Key role targeted cyber attacks are on the rise

Cyber criminals are launching cyber attacks against C-suite executives and their families

Add bookmark
Key role targeted cyber attacks are on the rise

Research by Ponemon Institute and cyber security company BlackCloak has found that hackers have been directly targeting C-suite executives and their family members with cyber attacks via their personal email addresses. 

In Understanding the serious risks to executives’ personal cybersecurity and digital lives, which was released on June 5, researchers found that 42 percent of organizations said that an executive or an executive’s family member had been the direct target of a cyber attack. This targeted threat vector is also referred to as key employee/role targeting

Cyber Security Hub research has found that more than one in four (26 percent) cyber security professionals believe that key employee/role targeting will have the biggest impact on cyber security in 2023.

The Ponemon Institute and BlackCloak institution found that executives and their families are targeted with a number of threat vectors including social engineering-, malware- and network infiltration-based attacks.

Chris Pierson, founder and CEO of BlackCloak, explained to cyber security news site Cybersecurity Dive that “cybercriminals have realized that most executives are almost completely unprotected outside of their corporate accounts and devices”, meaning that they are particularly vulnerable to these attacks. 

The research also found that this issue represents a significant part of cyber security employee’s roles. On a scale from one to ten, where ten represents something intensely time-consuming, 35 percent of respondents rated the amount of time they spent on key role targeting as a nine or ten. 

Read more about social engineering attacks in Cyber Security Hub’s guide to this manipulate threat vector. 


Upcoming Events

Automotive Cyber Security, Connectivity & SDV Week 2025

18th - 20th November, 2025

Van der Valk Hotel Berlin Brandenburg, Germany

Automotive Cyber Security, Connectivity & SDV Week 2025

Digital Identity Week

1st - 2nd September 2026

Sydney, Australia

Digital Identity Week

Latest Webinars

From Dependencies to Defences: Navigating Software Supply Chain Security

2025-09-24

11:00 AM - 12:00 PM SGT

Learn how to defend your software supply chain from dependency threats and build resilient security...

Unpacking global regulatory frameworks to enhance third-party operational resilience

2024-11-14

11:00 AM - 12:00 PM EST

Join this webinar to explore the resilience-focused requirements of DORA, NIS2 and other global regu...

Preventing financial and reputational risk with process intelligence

2024-05-23

11:00 AM - 12:00 PM EDT

Learn how to manage risk stemming from poorly controlled processes in a collaborative way

Recommended