
"VIP only: this feature needs monitoring"is a line that turns up in scoping documents, renewal notes and board actions all the time, usually written by someone who already knows the executive team is exposed but has not yet decided what that actually means in practice. VIP monitoring follows people. External attack surface management follows infrastructure. Both matter, and buying one while assuming it covers the other is the most common way UK security teams end up paying twice and still missing the finding that costs them money.
This is the operational build: who belongs on the list, what to watch per person, how to score it, what to do when something lands, and the UK GDPR footing the whole thing needs before the first report reaches a director's inbox.
A VIP monitoring programme builds a profile for each named individual and watches the open, deep and dark web for exposure tied to that person. Your external asset discovery work answers a different question: which domains, subdomains, IP ranges, cloud services and APIs are visible from the outside. One is entity-led. The other is infrastructure-led. They feed each other, but they are not substitutes.
Much of the search traffic around this topic comes from people expecting something closer to surveillance. VIP monitoring does not involve device access, reading private messages, intercepting calls or tracking location. It observes what is already exposed to an attacker doing external reconnaissance. Say that plainly to the executive, in writing, before you start. It removes most of the objection.
Lookalike domain detection sits in brand protection, DNS monitoring and VIP monitoring. Credential exposure sits in OSINT and dark web monitoring as well as VIP profiles. Before renewal, map each alert type to one owning source and turn the duplicates off. Two tools alerting on the same registered domain does not double your coverage. It doubles the noise, and noise is what kills these programmes.
Job title is a poor selector. Build the list from access and exposure instead.
The most attacked person on a VIP list is rarely the most senior. Executive assistants hold mailbox and calendar delegation, which means an attacker who reaches the EA effectively reaches the executive's diary, travel plans and correspondence. The finance approver who signs off payments is the person a whaling email is actually aimed at. Add heads of HR, who hold payroll and personal data, and non-executive directors carried across several boards, whose exposure at another organisation becomes your problem.
Some individuals need monitoring precisely because their exposure is sensitive: a director in a contested divorce, an executive who has received threats, someone whose personal circumstances would be damaging if circulated internally. Mark those profiles as guarded, restrict findings to a named two or three people, and keep them out of the general reporting pack. Access control on the findings is part of the programme design, not an afterthought.
Twelve people reviewed properly every quarter beats sixty people nobody reads. If the list has grown past the point where you can name every entry and why they are on it, it has stopped being a VIP programme and become a subscription.
Every profile should have two halves, because remediation ownership differs. Internal identity covers corporate email, work mobile, SSO accounts and any application-level logins. IT can force a reset, revoke sessions and enforce policy on all of it. External identity covers personal email, home address, family members, side businesses and personal social accounts. None of that can be fixed by a policy push. It needs the individual's cooperation and a very different conversation, usually one that starts with what you will not be doing.
The finding that causes real losses is almost never a forum post about the CEO. It is a stealer log entry from an executive's personal laptop containing corporate credentials saved in a home browser. Those credentials sit outside every corporate control. When the password policy fires and rotates the corporate account, the saved one does not move, because nobody knows it exists.
A worked example. A CFO's personal email address appears in an infostealer log alongside saved credentials for the company expenses portal, an application procured by finance, sitting outside SSO, with no MFA. A corporate password reset achieves nothing here. The fix is enforcing MFA on that specific application, revoking active sessions, and checking whether stolen session cookies allow re-entry without the password at all. Session tokens survive password changes. Plenty of teams learn that the hard way.
Watch for lookalike and typo-variant domains, unregistered variants of the executive's name, fake LinkedIn and X profiles, and spoofed WhatsApp or Telegram accounts using their photograph. Certificate transparency logs and new-registration feeds surface most of these before the first email is sent, which is the only window that matters.
Document metadata naming individuals, conference biographies listing personal email addresses, data broker profiles assembling home address and relatives, and Companies House director records. UK directors' usual residential addresses often sit in plain sight on the register. An SR01 application removes the usual residential address from public view, and it is a cheap, one-off action that cuts a data point used in doxxing, SIM swap attempts and physical security planning. GOV.UK sets out the process for restricting the disclosure of your information; check the current forms and fees before advising, as Companies House processes have been changing under the Economic Crime and Corporate Transparency Act. Put it in the VIP onboarding checklist alongside the welcome briefing.
Most raw VIP mentions are namesakes, syndicated versions of the same news article, and breach dumps recirculated under a new title. Entity disambiguation and deduplication matter more than the number of sources a vendor claims to cover. If a platform surfaces four hundred mentions of a common surname and expects your analyst to sort it out, you have bought a workload, not a control. Alert fatigue closes these programmes faster than any missed finding.
Agree three tiers in advance and write them down. A live credential on a payment-capable account triggers a same-day call. A lookalike domain with MX records configured triggers a same-day call. An old breach entry with no corporate reuse waits for the weekly summary. A data broker listing with no new detail is logged and left alone until the quarterly review.
Report resolution times, credential validity rates and the number of profiles with unresolved high findings. A count of mentions tells the board nothing except how loud the internet is.
Scope the reset to every account sharing that password or email, revoke active sessions on the affected service, enforce MFA at the application level, and check conditional access rules. Then have the personal device conversation. It is awkward, it works better when the individual has been briefed at onboarding, and it is far easier if you can show the exact saved-credential entry rather than issuing a general warning about home browsers.
Impersonation is time-sensitive, not continuous. Lookalike domains and fake profiles cluster around results announcements, funding news and acquisitions. Capture evidence the moment the domain is spotted, because by the time a whaling email lands the site has usually been altered or parked.
A concrete pattern: a domain differing from yours by a single character is registered eight days before a results announcement, then used to send payment redirection emails to two people in accounts payable. Capture the RDAP or WHOIS record, full-page screenshots, DNS and MX configuration and hosting details first. Escalate to the registrar and hosting provider abuse channels in parallel, report the sending infrastructure, and for persistent cases consider Nominet's Dispute Resolution Service for.uk names or a UDRP filing for gTLDs. Registrar escalation is usually faster than any dispute process.
Whaling does not land on the executive. It lands on the EA and on finance. The moment an executive is impersonated, brief those two groups directly, name the domain, and reconfirm the callback procedure for any bank detail change. That single step blocks more losses than the takedown does.
Feed outcomes back into the profile so resolved findings stop re-alerting. A stealer log entry that has been reset, session-revoked and MFA-enforced should be marked closed against that person, not resurfaced next month when the same corpus is reindexed.
Monitoring identified individuals is personal data processing under UK GDPR and the Data Protection Act 2018. The usual lawful basis is legitimate interests, supported by a documented legitimate interests assessment covering purpose, necessity and the balancing test. The ICO's guidance on legitimate interests sets out what that assessment needs to contain. Systematic monitoring of individuals will normally warrant a data protection impact assessment too, and the ICO's employment practices guidance on monitoring workers is the reference point for how transparency should be handled.
Three practical rules keep the programme defensible. Tell each individual in writing what is monitored and what is not, before the first report. Minimise: monitor family members only where there is a specific, justified reason, and hold the smallest set of personal identifiers that makes disambiguation possible. Set retention limits and restrict who can view guarded profiles, with access logged.
For assurance, map the programme to ISO 27001 Annex A controls covering personnel and supplier security, and report it in the language the NCSC's board toolkit encourages: risk owned, action taken, residual exposure. Boards respond to that far better than to source counts.
Run two outputs. A short per-person report, shared with that individual and their remediation owner. A management summary for the board with no personal detail beyond aggregate risk. Between reports, send a weekly "what changed"update rather than a full re-issue, on screen, as PDF or scheduled by email.
Route actionable findings into Slack, Microsoft Teams, Jira or your ticketing queue so ownership is explicit and the clock is visible. Pair the people-led view with continuous monitoring of your public-facing assets so an impersonation domain and a newly exposed service are triaged in the same queue.
Review the list itself every quarter: joiners, leavers, promotions, new board seats, a newly public spokesperson. VIP monitoring only stays useful while the list reflects who is actually being targeted, and that changes faster than most organisations expect. If you are scoping this now, talk through the profile design before you buy sources, because the selection and scoring work is what turns "VIP only, this feature needs monitoring"into a control the board can rely on.
VIP monitoring is continuous, entity-led monitoring of named high-profile individuals for exposure across breach data, infostealer logs, dark web forums and marketplaces, Telegram channels, social media, data brokers and public registers. It builds a profile per person and alerts when new exposure appears. It does not involve device access, message interception or location tracking.
Select on access and visibility rather than title: payment approvers, privileged administrators, publicly visible spokespeople, anyone involved in M&A or litigation, and named officers on public filings. Add the roles most lists omit, particularly executive assistants with mailbox and calendar delegation, finance approvers, heads of HR and non-executive directors sitting on multiple boards. Keep it small enough to review properly each quarter.
No. A dark web monitoring service watches criminal sources for your organisation's data generally. VIP monitoring uses some of those same sources but is scoped to named individuals and includes impersonation, public register and data broker exposure. External attack surface management is different again, mapping internet facing infrastructure rather than people.
It can be, with the right footing. Establish and document a lawful basis under UK GDPR and the Data Protection Act 2018, normally legitimate interests supported by a legitimate interests assessment, and complete a data protection impact assessment for systematic monitoring. Tell the individual in writing what is and is not monitored, minimise the personal and family data held, set retention limits, and restrict access to sensitive profiles.
High-severity findings such as a live credential on a payment-capable account or a configured lookalike domain should be actioned the same day. Everything else fits a weekly change summary, with a management view for the board on your normal reporting cycle. Review the VIP list itself quarterly to reflect joiners, leavers, promotions and changes in public exposure.
Unlock full visibility of your external attack surface with DarkInvader’s continuous, real-time monitoring. Create your free account to discover unknown assets, detect emerging risks and stay ahead of potential threats before attackers can exploit them.
Create My Free Account