- Home Home
- Insights Insights
- Podcasts Podcasts
- Executive threats: behavioural risk, online intelligence Executive threats: behavioural risk, online intelligence
Ground Truth | Executive threats: behavioural risk, online intelligence
Insights from Control Risks and GE Aerospace
Threats directed at executives and organisations are becoming more common and complex. What once might have been dismissed as online hostility or isolated grievances can evolve rapidly into real risks for people and businesses alike.
In this episode of Ground Truth, Control Risks experts explore how organisations can identify, assess and manage threats directed at executives, employees and corporate assets. The discussion examines how online threat intelligence, behavioural threat assessment and workplace violence prevention programmes help organisations distinguish credible threats from online noise, identify indicators of escalation and prevent threats from developing into real-world incidents.
Speakers:
- Shawn VanSlyke, Director of Response, Behavioral Threat Assessment and Management, Control Risks, former FBI Behavioral Analysis Unit
- Alex Hillier, Global Head of Online Threat Intelligence, Control Risks
- Terri Patterson, Senior Director of Insider Risk, Crisis Management and Enterprise Risk, GE Aerospace
In order to play this media, we need your consent to add cookies to your device. Do you accept these cookies? Find out More.
Key takeaways
- Executive threats are rising. Control Risks has recorded a 566% increase in threat cases between 2020 and 2025 in its caseload, reflecting a broader shift in the operating environment facing organisations and their leaders.
- Online hostility increasingly translates into real-world risk. Threats rarely emerge in isolation. Online grievances, sustained hostility and concerning behavioural indicators can provide early warning signs of potential escalation into physical security incidents.
- Behaviour matters more than explicit threats. The most serious risks are not always associated with the loudest voices. Sustained grievances, mounting personal stressors and signs of movement from intent to action are often stronger indicators of concern than threatening language alone.
- No sector can assume immunity. While some industries have long operated in highly politicised environments, increasing social and political polarisation means organisations across all sectors face heightened vulnerability.
- Prevention is more effective than reaction. The strongest threat management programmes focus on identifying vulnerabilities, monitoring emerging risks and establishing cross-functional processes before a crisis occurs.
- AI is changing the threat landscape. Artificial intelligence is increasing the volume of online content and complexity of investigations, but it is also creating opportunities to identify patterns and improve the speed and effectiveness of threat intelligence programmes.
Top implications for businesses
- Treat executive threat management as a strategic risk issue
Threats directed at leaders are no longer purely security concerns. They can affect reputation, operations, employee confidence and organisational resilience.
- Bridge the gap between cyber, intelligence and physical security teams
Threats increasingly move across digital and physical domains. Organisations need integrated processes that connect intelligence gathering, risk assessment and protective measures.
- Focus on indicators of escalation, not just explicit threats
Monitoring programmes should look beyond direct threatening language to identify behavioural warning signs, grievances and mobilisation indicators.
- Reduce executive online exposure
Many threat actors use readily available online information to build a picture of potential targets. Regular assessments of executives' digital footprints can reduce vulnerabilities.
- Establish a formal threat assessment programme
Multidisciplinary threat assessment and management processes help organisations identify concerns early, assess risk consistently and coordinate responses effectively.
- Build proactive monitoring capabilities
Waiting for a severe incident can leave organisations on the back foot. Continuous monitoring helps identify emerging risks and provides decision-makers with actionable intelligence.
Read the podcast transcript
Introduction: A rising threat landscape 00:00
Caspar: Welcome to Ground Truth, the podcast from Control Risks. This is the place to hear the latest insights on how organizations across the world are optimizing their use of strategic intelligence and becoming more secure.
I'm your host, Caspar Leighton, and in this episode we're looking at how organizations handle threats of violence to their employees. At Control Risks, we've been helping organizations prepare for and respond to executive threat for decades. The problem is getting worse. Between 2020 and 2025, we recorded a 566% increase in the number of threat cases we responded to.
So what's behind this rising phenomenon? Organizations today are operating in an unrelenting climate of political polarization, social unrest, and online incivility. Some sectors are well used to operating in a highly politicized and sometimes confrontational context. For others, it's a more recent problem. One thing is clear: in an age of activated societies and a greater acceptance of the use of violence to achieve political or ideological aims, no sector can consider itself immune to executive threat.
I'm pleased to be joined by a couple of Control Risks experts on this podcast. Joining us from Washington, DC is Shawn Van Slyke, Director of Response with behavioral threat assessment and management expertise, and Alex Hillier, global head of our online threat intelligence team here in London. We'll also be hearing from one of our clients, Terri Patterson is Senior Director of Insider Risk, Crisis Management, and Enterprise Risk at GE Aerospace. Terri also joins us from Washington, DC.
What are the most common threat scenarios companies face?
Caspar: Okay, well, let's jump in. Shawn, if you've not experienced this world, I suspect your understanding of things like threat is fairly shaped by what you might see on Netflix. But in reality, what's the kind of work you find yourself getting involved with in helping our clients?
Shawn: Some of the more common scenarios we encounter from a threat perspective include online threats to executives from consumers of their services — clients or customers who may have some sort of grievance toward the business. Also, threats of retaliation from recently terminated employees. And a third scenario would be the potential spillover of domestic violence involving a victim employee who's being threatened by a domestic partner, with the potential for that situation to spill over into violence in the workplace.
How has the threat landscape changed in the last few years? 2:38
Caspar: Turning to you, Terri, how has the threat landscape faced by organizations changed in the past couple of years?
Terri: Well, I think what security professionals have seen across the industry is a steady increase in threats. We've certainly become much better at identifying concerns early, which is exactly where we want to be, firmly in that preventive space, but mitigating those concerns using cross-functional teams is, I think, another space where the industry has really matured over the last five years and certainly over the last couple of years.
I'm always really cautious about trying to assign ideology or some causation to the numbers we see, but we have certainly become much more adept at identifying those threats over the last five years, and across the industry we've certainly seen that steady increase in the threat landscape, the concern, and the risk level over the last five years.
I want to be really cautious here, though, because we — and by "we" I mean corporate security professionals — have become much more mature in our ability to identify those threats and concerns early. The maturation of the threat management process in the corporate setting has really matured over the last five years, and so much more frequently we're using a standardization process to triage those concerns. We're measuring our progress through key performance indicators to see how quickly we're addressing and responding to threats, and then, of course, we're making adjustments as needed in that effort for continuous improvement around threat management and threat mitigation.
So again when we think about our threat landscape, for me that includes not only our risk exposure — the zeitgeist of the times, if you will, what the threat picture looks like in the general community — and then again our ability to respond to those threats in a way that keeps us in that prevention space. And that's where I think corporate security professionals have really matured. I know we don't talk about COVID anymore, but it's been in the last five or six years that we've seen that increase in the numbers of concerns reported, really opening the aperture beyond just those traditional security concerns and focusing on concerning behavior in general. I think that has really helped us stay ahead of the threats lodged against our assets.
Grievance-based violence: what patterns do threat actors show? 5:30
Caspar: So we talk about grievance-based violence, and there must be an almost limitless list of potential grievances out there. But is there any commonality in the threat actors you see — are there patterns you see in your line of work?
Shawn: Well, we certainly advocate for all threats to be taken seriously, but that doesn't mean all threats are created equally. In fact, most threats are made for some reason other than as an indicator of potential violence. There are a number of reasons people make threats — they may be venting negative emotions, or they may be instrumental in nature, an attempt to frighten or intimidate the target, or entice the target into taking some action favorable to the threatener.
The situations we get most concerned about are ones where we start to see some sort of movement from thought to action. And I'd say the types of individuals who cause the greatest concern are those with some sort of sustained and profound grievance against our client or the intended victim — perhaps those facing mounting and significant life stressors, whether financial, mental-health related, or job-related, and those who may be in some sort of downward spiral.
Inside a behavioral threat assessment team 6:55
Caspar: And what sort of capabilities does your team, and the wider Control Risks team, bring to bear in these situations?
Shawn: My team is comprised of eight former members of the FBI's Behavioral Analysis Unit, who focused on issues of behavioral threat assessment, management, and targeted violence. We have very unique expertise and capability in that regard — we've collectively assessed literally thousands of cases over our 80-plus years of combined experience conducting these types of assessments. We've also been involved in specialized training and education, provided a great deal of training ourselves, and done research and publications on best practices around workplace violence prevention.
Once we get involved in a situation, we're able to step in and conduct an assessment to help the client understand what their level of concern might be. We follow a very methodical, established process where we look at the totality of the circumstances, assess the warning signs or risk factors, as well as the protective factors and stabilizers that may be present in the threatener's life, to help the client understand what their level of concern for potential violence should be.
A big part of that analysis is the findings provided by our OTI team, which can not only help us understand the threats issued by a particular subject, but also give us insight into their patterns of thinking and behaviors that may show movement toward violence.
What is online threat intelligence (OTI)? 8:39
Caspar: Great — you mentioned OTI, which, for our listeners, I'll spell out again is online threat intelligence. We're used to that expression, but out in the real world it's perhaps not so commonly used. This seems like a great point to turn to Alex. Alex, I guess looking at your and Shawn's respective careers — Shawn's career, like mine, overlaps almost entirely with the arrival and eruption of the internet, online content, and that as a whole forum in which people communicate and express themselves. What's a neat definition of online threat intelligence?
Alex: Easy question. First up, the definition of what we do, and the kind of mission statement we have as a team, is that online threat intelligence encompasses where we're looking for concerning pieces of content towards clients, as well as the methods by which we investigate and analyze that content. Typically, for us that looks like using a number of different pieces of collection software alongside the expertise of our analysts to identify information across open-source platforms — conventional social media platforms, the kind of things most people in this room probably use every day, alongside more niche social media sites that are more applicable to specific locations, for example — and then imbuing that with deep and dark web source capability as well.
Ultimately, what we're aiming to do is bridge the gap between cyber and physical security, to give as comprehensive a view as possible of what's being said about organizations on those platforms, and who the individuals of concern are, if any, who may pose a risk to your organization.
Ethical and legal boundaries of online investigations 10:34
Caspar: I imagine, when you're looking at what people are thinking, saying, and doing online, there are considerable ethical and even legal considerations around this work. How do those factor into the way you work, and what are the lines you work within?
Alex: It's the absolute fundamental of every single investigation we conduct. We're specifically accredited by the Bank of England, amongst others, to conduct online investigations in a safe, secure, ethical, and compliant manner, and we're audited on those requirements every year. We have a very strict set of standard operating procedures that we train on regularly to ensure that wherever we're conducting an investigation, we're maintaining those global standards while also adhering to specific regional requirements.
If we're looking at an individual based in South Korea, for example, who has threatened somebody working for a specific firm, what we're able to access, store, and how we do that looks fundamentally different than it may in the state of California, for example. It's important that we're cognizant of that in all our activity, and that we're utilizing open-source information — we're not engaging in any hacking or penetration of any kind. This is all information freely available on the internet, and that, among other very strident measures, ensures we don't cross any ethical or legal lines in our investigations.
Connecting behavioral threat assessment and OTI 11:56
Caspar: Great. And when you're working with the behavioral threat specialists on Shawn's team, there's an established threat there — you know what you're looking at in terms of a threat. How does that inform the way you go about your investigations?
Alex: If we hear from Shawn or Shawn's team, it's a significant case, and we know that's something we need to treat as a priority. Really, our role is to provide as complete an intelligence picture about that subject as we can, so our behavioral threat experts can utilize that to analyze and communicate to a client how concerned they need to be and what they should do about that individual situation. That may range from identifying the individual behind a piece of direct threatening communication that isn't in the public domain, all the way up to some of the things Shawn talked about in a previous response — what kind of information can we glean about the subject's day-to-day life that's relevant from a threat assessment perspective, and can ultimately help inform Shawn and his team as they complete the most thorough threat assessment possible.
How to tell a credible threat from online noise 13:07
Caspar: Right — and the other main plank of your work is when you're not working with an established, known, identified threat, but you're actually looking for signs of an emerging threat from someone's online behavior. The internet is massively noisy — an awful lot of people going on, keyboard warriors, whatever you want to call them. So how do you distinguish between all that noise and something that's actually credible and potentially sinister?
Alex: It's a good question, and I think there are fundamentally two ways to approach that. The first is, I don't think it takes a great degree of intelligence expertise to identify if somebody is saying they're going to go to an organization's headquarters with a firearm, for example, and they're talking about it in the context of a direct threat of violence — that's something you're going to investigate regardless of your expertise.
What we really focus on, and where expertise in this field is particularly important, is identifying what sits just below that threshold. If there are individuals who aren't making necessarily threatening commentary but have a sustained personal grievance with an organization, that can often be a better predictor of future behavior than whether a threat has actually been made. There are some obvious situations — low-level language in certain internet communities or forums — where, if you have experience operating within them, you can recognize what's superfluous language versus a non-credible statement.
The other element is looking into the individual, because an individual statement is very hard to measure for credibility without knowing who made it in the first place. Understanding what you can glean about that individual helps you see whether a piece of online commentary is concerning — if it comes from person A, perhaps not; if it comes from person B, perhaps that does lend an additional layer of concern.
Warning signs that words are turning into action 15:19
Caspar: And in your experience, what are the signs — as much as you can give away tradecraft — that words are turning into action?
Alex: Again, this is where nothing at Control Risks operates in isolation. This is where we have our own experience and expertise, but it's also where we make sure we draw across the multiple disciplines within Control Risks. Shawn and his team have fantastic experience assessing thousands of threat cases, and we want to incorporate all of that knowledge — things like, are there indications of mobilization? Is someone carrying out plan-of-attack behaviors? Are they conducting surveillance on a target?
We've seen in lots of cases we've worked on that an individual may make what could be considered a relatively flippant comment — maybe "I'll visit a corporate site" — and once we've identified their more developed online persona and other social media profiles, we've been able to see that, through that broader online presence, they've actually been seeking to obtain, say, an executive's home address. Taken all together, these things give a better indication of whether someone is likely to take that action forward.
Terri: I want to highlight that we're also focusing, as threat management professionals and security professionals, on those cross-functional teams, and you'll hear more and more of the language around "concerning behavior" being used versus strictly "threats." We're always going to respond to threats — sometimes we say in the industry that's our easiest day in some ways, because we know exactly what the concern is. If a threat is detected, we're going to respond in a very robust way. We also want to keep our eye on concerning behavior that may not be the traditional threat a corporate security team would address, but again, we're using those cross-functional — some would call them multidisciplinary — teams in the corporate environment to address those concerns early and often.
How Control Risks supports clients through an active threat 17:39
Caspar: Right, Shawn — when we have an established threat actor, an established target, it's real. What do we do to support clients?
Shawn: As Alex mentioned, it really depends to a large extent on the context of the situation. Often we're dealing with an internal threat from an employee or contractor who already has access to the business, or it may be an external actor who's only communicating through social media. Initially, we want to help them understand the immediacy of the threat — are we seeing progression from words to action? We often talk about the pathway to violence in behavioral threat assessment, where there's movement from thoughts to research to planning and preparation before an attack is committed.
The good news about that type of intended or targeted violence is that it gives our clients an opportunity to respond and take preventative measures if they're able to observe and notice some of these concerning behaviors at an earlier stage. So it really depends on the immediacy of the situation what our initial recommendations to the client may be. We're going to help them make sure they have appropriate physical security precautions in place, and we may talk them through separation or termination strategies if it's a threatening employee. We may also talk about protective orders or restraining orders if appropriate under the circumstances.
Once we've helped them respond to the situation, we then take a much more holistic look at the individual in question — their background, whatever we can find out about them, including all the OTI findings Alex outlined, any documentation the client has available, and we may talk to managers or co-workers who can give us more insight on the person of concern. It may involve reviewing voluminous amounts of prior incident information and prior email history, to better understand the individual of concern.
From there, we work with the client to help implement more immediate and longer-term threat management strategies that will be effective in mitigating the potential for the incident to escalate to violence. We'll also provide a formal report that includes the background of the situation, our analysis, potential trip wires for future violence, and threat management recommendations, so they have guidance moving forward. And we do all of this on a very confidential basis for the client as well.
Caspar: And how does this work sit alongside the work and responsibilities of police forces, government agencies, and so on? Because clearly a lot of this is straying very heavily into illegal activity — crimes potentially about to be committed. What's the relationship there?
Shawn: Once we initially get involved in a situation, part of that initial assessment of the immediacy and urgency may involve recommending to the client that they notify law enforcement immediately. Ultimately, though, that's really the client's decision — we can talk them through the advantages or potential implications of involving law enforcement to help them make a better decision, but they're the ones who will decide when and how to involve law enforcement. Once law enforcement is involved, we generally aren't going to make direct contact with the authorities unless requested to do so by the client. Rather, we work in parallel with law enforcement and provide our recommendations and analysis directly to the client.
Is executive threat only a US problem? Global trends 21:59
Caspar: Alex — Shawn is talking to us from Washington, DC, and there's a pretty good understanding that the problem of executive threat, access to firearms, workplace violence is much more advanced in the United States. But what are we seeing in other regions of the world? Are there similar trends in Europe, Latin America, Africa, or Asia?
Alex: We do see differences — I think that's the right perspective to take. But where we might see a difference in the method threat actors use to target corporate executives or organizations, that targeting does still exist. Particularly in the European market, for example, with what we've seen over the last couple of years around protest activity, disruption of company events, and vandalism related to companies with alleged ties to the Israeli government, those things have caused significant disruption to those businesses. There have been executives approached at their home addresses — not necessarily any violent activity as a result, but that confrontation increased discussion of grievances, and similar levels of intent to do something.
So we do see differences in geography — as I said in the introduction, we have a team in the Asia-Pacific region as well, and what we deal with in Australia might be very different from Japan or South Korea. But there's certainly been an increase in online activity targeting organizations regardless of location. It's the method, and ultimately what they're trying to do to publicize their cause or grievance, where there's the bigger distinction.
How political violence and executive threats feed off each other 23:45
Caspar: You've both mentioned the increasing acceptance of violence as a way of achieving political or ideological ends, and Control Risks has been tracking rising political violence for a number of years. It sounds like rising political violence and violence against businesses and executives probably feed off each other pretty strongly, right?
Alex: I think so. In our line of work, we've seen a clear trend line, particularly since the COVID pandemic, of things likely to have a significant multiplying effect on online threats and targeting of executives and organizations. You're seeing a significant amount of conspiratorial content online — there's a real distrust of official narratives and sources of truth. Taking in developments around global conflict, economic instability, and the climate crisis, there's a general pervading perception on online platforms — whether correct or not — that major organizations aren't feeling the negative effects of those problems, and are in some cases directly contributing to them. That narrative is promoted and shared amongst lots of different groups in society, and it cuts across the entire political and ideological spectrum far more than you'd have observed five or ten years ago.
Terri: There's a lot of noise in the background that threat management teams have to address, and identifying and establishing standard processes — standard work around how you're going to triage that noise, that chatter, if you will — is really important, because no team has unlimited resources. You have to triage those concerns in a way that's based on empirical data and risk factors that have been tested and tried over the years and are accepted within the industry.
Beyond that, when we think about the correlation between increased volatility — general angst in a population — I think it's safe to say we have enough data to say there's certainly a correlation between increased economic, social, political, and geopolitical volatility in the general community and threats — threats to our schools, our churches, our corporate environment, our government entities. I think the data supports that correlation, though not causation — again, being very careful there. It's not a new phenomenon: when we see social, political, or ideological volatility in the community, we do tend to see an increase in threats and in violent behavior. That's something that's been long studied — when I was at the FBI, we conducted ad hoc research projects and reviews of cases, and we saw that connection between general stress, both in individual cases and in the data in aggregate. So I think it's fair to say most threat management professionals would agree there's a correlation.
How to build a corporate threat management program 27:21
Caspar: So we're getting a clear picture of a complex and volatile world our clients are operating in. How do organizations best prepare to understand their threat environment and mitigate the risks?
Terri: When it comes to preparation, this is where companies have an edge — we have more professionalized corporate security teams, with access to professional threat management expertise. I've recommended for many years that corporations take a cross-functional approach: establish a threat management team that brings in security, HR, legal, investigations, and health services, to talk through the issues you might need to address.
You need a strong triaging process — as concerns come in, you need to prioritize them, or you'll drown. We really don't like checklists when it comes to threat management — any professional will tell you that. However, when it comes to triaging, that's a good place to have a checklist of sorts, because you want to keep that standardized, while having a customized threat management strategy for the individual cases.
This requires training your staff to escalate concerns, with a variety of ways to do so — through their manager or through an anonymized system, typically a compliance hotline. You also want a monitoring system, typically through your GSOC or protective intelligence team, to monitor threats coming in from outside. Having those various mechanisms for receiving concerns, a standardized approach to triaging them, and a well-trained threat management team that gets a lot of reps through training, means that cross-functional team can work together. Each member should have a role to play — you need to hear from everyone, because sometimes a dominant personality will consume the time, so you need to require everyone to weigh in during those meetings. That's an industry standard around threat management, and I've found time and again that it works well when it's consistent and timely.
Proactive online threat prevention: minimizing executive vulnerability 30:45
Caspar: Alex, you've already shared a lot about how you bring understanding to companies about their online threat environment. What's the proactive part of your job — the educational piece — beyond saying "we've spotted something you need to look at"?
Alex: Actually, the majority of our work is focused on that preventative approach. When we're engaged with an organization, we look at a few key measures to focus their understanding of their online threat environment, and how that might manifest into physical security challenges — so, looking at who's currently talking about your organization, rather than waiting for an incident. You'll always need some level of reactive capability — you can't anticipate everything.
Caspar: So it's the usual suspects, almost.
Alex: Exactly. And we're frequently conducting executive and threat vulnerability assessments — not just looking at who's talking about you, but if they were to target you, if there was no signal before some kind of threat was carried out. A lot of that research may be conducted by the threat actor on the same online platforms most of us use daily, and corporate executives and leadership are no different. So we spend a lot of time advising clients on how to minimize their online vulnerabilities — because if an individual threat actor can identify where you live, where you send your kids to school, what you do on the weekend, based on your social media presence, you're starting to sound like the Netflix story — where do your kids go to school — but it's that kind of stuff. It's real.
And this is where it can sound overly dramatic, but would you rather take those precautions or deal with the potential consequences? That's why, when we advise clients, we're trying to reassure them — the vast majority of people we engage with are never going to have to deal with the worst-case scenario, but you'd rather take preventive measures to avoid that becoming a possibility where you can. A lot of them are actually relatively simple — it's not an enormous layer of technical sophistication. There are simple steps we work through with clients to help them understand and minimize their online vulnerabilities: what to do if they identify something in open sources, or if somebody starts messaging them directly or sending emails — how do you respond to it? And making sure that, for big organizations, your intelligence and security teams, or your threat assessment teams, are talking to each other — and not assuming that because you're a small company, or you operate outside the United States, this isn't a problem for you. You always need this as part of your overall strategy for threat and risk.
How AI is changing threat intelligence 35:40
Caspar: And we're getting close to the end, but can I ask the AI question? How is that changing the problem we're talking about?
Alex: It provides us with both challenges to overcome and opportunities. There's an enormous amount of content available online, which is only going to increase with the broad availability of AI technology in our day-to-day lives, and we're already seeing that impact in the amount of material we need to cover to provide a comprehensive picture of an organization's online threat environment.
However, it also provides opportunities — there are increases in the efficiency of investigative methods, which mean we can spend more time dealing with incidents of greater concern, and we're able to identify and spot patterns between pieces of commentary — where they're coming from, whether they're associated with specific threat actors, whether accounts or profiles are linked to one another. Those are things we can do and have been doing for a long time. The opportunity to leverage that technology to increase our efficiency means we're able to do more of that for our clients, and take even more sophisticated steps to get ahead of future developments in the threat intelligence space.
Caspar: So the jury is still out on whether AI will bring about the end of the world, but it has brought about the end of this podcast. I'd like to thank my guests, Shawn Van Slyke in Washington, DC; Terri Patterson of GE Aerospace, also in Washington, DC; and Alex Hillier here in London, for joining us on this episode of Ground Truth. Thank you for listening, however you consume this podcast, and do stay tuned for the next edition of Ground Truth in about a month from now. Bye for now.