Disaster recovery will not get a family office through a cyber incident
Two or three times a year a family office COO asks me a version of the same question. We have backups, the provider tests the failover, we were down for an afternoon last year and it was fine. Are we covered for ransomware? The plan will do part of the job and work against you for the rest of it.
Ocorian’s 2026 report found that 22% of family offices have no incident-response plan at all, and that 43% had been attacked in the past two years. The more common position is worse than having nothing, because it looks like readiness: a disaster recovery arrangement inherited from an IT provider, tested annually, that answers a question nobody is asking. The benchmark numbers are worth reading in full.
What each plan assumes
Disaster recovery rests on one assumption. The infrastructure is sound and you cannot reach it. A hurricane takes Nassau off the grid. A data centre floods. A provider has a regional outage. A laptop dies. Nothing in the environment has turned against you. The data, the accounts and the configuration can all be trusted. Availability is the only thing missing, and the plan exists to restore it.
Cyber recovery starts from the opposite assumption. The infrastructure is reachable and you cannot trust it. Someone else has held access to it, possibly for weeks, and everything inside it is now a question.
In a business email compromise, nothing goes down. Mail flows, files open, the portal works. Somebody has been reading the correspondence long enough to learn how the office authorises a payment, and they intervene on a property completion or an art purchase with amended wire instructions that arrive in the existing thread, on the day the payment was due. Family offices are unusually exposed to this because their payments are large and irregular, which is the pattern that defeats controls built to notice something unusual. There is no outage to recover from and no backup that helps, and it is the most expensive thing likely to happen to the office.
Failover copies the attacker to the second site
The mechanism at the centre of disaster recovery is replication. A second copy of the environment is kept close behind the first so you can move to it quickly. When the problem is a flood, that works.
When the problem is an intruder, replication has been copying the compromise to the secondary site for as long as the intruder has been present. Automated failover then promotes a compromised environment and declares it healthy. The tighter the replication, the more complete the copy. The early instinct in a cyber incident should be to stop replication, and somebody needs the standing authority to make that call at three in the morning without finding a principal first.
The same applies to Microsoft 365, where most family offices actually live. There is no second site to fail to. Deletion and encryption synchronise. Retention and versioning are the recovery mechanism, and an attacker holding global administrator rights can reach the settings that govern both.
You will restore from an older backup than you expect
Disaster recovery measures the amount of data you can afford to lose. The newest restore point wins.
In a cyber incident the newest restore point is the one most likely to contain the attacker. Mandiant’s M-Trends has put global median dwell time in the low tens of days for several years running, and the intrusions that matter most to a family office sit at the long end of that range: quiet credential theft, a hidden mailbox rule copying the CFO’s correspondence, slow reading of a file share ahead of a payment. What you need is the newest known-clean restore point. Establishing which one that is takes forensic work, and it can sit weeks behind the newest copy you hold.
Restore to a point three weeks back and somebody has to reconstruct three weeks of work from custodian statements, bank confirmations and email that has itself been quarantined. A bank puts a team on that. An office of six puts the one person who understands the ledger on it, while that same person is also expected to be managing the incident. Decide now which of them it is.
Attackers also go after the backups themselves. Sophos found that in 94% of ransomware attacks they attempted to compromise the victim’s backups. A backup that the production identity plane can reach and delete sits inside the blast radius. What you need is immutability, and a copy held outside that identity plane. Sophos State of Ransomware, Mandiant M-Trends
The estate includes the family’s own devices and accounts
A bank can draw a boundary around its estate. A family office cannot.
The principal reads office mail on a personal phone. Documents move through a family WhatsApp group. An adult child has access to the shared drive for the property they are buying. Household staff, a PA, aircraft and yacht crew hold credentials to booking and payment systems. Somebody set up the family’s cloud photo storage a decade ago on an account nobody now controls. None of this appears on an asset register, and all of it is a route in and a route out.
Having no boundary widens what an attacker can reach, and it means recovery reaches into the private lives of the people you work for. Resetting the principal’s credentials means asking a principal to hand over a phone. Deciding whether an adult child’s personal account is in scope is a conversation nobody has rehearsed. Have it before the incident, because during one it becomes a family argument conducted under time pressure.
Identity has to be recovered before data
What has to be recovered is the identity plane: Entra ID, privileged accounts, conditional access policies, MFA registrations, live sessions and refresh tokens, mail flow rules, and the service principals and application consents an attacker may have granted themselves on the way in. Restore the data, leave identity untouched, and the attacker still has access to everything you have just brought back. Mass token revocation and a consent review belong in the first hour.
Two things make this harder in a family office. Administrative rights are often held by the outsourced IT provider rather than by anyone at the office, so the first step is reaching a third party who may have been the point of entry. And the office frequently has one global administrator account, shared, with the password in a manager somebody set up years ago. Break-glass access held offline, and actually tested, is rarely in place.
Stolen data cannot be restored
Both plans assume the damage is done to availability. For a family office that assumption is the wrong way round, because the damage that ends relationships is done to privacy.
Extortion has moved steadily away from encryption. Stealing data before encrypting it gave attackers a second lever, and a growing number of groups have since dropped the encryption altogether. Cl0p’s mass campaigns against managed file transfer products took data from hundreds of organisations without encrypting anything. BianLian and Karakurt made theft-only extortion their standard model. Encryption is loud, it triggers detection and it takes effort, while quiet theft produces better leverage against anyone who fears exposure more than downtime.
Few organisations fear exposure more than a family office. What sits in the file share is the family: passports, trust deeds and structure charts, succession plans, divorce papers, medical and school records, property addresses and travel patterns. Discretion is often the main thing the family wanted when the office was formed. You can explain a fortnight of downtime to a principal. There is no explaining publication.
Some of that material creates a physical security problem. Addresses, routines, school details and travel plans in the hands of an extortion group change the family’s exposure in ways a data breach at a bank never does. Anyone advising on kidnap and ransom, residential security or personal protection needs to be in the room for that conversation, and they are almost never on the incident contact list.
No recovery capability touches any of this. You can hold immutable backups, restore to a clean point in an afternoon, and remain fully exposed, because the copy the attacker holds is unaffected by anything you restore. Paying buys a promise of deletion that cannot be verified, and with some groups it raises a sanctions question before a commercial one. The instinct in a family office is to pay and keep it quiet. Say that to principals before it ever comes up.
The controls that help sit earlier. Egress monitoring will notice several gigabytes leaving a mailbox or document library at two in the morning, and alerts on bulk download and unusual external sharing catch most of the rest. The other control is holding less data. Family offices hoard, because no compliance function ever made them stop: forty years of tax filings, files on closed structures, correspondence for people who left the family’s orbit a decade ago, all of it live and searchable. Every year of it adds to what an attacker can threaten to publish.
Rebuilding fast destroys the evidence
Everything in a disaster recovery plan optimises for getting back quickly, and wiping a machine and starting again is a virtue.
Wipe a machine quickly in a cyber incident and you destroy the evidence needed to establish what happened on it. Scoping is what lets you tell the family which of their documents were taken and which were not. Without it every answer becomes “we cannot say”, and “we cannot say” to a principal about their own children’s records is a conversation from which an office does not fully recover.
Preserve first, then rebuild. It adds hours to the restore and saves months afterwards.
Who has to be told, and when
Declaring a disaster is an operational call. The provider invokes the runbook, restores service, and tells you afterwards. Nobody’s obligations changed while it was happening.
A cyber incident starts several clocks at once, and a family office has a different set from a regulated firm.
- The insurer. First, establish whether you have cover at all. Many offices do not, or hold something inside a private client policy that was never read against this. Where cover exists, most policies require notification before you engage anyone, and using your usual IT provider for forensic work can prejudice it. Call the hotline before you call anyone else.
- Counsel. Instructing the forensic firm through counsel is what keeps the resulting report privileged. That decision cannot be made retrospectively, and in a structure spanning several jurisdictions it needs settling once, in advance.
- Data protection. A single-family office may sit outside the SCB and Central Bank perimeter, but it does not sit outside data protection law. The Bahamas Data Protection (Privacy of Personal Information) Act applies. If any family member is resident in the European Union, the GDPR 72-hour clock runs in parallel, and it starts when you become aware, well before you have answers.
- Banks and custodians. These are the deadlines that bite. Your banking and custody relationships carry contractual notice terms, and the counterparty is a regulated institution being told its client has been compromised. Handled badly, this is where accounts get frozen and onboarding elsewhere becomes difficult.
- The family. Which family members are told, by whom, and in what order. Somebody has to decide whether an adult child whose passport was in the file share hears it from the office or from a leak site.
The incident is also often not yours to begin with. The administrator, trustee, custodian or outsourced CIO may be the party compromised, and a family office is usually the smallest client in that chain and the last to be called. A mapped list of which providers touch payments, data and access, with their notification obligations to you written into the engagement terms, is cheap to produce and almost nobody has one.
The incident does not end when service comes back
Disaster recovery ends when service resumes.
In cyber recovery, service resumption is roughly the midpoint. Eviction has to be planned and simultaneous. Rotating credentials one system at a time tells the attacker you have found them and gives them time to re-establish access through a route you have not yet located, so eviction becomes a project with a cutover date. After it come months of heightened monitoring, a rebuilt identity baseline, and in a meaningful proportion of cases a second attempt through the same door.
Where data was taken the tail is longer and outside your control. A leak site runs its countdown on somebody else’s schedule. Stolen files resurface when a group rebrands or a dump is aggregated years afterwards, and each reappearance means another conversation with the family. Plan for months. The theft itself never closes.
What I ask an office to put in place
Keep two plans and one person accountable for both. Merging them produces a document that is wrong about each.
- Out-of-band verification for payments, with a callback to a number held on file rather than one supplied in the request, applied to every payment above a threshold the family sets. It is the control that would have stopped the wire fraud above.
- Backups that are immutable and held outside the production identity plane, with retention longer than plausible dwell time. Ninety days is a floor.
- Break-glass administrative access held offline by the office, not solely by the IT provider, and tested once a year by someone actually logging in.
- A written scope covering which family devices, personal accounts and household staff are inside the plan. Agreed with the family while nothing is happening.
- Egress and bulk-download alerting across mail and document platforms, tuned to volume and timing rather than content. It is most of the early warning you will get for a theft-only attack.
- A retention cull with a date against it. Decades of closed-structure files sitting live add to what can be published.
- An incident contact list that includes counsel, the insurer’s hotline, the forensic firm, the banks, and whoever advises the family on physical security. Printed, and held somewhere other than the system you may lose.
- A decision tree naming who declares an incident, who can stop replication at three in the morning, who speaks to the banks and who speaks to the family. Written while the principal is contactable, because incidents do not wait for someone to come off a boat.
- Test them differently. The disaster recovery test is a failover drill with a stopwatch. The cyber test is an hour around a table starting from “assume our email has been read for six weeks”. Most offices have never run the second one.
That second test takes an hour. Run it before you buy anything else on this list, because it will tell you which of these items you actually need.