Laptop, portable hotspot and phone on a charter yacht’s teak table overlooking a coastal villa.

Every control a family office builds runs through an agreement. The managed service provider works to a standard the office wrote into a contract, the integrator who installed the cameras accepts terms on remote access, the law firm answers a security review because the relationship gives the office standing to ask, and household staff are instructed at hiring because that is the moment leverage exists. Remove the agreement and most of the program has nothing to grip.

That is the ordinary condition for several weeks of most years. The family boards a chartered vessel whose crew, network and systems belong to an operator the office met through a broker, takes a villa for the season, works from an aircraft it does not own, or occupies a residence where the property’s own staff hold the keys and the property’s own contractor runs the network. In each of those the office is a guest, the counterparty’s obligations run to the asset rather than to the family’s information, and the arrangements were settled long before anyone thought to ask about them.

What the office can still influence reduces to two things, which are what it selects and what the family carries with it.

The network is no longer the main problem

In our experience the advice most offices hold on this subject is a decade old and has been overtaken in part. The United States Federal Trade Commission’s consumer guidance, dated February 2023, states that “connecting through a public Wi-Fi network is usually safe”, because “most websites do use encryption to protect your information” where once most did not.

The United Kingdom’s National Cyber Security Centre is precise about what a virtual private network adds to that. It is “one way to guarantee the security of ‘data in transit’ across an untrusted network”, subject to the limit that “only traffic which is routed over the VPN will be protected by it.” A VPN protects the journey and says nothing about the destination, which is where the FTC places what remains: criminals “create fake websites and encrypt them to make you think they’re safe when they’re not”, so data “may be encrypted on its way to the site, but it won’t be safe from scammers operating the site.” Device behavior on public networks has its own body of official guidance, and the United States National Security Agency issued an information sheet on it in July 2021 addressing the techniques used against wireless devices in public and the steps that reduce them.

Carrying a connection the office controls is still worth doing and is not the control that decides the outcome. In a borrowed environment the exposure sits in the people and the arrangements: who else is on the network, who has physical access to the rooms and to the devices left in them, who holds the itinerary, and who the family will believe when somebody calls.

What you can ask a charter operator that you cannot ask a villa

One borrowed environment has a framework behind it. The International Maritime Organization maintains guidelines on maritime cyber risk management, which define the discipline as “the process of identifying, analyzing, assessing and communicating a cyber-related risk and accepting, avoiding, transferring or mitigating it to an acceptable level.” They are high-level recommendations rather than a certificate, and whether they reach a particular vessel turns on its flag, its tonnage and whether it is operated commercially, which is a question for the operator rather than for the office.

Ask about them anyway. An operator who can say how the guidelines are applied to the vessel, who maintains the navigation and entertainment systems, and whether guest and crew networks are separated, has somebody accountable for the answer, and an operator meeting the question for the first time has said something useful about the rest of the arrangement.

No equivalent exists for a villa, a chalet or most charter aircraft, so the questions there have to be concrete: who else holds keys and codes, whether any recording device is present inside, who administers the property’s network and whether the family can be given a separate one, and what the property does afterwards with the passport scans, reservation details and payment instruments it collected.

The itinerary is the asset

A charter or a seasonal rental is not one counterparty. It is a broker, an operator, a crew or household team, a management company, a marina or ground handler, and an insurer, and a plan for where the principal will be over a given fortnight passes through every one of them. Few of those parties have an obligation to the family beyond delivering the booking, and several keep the record long after the trip has ended.

A charter or tenancy agreement generally requires a passport for every guest, a payment instrument, and frequently an address and a date of birth, and that package sits with a broker and an operator under retention terms nobody has read. Ask before sending it where it will be held, for how long and who inside the operator can see it, which is the question the office already puts to any other counterparty holding family documents.

The office cannot prevent that distribution and can decide how much of it carries the family’s name. Booking through an entity, routing contact through one person in the office rather than to the principal directly, and confirming changes only on a channel agreed at the outset each narrow what a stranger is able to learn or to use.

The people around the family are not the office’s people

Insider risk in a family office is a question of what a position can cause rather than of who sits on the payroll, which is an argument we have made at length. A borrowed environment takes it to the limit: the crew, the housekeepers, the drivers and the ground staff hold physical access, see what is left on a table, hear what is said across a deck and know the schedule, and the office screened none of them, instructed none of them and can remove none of them.

The family’s own verification conventions therefore matter more rather than less, because the colleagues who would ordinarily notice that something is wrong are not there. Habits have to travel as well: documents put away rather than left out, devices not handed to a crew member who offers to sort out the printing, and no assumption that a room is private because its door is closed.

What to build

  • Decide what the trip is for before deciding what to carry. A holiday where nobody opens a deal file needs a different posture from a working fortnight, and offices routinely apply the same one to both.
  • Carry the connection rather than borrow it. A cellular hotspot the office controls takes the shared network out of the question at a cost that is trivial against the charter.
  • Take clean devices where the work justifies it. A fully loaded laptop going abroad for a week is a decision rather than a default, and the alternative is a device holding only what the trip needs.
  • Do not connect to hardware you do not own. Chargers, cables, docking stations and printers supplied by a property are equipment of unknown provenance, and the NCSC puts the general case plainly: “pairing of untrusted or unmanaged peripherals could result in the extraction of data outside of your control.”
  • Put the selection questions before the signature. Whoever books the charter or the villa should be holding the questions, because a broker will not ask them unprompted.
  • Name one channel for changes. Itinerary alterations, payment requests and staffing changes are confirmed on a route agreed before departure, which is the discipline the office already applies to instructions that move money.
  • Brief the family and the travelling staff before departure. Ten minutes on what to expect is worth more than a document nobody opens on a plane.

What to ask this week

Who in this office books the charters and the rentals, and has anyone given them questions to ask? When the family last took a property for a season, who else held keys, and does anybody know? Which of the family’s devices went abroad last year carrying material that did not need to travel? If a message arrived tomorrow changing the arrival arrangements, which channel would confirm it? And who has told the family that the crew are not the office’s staff?

Where this sits

Securing the residences the family owns, and holding the integrators who service them to a standard, is the same problem with the contractual lever intact, and we set it out in the household perimeter. The method for assessing a counterparty the office does have an agreement with is in running a security review on your advisors. Confirming that an instruction came from the person it appears to come from is covered in verifying someone you know, and the rule for a caller claiming outside authority is in verifying a caller who claims authority.

Building the selection questions, the travel posture and the briefing is work we handle through cybersecurity program development. Keeping it current as properties, charters and counterparties change is what ongoing advisory is for.

Sources

Federal Trade Commission (United States), Are Public Wi-Fi Networks Safe? What You Need To Know, February 2023

National Cyber Security Centre (United Kingdom), Virtual Private Networks (VPNs), device security guidance, reviewed 13 May 2025

National Cyber Security Centre (United Kingdom), Using peripherals securely, device security guidance, reviewed 13 May 2025

International Maritime Organization, Maritime cyber risk, and Guidelines on Maritime Cyber Risk Management MSC-FAL.1/Circ.3/Rev.4

National Security Agency (United States), Securing Wireless Devices in Public Settings, 29 July 2021, via CISA