Cybersecurity and the Unique Risks Facing Wealthy Families
For most organizations, cybersecurity is a technology problem. For family offices, it is something more personal — and more complex.
That distinction was reinforced at every turn during the Family Wealth Report Family Office Cybersecurity Forum, held in June 2026 in New York. The event brought together leaders from single-family offices, multi-family offices, RIAs, trust companies, cybersecurity firms, and technology providers to examine the evolving threat landscape facing wealthy families and the institutions that serve them. The conclusion was consistent: traditional cybersecurity frameworks were not designed for environments like ours, and the gap between standard enterprise security and what family offices actually require is widening.
The attack surface has expanded beyond the organization
The most important shift in how cyber risk is understood today is not technical — it is strategic. Sophisticated attackers targeting high-net-worth individuals and families do not begin with your network. They begin with publicly available information.
LinkedIn profiles, social media, published news, and business registrations become raw material for what security professionals call a “target map”: a comprehensive picture of an individual’s relationships, routines, and access points. That map includes family members, household staff, personal assistants, legal and financial advisors, and the organizations connected to all of them. Every relationship in a family’s orbit represents a potential entry point.
This is the defining challenge for family offices. According to research presented at the forum, 50% of family offices have suffered a cyber event and were not adequately prepared. The families served by those offices carry a level of public visibility and relational complexity that enterprise security programs are not built to address.
Identity is now the primary attack surface
Across multiple sessions, presenters converged on the same finding: identity is the most targeted and vulnerable component of modern cybersecurity. Traditional passwords and SMS-based multi-factor authentication (MFA) are no longer considered reliable protections. AI-generated phishing content has become convincing enough to deceive careful, sophisticated users — meaning human judgment alone can no longer be the last line of defense.
Phishing-resistant MFA — authentication mechanisms tied to a specific physical device rather than a code delivered by text or email — represents the current standard of practice. Beyond authentication, family offices should be continuously reviewing who has access to what, reducing the “blast radius” of any single compromised account by limiting unnecessary privileges.
Resilience, not just prevention
One of the defining statements of the forum came from David Robinson, CISO and Managing Director at BNY: “Stop doing security and start being secure.” The distinction matters. Security as a prevention-only mindset assumes attacks can be reliably blocked. A resilience mindset assumes compromise is possible — and prepares accordingly.
For family offices, this means investing in recovery capabilities alongside protective controls: incident response plans that are tested and current, business continuity procedures that account for operational disruption, and clear escalation protocols so that when something happens, every minute is not wasted figuring out who to call.
The convergence of personal and institutional risk
Perhaps the most significant development in family office cybersecurity is the convergence of institutional and personal risk. Protecting a family today means extending oversight into domains that have historically been considered private.
Digital footprint management — removing personal information from public data broker sites, monitoring for exposed credentials on the dark web, and setting up protections against SIM-swap attacks — is now a standard component of comprehensive cyber programs for ultra-high-net-worth individuals. The distinction between protecting an organization and protecting a family is, in practice, no distinction at all.
Vendor and AI governance cannot be after thoughts
Two additional areas generated significant discussion at the forum. Third-party risk continues to grow: attackers frequently gain access not through a direct breach but through a vendor who holds organizational data. Family offices should require written documentation from all vendors regarding data handling, AI usage, and governance practices.
On AI specifically, the forum was direct. Sensitive information should never be entered into public AI platforms. Agentic AI systems — those capable of taking actions without a direct human prompt — introduce new risks that require governance frameworks before deployment. The guidance from J.P. Morgan’s Head of Cyber Advisory was practical and pointed: “If you don’t want it on the front page of a newspaper, don’t put it into AI.”
What this means for Pitcairn and the families we serve
At Pitcairn, we have long understood that protecting a family’s wealth requires protecting far more than a portfolio. The forum reinforced what our work has always reflected: the most meaningful risks facing the families we serve are not confined to any single domain. They extend across generations, relationships, and institutions.
Cybersecurity, at its best, is an expression of the same values that define everything we do: care, continuity, and a commitment to protecting what matters most.