
The first hour is two calls and one decision: call the financial institution, call law enforcement, and decide who owns the incident. All three should be assigned before anything happens, because almost everything that has to move quickly in the first 24 hours is a question about authority rather than technology. Who may call the bank. Who may spend money nobody has budgeted. Who speaks to the principal, and who says nothing to anyone. An office that has not settled those questions will spend its most valuable hours discovering who is allowed to act, which is one reason documented response procedures remain absent in so many trust-based offices.
The first hour is two calls and one decision
If money has moved, the first call is to the financial institution. The FBI’s 2025 Internet Crime Report is direct: on discovering a fraudulent transfer, “time is of the essence,” and victims should contact the institution immediately and “request a recall of the funds along with any necessary indemnification documents.” It also notes that institutions differ in what help they provide, so the useful version of this step is to know your bank’s answer in advance rather than learn it at the worst moment.
The second call is to law enforcement. FinCEN reports greater success recovering funds when fraudulent transfers are reported “to law enforcement within 24 hours.”
It is worth being accurate about what those calls achieve. Recovery is real and unreliable. Through the Financial Fraud Kill Chain, the FBI’s Recovery Asset Team handled 3,900 incidents in 2025 covering $1,163,919,846 in attempted theft and froze $679,013,183 of it, a 58 percent success rate. That figure spans every incident type the team handles rather than wire fraud alone, and IC3 notes tech support and account takeover initiations rose in 2025. So speed materially changes the odds without guaranteeing anything.
The decision that runs alongside both calls is ownership. Our recommendation is that this is pre-assigned to a named person, with a named alternate, because the alternative is a conference call in which nobody is sure who can commit the family to anything.
What a written plan actually has to contain
There is a well-specified public answer to this, though its legal reach is narrower than its usefulness. The FTC Safeguards Rule requires a written incident response plan, and its required elements are: the goals of the plan; the internal processes the organization will activate; “clear roles, responsibilities, and levels of decision-making authority”; communications and information sharing both inside and outside the organization; a process to fix identified weaknesses in systems and controls; procedures for documenting and reporting security events and the response; and a post mortem, with revision of the plan and the wider security program based on what was learned.
The applicability caveat matters. That rule binds entities that are “financial institutions,” which the FTC defines as those engaged in an activity “financial in nature” or incidental to such activities under section 4(k) of the Bank Holding Company Act of 1956. Whether a particular family office falls inside that definition depends on what it actually does and is a question for counsel. We use the list here because it has what a plan should contain, not because every family office is obliged to produce one.
Why incident response stopped being a technical document
In April 2025 NIST superseded its long-standing Computer Security Incident Handling Guide and reissued incident response as a risk-management profile, SP 800-61r3, built around the Cybersecurity Framework. Its opening position is that “incident response is a critical part of cybersecurity risk management and should be integrated across organizational operations.” All six framework functions carry response roles: Govern, Identify and Protect cover prevention, preparation, impact reduction and improvement from lessons learned, while Detect, Respond and Recover cover discovery, containment, eradication, recovery and the reporting and notification that go with them.
An organization cannot know the timing of the next incident “other than knowing that another incident is inevitable.” Who holds the mandate to act on that is the subject of our piece on family office cybersecurity governance.
The people you will need are not all your employees
This is where a family office diverges from the organizations most response guidance imagines. NIST notes that “many individuals, teams, and third parties hold a wide variety of roles and responsibilities across all of the Functions that support an organization’s incident response,” and that some third parties fill a primary role, giving the example of a managed security provider performing detection, response and recovery.
For a family office that set is usually the outside IT provider, the bank or custodian, outside counsel, the insurer, and sometimes a household employee who noticed something first. The office employs almost none of them and can direct even fewer. So the plan is not an internal document with an internal call tree. It has to assign authority across a group of people who answer to different organizations, which is a different exercise from the one an IT provider will run, and one that sits outside what an IT contract actually covers.
NIST adds a point worth acting on before an incident rather than during one: legal review of contracts with technology suppliers and other third parties is relevant “when there are incident response implications.” The question of what your provider is actually obliged to do at 2 a.m. is answerable now, in writing, at no cost.
The parts a family office has to add
Name one person to brief the principal, and make it someone other than the person running the response. Those two jobs compete for the same attention at exactly the wrong moment, and the briefing role requires judgment about what is known versus suspected.
Decide emergency spending authority and a limit in advance. The FTC’s element requiring “levels of decision-making authority” is the right instinct; the family-office version of it is a number and a name, agreed while nobody is under pressure.
Tell household staff who to call. They are a genuine discovery channel, they are frequently the first to see something odd, and in most offices nobody has ever told them that reporting it is part of their role.
Treat privacy and reputational exposure as a separate workstream with its own owner. A family incident is not a corporate disclosure exercise, and the instinct to manage it quietly inside the response team tends to mean it is managed by nobody.
A plan is not tested until the outside parties have been in the room
NIST is clear that exercises do double duty. They inform program evaluation, and they “prepare staff and involved third parties (e.g., critical service providers and product suppliers) for future incident response activities.” Procedures, it adds, “can be tested or exercised periodically to verify their accuracy.” For formats, it points to NIST’s dedicated guidance on simulations and tabletop discussions.
Our recommendation: run the exercise once with the actual outside providers present, not as an internal walkthrough. An internal rehearsal tests whether your staff know the plan. It does not test whether your IT provider will pick up, whether your bank’s fraud desk works the way you assume, or whether counsel is reachable on a Friday evening. Those are the assumptions that fail.
Where to start
Four moves, in the order we would take them, none requiring a budget.
- Write the call list, with names, roles and numbers, covering the bank, the IT provider, counsel and the insurer.
- Decide who may authorise emergency spend, and up to what amount.
- Ask your bank and custodian what they will actually do on a recall request, and record the answer next to their number.
- Then schedule one exercise, with those outside parties in the room.
Writing the plan and running the first exercise is work we handle through cybersecurity program development. Keeping it current as staff and providers change, and holding the outside parties to their part of it, is what ongoing advisory is for.
Sources
U.S. Federal Trade Commission, FTC Safeguards Rule: What Your Business Needs to Know
FBI Internet Crime Complaint Center, 2025 Internet Crime Report
