Executive Support Security Due Diligence
Evaluate identity, access, data handling, incident response, continuity, and offboarding before an executive support provider receives sensitive access.

- Define the executive support outcome
- Match role scope to leadership cadence
- Use a structured selection process
Start with the first two workflows
Security review should begin with the work a provider will actually perform, not a generic request for every control document. Map the first two workflows from trigger to accepted output. Calendar scheduling may require availability and delegated editing but not private event detail. Inbox triage may require reading selected messages while sending remains restricted. Name the company owner, systems, information classes, decision rights, and evidence needed for each step before discussing access.
Separate access from authority
A person may technically open a mailbox, move a meeting, or view a board folder without having authority to disclose, commit, approve, or send. Document those distinctions in the operating scope and permission design. Use verbs such as view, prepare, recommend, execute, release, and escalate. An urgent message or senior sender does not expand authority. The provider should be able to explain how staff recognize a boundary and who answers when the rule is unclear.
Require individual identity
Every worker and backup should use an attributable identity protected by multifactor authentication. Shared executive passwords weaken logging, complicate revocation, and make incident review unreliable. Ask how accounts are requested, approved, provisioned, changed, and removed. Confirm whether the provider uses company-managed delegation or its own tools, who administers those tools, and how the company can retrieve evidence without depending on the person whose activity is being reviewed.
Inspect devices and working locations
Ask which devices may handle company information, how they are encrypted, patched, locked, monitored, and retired, and whether personal devices or shared workspaces are permitted. The relevant answer depends on the data and contract, but it should be explicit. Review download behavior, local storage, printing, screenshots, removable media, and offline work. A policy statement matters less when the provider cannot show how a new worker receives and follows the required configuration.
Trace where information can travel
Follow a realistic attachment, calendar detail, contact record, and travel profile through email, chat, task systems, document stores, browser extensions, and provider platforms. Identify subprocessors and external support staff. Prefer controlled links over copied files when access can be managed at the source. Define retention and deletion for working copies. The review should expose hidden duplication without creating a new spreadsheet full of sensitive content.
Test a lookalike executive request
Use a fictional request from a domain or account that resembles an executive. It asks for an urgent calendar disclosure or document and discourages verification. Observe whether the provider checks identity, pauses the action, preserves the message, and alerts the approved contact. Do not reward speed. The exercise should show the exact stopping behavior, escalation channel, fallback when the security owner is unavailable, and record that remains after the event.
Examine backup activation
Coverage can improve continuity while expanding access. Name the backup, workflows covered, activation authority, minimum permissions, duration, and return handoff. Test a benign absence. The backup should find current instructions and open commitments without inheriting every historical message. When primary support returns, reconcile actions and remove temporary rights. A promise of team coverage is incomplete until the provider demonstrates this lifecycle and its audit trail.
Make incident terms operational
Contract language should identify what the provider reports, to whom, through which channel, and within what time after discovery. Ask how staff recognize a suspected incident and preserve evidence. Clarify cooperation, containment, customer decisions, regulator or affected-person communication, and post-incident review. The provider should not promise conclusions before investigation, but it must not wait for certainty before notifying the authorized company owner under the agreed rule.
Review people changes immediately
Role changes, leave, substitution, performance restrictions, and termination can alter access needs before a scheduled quarterly review. Define the event that triggers reassessment and the owner on both sides. Sample a fictional transfer from calendar support to board coordination and identify which old permissions disappear before new ones arrive. Keeping access because it may be useful later contradicts least privilege and increases the work required during an urgent revocation.
Verify offboarding end to end
Run the exit path from notice through open-work transfer, record return, device or account action, forwarding removal, integration ownership, credential rotation where needed, and deletion evidence. Confirm that company records remain usable without the provider's proprietary identity. Search for shared links, rules, automations, and scheduling pages that can survive account removal. Close the transition only when operations accepts the work and the security owner confirms revocation.
Use evidence proportionate to risk
Request evidence that answers the proposed workflow risk: access lists, configuration samples, training records, incident exercises, audit reports, deletion procedures, or contract commitments as appropriate. Certifications may support review but do not reveal which person can read a particular inbox. Document gaps, compensating controls, owner decisions, and expiry. Avoid collecting more provider-sensitive material than authorized reviewers can protect and use.
Ask who can change the controls
A documented setting can change after review. Identify the administrators who can widen permissions, add a subprocessor, disable logging, alter retention, or create an integration. Ask what approval and notification accompanies each change. Sample one recent non-sensitive change record if available. The company should know which changes require its consent, which merely require notice, and how it detects an unapproved deviation. Configuration ownership is part of the service boundary, not a purely technical detail.
Keep executives out of the verification shortcut
Providers sometimes rely on the supported executive to approve unusual requests in the same compromised channel. Define an independent verification route for high-consequence actions, such as a known security contact, approved call-back method, or controlled request system. The route should work during travel and absence without broadcasting confidential context. Test it before access begins. Executive urgency should not force a worker to choose between service expectations and the company's security rule.
Set the launch decision and review date
Approve only the bounded workflows whose identities, permissions, information paths, incident route, backup, and exit controls are understood. Record rejected or deferred access separately. Launch with least privilege and review early activity, exceptions, suspicious requests, and corrections after the first two cycles. Expand only when the operating evidence supports it. A mature decision may also conclude that one workflow should remain internal or in a more controlled system.
Related resources
Read also: Executive assistant support and Executive assistant access onboarding checklist. Source: NIST Cybersecurity Framework 2.0.
FAQ
Can one person perform both roles?
Sometimes, but only when the combined outcomes, authority, capacity tradeoffs, and review expectations are explicit.
Which role should a founder hire first?
Hire against the first missing outcome: stabilize executive flow when logistics and follow-through are failing; add broader synthesis when cross-functional decisions remain unresolved.
Discuss executive support