Astris CSP
Briefing No. 08 · Family Offices · Resilience · 2026
83%

Your attack surface is your providers, not just your office

16 July 2026 · By David Evans

Ransomware is no longer waiting for a human to run it. Check Point Research documented JadePuffer this month — an autonomous ransomware operation that used a large language model to conduct an intrusion from initial access to execution without direct human control. For an office running a lean team and relying on providers to fill security gaps, the asymmetry just widened: no shift handoffs, no operator delays between reconnaissance and payload delivery. Check Point Research

Supply chain: the Deutsche Bank incident

On 4 July, the ransomware group Unsafe claimed to have breached Deutsche Bank through a third-party supplier, posting what appeared to be database extracts including employee email addresses, password hashes, and internal records. Deutsche Bank confirmed a supplier incident was under investigation but disputed the extent of the breach. Cybernews · Computing

Unsafe specifically targets financial institutions in Switzerland, Germany, France, and the US. For a family office principal, what happened inside Deutsche Bank’s own systems matters less than the pattern: a disputed breach claim buys weeks of operational uncertainty, and your custodian or administrator is exposed to the same kind of supplier hit. If that provider sits in your payment chain, the disruption reaches you regardless of your own controls.

London: a concrete compliance deadline is approaching

In March, the FCA published PS26/2 introducing unified rules for operational incident and third-party reporting. Regulated firms have until 18 March 2027 to document their critical third-party dependencies and report serious incidents through a new unified portal. Global Regulation Tomorrow

Family offices sit outside the FCA perimeter, but their custodians, administrators and platforms do not. As those firms build Critical Third Party registers and tighten their own supplier reviews, they will start asking the same questions of you. An office that can already account for its provider dependencies and recovery steps handles that easily. An office that can’t will spend real time reconstructing it under a deadline.

Switzerland: the resilience standard has shifted

FINMA’s June 2026 guidance on cyber risk management formally describes the move from prevention to measurable resilience as the new supervisory standard, with supply chain incidents identified as the primary threat vector. A single annual tabletop exercise is no longer evidence of readiness. FINMA

For Swiss-domiciled structures, auditors and relationship managers used to ask whether you had been attacked. Now they ask whether you can show you would recover, and they expect documented, tested recovery scenarios as the answer. That is a fair thing to be asked: being attacked is largely outside your control, but having a recovery plan on paper is not.

Caribbean: voice authorisation is no longer reliable

Deepfake voice cloning now requires three seconds of audio. Convincing video deepfakes cost under ten dollars per campaign. Ocorian’s 2026 survey of 200 family office professionals found 83% are concerned about impersonation attacks, yet only 60% are confident their staff could identify one in real time, below the 69% industry average. Ocorian

In Caribbean structures such as Cayman, Bermuda and the BVI, short decision chains can authorise large transfers on a single call. That makes voice recognition a weak control, and it means out-of-band confirmation for payment instructions is now the minimum standard. If your process hasn’t been reviewed since last year, start there.

Most of this points the same way. The FCA’s downstream review cycle is open, FINMA has raised its recovery standard, and autonomous tooling has closed much of the timing gap defenders used to rely on. None of the work involved is heavy, but it is worth doing ahead of the next review rather than during it.

← Briefings & journal