Growing hostile-state activity, proxy networks and locally recruited operatives are changing the environments in which protected individuals travel, work and live. Increasingly, risk may arise not from the client’s own profile, but from the people, organisations and locations around them. For Executive Protection, that has direct implications for threat assessment, advance work and protective intelligence.
For years, Executive Protection threat assessments focused on a familiar range of risks: crime, kidnapping, stalking, politically motivated violence, terrorism, lone actors and organised criminal groups. None of these threats has disappeared. What is changing is the environment in which protected individuals now operate.
Across Europe, there is growing evidence of activity linked to foreign states, intelligence services, proxy structures and locally recruited individuals acting on their behalf. Sabotage, arson and operations targeting logistics, businesses, infrastructure and specific individuals are increasingly taking place within ordinary civilian settings.
For professionals working in executive and close protection, this is not an abstract discussion about geopolitics. It is a practical risk-management issue.
A client may have no dispute with any state, appear on no target list and have no involvement in the defence sector. They may simply be a CEO, investor, entrepreneur or public figure who happens to be staying in the same hotel, attending the same conference or dining in the same restaurant as someone who is of genuine interest to a hostile actor.
A VIP could always find themselves in the wrong place at the wrong time. What is changing is the type of event that can turn an otherwise routine civilian setting into the wrong place. Increasingly, that environment may become part of an act of sabotage, proxy activity or an operation connected to a conflict being pursued far beyond the conventional front line.
The practical consequence is straightforward: the client’s own threat profile may no longer provide the whole picture. The environment into which they are being introduced may matter just as much.
When conflict moves beyond the front line

One of the clearest examples is the case of Armin Papperger, CEO of Rheinmetall.
In July 2024, reports emerged of a Russian plot to assassinate him. US intelligence reportedly identified preparations for the attack and informed the German authorities. In January 2025, NATO’s James Appathurai publicly confirmed the threat to Papperger and placed it within a wider campaign involving arson, railway disruption, attacks on politicians’ property and plans targeting industrial leaders.
A client’s business interests have always mattered to a competent threat assessment. What is different now is the scale of the exposure and the relevance of connections that might previously have seemed peripheral.
A private-sector CEO may attract the attention of a foreign state not because of wealth, visibility or a personal dispute, but because the organisation they lead is seen as contributing to an adversary’s strategic capability. Nor is this limited to defence manufacturers. Technology, logistics, energy, telecommunications, infrastructure, finance and particular supply chains may all create relevant exposure.
The traditional question — “Who might want to harm our client?” — still matters. But for some clients, another may be just as important: could the organisation they represent attract hostile-state or foreign intelligence interest?
The more difficult scenario is one in which the client has no connection to the conflict at all, but is operating in the same environment as someone who does.
The same hotel, conference, airport terminal or office building may bring together individuals with completely different threat profiles. The actual target of an operation may not be our client. They may simply be a few metres away.
A similar dynamic can be seen in the arson attack on an industrial unit in Leyton, east London, in March 2024. The premises contained supplies intended for Ukraine, including humanitarian aid and Starlink equipment. British authorities later established that those responsible for organising the attack were acting on behalf of Russia.
The case involved contact with the Wagner Group, the recruitment of operatives, reconnaissance of potential targets and preparations for further activity. It illustrates a proxy model in which the state connection may be almost invisible at the point of execution.
At street level, such an operation may look like ordinary criminality. Local recruits, encrypted messaging, money, surveillance and an arson attack may give few obvious indications of state direction or intelligence involvement.
The same investigation identified preparations for further attacks in Mayfair and a plan to kidnap the owner of the premises, a prominent critic of the Russian state. Sabotage, commercial interests, physical locations and a direct threat to an individual all formed part of the same operational picture.
For a CPO, the implication is simple enough. A logistics company, office, distribution centre or manufacturing facility should not be assessed solely in terms of physical security. It also matters who operates from that location, what they do and whether their activities may attract interest beyond the conventional criminal threat environment.
Another aspect of the problem emerged through self-igniting parcels sent through European logistics networks in 2024. Packages caught fire in sorting facilities, warehouses and during transport. One ignited at Leipzig Airport shortly before it was due to be loaded onto an aircraft.
In March 2026, Eurojust reported that a multinational investigation had identified 22 suspects in Poland and Lithuania believed to have acted on behalf of Russian military intelligence. Investigators also uncovered what were described as test consignments sent to the United States and Canada.
The implications extend well beyond mail screening. Protected travel depends on civilian logistics infrastructure: airports, terminals, hotels, baggage systems, courier networks and freight services. Protection teams also move equipment, documents and other operational items through those same systems. Disruption can affect both security and programme continuity.
A fire in a sorting facility or the closure of a terminal may be nothing more than a technical incident. A CPO is not expected to determine whether it has an intelligence dimension. What matters is how it affects the principal and whether it forms part of a wider pattern in that city, region or country.
Civilian space is not always neutral
The fire at the Marywilska 44 shopping complex in Warsaw in May 2024 was initially understood primarily as a major commercial disaster. In May 2025, the Polish authorities announced that they regarded it as a deliberate act of arson commissioned by Russian services. According to a joint government statement, the perpetrators’ actions were organised and directed by an individual based in the Russian Federation.
What matters here is the nature of the location. A shopping centre is not a military base or defence facility. It is an ordinary civilian environment: retail units, restaurants, car parks, service businesses and large numbers of people with no connection to any conflict.
These are precisely the kinds of places that routinely feature in protective programmes. If they can become targets of sabotage for reasons entirely unrelated to the principal, asking only whether the client is the target no longer provides a complete picture of risk.
The location itself may be attractive to an adversary for economic, political, media or symbolic reasons. For the client, that motivation quickly becomes secondary if they are inside the building when a fire, explosion or emergency evacuation begins.
The bombing in Monaco in June 2026 illustrates the issue even more directly.
An explosive device was left outside a building and remotely detonated as businessman Vadym Yermolaiev approached the entrance with his partner and son. Anastasiia Berezovska became the principal suspect. According to the Monaco prosecutor’s office, the preparation of the attack suggested that she was unlikely to have acted alone and investigators were examining possible accomplices and those who may have commissioned it.
Several days later, Berezovska was found shot dead in Ukraine. Two men were subsequently detained in connection with her death, including an officer serving with Ukrainian military intelligence and a former law-enforcement officer.
There is, however, no sufficient basis at present for describing the Monaco bombing itself as a confirmed operation by any state or intelligence service. The motive, commissioning party and full background remain under investigation.
For protective security, the relevance of the case lies elsewhere. The attack took place in a high-end civilian setting. The target was accompanied by family members. It involved prior reconnaissance, an explosive device and remote initiation. This was not a war zone, but an environment in which our own client, their family or a business associate might easily have been staying.
A protection team may never know who ultimately authorised such an operation. What matters is what an incident of that nature would mean for the principal and the protective operation.
The underlying phenomenon is not new. One of the best-known historical examples remains the killing of Mahmoud al-Mabhouh in a Dubai hotel in 2010.
The investigation reconstructed the movements of a multi-person team that monitored the target, used false or unlawfully obtained identities and European passports, exploited hotel infrastructure and rapidly left the UAE after the killing. Dubai Police attributed the operation to Mossad, while Israel did not formally acknowledge responsibility.
The lesson remains relevant: a high-end hotel does not become neutral territory simply because it has CCTV, security staff, access control and an international brand. Good security reduces many forms of risk. It does not remove the possibility of a professionally planned operation against someone who happens to share the same environment as our client.
From the client’s threat profile to the threat profile of the environment

The wrong conclusion from these cases would be that close protection personnel should attempt to confront foreign intelligence services.
That is not their role. A protection officer is not a counter-intelligence operative, does not conduct state-level investigations and does not replace national security agencies. The task remains to protect the client, manage risk, preserve continuity and reduce exposure.
What changes is the information required to do that effectively.
Professional threat assessment should not stop at threats directed against the principal. Increasingly, attention also needs to be paid to risk generated by another individual, organisation, location or event within the client’s immediate environment.
For planning purposes, it is useful to think in terms of collateral exposure: the client may not be the intended target, yet still be exposed to the consequences of action directed elsewhere.
Those consequences might include an explosion, fire, evacuation, police lockdown, road closure, terminal shutdown, protest, attack on another individual or sabotage of infrastructure.
From the principal’s perspective, the original motive quickly becomes secondary. If the client cannot leave the building, their vehicle has been cut off, the hotel is being evacuated or an attack is taking place nearby, the threat has become their problem regardless of the perpetrator’s original intent.
This has direct implications for advance work.
Routes, access points, parking, evacuation options, venue procedures, medical support and contingencies remain fundamental. But a team can assess every one of these correctly and still miss a significant source of risk if the analysis ends with the client.
A well-secured hotel may also be hosting a government delegation, senior defence-sector executives or a businessman of interest to a foreign intelligence service. An office building may contain companies involved in strategic logistics, energy or technology used by one side in a conflict. A restaurant selected simply for dinner may belong to an entrepreneur with significant political exposure.
Advance work should not become an intelligence assessment of an entire city. But it may mean looking beyond the venue itself: what major events are taking place nearby, which delegations are in town, who else uses the building and whether any of those factors materially change the local threat picture.
In some circumstances, it may also matter who owns or primarily occupies a venue and whether that organisation carries particular political, commercial or conflict-related exposure.
The wider state-threat environment matters too. A series of arson attacks, arrests linked to foreign intelligence activity, incidents involving infrastructure or official warnings from national authorities do not automatically mean that a specific principal is at greater risk. They may, however, indicate that the environment into which the client is being introduced has changed.
MI5 has publicly warned that hostile states are increasingly using proxies to conduct surveillance, sabotage, arson and physical violence, including individuals recruited through online platforms. For the protection team, the practical point is simpler: current reporting on this activity should feed into the wider risk picture before the principal arrives.
Local incidents should be read in the same way. A single warehouse fire may mean nothing. Several similar events affecting the same sector or infrastructure deserve attention, even where the EP team cannot establish the underlying cause.
The same applies to protest activity. It is not always enough to ask whether a demonstration is directed at the client or the client’s organisation. The more useful question may be who else is being protested against in the locations through which the client will move.
A protest against another company in the same building, a delegation staying at a nearby hotel or an event taking place several hundred metres away may be enough to create road closures, police deployments, public disorder or difficulties with extraction. The demonstrators do not need to know that the principal is present for the consequences to affect the protective operation.
That leads to a question which should feature more often in advance planning:
If our client is not the target, who or what in their immediate environment might be — and what happens to our client if that threat materialises?
Traditional threat assessment remains essential. In the current operating environment, however, it may no longer provide the whole picture.
Advance does not end with the site survey

Information gathered during an advance may be accurate when collected and no longer reflect the real situation several days later.
A delegation arrives at the hotel that was not previously expected. A demonstration is announced. An infrastructure incident occurs. National authorities issue a new warning. Transport arrangements change. A high-profile participant is added to an event and alters the security profile of the venue.
In a dynamic threat environment, advance work has to be treated as a process rather than a one-off activity. An assessment completed several days earlier needs another look before arrival, and it needs to keep evolving once the programme is under way.
In practice, protective intelligence, advance work and dynamic risk assessment need to inform one another throughout the programme. The objective is not to predict every possible hostile operation. It is to identify meaningful changes early enough to avoid placing the client in an environment that could reasonably have been avoided.
Consider a routine programme.
The client arrives in London, Dubai, Zurich, Warsaw or Monaco. There is a hotel, dinner, a business meeting, a private visit and perhaps a marina or club.
The team has checked the route, access points, parking, alternative exits, venue security and medical support. From the perspective of a conventional advance, everything appears satisfactory.
But another politically exposed individual is staying in the same hotel. A defence-related company operates from the building the client will visit. A demonstration against a foreign delegation has been announced nearby. The city has experienced a series of suspicious incidents over the preceding weeks. The restaurant belongs to a businessman involved in a dispute with a foreign state.
People appear in the lobby who have no interest whatsoever in our client.
If an explosion, arson attack, emergency evacuation, police lockdown, attack on another individual or act of sabotage follows, the client becomes part of the incident whether or not they ever featured in the perpetrator’s planning.
It is no longer enough to understand who may want to target our client. We also need to understand who or what may be targeted around them — and what will happen to the client if that target is attacked.
Because the threat to our client may be created by an adversary who never came for them in the first place.
Selected sources
- Reuters — reporting on the plot against Rheinmetall CEO Armin Papperger and wider Russian sabotage activity in Europe, 2024–2025.
- Counter Terrorism Policing and Crown Prosecution Service — materials relating to the Leyton arson attack, activity undertaken on behalf of Russia and preparations for further operations in London, 2025.
- Eurojust — “Joint investigation team disrupts group using self-igniting parcels for terrorist attacks”, 6 March 2026.
- Polish Ministry of Justice / Ministry of the Interior and Administration — joint statement concerning the Marywilska 44 fire, 11 May 2025.
- Reuters — reporting on the Monaco bombing, the investigation involving Anastasiia Berezovska and her subsequent death in Ukraine, June–July 2026.
- MI5 — “Director General Sir Ken McCallum gives threat update”, 16 October 2025.
- Reuters and Hansard — reporting and parliamentary material concerning the killing of Mahmoud al-Mabhouh in Dubai and the use of third-country passports, 2010.
This article forms part of a Global Protection Group series examining the practical realities of Executive Protection and the professional preparation required for protective work. The series addresses recurring questions and misconceptions, placing key issues in the context of real-world operating conditions and challenging persistent myths about the profession.


