A study by Ocorian has highlighted a need for family offices – private firms managing the wealth of high-net-worth families – to ensure they have the necessary precautions and defences in place amid the “increasing reality” that they could face a cyber security attack.
Family offices based in the UK, Switzerland, Mauritius, South Africa, India, Hong Kong, Singapore, Taiwan, UAE, Saudi Arabia, Bahrain, US, Jersey, Guernsey, Bermuda and Cayman were surveyed as part of the research.
Outlining the findings of its study among family members and senior family office employees – handling total wealth of $119.37 billion – Ocorian noted that almost a fifth (19%) did not have any defence plans in place to protect themselves from a potential cyber attack, though 18% said that they did plan to put one in place.
Three-quarters of respondents had taken steps to strengthen their defences in the past two years. However, just 7% said they had plans in place more than two years ago.
While many are taking steps to put the necessary precautions and defences in place, such as getting expert third-party advice, there are still too many who are highly susceptible
Ian Rumens, Head of Private Client – Jersey, at Ocorian
Additionally, more than a fifth (22%) of those surveyed reported that they did not have an incident plan in place to respond and recover in the event that they suffered a cyber attack.
Ian Rumens, an executive director in Ocorian’s Jersey private client team, said that cyber security attacks were becoming “an increasing reality”.
He warned that they can have “huge implications” for family offices, including “damaging reputations, triggering loss of stakeholder confidence and putting long-term relationships at risk”.
Mr Rumens continued: “While many are taking steps to put the necessary precautions and defences in place, such as getting expert third-party advice, there are still too many who are highly susceptible.
“The financial impact can also be significant, from direct theft and fraud to business interruption, incident response costs, regulatory fines and potential litigation.
“It’s also vital that family offices work closely with all their service providers and suppliers to make sure those partners have the right protections in place too, helping reduce the risk of a cyber incident spreading through the wider ecosystem.”
Mr Rumens added that organisations should also seek to ensure they have regularly tested strong backup and recovery arrangements to help protect against data loss or corruption.
He pointed out that those who did not – and had no incident plan in place – could take “much longer to respond and recover afterwards”.
