security, residential protection, protective intelligence, adversarial security assessments, and security auditing throughout Beverly Hills and Southern California.
His work focuses on moving private security beyond simply “providing a body” and toward intelligence-led, risk-based protection programs designed to identify vulnerabilities before an adversary can exploit them.
Looking for Executive Protection or Residential Security Services?
If you are a high-net-worth or ultra-high-net-worth individual, family office, estate manager, chief of staff, or executive in Beverly Hills, Los Angeles, Malibu or Southern California, MSB Protection provides executive protection, residential security, 24/7 protection, protective intelligence, medical-readiness planning, and security risk management.
We evaluate the complete security environment, from threat exposure and residential vulnerabilities to personnel, technology, procedures, protective intelligence, and emergency response, and build a program around the risks that actually exist.
Contact us for a confidential consultation or message us at +1 (805) 285-2807.