Family Office Cybersecurity Best Practices

The first hour is two calls and one decision: the bank if money has moved, the insurer’s breach hotline, and someone deciding who owns the incident. All three should be settled before anything happens, because almost everything that has to move quickly in the first 24 hours is a question about authority rather than technology: who may call the bank, who may spend money nobody has budgeted, and who speaks to the principal while everyone else says nothing to anyone. An office that has not settled those questions will spend its most valuable hours discovering who is allowed to act, which is one reason documented response procedures remain absent in so many family offices.

The first hour is two calls and one decision

If money has moved, the first call is to the financial institution, because the recall window is measured in hours. In the United States the FBI’s Internet Crime Complaint Center puts it directly: on discovering a fraudulent transfer, “time is of the essence,” and victims should contact the institution immediately and “request a recall of the funds along with any necessary indemnification documents” [FBI’s 2025 Internet Crime Report]. The same body notes that institutions differ in what help they provide, and that variation is wider still across countries, so the useful version of this step is to know your own bank’s answer in advance rather than learn it at the worst moment.

The second call is to the breach hotline on your cyber insurance policy, and this is the call most family offices have never rehearsed. It is our recommendation rather than anything a source prescribes, and the reasoning is straightforward: an insurer that is notified early can put a directed response in motion, while one that learns late is being told about decisions already taken. The practical difference in the first hours is between a family improvising with whoever they can reach and a family working to a process someone has run before.

That is the case for carrying cover at all, and it is a governance argument rather than a procurement one. As we have argued in the context of who owns what, most family offices discover the shape of their coverage during a claim rather than before one. Three questions settle it while nobody is under pressure, and your broker can answer all three in a single conversation.

  • Who answers that hotline?
  • What notice does the policy require, and how quickly, for cover to respond as intended?
  • Does the policy appoint the legal and forensic help, or is the family expected to find it?

The answers belong next to the number in the call list. We do not place or sell insurance, and what any particular policy covers varies by carrier and by jurisdiction, which is precisely why the questions are worth putting to your own.

There is no third call, and that is the point of the second one. What follows is the insurer’s to direct, including whether and when to involve law enforcement, which turns on what happened and on advice the family should not be improvising under pressure. The clock is real: FinCEN records greater success recovering funds when fraudulent transfers are reported “to law enforcement within 24 hours” [FinCEN]. In the United States that route runs through IC3 and the Financial Fraud Kill Chain, while elsewhere it runs through the national cybercrime or fraud reporting body, and a window that short is not one to work out from a standing start, which is why the plan names who makes that call and on whose advice.

It is worth being accurate about what those calls achieve, because recovery is real and unreliable at the same time. In 2025 the FBI’s Recovery Asset Team handled 3,900 incidents covering $1,163,919,846 in attempted theft and froze $679,013,183 of it, a 58 percent success rate. That figure spans every incident type the team handles rather than wire fraud alone, it covers one country’s mechanism, and the same report notes that tech support and account takeover initiations rose over the year. Speed materially changes the odds without guaranteeing anything.

The decision running alongside both calls is ownership, and our recommendation is that it is pre-assigned to a named person with a named alternate, because the alternative is a conference call in which nobody is sure who can commit the family to anything.

All of this belongs in a written incident response plan: the two numbers, who is allowed to dial them, who may commit money, and who speaks to the principal. If you are reading this, the odds are you do not have one, or you have something an IT provider wrote that covers servers rather than authority. So the rest of this runs through what should happen, and then comes back to the plan, which is what turns any of it from something your office could describe afterwards into something it can do.

Why incident response stopped being a technical document

In April 2025 NIST superseded its long-standing Computer Security Incident Handling Guide and reissued incident response as a risk-management profile, SP 800-61r3, built around the Cybersecurity Framework. Its opening position is that “incident response is a critical part of cybersecurity risk management and should be integrated across organizational operations” [SP 800-61r3]. All six framework functions carry response roles: Govern, Identify and Protect cover prevention, preparation, impact reduction and improvement from lessons learned, while Detect, Respond and Recover cover discovery, containment, eradication, recovery and the reporting and notification that go with them.

NIST stopped publishing procedures because the details of handling change too often and vary too much across technologies and organizations to maintain in a static document, so the call sequence recommended here is Annapurna’s rather than NIST’s. What NIST supports is the framing, the emphasis on preparation and governance, and the requirement to exercise. The framework is American in origin and widely used well beyond it, which is also true of the argument it supports.

An organization cannot know the timing of the next incident “other than knowing that another incident is inevitable”. Who holds the mandate to act on that is the subject of our piece on family office cybersecurity governance.

The people you will need are not all your employees

This is where a family office diverges from the organizations most response guidance imagines. NIST notes that “many individuals, teams, and third parties hold a wide variety of roles and responsibilities across all of the Functions that support an organization’s incident response,” and that some third parties fill a primary role, giving the example of a managed security provider performing detection, response and recovery.

For a family office that set is usually the outside IT provider, the bank or custodian, outside counsel, the insurer and the response team it appoints, and sometimes a household employee who noticed something first. The office employs almost none of them and can direct even fewer, so the plan is not an internal document with an internal call tree. It has to assign authority across a group of people who answer to different organizations, and frequently in different countries and time zones, which is a different exercise from the one an IT provider will run and one that sits outside what an IT contract covers.

NIST adds a point worth acting on before an incident rather than during one, which is that legal review of contracts with technology suppliers and other third parties is relevant “when there are incident response implications”. The question of what your provider is obliged to do at 2 a.m. in its own local time is answerable now, in writing, at no cost.

The parts a family office has to add

Name one person to brief the principal, and make it someone other than the person running the response, since those two jobs compete for the same attention at exactly the wrong moment and the briefing role requires judgment about what is known versus merely suspected.

Decide emergency spending authority and a limit in advance. The requirement for “levels of decision-making authority” is the right instinct, and the family-office version of it is a number and a name agreed while nobody is under pressure.

Tell household staff who to call, because they are a genuine discovery channel and are frequently the first to see something odd, yet in most offices nobody has ever told them that reporting it is part of their role.

Treat privacy and reputational exposure as a separate workstream with its own owner. A family incident is not a corporate disclosure exercise, and the instinct to manage it quietly inside the response team tends to mean it is managed by nobody.

Coming back to the plan: what it has to contain

So write it down. There is a well-specified public answer to what belongs in it, though its legal reach is narrower than its usefulness. In the United States, the FTC Safeguards Rule requires a written incident response plan, and its required elements are: the goals of the plan; the internal processes the organization will activate; “clear roles, responsibilities, and levels of decision-making authority”; communications and information sharing both inside and outside the organization; a process to fix identified weaknesses in systems and controls; procedures for documenting and reporting security events and the response; and a post mortem, with revision of the plan and the wider security program based on what was learned [FTC Safeguards Rule].

Two caveats matter, the first being that the rule binds only entities meeting a particular US statutory definition of “financial institution,” so whether a given family office falls inside it depends on what it does and is a question for counsel. Families outside the United States are not bound by it at all, and those with entities in several countries may face a different obligation in each. We use the list because it has what a plan should contain, not because every family office is obliged to produce one, and the seven elements are as useful in Zurich or Singapore as in New York.

Of the seven elements, one concerns fixing technical weaknesses and the other six are governance, covering goals, process, authority, communications, documentation and learning.

A plan is not tested until the outside parties have been in the room

NIST is clear that exercises do double duty, informing program evaluation and preparing “staff and involved third parties (e.g., critical service providers and product suppliers) for future incident response activities”. Procedures, it adds, “can be tested or exercised periodically to verify their accuracy”.

Our recommendation: run the exercise once with the actual outside providers present rather than as an internal walkthrough. An internal rehearsal tests whether your staff know the plan, and it does not test whether your IT provider will pick up, whether your bank’s fraud desk works the way you assume, whether the insurer’s hotline reaches someone who can act at three in the morning in your time zone, or whether counsel is reachable on a Friday evening, and those four assumptions are the ones that fail.

Where to start

Five moves, in the order we would take them, none requiring a budget.

  • Write the call list, with names, roles and numbers, covering the bank, the insurer’s breach hotline, the IT provider and counsel.
  • Ask your broker who answers that hotline, what notice the policy requires, and whether it appoints the legal and forensic help, and record the answers next to the number.
  • Decide who may authorise emergency spend, and up to what amount.
  • Ask your bank and custodian what they will do on a recall request, and record that answer too.
  • Then schedule one exercise, with those outside parties in the room.

Writing the plan and running the first exercise is work we handle through cybersecurity program development. Keeping it current as staff and providers change, and holding the outside parties to their part of it, is what ongoing advisory is for.

Sources

NIST Special Publication 800-61r3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile, April 2025

U.S. Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know

FBI Internet Crime Complaint Center, 2025 Internet Crime Report

FinCEN Advisory FIN-2019-A005, Updated Advisory on Email Compromise Fraud Schemes