Protect the VIP — 0:
The $25.6M Blind Spot
In January 2024, a finance employee at Arup — a British multinational engineering firm — received an email from an account claiming to be the company's CFO, requesting a series of confidential transactions. He suspected phishing. Then came the video call.
Everyone on it looked right. Sounded right. The CFO was there. So were several colleagues from other offices — synchronized facial movement, natural voices, the ordinary friction of a real meeting. Over the course of that call, the employee authorized fifteen separate transfers. Total: $25.6 million.
Every person on that call was a fabrication. Not stolen footage, not a pre-recorded clip — a live, interactive, AI-generated impersonation of people who were never in the room.
By the time anyone at Arup verified the request through an actual channel, the money had already moved through several jurisdictions. It hasn't come back.
This wasn't a technology failure. The deepfake worked exactly as advertised — that's not news anymore, it's a commodity. What failed was upstream of the technology: nobody had mapped what needed protecting, from whom, or what a legitimate request from that CFO was supposed to look like when it actually mattered.
That's not a cybersecurity gap. That's the absence of a threat model.
Executive protection — the kind that covers both the inbox and the sidewalk — starts with the same five questions used everywhere from special access programs to counterintelligence: what has to stay protected, who wants it and why, where the gaps actually are, how bad it gets if they're exploited, and what you do about it before they are.
That process has a name: OPSEC. Five steps, developed for a different kind of battlefield, that map cleanly onto a modern executive's exposure. Applied backward to Arup, here's what each step would have caught.
// Step 1: Identify Critical Information
Strength is not the vulnerability. What strength is built on top of, is.
A supply chain doesn't fail at its strongest link. It fails at the vendor nobody was watching — the subcontractor three tiers down who never made it into the risk assessment. Executive protection works the same way. The VIP can be hardened, trained, disciplined. None of that matters if the vulnerability was never his to control in the first place.
Critical information, in this context, isn't classified documents or trade secrets. It's the answer to questions nobody thinks to protect: Where do the kids go to school? Is there a compulsion — gambling, an affair, an addiction to being seen? What does the person's past look like before they became the person on the letterhead?
None of this is inherently scandalous. That's not the point. The point is elicitation. Once a piece of personal information exists outside the VIP's control, nobody gets to decide — coldly, in advance — whether it will be used to pressure, embarrass, or coerce. The information doesn't need to be true, or even damaging on its own. It needs to be leverageable. That's the entire bar.
This is why the strongest people are sometimes the least protected. A reputation for being untouchable — sharp, feared, impenetrable — is armor built for a different threat model. It doesn't defend against a threat actor patient enough to earn trust first, and extract second.
This isn't theoretical. Years ago, I worked closely with someone who had built a reputation on being untouchable — sharp-tongued, feared, the kind of person whose approval nobody expected and nobody asked for twice. The reputation worked. It kept people at a distance, which is exactly what it was designed to do.
It took time, but eventually the distance closed. Not through any technique — just consistency, and enough of it that trust stopped being a decision and became a habit. What came out on the other side wasn't a weakness. It was a person, underneath armor that had been mistaken — by everyone, including him — for the whole picture.
We parted ways eventually. Tears, on both sides, which surprised neither of us by then. He taught me more than I can list here. I told him once that nobody knows the value of something until they've lost it — I meant it about him, and it still holds a decade later.
The lesson isn't sentimental. It's operational: if a stranger with patience and no formal training can get there, a threat actor with a specific objective and no time pressure gets there faster. The armor was never the vulnerability. The unmapped person underneath it always was.
// Step 2: Analyze Threats
There are two different problems here, and treating them as one is where most assessments fail.
The first is the unknown threat landscape. You can't rank what you haven't mapped. Before any threat gets prioritized, the question is coverage: what percentage of the exposed surface is actually monitored, and where do the dead zones sit — the places nobody's watching because nobody thought to look. This is attack surface work before it's threat work.
The second is the threat that already has a name. A disclosed threat — "subject X is exposed because of Y" — already carries its own reconnaissance embedded in it. Here the method reverses: work backward from what the threat reveals about itself. Names, companies, projects, personal situations surface along the way. Data builds the picture, and the more of it accumulates, the more it tells its own story — which is why even irrelevant details eventually stop being irrelevant.
Vector is secondary to this. A vulnerability with real depth matters more than the method used to reach it — the same way a critical zero-day sitting behind a firewall carries a lower real-world risk than its severity rating suggests, for as long as it stays unexposed. Exposure calculates risk. Severity alone doesn't.
Separating signal from noise runs on two different tracks, depending on access.
With direct access, HUMINT tradecraft applies without modification: everyone has a wound. Find it, and the rest resolves itself. Be paternal with someone who wants to be treated like a son. Be a peer to someone whose ambition outpaces their competence. Show weakness to someone who feeds on authority. The approach adapts to the target — the objective doesn't. Once the wound is found, one precise question is enough. Noise goes quiet. Severity declares itself.
Without direct access, the read comes from precedent and movement. Has this actor threatened before — and did they follow through? A dog that barks doesn't bite. One that bites without barking is the actual risk. Watch for operational tells that move before the rhetoric does: logistics, positioning, assets relocating quietly while the public conversation hasn't caught up yet. A carrier group repositioned fifty kilometers off a coastline isn't an accident of scheduling — it's a message, delivered in a vocabulary that doesn't need translation. Actors capable of real threat don't gamble. They signal.
// Step 3: Analyze Vulnerabilities
Take a VIP with little or no advisory — the kind who leaves candy wrappers along the way without noticing. This is where OSINT does the heavy lifting: oversharing from years before anyone talked about data hygiene, plain carelessness, or a breach that surfaced information nobody meant to expose. Nothing escapes the lens. The only real limit is analyst expertise — a competent one goes exactly as far as they choose to go.
The pattern that shows up first, almost every time, is procedural. A LinkedIn profile with a photo, an email, a phone number — cross-referenced, that same data opens a Facebook account, and from there, the family's profiles. Or something more technical: no hardened device, no antivirus, work and personal life running through the same phone when two would solve it. A businessperson who could buy a hardware security key without noticing the expense, and doesn't. This is rarely a budget problem. It's an advisory gap, or plain resistance to changing habits that have never cost anything — yet.
Vulnerabilities don't only live in the person being protected. They live in whoever's doing the protecting.
I'll use myself, because parsing a vulnerability starts with naming it without flinching. I work best alone, or alongside one person at my level with clearly scoped tasks — no committee, no ambiguity about who owns what. For years I didn't see this as a limitation. It is one. It slows down anything that needs more hands moving in parallel, and I couldn't see it until it got pointed out enough times, with enough insistence, that ignoring it stopped being an option. Processing it took longer than finding it did. It still isn't fully resolved — it's managed.
The discipline is identical in both directions. Finding the gap in a VIP's coverage and finding the gap in your own working style is the same operation, aimed at a different mirror.
// Step 4: Assess Risk
Risk assessment isn't one process. It's calibrated to the room you're standing in.
In a lean environment — a startup running on short runway, one person against the whole ocean, no budget for anything past a basic SIEM — there's no time to fill out a formal risk-rating matrix nobody will read anyway. Security here isn't a product, it's a process that ships subproducts, and it only survives if you build ownership into the workflow itself. "Request your own pentest" as a step developers can't skip before anything hits prod. An OSINT front for the People team, so nobody gets hired without someone having looked. These aren't policies. They're code, and like any code, they need maintenance, bug fixes, and someone pushing adoption.
This is where experience replaces the matrix. You already know the largest volume of real-world attackers are script kiddies and juniors hunting their first bug bounty — which means an exposed SQL injection on a public endpoint is a bigger emergency than a well-hidden SSRF behind a misconfigured microservice header, even if a formal severity score says otherwise. The pieces sort themselves out once you know who's actually knocking.
A regulated environment runs on the opposite instinct. In PCI-DSS scope, the matrix gets filled — every field, every keystroke logged into a change control record. There's no shortcut here, and looking for one is its own risk.
Applied to Arup, in fairness first: the attack was sophisticated for its time. It's plausible the people responsible for building that company's security culture had no reason to think real-time multi-participant video deepfakes were even possible yet. That's a fair read of the moment.
Strip that away, though, and the real gap wasn't technical. It was the absence of a control and validation procedure — and the concentration of authority in a single point of failure. Here's the test: if the owner of the company emails me directly and says "Pablo, shut down all security controls" — that doesn't happen. Not because I refuse on principle, but because the request itself should trigger a protocol: I choose the channel based on how critical the ask is, I'm never the only one evaluating it, the reasoning gets documented, and the core team aligns before anything executes. Power never concentrates in one person. Ever.
Which is the actual lesson buried in Arup: phishing is a more dangerous vector today than SQL injection was in 2010 — not because the technology got smarter, but because the target moved from the database to the human authorizing the transfer, and most control frameworks never moved with it.
// Step 5: Apply Countermeasures
There's exactly one countermeasure for what happened at Arup, and it isn't a product: enforced deliberation. Some decisions earn the right to move slowly, and a transfer at that scale is one of them.
Call it old school if you want. Above a certain threshold, the move happens in a room, with everyone looking at each other, not through a screen. Minutes get taken. Every approval carries a name and a signature — an owner, not a rubber stamp. Meetings that "the wind carries away," with no record and no accountable signer, are exactly the gap that let fifteen transfers clear in a single day. A deepfake can fill a video call convincingly. It can't yet walk into a room and shake hands cheaply enough to make the attack economical. That's not nostalgia. That's raising the attacker's cost past the point where the math still works for them.
Prioritizing which countermeasure ships first runs on a different axis than which one matters most.
In a lean environment, the choice is the lowest-friction option — the one that ships without stalling the business — and the leader personally absorbs whatever risk is left over. You don't get to block the business from moving, in any direction, just because the security posture isn't finished. That's the job: carry the remainder yourself until the rest catches up.
In a regulated environment, the calculus inverts. Countermeasures show up as policy, under signature, with compliance sign-off and random audits when warranted. Friction isn't a cost to minimize here — it's the control.
// Where This Goes Next
The five steps above aren't unique to Arup. They're the same five this series applies, one at a time, to a different piece of the same problem: what gets exposed without anyone noticing (Chapter I), what runs unguarded on the device in your pocket (Chapter II), how you talk to the outside world without the conversation itself becoming the leak (Chapter III), who and what occupies your physical space (Chapter IV), and finally, what happens when the analyst reading the signals and the operator standing in the room have to become one function instead of two (Chapter V).
No blind spots. No exceptions. That starts with Chapter I.
Case details are drawn from public reporting on the Arup Hong Kong deepfake fraud, widely covered from February 2024 onward.