Family office

Serious assets, protected by a very small team

A family office can hold hundreds of millions in assets and run on a handful of people. That combination is exactly what attackers look for, because the money is significant and the security team usually does not exist.

Published research

43% of family offices were attacked in the last year or two

Deloitte's Family Office Cybersecurity Report found that 43% of family offices globally had experienced a cyberattack in the previous 12 to 24 months, rising to 57% in North America and 62% for offices with more than one billion US dollars under management. Despite that, 31% had no incident response plan at all.

Source: Deloitte Family Office Cybersecurity Report

What it means for you

Size attracts attention, and a lean team is the reason an attack works rather than a reason it will not happen.

What we hear

The pressure points in family office

Wire and payment instructions

Large transfers approved over email, which is the single most targeted process in this sector.

Family devices outside the office

Phones, laptops, and home networks used by family members who are not employees and never will be.

Several entities, one small team

Trusts, holdings, and operating businesses each with their own systems and no single owner of IT.

Discretion above everything

You need the work done quietly, by people who do not talk about who they work for.

What we put in place

Built for how you actually operate

Not a generic support plan with your industry written on the cover. These are the things that matter in your environment.

Payment fraud controls

Verification steps for wire and payment instruction changes, plus email controls that make impersonation far harder to pull off.

Protection for principals and family

Device security, secure home network setup, and private account hardening for the people an attacker would research first.

Identity controls across entities

Multi factor authentication, conditional access, and a clear record of who can reach which entity's systems.

An incident response plan that exists

Written steps, named contacts, and a tested path back, so nobody is improvising on the worst day.

Backups for private records

Immutable offline copies of documents, accounting data, and correspondence, tested rather than assumed.

Quiet, senior support

A small group of experienced technicians who know the family, hold confidentiality seriously, and do not rotate.

What changes

What it looks like once this is running

We start by reviewing what you have now and telling you honestly what would cause problems. No obligation, and no pressure either way.

Talk about your environment
  • A verification step between a fraudulent email and a large transfer
  • Family and principal devices protected, not just office machines
  • One clear picture of access across every entity
  • A written response plan instead of a scramble

Let us look at your setup

A short call, a clear picture of where you stand, and a straight answer about what is worth fixing first.