Family risk and cybersecurity
AI-enabled cyber risk: authorisation design and operational resilience for family offices
G70 content review draft | Information as at 5 August 2026
When voice, video and email can all be credibly imitated, cybersecurity is no longer only about blocking malware. It is about redesigning how an instruction earns trust.
AI changes the cost and speed of an attack
Generative tools did not create every cyber risk, but they are reducing the time needed for reconnaissance, impersonation and social engineering. Attackers can organise public information, imitate tone, create deepfake audio or video and target several family members and providers at once. The most sensitive exposure for a family office usually lies in the connections between identity, authority, schedules, asset data and payment instructions.
Regulatory data is a warning, not a universal legal rule
In its June 2026 circular, the Securities and Futures Commission cited Hong Kong Computer Emergency Response Team Coordination Centre data showing cyber incidents rising from 12,536 in 2024 to 15,877 in 2025—about 27%. The circular directly applies to licensed corporations, licensed virtual-asset service providers and associated entities, and should not be presented as a legal requirement for every family office. Its principles on vulnerability management, authentication and monitoring are nevertheless relevant to highly sensitive private organisations.
Move from recognising a person to verifying a process
A familiar voice, a face on video or caller ID is not sufficient authorisation in a deepfake environment. Adding a beneficiary, changing bank instructions, resetting multi-factor authentication, exporting large datasets and elevating administrator rights should require separate maker and checker roles, plus confirmation through a pre-registered channel different from the originating message. Good controls assume that one account or one colleague may be compromised, without allowing that compromise to complete a high-impact action.
The attack surface includes every external relationship
Email, cloud storage, accounting, IT support, banking platforms, asset management and communications are often spread across providers. Each connection can extend the movement of data and permissions. Provider due diligence should therefore continue after procurement, covering access rights, subcontracting, incident-notification timeframes, data location and recovery capacity. Access should be withdrawn when the relationship ends.
Resilience must be exercised, not merely documented
Useful testing asks whether the team can suspend access, notify banks, preserve evidence and move to clean systems within an hour of an executive email takeover, deepfake payment request, cloud leak or abnormal trading activity. The use of AI also requires controls: sensitive identity, transaction and asset data should not be entered into public models, while AI connected to mail, files or workflows should have least privilege and auditable records.