
IT security for family offices
A small team, large assets, no IT staff and payment approvals under time pressure. Where we start in family offices.
The situation
Swiss single family offices run very small core teams. In the 2026 survey by SFOA, UBS and the University of St. Gallen, 61 percent run a team of one to five people, and specialist work is deliberately given to outside partners.
On security for the family and the premises, 56 percent offer nothing at all. It is the least covered service in the whole catalogue. At the same time this small team manages very large assets and holds a family's most confidential documents.
The most expensive point of attack is not the technology, it is the approval. Mail and phone without a binding call-back rule are the most common way in. In the FBI IC3 2025 annual report, business email compromise was the second costliest fraud category overall, with around USD 3 billion in reported losses.
And the damage is rarely technical. It comes from publicity and lost trust. Discretion is the actual value in this business, and it is rarely written down anywhere as something that is protected.
What we find in this industry
- No IT team, distributed infrastructureSystems, service providers, private devices and second residences belong to the same risk picture but to no shared responsibility. Nobody has the full view because nobody owns it.
- Payment approvals under time pressureMail and phone without a binding call-back rule are the most common point of attack. The urgency is not a coincidence, it is part of the attack.
- External providers hold the most confidential documentsFiduciary, legal, IT and administration work with everything. A structured review of those partners rarely happens, even though they are the largest way in.
- Private and business life blurFamily members, assistants and household staff use the same channels as the office. A separation usually exists only in theory.
- There is no plan for the serious caseWho decides, who is informed and who calls the bank tends to be settled during the incident. By then there is no time, and that is exactly where the damage happens.
- Discretion is the actual valueThe damage is rarely technical. It comes from publicity and lost trust, and it cannot be bought back with insurance.
Typical trigger
An attempted fraud on a payment, or a family asking how things stand after an incident in their circle.
The ODCUS difference
No selling of additional tools. The first step is always: what do you already have, what of it works, and what can we cut? Most mandates start by reducing cost and improving protection at the same time.
Why these services fit
Security responsibility without creating a position
Family offices give specialist work to outside partners anyway. Security is exactly that kind of work: too important to do on the side, too small for a dedicated role.
We take it on as a mandate, with one fixed point of contact and no rotating faces.
Know where the family office really stands
We review systems, processes and payment approvals and derive a prioritised plan, sized for a lean structure.
Carried out discreetly, with a result the family understands, not only the IT provider.
Payment processes and providers under control
We establish approvals with a binding call-back rule, vet the external partners and keep the incident plan current.
This is the part that prevents the most frequent and most expensive damage, and it costs less than any technology.
For the personal protection of private individuals and their families we run a separate, discreet offering under Digital Shield.
Who it is for
- Single and multi family offices with a small core team
- Structures without their own IT staff and with several external providers
- Offices where payment approvals run over mail and phone
- Families who want a review after an incident in their circle
Related engagements
- Ransomware recovery after full encryption
- Hardening a Microsoft 365 tenant including device management
- Privileged Identity and Access Management with Entra ID
Anonymised looks at real engagements. Not all of them come from this industry, but the task is the same.
FAQ
There are three of us and we have no IT. Is that not too small for this?
The opposite. The smaller the team, the less capacity there is to learn this on the side. The scope follows the structure, not the assets under management.
What is the single most effective measure?
A binding call-back rule for payment approvals, to a pre-registered number, with the clear rule that urgency is never a reason to skip it. It costs no licence and prevents the most common large loss.
How discreet is such a mandate?
You work with the same person throughout, with no handover to third parties and no external naming. We pass on references only with explicit consent.
Do you also cover the family's private sphere?
For the personal protection of private individuals and their families we run a separate, discreet offering under Digital Shield. The family office itself is what we look after here.
Let us talk about your situation
Thirty minutes, free and without obligation. We tell you honestly whether and where we can help.

