A family office's security responsibility does not begin when somebody approaches the gate. Increasingly the threat never approaches the gate at all. It is already communicating with the principal every day, through a phone, a laptop or a social media account — and the gate, the camera and the officer are all facing the wrong direction.
Both of the cases below were handed to me by a family office. Neither involved a perimeter. Both could have ended in a substantial loss, and one of them could have ended somewhere considerably worse than money.
A real photograph does not mean you are dealing with a real identity.The relationship that was not a person
A family office contacted me about one of its principals — an elderly woman living alone who had formed what she believed was a romantic relationship with a man she met through social media. Over time the relationship had become increasingly important to her. She was also sending him substantial sums of money.
At first glance he was convincing. The photographs were real. The man in the photographs was real — an attractive, adventurous man in his fifties, apparently living in South America. There was one problem. He had nothing whatsoever to do with the relationship. His identity had been stolen.
As the work went on, I found photographs of that same man being used across eight separate fraudulent identities. The real man appeared to have no idea any of it was happening.
The principal had assembled what looked like considerable proof of legitimacy — passports, addresses, employment information, places of work, official-looking documents. It was convincing until it was verified. The passports were fraudulent. The addresses did not check out. The employment history was false. The supporting documents were fabricated.
The activity traced not to the sophisticated middle-aged adventurer being portrayed online, but to someone roughly twenty years old, in a country in West Africa. The identity was a constructed front. Once the findings were presented to the family office and the principal, the communication stopped.
Why is a romance scam a security problem and not just a financial one?
Because the money is rarely the largest exposure. Once trust is established, a principal may begin sharing things that are worth far more to the wrong person than a transfer:
- Personal and family information
- Private photographs
- Financial details
- Travel schedules
- Personal vulnerabilities
- Names of employees
- Information about residences
That material can be used for manipulation, blackmail or extortion — or to enable a physical threat. For a prominent or ultra-high-net-worth family, a digital relationship becomes a physical security problem. Which is why I do not treat these as private matters that happen to involve money. They are part of the family's risk environment.
The structure of these schemes is consistent. They are not built around an immediate request for funds. They are built around emotional attachment, and around a reason why ordinary verification is always difficult. He is working offshore. He is somewhere remote. Communication is limited. The details vary; the purpose does not — establish the relationship while keeping independent verification out of reach.
The investment that was too good to be true
A second case, different shape, same lesson. A principal had been introduced to an entity offering an unusual investment involving a particular currency and financial instrument. The projected return was extraordinary — in the region of forty to fifty per cent or more on each dollar. He was considering not only investing himself, but bringing in family members and close friends, on the reasoning that a larger total investment would produce a proportionally larger return.
Before any commitment, I was asked to look into it. What followed was several weeks of research, inquiry and verification across multiple jurisdictions — the United States, the Caribbean, and two European countries. The conclusion was that the proposed investment was a scam. I gave the principal the documentation, and he decided not to proceed.
The financial loss would have been considerable. But had he brought in family and friends first, the damage would not have stopped at money. It would have reached the relationships of people who trusted his judgment — which is the harder thing to repair.
The red flags in that work are the usual ones, and they recur: questionable entities, unusual corporate structures, offshore relationships, unverifiable principals, inconsistent documentation, unrealistic returns, and arrangements complicated enough to make scrutiny feel impolite. Once funds have moved through offshore entities and multiple jurisdictions, recovery is extremely difficult. Which is the entire argument for doing the work beforehand.
Identify. Verify. Assess. Then advise.
My role is not to tell a principal whom to date, trust, befriend or do business with. It is to establish who they are actually dealing with, what they are actually being offered, and what may sit behind it — and then to hand them facts so they can decide for themselves. The cost of finding out is almost always insignificant against the cost of finding out too late.
What should trigger due diligence in a family office?
A program should name these in advance, so that raising one is procedure rather than an accusation against someone the principal likes:
- A new relationship involving substantial or recurring financial activity
- Any request for money, in any framing
- An investment opportunity introduced socially, or one whose returns are unusual
- A new party gaining access to sensitive family information
- Persistent reasons why ordinary verification is impossible
- Pressure to decide quickly, or to keep the matter private from advisors
It does not matter how sophisticated the presentation is, or who made the introduction. If an opportunity appears too good to be true, that is precisely the moment to examine it.
What a family office program has to cover
Both of these cases sat outside what most people picture when they think about security, and inside what a program is supposed to cover. A complete program reaches across all of it:
- Routines — how predictable the family's movements are
- Residences — access, credentials, and who still holds them
- Travel — advance work, and what happens to the itinerary afterward
- Digital footprint — what a stranger can assemble, and who is speaking to the principal
- Household staff — re-vetting the people already inside
- Corporate staff — where company exposure reaches the family
- Existing vendors — and where one scope ends and the next begins
Most families I am asked to look at have competent providers across several of these and nobody accountable for the connections between them. That gap is where both of these cases lived.
Related reading: what a security risk assessment examines, and security consulting versus guard services.