
A family office asking about insider risk is usually asking about its employees, and usually reaching for employee controls: screening at hire, a policy everyone signs, monitoring on the network. That is a reasonable programme for the six or eight people on the payroll. It does not reach the several dozen others who hold keys, codes, calendars and credentials, because the office does not employ them and cannot govern them that way.
CISA’s definition is the useful starting point precisely because it says nothing about employment. An insider is “any person who has or had authorized access to or knowledge of an organization’s resources, including personnel, facilities, information, equipment, networks, and systems,” and the agency’s own examples run to contractors, vendors and custodians. Applied to a family, that covers the house manager, the chef, the chauffeur, the nanny, the caretaker at the property nobody visits in winter, the seasonal crew, the executive assistant, the bookkeeper, the paralegal at the family’s law firm, the agent who holds every passport number, and the family’s own adult members.
Start with what a position can cause, not with why someone would
Writing on this subject, including the earlier version of this article, tends to open with motive: financial pressure, grievance, ideology, ego. Motive taxonomies are satisfying to read and they predict nothing anyone can act on.
CISA’s framing is more useful. Its definition turns on access used “wittingly or unwittingly,” and it treats unintentional insider threat as a category in its own right, separating negligence from accident, with examples as ordinary as holding a door open for someone, losing a device that holds sensitive data, misdirecting an email or clicking a malicious link. In our experience that category accounts for a large part of what a family office actually encounters. Nobody involved had a motive.
So the first piece of work is a map rather than an interview. For each position, the question is what this person could cause on their worst day. Five consequences cover almost everything in a family office: the ability to move money or to cause someone else to move it; the ability to grant physical access to a property or a vehicle, which means gate codes, alarm codes, key management and the camera account; possession of a credential to a system the family depends on; knowledge of where the family will be and when; and the ability to put family information into a third party’s system.
Write the roster against those five and two things usually become visible. The estate manager and the executive assistant appear in three or four of them, and neither has ever been told so. The IT contractor appears in one, at a depth nobody else approaches. And the position offices tend to worry about, the newest and most junior hire, frequently appears in none.
The people you cannot put on a policy
Having the map does not give the office authority. It employs the assistant. It does not employ the paralegal, the alarm installer’s technician, or the agency that supplies temporary staff at the summer house. Network monitoring does not reach them, and a policy they never signed is not a control.
Three levers are available instead, and only one of them still works after the fact.
The first is the engagement terms. Whatever security expectation exists has to be in the contract or the employment terms at the point of hiring, because that is the only moment the office has leverage over someone it does not employ. Asking an established agency to accept new obligations in year three is a negotiation. Asking in the first draft of the agreement is a formality.
The second is instruction at onboarding. It costs nothing and it is almost never done for household positions, who are typically briefed on discretion, on the family’s preferences and on the alarm, and on nothing else.
The third is screening proportioned to what the position can cause, which most offices do once and then never revisit. The common failure is not a bad check at hire. It is that the person hired to drive now holds the gate code and the spare keys to two properties, and nothing was re-run when the access grew.
Teaching to the position, not to the threat
CIS Control 14 states the object plainly: “establish and maintain a security awareness program to influence behavior among the workforce to be security conscious and properly skilled to reduce cybersecurity risks to the enterprise.” NIST’s September 2024 guidance on building a learning programme is more explicit about what success looks like: the programme “should encourage behavior change as part of risk management and lead to developing a privacy and security culture in the organization.”
Neither describes an annual module, and an annual module is what most offices buy. It is built for salaried staff with corporate email and a managed laptop. The house manager may have neither, and will not recognise a single screenshot in it.
What that position needs is ten minutes on the request it will actually receive. A caller says the principal is on a flight and needs the gate code released for a delivery. A message from the family’s attorney asks for a scan of a passport. A courier arrives for a package nobody ordered. The chauffeur needs a different ten minutes, about the travel calendar and who is entitled to ask for it. The bookkeeper needs a third, about payment instructions that change.
What those conversations should not attempt is the verification procedure itself. How an instruction gets confirmed, on which channel and against which number of record, is a control the office designs centrally and writes down once. The position needs to recognise that a request is abnormal and to know who to call. It should never be improvising the protocol at the gate.
The family should get the same instruction as the staff. The FBI’s September 2026 advisory on consent phishing records campaigns that reached “prominent victims, their family members, and personal acquaintances” through direct messaging. The advisory is not about family offices and does not claim to be. But the population it describes being contacted is, in a family office, largely a population that appears on no training roster at all.
Detection is people
“Detecting and identifying potential insider threats requires both human and technological elements,” CISA writes, and in a family office the technological half is thin. There is no security operations centre watching the residence, and there should not be. The human half carries most of the weight, which CISA puts directly: “an organization’s own personnel are an invaluable resource to observe behaviors of concern.” It adds, of insiders who do turn to malicious activity, that researchers find “the acts are rarely spontaneous; instead, they are usually the result of a deliberate decision to act.” Deliberate decisions take time, and time is what makes observation worth anything.
The obstacle in a family office is not observation. It is reporting. The person best placed to notice something about the estate manager is usually the person who reports to the estate manager, inside a household where the working relationship is closer and more personal than an office one. There is rarely a route for a concern that does not run through the person the concern is about. That is a structural gap, and it is closed with a phone number rather than a system.
What this looks like as a programme
The sources above establish the definitions and the object. What follows is Annapurna’s recommendation on how to run this inside a family office rather than a requirement drawn from any of them.
Build the roster by consequence rather than by employment status, and keep it to one page. It is the training plan, the screening plan and the offboarding checklist at the same time, which is why it is worth the afternoon it takes.
Put the security expectation into the engagement or employment terms at hiring, for agencies and contractors as well as for staff. Keep it short and specific enough to mean something: who may be sent, what they may be told, what happens to information afterwards, and who the office calls if that changes.
Proportion screening to what the position can cause, and re-run it when a position gains access it did not have when it was hired.
Teach each position the request it will receive, briefly, in person, once a year. In person matters here more than it does in an office, because these are people whose work is not done at a desk and who will not complete a module.
Include the family. The instruction is the same and the delivery is different, and the advisory above suggests they are contacted more directly than anyone else.
Give people a route to report a concern that does not pass through the person they would be reporting on. In a small household that usually means an external number, which is one of the few things an outside advisor can offer that an internal programme structurally cannot.
Remove access on the day a position ends. Gate and alarm codes, the camera account, shared logins, vehicle apps, the building fob. Record who did it. Household arrangements fail here more reliably than anywhere else, because a departure is a social event rather than an administrative one and nobody owns the checklist.
What to ask this quarter
Who holds a gate or alarm code at each property, and when was that list last known to be correct? Which positions can cause a payment to move, directly or by asking? What does the agreement with the agency supplying household staff say about security, if anything at all? Who has told the house manager what an unusual request sounds like? And if someone wanted to raise a concern about the most senior person in the household, who would they call?
Most offices can answer the first question and not the other four. That is the ordinary starting position, and none of the four is expensive to fix.
Where this sits
The argument that this gap is human rather than technical is one we have made at length in the weakest link, and the question of who is accountable for the operations layer is worked through in family office cybersecurity governance. This article is the method those arguments imply.
Building the consequence roster, writing the terms and delivering the role-specific instruction is work we handle through cybersecurity program development. Keeping it current as positions, properties and people change is what ongoing advisory is for.
Sources
CISA, Defining Insider Threats
CISA, Detecting and Identifying Insider Threats
CIS Critical Security Control 14, Security Awareness and Skills Training
