Technology

Digital Privacy, Cyber Insurance: Why Family Offices Need Both

Editorial Staff July 20, 2026

Digital Privacy, Cyber Insurance: Why Family Offices Need Both

A panel at the recent family office forum on cybersecurity, hosted by this news service, examined threats of impersonation and intrusion.

This article summarizes a recent panel discussion from the Family Wealth Report's Family Office Cybersecurity Forum. See a media report of the event here by our US correspondent. (This report, based on major issues stemming from the event, can be found here.

The speakers on the panel were Gary Belvin of CISO, who was moderator; Mykolas Rambus, CEO and co-founder of Hush; Seth Spreadbury, national family office practice leader at Marsh McLennan Agency; and Sam Carruthers, head of partnerships at VanishID.

Almost everything an attacker needs to target a family is already available online. Address histories, family relationships, an estimate of net worth, a principal's routines, a child's phone, passwords exposed in multiple breaches. This information sits on data broker sites and in leaked records, waiting to be assembled.

Attackers pursue family offices deliberately. A family office holds the wealth, data, and reputation of a mid-size company, yet operates with the staff and systems of a small one. Criminals gather a family's information once, then put it to two uses: impersonating the principal and gaining unauthorized entry to the office's systems.

Impersonation and intrusion: two threats family offices face
The panel focused on the two forms of attack responsible for most of the harm we see in family offices.

The first is fraud carried out through email. An attacker gathers enough publicly available information to imitate a trusted email account. Then, knowing a transaction is expected, they send an email that appears entirely legitimate: an email address just one letter off, an invoice that looks routine, or a last-minute change to payment instructions. Nothing is broken into, yet the fraud succeeds when a single person acts on a single convincing message rather than risk bothering the principal to confirm it. Seth Spreadbury of Marsh McLennan Agency observed that this is what insurers see most often in their loss data, with deception and fraud the leading cause. Deloitte found that deceptive emails of this kind were present in 93 per cent of the family offices that were attacked.

The second is an intrusion rather than a deception, and it is often paired with extortion. The attacker asks for nothing at first. They gain access, usually with a password that was reused or stolen and is already circulating online. Nothing is forced; they simply sign in because the family didn't set up phishing-resistant two-factor authentication. They then copy everything of value, lock the systems, and demand payment to restore them. The more difficult problem is that restoring the files does not end the threat, because the attacker has kept a copy of the data. The leverage is no longer the locked system but the threat to publish what was taken. 

For a family, that threat is the real weapon. In an earlier session, a presenter described a case in which an attacker obtained intimate photographs documenting an affair. The money can be recovered. The exposure cannot. A 2025 threat report from Anthropic documented a single individual using an artificial-intelligence tool to carry out this kind of attack against at least 17 organizations in one month, reviewing each victim's financial records and generating a tailored ransom demand for each. One person accomplished the work of an entire team.

On our panel, Sam Carruthers of VanishID described a client whose child's phone number was exposed. Attackers telephoned the child directly and determined which school he attended, turning a digital risk into a physical one. Both forms of attack draw on the same intelligence: the information that allows a criminal to impersonate the principal is the same information that shows them where to gain entry. The preparatory work behind them is increasingly automated. What once required weeks of effort from a skilled person now takes software a matter of minutes, so that by the time an advisor learns a bank or vendor has been breached, a profile of the family may already exist.

Family offices have unique cyber risk profiles
Family offices are unusually difficult to protect. They hold enterprise-scale wealth but defend it with small-business resources, often a handful of staff and a single IT contractor. When the assets are substantial and the defenses are thin, a single convincing email or one reused password can move seven figures, or expose a family's private life, in an afternoon.

The deeper challenge is that what is being protected is a family, not a company. Exposure varies widely across a household. A principal may secure every account while a college-age child posts the home, the school, and the travel calendar to a public profile. The least cautious member of the household sets the level of risk for everyone, a problem no corporate security program must manage.

Privacy tools: the first half of the answer
Privacy tools reduce exposure by removing personal information before an attacker can collect it, and by giving a family awareness of what has leaked so fraud doesn't catch them by surprise.

Mykolas Rambus, chief executive and co-founder of Hush, built a substantial data business before founding Hush and understands precisely what is for sale about principals and their families. He cautioned that certain information is nearly impossible to remove once it has reached the dark web.

Choosing among the tools
Begin with coverage. Does the service protect the entire household, including children and key staff, or only the principal? Protecting the principal alone secures the strongest profile and leaves the weakest one exposed, which inverts the priority.

Consider the model next. Is removal performed once, or continuously as the data reappears? Continuous removal is the right answer, because the data does reappear. Does the service actively monitor for leaked passwords, or merely remove listings from broker sites? And when something significant surfaces, does a person make contact, or is it left in a dashboard that no one opens?

Finally, test a service before committing to it. A short engagement will reveal whether it surfaces real, specific findings about a family before the full household tier is purchased. The strongest providers prove their value within the first week. It is also worth moving the household to passwordless logins in parallel. Nothing reduces the risk of a reused password more effectively than having no password to reuse.

Cyber insurance: the second half
Privacy tools reduce the target. They do not eliminate it, which is why insurance is the second half of the answer rather than an optional addition. It covers what remains when defenses fail, and that recovery is costly: response and investigation, legal counsel, and weeks of lost operation while systems are rebuilt. Even so, Deloitte found that 63 per cent of family offices carry no cyber insurance. It is one of the largest gaps.

One feature works in a family's favor. Premiums are often based in part on revenue, and a family office reports very little of it relative to the value it protects. The coverage is frequently a bargain for the assets behind it.

Insurance can also be your advocate for security best practices. The market has shifted in the buyer's favor too. Five years ago a policy required only a one-page application. Today it requires evidence of two-step login verification and tested backups, and the same measures that make a family insurable also reduce the premium.

Two cautions are worth noting. First, email fraud and system intrusions often fall under different policies, crime coverage as against cyber coverage, with different limits. Many families assume that one policy covers both and discover otherwise at the time of a claim. The two should be considered together, just as the two forms of attack should. Second, some common advice is simply mistaken. A cyber claim does not raise premiums the way a motor accident does, so coverage that exists should be used. And about ransom, even where a policy reimburses the payment, the interruption to the business is a separate cost, and payment to certain groups may be unlawful under sanctions rules.

The two halves are not interchangeable, and neither is sufficient on its own. Privacy tools reduce the likelihood that a family is successfully targeted. Insurance limits the damage when an attack succeeds. By pursuing both strategies, family offices can be in a stronger position to handle the unique security challenges that face them.

Gary Belvin is a former CISO [chief information security officer] and founder of GDB Security, where he advises family offices on their cybersecurity. He moderated the closing panel at the Family Wealth Report Family Office Cybersecurity Forum.

Register for FamilyWealthReport today

Gain access to regular and exclusive research on the global wealth management sector along with the opportunity to attend industry events such as exclusive invites to Breakfast Briefings and Summits in the major wealth management centres and industry leading awards programmes