Skip to main content
Pitcairn Perspectives

When the Firewall Isn't Enough

Banner Graphic Banner Graphic Banner Graphic Banner Graphic Banner Graphic

Joan Hafer

Director, IT & Security Information

August 31, 2026
Cybersecurity and the Unique Risks Facing Wealthy Families

For most organizations, cybersecurity is a technology problem. For family offices, it is something more personal — and more complex.

That distinction was reinforced at every turn during the Family Wealth Report Family Office Cybersecurity Forum, held in June 2026 in New York. The event brought together leaders from single-family offices, multi-family offices, RIAs, trust companies, cybersecurity firms, and technology providers to examine the evolving threat landscape facing wealthy families and the institutions that serve them. The conclusion was consistent: traditional cybersecurity frameworks were not designed for environments like ours, and the gap between standard enterprise security and what family offices actually require is widening.

The attack surface has expanded beyond the organization

The most important shift in how cyber risk is understood today is not technical — it is strategic. Sophisticated attackers targeting high-net-worth individuals and families do not begin with your network. They begin with publicly available information.

LinkedIn profiles, social media, published news, and business registrations become raw material for what security professionals call a “target map”: a comprehensive picture of an individual’s relationships, routines, and access points. That map includes family members, household staff, personal assistants, legal and financial advisors, and the organizations connected to all of them. Every relationship in a family’s orbit represents a potential entry point.

This is the defining challenge for family offices. According to research presented at the forum, 50% of family offices have suffered a cyber event and were not adequately prepared. The families served by those offices carry a level of public visibility and relational complexity that enterprise security programs are not built to address.

Identity is now the primary attack surface

Across multiple sessions, presenters converged on the same finding: identity is the most targeted and vulnerable component of modern cybersecurity. Traditional passwords and SMS-based multi-factor authentication (MFA) are no longer considered reliable protections. AI-generated phishing content has become convincing enough to deceive careful, sophisticated users — meaning human judgment alone can no longer be the last line of defense.

Phishing-resistant MFA — authentication mechanisms tied to a specific physical device rather than a code delivered by text or email — represents the current standard of practice. Beyond authentication, family offices should be continuously reviewing who has access to what, reducing the “blast radius” of any single compromised account by limiting unnecessary privileges.

Resilience, not just prevention

One of the defining statements of the forum came from David Robinson, CISO and Managing Director at BNY: “Stop doing security and start being secure.” The distinction matters. Security as a prevention-only mindset assumes attacks can be reliably blocked. A resilience mindset assumes compromise is possible — and prepares accordingly.

For family offices, this means investing in recovery capabilities alongside protective controls: incident response plans that are tested and current, business continuity procedures that account for operational disruption, and clear escalation protocols so that when something happens, every minute is not wasted figuring out who to call.

The convergence of personal and institutional risk

Perhaps the most significant development in family office cybersecurity is the convergence of institutional and personal risk. Protecting a family today means extending oversight into domains that have historically been considered private.

Digital footprint management — removing personal information from public data broker sites, monitoring for exposed credentials on the dark web, and setting up protections against SIM-swap attacks — is now a standard component of comprehensive cyber programs for ultra-high-net-worth individuals. The distinction between protecting an organization and protecting a family is, in practice, no distinction at all.

Vendor and AI governance cannot be after thoughts

Two additional areas generated significant discussion at the forum. Third-party risk continues to grow: attackers frequently gain access not through a direct breach but through a vendor who holds organizational data. Family offices should require written documentation from all vendors regarding data handling, AI usage, and governance practices.

On AI specifically, the forum was direct. Sensitive information should never be entered into public AI platforms. Agentic AI systems — those capable of taking actions without a direct human prompt — introduce new risks that require governance frameworks before deployment. The guidance from J.P. Morgan’s Head of Cyber Advisory was practical and pointed: “If you don’t want it on the front page of a newspaper, don’t put it into AI.”

What this means for Pitcairn and the families we serve

At Pitcairn, we have long understood that protecting a family’s wealth requires protecting far more than a portfolio. The forum reinforced what our work has always reflected: the most meaningful risks facing the families we serve are not confined to any single domain. They extend across generations, relationships, and institutions.

Cybersecurity, at its best, is an expression of the same values that define everything we do: care, continuity, and a commitment to protecting what matters most.

 

Disclaimer: Pitcairn Wealth Advisors LLC (“PWA”) is a registered investment adviser with its principal place of business in the Commonwealth of Pennsylvania. Registration does not imply a certain level of skill or training. Additional information about PWA, including our registration status, fees, and services is available on the SEC’s website at www.adviserinfo.sec.gov. This material was prepared solely for informational, illustrative, and convenience purposes only and all users should be guided accordingly. All information, opinions, and estimates contained herein are given as of the date hereof and are subject to change without notice. PWA and its affiliates (jointly referred to as “Pitcairn”) do not make any representations as to the accuracy, timeliness, suitability, completeness, or relevance of any information prepared by any unaffiliated third party, whether referenced or incorporated herein, and takes no responsibility thereof. As Pitcairn does not provide legal services, all users are advised to seek the advice of independent legal and tax counsel prior to relying upon or acting upon any information contained herein. The performance numbers displayed to the user may have been adversely or favorably impacted by events and economic conditions that will not prevail in the future. Past investment performance is not indicative of future results. The indices discussed are unmanaged and do not incur management fees, transaction costs, or other expenses associated with investable products. It is not possible to invest directly in an index. Projections are based on models that assume normally distributed outcomes which may not reflect actual experience. Consistent with its obligation to obtain “best execution,” Pitcairn, in exercising its investment discretion over advisory or fiduciary assets in client accounts, may allocate orders for the purchase, sale, or exchange of securities for the account to such brokers and dealers for execution on such markets, at such prices, and at such commission rates as, in the good faith judgment of Pitcairn, will be in the best interest of the account, taking into consideration in the selection of such broker and dealer, not only the available prices and rates of brokerage commissions, but also other relevant factors (such as, without limitation, execution capabilities, products, research or services provided by such brokers or dealers which are expected to provide lawful and appropriate assistance to Pitcairn in the performance of its investment decision making responsibilities). This material should not be regarded as a complete analysis of the subjects discussed. This material is provided for information purposes only and is not an offer to sell or the solicitation of an offer to purchase an interest or any other security or financial instrument.

Back to All