Skip to content
LANEDEN

Threat Simulation

Executive Threat Assessment

Senior leaders are targeted precisely because of who they are: their names authorise payments, their inboxes carry weight, and their personal lives leak online in ways corporate controls never touch. We assemble the picture an attacker would build of your executives — from breach corpora, public registers, data brokers and social media — and, where you choose, test what could be done with it.

Who this is for

What is holding, and what is open

Every assessment records both. Knowing which controls already work is half of knowing what to change.

3

Holding

Already working — and worth protecting as the role changes.

  • Private personal accounts — control holdingPersonal social accounts are locked down, which removes the easiest source of routine, location and relationship detail.
  • Legacy accounts removed — control holdingDormant handles carrying an old personal address have been deliberately closed — good hygiene, and it shrinks the historical footprint.
  • Corporate and personal kept apart — control holdingNo corporate address on personal accounts, no personal address on corporate filings. That separation is doing real work.
4

Open

What an attacker can still assemble today.

  • Credentials in breach corpora — exposure openA personal address and password hash appear in more than one corpus, the most recent within 30 days — the raw material for credential stuffing.
  • Address in the open register — exposure openCurrent and previous addresses sit in the open electoral register, which propagates to commercial people-search brokers.
  • Family exposure — exposure openA relative's public profile and a shared family tree expose relationships the subject has kept private on their own accounts.
  • Voice and likeness published — exposure openLong-form conference audio and front-facing video are enough to clone a voice, at a time when payment calls are still taken on trust.

Illustrative — a synthetic subject.

What we test

Coverage runs in depth, not breadth alone — each stage goes past where the one above it stops.

  1. Credentials

    What is already exposed

    Breached credentials and stealer-log appearances across personal and corporate identities. Where a hash is recovered we attempt to crack it under controlled conditions, to establish whether the secret is still usable and what it says about how the subject builds passwords.

  2. Public record

    What the state publishes

    The open electoral register, Companies House appointments and the partial dates of birth they carry, Land Registry title and price records, and the birth, marriage and death indexes used to answer security questions. All of it legal, none of it removable by asking nicely.

  3. Brokers

    What is resold

    Data-broker and people-search listings carrying home addresses, phone numbers, historic addresses and named relatives — the layer that re-lists after removal, which is why closure is re-checked rather than declared.

  4. Social

    What the household leaks

    Social-media leakage including family accounts and published family trees: routines, relationships, pets, employers and the answers to account-recovery questions. The subject may be locked down; the household often is not.

  5. Recovery

    Whether the account can be taken back

    Partial recovery addresses and numbers disclosed by password-reset flows, MFA method, and security answers derivable from public record. This is where the layers above combine into an account takeover.

  6. Likeness

    Face, voice and name

    Reverse-image and facial-search hits, long-form public video or audio that gives voice cloning something to work from, and lookalike domains or unofficial profiles positioned to abuse the executive's name.

  7. Susceptibility

    What can be done with it

    Where commissioned, controlled whaling, spear-phishing and voice pretexting built from everything above — including approaches routed through family. A measured read of susceptibility rather than an assumed one.

What the testing looks like

Pages from the report — here is what you actually receive.

The report you receive

One sheet per subject. The ranked list is what is open; the ledger underneath is who fixes it, by when, and what counts as proof — a finding is not closed because someone intends to close it.

Screenshots show synthetic demo data.

How the service tiers up

Baseline exposure assessment

OSINT profiling of named executives across the open, deep and dark web: breached credentials and stealer-log appearances, public-register and data-broker exposure, social-media and family leakage, likeness and impersonation risk, dormant accounts and historical footprint. Every finding is written up with its source, its impact and a specific remediation, and each subject is scored for both how likely they are to be targeted and how likely a targeted attempt is to succeed.

Targeted attack simulation

With written consent, we run controlled spear-phishing and vishing against assessed executives using the exposure we found — measuring real-world susceptibility, not theory.

Continuous monitoring and removal — powered by Gravitas

Product

Our Gravitas platform keeps watch year-round over breach corpora, stealer campaigns, broker listings and impersonation infrastructure, and files opt-outs and removals on the subject's behalf under signed authority. Because brokers re-list, closed exposure is re-checked on a recurring cadence rather than declared fixed once.

Learn about Gravitas →

What you get

The package in three parts — what you read, what you act on, and what happens after.

What you read

Written for the individual first, with the technical detail underneath.

  • A per-executive report: a plain-English conclusion, then finding-by-finding detail
  • Two separate scores per subject — how likely they are to be targeted, and how likely an attempt is to succeed
  • The consolidated target profile: every identifier, address, account and credential an attacker would assemble
  • Good practice recorded as well as gaps, so the subject knows what is already working

What you act on

Every finding carries its remediation route, not just its risk.

  • Prioritised remediation with the routes attached — resets, opt-outs, service addresses, recovery hardening
  • Platform hardening checklists: LinkedIn, Facebook, X, WhatsApp and Instagram
  • An executive security checklist covering devices, travel, SIM-swap and physical security

What happens after

The engagement does not end at delivery.

  • Where simulation is commissioned, a measured read of real susceptibility rather than assumed risk
  • Discreet handling throughout, shared only with the individuals and sponsors agreed at scoping

How it runs

How a simulation runs

  1. Scoping & Rules of Engagement

    Which hosts, people or systems are in play, at what intensity, in what window — plus your point of contact, the escalation route, and who holds the authority to stop it.

  2. Reconnaissance & Scenario Build

    Building the thing that will actually run: a pretext assembled from your own public footprint, an agent and scope for a ransomware run, or a load suite from your API collection.

  3. Written Authorisation

    Nothing executes until it is signed. Where a simulation touches your people or your availability, that authorisation is a separate document from the standard engagement terms.

  4. Controlled Execution

    The exercise runs inside the agreed window, watched by a named engineer, with the means to halt and reverse it immediately if you ask or if anyone becomes distressed.

  5. Detection & Response Measurement

    What your tooling saw, what your people did, and how long each took. This is the output that matters — the simulation itself is only the instrument for producing it.

  6. Stand-down & Reporting

    Everything is reversed and removed: files restored, assets deleted, campaigns closed, with the restoration reconciled. Then the annotated timeline, the findings and what to change.

This is our simulation sequence. The six-phase methodology CREST assessed governs our penetration testing, which is a different service.

Prerequisites

  • Written consent from each executive being assessed
  • Seed data for each subject — legal and known names, current and previous addresses, personal and corporate email addresses, phone numbers and usernames — plus validation data we can check findings against, so nothing is attributed to the wrong person
  • A named sponsor and an agreed distribution list for reporting
  • A signed Laneden authorisation form; simulation tiers require additional explicit written consent from each individual targeted

Frequently asked questions

Is it legal to profile our executives like this?

Yes, on one condition we never waive: the individual's own written consent. With that in place the work stays passive. We collect from open and lawfully accessible sources and from breach-monitoring services; we do not interact with criminal actors, obtain anything by deception, or use a recovered credential to access an account — even though a real attacker would. The assessment is conducted in line with UK GDPR and processes personal data only for the agreed protective purpose.

You mention family members. How is their data handled?

Family exposure is assessed only because attackers use it — approaches to executives are routinely routed through relatives — and only with the executive's written consent. We do not investigate minors and do not store information or images relating to anyone under 18. Findings about adult family members are reported only to the extent needed to explain the risk to the subject, and the recommendation is almost always a conversation and a privacy check-up, not a file on a relative.

Will the executives know they are being assessed?

For the baseline assessment, always — consent requires it. For attack simulation, the individual consents in advance to being targeted during a window without knowing the specific pretext, which preserves both ethics and realism.

What happens if you find something urgent?

We do not wait for the report. If a finding suggests an immediate risk to someone's physical safety, it is escalated to the agreed contact within an hour of being confirmed, with the remediation that closes it.

What happens to the findings afterwards?

Reports go only to the agreed recipients. Collected material — credentials, personal details, working notes — is retained only briefly after delivery so we can answer follow-up questions, then permanently deleted, and we confirm destruction in writing on request. Subjects can ask us for the source of any finding in their report, so nothing in it has to be taken on trust.

Related services

Ready to test your defences?

Tell us about your executive threat assessment requirement — we'll come back with a scoped proposal within two working days.

Free remediation retesting* to confirm your fixes (subject to assessment size).