The death of UnitedHealthcare CEO Brian Thompson in December 2024 forced a long-overdue conversation in boardrooms and security departments across the country. Not because targeted violence against executives is new — it isn't — but because the attack exposed how many organizations treat executive protection as a physical problem rather than an intelligence one. The security detail, the motorcade, the hardened office — none of it matters if you have not first answered a more fundamental question: who actually poses a threat, and what are they prepared to do?
Executive threat assessment is the discipline that answers that question. It is not a background check. It is not a social media audit. It is a structured analytical process that evaluates the full threat environment around a specific individual — mapping actors, motivation, capability, intent, and trajectory — and translates that into actionable protective intelligence. This piece outlines what a rigorous assessment looks like, when to commission one, and where most organizations go wrong.
What Executive Threat Assessment Actually Is
The term is used loosely. Security consultancies, HR firms, and law enforcement liaison services all claim to offer it. In practice, the discipline spans a wide spectrum — from a cursory internet search to a multi-week intelligence operation involving physical surveillance, source development, and behavioral analysis. The difference matters enormously, because the failure mode of a superficial assessment is identical to doing nothing at all: false confidence.
A rigorous executive threat assessment has three primary components:
- Threat actor identification. Who, specifically, has expressed grievance, hostility, or interest in the subject? This includes terminated employees, litigants, activists, former partners, online commenters who have escalated in specificity or intensity, and third parties with a transactional grievance against the organization the executive represents. The population is broader than most clients expect.
- Behavioral threat analysis. Identifying a name is only the first step. The analytical work is understanding pathway to violence — the sequence of behaviors, communications, and circumstances that distinguish someone venting frustration from someone moving toward action. This draws on established frameworks including the WAVR-21 (Workplace Assessment of Violence Risk) and structured professional judgment instruments developed for law enforcement and clinical settings.
- Environmental mapping. What is the physical and digital environment the executive occupies? What events, travel patterns, or public-facing obligations create predictable exposure? An executive who routinely attends the same industry conference in the same city at the same hotel each year is not an unpredictable target — they are a scheduled one.
These components feed a written assessment that categorizes identified individuals by threat level, recommends monitoring protocols, and informs the protective posture for the subject. The assessment is not a one-time product. It is a living document that should be updated whenever the threat environment changes.
Triggers: When to Commission an Assessment
Most organizations commission executive threat assessments reactively — after a threatening communication arrives, after a workplace incident, or after a public controversy creates a spike in hostile attention. Reactive assessment has value, but it represents the minimum viable standard. The more sophisticated approach treats threat assessment as a persistent, proactive function for any executive with meaningful public visibility, organizational authority, or adversarial exposure.
Specific triggers that should prompt an immediate assessment or reassessment include:
- A significant termination or reduction in force, particularly where the executive was the visible decision-maker
- High-profile litigation, regulatory action, or public controversy naming the individual
- Activist campaigns targeting the executive personally — not just the organization
- A direct threatening communication, regardless of apparent seriousness
- Evidence of surveillance, inquiry, or fixated attention (repeated unsolicited contact, showing up at multiple unconnected events)
- A significant change in the executive's public profile — a major media appearance, a controversial policy decision, a political appointment
- Intelligence indicating that the organization itself is under elevated threat from an organized actor
The last point is frequently underweighted. Organizations under targeted pressure from activist networks, hostile state actors, or organized criminal enterprises should treat executive threat assessment as a component of their broader organizational intelligence posture — not a siloed function reserved for crisis moments.
The Intelligence Inputs That Matter Most
Effective executive threat assessment is an intelligence collection and analysis problem, not a security operations problem. The distinction matters because it determines where you look and who does the work.
The most operationally significant inputs are rarely found in the places security teams default to. Public social media monitoring catches explicit threats and high-volume harassment, but it misses the actor who has gone quiet precisely because they have moved from expression to planning. Court records, civil filings, and restraining order histories surface patterns of escalating behavior that predate any direct approach to the subject. Dark web and fringe platform monitoring captures ideological radicalization and operational coordination that mainstream platforms have removed. And human source development — conversations with people who know the threat actor — provides the behavioral context that no database can replicate.
The synthesis matters as much as the collection. A single data point — a threatening voicemail, a hostile social media post, an unusual inquiry about the executive's schedule — is rarely sufficient to assess threat level. The analytical value is in pattern recognition across sources and time. An actor who sends one angry letter is different from one who sends twenty letters over six months, researches the executive's home address, and attends a public event the executive spoke at. The trajectory tells the story that any individual data point obscures.
Common Failures and How to Avoid Them
Organizations that have invested in executive protection infrastructure often discover, under pressure, that their threat assessment function has significant gaps. The most common failures follow predictable patterns.
Conflating physical security with threat intelligence. A protection detail manages risk that has already been identified. It does not generate the intelligence that identifies it. These are complementary but distinct functions, and organizations that fund one without the other are accepting blind spots they may not recognize until it is too late.
Underestimating the insider threat population. The majority of targeted violence against executives originates from people with a prior organizational relationship — former employees, vendors, contractors, or other individuals who have had direct contact with the subject. The unknown stranger is a real risk, but the known grievant is statistically the more common one. Threat assessment programs that focus exclusively on external actors miss the population most likely to act.
Failure to monitor for escalation. A threat actor assessed as low-risk at the time of initial evaluation may escalate significantly following a triggering event — a court ruling, a public statement by the executive, a personal crisis in the actor's own life. One-time assessments without ongoing monitoring create false confidence. The threat environment is not static.
Legal over-caution that suppresses information sharing. In many organizations, HR, legal, security, and executive leadership receive threat-relevant information in siloed channels that are never synthesized. The result is that no single function has the full picture. Effective programs require a cross-functional information sharing protocol that is designed in advance, not improvised after an incident.
The executives most at risk are frequently those whose organizations believe they are already adequately protected. The gap between perceived security and actual threat intelligence is where incidents occur. Closing that gap requires treating executive threat assessment as an ongoing intelligence discipline — analytical, source-driven, and systematically integrated with protective operations.
Kronus Intelligence Group conducts executive threat assessments for senior leaders, board members, and high-profile individuals operating in complex or adversarial environments. Our work combines open-source intelligence collection, behavioral analysis, and human source development to produce assessments that are operationally grounded — not compliance checkboxes.
Kronus Intelligence Group builds and operates custom intelligence infrastructure for organizations that cannot afford to be wrong. If your environment requires it, we want to hear from you.
Start a Confidential Conversation →