Every organization that experiences a cybersecurity incident, no matter how big or small, has an opportunity to come out materially stronger if they use the incident to build intelligence and be better prepared for the next one. Don’t be scared, be prepared.
Don’t Be Afraid to Get Into It
When a family office identifies a cybersecurity incident, a common reaction is to contain the damage by bringing in experts to resolve the incident and navigate the disclosures. After the initial impact and resolution, it’s expected that leaders and principals are left feeling deeply vulnerable and wanting to put the incident behind them. This reaction is understandable, but flawed if it means they miss the opportunity to learn from the incident and better defend themselves from the next attack.
Bitsight’s threat intelligence research found that the most resilient organizations are those that effectively transform any incident into actionable intelligence. Organizations that adopt structured post-incident processes recover faster, minimize operational and reputational damage, and are significantly less likely to experience a repeat compromise. The incident is not the worst thing that can happen; failing to learn from it is.
The Mercer Advisors breach, the Pathstone exposure, and the Beacon Pointe incident, detailed in a previous issue of this Briefing, share a characteristic beyond the attack itself: each left behind a public record, a legal proceeding, and an implicit question about what the organization knew, when it knew it, and what it did next. The organizations that come out of incidents like these with stronger programs, clearer policies, and documented evidence of remediation are in a materially different position than those that simply closed the incident ticket. SFOs have the same opportunity.
The Opportunity of Incidents
Three things become visible as a result of a cybersecurity incident that otherwise would be difficult, if not impossible, to ascertain: the entry point, the dwell time, and the detection gap.
The Entry Point. How the attacker got in, and the human and process conditions that made it possible. In most family office breaches, the entry point involves a combination of a technical gap and a procedural one:
An MFA configuration that was never updated;
a vendor connection that no one knew was active;
a phishing email that landed because it looked authentic and staff did not recognize it.
The entry point is a direct map to the gap(s) that most needed addressing.
The Dwell Time. How long the attacker was inside before it was discovered. In the 2025 and 2026 family office breaches, dwell times ranged from hours to weeks. The gap between compromise and detection is a direct measure of the organization’s detection capabilities. Most family offices lack dedicated security monitoring and can have much longer dwell times than they realize. Long dwell times can be frightening to consider but they can also be instructive in signaling whether investment in monitoring and other awareness tools is warranted.
The Detection Gap. How the incident was discovered. A vendor notification, client complaint, an extortion demand, a routine review - each of these can help determine whether the organization has any real ability to detect future incidents or whether it will always be learning about breaches from external parties. Most family offices learn about incidents the wrong way but that awareness can lead to taking action to fix it.
The Post-Incident Review
Lead with Curiosity. The purpose of the post-incident review is not to place blame but rather to more accurately understand what happened and how it can be prevented in the future. The best practice is a structured post-incident review within 24 to 72 hours of resolving an incident, while details are fresh in people’s minds.

The answer to the sixth question, what single change would have had the greatest impact, is usually the one the organization most needed to hear before the incident - yet couldn’t hear without it.
What Incidents Typically Reveal in Family Offices

MFA was absent or incomplete. The Mercer class-action specifically alleges the firm lacked multi-factor authentication on systems containing 5.7 million records. Deloitte’s 2026 family business cybersecurity report found that only 57% of family businesses have implemented MFA. An incident that exploits a missing MFA requirement reveals exactly where to start.
Vendor and third-party access was unmapped. In the Family Wealth Report’s 2026 Cybersecurity Forum analysis, the most common finding from breached organizations was that a connected application had access to client records, estate documents, and family correspondence that nobody knew needed to be managed. The Drift/Salesloft supply chain breach reached over 700 organizations through a single vendor integration. An incident surfaces every connection that was invisible before.
No incident response plan existed. Less than 40% of family offices have incident response plans in place. When an incident hits an organization without a plan, the first hours are spent deciding who is in charge rather than containing the damage. An incident without a plan is its own demonstration of what having a plan would have been worth.
Staff awareness had not been tested under realistic conditions. Ideally, family offices will develop an incident response plan and train staff to that plan. However, most training, where it exists, is tailored to general practices, not to a bespoke plan. An incident reveals the gap between what staff were trained to recognize and what they actually encountered. Even with increasing incidents and growing threats, only 17% of family offices plan to prioritize awareness training in 2026.
Haven’t Had an Incident Yet? Practice Now
The lessons a crisis teaches can be learned without the crisis, but only if the organization is willing to deliberately manufacture the future discomfort.
A tabletop exercise presents a realistic scenario (maybe starting with a vishing call leading to a credential compromise) and walks the team through what they would actually do. The exercise surfaces the same gaps an incident would reveal:
No one knows who to call
The vendor relationship is unclear
The principal’s role in the response is not defined
The notification obligation is unfamiliar
Working through this process proactively allows teams to surface questions and identify gaps that can be addressed and documented before an incident occurs.
The secondary value of the exercise is that it forces the conversation, giving the principal a better understanding of what is actually at risk, and helping teams learn whether their response instincts are right.
With 63% of family offices experiencing a cybersecurity incident in the past two years incurring median losses of $830,000 per event, those that come out of the next incident materially stronger will be the ones that either learned from a previous incident or put in the work to simulate one first.
What We’re Watching
For registered investment advisers, the SEC’s updated Regulation S-P rules, which took effect for large RIAs in December 2025, require client notification within 30 days of a breach. That notification creates a public record. A well-conducted post-incident review is not only an improvement exercise, it can be the beginning of a legal defense. An organization that can document what it knew, what it did, how it remediated, and what it changed is in a fundamentally different position in a subsequent proceeding than one that cannot. The standard being established in the Mercer litigation is one that other family offices will be measured against. It is also likely to produce a ruling on what constitutes adequate cybersecurity for a firm managing assets at that scale. Whatever standard the court establishes will inform how other wealth management firms are evaluated in subsequent proceedings. For RIAs and other wealth managers, the documentation of your incident response, your post-incident review, your remediation, and your ongoing training program is now part of your legal posture, not just your security posture.
Our Family Office AI survey is coming this summer. Stay tuned!
Our TCF Insights Series, a 3-part discussion of our 2025 State of Family Office Cybersecurity survey report and findings, concluded June 17. The session recordings are available here. Enjoy!
Start a conversation with us about where your family office stands on its cybersecurity program.

