Site icon EP Wired – Executive Protection Magazine

The Illusion of Protection: Why Executive Security Program Development Fails Before the Threat Arrives

Security Program

Security Program

By Nic Moretto, SAS-AP® | Founder & CEO, TESS GLOBAL | Tactful Elite Security Solutions | Merritt Island, Florida 

The principal walks out of the hotel lobby at 7:14 a.m. Two agents greet him. A driver has the vehicle running at the curb. Everything looks exactly right. 

Except the advance team never walked the lobby. Nobody identified the two unmonitored entry points on the east side of the building. The threat assessment sitting in a shared folder was completed fourteen months ago and has not been opened since. The venue the principal is heading to has its own security director — and nobody has spoken to him. There is no protocol defining who makes the call if something happens in the transition between the hotel door and the vehicle door. 

Nothing happened that morning. The principal arrives safely. The team calls it a successful operation. 

They are wrong. They executed supervised movement, not a security program. In today’s threat environment, that distinction is the distance between protection and exposure. 

As of October 2025, incident volume targeting corporate executives had already doubled the total recorded in all of 2024 — the highest level on record according to the Security Executive Council’s Executive Targeting Report. The threat environment is not waiting for programs to catch up. 

This article is not about the threats that arrive. It is about the five structural gaps in executive security program development that create vulnerability before any threat actor identifies a target. 

SECTION 1 — WHAT A SECURITY PROGRAM ACTUALLY IS, AND WHAT MOST ORGANIZATIONS HAVE INSTEAD 

“Having security personnel is not the same as having a security program. One fills a post. The other fills a gap before it becomes a crisis.” 

There is a version of executive security most organizations recognize — a trained agent, a secure vehicle, a detail lead who has done this before. It is visible. It is reassuring. And in the current threat environment, it is not enough. 

The distinction between having security personnel and having a security program is not a matter of budget or headcount — it is a matter of architecture. A security program is a structured, documented, continuously updated system built before the threat arrives, functioning when the threat arrives, and evaluated after — because avoidance is the goal, not response. 

What most organizations have instead is a reactive posture dressed in the language of protection. When nothing happens, the program is declared effective. When something happens, the program is declared insufficient — and the budget is suddenly available. 

1.1 — The Presence Trap 

The presence trap is the most common failure in executive security program development — the organizational belief that visible security equals effective security. A suited agent at a door communicates security to the people inside the building. It communicates opportunity to a threat actor outside it, because a static, predictable, presence-based posture is a pattern. And patterns are the first thing an adversary maps. 

Intelligence-led security program development begins with the assumption that presence alone is a vulnerability, not a protection. The question is never “do we have someone there?” It is “does that person know what to look for, what to do when they find it, and who to tell in the next sixty seconds?” 

1.2 — Security Program Development Defined 

Security Program Development is the discipline of building the architecture behind the personnel — continuous intelligence gathering, advance work conducted as an intelligence function, protocols that define decision authority at every transition point, training cadence that operationally tests those protocols, EP-venue integration, COOP Security Support, and measurement systems that track upstream indicators rather than downstream incidents. 

This is the discipline that twenty-two years of operational experience in the security industry builds — and that TESS Global has executed across more than a decade of security program development and executive protection assignments, from high-consequence corporate environments to nine consecutive years as primary security provider for a major performing arts venue on Florida’s Space Coast. 

1.3 — Why the Distinction Matters Now More Than Ever 

According to ASIS International’s 2025 Executive Protection research — conducted across 500-plus security professionals worldwide — 42% of organizations report significantly more emphasis on executive protection compared to eighteen months prior. High-profile incidents drove that shift for 69% of respondents; a general increase in public threats for 72%. The demand for executive security has accelerated. The supply of genuine security program development has not kept pace. 

That gap is where the five failure points live. 

Defining what a security program actually is makes the next question unavoidable — why do so many organizations not have one? 

SECTION 2 — THE PRE-THREAT FAILURE FRAMEWORK 

Most security program failures are not discovered during an incident. They are discovered after one — when the post-incident review reveals that the structural gap existed for months or years before the threat actor ever identified the target. The following five failure points are operational patterns observed across more than a decade of security program development and executive protection assignments. Each one is fixable. None require additional headcount or budget. All require architectural discipline. 

Failure Point 1 — The Threat Assessment That Never Gets Updated 

“A threat assessment that was accurate twelve months ago is not an assessment — it is a historical document.” 

Every serious EP program begins with a threat assessment. It documents the principal’s risk profile, identifies known threat actors, maps vulnerabilities across the principal’s routine, and establishes the baseline from which all protective decisions are made. 

Then it gets filed. 

The threat environment does not file itself. A disgruntled former employee who rated low eighteen months ago may have spent that time building a grievance, acquiring capability, and mapping the principal’s patterns. A geopolitical shift can change international travel risk in seventy-two hours. An executive’s social media footprint can expand personal exposure significantly between assessment cycles. 

A threat assessment is not a deliverable. It is a living document with a maintenance schedule. Intelligence-led security program development treats threat assessment as a continuous function — not an annual report. 

THE STANDARD: Assessments refreshed on a defined cycle, triggered by principal life changes, environmental shifts, or new threat intelligence — not by calendar alone. 

Failure Point 2 — Advance Work Treated as Logistics, Not Intelligence 

“Advance work that stops at the venue floor plan and the motorcade route is logistics. Advance work that maps sightlines, identifies behavioral anomalies, and stress-tests assumptions is intelligence.” 

Advance work is the most important intelligence function in executive protection. It is also the most consistently reduced to a logistics checklist. 

The advance team confirms the venue. Walks the route. Locates the nearest hospital. And considers the job done. What that process does not do is what advance work as an intelligence discipline actually requires: systematic vulnerability mapping of every transition point, behavioral baseline establishment so anomalies are identifiable on the day, sightline analysis identifying concealment positions and observation advantages, integration of current threat intelligence into the specific venue and time context, and stress-testing of every assumption the detail will rely on — including the ones that seem obvious. 

As explored in Situational Awareness at Scale — published in EP Wired’s May 2026 issue — situational awareness is an active intelligence discipline requiring a structured system for observation, interpretation, and response. That system must be embedded in the advance function before the principal ever arrives. An advance team not running a situational awareness protocol is doing reconnaissance theater, not advance work. 

THE STANDARD: Advance work conducted as a structured intelligence function producing five documented outputs — vulnerability map, sightline analysis, anomaly baseline, transition point protocol, and threat intelligence integration note. 

Failure Point 3 — The OSINT Gap: The Most Powerful Intelligence Tool in EP That Most Programs Never Actually Use 

“OSINT is the most powerful intelligence tool available to the EP practitioner today. It is also the most consistently unused.” 

Open Source Intelligence — OSINT — is the systematic collection, processing, and analysis of publicly available information to produce actionable threat intelligence. Court records. Property records. Corporate filings. Social media platforms. Open web mentions. Dark web adjacent signals. Geospatial data. Pattern-of-life indicators derived from publicly available sources. 

All of it is legal. All of it is accessible. Most of it was ignored. 

According to ASIS International’s 2025 Executive Protection research, real-time OSINT was ranked as a critical capability by 63% of EP professionals surveyed — yet only 50% reported having full technical capability to deploy it. That 13-point gap between recognizing OSINT as essential and actually operationalizing it is not a budget problem. It is an architecture problem. 

The consequence is a systematic blind spot. Threat actors operate in the digital domain before they operate in the physical one. A fixated individual builds an online footprint — search patterns, social media behavior, forum participation — weeks or months before moving toward physical action. That footprint is findable. It requires a structured OSINT function to find it, a protocol to evaluate it, and an integration pathway to translate the finding into a physical posture adjustment. 

As covered in Advanced Force Multipliers — published in EP Wired’s June 2026 issue — OSINT is not a supplemental function. It is a primary intelligence discipline that most EP programs treat as optional. The programs that treat it as optional are the programs that get surprised. 

AI-integrated security operations represent the next evolution — augmenting manual collection with scalable pattern recognition, real-time alerting, and continuous monitoring at a scale no manual process can match. 

THE STANDARD: A designated OSINT function with defined collection parameters, a protocol for evaluating findings against current threat assessments, a clear chain of custody from collection to detail briefing, and an integration pathway that translates digital threat signals into physical posture adjustments. 

OSINT LEGAL DISCLAIMER 

⚠ LEGAL DISCLAIMER — OSINT USE: All Open Source Intelligence collection activities described in this article must be conducted in strict compliance with applicable federal, state, and local privacy laws, including but not limited to the Electronic Communications Privacy Act (ECPA), the Computer Fraud and Abuse Act (CFAA), and applicable state privacy statutes. Platform terms of service must be observed at all times. OSINT collection activities involving individuals may implicate privacy rights, consumer protection laws, and data protection regulations. Nothing in this article constitutes legal advice. Security practitioners are strongly advised to consult qualified legal counsel before initiating any intelligence collection activities involving individuals, organizations, or protected systems. The tools and techniques referenced herein are for lawful, ethical, and professional use only. 

 FIGURE 1 — OSINT FOR THE EP PRACTITIONER: A TIERED  TOOLKIT 

Open Source Intelligence is a discipline, not a software purchase. Each tool is evaluated across four attributes: Function, Cost Tier, Difficulty Tier, and Primary EP Use Case. Selection should be based on program size, analyst capability, and operational requirement. 

Maltego  |  Relationship & Network Mapping Function: Visualizes relationships between people, organizations, locations, and digital identities. Maps social networks, corporate structures, and digital footprints in a graphical interface. Cost Tier: Freemium — Community edition free; commercial license for advanced data sources.     Difficulty: Intermediate — Requires analyst training to extract full investigative value. Primary EP Use Case: Building threat actor relationship maps during threat assessment cycles. Identifying network connections between a known threat actor and the principal’s environment. 

Liferaft Navigator  |  Real-Time Threat Monitoring Function: Purpose-built for EP and physical security teams. Monitors surface, deep, and dark web in real time with geospatial visualization — connects online threat signals to real-world locations and events. Cost Tier: Paid — Subscription platform, enterprise pricing.     Difficulty: Field Ready — Designed for operational security teams, interface optimized for physical security use cases. Primary EP Use Case: Real-time monitoring during principal movements and events. Connecting online threat signals to specific locations and time windows. 

Flashpoint  |  Real-Time Threat Monitoring Function: Combines social media intelligence with deep and dark web monitoring. Provides early warning signals from closed forums, encrypted channels, and criminal marketplace discussions. Cost Tier: Paid — Enterprise subscription.     Difficulty: Intermediate — Requires security analyst familiarity to interpret deep and dark web signal context. Primary EP Use Case: Identifying threat actors who have moved from surface-level activity into deeper planning channels. Early warning for organized threat activity targeting named executives. 

ZeroFox  |  Real-Time Threat Monitoring Function: Social media threat monitoring, executive digital protection, and impersonation detection. Monitors executive names and personal identifiers across social platforms for threatening content. Cost Tier: Paid — Enterprise platform with modular pricing.     Difficulty: Field Ready — Dashboard-oriented interface accessible without deep analyst background. Primary EP Use Case: Continuous monitoring of executive digital exposure. Detecting threatening social media content and impersonation attempts before they escalate to physical action. 

Spokeo / BeenVerified  |  People Search & Digital Exposure Function: Aggregates publicly available personal data — addresses, phone numbers, associates, property records, and court records — into searchable profiles. Cost Tier: Freemium — Limited free search; low-cost subscription for full access.     Difficulty: Field Ready — No technical skill required. Consumer-grade interface with professional EP applications. Primary EP Use Case: Principal digital footprint assessment — understanding exactly what a threat actor can find about the principal in under sixty seconds of searching. 

OSINT Industries  |  People Search & Digital Exposure Function: Comprehensive executive digital footprint scanning with breach data integration. Runs full-spectrum scan of online presence including social media, public documents, and breached credentials. Cost Tier: Freemium — Free tier available; paid for full capability.     Difficulty: Field Ready — Designed for accessible use without deep analyst background. Primary EP Use Case: Principal breach exposure assessment. Identifying leaked personal data — addresses, phone numbers, geolocation tags — that creates physical vulnerability. 

Social Searcher  |  Social Media Intelligence Function: Cross-platform social media monitoring. Tracks keywords, hashtags, user profiles, and brand mentions across multiple social networks simultaneously. Cost Tier: Freemium — Free tier for basic monitoring; paid for real-time alerts and historical data.     Difficulty: Field Ready — Simple interface accessible to any trained EP practitioner. Primary EP Use Case: Monitoring principal name mentions for threatening content. Event-specific monitoring for threat signals in the hours before a public appearance. 

Google Dorking  |  No-Cost Technique Function: Uses advanced Google search syntax to surface publicly indexed information that standard searches miss — exposed documents, cached pages, organizational charts, location metadata embedded in images. Cost Tier: Free — Zero cost. Requires only a Google account and practitioner skill.     Difficulty: Intermediate — Syntax requires learning and practice. Significantly more powerful than standard search when used correctly. Primary EP Use Case: Advance work intelligence gathering on venues, events, and individuals. Surfacing publicly available information a standard search does not return. 

Have I Been Pwned  |  No-Cost Technique Function: Checks whether an email address or phone number has been exposed in a known data breach. Covers thousands of breach datasets. Cost Tier: Free — Zero cost for individual checks.     Difficulty: Field Ready — Single input, immediate output. No technical skill required. Primary EP Use Case: Principal breach exposure check. Identifying whether the principal’s personal or professional email addresses have been compromised — creating credential, identity, and physical vulnerability. 

ExifTool  |  No-Cost Technique Function: Extracts metadata from images, video, audio, and documents — including timestamps, geolocation coordinates, device identifiers, and edit history. Cost Tier: Free — Open source, zero cost.     Difficulty: Intermediate — Command-line interface. Requires basic technical familiarity to operate effectively. Primary EP Use Case: Extracting geolocation data from images posted publicly by or about the principal. Identifying inadvertent location disclosure embedded in social media photography. 

 Failure Point 4 — Event Security and EP Integration Failure 

“When EP protocols and venue security protocols contradict each other in real time, someone makes a decision on the spot. That someone should not be making it for the first time.” 

Executive protection details and venue security teams operate from different command structures, different protocols, different communication channels, and different definitions of success. The EP detail’s priority is the principal. The venue security team’s priority is the venue. In normal conditions, those priorities coexist. At the moment they conflict — and they will conflict — the absence of a pre-established integration framework produces a command vacuum at exactly the wrong time. 

In nine years as primary security provider for a major performing arts venue with over 150 operations annually, the most consistent operational gap observed was not the absence of trained personnel on either side. It was the absence of a unified command framework defining decision authority at the seam between the EP detail and the venue security operation. 

Who has override authority when the EP detail’s extraction route conflicts with the venue’s emergency egress plan? Who makes the call when the detail lead identifies a threat the venue security director has not yet assessed? Who briefs whom, in what sequence, when an incident begins to develop? These are not questions to answer for the first time during an incident. 

THE STANDARD: A pre-event integration protocol produced before every significant operation defining unified command structure, communication channels, decision authority at every transition point, and conflict resolution procedures when EP and venue security priorities diverge.

Failure Point 5 — The Program That Exists Only on Paper 

“A protocol that has never been trained is not a protocol. It is a document waiting to fail under pressure.” 

The most dangerous program in executive security is the one that looks complete from the outside. The binder is full. The protocols are written. The threat assessment is current. None of it has ever been tested under conditions that approximate reality. 

Protocols fail under pressure for one reason: the people executing them have only ever read them, never run them. A detail lead who has run the extraction protocol twenty times in training executes it in four seconds under pressure. A detail lead who has read it twice executes four seconds of hesitation followed by improvisation. 

COOP Security Support — Continuity of Operations Security Support — is the component of program architecture that ensures the program does not collapse when the primary detail lead is unavailable, when a threat scenario forces operational restructuring, or when an incident creates cascading disruptions. Most EP programs are built around people, not architecture. When the key person is unavailable, the program becomes that person’s institutional knowledge — inaccessible at exactly the moment it is most needed. 

A program built on architecture rather than personnel survives personnel changes. It survives operational disruptions. It survives incidents. That is the definition of a mature security program. 

THE STANDARD: A documented training cadence that tests every protocol on a defined schedule, a COOP Security Support architecture ensuring program continuity independent of any single individual, and a post-exercise review process that identifies gaps before a real incident does. 

Each of these failure points is fixable. Not with more personnel. Not with more budget. With better program architecture. 

 SECTION 3 — WHAT INTELLIGENCE-LED SECURITY PROGRAM DEVELOPMENT ACTUALLY LOOKS LIKE 

“Intelligence-led security does not begin when the threat arrives. It begins ninety days before the principal’s next public appearance.” 

The five failure points share a common cause — programs built around personnel deployment rather than program architecture. The fix is the architecture of intelligence-led security program development — a structured, documented, continuously updated system that functions before, during, and after every operational assignment. 

3.1 — The Intelligence Cycle and Living Threat Assessment 

The intelligence cycle — Collection, Processing, Analysis, Dissemination, Feedback — is the operational backbone of every mature security program. In a security program context, it operates continuously, not event-by-event. The threat assessment is its primary product, updated when the principal’s circumstances change, when the geopolitical environment shifts, or on a defined minimum calendar cycle. AI-integrated security operations enter at this layer — automating collection and processing phases to augment analyst judgment, not replace it. 

3.2 — The Advance Function as an Intelligence Discipline 

Every advance produces five documented outputs: vulnerability map, sightline analysis, behavioral anomaly baseline, transition point protocol, and threat intelligence integration note. These feed directly into the pre-operation briefing and become part of the program’s operational record — not a checklist filed and forgotten. 

3.3 — The OSINT Function — From Gathering to Operationalizing 

A designated OSINT function is built into the program architecture — not assigned ad hoc to whoever has time. Collection parameters are defined. Evaluation protocols are documented. The chain of custody from finding to detail briefing is established and tested. The function operates continuously — not only when a specific threat has been identified. 

3.4 — Protocol Integration — EP Detail and Venue Security Unified Command 

Every significant operation includes a pre-event integration protocol developed jointly with the venue security team. Unified command structure is established before the operation begins. Communication channels confirmed. Decision authority at every transition point defined in writing. Conflict resolution procedures agreed upon before they are needed — not improvised when they arise. 

3.5 — Training Cadence, Operational Readiness, and After Action Review 

A defined training schedule tests every protocol under realistic conditions on a recurring cycle — tabletop exercises for complex scenarios, live run-throughs for transition point protocols, integration exercises with venue security teams before significant operations. 

The training cycle is not complete when the exercise ends. It is complete when the After Action Review is documented, and the findings are translated into protocol updates. The same standard applies to every operational assignment. Missed indicators, unnecessary exposure, or communication gaps are not failures to minimize — they are intelligence to capture and close. 

The AAR is the mechanism by which a security program learns from itself. A program without a systematic AAR process accumulates experience without extracting wisdom from it. Every operation — successful or not — produces intelligence. The AAR is how that intelligence survives beyond the memory of the individual who held it. 

3.6 — Continuity of Protection — COOP Security Support as Program Architecture 

A mature security program does not depend on any single individual for its continuity. COOP Security Support architecture documents the program’s operational knowledge independently of the personnel who hold it — ensuring the program continues to function when the primary detail lead is unavailable, when an incident forces operational restructuring, or when cascading disruptions challenge multiple components simultaneously. This is not a contingency plan. It is a design standard. 

Building this program is the practitioner’s responsibility. Funding it is the organization’s. That conversation requires a different language. 

SECTION 4 — THE PROGRAM DEVELOPMENT CONVERSATION NO ONE IS HAVING WITH THE C-SUITE 

“The question boards are asking is not whether their executive has a security detail. It is whether their executive has a security program.” 

The organizational conversation about executive security has changed. Median spending on executive security climbed nearly 120% to approximately $95,000 (Equilar), while 34% of S&P 500 firms disclosed personal security perks by mid-2025 (Bloomberg Law) — a 21% year-over-year increase. Boards are funding security. The question is what they are funding. 

The challenge is not making the case for protection — the threat environment has made that case. The challenge is making the case for program development over personnel deployment. Personnel deployment is visible and immediately measurable. Program development is architectural, and its value is measured in prevented incidents, which by definition do not appear in the incident log. 

The language that works at the board level frames security program development as enterprise risk management. Executive contribution accounts for 30% of a company’s value according to research surveying more than 2,500 security chiefs at companies with combined revenue exceeding $25 trillion. A security program protecting that contribution is not a cost center. It is a risk management investment — measured in leadership continuity, operational stability, and the market confidence that does not collapse when the principal walks safely from a venue a threat actor had mapped. 

The conversation security professionals need to be having with the C-suite is about program architecture. What does our current program consist of? What are its documented components? Where are the structural gaps? What would it cost to close them? What is the risk-adjusted cost of leaving them open? That conversation requires the security professional to have done the program development work first — because you cannot audit a gap in a program that does not exist as a documented architecture. 

Once the C-suite funds the program, they will ask one question: how do we know it is working? 

SECTION 5 — MEASURING WHAT ACTUALLY MATTERS 

“If your only metric is whether something happened, you are measuring luck, not protection.” 

Most EP programs measure outputs — incidents responded to, hours on post, personnel deployed. These tell you what the program did after something occurred. They tell you nothing about structural health before the next threat arrives. A program built on Security Program Development and Intelligence-Led Security measures upstream indicators instead. 

Metric 1 — Threat Assessment Currency When was it last updated? What triggered it? What changed? A current, triggered assessment means the program is actively processing its threat environment. A stale one means the program is operating on outdated intelligence regardless of personnel deployed. Metric 2 — Advance Intelligence Output Quality Does every significant operation produce all five documented advance outputs? If yes, the program’s pre-threat intelligence architecture is functioning. If not, the program is operating on logistics, not intelligence. Metric 3 — OSINT Function Activity Is the function running continuously? How many collection cycles in the last thirty days? How many findings evaluated? How many triggered a protocol response? An OSINT function activated only reactively is a research capability sitting unused. Metric 4 — Protocol Training Frequency How many protocols trained in the last ninety days? How many tabletop exercises conducted? How many integration exercises with venue security teams? A program that cannot answer these questions has a training gap — regardless of how well its protocols are written. Metric 5 — Integration Protocol Coverage What percentage of significant operations in the last twelve months included a pre-event integration protocol developed jointly with the venue security team? This metric exposes the EP-venue integration gap more directly than any incident report ever will. Metric 6 — COOP Architecture Status Is the COOP Security Support architecture documented, current, and tested? Can the program function if the primary detail lead is unavailable today? If the answer is no, the program’s continuity is a single point of failure. Metric 7 — AAR Completion Rate and Action Item Close-Out What percentage of operations and training exercises produced a documented After Action Review? Of the action items generated — protocol updates, training gaps, communication failures, route adjustments — what percentage were formally closed out? An AAR that generates action items nobody acts on is documentation theater. An AAR process with strong close-out rates is a program actively improving itself between incidents. 

These seven metrics require no sophisticated technology. They require discipline — the discipline to measure what the program actually does rather than what it looks like from the outside. 

The questions practitioners ask most often about security program development deserve direct answers. 

SECTION 6 — FREQUENTLY ASKED QUESTIONS 

FAQ 1 — What is the difference between having security personnel and having a security program? Security personnel fill posts. A security program fills the gaps posts cannot cover — the intelligence function that identifies threats before they arrive, the advance work that maps vulnerabilities before the principal walks in, the protocols that define decision authority at every transition point, and the training cadence that ensures those protocols function under pressure. Personnel without program architecture are the most expensive form of reactive security available. Both are required. The program comes first.FAQ 2 — How often should an executive threat assessment be updated? There is no universal calendar answer. Any program updating on a fixed annual schedule is not running an intelligence-led process. Quarterly review is a reasonable minimum baseline — with immediate updates triggered by any of the following: a significant change in the principal’s public profile or controversy exposure, a new threat actor identification, a geopolitical shift affecting the principal’s operating territory, a routine change creating new pattern exposure, or any direct threat communication regardless of assessed credibility. The assessment is a living document. It should read like one. FAQ 3 — What is OSINT and how does it apply to executive protection programs? Open Source Intelligence is the systematic collection, processing, and analysis of publicly available information to produce actionable threat intelligence. In an EP context that means monitoring the principal’s digital exposure, identifying threat actor behavioral indicators across open web and social media platforms, assessing venue and event-specific threat signals, and maintaining continuous situational awareness through publicly available data. Sixty-three percent of EP professionals rate real-time OSINT as critical — yet only 50% have full capability to deploy it. The OSINT Toolkit in this article maps specific tools and techniques at every program size and budget level. FAQ 4 — What should advance work include beyond logistics and route planning? Advance work conducted as an intelligence discipline — as explored in Situational Awareness at Scale, EP Wired May 2026 — produces five documented outputs: a vulnerability map of every transition point, a sightline analysis identifying concealment positions and observation advantages, a behavioral anomaly baseline for the venue, a transition point protocol defining decision authority at every handoff, and a threat intelligence integration note connecting current intelligence to the specific venue and time context. An advance team that does not produce these outputs completed a reconnaissance trip, not an advance. FAQ 5 — How do you measure whether an executive protection program is actually working? Stop measuring incidents responded to. Start measuring upstream indicators: threat assessment currency, advance intelligence output quality, OSINT function activity, protocol training frequency, integration protocol coverage, COOP architecture status, and AAR completion rate. A program with strong upstream metrics and zero incidents is a functioning program. A program with zero incidents and no upstream metrics is a lucky one. Luck is not a security posture. FAQ 6 — What is intelligence-led security and how does it differ from traditional executive protection? Traditional executive protection is built around the principal’s physical safety at the point of exposure — close protection, secure movement, incident response. Intelligence-led security is built around the threat environment before the point of exposure — continuous intelligence gathering, proactive threat assessment, advance work as an intelligence discipline, and OSINT-driven early warning. The difference is not replacing physical protection. It is making physical protection the last line of defense rather than the only one. Security Program Development builds the architecture between the threat environment and the principal — filling the space where most programs have nothing but presence and hope. 

Every answer above points to the same conclusion. 

THE STANDARD HAS CHANGED. HAS YOUR PROGRAM? 

Return to the principal walking out of the hotel lobby at 7:14 a.m. 

Two agents greet him. A running vehicle. Everything that looks right. 

Was the program built — or the appearance of one? Someone walked that lobby as an intelligence function before the principal stepped into it. The threat assessment was current when the detail lead read it this morning. The OSINT function cleared the seventy-two-hour window before this movement. Every member of the detail has run the door-to-vehicle protocol under realistic conditions. The AAR from the last operation produced closed action items before this one began. The program functions tonight if the detail lead is unavailable tomorrow. 

Nothing happened that morning. That is the goal. But nothing happening is only evidence of a functioning program when the program was actually built to prevent something from happening.  

The threat environment in 2026 is not waiting for programs to evolve. Incident volume targeting corporate executives doubled in a single year. The threats that arrived did not appear without warning — they developed in the digital domain, gained momentum through observable indicators, and exploited gaps that a properly architected program would have closed. 

Build the program. Not the appearance of one. 

The standard has changed. The question is whether yours has. 


 About The Author:  

Nic Moretto SAS-AP® | Founder & CEO, TESS GLOBAL | Tactful Elite Security Solutions Merritt Island, Florida   

Nic Moretto, SAS-AP® is the Founder & CEO of TESS GLOBAL | Tactful Elite Security Solutions, a BBB A+ Accredited, Florida-licensed security agency headquartered on Florida’s Space Coast, operating since 2014 and recognized as a Top 3 Space Coast Security Guard Service in both 2025 and 2026. TESS Global specializes in Intelligence-Led Security, Security Program Development, and COOP Security Support for high-consequence environments. 

With over twenty-two years of experience across executive protection, armed security, and security program development, Nic holds multiple Florida state licenses including Class B, C, D, DI, and G, and carries the Situational Awareness Advanced Practitioner (SAS-AP®) designation through the Arcuri Group. He has built a reputation for proactive, intelligence-driven security across Florida’s Space Coast and Central Florida region. 

A monthly contributing author to EP Wired and an active voice in operational preparedness and modern security program development, Nic is the author of Situational Awareness at Scale (EP Wired, May 2026) and Advanced Force Multipliers(EP Wired, June 2026). 

LinkedIn: https://www.linkedin.com/in/nic-moretto-sas-ap/ 

Exit mobile version