Family Office Authority Control for UHNW Operations
A family office can hold extraordinary power over a UHNW family’s life.
Money.
Residences.
Travel.
Vehicles.
Vendors.
Household staff.
Calendars.
Insurance.
Legal matters.
Medical information.
Children’s schedules.
Executive protection.
Residential security.
Private aviation.
Banking instructions.
And sometimes the authority to change all of those things with one email or phone call.
That is why I do not think about family office security primarily as an IT problem.
I think about authority.
Who is allowed to cause something important to happen?
Who can move money?
Who can change bank instructions?
Who can add a vendor?
Who can issue a gate credential?
Who can tell the driver that the principal’s destination changed?
Who can give a contractor access to a residence?
Who can send the full family itinerary?
Who can create a new administrator in the family’s cloud environment?
Who can override the normal process because the principal supposedly said it was urgent?
Those questions matter because modern impersonation is getting much better.
The FBI’s 2025 Internet Crime Report recorded more than one million complaints and approximately $20.9 billion in reported losses. Business email compromise alone accounted for about $3 billion in reported losses. For the first time, the report also included a dedicated discussion of artificial intelligence-related fraud: 22,364 complaints associated with nearly $893 million in reported losses.
California had the highest reported internet-crime losses of any state in the 2025 IC3 data, at approximately $3.67 billion.
That does not mean every family office is about to be attacked.
It means email address, caller ID, text message, senior title and even a familiar voice should no longer be treated as sufficient authorization for an unusual high-impact action.
In May 2025, the FBI warned about an ongoing campaign in which malicious actors impersonated senior U.S. officials using text messages and AI-generated voice messages. The purpose was to establish trust and eventually gain access to personal accounts or information.
If criminals can imitate senior government officials, a UHNW family office should assume that a believable message from the principal, CEO, family member, attorney, banker or vendor may eventually need independent verification.
The security answer is not paranoia.
It is process.

Key takeaways
- Family office security is authority control. Know who can initiate, approve and execute sensitive actions.
- A senior title should not eliminate verification. An unusual request from the principal, CEO or family member can still require confirmation.
- Voice is no longer sufficient authentication. AI-generated voice impersonation makes independent verification more important for high-impact requests.
- Separate initiation, approval and execution where the consequence is high. One compromised employee should not automatically be able to create and complete an irreversible action.
- Payment changes deserve independent confirmation. A new bank account should not be verified through the same email thread that requested the change.
- Physical and digital authority belong in the same review. A person can lose email access and still retain a gate remote, property key or alarm credential.
- Role changes matter as much as terminations. Employees accumulate unnecessary authority when access follows history instead of current responsibility.
- Vendor access should expire. Temporary work should create temporary access unless there is a documented business reason otherwise.
- The family calendar is sensitive operational information. Different people should receive only the portion required for their role.
- Emergency overrides need rules too. Urgency should speed the verification process, not remove it.
- Fraud response has to be immediate. If money was sent fraudulently, the FBI advises contacting the originating financial institution immediately and filing with IC3 as quickly as possible.
- The security model should preserve convenience. Strong family-office controls should make sensitive actions deliberate without making normal work unnecessarily slow.
The family office is often the control plane for the household
People tend to think of the family office as administration.
That understates its security significance.
The family office often connects:
the principal;
spouse;
children;
estate managers;
household staff;
bankers;
attorneys;
investment professionals;
accountants;
executive assistants;
drivers;
aircraft providers;
travel advisers;
insurance;
IT;
medical providers;
event planners;
and residential security.
That makes it a concentration point.
Not only for information.
For authority.
Authority is more important than access alone
Access asks:
“Can this person see the bank account?”
Authority asks:
“Can this person cause $500,000 to leave it?”
Access asks:
“Can this employee view the family calendar?”
Authority asks:
“Can they change the principal’s airport pickup?”
Access asks:
“Can this vendor enter the property?”
Authority asks:
“Can they create another credential for somebody else?”
Those are different security questions.
Create an authority map
I would want the family office to understand who can perform important actions.
Not based only on job title.
Based on actual capability.
For example:
- create a new payee;
- approve a wire;
- release a wire;
- change bank information;
- open a new financial account;
- approve a vendor;
- sign a vendor agreement;
- issue building access;
- issue estate access;
- change an alarm credential;
- change a gate code;
- authorize a contractor;
- access the principal’s full schedule;
- change an itinerary;
- change transportation;
- release residential information;
- release medical information;
- access the family’s password manager;
- create another system administrator;
- export sensitive records;
- approve private-aircraft movement;
- or override normal procedures.
Then ask whether the current authority still matches the current job.
Titles can hide authority accumulation
A long-serving employee may gradually become:
calendar administrator;
vendor approver;
travel coordinator;
banking contact;
cloud administrator;
and emergency contact.
Nobody deliberately designed that concentration.
It happened because the person is competent and trusted.
Trust is not the problem.
Concentrating too much authority in one place can become the problem.
One compromised employee should not unlock the entire organization
Suppose somebody takes control of one executive assistant’s email.
Can they:
see the principal’s schedule?
change transportation?
communicate with the driver?
contact the hotel?
send the residence address?
request money?
approve a vendor?
If yes, one compromised account has become much more than an email problem.
Separate initiation, approval and execution
This is one of the most useful ways to control higher-consequence actions.
Person A can request.
Person B approves.
The financial institution or another authorized person executes.
That may be unnecessary for a $120 catering invoice.
It may be entirely appropriate for:
a six-figure wire;
a new beneficiary;
an account-number change;
a large asset transfer;
or another irreversible transaction.
The threshold should follow consequence
I do not want two-person approval on every administrative action.
That turns security into bureaucracy.
I want additional controls where one mistake produces a serious consequence.
Set thresholds.
Dollar amount.
New beneficiary.
International transfer.
First transaction with a vendor.
Bank-account change.
Unusual urgency.
Whatever fits the family.
Business email compromise remains an enormous financial threat
The FBI describes business email compromise as one of the most financially damaging forms of online crime.
A typical scheme can involve a criminal appearing to be a known vendor, executive or other trusted person and requesting a legitimate-looking financial action.
Reported BEC losses were approximately $2.77 billion in 2024 and approximately $3 billion in 2025.
For a family office, the scenario can be even more believable because the organization routinely handles unusual requests.
Private jet.
Art purchase.
Property closing.
Emergency repair.
Attorney wire.
Large insurance payment.
Investment transfer.
Luxury vehicle.
Household payroll.
Those transactions may be perfectly legitimate.
That makes a fraudulent one easier to hide inside normal UHNW activity.
Banking changes should receive stronger verification than routine invoices
A long-standing vendor says:
“We changed banks.”
Pause.
Verify through the known vendor contact using information you already had before the request arrived.
Do not reply to the same email and ask:
“Is this really you?”
If the account is compromised, the criminal answers.
The FBI recommends using secondary channels to verify changes to account information.
Build a known-channel directory
The family office should maintain trusted contact information for sensitive counterparties.
Bank.
CPA.
Attorney.
Payroll provider.
Insurance broker.
Aircraft operator.
Major contractor.
Investment adviser.
Security company.
Important vendors.
If an unusual request arrives, use the known number.
Not the number inside the suspicious message.
Caller ID is not verification
The FBI’s account-takeover guidance specifically warns that caller ID should not automatically be trusted and recommends independently looking up a known number before returning a suspicious call.
That principle should become routine inside a UHNW family office.
Voice recognition is not enough anymore
This is where current AI developments matter.
A family office employee may know the principal extremely well.
They hear the principal’s voice every day.
Historically, that could feel like strong authentication.
It is becoming weaker.
The FBI’s 2025 senior-official impersonation warning specifically described malicious actors using AI-generated voice messages while impersonating senior officials.
The FBI’s 2025 Internet Crime Report later identified more than 22,000 AI-related complaints associated with almost $893 million in reported losses.
A familiar voice can be evidence.
It should not always be final authorization.
Create a principal-verification protocol
This does not have to feel ridiculous.
Most instructions from the principal proceed normally.
Additional verification is triggered when the request is unusual.
Examples:
“Wire $700,000 immediately.”
“Do not tell the CFO.”
“Send me the password.”
“Change the driver to this person.”
“Give this contractor the Malibu gate code.”
“Send me the children’s schedule.”
“Transfer the funds to this new account.”
“I lost access to my phone. Use this new number.”
“I need every account credential right now.”
Those are exception requests.
Verify the action, not just the person
This distinction matters.
The message might genuinely come from the principal.
The request can still be mistaken.
Wrong account.
Wrong recipient.
Misunderstood amount.
Compromised device.
Coercion.
A deliberate verification step protects the principal too.
Do not build the whole system around a secret code word
A family can use a private phrase if it wants.
It can help.
I would not make it the only verification method.
The phrase can be forgotten.
Disclosed.
Overheard.
Or eventually copied.
Use layered confirmation.
Urgency is a reason to speed verification, not eliminate it
This rule is simple.
“We need it in five minutes.”
Fine.
Verification takes thirty seconds.
“The principal said nobody else can know.”
If the requested action requires secondary approval, confidentiality does not remove the control.
“The banker is waiting.”
Then call the banker through the known number.
Isolation language should increase attention
Fraudulent and coercive instructions often try to isolate one decision-maker.
“Do not call anyone.”
“This is confidential.”
“The principal will be angry if this gets delayed.”
“Only you can help.”
“Do it before compliance notices.”
A legitimate principal may occasionally request confidentiality.
That does not mean the organization should abandon critical controls.
The principal should know the controls too
This is crucial.
If the family office has a verification process but the principal believes verification is insubordination, employees will eventually bypass it.
The principal needs to support the system.
If I send an unusual wire request, call me.
If my voice message tells you to bypass controls, verify it.
If my phone number changes unexpectedly, do not trust the change automatically.
That cultural support is worth more than another page in a policy.
Emergency authority should be preassigned
Sometimes the principal truly cannot be reached.
Medical emergency.
Aircraft in flight.
No communication.
Major disaster.
Then what?
The family office should know who has emergency authority.
Spouse?
Chief of staff?
Family-office president?
Trustee?
General counsel?
The exact structure depends on the family.
But it should exist before the crisis.
Emergency authority should have boundaries
Person can approve:
hotel relocation;
emergency aircraft;
temporary security;
medical transport;
reasonable household expenses.
Maybe they cannot:
liquidate investments;
change trust arrangements;
or transfer unrestricted millions.
Emergency authority should match the actual continuity requirement.
Role-based access should follow current responsibility
The original article was right to focus on access.
I would go further.
Access should follow today’s role.
Not yesterday’s convenience.
The travel coordinator needs travel information.
The residential-security manager needs property-access information.
The accountant needs financial information.
The IT administrator needs systems access.
That does not mean each person needs everything the others have.
Family offices accumulate access gradually
This is rarely deliberate.
An employee covers for somebody.
Gets temporary access.
Keeps it.
A project begins.
Vendor receives access.
Project ends.
Access remains.
Somebody is promoted.
New permissions are added.
Old permissions never removed.
Ten years later, nobody knows why the person still has them.
Review role changes as security events
People focus on termination.
Internal role changes matter too.
An employee moves from:
principal support
to philanthropy.
Do they still need the full travel calendar?
A property manager stops managing Malibu.
Do they still need the Malibu gate application?
An assistant no longer handles banking.
Why can they still access wire instructions?
Run periodic access certification
I want managers to periodically review:
who has access;
what they can do;
why they still need it;
and who owns the decision.
Not because I assume somebody is malicious.
Because access drifts.
Physical and digital access should be reviewed together
This is where a lot of offboarding fails.
IT terminates:
email;
cloud;
VPN;
password manager.
Good.
But the former employee still has:
gate remote;
garage remote;
residence key;
building badge;
alarm credential;
vehicle app;
vendor portal;
or a shared calendar copied to a personal device.
That is still incomplete.
Offboarding should begin before the final conversation when appropriate
For planned departures, responsible leaders can prepare:
account disablement;
device collection;
key recovery;
gate credential removal;
vendor notification;
password changes;
and data-transfer ownership.
Then execute according to the employment situation and legal requirements.
Do not rely on the departing employee to remember everything they have
Use an inventory.
Laptop.
Phone.
Tablet.
Key.
Badge.
Remote.
Vehicle access.
Authentication token.
Property credential.
Cloud account.
Bank token.
Password manager.
Shared mailbox.
Vendor account.
Shared accounts create accountability problems
“Everyone uses the housemanager login.”
That is convenient.
It also makes it harder to know:
who accessed something;
who changed something;
who should lose access;
and whether an old password remains known.
Named accounts are generally easier to manage for sensitive systems.
Where shared credentials are unavoidable, ownership has to be explicit
Who maintains the credential?
When is it changed?
What event triggers rotation?
Who knows it?
A shared credential cannot become permanent institutional folklore.
Vendor access deserves the same authority review
The family office depends on vendors.
That is normal.
But vendors can hold significant operational access.
IT provider.
Accountant.
Property-management software.
Alarm company.
Executive transportation.
Private aviation.
Travel provider.
Insurance administrator.
Payroll processor.
Construction company.
Event company.
Residential contractor.
Ask what the vendor can actually do
Not only:
“Do they have an account?”
Ask:
Can they see family addresses?
Can they see schedules?
Can they add users?
Can they download files?
Can they change banking information?
Can they unlock a property?
Can they invite subcontractors?
Can they create permanent credentials?
Subcontractors should not appear invisibly
The family hires Company A.
Company A hires Company B.
Company B sends a technician the family has never heard of.
That may be legitimate.
The family office should know whether subcontracting is allowed and what access those personnel receive.
Temporary access should have an end date
Construction project ends December 15.
Access expires December 15.
If work extends, renew it.
That is cleaner than granting indefinite access and hoping somebody remembers later.
Vendor data access should be limited too
The FTC’s current cybersecurity guidance for businesses advises limiting vendor access to what is necessary for the job and only for the period the vendor needs it. Its breach-response guidance likewise recommends reviewing what service providers can access and restricting privileges that are no longer necessary.
That is common sense for a UHNW family office.
The landscaping company does not need travel schedules.
The travel company does not need trust documents.
The alarm vendor does not need investment records.
A vendor breach can become a family-security problem
If a vendor account exposes:
home address;
principal name;
telephone numbers;
travel;
vehicle information;
children;
gate information;
or residence diagrams,
the issue is no longer simply the vendor’s IT problem.
The family office should understand what information was exposed and what physical-security decisions may need to change.
Create a vendor compromise response
Vendor reports a breach.
Ask:
What family information did they hold?
What credentials did they have?
What systems could they reach?
What time period?
Do credentials need revocation?
Do gate codes need changing?
Does the residential team need notification?
Does the executive protection team need relevant information?
Family-office security should connect consequences across departments
This is where operational security differs from siloed IT.
A breached calendar can become a travel-security issue.
A compromised vendor portal can become a residence-access issue.
A payment-fraud attempt can reveal that an email account is compromised.
An unusual call about the principal’s location can become a protective-intelligence report.
The family office needs to connect those dots.
The family calendar is an authority problem too
People think mainly about who can see it.
I also care who can change it.
Can an assistant:
change the airport?
replace the driver?
change the hotel?
add a private residence?
cancel executive protection?
move the principal to another event?
The ability to edit the schedule is operational authority.
A schedule change should have an authorized source
The CEO’s business partner emails:
“Send him here instead.”
That person may be important.
They may not have authority to redirect the principal.
Define:
principal;
spouse;
chief of staff;
executive assistant;
or whoever legitimately controls the itinerary.
The protection team needs accurate information without seeing everything
The executive protection team may need:
flight;
hotel;
meeting address;
event timing;
transportation;
and relevant guests.
It does not necessarily need:
investment materials;
board documents;
private legal advice;
or unrelated family records.
Use information slices
Driver gets:
pickup;
destination;
time.
Residential team gets:
expected return;
authorized visitors;
relevant household movement.
Travel coordinator gets:
flight;
passenger requirements;
lodging.
The full picture stays with the people who actually require it.
Do not forward the master itinerary because it is convenient
“See attached.”
That one attachment may contain:
family names;
hotel;
aircraft;
school;
private meetings;
residence addresses;
phone numbers;
and future absence from home.
Send what the recipient needs.
Travel documents require the same discipline
Passport information.
Known Traveler Number.
Birth date.
Aircraft manifest.
Hotel confirmation.
Those are operationally necessary in some places.
They should not spread through dozens of casual email threads.
The residence-access list and family-office employee list should talk to each other
Employee leaves the office.
Residential security should know if they previously had property access.
A contractor changes.
Family office should know if the gate system needs updating.
The residential security program and family office should not maintain unrelated authorization lists.
Use one access-change workflow
Person joins.
Role approved.
Digital access assigned.
Physical access assigned.
Role changes.
Access reviewed.
Person leaves.
Both are removed.
That is much stronger than relying on separate people to remember separate systems.
Residence information should be treated as sensitive operational data
Not only the address.
Gate instructions.
Alarm information.
Household names.
Staff roster.
Vendor schedule.
Children.
Vehicles.
Principal home status.
Those details can become physically useful to an outsider.
Mail and package handling is an authority issue too
Who can open principal mail?
Who routes legal documents?
Who receives financial correspondence?
Who handles replacement credit cards?
Who handles medical shipments?
Who decides a package goes directly to the residence?
Those roles should be deliberate.
Do not allow sensitive mail to float through the office
Defined receiving point.
Defined routing.
Defined destruction.
That reduces both accidental disclosure and confusion.
Document destruction should match document sensitivity
Bank statements.
Old travel itineraries.
Medical correspondence.
Employee records.
Residence information.
Those should not go casually into an ordinary trash stream.
Devices are family-office assets when they hold family-office information
A laptop may physically belong to an employee.
If it contains sensitive family information, the organization still needs a security policy governing:
access;
storage;
backup;
loss;
replacement;
and departure.
Personal messaging can create invisible records
The principal texts one employee.
That employee forwards it to another.
Vendor responds on WhatsApp.
Banking instruction moves to SMS.
Now the transaction history exists across several private devices.
That complicates verification and incident response.
Sensitive operational actions should have a known record
I do not care whether every lunch reservation lives in a formal system.
I do care whether:
bank changes;
new vendor approvals;
gate access;
large transfers;
and major itinerary overrides
can be reconstructed later.
Keep approval records proportionate
Who requested?
Who verified?
Who approved?
When?
What changed?
That may be enough.
Audit logs become valuable after something goes wrong
Who added the vendor?
Who changed the bank information?
Who created the administrator?
Who exported the file?
Who opened the principal’s schedule?
If the system can answer those questions, investigation becomes easier.
Do not give administrators unlimited permanence
IT administrators naturally need powerful access.
That access should still be attributable and reviewable.
A former outsourced IT technician should not remain a hidden administrator for three years because nobody knew the account existed.
Administrative accounts deserve special offboarding
When IT vendors or administrators change:
review admin accounts;
service accounts;
API credentials;
remote-support tools;
backup accounts;
password vaults;
and recovery methods.
Deleting an email account alone does not address privileged access.
Family office security also needs a reporting culture
An employee receives a strange request.
They should be comfortable saying:
“I want somebody to look at this.”
Not:
“I do not want to bother anyone.”
Employees should report anomalies before they prove a crime
Vendor asks an unusual question.
Principal’s supposed new phone number sends an urgent request.
Someone asks which residence the family is using.
A caller tries to confirm travel.
A bank-change email looks slightly different.
A former employee requests access to an old folder.
Report it.
Then assess it.
One strange contact may be meaningless
Five across several departments may not be.
This is where protective intelligence belongs behind the family office.
The receptionist sees one part.
EA sees another.
Residential security sees another.
Travel sees another.
If the reports never meet, nobody sees the pattern.
This should remain separate from broad online monitoring
Family office security does not need to become an intelligence agency.
The office needs a disciplined intake process for security-relevant events that actually touch the family or operation.
That keeps this function focused.
Use a clear escalation ladder
Example:
Routine administrative issue.
Supervisor.
Security-relevant anomaly.
Security lead.
Potential financial fraud.
Finance plus security.
Potential threat to a person.
Executive protection or residential security plus law enforcement where appropriate.
Compromised bank transfer.
Financial institution and IC3 immediately.
Fraud-response speed matters
If a fraudulent transfer has already occurred, the FBI advises contacting the originating financial institution immediately to request a recall or reversal and filing an IC3 complaint as soon as possible. IC3 may be able to assist financial institutions and law enforcement with attempts to freeze funds.
That response should already be written down.
Do not spend the first hour debating whether the email was really fake
Bank first.
Preserve evidence.
IC3.
Appropriate law enforcement.
Then continue internal analysis.
Time matters more than embarrassment.
Preserve the original fraud evidence
Email.
Headers.
Phone number.
Text message.
Wire instruction.
Account information.
Invoice.
Call recording where lawfully available.
Approval record.
Do not reduce everything to:
“We received a fake email.”
Do not immediately delete the compromised account history
Secure the account.
Revoke compromised access.
Preserve what may be necessary for investigation.
Then determine scope.
Account takeover can require credential revocation beyond one password
IC3’s current account-takeover guidance advises resetting or revoking exposed user accounts, service accounts, certificates and other secret credentials when compromise occurs.
That is particularly important in a family office because one mailbox may connect to many other services.
Ask what the compromised account could reach
Email compromised.
Could it reset banking?
Password manager?
Travel?
Cloud drive?
Alarm?
Vehicle account?
Hotel account?
Private aviation?
Vendor portal?
The answer defines the incident scope.
The family office should know its critical systems before an incident
Banking.
Payroll.
Email.
Calendar.
File storage.
Password management.
Travel.
Residential access.
Security reporting.
Device management.
Backup.
List them.
Then define an owner for each one
Who can approve users?
Who disables them?
Who calls the vendor?
Who reviews logs?
Who handles emergency recovery?
No system should be everybody’s responsibility.
A family office should know its most consequential single points of failure
One employee knows every password.
One phone receives every authentication code.
One assistant controls the calendar and transportation.
One IT provider can administer every system.
One banker can only reach one family-office employee.
That may work for years.
Then the person is:
unavailable;
terminated;
hospitalized;
compromised;
or simply on an aircraft.
Continuity and security are connected
A control that prevents fraud but stops all legitimate activity when one employee is unavailable is not ideal.
I want secure redundancy.
A backup approver.
A recovery process.
Emergency access that is itself controlled.
Use break-glass authority carefully
Some organizations maintain emergency access for critical situations.
That can be appropriate.
But emergency credentials should not become a permanent shortcut around the normal process.
Use.
Log.
Review.
Reset where necessary.
Security exceptions should expire
Temporary additional administrator for a migration.
Temporary gate access for a construction project.
Temporary calendar access for a visiting assistant.
Temporary vendor access for tax season.
Set an end date.
Do not make temporary permanent by forgetting
Many security weaknesses are not created by bad decisions.
They are created by temporary decisions that never end.
The family office should maintain an access-change calendar
Vendor access expires.
Contract renewal.
Temporary permission ends.
Quarterly access review.
Annual key audit.
Credential review.
Those events can be scheduled.
Physical keys need an inventory too
Main residence.
Guest house.
Garage.
Office.
Storage.
Second residence.
Mechanical room.
Vehicle.
Who holds what?
Do not assume.
Gate remotes are credentials
They should be treated like access cards.
Issued.
Assigned.
Recovered.
Disabled where technologically possible.
Alarm codes should not outlive employment
And the family should know whether codes are:
individual;
shared;
or tied to a vendor.
Individual credentials provide better accountability.
Property apps create another offboarding category
Smart locks.
Garage.
Cameras.
Intercom.
Gate.
HVAC.
Lighting.
Vehicle chargers.
A former employee may never hold a physical key but still control part of the residence through an application.
Household devices should be included in role reviews
Tablet on the wall.
House phone.
Shared iPad.
Security workstation.
Old phone kept for vendor access.
Each can retain credentials after staffing changes.
Family members themselves may bypass the controls
This is real.
Family member says:
“Just give my friend the gate code.”
Principal forwards their master itinerary.
Teenager shares the Wi-Fi.
Spouse tells a vendor when the family is traveling.
Security has to fit the family.
You cannot build a program as if household members are corporate employees.
The right answer is usually easier secure behavior
Guest access link.
Temporary gate credential.
Simple approval process.
Easy secure file sharing.
Fast way to request travel.
If the secure method is harder than sending a text, people will eventually send the text.
Good family office security should reduce friction where risk is low
Ordinary lunch reservation?
Fast.
Normal recurring invoice?
Fast.
Known driver and known route?
Fast.
Routine housekeeping vendor?
Fast.
Security friction belongs at the exception.
High-risk exceptions deserve deliberate friction
New bank details.
New payee.
Large unusual wire.
Unknown vendor.
New residence credential.
Unexpected itinerary change.
Request for full family data.
New administrator.
Unusual principal instruction.
That is where I want people to slow down briefly.
California’s current fraud exposure makes this especially relevant
The FBI’s 2025 state data reports approximately $3.67 billion in internet-crime losses associated with California victims, the highest total of any state.
California’s 2025 IC3 data also recorded thousands of BEC victims, phishing and spoofing reports, extortion complaints and AI-related incidents.
I would not use those statistics to tell every UHNW family that they are uniquely targeted.
I use them to demonstrate that impersonation and account compromise are operating realities around us.
Impersonation itself is producing billions in reported losses
The FTC reported $3.5 billion in losses to imposter scams during 2025, with nearly one in three fraud reports involving impersonation. Almost $1 billion was reported lost to business impersonators alone.
Again, that is broad consumer data.
It is not family-office-specific.
But the trend matters.
Criminals succeed by borrowing trusted identities.
A family office is built around trusted identities.
Trust should determine relationships, not eliminate controls
I trust the principal.
I still verify an abnormal $2 million instruction.
I trust the accountant.
I still verify a sudden bank change.
I trust the estate manager.
I still remove property access when their role ends.
I trust the IT company.
I still want to know what they can access.
That is not distrust.
It is mature operations.
Authority controls protect employees too
A good employee can be manipulated.
Compromised.
Pressured.
Impersonated.
Or simply make a mistake.
Two-person control means one employee does not carry the full consequence alone.
Employees should be allowed to challenge unusual instructions respectfully
“I know this came from the principal. Our process requires me to verify the new beneficiary.”
That should be normal.
Not career-limiting.
Executives should reward verification
“Good catch.”
Even when the request was legitimate.
That one response teaches the office more than a mandatory annual slide deck.
Authority controls also reduce internal disputes
Who approved the contractor?
Who changed the wire?
Who authorized the driver?
Who gave access to the estate?
A clear process answers those questions.
It protects relationships as much as assets.
Family offices supporting multiple residences need property-specific authority
Beverly Hills.
Malibu.
Westlake Village.
Montecito.
New York.
Europe.
A person may legitimately need access to one residence but not the others.
Do not automatically synchronize every physical permission.
A Malibu contractor should not become a Montecito contractor by default
Even if the same family owns both homes.
Scope access to scope of work.
Property-access requests should originate from known authority
“The principal told me I can come in.”
Maybe.
The gate team should have an authorization source.
Estate manager.
Family office.
Designated household manager.
Not the visitor’s claim alone.
The family office should know when residential access changes
Former housekeeper.
New nanny.
Construction foreman.
Temporary dog sitter.
Private chef.
Visiting assistant.
Those changes should reach residential security.
Residential security should report access exceptions back
Vendor arrived who was not expected.
Former employee attempted entry.
Person used an old gate code.
Contractor brought additional workers.
Guest said the principal approved them.
That information should return to the family office.
The two systems should reinforce each other
Family office controls authorization.
Residential security observes actual access.
When the two disagree, investigate the gap.
Executive protection adds another authority layer
The mobile team receives:
schedule;
transportation;
event information;
flight;
hotel;
and residential return information.
Who can change those instructions?
That should be known.
An outside executive should not be able to redirect the principal casually
“I am the CEO’s business partner. Take him to this address.”
The person may genuinely be important.
The protection team still follows the principal’s authorized movement process.
Family office process and executive protection should agree before travel
Who owns the itinerary?
Who can amend it?
Who approves a new driver?
Who receives incident reports?
Who handles emergency relocation?
The answers should not change when the plane lands.
What families and family offices can do now
Build an authority matrix
List sensitive actions and the people who can initiate, approve and execute them.
Identify high-consequence actions
Large wire.
New beneficiary.
Bank change.
Administrator creation.
Residence access.
Full itinerary release.
Apply two-person control selectively
Use it where a single compromised employee could create a major irreversible consequence.
Create a principal-verification process
Especially for unusual financial or access instructions.
Do not rely solely on voice recognition
Current AI impersonation makes that increasingly weak authentication.
Create a known-channel contact directory
Bankers.
Attorneys.
Accountants.
Critical vendors.
Verify bank changes out of band
Never through the same thread requesting the change.
Create fraud-response instructions
Bank immediately.
Wire recall.
Preserve evidence.
IC3.
Appropriate law enforcement.
Review employee authority by role
Not just system login.
Review access after promotions and transfers
Do not wait for termination.
Run periodic access reviews
Digital and physical together.
Inventory privileged accounts
Cloud admins.
IT vendor accounts.
Banking admins.
Password-vault administrators.
Inventory physical credentials
Keys.
Badges.
Gate remotes.
Alarm codes.
Property applications.
Make offboarding checklist-driven
Assign ownership for every category.
Expire vendor access
Do not leave project credentials open forever.
Review subcontractor authority
Know whether a vendor can introduce additional people or accounts.
Limit full-calendar access
Use information slices where possible.
Define itinerary-change authority
Principal.
Spouse.
EA.
Chief of staff.
Whatever the family chooses.
Connect family office and residential-security access lists
One should update the other.
Create an anomaly-reporting path
Make unusual requests easy to report.
Record high-impact approvals
Who requested?
Who verified?
Who approved?
Design emergency authority before an emergency
Know who can act when the principal cannot.
Create secure redundancy
No single person should be the only way to operate a critical household function.
How MSB Protection approaches family office security
At MSB Protection, I look at the family office as part of the protective environment around the family.
I am not trying to turn it into a security department.
I want to understand where authority sits.
Who can move something?
Who can reveal something?
Who can change something?
Who can approve access?
Who can override normal operations?
Then I look at what happens if that person:
makes a mistake;
is impersonated;
has an account compromised;
leaves the organization;
becomes unavailable;
or receives a request under pressure.
That review can sit inside a broader security assessment and connect directly to:
- family office operations;
- protective intelligence;
- executive protection;
- residential security;
- travel security;
- vendor management;
- and emergency continuity.
I am less interested in whether the office has a fifty-page security policy than whether sensitive actions actually work correctly.
A policy may say bank changes require verification.
Show me how the office verifies one.
A policy may say terminated employees lose access.
Show me the last terminated employee.
Were the:
email;
cloud accounts;
gate remote;
alarm credential;
vehicle access;
password manager;
and vendor accounts
actually addressed?
That tells me more.
Security controls have to survive the principals convenience
UHNW life moves quickly.
Trips change.
Properties change.
New employees start.
Contractors appear.
Banking transactions can be large.
Emergency purchases happen.
Family members expect fast service.
The security model has to work in that environment.
If every unusual request takes three days to approve, people will bypass the process.
The better answer is fast verification.
Known contacts.
Clear thresholds.
Backup approvers.
Simple records.
And employees who know exactly what requires another set of eyes.
The goal is not zero trust between people
Families need trusted employees.
Family offices cannot operate without trust.
The point is that good controls reduce how much damage one compromised point of trust can create.
Trust the employee.
Verify the unusual transfer.
Trust the vendor.
Expire their credential when the project ends.
Trust the executive assistant.
Do not give the account unlimited permanent authority because they covered another role three years ago.
Trust the principal.
Still confirm the strange midnight request to change a bank beneficiary.
That is mature family-office security.
Frequently asked questions
What is family office security?
Family office security is the protection of the people, information, access and decision-making processes that support a high-net-worth or ultra-high-net-worth family. It can include financial approval controls, vendor access, physical property credentials, itinerary protection, employee lifecycle management, protective intelligence and coordination with executive and residential protection.
What is authority control in a family office?
Authority control means defining who can initiate, approve and execute sensitive actions such as moving money, changing bank instructions, giving property access, modifying itineraries or releasing private information.
Why is authority different from access?
Access determines what someone can reach. Authority determines what they can cause to happen. An employee might be allowed to view financial information without being authorized to move funds.
Should one employee be able to initiate and approve a large wire?
That depends on the family’s structure and risk tolerance, but high-consequence actions can benefit from separation between initiation and approval so one compromised account or mistake does not automatically complete the transaction.
What is two-person approval?
It means requiring a second authorized person to confirm a sensitive action. It can be useful for large transfers, new beneficiaries, significant banking changes, privileged system access and other high-impact decisions.
Should every payment require two approvals?
No. Controls should remain proportionate. Routine low-value transactions can follow simpler procedures while higher-risk exceptions receive additional verification.
How large is the business email compromise problem?
The FBI reported approximately $3 billion in BEC losses during 2025. The FBI considers BEC one of the most financially damaging forms of online crime.
Can criminals impersonate a principal using AI voice?
Yes. The FBI has already warned about campaigns using AI-generated voice messages to impersonate senior U.S. officials. A familiar-sounding voice should therefore not be the only authorization for an unusual high-value request.
How common were AI-related fraud complaints in 2025?
The FBI’s 2025 IC3 report identified 22,364 complaints involving an AI-related descriptor, associated with nearly $893 million in reported losses.
Should family office staff use a secret word with the principal?
A private phrase can be one layer of verification, but I would not depend on it exclusively. Known-channel callbacks, secondary approval and transaction-specific confirmation provide additional layers.
How should staff verify an unusual principal request?
Use a trusted communication path that existed before the unusual request, such as a known telephone number or established secondary contact, and follow the family’s predetermined approval procedure.
Should staff trust caller ID?
Not automatically. The FBI advises against relying on caller ID and recommends independently finding the organization’s known contact information when a suspicious caller claims to represent a company.
How should a vendor bank-account change be verified?
Contact the established vendor representative through a previously known channel. Do not confirm the change solely by replying to the email that supplied the new banking instructions.
What should a family office do after discovering a fraudulent wire?
Contact the originating financial institution immediately and request a recall or reversal, preserve the evidence and file a detailed IC3 complaint as quickly as possible.
Can the FBI help recover a fraudulent wire?
IC3 states that it may be able to assist financial institutions and law enforcement in attempts to freeze fraudulently transferred funds. Speed is important.
What records should be preserved after payment fraud?
Preserve original emails, wire instructions, account information, invoices, telephone numbers, messages, approval records and any other information showing how the transaction was initiated and authorized.
Should a family office employee have access to the full family calendar?
Only when the role requires it. Many employees can perform their work using specific appointments, movements or travel details without receiving the complete family itinerary.
Why is a family itinerary a security document?
It can reveal residence occupancy, travel, children’s locations, executive movements, hotels, aircraft, events and predictable transition times.
Who should be allowed to change the principal itinerary?
The family should define authorized sources, such as the principal, spouse, executive assistant or chief of staff. A senior title alone should not automatically create authority to redirect the principal.
Should the executive protection team receive the full family schedule?
The team needs the information necessary to protect the principal’s movements. Unrelated financial, legal or family information can remain restricted.
How should employee offboarding work?
Use one process covering both digital and physical access, including email, cloud systems, password managers, banking access, devices, keys, badges, gate remotes, alarm credentials and property applications.
Why should role changes trigger an access review?
Employees often retain old permissions when they move to new responsibilities. Reviewing access at the role-change point prevents authority from accumulating indefinitely.
How frequently should family-office access be reviewed?
There is no universal interval, but periodic reviews and event-driven reviews after role changes, vendor changes, staffing changes or security incidents help identify access that is no longer justified.
Should vendors receive permanent access?
Only when there is a continuing operational need. Project-based vendors are generally easier to manage when their access has a defined expiration date.
What should a family office know about subcontractors?
Know whether the contracted vendor can introduce subcontractors, what access those subcontractors receive and whether the family office must approve them.
Why should digital and physical access be reviewed together?
Because offboarding can fail in either direction. A former employee may lose their cloud account while retaining a property credential, or lose building access while keeping sensitive digital information.
Should family offices use shared accounts?
Named accounts generally provide better accountability for sensitive functions. Where shared credentials are operationally necessary, ownership, rotation and revocation procedures should be clear.
Who should control administrative IT accounts?
Privileged access should be limited to the people and providers who genuinely need it, attributable to specific users where possible and reviewed when IT personnel or vendors change.
What happens if a family office IT vendor is breached?
Determine what family information and systems the vendor could access, revoke or change affected credentials, evaluate whether physical-security information was exposed and coordinate any necessary response across IT, family-office leadership and the protection team.
Does a vendor data breach affect residential security?
It can. If exposed data includes home addresses, gate information, camera details, household schedules or family information, physical-security procedures may need to be reassessed.
What information should a driver receive?
Normally the information needed to complete the assigned movement: pickup, destination, timing and relevant contact details. The driver may not need the entire family calendar.
Should a residential security team know about employee terminations?
Yes when the employee had residence access or other property-related credentials. Physical authorization should change when employment or role status changes.
What should residential security report back to the family office?
Relevant access exceptions such as unexpected vendors, old credentials still functioning, former employees attempting entry or individuals claiming authorization that cannot be verified.
Should household staff report strange phone calls or requests?
Yes. Employees should be able to report unusual requests without first proving malicious intent. The appropriate security or family-office function can then evaluate the information in context.
Why should anomalies from different departments be compared?
One unusual call may mean nothing. Similar contacts involving an assistant, residence and travel provider may create a different picture when examined together.
What is emergency authority?
It is predetermined authority allowing designated people to make defined decisions when the principal or normal decision-maker is unavailable.
Should emergency authority be unlimited?
Not necessarily. It should cover the actions required to preserve safety and continuity while maintaining appropriate limits around highly consequential financial or legal decisions.
What is a break-glass account?
It is emergency access maintained for situations where normal access fails. Where used, it should be tightly controlled, logged and reviewed rather than becoming a routine shortcut.
Why should temporary permissions expire automatically?
Because people frequently forget to revoke them after the project or staffing need ends. Expiration converts removal from a memory problem into a system behavior.
Does family office security mean distrusting employees?
No. Strong controls protect trusted employees from mistakes, impersonation and coercion while reducing the damage one compromised account or process can cause.
How can family office security remain discreet?
Put most controls behind normal workflows. Routine activity should remain fast. Additional verification should appear mainly when the action is unusual, high-value or high-consequence.
What should a UHNW family office security assessment examine?
A professional security assessment can review authority structure, payment controls, principal verification, digital and physical access, vendor permissions, employee lifecycle procedures, itinerary handling, residential coordination, emergency authority and incident response.
Final thoughts: control the authority, not just the information
A family office can have excellent cybersecurity and still have weak operational security.
The passwords are strong.
Multi-factor authentication is enabled.
The computers are encrypted.
But one convincing message can still cause an employee to:
move money;
change a driver;
open a gate;
send an itinerary;
add a vendor;
or release sensitive information.
That is why I focus on authority.
Who can request?
Who can approve?
Who can execute?
What needs independent verification?
What happens when the instruction appears to come directly from the principal?
What happens when the voice sounds exactly like them?
What happens when the request is urgent?
What happens when the employee leaves?
What happens when the vendor’s work ends?
What happens when the principal cannot be reached?
What happens when something fraudulent already occurred?
Those questions create a real family-office security program.
The objective is not to make trusted staff feel distrusted.
The objective is not to require four signatures every time somebody orders flowers.
The objective is not to slow the family down.
The objective is to make high-consequence actions deliberate.
Routine work remains routine.
Exceptions receive attention.
Large changes get verified.
Temporary access expires.
Former employees lose authority.
Vendors receive only what they need.
The protection team receives the information it requires.
The residential team knows who belongs at the estate.
The family office can reconstruct important approvals.
And one compromised email, phone or trusted relationship does not automatically unlock the entire household.
That is what family office security should accomplish.
About Michael Braun
Michael Braun is a former Special Unit Operator, former Manager at Gavin de Becker & Associates, and Founder & CEO of MSB Protection, an executive protection and residential security firm serving high-net-worth and ultra-high-net-worth clients.
Braun has built his career at the intersection of specialized protective operations, executive protection, residential security, protective intelligence, and security risk management. His experience spans special-unit operations, leadership within Gavin de Becker & Associates, and the development and oversight of private protection programs within demanding UHNW environments.
He has been recognized by The Top 100 Magazine as a leading CEO in the private security field and is the subject of an upcoming Marquis Who’s Who feature highlighting his leadership and contributions to the profession.
Today, Braun is recognized for his work in executive protection, UHNW estate security, residential protection, protective intelligence, adversarial security assessments, and security auditing throughout Beverly Hills and Southern California.
His work focuses on moving private security beyond simply “providing a body” and toward intelligence-led, risk-based protection programs designed to identify vulnerabilities before an adversary can exploit them.
Looking for Executive Protection or Residential Security Services?
If you are a high-net-worth or ultra-high-net-worth individual, family office, estate manager, chief of staff, or executive in Beverly Hills, Los Angeles, Malibu or Southern California, MSB Protection provides executive protection, residential security, 24/7 protection, protective intelligence, medical-readiness planning, and security risk management.
We evaluate the complete security environment, from threat exposure and residential vulnerabilities to personnel, technology, procedures, protective intelligence, and emergency response, and build a program around the risks that actually exist.
Contact us for a confidential consultation or message us at +1 (805) 285-2807.