How a Protection Team Mapped the Risks Before a CEO's Public Appearance
A high-profile keynote meant a published time, a published place, and a very public principal. Here's how a corporate protection team used Expose to find the risks in advance - and quietly close the gaps before anyone arrived.

On this page
A published time, a published place
Ray Donnelly had run advance work for corporate protection teams for eleven years, and one thing had never changed: a keynote announcement is also a targeting announcement. The moment a company's communications office puts out a press release - "Meridian Technologies CEO Carolyn Voss will deliver the opening keynote at the TechForward Summit, Thursday at 10 a.m., Convention Center South Hall" - the principal's location, schedule, and public identity are handed to the world at no cost. Anyone curious enough to look can know exactly where she will be, exactly when she will be there, and exactly how to find her photo and biographical details. For a protection team, that's not news; it's the environment. The question is what you do with it.
Ray's team had been retained to support Carolyn Voss for the TechForward Summit - a three-day industry conference that would bring thousands of technology executives, press, and attendees to a major convention center downtown. Carolyn was a recognizable figure in her sector, which meant her name and face circulated widely online. She was also, like most C-suite executives, carrying more exposed personal data than she realized. Ray's job, starting three weeks before the event, was to understand the threat picture before the event happened - not while it was happening. He opened Expose and began the investigation.
The three questions that drive an OSINT investigation
Ray structured his work around three questions that any protective investigation has to answer before a public appearance. Each one had a different flavor of open-source research behind it.
- Is anyone talking about this event or about the principal in a way that suggests a threat? Public forums, social platforms, and open discussion channels often surface fixated individuals before they surface in person.
- What personal information about the principal is already exposed online? Home address, daily routine, family members' names, vehicle details - any of it widens the attack surface and can be used for planning by someone who intends harm.
- What is the physical and contextual environment of the venue? Adjacent streets, parking access, secondary entrances, nearby buildings - the landscape that shapes how a protective plan is built and where the gaps are.
These aren't hypothetical questions. They're the ones that, if you don't answer them in advance, you answer on the day - under pressure, with no time to act on the answers. Ray's philosophy was simple: every gap in your picture is a gap in your plan. Expose let him close those gaps early.
Scanning for threat chatter
The first thing Ray did was run Carolyn's name and the event name through Expose to surface public posts, forum discussions, and open-platform mentions connected to either. He was looking for the signal that serious analysts know is rare but never impossible - a fixated individual whose public language has moved from frustrated commentary into something more personal, more targeted, more indicative of planning.
What he found, mostly, was noise. A lot of it. Industry commentary, conference discussion, promotional posts, travel logistics shared by attendees, a handful of critical opinions about Meridian's latest product release. Professional critics and disgruntled commenters are common at any profile; they are almost never a genuine threat, and treating them as one is how protection teams burn credibility and exhaust themselves before a principal walks through a door. Ray triaged them out methodically, applying a consistent standard: volume of anger is not the same as specificity of intent. A dozen people furious about a business decision are not a threat; they are the background radiation of public life.
One account stood out. A user on a public platform - Ray gave him the working designation "Foxtrot" in his notes - had been posting about Carolyn Voss repeatedly over the preceding six weeks. The posts had a quality that Ray recognized from training: they were personal in a way that professional criticism isn't. Foxtrot didn't write about Meridian's business decisions. He wrote about Carolyn specifically - her schedule, her travel, her appearances. In two posts, he'd referenced TechForward by name and expressed, in language that stopped well short of an explicit threat but well inside the range of a serious flag, an intention to "make her answer" for something she'd supposedly done to him. Ray documented everything, noted the escalating pattern across the weeks, and kept reading.
A fixated individual surfaces
Ray ran Foxtrot's public-platform identity through Expose to look for corroborating signals across sources. Some of what the platform returned was inconclusive - fragments that might or might not belong to the same individual. But enough pieces fit: an older professional profile, a public record of a business dispute with a Meridian subsidiary, several other online accounts with overlapping language and style. None of this was private information; all of it had been put into the public domain by Foxtrot himself. The picture was consistent and it was concerning. Ray did not reach for a verdict.
"My job in this phase is not to decide whether someone is dangerous," Ray said. "That's not a determination a protection team makes unilaterally on the basis of social-media posts. My job is to assess whether something is credible enough to go further - and if it is, to hand it off to the people who have the authority and the tools to assess it properly. In this case, it was."Ray compiled his documentation on Foxtrot - the public posts, the escalating pattern, the corroborating open-source material, the connection to the event - and took it to law enforcement. He briefed the company's legal team simultaneously. What happened next was law enforcement's work, not his. His responsibility was to surface the credible signal quickly enough that the right authorities had time to act on it. That's what an OSINT investigation exists to do.
What the internet already knew about Carolyn Voss
Parallel to the threat-chatter scan, Ray ran Carolyn's email through Expose to map what personal information about her was already in the public domain. This is a part of protective advance that many organizations neglect until it's too late - the principal's exposed personal data is an attack surface in its own right, and it's one that can, at least partly, be reduced before an event.
What Expose returned was uncomfortable reading, though it was not unusual. The aggregated picture of a public executive's open-source footprint tends to be larger than anyone expects:
- Her home address - the actual street address of her primary residence - appeared on multiple data-aggregator sites, compiled from property records and populated without her knowledge or consent.
- Her vehicle's make, color, and partial registration were derivable from a combination of local public records and background-context photos she'd shared on social media over the years.
- The names and general locations of two family members appeared in biographical profiles and older social media posts - information that creates leverage for anyone willing to use it.
- Her approximate daily departure time from home had been publicly inferrable from a series of geotagged posts made over several months - a pattern she hadn't noticed she was establishing.
None of this had been stolen. All of it had been assembled from public sources - the kind of correlation that takes a motivated individual hours to do manually, and that Expose had done in minutes. Ray briefed Carolyn directly. He did not frame it as alarmist; he framed it as a problem with a partial solution. Some of the exposure could be walked back - the data-aggregator listings could be removal-requested, which the company's security team initiated immediately. The social-media pattern would stop with a simple change in behavior. The family-member information was already public, so the answer there was awareness and a conversation with the relevant family members about being on guard for unusual contact. None of it was fixable completely, but all of it could be reduced.
Building venue and environmental context
The third strand of Ray's advance was the venue itself. The TechForward Summit's convention center was a large, publicly accessible facility with multiple entry points, a public parking structure connected by a sky bridge, an adjacent hotel used by speakers and VIP guests, and a loading area that opened onto a side street. Ray used Expose alongside standard advance-work tools to build environmental context - what was publicly known about the facility's layout, what nearby locations offered elevated vantage or close approach, and what the event's published agenda revealed about Carolyn's specific movements.
The published conference agenda was more detailed than it needed to be. It listed not just the keynote time and hall but the speaker-reception location the evening before, the post-keynote press availability room, and the panel session Carolyn was scheduled to join the following afternoon. Each published detail is a vector for pre-positioning by someone who intends to be there when the principal is. Ray worked through the agenda item by item, adjusting the protective plan to reduce predictability at each transition point - routes, timing, access management, contingency exits.
He coordinated with the conference's own security team, sharing the relevant elements of his assessment without sharing operational detail that wasn't theirs to need. They were cooperative. Conference security teams usually are, once they understand that an protection team's interest is in a clean, uneventful event, not in taking over their floor.
One of the hardest disciplines in OSINT-informed protective work is what Ray calls the triage threshold - the judgment about which signals warrant action and which should be logged, monitored, and set aside. The temptation, especially early in a career, is to treat every piece of concerning information as urgent. That way lies exhaustion, false alarms, and a principal who stops listening to her own protection team because every flag has been a fire drill.
The quiet measure of success
Carolyn Voss delivered her keynote on Thursday morning at 10 a.m. The session ran without incident. She moved through the press availability, attended two side meetings, and left the venue on a route Ray's team had adjusted from the published plan. The day after, she was on a flight home. Nothing happened.
That's the language of success in protective work, and it's genuinely difficult to communicate to people who aren't in it. Nothing happened because the gaps were closed before the event, not during it. The fixated individual did not appear at the venue - whether because of the law-enforcement action that Ray's referral had set in motion, or for reasons that will never be known. The exposed personal data had been partially remediated, reducing Carolyn's surface area for the future. The protective plan had been built around the real environmental picture, not an assumption. The appearance was uneventful because the work that makes appearances uneventful had been done three weeks earlier, in the quiet.
"People sometimes ask how you know the work made a difference if nothing happened," Ray said. "My answer is that you don't, definitively - and that's fine. The job is to reduce the probability of a bad outcome. You don't have to prove a counterfactual to know that a smaller attack surface is better than a larger one, and that finding a fixated individual before an event is better than finding out about them during one."What open-source intelligence actually does for a protection team
There's a version of this story that overplays the technology: Expose found the threat, the team acted, the principal was safe. That's not quite right. What Expose did was what good OSINT tooling does - it compressed the time between the question and the picture. The questions Ray was asking are the questions protective team has always asked. The difference is that answering them used to mean weeks of manual search, jurisdictional gaps, and missed connections across platforms that don't talk to each other. A correlated, fast, multi-source picture of the threat environment and the principal's exposure is now available in the early hours of an advance rather than the final days.
That matters because time is the resource that protective planning runs on. The earlier a gap is identified, the more options there are for closing it. A fixated individual found three weeks out gives law enforcement time to act. Exposed personal data found three weeks out gives the security team time to pursue removals. A venue picture built three weeks out gives the protective plan time to be built around reality instead of assumption. OSINT doesn't replace the judgment of experienced people - it gives those people a better picture, faster, so the judgment they exercise is actually informed.
Carolyn's keynote is already a footnote in her calendar. That's the point. The events that go right leave no trace of the work that made them go right - only the quiet, unremarkable fact that nothing happened, and a protection team that knows why.
What does the open internet already know about your principal?
Expose surfaces exposed personal data and public threat signals - so a protection team can reduce the attack surface before an event, not after.