# Family Office Cybersecurity: The Risk You Cannot Buy Software For

> Why family offices are targets: business email compromise, deepfakes, the digital footprint, kidnap & ransom cover, callback verification, the first hour.

Author: Дана Берзег — адвокат, Family Office (https://wiki.private.law/authors/berzegova)
Last modified: 2026-07-30T18:16:00.000Z
Canonical: https://wiki.private.law/en/family-cybersecurity
Topics: structures
Jurisdictions: global
Semantic tags: company

---

Two years of industry research now converge on a conclusion that would have sounded odd not long ago: cybersecurity has become the number one operational risk for family offices — ahead of market volatility, succession and tax change. In the Family Office Operational Excellence Report 2025 (Campden Wealth, 146 offices surveyed November 2024 to March 2025), 70% of respondents named cyber their top operational risk, and more than 60% said they had already experienced at least one attack. Deloitte's Family Office Cybersecurity Report 2024 (354 single family offices, average AUM US$2.0 billion) reports a similar picture: 43% were attacked in the preceding 12–24 months, and a quarter three or more times.

The asymmetry behind those numbers matters more than the numbers themselves. On Deloitte's data, 31% of offices have no incident response plan at all, another 43% concede that theirs "could be better", and only 26% consider it robust. Most structures managing billions are therefore in a position where the question is not whether they will repel an attack, but whether anyone will know what to do in the first hours after one. What follows is about the mechanics of that risk — and about why almost everything that genuinely works against it is procedural rather than technological.

## A bank's capital behind a small firm's defences

A [family office](https://wiki.private.law/en/family-office) handles capital on a banking scale with the organisational defences of a small company: a handful of people, high mutual trust, minimal formal procedure and, as a rule, no dedicated information security function at all. Three structural weaknesses follow.

**Concentration.** A single administrator's mailbox typically holds everything at once: account details, ownership charts, transaction documents, passport scans, correspondence with banks. Compromising one account gives an attacker not a fragment but a map.

**A perimeter made of counterparties.** The office works through providers — administrators, auditors, lawyers, custodians, IT contractors. Campden Wealth finds 94% of offices outsource IT and 90% outsource cybersecurity itself; the real perimeter is the sum of the providers' perimeters. Deloitte, meanwhile, records that 68% have not adopted a "know your vendor" process.

**Informality.** Small headcount and high trust mean decisions are made quickly and often verbally. That speed is precisely what gets exploited.

## Business email compromise: the vector software cannot close

The main route by which money leaves a family office is not a system breach but an intrusion into correspondence. Business email compromise works like this: the attacker gains access to one party's mailbox — or registers a domain differing by a single letter — reads the thread silently for weeks, and at the last moment sends "updated" payment details. Formally nothing is broken: the message arrives from a genuine or near-genuine account, in the right thread, with the transaction details correct.

Scale, per the FBI's IC3: in 2025 BEC accounted for 24,768 complaints and US$3.05 billion in reported losses, second only to investment fraud. Cumulatively, from October 2013 to December 2023, the FBI puts global exposed BEC losses at US$55.5 billion across 305,033 incidents.

Technical controls are close to useless here, because from the systems' point of view everything is legitimate — an employee initiates the payment himself. The remedy is procedural:

- **Callback verification.** Any change of payment details is confirmed by an outbound call to a number held in your own system of record, never one supplied in the email. J.P. Morgan puts the rule bluntly: make the call yourself, treat an inbound call as no confirmation at all, and speak to the person actually responsible for the change.
- **Dual authorisation above a threshold** — two independent people, neither able to release a transfer alone.
- **An outright prohibition on changing payment details on the strength of an email**, stated as a principle rather than a preference.
None of this requires budget. All of it requires that the rule be written down and that urgency cannot be invoked to bypass it.

## Deepfakes: how voice verification broke

Callback rests on the assumption that a person recognises the voice on the other end. Since 2024 that assumption has ceased to be a defence.

The canonical case is the engineering firm Arup. In January 2024 an employee in its Hong Kong office received a message purportedly from the UK-based CFO about a "confidential transaction", then joined a video conference populated by synthesised images and voices of the CFO and several colleagues he knew personally. He went on to make 15 transfers to five Hong Kong bank accounts totalling HK$200 million — roughly US$25 million. The company confirmed that "fake voices and images were used", adding that none of its internal systems had been compromised.

That last clause is the important one. Nothing was hacked; what broke was verification.

The trend is independently corroborated. CrowdStrike's 2025 Global Threat Report recorded a 442% rise in vishing in the second half of 2024 against the first. FinCEN issued a dedicated alert on 13 November 2024 (FIN-2024-Alert004) on deepfake-media schemes designed to defeat identity verification at financial institutions.

What replaces "I know that voice":

- Pre-agreed code words or challenge questions whose answers have never been published or transmitted digitally.
- Out-of-band confirmation: on a channel other than the one the request arrived on, and initiated by the receiving party.
- The understanding that urgency and demands for confidentiality are not grounds to relax a procedure but a signal to tighten it. In both BEC and deepfake scenarios, those two elements are almost always present.
## The family's digital footprint

Attacks begin with reconnaissance, and families often supply the raw material themselves: a voice cloned from a short podcast clip, an ownership structure read off a corporate register, addresses and family connections aggregated by data brokers and sold as ordinary merchandise.

**Data brokers.** An entire industry compiles addresses, phone numbers, property records and relatives from open sources. Records can be removed via opt-out, but not permanently: the data reappears from new feeds, which makes this a cycle rather than a one-off exercise.

**Public registers.** Here the landscape has shifted toward privacy. On 22 November 2022 the Court of Justice of the EU, in joined cases C-37/20 and C-601/20 (WM and Sovim SA v Luxembourg Business Registers), invalidated the Fifth AML Directive provision granting the general public access to beneficial ownership registers, holding it a serious interference with rights under Articles 7 and 8 of the EU Charter. Access reverted to a "legitimate interest" standard — discussed further in the notes on [UBO registers](https://wiki.private.law/en/ubo-registers) and [nominee structures](https://wiki.private.law/en/beneficial-ownership-nominee).

**The family outside the office.** Geotagged posts, school uniforms in photographs, location check-ins, children's open accounts. This is not a matter of prohibitions but of a family agreement on what gets published — best recorded where the other agreements sit, in the [family charter](https://wiki.private.law/en/family-charter).

Legal tools exist, but their limits are firm: the right to erasure (Article 17 GDPR) does not reach data a controller is required by law to retain, and the "right to be forgotten" in European practice means delisting from search engines rather than deletion at source.

## The physical perimeter: kidnap & ransom and travel security

The digital footprint connects directly to physical security: a public address and a predictable routine are inputs for more than fraudsters. A kidnap & ransom policy typically covers the ransom itself, fees for professional negotiators and crisis consultants, medical care and evacuation, legal costs and loss of income. It operates on an indemnity basis — costs already incurred are reimbursed; funds are not advanced.

The critical condition attaching to such policies is confidentiality: disclosing the mere existence of cover can be grounds for denying a claim, on the straightforward logic that known cover changes an attacker's calculus. The circle of people aware of the policy is kept correspondingly small. The practical half is a travel risk assessment ahead of trips to higher-risk jurisdictions, plus pre-agreed protocols for confirming that a person is safe and speaking freely.

## Hygiene: what actually reduces the odds

The baseline set of measures is dull, and that is its virtue.

- **FIDO2 hardware keys instead of SMS-2FA.** CISA's joint guidance on mobile communications (December 2024) is explicit: do not use SMS as a second factor, because it is unencrypted and not phishing-resistant; FIDO is the strongest form of MFA, and hardware keys the most effective implementation. SMS is additionally exposed to SIM swap.
- **A password manager** with a unique credential per service — also from the same CISA guidance.
- **Separation of personal and work devices,** disk encryption, and offline backups tested for restoration rather than merely for existence.
- **Least privilege inside the office.** Access by role rather than by tenure; revocation when a function changes, not only on departure.
- **Provider diligence.** A SOC 2 Type II report from an administrator, custodian or cloud service is an attested description of operating controls, not a marketing claim.
- **Regular simulated phishing** for everyone, family members and household staff included.
Crypto assets form a separate perimeter where the risk is irreversible: a transfer cannot be recalled, and a compromised seed phrase means permanent loss. Multisig, hardware devices and physical separation of storage are the working answers — set out in more detail in the notes on [crypto in private wealth](https://wiki.private.law/en/crypto-private-wealth) and [digital asset inheritance](https://wiki.private.law/en/crypto-inheritance).

## Insurance: where cover actually stops

Deloitte finds that 63% of offices carry no cyber insurance at all. But holding a policy is not the same as having cover: a BEC loss sits awkwardly across the standard insuring agreements of a crime policy. Employee theft presupposes a dishonest employee — and a deceived employee is honest. Computer fraud requires a computer to have caused the transfer, whereas a person made the decision. Funds transfer fraud requires a fraudulent instruction to the bank — and the bank received a genuine instruction from an authorised signatory.

Such losses are therefore addressed by a separate extension: social engineering fraud, or a fraudulent instruction endorsement. Its sublimit is usually well below the policy's overall limit, and payment is conditional: insurers require evidence that callback verification and dual authorisation were in fact followed. The circle closes — the procedure is not an alternative to insurance but a precondition for it working.

## The first hour

An incident response plan is not a document; it is an answer to the question "who calls whom". The minimum version fits on one page: who declares an incident; the bank's number for an urgent payment recall — the first hours determine whether the money comes back; contacts for outside IT forensics and legal counsel; who notifies the data protection authority if personal data is involved (72 hours in the EU under GDPR); who says what to the family. Plus the rule that until confirmation arrives over an independent channel, no new payment instruction is executed.

Print that list. If the incident has touched email and file storage, access to the electronic copy may be the first thing you lose.

> 🍓 Family office cybersecurity is not a product but a set of procedures, and nearly all of them cost nothing. The dominant vector is not a system breach but an intrusion into transaction correspondence, and the remedy is callback verification on a previously known number, dual authorisation of payments, and a ban on changing payment details by email. Deepfakes have made voice recognition useless as a verification method, and code words plus out-of-band confirmation have taken its place. The difference between an office that survives an incident and one that does not is usually measured not in security budget but in whether the rule was written down and whether anyone knows who to call in the first hour.

## Sources

- Deloitte Private. The Family Office Cybersecurity Report, 2024 — [deloitte.com](https://www.deloitte.com/global/en/services/deloitte-private/research/family-office-cybersecurity-report.html)
- Campden Wealth. The Family Office Operational Excellence Report 2025 — [campdenwealth.com](https://www.campdenwealth.com/sites/default/files/FO_Op_Exc_2025_report_digital.pdf)
- Dentons. The Evolving Risk Landscape for Family Offices: Cybersecurity Defense Gaps — [dentons.com](https://www.dentons.com/en/services-and-solutions/the-evolving-risk-landscape-for-family-offices-a-dentons-survey-report/in-focus-cybersecurity-defense-gaps)
- FBI Internet Crime Complaint Center. 2025 Internet Crime Report — [ic3.gov](https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf)
- FBI IC3. Business Email Compromise: The $55 Billion Scam (PSA, September 2024) — [ic3.gov](https://www.ic3.gov/PSA/2024/PSA240911)
- South China Morning Post. Arup confirmed as victim of HK$200 million deepfake scam — [scmp.com](https://www.scmp.com/news/hong-kong/law-and-crime/article/3263151/uk-multinational-arup-confirmed-victim-hk200-million-deepfake-scam-used-digital-version-cfo-dupe)
- Dezeen. Arup victim of multimillion-dollar deepfake video scam in Hong Kong — [dezeen.com](https://www.dezeen.com/2024/05/17/arup-victim-deepfake-video-scam/)
- CrowdStrike. 2025 Global Threat Report — [crowdstrike.com](https://www.crowdstrike.com/en-us/press-releases/crowdstrike-releases-2025-global-threat-report/)
- FinCEN. Alert on Fraud Schemes Involving Deepfake Media (FIN-2024-Alert004, 13 November 2024) — [fincen.gov](https://fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-involving-deepfake-media-targeting-financial)
- CISA / NSA / FBI. Mobile Communications Best Practice Guidance (December 2024) — [cisa.gov](https://www.cisa.gov/sites/default/files/2024-12/joint-guidance-mobile-communications-best-practices_v2.pdf)
- CJEU. Joined Cases C-37/20 and C-601/20, WM and Sovim SA v Luxembourg Business Registers (22 November 2022) — [eur-lex.europa.eu](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A62020CJ0037)
- J.P. Morgan. BEC busters: four callback do's and don'ts — [jpmorgan.com](https://www.jpmorgan.com/insights/cybersecurity/business-email-compromise/when-callbacks-go-wrong)
- Ward and Smith, P.A. Social Engineering Fraud and Your Crime Policy — [wardandsmith.com](https://www.wardandsmith.com/article/social-engineering-fraud-and-your-crime-policy-why-your-insurer-may-deny-the-claim-and-what-you-can-do-about-it)
- Buchalter. Kidnap and Ransom Insurance Coverage: The Basics — [buchalter.com](https://www.buchalter.com/blogs/kidnap-and-ransom-insurance-coverage-the-basics/)
- Crisis24. A Unique Target: Understanding Why Cyberattacks on Ultra-High-Net-Worth Families are More Common — [crisis24.com](https://www.crisis24.com/articles/a-unique-target-understanding-why-cyberattacks-on-ultra-high-net-worth-families-are-more-common)

---

## Factual claims

- Scale, per the FBI's IC3: in 2025 BEC accounted for 24,768 complaints and US$3.05 billion in reported losses, second only to investment fraud.
- Deloitte finds that 63% of offices carry no cyber insurance at all.
