The Resilience Brief

Pattern-of-Life Intelligence: Managing Exposure in the AI Era

Steven Season 2 Episode 5

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 21:45

This white paper explores the concept of involuntary pattern-of-life exposure, where publicly available data is aggregated to predict the movements and habits of ultra-high-net-worth individuals. The author argues that modern artificial intelligence has drastically lowered the cost and effort required for adversaries to fuse disparate information—such as social media posts, property records, and vendor marketing—into dangerous intelligence mosaics. By applying classical theories of criminology and national security, the text demonstrates how routine, legal disclosures can inadvertently compromise physical and digital safety. To address these evolving threats, the document proposes a new discipline called exposure management, which shifts focus from securing private systems to managing an individual's discoverable footprint. This framework is designed to integrate with the NIST Cybersecurity Framework 2.0, offering structured recommendations for family offices and security professionals to audit and minimize public vulnerabilities.

SPEAKER_00

There is this uh really dangerous assumption built into modern security today. You deploy the most sophisticated firewalls money can buy. You enforce these, you know, rigorous multi-factor access controls across your entire organization.

SPEAKER_01

Right. And you just rest easy.

SPEAKER_00

Exactly. You assume your primary threat is an adversary trying to, I don't know, brute force their way into your restricted systems. You view security as this binary state.

SPEAKER_01

Yeah, you're either breached or you're secure.

SPEAKER_00

But the reality facing high-profile individuals, corporate leaders, and ultra-high net worth families today, it shatters that illusion completely. Because the most severe physical and operational threats, they no longer come from hackers bypassing your encryption.

SPEAKER_01

No, not at all.

SPEAKER_00

They come from adversaries who will never even touch your secure networks. Instead, they just lawfully gather public everyday information to build a uh a predictive model of your life.

SPEAKER_01

Right. They know exactly where you will be, who you'll be with, and precisely when you'll be most vulnerable.

SPEAKER_00

Which is terrifying.

SPEAKER_01

It is. I mean, that binary thinking is just a relic of a bygone era. We have spent decades optimizing the entire cybersecurity industry around confidentiality, meaning you know, stopping unauthorized access to private data.

SPEAKER_00

Right.

SPEAKER_01

But the modern threat landscape is defined by predictability. Adversaries aren't looking for your private passwords anymore. They are aggregating the vast trails of information that you, your family, and your vendors just voluntarily and legally disclose to the public every single day.

SPEAKER_00

So welcome to the Resilience Brief. Today we are delivering a specialized deep dive specifically for chief information and resilience officers, CROs, and family office risk leaders.

SPEAKER_01

Yeah, this is a critical one.

SPEAKER_00

Our mission today is to dissect a really groundbreaking white paper by Dr. Stephen Wilson. It's titled Pattern of Life Intelligence and the Involuntary Exposure of Ultra High Networth Principles.

SPEAKER_01

It's quite a title, but the content is just it's essential.

SPEAKER_00

It really is. We are going to look at how entirely harmless data becomes a weaponized targeting package, and then lay out the practical playbook you need to manage this entirely new era of predictive threat modeling.

SPEAKER_01

It is absolutely required reading for anyone managing risk at the executive level today. I mean the security industry has historically relied on the CIA triad. Right. Trevor Burrus, Jr.

SPEAKER_00

Right. Confidentiality, integrity, and availability. Trevor Burrus, Jr.

SPEAKER_01

Exactly. But Dr. Wilson points out that the CIA triad has this massive fatal blind spot. It only protects the information you actually own and control.

SPEAKER_00

Aaron Ross Powell Oh, that makes sense. Yeah.

SPEAKER_01

So if you are a CIRO tasked with protecting a principal, the CIA triad does absolutely nothing to protect them from risks arising from unowned, unrestricted information.

SPEAKER_00

We are talking about like county property records, philanthropic donor lists, uh a contractor's marketing website, or even just the background of a social media post. Exactly. To understand how that scattered mundane data turns into a physical threat, we have to look at something called mosaic theory. The paper traces this back to U.S. National Security and Freedom of Information Act case law, specifically referencing legal scholar David Posen.

SPEAKER_01

Aaron Powell Yeah, and Posen's articulation of mosaic theory is just brilliant. Because in the realm of national security, federal courts has consistently allowed intelligence agencies to withhold completely unclassified documents from the public.

SPEAKER_00

Aaron Powell Which sounds counterintuitive at first.

SPEAKER_01

Right. But the legal reasoning is that while document A is harmless and document B is harmless, if you put them together, they produce a highly sensitive, classifiable inference. The whole becomes vastly more dangerous than the sum of his parts.

SPEAKER_00

And Dr. Wilson applies this directly to the high net worth individual, creating this really detailed data taxonomy of those innocuous pieces. He categorizes them into identity, geospatial data, relational data, temporal data, financial data, and security posture data. Trevor Burrus, Jr.

SPEAKER_01

It's a lot of data points.

SPEAKER_00

It is. So like a zoning permit for a massive new swimming pool at an LLC on property that's just public geospatial and financial paperwork. Right. Or a prominent landscape architect posting an award for a beautiful new garden design as just a professional accolade.

SPEAKER_01

Aaron Powell But an adversary isn't looking at those in isolation. They map the address on the zoning permit to the LLC, right? Then they cross-reference the LLC's tax filings to find the principal's name.

SPEAKER_00

Oh wow.

SPEAKER_01

And then they match the background of the landscape architect's award photo to the topography of that specific property. Suddenly they know exactly where a high-profile target lives, what the physical layout of their backyard looks like, and where the new construction blind spots are.

SPEAKER_00

It is literally like an adversary completing a jigsaw puzzle of your principal's life. But and this is the crazy part. The principal isn't even the one handing them the pieces. It's the landscape architect, the children's private school newsletter, the charity foundation's IRS Form 990. They are all just handing the adversary handfuls of pieces. Trevor Burrus, Jr.

SPEAKER_01

Yep. Completely legally. Trevor Burrus, Jr.

SPEAKER_00

But I mean, a jigsaw puzzle of a backyard doesn't inherently mean someone is going to climb the fence, right? So at what point does that aggregated data cross the line into an actionable threat?

SPEAKER_01

Aaron Ross Powell The trigger there is predictability. The pieces of the mosaic are dangerous when they form a predictable pattern of life. And this ties into this foundational criminological principle from 1979 called routine activity theory, developed by Cohen and Felsen.

SPEAKER_00

Aaron Powell Right. I remember reading about this.

SPEAKER_01

Aaron Powell Yeah, they prove that crime doesn't just happen randomly. It requires three specific elements converging in time and space. You need a motivated defender, a suitable target, and the critical piece, the absence of a capable guardian.

SPEAKER_00

So predictability literally creates the opportunity for the thief. If an adversary knows your routines, they don't have to guess when guardianship is absent, they just wait for it.

SPEAKER_01

Exactly. Pattern of life analysis is the deliberate technique of mapping those routines to eliminate the offender's uncertainty. Wow. So think about a predictable daily school run, a recurring Tuesday board meeting across town, or a highly publicized two-week international philanthropic trip. The adversary doesn't have to stake out your house in a suspicious van anymore.

SPEAKER_00

Right, no more guys with binoculars across the street.

SPEAKER_01

Exactly. Your aggregated public data basically acts as a remote surveillance camera. It tells them exactly when the estate is empty or when the principal is in transit and vulnerable.

SPEAKER_00

I want to pause on the mechanism of how this data actually gets out there because we really need to talk about the platforms we use every day. Dr. Wilson introduces a concept that I found incredibly clarifying.

SPEAKER_01

Oh, the contextual integrity part.

SPEAKER_00

Yes. He draws on Helen Nissenbaum's theory of privacy as contextual integrity and a related term, context collapse, which was coined by Dana Boyd.

SPEAKER_01

Aaron Ross Powell Those concepts are vital because they totally reframe what a privacy violation actually is. Right. We tend to think a privacy breach is when, like, a hacker steals your secret emails and dumps them online. But Nissenbaum argues that a privacy violation is often much more subtle.

SPEAKER_00

How so?

SPEAKER_01

Well, it happens when information you shared for one very specific social norm is extracted and repurposed entirely out of context for a completely unintended audience.

SPEAKER_00

You know, it makes me think of giving a slightly embarrassing inside joke heavy toast at your best friend's wedding.

SPEAKER_01

Oh, that's a great analogy.

SPEAKER_00

Right. Because in the context of a room full of friends who have had a few drinks, it is perfectly appropriate and safe. But if that microphone were secretly hooked up to the speakers at a rival corporate board meeting, it would be a complete disaster. The information didn't change at all, but the context collapsed.

SPEAKER_01

That is exactly it. Let's apply that to a high-profile executive. Say they share a photo of their family at a charity gala in the events printed program. The context there is just reinforcing philanthropic norms among their peers.

SPEAKER_00

Aaron Powell Sure, it's safe within that room.

SPEAKER_01

Exactly. But when an open source intelligence analyst, or heaven forbid, a kidnapped for ransom network, digitizes that program and then uses it to estimate liquid wells, identifies the faces of the children, and targets the family that is a violent breach of contextual integrity.

SPEAKER_00

Aaron Powell And social media platforms are architecturally designed to cause this. I mean, they are what the paper calls networked publics. They make data searchable, persistent, and highly scalable. They literally strip away the context you originally relied upon for safety.

SPEAKER_01

Aaron Powell And the white paper really grounds this in reality. It brings up the bling ring burglaries that hit Los Angeles back in 2008 and 2009.

SPEAKER_00

Oh, I remember that.

SPEAKER_01

Yeah. And the thing is, this wasn't a sophisticated cartel. It was a group of teenagers. But they systematically burglarized the homes of high-profile celebrities.

SPEAKER_00

Aaron Powell And they didn't do it by hacking alarm systems, did they?

SPEAKER_01

Not at all. They looked at paparazzi photos to confirm a target was in Las Vegas. They checked public appearances and social media to see how long they'd be gone. And they just used early aerial mapping software to find the properties.

SPEAKER_00

It's so simple, it's scary. And then there is the 2016 Paris robbery of a major public figure. Trial testimony and investigations strongly indicated that the offenders used the victim's own social media activity to establish her exact location in a private residence. Yep. And they used it to confirm the physical presence of millions of dollars in high-value jewelry right there on the premises.

SPEAKER_01

The victim shared updates intended for a specific context, you know, fans, fashion followers, friends, right?

SPEAKER_00

But the digital platforms collapsed that context and basically handed a pristine, time-stamped pattern of life map directly to motivated offenders.

SPEAKER_01

I do have to play devil's advocate here for a second because this sounds dangerously close to victim blaming.

SPEAKER_00

I know, it really can sound like that.

SPEAKER_01

Are we essentially telling CROs that if their executors get robbed, it is their fault for using Instagram or celebrating their philanthropy publicly?

SPEAKER_00

Aaron Powell It is a really common reaction to feel that way, but looking at it as victim blaming entirely misses the systemic nature of the threat here.

SPEAKER_01

Aaron Powell Okay, unpack that for me.

SPEAKER_00

Well, we are not judging the moral behavior of the user. We are analyzing the architectural design of modern information platforms. These platforms are engineered at a base code level for frictionless sharing and limitless searchability.

SPEAKER_01

Right. That's their whole business model. Exactly. So as a security leader, you just have to recognize that your principal is operating in an environment where the architecture actively works against their physical security, acknowledging that structural reality isn't victim blaming, it is the prerequisite for deliberate risk management.

SPEAKER_00

That's a great distinction. But you know, a loose-lipped landscape architect or an overshared Instagram post is really just a drop in the bucket. The structural reality gets infinitely more complicated when we look at the broader ecosystem surrounding ultra-high net worth individuals. Absolutely. Because the threat isn't just the apps they install on their own phones, it is the vast array of people they hire. Basically, your vendors are actively leaking your life.

SPEAKER_01

Dr. Wilson insists that we have to view the modern household and estate as a system of systems. If you work in physical security, you know, CPT crime prevention through environmental design.

SPEAKER_00

Right.

SPEAKER_01

It dictates how you design physical spaces. You trim the hedges. So security cameras have clear sight lines. You design pathways that naturally deter trespassers. Well, we now have to apply CPT to the informational environment. You'll have to restrict the digital sight lines to the principal's private life.

SPEAKER_00

And the density of professional services surrounding an executive is just staggering when you really think about it. You have architects, high-end security integrators, landscape designers, marine crews for yachts, private aviation operators, interior decorators.

SPEAKER_01

And every single one of those vendors operates under a fierce commercial incentive to boast.

SPEAKER_00

Of course they do.

SPEAKER_01

They want to win their next high net worth client. And the best way to do that is to post portfolio photography, detailed case studies, and sometimes actual blueprints of the highly customized, incredibly expensive work they just completed.

SPEAKER_00

It is the ultimate operational irony. You spend millions building a state-of-the-art physical fortress to protect your family, complete with biometric access and reinforced safe rooms. Right. And then the contractor who built it publishes a multi-page case study on their corporate LinkedIn. They proudly display the blueprints, the specific camera placements, and the technical specifications of your safe room door just to win an industry award.

SPEAKER_01

It's wild. In intelligence terms, those vendors act as massive open nodes for mosaic collection. And this is a very distinct governance problem for the CIR. How so? Well, this is not traditional third-party cyber risk management. You aren't worried about the vendor servers getting hacked.

SPEAKER_00

Right. It's not a data breach. Trevor Burrus, Jr.

SPEAKER_01

Exactly. This exposure is a deliberate, lawful feature of the vendor's own marketing department. It is entirely public, and it provides an adversary with tactical intelligence that they used to have to risk their lives to gather.

SPEAKER_00

Aaron Powell But I mean, criminals have always scouted properties, private investigators have always gone through public records. Why is the CIRO suddenly facing an existential crisis right now? Like what changed the game so drastically?

SPEAKER_01

Artificial intelligence. Open source intelligence, or OSINT, has existed since the Cold War. AI hasn't changed the fundamental nature of intelligence gathering, but it has completely revolutionized the economics of aggregation.

SPEAKER_00

Aaron Powell Meaning it's just faster and cheaper now.

SPEAKER_01

Exponentially. What used to take a team of state-sponsored intelligence analysts months of painstaking manual correlation can now be executed instantly, continuously, and cheaply by software.

SPEAKER_00

The paper breaks down the specific AI capabilities that make this possible, and I have to say the mechanics of it are terrifying. Take natural language processing or NLP.

SPEAKER_01

Yeah, that's a big one.

SPEAKER_00

In the past, if an analyst found a zoning permit for a Bill Smith and a charity gala program mentioning a William Smith, a human had to sit there and figure out if they were the same person. Right. But NLP algorithms perform instant entity resolution. They can ingest millions of heterogeneous documents like PDFs, news articles, tax filings, and disambiguate names, aliases, and corporate affiliations in literally milliseconds.

SPEAKER_01

And then the software applies graph analytics on top of that.

SPEAKER_00

Right.

SPEAKER_01

It takes those resolved entities and maps the relationships dynamically. It can instantly draw a web connecting the LLC that bought a property to the principal's name in a local news article, to the highest paid contractor on an IRS form, all the way to the school schedule posted on a community board.

SPEAKER_00

And the most visceral example of this is computer vision. The paper references the 2020 reporting on ClearView AI, which proved that commercial scale, completely unregulated facial recognition is already here.

SPEAKER_01

It's already fully operational.

SPEAKER_00

Right. They scraped billions of public images from the web, social media, news sites, background photos, just to create these comprehensive identity graphs without a shred of subject consent.

SPEAKER_01

And if we pull that back to contextual integrity for a second, ClearView AI basically automates context collapse at an unimaginable scale.

SPEAKER_00

Wow. Yeah.

SPEAKER_01

A photo of your principal just walking in the background of a tourist's vacation photo in a public park can be technically correlated into an identity graph. It links their face to a location in a timestamp, and it's accessible to anyone with a license to the software.

SPEAKER_00

So the barrier to entry for highly targeted predictive physical attacks has basically dropped to zero.

SPEAKER_01

Pretty much.

SPEAKER_00

This totally rewrites the threat actor taxonomy. It is no longer just state intelligence services with unlimited budgets who can build predictive behavioral models.

SPEAKER_01

No, not at all.

SPEAKER_00

Now you've got financially motivated criminal rings, kidnapped for ransom operations, and fixated stalkers possessing what is essentially military-grade intelligence capabilities.

SPEAKER_01

Organized burglary rings actively recruit individuals with OSUNT skills for reconnaissance roles now. Kidnap and extortion networks routinely run pattern of life analysis for operational planning. The AI does all the heavy lifting, basically serving up a dashboard of your principal's vulnerabilities.

SPEAKER_00

Okay, so the threat is clear, the mechanism is AI, and the vulnerabilities are just bleeding out of every vendor and public reckon. What is a security leader actually supposed to do about it? How do you defend against an adversary who only uses lawful data?

SPEAKER_01

Dr. Wilson introduces a specific governance discipline to combat this called exposure management. It is defined as the systematic identification, assessment, and reduction of an individual's discoverable digital and physical footprint. And it operates independently of, but complementary to your conventional vulnerability management.

SPEAKER_00

To make this actionable, the paper actually maps exposure management directly to the NIST Cybersecurity Framework 2.0, providing a structure that every CIRO already understands, which I think is super helpful.

SPEAKER_01

Extremely helpful. So under the govern and identify functions, the CIRO must formally charter an exposure management program.

SPEAKER_00

Because you can't manage what you haven't measured.

SPEAKER_01

Exactly. You cannot manage a footprint you haven't quantified. This means conducting continuous OSINT self-assessments to build a baseline inventory of what pattern of life data is currently discoverable out there.

SPEAKER_00

Then we move to the protect function, which involves both technical and procedural friction. You implement mandatory metadata scripping on all photos before they ever leave a device. You enforce delayed posting policies for the principal's social media, ensuring they are never broadcasting a live location.

SPEAKER_01

And you have to aggressively address that vendor ecosystem we talked about.

SPEAKER_00

Oh, absolutely.

SPEAKER_01

The CRO must rewrite vendor risk agreements to explicitly restrict marketing. You mandate strict contractual limits on case studies, portfolio photography, and testimonials. If a contractor wants the job, they sign away their right to use your estate for their LinkedIn clout.

SPEAKER_00

Under Detect and Respond, the focus shifts to continuously monitoring data broker sites, public property records, and corporate filings, and executing takedowns and opt-outs wherever legally possible. But there is massive friction here when dealing with the human element, isn't there? Because you can't just hand a billionaire a mechanical checklist and tell them they aren't allowed to post about their new yacht.

SPEAKER_01

Oh, you will fail immediately if you try that. Right. You have to educate the household, both family members and domestic staff on the underlying mechanism of exposure. You teach them about contextual integrity.

SPEAKER_00

Make it real for them.

SPEAKER_01

Exactly. When a principal actually understands how a seemingly harmless photo of their dog is being scraped by a machine learning algorithm to map the interior layout of their home, they stop seeing security protocols as an annoyance. They become active participants in their own defense.

SPEAKER_00

But how do you actually prove the defense is working? You can write all the airtight vendor contracts and family policies you want, but you don't know what you are missing. I was reading the section on testing these defenses, and the concept of red teaming the family seems like the only real way to validate the program.

SPEAKER_01

It is arguably the most critical recommendation in the entire paper. Just as you would commission a penetration test for your corporate network, you periodically commission an independent OSINT reconstruction exercise focused purely on your physical and informational footprint.

SPEAKER_00

So you're hacking yourself, basically, but with open data.

SPEAKER_01

Exactly. You hire an external team of analysts to attempt to construct a pattern of life profile of the principal using only legally available public data. It is the only way to strip away your own assumptions and see what a motivated adversary can actually build.

SPEAKER_00

That is the ultimate executive takeaway for today. If you are leading security or resilience for a high-profile organization or family, your mandate has fundamentally changed.

SPEAKER_01

It really has.

SPEAKER_00

You cannot stop at the edge of the servers and systems you legally own. You must actively manage the entire information environment that surrounds your principles. You have to treat your landscape architect's marketing department and your county's public zoning records as critical vulnerabilities that require continuous red teaming and strict contractual controls.

SPEAKER_01

The role of the CIRO has evolved. Deploying traditional cybersecurity controls is still necessary, of course, but it is just no longer sufficient to prevent sophisticated physical and operational targeting.

SPEAKER_00

As we wrap up this deep dive, there is a final highly provocative thought from Dr. Wilson's paper that you really need to consider. It is a chilling paradox regarding the NIST AI Risk Management Framework, or AI RMF 1.0.

SPEAKER_01

Yeah, this part really highlights the double-edged sword of the tools we use to defend ourselves.

SPEAKER_00

Exactly. As a CRO, you're going to deploy advanced AI OSINT tools defensively. You will use the exact same natural language processing and graph analytics we discussed to monitor your principal's exposure and conduct that continuous red teaming. Right. But by doing so, you introduce a brand new catastrophic risk. What happens if the defensive AI tool itself becomes compromised?

SPEAKER_01

It's a terrifying scenario because in your meticulous effort to map your principal's vulnerabilities, to find every loose piece of the mosaic and pull it together to see what the enemy sees, you have curated the perfect centralized pattern of life intelligence database. Yep. If your defensive system is breached, you have inadvertently handed the adversary the exact predictive behavioral model you were trying to protect against.

SPEAKER_00

In the realm of pattern of life intelligence, the watcher must also guard their own shadow. The pieces of the puzzle are already scattered across the internet. Your job is to make sure the adversary can never put them together without doing the work for them. Thank you for joining this deep dive, and remember to stay resilient.