What this service does
At the principal-household level, digital and physical risk cannot be separated, so we protect the whole surface: the principal, the family, and the household and staff who have access to both.
You work directly with the examiner who scopes the engagement, with no junior handoffs and no call center, under an NDA signed before the first detail is shared.
Discreet by default, and built around your counsel and security team rather than around a sales motion.
Advisors, attorneys, and executive-protection firms: we co-engage alongside your existing relationship under NDA, with findings flowing to you and your client. Start a confidential co-engagement.
Engagements are confidential and structured to begin within 48 hours of the consultation.
Some service tracks are offered at a fixed fee; complex investigations are billed hourly with a clear scope, milestone updates, and a cap agreed up front.
The managed plans further down are a third arrangement, a fixed monthly fee for the office’s own staff and systems, and they are published.
Quinn (Founder and CEO) oversees every engagement and reviews every case before findings leave the practice; the practitioner team executes the technical work under her methodology.
- A direct line to Quinn, the founder, not a sales pipeline.
- Worked in-house by the examiner who scoped it.
- Explainable findings you can verify, with the methodology shown.
Family office engagements draw on executive threat assessment coordination, bug sweep and TSCM coordination, privacy and digital-footprint reduction, OSINT threat assessment, and personal cyber insurance coordination. Household-staff vetting uses the background investigation referral for household staff, partners, and significant introductions; field work runs through a licensed private investigator referral.
What this means for you
- Written scope before any work. You see a written scope covering deliverables, timeline, and price, and you approve it before we begin. You are never billed for work you did not authorize.
- We commit to findings, not outcomes. We tell you up front what the evidence can and cannot establish. Recovery, attribution, and prosecution are decided by banks, platforms, insurers, and courts. We produce the record they act on, and we put that distinction in writing.
- Every case is investigated, not just scanned. A credentialed examiner reviews every case before findings leave the practice. You get a documented investigation to court-admissible standards, not a single automated scan and a one-line answer.
- We will tell you if you do not need us. If a free or simpler step would resolve your situation, whether a police report, an IC3 filing, or a platform's own recovery flow, we point you there first.
What actually reaches a family office
What follows describes the rules as they are written. It is not an assessment of your office. Which of them reaches you turns on how you are structured and what you do, and those are questions you can answer about yourself in an afternoon.
A qualifying single-family office sits outside Regulation S-P
The word carrying the weight is qualifying. The family office exclusion at 17 CFR 275.202(a)(11)(G)-1 is conditional. It reaches an office that advises only family clients, that is wholly owned by family clients and exclusively controlled by family members or family entities, and that holds itself out to no one as an investment adviser. Fail any one of the three and the exclusion is gone.
It is also an exclusion from the definition of investment adviser rather than an exemption from registration. That distinction is what decides the question, because 17 CFR 248.1 applies Regulation S-P to brokers, dealers, investment companies and Commission-registered advisers. An office that is not an investment adviser in the first place never arrives at the rule.
A multi-family office generally does not
Advising unrelated families generally forfeits the exclusion, and forfeiting it generally means registering. A registered adviser is inside Regulation S-P, with six obligations and a record left by each one. We walk those item by item in what an SEC examination asks a registered investment adviser for. That is the working line between the two structures, and it is worth knowing which side of it you are on before someone else decides.
The Safeguards Rule reaches you only if you are significantly engaged, for a fee
This is one test with conditions attached rather than a ladder of prongs. The rule binds a financial institution, which 16 CFR 314.2(h)(1) describes as a business significantly engaged in financial activities. The relationship it protects is one where a financial product or service is obtained for a fee, at 16 CFR 314.2(e)(2)(i)(G). Two carve-outs sit beside that. Someone is not your consumer solely because you hold assets as their trustee, at 16 CFR 314.2(b)(2)(vi), nor solely because they benefit from a trust you administer, at (vii).
Where it does attach, size changes four things and nothing else. 16 CFR 314.6 lifts four requirements for an institution holding customer information on fewer than five thousand consumers: the written risk assessment at 314.4(b)(1), penetration testing and vulnerability scanning at (d)(2), the written incident response plan at (h), and the annual written report to the board at (i). The rest of the rule survives at any size, the written information security program included.
The state law that does reach you, with no size threshold
Fla. Stat. 501.171(2) requires a covered entity to take reasonable measures to protect and secure data in electronic form containing personal information. It carries no size threshold and no industry qualifier. A two-person family office in Florida holds the same duty as anyone else holding the same data.
What it does not carry is a client lawsuit. Subsection (10) is headed no private cause of action and says the section does not establish one, so no private plaintiff sues under it. Enforcement runs through the Florida Attorney General.
The question worth asking about your health plan
If the family self-insures a health plan for household staff, there is a question worth putting to your benefits counsel. Under 45 CFR 160.103 a group health plan is one with 50 or more participants, or one administered by an entity other than the employer that established it. Only the second of those is sizeless. The first carries a 50-participant floor.
Two precisions matter more than the answer. The covered entity would be the plan, not the family office and not the family. And a fully insured plan whose sponsor receives only summary health information sits under 45 CFR 164.530(k), which is a different situation with different paperwork. This is a question to put to counsel, not one to accept an answer to from a security vendor.
Who carries the loss when the wire goes out
Start with the allocation rule rather than with the exception. UCC 4A-202(b) makes a payment order effective as the customer’s own order, authorized or not, where the bank’s security procedure was a commercially reasonable method of guarding against unauthorized payment orders and the bank proves that it accepted the order in good faith and in compliance with that procedure. Read plainly, the default is that the loss stays with the customer.
UCC 4A-203(a)(2) is the customer’s way out of that default, and it is narrow. It puts the customer to proof that the order was not caused by anyone entrusted with duties relating to payment orders or to the security procedure, and not by anyone who obtained the means of breaching that procedure from a source the customer controlled. A compromised mailbox inside the family office is precisely the fact pattern that closes this door.
Two things about that article before it does any work for you. It is state law. Every state enacts its own version and Florida’s is Fla. Stat. 670.202, so the geography here is fifty jurisdictions rather than thirteen circuits.
It also does not reach every account you hold. UCC 4A-108 takes the article off any funds transfer any part of which is governed by the Electronic Fund Transfer Act. What follows is about the office’s and the entities’ commercial accounts rather than a principal’s consumer accounts, which is a distinction worth drawing on a page that also discusses a principal’s own phone.
Two customers, one article, opposite outcomes
In Choice Escrow & Land Title, LLC v. BancorpSouth Bank, 754 F.3d 611 (8th Cir. 2014), the customer was left carrying a $440,000 fraudulent wire. The bank’s security procedure was held commercially reasonable, and the customer had declined the dual control the bank offered. The court also returned the bank’s counterclaim for attorney’s fees for further proceedings, so the matter did not end when the wire did.
In Patco Construction Co. v. People’s United Bank, 684 F.3d 197 (1st Cir. 2012), the First Circuit went the other way. It held that the security procedure in Patco was not commercially reasonable, which took the loss off the customer. The caveat belongs in the same breath as the holding. That court reversed and remanded rather than entering judgment for the customer, and the parties settled afterward.
What separated those two customers was the quality of the security procedure and the quality of the evidence about it. That is a record you either hold on the day or you do not, and it is the thing this practice actually sells.
You already have the controls. The gap is what happens next.
The peer data is worth conceding rather than arguing with. In Campden Wealth and RBC’s North America Family Office Report 2025, with 317 offices responding, two-factor authentication was in place at 92% and dual authorization on payments at 84%. Cyber ranked sixth of nine near-term operational risks. That is a population which has already bought prevention.
Here is the figure that weakens our case most, from that same survey. 71% reported experiencing a cyberattack in the past year, and none of them reported a material financial loss or a data breach. Quoting the 92 and the 84 from that report while leaving the 71 out would be using one source selectively.
The answer sits in the wording. That is reported loss, among respondents who chose to answer, and a loss nobody reconstructed is a loss nobody measured. An office that cannot show what its wire procedure did on the day it mattered has no way of knowing which of those two columns it belongs in.
One addition on the Deloitte number this page carries further down. The figure quoted there is the global one. The North America figure in that same report is 57%, across the same 12 to 24 month window. Fieldwork closed in December 2023 and respondents self-selected, so read it as a floor on what offices will admit rather than as a measurement of what happened to them.
Which sets up the pivot plainly. Prevention in this market is saturated and reconstruction is not. UCC 4A-202(b) does not ask whether you had two-factor authentication. It asks whether the security procedure was commercially reasonable and whether the bank followed it, and answering that is an evidence problem. Producing that evidence is what the plans below are built to do.
Three staff, and one of them is also IT
Figure 3.3 of that same Campden and RBC report puts a small North America family office at three total staff. Both firms define Administration to cover human resources, information technology and premises, so one of those three people carries IT alongside two other functions.
The checkable form is the honest one. Not one of those three is a full-time IT hire. A three-person office can still retain a contractor and many do, so the question is not whether anyone is looking after the systems. The question is who reconstructs what happened while the office is answering a bank at speed.
Plans start at $995 per month. Every plan price on this page is stated at the same size, up to 10 named users and 12 protected devices, on a 12 month term, billed either monthly or as a year paid in advance. The same four plans are described for firms of other kinds on our managed security and compliance page.
The four plans
| What you get | Monitor $995 per month Up to 10 named users and 12 protected devices You have IT covered and your compliance paperwork is current. | Managed IT $1,595 per month Up to 10 named users and 12 protected devices You want us to be your IT department, and your paperwork is current. | Monitor + Comply $1,950 per month Up to 10 named users and 12 protected devices Recommended You have IT covered but need the compliance program built and kept. | Complete $2,495 per month Up to 10 named users and 12 protected devices You want one firm accountable for all of it. |
|---|---|---|---|---|
| Protection | ||||
| Backup of every server, laptop and mailbox | Included | Included | Included | Included |
| Managed detection and response on every device | Included | Included | Included | Included |
| Multi-factor authentication across all five access points | Included | Included | Included | Included |
| Email filtering and security awareness training | Not included | Included | Not included | Included |
| Patch management to a stated target | Not included | Included | Not included | Included |
| Proof | ||||
| Dated monthly evidence pack for your records | Included | Included | Included | Included |
| Quarterly restore test, documented | Included | Included | Included | Included |
| Quarterly privileged access and patch compliance report | Included | Included | Included | Included |
| Cyber insurance application support, from records | Included | Included | Included | Included |
| Day-to-day IT | ||||
| Helpdesk for your staff | Not included | Included | Not included | Included |
| New starters, leavers and device setup | Not included | Included | Not included | Included |
| Remediation and hardening hours included each month | Not included | 2 hrs | Not included | 2 hrs |
| Regulation S-P compliance program | ||||
| Written incident response program, reviewed annually | Not included | Not included | Included | Included |
| Client notification decision file, including reasons not to notify | Not included | Not included | Included | Included |
| Vendor inventory, due diligence and 72-hour notice terms | Not included | Not included | Included | Included |
| Annual tabletop exercise with written after-action report | Not included | Not included | Included | Included |
| Records schedule and examiner-ready document pack | Not included | Not included | Included | Included |
Getting started: deployment and a first verified restore is a one time $9,500. The compliance program build is a one time $12,500, required once on the two plans that include it. Bespoke work for a principal is scoped separately, after a confidential assessment.
Your insurance application, control by control
Must have
One carrier's own bind-condition sheet marks controls of this kind as required before it will bind coverage. These are the ones that stop a deal.
Changes the price
You can get a policy without it, but it costs more, or you get lower limits.
On the form
They ask, and the answer goes on file, but on its own it rarely stops anything.
| What the application asks | Monitor | Managed IT | Monitor + Comply | Complete |
|---|---|---|---|---|
| Must have | ||||
| Two-step login (MFA) on email | Covered | Covered | Covered | Covered |
| Two-step login on any way in from outside the office | Covered | Covered | Covered | Covered |
| Security software on every laptop and server | Covered | Covered | Covered | Covered |
| Backups an attacker cannot reach or overwrite, and proven to restore | Covered | Covered | Covered | Covered |
| Calling to confirm a payment before you send it, and a second person approving large onesA must-have for the part of the policy that covers being tricked into sending money, rather than for the policy as a whole. | Covered | Covered | Covered | Covered |
| Changes the price | ||||
| Two-step login on the accounts that can change everything, and on the backup system | Covered | Covered | Covered | Covered |
| What share of devices are covered, and whether the software cuts an infected one off the network by itself | Covered | Covered | Covered | Covered |
| Backups kept apart from the day-to-day network, so one break-in cannot take both | Covered | Covered | Covered | Covered |
| Someone has actually restored a file from backup and written down that it worked | Covered | Covered | Covered | Covered |
| Email screened before it arrives, and attachments opened somewhere safe first | Not covered | Covered | Not covered | Covered |
| How fast you install urgent security updates, and how often you hit that target | Not covered | Covered | Not covered | Covered |
| How many accounts can change anything, and why each one needs to | Covered | Covered | Covered | Covered |
| How long your logs are kept, and whether they survive the machine that produced themThe reconstruction row. Logs that died with the laptop are the usual reason nobody can say what happened. | Covered | Covered | Covered | Covered |
| On the form | ||||
| Software the maker has stopped fixing, still in use | Covered | Covered | Covered | Covered |
| Staff training, and test phishing emails sent to see who clicks | Not covered | Covered | Not covered | Covered |
| A written plan for a break-in, rehearsed once a year | Not covered | Not covered | Covered | Covered |
| Checking the outside companies that touch your client data | Not covered | Not covered | Covered | Covered |
| Whether administrator access, new devices and bypass codes are written down as they changeThe second reconstruction row, produced by the quarterly access exception review. It is the record that answers who could have done this. | Covered | Covered | Covered | Covered |
These are questions from real insurance applications. Where a plan does not cover something, we say so here rather than let you find out on the form.
What we do, and how often
Every month
- Control drift reviewProduces: A triaged, recorded list of what stopped reporting and what was escalated
- Backup verificationProduces: Confirmation that every server, laptop and mailbox is backed up
- Evidence packProduces: A dated snapshot of every device and user, filed to your archive
Every quarter
- Restore testProduces: A written result for a real file set restored from backup
- Patch compliance reportProduces: Performance against a stated target, with the rolling twelve-month rate
- Access exception reviewProduces: A record of new devices, bypass codes and administrator accounts
- Report to the person who owns this for the familyProduces: One page: what changed, what lapsed, what needs a decision
Every year
- Privileged account reviewProduces: Every administrator account listed with a written reason it still exists
- End-of-life inventoryProduces: A written statement of what protects anything the maker no longer supports
- Insurance evidence packProduces: The control sections of your application or renewal, supported by dated records
What is included, what is not, and what stays yours
We do
- Configure, monitor and maintain every product in your plan
- The monthly, quarterly and annual work in the service calendar above
- Deliver a dated evidence pack to your archive every month
- Retain and preserve the logs and records that let an incident be reconstructed afterward
- Produce the dated record of what your payment verification procedure did, so it can be shown rather than recalled
- Keep chain of custody on anything we examine, to the standard a court applies
- Support one insurance application or renewal each year
- Escalate anything we find, with a written record
- On Managed IT and Complete: helpdesk, new starters and leavers, device setup, and two hours of remediation and hardening every month
We do not
- Helpdesk on the two Monitor plans, which stays with your own IT
- Incident response and forensics inside the monthly fee, which is billed separately
- Buying or owning your hardware, software licenses, phones or cabling
- Legal, regulatory, tax or insurance advice
- Writing or sending your breach notifications
- Acting as the family's principal-facing security lead, or standing in for that person
- Physical security, executive protection and travel logistics, which we coordinate with rather than provide
- Work on site or outside business hours, except by arrangement
You do
- Name a primary and a backup technical contact, and tell us if that changes
- Respond within four business hours when we escalate something urgent
- Adopt the policies we prepare, with your counsel
- Own the accuracy of anything you file with a regulator, a bank or an insurer
- Tell us before you add people, residences, entities, systems or vendors
- Keep your own IT resource in place on the Monitor plans, or tell us if that ends
Written plainly here so nothing is a surprise in month three. The agreement carries the same boundaries in full.
Device compromise and spyware concerns for principals
The question principals and their family offices bring us is quiet and specific: is the principal’s phone compromised, and who else can see what it sees?
The concern is well-founded.
In Deloitte Private’s Family Office Cybersecurity Report 2024, 43% of family offices globally reported experiencing a cyberattack within the last 12–24 months, and nearly one-third (31%) had no cyber incident response plan.
A principal’s device sits at the intersection of both numbers: it is the highest-value target in the household, and often the least governed.
The forensic questions are the ones we answer in our casework for any monitored device, applied to a principal’s threat model.
When a phone behaves strangely, or a family member or household staffer reports something that does not sit right, we examine the device with the owner’s authorization, check it against published indicators of compromise, and document what is and is not present.
Consumer monitoring tools and targeted commercial spyware are different problems with different checks: our guide to Stalkerware Detection and Removal covers the first, and Is Someone Monitoring My Phone? walks the self-checks a principal or family member can run safely before any examination.
Where the findings may matter legally, in a divorce, a dispute with former staff, or litigation, the examination is run to evidence standards from the start; see Private Digital Forensics for Individuals.
The honest limit applies at this level of the market too: a finding of “no known indicators of compromise” is not proof a device is clean, and we say so.
What the engagement produces is a documented, defensible answer, an incident-response path if something is found, and a hardening plan so the family is not relying on luck the next time.
How an engagement begins
- Confidential consultation. NDA-protected. 30-60 minutes. Direct conversation, no sales process.
- Scoped engagement. Written proposal with defined deliverables and pricing, a fixed fee where it applies and hourly with milestone caps for open-ended investigations.
- Investigation and findings. Court-admissible standards. Written report you can act on.
Rates, growth and the small print
Project and hourly rates
| Work | Standard | On a plan |
|---|---|---|
| Remediation beyond the included allowance | $400/hr | $195/hr |
| Security consulting, assessment and hardening | $400/hr | $275/hr |
| Incident response, containment and rebuild | $400/hr | $275/hr |
| Forensic examination and written report | $400/hr | $325/hr |
| Deposition and trial testimony, four-hour minimum | $400/hr | $400/hr Same as the standard rate. |
| Done-for-you device forensics | from $2,000 | from $2,000 Same as the standard rate. |
| Refundable engagement retainer | $5,000 | Waived |
All rates per hour unless stated. There is no surge for nights, weekends or holidays, on either column. Court time is never discounted, because the hour is the same hour whoever is paying for it.
As your firm grows
Additional named user
$35/mo
Additional workstation
$5/mo
Additional server
$70/mo
New user setup
$150
User departure and offboarding
$100
New device deployment
$200
Term
Twelve months, billed either monthly or as a year paid in advance, renewing unless either of us gives 60 days' notice.
Your data
Your tenants are yours. On exit we return your records in a usable format within 30 days and certify what we destroyed.
Confidentiality
Every person who touches your data signs the confidentiality agreement before they touch it, and we tell you within 72 hours of becoming aware of a breach affecting a system holding your information.
Insurance
We recommend you carry cyber cover and we supply the control evidence to your broker. We are not licensed in insurance and give no insurance advice.
Why this work matters
Family office cybersecurity is different: the attack surface is the principal, the household, and everyone with access to both.
Quinn holds 9 active certifications across GIAC, a methodology trusted by Fortune 50 enterprises, defense contractors, and the attorneys who refer to us.
















