Also on CyberFence: CyberFence's industry directory for other professions · CyberFence for Teams for business VPN with BAA and SSO .

Professional executive assistant working on laptop in modern high-rise office with city view

Executive assistants occupy a uniquely exposed position in the organizations they support. They have access to executive email accounts, board meeting materials, compensation data, M&A discussions, travel itineraries, and sometimes financial accounts — the most sensitive information in the company. At the same time, their work takes them everywhere: hotel lobbies, airport lounges, conference centers, and client offices, all with their laptops open and their credentials active.

This combination makes EAs one of the most targeted professional roles in corporate spear-phishing campaigns. Attackers know that compromising an executive assistant's credentials often yields access to executive-level communications and systems — without ever needing to target the executive directly.

A VPN is not glamorous, but for an EA, it is one of the most practical security tools available. Here is why it matters for this specific role, and what to look for.

What Executive Assistants Actually Have Access To

The scope of access an EA manages varies by organization, but at a senior level it commonly includes:

  • Executive email — often with delegated access or the ability to send as the executive
  • Calendar and scheduling systems that reveal who the executive is meeting with and when
  • Board meeting materials, including pre-decisional documents, financial projections, and M&A discussions
  • Travel itineraries — which function as a real-time map of executive whereabouts
  • Expense management and corporate card portals
  • HR and compensation systems for executives and senior staff
  • Document management systems with legal, regulatory, or strategic filings
  • CRM access for executive relationships and pipeline data

Each of these represents a high-value target on its own. Together, they make an EA account one of the most valuable assets an attacker can compromise in a corporate network.

Why Executive Assistants Are Targeted by Spear-Phishing

Spear-phishing — targeted phishing attacks that use personalized information to appear legitimate — specifically targets EAs because they sit at a strategic point in the information flow. An attacker who wants executive communications does not need to crack a heavily protected executive account. They target the EA whose delegated access is just as valuable and whose account may receive less security scrutiny.

Common attack patterns targeting executive assistants include:

  • CEO fraud / business email compromise (BEC): Attackers impersonate the executive and ask the EA to take an action — wire a payment, share a document, or reset credentials. These attacks are highly convincing and often land when the EA is traveling or working remotely.
  • Vendor impersonation: Fake invoices or requests from vendors the EA regularly works with, using spoofed or compromised vendor domains.
  • IT impersonation: Fake security alerts or password reset notices that capture the EA's credentials through a lookalike login page.
  • Travel and booking phishing: Fake booking confirmations or change notices targeting EAs who manage executive travel.

What all of these have in common is that they work best when the target is distracted — on the road, connecting from an unfamiliar network, quickly checking email between meetings. Which is exactly when a VPN matters most.

Protect every connection from the road or the office

CyberFence encrypts all traffic with AES-256-GCM encryption and blocks malicious domains through Web Shield DNS filtering before they load. One subscription covers every device — laptop, phone, and tablet.

Available on Windows, macOS, iOS, and Android. US-operated. Zero logs.

Try CyberFence Free

The Travel Risk Is Concrete and Well-Documented

EAs who travel with executives — or manage executive travel logistics while working remotely — regularly connect from hotel networks, airport lounges, conference centers, and client offices. These are consistently the highest-risk locations for network-based attacks.

According to Forbes Advisor research, 40% of travelers have had their information compromised while using public Wi-Fi. Hotels and airports are among the top three locations where compromises occur. Microsoft issued a specific advisory in 2026 documenting active hotel Wi-Fi attack campaigns targeting business travelers — a threat that directly maps to the EA use case.

When an EA connects to hotel Wi-Fi to check executive email, review board documents, or log into a travel management system, all of that traffic can be intercepted on an unprotected network. A VPN closes this gap by encrypting everything between the device and the destination system before it ever touches the hotel network.

The Specific Risks of Unprotected Connections for EAs

Session Hijacking on Executive-Delegated Accounts

When you access web-based email or document systems, the browser stores a session token that proves you've already authenticated. On an unprotected network, an attacker can capture that token and use it to access the same account — without needing your password. This is called session hijacking, and it is a documented attack technique that works against any web application on an unencrypted connection. For an EA with delegated access to an executive's email, a hijacked session means an attacker has full send-as access to that inbox.

DNS Hijacking Targeting Login Pages

On networks where an attacker controls the router or DNS resolution, they can redirect your login attempt for a legitimate service — Office 365, a corporate portal, an expense management system — to a convincing fake version of that page. You enter your credentials, the fake page captures them, and you're redirected to the real site as if nothing happened. Web Shield DNS protection resolves this by encrypting your DNS queries and blocking known malicious domains before the redirect can occur.

Man-in-the-Middle on Corporate Communications

On hotel and airport Wi-Fi, an attacker positioned between your device and the internet can intercept unencrypted traffic, modify it in transit, or capture credentials passed over older or improperly configured connections. For an EA processing board communications or financial approvals remotely, this is a direct business risk — not just a personal data risk.

What to Look for in a VPN for This Role

Not all VPNs are appropriate for professional use involving sensitive organizational data. Here is what matters specifically for an executive assistant role:

  • AES-256-GCM encryption: The current standard for protecting data in transit. This is what major financial institutions and government contractors require for sensitive communications.
  • Zero-logs policy: Your activity — what systems you connect to, when, and from where — should not be stored anywhere. An EA's work patterns are sensitive information; a VPN that logs your activity creates a record that could itself become a liability.
  • DNS protection (Web Shield): Blocks phishing domains at the network layer before they can load. This is the layer that stops the credential-harvesting fake login pages that are most common in spear-phishing attacks against administrative professionals.
  • Kill switch: Ensures that if the VPN connection drops momentarily, no traffic leaves the device unencrypted. Critical when accessing executive email on mobile networks that may fluctuate.
  • Multi-device coverage: An EA's work does not stay on one device. A single subscription that covers laptop, phone, and tablet ensures every access point is protected.
  • US-operated infrastructure: For organizations that handle regulated data or government-adjacent work, knowing that your VPN traffic routes through US-operated servers under US legal frameworks matters.

Practical Setup for Executive Assistants

The security benefit of a VPN depends entirely on actually using it. Here are the habits that matter:

  • Connect before opening any work application — make VPN connection the first step, before email, before calendar, before anything else. This eliminates the window of unprotected exposure that occurs when you connect to a new network.
  • Use it on every non-office network — including hotel Wi-Fi, conference center Wi-Fi, client office networks, and home Wi-Fi when working remotely. The risk is not limited to obviously public locations.
  • Enable the kill switch in settings — this should be a one-time configuration step, not something you think about daily.
  • Install on your phone as well as your laptop — executive communications increasingly happen on mobile. Checking delegated email on an unprotected hotel network on your phone carries the same risk as doing it on your laptop.
  • When in doubt about a login page, don't enter credentials — Web Shield blocks most phishing domains, but the habit of pausing before entering credentials on any page you weren't expecting is its own layer of protection.

The Bottom Line for Administrative Professionals

The executive assistant role is one of the most trusted positions in any organization — and that trust makes it a target. Attackers who compromise an EA account often gain access to more actionable intelligence than they would get from many other entry points in the organization.

A VPN does not replace strong passwords, multi-factor authentication, or security awareness training. But it closes the network-layer attack vector that is most commonly exploited when professionals work from hotels, airports, and client locations — which is where the highest-stakes work for an EA often happens.

For an EA who carries executive communications in every bag, a few dollars a month for encrypted connections on every device is one of the most cost-effective security investments available.

CyberFence covers every device, every network

AES-256-GCM encryption, Web Shield DNS blocking, zero logs, kill switch, and US-operated infrastructure. Monthly $7.99/mo or Annual $88.21/yr ($7.35/mo, save 8%).

Works on Windows, macOS, iOS, and Android. One subscription, all your devices.

Start Your Free Trial

Want to go deeper? Read how CyberFence protects other regulated industries , the CyberFence Teams product page , or CyberFence plans and pricing .