Q&A: BlackCloak’s Dr. Chris Pierson On Deepfakes, Executive Risk, And Building A Circle Of Trust

BlackCloak's Dr. Chris Pierson on why executives are the softest target, how AI has changed the deepfake threat, and the new Impersonation Protection with circle of trust launching at Black Hat 2026.

Published on Jul 28, 2026
Joel Witts Written by Joel Witts
BlackCloak Black Hat Interview

Companies spend millions defending the corporate network. Yet the executives who run those companies often have almost nothing protecting them at home. Their addresses sit on data broker sites, their passwords surface in breaches, and their voices and faces are all over earnings calls, conference stages, and the company website.

Attackers know this. Rather than breaking through hardened enterprise defenses, they target executives and their families in their personal lives, then use that access to get back into the business. The rise of AI-generated deepfakes has made those attacks faster, cheaper, and far more convincing.

Dr. Chris Pierson is the Founder and CEO of BlackCloak, the company that created the Digital Executive Protection category. Pierson is a former CISO and Chief Privacy Officer, and a longtime Department of Homeland Security advisor.

We spoke to him ahead of Black Hat 2026 about the threats facing executives today, why deepfakes have changed the game, and BlackCloak’s new circle of trust enhancement to their Impersonation Protection feature, which the company is debuting at the show.

Answers have been edited for clarity and length.

You’ve been a pioneer of the Digital Executive Protection category. For readers who aren’t familiar, can you talk about your background, what BlackCloak does, and how you came to found the company?

A lot of this came from my own experiences, both in the classified world and as a CISO. Your executives, your leadership team, your board members are the who’s who of the company. They’re always out there in PR, in the media, on the website. They’re the face of the business, and cybercriminals and nation states know that. A dedicated, focused attack on those executives or their family members can gain access to the home, personal devices, and personal email accounts, and from there back into the company. We’ve seen it happen in breaches like LastPass and LinkedIn, where the compromise started in someone’s personal life and led back into the enterprise.

I saw this firsthand, and I became frustrated that the risk couldn’t be mitigated with any of the tools I had as a CISO. Throwing some identity theft protection at it doesn’t work. So we created a category, Digital Executive Protection, and BlackCloak now protects up to 500 individuals at major Fortune 100 and Fortune 500 companies, along with their family members, in their personal lives.

The platform works through three functions: our threat intelligence platform, our own SOC (Security Operations Center), where our team monitors and protects devices, and the BlackCloak applications running on the endpoints of executives and their families. That covers four areas. First, privacy and identity, including data broker removal, dark web monitoring, home blurring, VPNs, and identity theft protection. Second, deepfake and AI protection for their image, voice, and likeness. Third, physical threat intelligence and travel advisory, a lot of which we deliver through our deception technology. And fourth, the home network, where we run dedicated penetration testing every seven days to make sure no one can intrude.

We’re only focused on the personal side, outside the four walls of the company. That’s the part that can come back to haunt the business or take down an executive for an extended period.

It’s striking how much companies spend on security, millions of dollars, while the executives themselves might have nothing protecting them.

Think about it. A company might spend fifty or a hundred million dollars on cybersecurity. Yet the executives who are named on the About Us leadership page are spending five dollars, maybe on some generic antivirus. That is insufficient. It is absolutely not going to stand up against a dedicated criminal organization or nation state, and it’s a risk to the company. These are the leaders, so there’s material business risk. Especially after the tragic murder of Brian Thompson at UnitedHealthcare, we all understand that the digital breadcrumbs and the physical risks have converged.

What do the threats facing executives actually look like?

Their addresses and phone numbers are exposed on data broker sites, so we have to shrink that attack surface to prevent doxxing and spotting. Their personal passwords are out there in breaches, and you can only change the password on their personal bank or brokerage account in their personal life. That isn’t the company’s remit.

We’ve had real cases. The mother of a general counsel at a top global institution was targeted. Attackers pieced together the digital breadcrumbs, figured out who she was, and sent people to her home to make bad things happen. We see ransomware on personal computers and extortion for the information and email accounts executives hold. Look at the recent compromise of Kash Patel’s personal Gmail. Everything is in your Gmail account.

One example really stays with me. We ran 41 straight weeks of clean penetration tests on a well-known bank CEO’s home. In week 42 we got in digitally, reached the safe room, and took full control of the alarm panel. What happened was that his home DVR had burned out over the weekend, the AV company came out to replace it, and they wired the new equipment outside the firewall. Suddenly someone could have had access to the safe room, could have shut off the hold-up alarms, and could have owned every computer on that home network, including the work laptop. That’s a kidnap and ransom risk to his family. This is serious, and it’s happening every day.

Deepfakes and AI social engineering are a growing concern. Many of our listeners will be familiar with the case where an employee wired $25 million after a deepfake video call impersonating leadership. How does that tie into BlackCloak, and why are these attacks more dangerous than traditional phishing?

AI and deepfakes blow away the idea that you only need to protect the inside of the company. This is the human attack surface, and it exists 24 hours a day.

What we’re seeing with deepfake voice and video is incredible. Your entire executive team is on Bloomberg, CNBC, and NASDAQ doing interviews, so their voices are recorded. Their high-, medium-, and low-resolution photos are on the website, put there by the PR and investor relations teams. There’s an enormous amount of material to build convincing voice and video fakes.

We fool ourselves into thinking we’re safe because we’ve integrated something into Zoom or Teams. But I’m not going to call your executive through your Zoom. I’m going to call their cell phone, their desk phone, their home phone, or reach them on Signal or WhatsApp, any way I can outside your controlled network, and you can’t stop it. A plug-in that scans Teams is useful for interviewing candidates and spotting a deepfake applicant, which is a good HR function. But it’s not going to confirm that the twenty people on your board call are who they say they are, or verify a call about M&A, litigation, or a financial transfer.

The technology to do this has gotten faster and easier, and it runs in real time. This isn’t like swapping one actor’s face for another in a movie ten years ago, which took thirty engineers and six months of supercomputers. This can be done live on a Chromebook with no real processing power. The threat landscape has changed, and the stakes are huge. All an attacker has to do is hit the personal life to affect the work life, or reach the work life through a personal device the company doesn’t control.

And executives travel constantly. You step off a plane, jet lagged, in a different time zone, and a deepfake message from someone you think is a colleague or family member lands. You’re highly susceptible in that moment.

You’re very susceptible. And here’s the interesting thing. In Ponemon surveys, 42% of executives say they’ve been targeted by a deepfake. In a Techstrong PulseMeter report, 36% say their family members have been targeted. That’s only who reported it, so the real number is almost certainly much higher. An attacker will always choose the personal device. Why go through the corporation with all its controls when you can target a personal device that has nothing on it? In that same poll, 76% of respondents said this problem has to be solved. It isn’t being solved yet, and funneling every attacker through Zoom is not the answer.

When you talk to executives, what practical advice do you give them about spotting these deepfake risks?

The number one thing I want people to do is use the BlackCloak platform, specifically our Impersonation Protection with circle of trust, because it lets you verify people instantly and out of band, without relying on any of your corporate technology or stack. If you can confirm out of band that it’s a trusted connection, you know it before the “do you want to transfer 10 million dollars” request goes through, or before you act on a message that the bank account has changed for a property you’re buying.

Beyond that, some high-level guidance. If someone is calling or on a video, change the dynamic by reaching back out to that person through a known, trusted connection. It’s not enough for a call to come in with the right number, or even a video call on FaceTime or Zoom. You have to initiate the call back to a known good person on a known good number before you act. For financial or HR matters especially, you want two people to turn the keys.

Family code words are the easy answer, but they often don’t work, because the one word people choose tends to be tied to something already exposed in a breach or sitting in a social media feed. What’s really needed is awareness that this is happening, education for executives in finance, legal, and HR and for their family members, and technology to supplement all of it.

One of the biggest challenges is that corporations lack visibility into their executives’ personal lives. How does BlackCloak bridge that gap, and what needs to be part of a complete strategy to protect digital executives?

Think about it the way we think about health insurance. A company selects a provider and offers it to employees and their families. The family gets the benefit of good health and care, the company benefits from executives who stay healthy and engaged, and everyone wins. Digital Executive Protection works the same way. When BlackCloak started eight years ago, bridging the gap meant being the trusted external third party that could give the CISO a tool to protect an executive’s privacy, cybersecurity, home network, and personal life without mixing that information back into the company. We share aggregate-level statistics only. We’re not an arm of the company monitoring its executives.

That’s why we’ve been successful. Around 25 to 27% of the Fortune 100 and roughly 22% of the Fortune 500 use us. We partner with the CISO, but we cover the other twelve hours of the day in a private, trusted, holistic platform, so the security team doesn’t have to step into an area full of legal and privacy risk. No CISO wants to assign staff to protect executives’ personal lives. But they also know the executive’s work and personal life are inextricably intertwined, and that it’s a material risk that has to be solved.

Your big launch at Black Hat is the new circle of trust. I’d love to hear how it works and the challenge you’re solving.

An executive has three main circles of people they work with. There’s the executive circle of other leaders and board members. There’s the family circle. And there’s the trusted third parties they interact with constantly, like their estate attorney, private wealth advisor, or chief of staff.

BlackCloak’s Impersonation Protection works through the trusted app the executive already has. Say I’m the CEO and you’re the CFO. If we’re on a call, I can open my BlackCloak app, go into the impersonation protection module, and send you a verification request. It confirms my biometrics and my location on the device, then sends it to you in real time. You open your app, see the request, and confirm whether it’s really you. Because it’s out of band and runs through a third-party app, it doesn’t matter whether our networks are clean or compromised. It works no matter how we’re communicating, whether that’s text, FaceTime, Zoom, Teams, a cell phone, a landline, WhatsApp, or Signal. Family members can verify each other the same way.

What we’re announcing at Black Hat is the expansion of that circle. The executive can now invite their private wealth advisor, lawyer, chief of staff, or another trusted person into the impersonation protection module. You invite them during a calm, non-urgent moment, confirm who they are, and from then on you have a way to verify them no matter where you are in the world. It’s a natural progression, and huge credit to our product and engineering teams. Everything BlackCloak does is built and operated by us.

This disrupts the old model. You no longer have to say you can only communicate on a verified corporate device through Zoom or a plug-in, or ask someone to send a photo so you can play junior investigator after the fact. And it works in the other direction too. If you can’t confirm that a board member is who they say they are and you click no, that instantly alerts our security operations center. We can also fork the alert over to your own SOC, so your team can run its own playbook, whether that’s turning off Okta access, restricting rights, or rotating the phone. That one-second yes or no can save you 25, 50, or 100 million dollars.

Your team mentioned a real kidnapping-related incident involving a nanny picking up a child. Can you talk about that example and why it crystallizes how important this technology is?

Executives are extremely busy and travel constantly, sometimes away from home for a week or two at a time. They don’t always know where their kids are, and often that falls to a spouse or to nannies. The problem is that the people it falls to aren’t always well trained on fraud, scams, deepfakes, and phishing. That makes them an attractive target for a dedicated adversary looking for lower awareness than the executive, who is getting plenty of training.

We’ve seen calls that emulate the kidnapping of a child, tied to real events pulled from social media. In one case the child was a collegiate athlete at a swim meet, where there are no phones near the pool and it’s far too loud to hear a call anyway. The child was out of pocket for a stretch of time, and a virtual kidnapping scammer used the pattern of life and the details grabbed from social media to twist the system and extract money. 

We’ve seen these for years. What AI and deepfakes have done is level the playing field and make them far easier to pull off. And executives can’t simply get off social media or stop appearing in public. Their families are out there too, at community events on the weekend, which unfortunately puts extra eyes on them.

You built this platform for your peers, coming from a CISO and privacy background. How did you approach the privacy of the data you collect on executives and their families?

Done correctly, we hold very little. For data broker removal we have their name, address, phone number, email, IP address, and usually their year of birth or age. That’s it. What we want is their trust and their relationship.

We take all the data that’s exposed across Google searches, data brokers, and the deep web, and we shrink it down. We reduce their footprint from the start, then keep reducing it through what we call privacy hardening, where we harden browsers, email accounts, and social media accounts so they share less information and leave fewer digital breadcrumbs. Done across the whole family, sometimes three generations of it, that adds real, meaningful value.

It’s built with privacy in mind. Three of our ten executives are Certified Information Privacy Professionals through the IAPP (International Association of Privacy Professionals), and we imbue everyone at BlackCloak with that same alignment. You can’t bolt privacy on. It’s either led by the CEO and built into the DNA of everything you do, or it isn’t. There’s no second chance on that.

Black Hat 2026 is kicking off next week. What are you most looking forward to at the show?

First and foremost, the random hallway conversations with my former CISO peers and CEO friends. The relationships are what matter. Great business happens on the back of great relationships. Beyond that, we’ll have a booth in the innovation lab where we’re showing off the new Impersonation Protection with circle of trust, live and in real time, so people can take part in it themselves. We’ll have some talks and a few events with close partners, including an AI versus CISO session with my good friend Sachin Bansal from Schellman. It’s going to be a lot of great conversations and a lot of fun. I hope everyone will stop by the booth or grab me in the hallway.

Learn more about BlackCloak

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Joel Witts
Joel Witts Content Director

Joel is the Director of Content and a co-founder at Expert Insights; a rapidly growing media company focussed on covering cybersecurity solutions.

He’s an experienced journalist and editor with 8 years’ experience covering the cybersecurity space. He’s reviewed hundreds of cybersecurity solutions, interviewed hundreds of industry experts and produced dozens of industry reports read by thousands of CISOs and security professionals in topics like IAM, MFA, zero trust, email security, DevSecOps and more.

He also hosts the Expert Insights Podcast and co-writes the weekly newsletter, Decrypted. Joel is driven to share his team’s expertise with cybersecurity leaders to help them create more secure business foundations.