Tuesday, September 29, 2026 Newsletter Advertise
Breaking
Products

Cisco Talos launches Executive Threat Detection hunting service

Cisco Talos Incident Response says the retainer-based service runs monthly human-led threat hunts on systems tied to up to 10 executives.

Cisco Talos launches Executive Threat Detection hunting service. Source: Cisco Talos

Cisco Talos Incident Response announced Executive Threat Detection (ETD) on September 29, 2026, a proactive service that applies monthly, human-led threat hunting and intelligence analysis to the corporate systems of an organization's senior leaders. The company said the offering joins its existing suite of retainer services.

What Cisco Talos is offering

Talos said ETD provides protection for up to 10 principals, with monthly custom threat hunts and reports relevant to those principals' corporate systems.

The company described the service as "a specialized, ongoing proactive service that provides monthly, human-led threat hunting and intelligence analysis," delivered by a dedicated team of Talos IR experts rather than automated tooling. Its stated goal is to detect the compromise of executive-associated assets before they can be leveraged for a larger breach.

The gap Talos says it is addressing

According to Talos, the threat landscape has become more personalized, and the company said it is seeing a significant surge in whaling and highly targeted campaigns where the objective is the leadership team rather than the average user.

Leadership accounts often hold elevated access to sensitive financial data, intellectual property and strategic roadmap communications, Talos wrote, and an executive's digital footprint often extends beyond the traditional corporate perimeter.

The company argued that enterprise-wide endpoint detection and response is typically tuned for the average user profile, and that low-and-slow techniques used to compromise a CEO or CFO can be lost in the noise of a 10,000-endpoint environment.

How the service works

Talos said its Incident Commanders and Intelligence Analysts perform a monthly open-source intelligence review looking for threats aimed at executive personas, citing examples such as a new phishing kit designed to bypass multi-factor authentication for high-profile targets or a zero-day exploit being sold on the dark web.

IR consultants then run two hunt types: Baseline Threat Hunting, a deep-dive review of events and telemetry that includes searching for living-off-the-land techniques, and Emerging Threat Hunting, which applies atomic and pattern-based indicators from the monthly OSINT review. Threat intelligence analysts separately monitor for indications that an executive's corporate information may have been compromised or leaked.

The company said ETD is designed to be compatible with a customer's existing security stack, and that Talos IR typically gains the visibility it needs with existing tools without requiring changes to executives' systems.

Deliverables and retainer integration

Subscribers receive a monthly ETD report detailing hunting notes, final dispositions and observations — including lower-severity risks such as vulnerable browser versions or outdated software — plus an executive threat news summary and strategic recommendations for remediation, Talos said.

Because the service is delivered through the standard Talos IR retainer, the company said customers can shift hours to an Emergency Response engagement if a monthly hunt uncovers a critical incident. Talos directed prospective customers to their Cisco account representative or the Talos IR portal.

What to do

  • Organizations interested in the service should contact their Cisco account representative or visit the Talos IR portal, according to Cisco Talos.
  • Review whether enterprise EDR tuning accounts for executive accounts, which Talos says can hide low-and-slow intrusion activity in large environments.
  • Track basic hygiene issues on leadership devices, such as outdated software and vulnerable browser versions, which Talos lists among its monthly reporting items.
Key facts and where they come from
  • ETD covers up to 10 principals with monthly custom hunts and reports.
    Executive Threat Detection offers protection for up to 10 principals, with monthly custom threat hunts and reports relevant to those principals’ corporate systems.
  • Talos says targeted campaigns against leadership are rising.
    Today, we are seeing a significant surge in whaling and highly targeted campaigns where the objective is the leadership team, not the average user.
  • The service is human-led rather than automated.
    ETD is a specialized, ongoing proactive service that provides monthly, human-led threat hunting and intelligence analysis.
  • Talos says no changes to executive systems are typically required.
    Talos IR typically gains the visibility we need with your existing security tools, not requiring any changes to your executives’ systems.
  • Hunt hours can be converted to emergency response.
    If a monthly hunt uncovers a critical incident, you can immediately transition those hours to an Emergency Response engagement
  • Monthly reporting includes lower-severity hygiene issues.
    We report on everything from high-priority threats to "mundane" but critical risks, such as vulnerable browser versions or outdated software.

Read the original from Cisco Talos →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Products