Print this article
When AI And Cybersecurity Intertwine For Good – And Bad
Tom Burroughes
1 October 2026
It is hard to avoid talking about AI and how it affects financial services and it is equally difficult to overlook cybersecurity threats. Earlier this year, FWR interviewed Jordan Arnold, the founding principal and CEO of Jetty Partners who, as reported, said: “I believe the most significant and growing threat is the one that cuts across both cyber and physical domains: the sheer volume of personal information now available online and the ease with which it can be weaponized. Home addresses, family details, travel patterns, property records, and public affiliations create visibility that can make families more vulnerable to being watched or targeted.” Unfortunately, there is an asymmetry between the knowledge of family office people responsible for cybersecurity and those pitching to them. This news service is holding a fintech summit in Manhattan on October 19.
A global PwC survey, for example, found that 58 per cent of security leaders ranked AI among their top cyber budget priorities for the year ahead. Yet half say attacks targeting AI systems are the threat they are least prepared to address.
When public registers of beneficial ownership are attacked, such as the recent incident in Liechtenstein, it is another reminder for HNW and UHNW individuals that they’re in the firing line. According to the FBI’s Internet Crime Complaint Center’s annual report, cybercrime costs reached a record high of $20.8 billion in losses in 2025. Business Email Compromise and financial fraud were identified as the two leading methods of cybercrime, both of which target HNW individuals. AI has only worsened the threat landscape, making deepfake impersonations and phishing emails and texts harder to detect.
One issue is that many organizations delegate cybersecurity tasks to third parties and the clients won’t know important questions to ask, Doron Goldstein, partner, US head of data innovation, privacy and cybersecurity at Withers, told Family Wealth Report in a recent call. He is based in New York.
The rise of AI adds to the challenge, although it raises potential defenses as well.
“Family offices have significant data about business operations and want to use AI to be smarter about it. Many family offices use tools because it is relatively available and they can get answers very quickly. However, these tools may use the data for other purposes. They may use and distribute data that should not have left the family office," he said.
Threat actors are becoming more sophisticated and AI adds to this, Goldstein said.
“It is not an unreasonable expectation that most of your data is in the hands of someone other than the entity to whom you gave it directly, whether in the public sector or private sector,” he said. “The vast majority of family offices – like many businesses – don’t know where their data actually is.”
Goldstein’s experience straddles those in the technology, law and academic sectors. He is a former managing partner of an internet advertising company and is also an adjunct professor at New York Law School where he teaches Fashion Law and Technology, a course that explores the interplay between the law and emerging technologies in the fashion industry. His work spans a variety of industries, with a concentration in online services, hospitality, fashion and retail, consumer products, and financial services.
Evolving threats and countermoves
Experts like Goldstein are increasingly important to organizations such as family offices, private banks and wealth advisors. Considering that holders of trillions of dollars of wealth are tempting targets, this is understandable. Experts such as Christopher Hamilton, managing director of alliances at BlackCloak, for example, have spelled out the threats in front of family offices.
A study from Presage Global and Nines, called The State of Family Office Security 2026, identified a need for improvement.
“With people claiming to offer tech solutions, beware those who claim to have solutions and be more attuned to those who want to ask questions about your specific needs,” Goldstein said, when considering how people should treat supposed experts who claim complete understanding.
An important task for family offices is to share ideas and learn best practice ideas from those who have been successful in trying to limit and mitigate threats and handling incidents, he said.
Family offices control wealth “well beyond the level of that most companies would have with a similarly-sized employee – and particularly IT personnel – base,” Goldstein contiued.
It is worth noting that many threats to family offices’ wealth from a cybersecurity point of view are not particularly sophisticated and can be mitigated by relatively straightforward controls and processes, he said.
Private AI?
FWR asked Goldstein what he thinks of moves to develop closed/private AI that avoids the risks of public systems. In early June, for example, Custodia, a Swiss privacy-first AI startup, said it had launched Sentinel, a physical AI thinking appliance developed and designed for executives, family offices, scientific researchers and those who have data too sensitive to trust to the cloud.
“You can buy private instances of LLMs. It is critical where that data goes afterwards,” he said. “That is what banks and the larger law firms do,” “Withers is doing that.” One system Withers uses is Legora, another is called Harvey. Family offices should consider using private AI more.
This news service turned to the topic of whether AI notetakers have a place in meetings, giving rise to potential risks to client/advisor privacy and confidentiality.
“That is a perfect example of the privacy and confidentiality concerns that family offices have and the convenience that AI offers,” Goldstein said. “Most of these notetakers don’t guarantee any kind of confidentiality. Most of the information is going to go off the system and into something else. People don’t think about that as much as they need to.”
At many meetings, a lot of invitees start with the AI notetaker already on; chats and comments during meetings can be captured, often in ways that participants don’t intend.
“I think AI notetakers should be permission-based by everyone on a call. It absolutely changes the nature of a call,” he said. “The Chatham House rule and other similar expectations give people opportunities to discuss matters in ways they would not be comfortable doing otherwise; with recording or AI transcripts of discussions, that opportunity disappears. Many discussions about the NextGen and so on may come up…for example, someone might say that `this person is not reliable’….”
“AI transcription services can be useful in limited ways, but needs careful consideration and agreement before each use,” Goldstein added.