How a protected person can be attacked through the people around them — and why a bodyguard alone is not enough.
The vehicle may be ready. The entrance checked. The phone secured. Yet one question remains that none of these measures can answer on its own: what happens when someone gets a trusted person to do the wrong thing? Not by force. Not by breaking down a door. With an instruction that looks like part of an ordinary working day.
It makes sense to judge a person’s protection not only by who may come close to them, but also by who can influence their schedule, pass on their information or make decisions in their name. It is precisely in this space that close protection, digital security, psychology and the way a company or household operates all meet.
The opening story and the other examples explicitly presented as hypothetical are illustrative. They do not describe actual Bodyguard Group® assignments. Public cases and expert findings are clearly distinguished and referenced; the source material was verified as of 16 September 2026.
01 — Everything was ready. Then the message came.
It is 5.42 pm.
The driver is waiting outside the hotel. The client is finishing a meeting. The evening programme is confirmed, the protection team knows the arrival point and reception knows whom to expect. There are only a few minutes left before departure.
The assistant receives a voice message. It sounds like the client. It concerns a change to the programme that really was discussed during the day. It contains no threats, no strange links and no request for a password. It asks only for an organisational adjustment: a different stop first, a different way of arriving and fewer people at the next meeting.
The assistant does not want to interrupt. She knows the client hates unnecessary phone calls during meetings. So she turns the instruction into a brief message for the driver and the protection team leader.
The driver is no longer assessing the original voice message. He is receiving an instruction from the assistant he deals with every day. The team leader, in turn, sees that the transport side has already accepted the new information. Everyone is cooperating. Each of them has the impression that someone earlier in the chain has checked it.
But nobody can give a precise answer to four questions: who actually issued the change, what they were authorised to do, what exactly they approved, and whether that approval also covers the security implications of the change.
In this hypothetical situation, we do not yet know whether it is fraud. It may be a genuine message, an imitated voice, a compromised account or a simple misunderstanding. And that is precisely the point. The person on the ground does not have to uncover the whole story within a few seconds. They need to recognise whether they have a sufficient basis for a decision.
A security problem does not begin only when an attacker has been proven. It also begins when a significant instruction is given more authority than has actually been verified.

02 — Trusting a person is not the same as approving every instruction they give
In everyday language, several different things can easily hide behind a single sentence: but we know this person.
Yet knowing someone, verifying their identity and accepting a specific decision are not the same act. Information security distinguishes between authentication, meaning the verification of identity, and authorisation, meaning the permission granted or the decision on access. This distinction is also reflected in NIST terminology. [1], [2]
For close protection, it is useful to translate this idea into day-to-day operations.
Are we really communicating with the assistant? Is the assistant allowed to change today’s meeting place? Is she also allowed to decide that the protection team will be reduced? And did she understand exactly what the client asked for?
A yes to the first question does not automatically guarantee the others.
In the same way, the right name, a photograph, a project name or knowledge of the schedule are not, in themselves, authorisation. In a hypothetical example, a supplier may quite legitimately know when a meeting is taking place. That knowledge does not, however, give them the right to obtain the list of attendees or to change the access arrangements.
Alongside identity and authority, we therefore suggest also keeping track of the specific scope of the approval. Confirming a change of time is not confirming a change of place. Agreeing to a visit is not agreeing to access to every area. Approving one person does not automatically approve the people accompanying them.
This is not hair-splitting. The point is to make sure that, as information is passed on, it does not expand the scope of a decision that no one actually made in that form.
03 — Three real examples. Three different forms of the same problem.
A conference call worth around two hundred million Hong Kong dollars
In a reply published on 26 June 2024, the Hong Kong authorities described a case reported at the end of January that year. An employee received a fraudulent email purporting to come from the chief financial officer and then took part in a fake video conference. In the end, the employee approved transfers to five local accounts. The loss amounted to around 200 million Hong Kong dollars. [3]
What matters is a detail that is easily lost in dramatic retellings. According to the authorities’ description at the time, the conference had been pre-recorded; there was no real interaction between the victim and the fraudster. The police finding cited in the reply pointed to the use of publicly available video and audio material. Further payment instructions followed via a messaging app. [3]
So the lesson is not that any live conversation can now be imitated perfectly. It is more sober than that: the look and sound of authority can lend support to a decision that also needed a different kind of verification.
A voice message that borrows someone else’s standing
On 15 May 2025, the FBI warned of a campaign in which, since April, attackers had been impersonating senior US officials. They used text messages and AI-generated voice messages. The aim was to establish trusted communication and gain access to personal accounts; the contacts obtained could then be used to impersonate further known individuals. [4]
For a protection team, the important point is the potential for further spread: the problem need not end with the account holder. The next recipient may get a message apparently from someone they already know. Our own conclusion for practice is therefore simple: protecting an identity must also be understood as protecting the people who rely on that identity.
The encryption held. Access to the communication still became the target.
On 4 September 2026, NÚKIB, the Czech National Cyber and Information Security Agency, warned of phishing campaigns targeting Signal users. It described how the attackers were not trying to break end-to-end encryption but to get users to take certain actions, such as linking an unknown device to their account or disclosing their login details. Among other things, it recommended checking linked devices and verifying suspicious communication through another channel. [5]
This is not an argument against encryption. It is an argument against the idea that encryption on its own settles the trustworthiness of every decision surrounding the communication.
These examples are not statistics on the likelihood of an attack on a Czech businessperson. They do not support the claim that the same threat awaits every family. They show documented mechanisms. The scope of any measures must reflect the specific person, the environment and the consequences of a possible failure.
04 — An attacker does not have to look for stupidity. They may come across good intentions.
Picturing the person who was deceived as someone exceptionally naive offers a comfortable explanation. At the same time, it draws attention away from the circumstances in which they made the decision.
When developing the Phish Scale, NIST researchers looked not only at the recognisable cues in a fraudulent message but also at how well it aligned with the recipient’s work context. The study, published in 2020, explains why the difficulty of spotting such a message varies with how well it fits into a particular person’s activities. So it is not just a question of whether it contains a typo. [6]
Let us return to our hypothetical assistant. She spends the whole day coordinating changes. The client really is meeting that partner. The delay is real. The request does not stand out because of its subject; it stands out because it asks for an important change without the corresponding confirmation.
Her willingness to help is not a character flaw. But that is exactly why it should not be the only basis for a decision.
Respect for authority can be thought about in a similar way. An employee need not believe everything they hear. They may simply assume that it is not their place to contradict an apparent instruction from the company’s owner. In our scenario, the question of authenticity collides with the question of professional obedience: am I even allowed to question this?
Another dimension is urgency. In its February 2025 warning about fraudulent phone calls, NÚKIB described pressure tactics and also situations in which several seemingly different institutions contact the victim. The number of voices in a story is therefore not, in itself, independent confirmation. [7]
For defence, we suggest watching above all for the moment when the rules change: a request for an exception, a narrowing of the circle of people involved, the exclusion of the usual verification or an extension of access. Urgency, politeness or confidentiality on their own are not proof of fraud. They are a reason to define more precisely what action is to be taken and who is responsible for confirming it.
Confidentiality is meant to limit the unnecessary spread of information. It should not remove the ability to verify the authority behind a decision.
05 — An experienced protection officer does not have to be a human lie detector
Reading the environment and people’s behaviour has its place in protection. It should not, however, be mistaken for an ability to reliably determine the truth from a look, a gesture or a tone of voice.
A 2019 review by Aldert Vrij, Maria Hartwig and Pär Anders Granhag points out that the non-verbal cues associated with deception identified so far are faint and unreliable. Detecting lies from behaviour alone has fundamental limitations. [8]
For practice, we draw an important distinction from this: an impression can prompt verification, but it should not replace it. A calm and convincing manner is not a pass. Nervousness is not a verdict.
Likewise, with voice and video imitations, it is unwise to build the whole procedure around looking for technical flaws. The FBI warns that generative artificial intelligence can be misused to imitate both voices and images, and to fake communication from loved ones or figures of authority. [9]
So let us use a person’s experience to spot inconsistencies, not to grant an unlimited exception. Professional self-confidence should also include the ability to admit: this impression alone is not enough.
Someone who carefully verifies an unclear request is not necessarily less experienced than someone who decides immediately. In that particular case, they may simply be distinguishing more precisely between judgement and evidence.

06 — How an unverified message becomes an official instruction
The most interesting part of our story is the stretch between the voice message and the vehicle pulling away.
At the start, there is an unverified piece of information. The assistant summarises it, the driver accepts it and another team member confirms that he is adjusting the preparations accordingly. The original doubt disappears along the way, even though nobody has added any new evidence.
For the purposes of this article, this phenomenon can be called the transfer of unverified authority. It is not a technical diagnosis but a description of an organisational error: the content gains weight from whom it has passed through, not from how it has been verified.
Consider the difference between two work messages. The first announces that the client has changed the meeting place. The second announces that a request for a change has come in and that confirmation is still being checked. Both sentences can come from the same message. Only the first creates the impression of a decision already made.
The practical solution is to preserve the status of the information. Not every message in the operational group is an instruction. It may be a proposal, an alert, an unconfirmed change or a valid instruction. For significant changes, it should be clear which status currently applies.
It is just as important to decide who closes off the change. There is no need for every team member to phone the client again. On the contrary: needlessly multiplying the checks could overwhelm operations. What we need is a designated responsible role and a clear confirmation for everyone else.
Under the proposed arrangement, then, the driver would not need to analyse an audio file. He would need to know that the approved instruction was issued by the responsible person and that it covers exactly the changes he is to carry out.
Security here does not lie in general suspicion. It lies in making sure that an assumption does not dress itself up as a verified fact as it is passed along.

07 — The hardest security conversation may be with your own client
What if it turns out that the client really did send the instruction?
That may settle the question of identity. It does not necessarily settle the question of security. The client may, for example, have approved a change of meeting without realising that it cancels an arrival point that had already been prepared, or that his team will not have enough information for the new programme.
The purpose of protection is not to take control of the client’s life. It is to create the conditions for an informed decision. The protection officer should explain what is lost with the change, what can be kept and what the workable options are.
There is a fundamental difference between vague disagreement and a specific professional message. Instead of a general refusal, one can explain that the new location has not yet been checked and offer an interim solution: keep the existing arrangements, postpone the change, or carry it out under clearly described conditions. Any specific decision must reflect the situation and the responsibilities agreed in advance.
Such an approach, however, is hard to push through only once you are standing at the car door. That is why it makes sense to agree in advance what a team member may put on hold when something is unclear, whom they will hand the matter to and what happens if the client cannot be reached.
In its guidance for boards, the NCSC explicitly points out that when leaders themselves bypass the rules or demand special treatment, they signal to everyone else that bypassing them is acceptable. [10]
In a hypothetical setting, a client can undermine even the best verification procedure by repeatedly penalising its use. On paper, there will be a duty to verify. In the team’s day-to-day experience, the rule will be not to cause delays. The next time an unclear instruction arrives, these two directives will collide.
That is why a professional agreement should not contain rules for staff alone. It should also contain the client’s commitment not to penalise anyone for a reasonable check carried out in line with the agreement.
The right to stop an unverified instruction cannot exist only in a manual. It has to hold up in front of the person who pays the team, too.
08 — Verification has to become a usable procedure
The general advice to “verify unusual requests” leaves too many questions open. What counts as unusual? Who verifies? What if nobody answers? And what happens in the meantime to the person, the vehicle or the information we are supposed to be protecting?
The following framework is a practical proposal to be adapted to a specific company or family, not a universal standard.
First, identify the decisions with significant impact
It makes no sense to apply the same procedure to a change in the brand of water in the car and a change in the person collecting a child. What matters is the impact, not how urgent the message sounds.
Separate confirmation is warranted above all for decisions that change physical access, the handover of responsibility, the extent of the information shared or material security conditions. For companies, this also includes changes to payment details; the FBI specifically recommends independently verifying changes to accounts and payment procedures. [11]
Then separate proposal, approval and execution
The person who proposes a change is not necessarily the person entitled to approve it. The person who carries it out may not be able to assess all its consequences. In a small household, one person may hold several roles. Even there, though, it helps to know which role they are performing at that moment.
For selected decisions, a check by a second person may be appropriate. But it must involve a genuine assessment. A second person who merely repeats the first confirmation is not an independent check.
Set the verification route and a fallback procedure
Verification should go to a contact point that was trusted in advance, not merely to a contact supplied by the suspicious message. The FBI recommends independent confirmation of identity and, for a new contact, verification through a previously confirmed channel or a trusted source. [4]
The procedure must also cover unavailability. If everything rests on a single person who cannot respond at that moment, the team needs to know whether it may turn to a deputy, whether to postpone the change or which pre-approved arrangement to keep in place.
Maintain a safe state, not blindly the original plan
An unconfirmed change should not automatically mean a change carried out. Equally, however, it should not mean an obligation to stay in a place where immediate danger has arisen.
In an acute threat, protecting life and following the relevant crisis procedure take priority. Verification rules are not meant to prevent a necessary response; they are meant to prevent every unclear message from being declared a reason to set them aside.
Close off the change for everyone it affects
Once a change is confirmed, the team needs a single valid version. What is changing, who approved it, when the change takes effect and which parts of the previous plan stay as they were.
A short record can be more useful than a long message history. Its purpose is not to generate paperwork but to prevent the driver, the assistant and the protection team from acting on three different ideas of the same evening.
09 — A different app does not necessarily mean independent verification
Independence cannot be measured by the number of icons on a screen.
Imagine a hypothetical situation in which someone has access to several accounts on a single device. In that case, moving the conversation from one app to another might not create an independent source of confirmation. In the same way, two colleagues may both confirm the same unverified information because they both took it from the same place.
A more useful question is: what would have to fail for both the original message and its verification to be untrustworthy at the same time?
This is not a demand for perfect technical independence in every routine conversation. It is a way of telling whether an additional confirmation genuinely adds anything new.
Nor should we treat the number on the display as conclusive proof. NÚKIB warns of phone number spoofing and distinguishes between looking up the real institution and verifying that it is the one we are actually communicating with. [7]
For our hypothetical team, then, it would not be enough for someone to call from a number that looks like the client’s and repeat the instruction. The team needs a verification route agreed in advance and proportionate to the importance of the decision, not yet another impression of resemblance.
Keeping contacts up to date also matters. When a phone, an employee’s role or a supplier changes, the verification procedure must be updated in a controlled way. It would be illogical to verify individual instructions carefully while accepting changes to the list of trusted contacts itself without the same attention.
All these considerations point to a single goal: each further step should increase certainty, not merely prolong the conversation.
Not even a request from a supposed protection team is beyond checking
Situations in which a request presents itself as a security measure deserve particular attention. In the warning mentioned above, NÚKIB also described the misuse of the identities of security institutions, including its own. Labelling a request as protective therefore does not prove that it is genuine. [7]
In a hypothetical setting, someone may cite an alleged risk to demand a change of programme, the handover of sensitive information or the removal of the usual contact point. For a defensive approach, it is important to assess not only the stated purpose but also the authority of the person requesting the change.
The reverse is also true. A genuine protection team should issue its requests in a recognisable way agreed in advance. It should not expect the client’s assistant to accept an unknown person as a new authority without further ado just because of an urgent-sounding security explanation.
A security argument should not be a universal pass that ends all questions. Otherwise, all anyone would need to do is pose as the protection team to be granted an exception from the very rules that are meant to protect.
10 — A company, a family and a hotel need the same principle, but different arrangements
It would be easy to adopt one strict procedure and send it round to everyone. It is better to adapt the rules to what each of the people involved is actually protecting.
Company: protect decisions, not just logins
In a hypothetical company, the finance department has secure access to the accounting system. That, however, says nothing yet about whether a change to a supplier’s account details comes from an authorised person. The security of the login and the correctness of the business documentation are two separate questions.
The FBI describes business email compromise as fraud in which a message apparently from a known sender leads to a payment being made or information being handed over. It recommends verifying payment requests and changes to payment details. [11]
Our own suggestion for companies is to separate changing the details from using them. The person processing a payment should be able to see whether the new details have been approved, rather than accepting them simply because they have already been entered into the system. Similar logic can be applied when adding guests to a meeting or granting access to confidential documents.
Family: do not burden the child with adult decisions
In a hypothetical household, it is important to determine which adults decide on changes and who is responsible for handing over care. The name of a person the child knows is not enough. What also matters is a specific agreement for that particular day and situation.
The proposed arrangement is not meant to turn the child into a checker of phone messages. The change should be confirmed by the responsible adults. A child needs appropriate, understandable rules and help within reach, not details of possible attacks.
Nor is the aim to set the parents, the school and the protection team against one another. Their task is to clarify in advance who confirms what, so that a handover does not have to depend on improvisation at the entrance. The specific arrangements must respect the responsibilities and powers of those involved, not replace them with internal security preferences.
Hotels and events: courtesy need not mean handing over information
In a hypothetical hotel, a professional-looking visitor may ask for information about a guest, or for a change of access, citing the guest’s team. The right response need be neither compliance nor a public accusation.
A member of staff can arrange verification through the designated route without disclosing sensitive details. There is a difference between helping to establish contact and confirming the client’s stay, schedule or specific whereabouts.
The same principle can be applied to changes in accreditation: hospitality staff should look for a permissible solution, not circumvent the access conditions. Admission to an event, access backstage and the opportunity to move around near the protected person should not merge into a single vague “VIP” label.

11 — Technology matters. It just must not be given a job it does not do.
It would be a mistake to take away from this article the idea that technical protection does not work. What is needed is a more precise definition of what it protects against.
The NCSC recommends using passkeys wherever they are available and explains their resistance to credential phishing. Where they are not available, it recommends strong passwords and two-step verification. [12]
It does not follow, however, that a securely logged-in user cannot make a wrong decision. If an authorised employee sends a document to the wrong recipient themselves, that is not necessarily a failure of their login key. The key dealt with access to the account, not with the legitimacy of every subsequent work task.
Similarly, it is necessary to distinguish between multi-factor authentication of a single user and approval by two people. The first helps to protect the login. The second can serve as an organisational check on a decision. They are not interchangeable tools.
The Signal case points to another boundary: alongside securing the transmission, attention must be paid to the devices and accounts that give access to the communication. Indeed, the NÚKIB recommendation mentioned above also includes checking linked devices. [5]
For a protection team, this leads to a practical suggestion: choose technology according to the specific problem. Do not expect encryption to settle questions of authority, cameras to settle questions of permission, or a perfectly written instruction to prove that it was the right one.
And at the same time, do not shift technical tasks onto a close protection officer without preparation. Coordinating with an information security specialist is something quite different from pretending that one person can handle transport, physical protection, account management and digital investigation all to the same standard.
12 — Access should match the task, not the degree of personal affection
Relationships built on long-standing trust invite the question of why anyone should restrict a person who has proved themselves so many times.
A better question is what they actually need for their work.
NIST describes the principle of least privilege as restricting access to the minimum necessary to perform assigned tasks. It is not an assessment of the user’s character. It is a matter of how permissions are designed. [13]
In a hypothetical household, the house manager may need access to the residence’s operational information, not to the family’s entire calendar. The driver needs the information for his journey, not automatically the content of a business meeting. A supplier should receive the information necessary for the job, not a complete picture of the client’s life.
Temporary access deserves particular attention. Under the proposed arrangement, permission granted for a single event should not persist indefinitely without a decision being made. Covering for a colleague should not quietly create another permanent authority. When a working relationship ends, accounts, keys, shared access and other permissions must be dealt with in line with the scope of that role.
The point is not to assume betrayal. The point is to limit the consequences of a mistake, a compromised account or a permission that remained valid for longer than it should have.
At the same time, protecting the client must not create unlimited surveillance of staff. The European Data Protection Board lists among the basic principles lawfulness, transparency, purpose limitation, data minimisation and storage limitation. Any specific vetting or monitoring requires an appropriate legal assessment. [14]
The practical limit can be put simply: a security team should know what it needs for protection and be able to explain why. It should not collect everything just because it might come in handy one day.
13 — A real employee, a mistake and a misused identity are not the same problem
When analysing an incident, we suggest keeping at least three working hypotheses apart: someone deliberately abused their authority; someone authorised acted in good faith on the basis of fraud or a mistake; or someone else acted under their identity.
This is an analytical distinction, not a reason to suspect a particular person in advance.
The same outward result can have different explanations. A sensitive document was sent from the assistant’s account. That alone does not determine who created the message, why it was sent or whether the assistant knew to whom she was actually passing the document.
That is why it is advisable first to establish the steps that can be documented: which account was used, what instruction arrived, who received it, what permissions existed and what was actually done. Only then should responsibility be assessed.
Looking for someone to blame too early can divert attention from another route that is still open. In our scenario, for example, replacing the assistant would not be enough if the new person inherited the same unclear procedure and the same pressure to comply immediately.
Let us also distinguish between an employee’s personal difficulties and evidence of a security breach. Needing support is not in itself evidence of being a danger. Managing permissions should be based on tasks and documented circumstances, not on improvised judgements about people’s character.
14 — Too many checks can obscure the one that matters
There is also the opposite risk to excessive trust: a system that demands so many confirmations that they turn into mechanical clicking or an endless operational conflict.
In research on security fatigue published in 2016, NIST described how the users it studied felt overwhelmed by security demands and gave up on some decisions. This was qualitative research, not a universal measurement of all employees. Its recommendations included reducing the number of decisions and making the secure choice simpler. [15]
For physical protection, we draw a design principle from this: save people’s attention for the decisions where the outcome really matters.
If every minor detail is verified in the same way, a serious change may not be given the weight it deserves. It is better to distinguish clearly between a routine adjustment, a significant change and a crisis. Each needs a different procedure and a different level of decision-making authority.
It is also worth asking why people bypass the rules. Is it a misunderstanding? A missing contact? A disproportionate delay? Or is it simply impossible to get ordinary work done by the rules? The answer need not excuse the breach, but it can show what needs fixing.
A good procedure should be firm enough to protect and usable enough that nobody needs to create a second, unofficial one just to get normal work done.
15 — What to do when doubt only arises afterwards
Sometimes suspicion only arises after a document has been sent, a payment made or the programme changed. At that point, it is more useful to limit further consequences than to decide straight away who should have known better.
The following sequence is an indicative framework. The specific response must be guided by the nature of the incident; if people are in immediate danger, their safety comes first.
First, halt any follow-on actions that can safely be paused. Do not carry on with further steps just because the first one has already happened. With a change of programme, check the current situation and hand coordination back to the responsible person. This does not mean moving the client without thinking or creating yet another improvised change.
In the case of financial fraud, do not delay contacting the bank and the police. In its consumer guide, the Czech Ministry of Industry and Trade recommends contacting the bank and the Police of the Czech Republic immediately. In immediate danger, or when urgent police intervention is needed, the emergency number in the Czech Republic is 158, or alternatively 112. [16]
Preserve the available material and record what happened. For handing over to specialists, it is useful to keep the original messages, times, account details and a description of the steps actually taken. Do not edit the material in a way that loses its original form, and do not circulate it to other people without good reason. Securing it must not delay a necessary protective response.
Deal with a suspected account takeover separately from the message itself. When recovering a hacked account, the NCSC recommends, among other things, checking email forwarding, changing login details, signing out connected devices and apps, and warning your contacts. The exact steps vary from service to service; in a corporate environment, the process should be coordinated by the relevant administrator or incident response team. [17]
Inform the people who may be following the same unverified instruction. You do not need to know the full explanation. They need to know that the specific instruction is no longer considered confirmed, and who will issue the next valid instruction.
Only after that comes the detailed review. Not only which message was fake, but also why it was able to change actual operations and where it should have been possible to stop its effect.
16 — Employees need a reason to speak up before they are sure
A security report does not always begin with a sentence about a detected attack. It may begin far more ordinarily: something is not right, I may have made a mistake, I am not sure about the last instruction.
The NCSC warns that people who fear the consequences may not report mistakes, and recommends an environment that encourages early reporting. At the same time, its guidance builds the defence against phishing in multiple layers, rather than relying solely on an employee’s ability to spot every fraudulent message. [18]
In our scenario, the assistant should be able to speak up even after she has forwarded the instruction. Her report is not an extra nuisance. It is an opportunity to stop the chain before other people take the next steps.
This does not mean doing away with accountability. It means separating the immediate response from the subsequent assessment. First come safety, access, the validity of instructions and the impact. Then comes the question of whether it was fraud, an unclear process, inadequate preparation or a deliberate breach of the rules.
So let us not judge the quality of the arrangements solely by the number of problems reported. Zero reports may mean calm operations; it may also mean that people do not know whom to contact. Without further context, success cannot be inferred from this number.
For your own team, we suggest tracking, for example, the time it takes from a doubt arising to its being handed to the responsible person, the availability of a deputy, or the ability to stop an unverified change without operational chaos. These are questions that can be tested and improved.
17 — Test the procedure, not an employee’s willingness to be humiliated
Training does not have to begin with a secret trap and end with a list of those who failed.
A good place to start is a joint tabletop exercise: the people responsible walk through a hypothetical situation and describe what they would actually do. There is no need to use real personal data or to provoke real fear for loved ones.
Imagine that a significant change of programme comes in, the person who issued it cannot be reached and two team members have conflicting information. Who decides that the change will not be made for now? Who verifies it? What exactly should the driver do in the meantime? How will the others find out the outcome?
Then change a single condition: the instruction is genuine, but the member of staff does not understand its scope. Or the original contact is no longer valid. Or the responsible person cannot be reached. The aim is not to parade an endless series of threats but to check whether the procedure copes with ordinary deviations.
In describing security behaviours, the UK police portal ProtectUK covers not only education but also creating the right conditions, encouraging the desired behaviour and evaluating the impact. Passing on information is therefore not the whole programme in itself. [19]
As a working output for a company or household, we suggest a single, concise page. It should answer who may approve significant changes, how they are confirmed, who stands in for someone who is unavailable, what remains valid while verification is under way and where doubts are to be reported.
If the people sitting at one table in a quiet room cannot agree on these answers, it is unreasonable to expect them to agree automatically at a moment when someone is already waiting by the vehicle.
18 — A few minutes later, outside the same hotel
Let us return to the opening story.
The driver receives information about the proposed change. This time, however, it is marked as unconfirmed. The team leader does not ask whether the voice sounded convincing enough. He establishes what is to change, who is allowed to approve it and whether approval has already been given.
The assistant uses the agreed verification route. In this version of the scenario, it turns out that the client really did send the message. But he wanted to change the order of his meetings, not to reduce the protection team or automatically change all the arrival arrangements.
No mastermind attacker was exposed. There was no dramatic intervention. What was caught was a misunderstanding that had begun to grow as it was passed on.
That is not a weaker ending to the story. It is an important test of the proposed system. A measure makes sense even when it prevents an ordinary mistake, not just a targeted fraud.
In another version, verification would show that the client had sent nothing. What followed would be different, but the first protective step would be the same: not allowing unconfirmed information to change people’s actual movements unchecked.
The vehicle door opens only once the team is working from a shared, valid version of the programme. The client does not need to know every intermediate step. He needs to know that the people around him do not mistake a willingness to oblige for a duty to stop thinking.
Protection that does not destroy trust
It would be easy to turn this subject into a story about a world where no one can be trusted. That would be the wrong goal.
Neither a family, nor a company, nor professional protection can reasonably function as a continuous interrogation. They need trust, independence and the ability to act. The task of a security regime is to give these things clear boundaries, not to remove them.
When it is clear who may decide what, verification need not turn into a personal dispute every time. When doubt can be admitted, mistakes need not be hidden. When access matches the task, a single error need not affect everything. And when the client respects the rules, his staff need not choose between protection and obedience every time.
None of these measures guarantees zero risk. The point is to reduce the room for unverified decisions and to lessen the consequences when a mistake happens anyway.
The yardstick, therefore, is neither the number of prohibitions nor the amount of technology. It is the ability to take the right next step at a moment when the information looks credible but is not yet sufficient.
A bodyguard can stand beside the client. But a trustworthy system must also stand behind the decisions of the people who organise the client’s life.
Good protection is not only about who can get to you. It is also about who can get others to do something in your name.
Sources and references
Verified as of 16 September 2026. The cases cited are presented in their historical context; they are not risk statistics for any particular client. The principles described are not a substitute for a legal assessment of a specific situation.
- NIST: Authentication (glossary)The difference between verifying identity and granting permissions.
- NIST: Authorization (glossary)Authorisation as a decision about access, not merely identity verification.
- Hong Kong SAR Government: LCQ9 — Combating frauds involving deepfake, 26 June 2024The case of a fake video conference and transfers of around HKD 200 million.
- FBI / IC3: Senior US Officials Impersonated in Malicious Messaging Campaign, 15 May 2025A campaign using AI-generated voice messages impersonating officials.
- NÚKIB: Analýza a doporučení k phishingovým kampaním proti uživatelům Signalu, 4 September 2026The target is device linking and login credentials, not breaking the encryption.
- Steves, Greene, Theofanos: Categorizing human phishing difficulty: a Phish Scale, 2020How hard phishing is to recognise depends on how well it fits the work context.
- NÚKIB: Upozornění na podvodné telefonáty, 19 February 2025Pressure, seemingly independent sources and spoofed phone numbers.
- Vrij, Hartwig, Granhag: Reading Lies: Nonverbal Communication and Deception, 2019Non-verbal cues associated with deception are faint and unreliable.
- FBI / IC3: Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, 3 December 2024Misuse of generative AI to imitate both voices and images.
- NCSC: Developing a positive cyber security cultureLeaders who bypass the rules normalise bypassing them for everyone else.
- FBI: Business Email CompromiseRecommendation to verify payment requests and account changes independently.
- NCSC: Passkeys — what you need to knowThe resistance of passkeys to credential phishing.
- NIST: Least privilege (glossary)The principle of the minimum permissions needed for a given task.
- European Data Protection Board: Basic principlesLawfulness, transparency, purpose limitation and data minimisation.
- NIST: Security Fatigue, 4 October 2016Overload from security demands leads people to give up on decisions.
- MPO: Průvodce pro spotřebitele — Podvodné voláníRecommendation to contact the bank and the Police of the Czech Republic immediately.
- NCSC: Recovering a hacked accountRecovery steps after a suspected account takeover.
- NCSC: Phishing attacks — defending your organisationAn environment that encourages early reporting of suspicious messages and mistakes.
- ProtectUK: People, security culture and behavioursSecurity behaviour as a combination of education, conditions and evaluation.
Do you need to check who may make decisions in your name?
If you are dealing with your own security, or that of your family or company, and need to put a verified procedure in place for approving changes, BODYGUARD GROUP® can start by assessing the situation discreetly and then propose a proportionate solution.
Discreet consultation



