Frequently Asked Questions

Confidentiality and discretion

How do you keep our family’s affairs private?

Access is limited to the people doing the work, under a non-disclosure agreement and with a written record of what was accessed. Client data is encrypted, with keys held so that our staff cannot read client files. We publish no client names, use no client logos, and do not reference engagements in marketing. If discretion matters more than any other factor, say so at the start and we will scope the work around it.

How do you stop insider threats?

Access is limited to what a role actually needs and reviewed when roles change. Privileged actions are logged to records that cannot be quietly altered. Unusual patterns are flagged for review by a person, not acted on automatically, because the cost of a false accusation inside a family office is high. When something needs investigating, it is handled discreetly and with your counsel involved from the start.

How is attorney-client privilege kept online?

Client matters are separated so that access follows matter assignment, not job title. Material is encrypted, keys are held so that we cannot read it, and every access is recorded. Communication with clients and counsel runs over end-to-end encrypted channels rather than ordinary email. Where a firm has ethical wall requirements, we implement them technically rather than by policy alone.

What about household staff and vendors?

Staff and vendors get access appropriate to their role, on their own accounts, with confidentiality terms in their contracts and short practical training rather than a policy document. Vendor access is reviewed on a schedule, and removed when an engagement ends, which is the step most often missed.

Governance, compliance and regulators

What does my board or family council actually get?

A board sees three things: the assessment, with risks ranked and tied to the assets they affect; a report each quarter showing what was closed, what remains, and what changed; and dashboards quantifying breach cost avoided and continuity improvements, where you want those figures. We are direct about what such estimates are: models built on your own numbers and published breach data, useful for comparing options rather than predicting a loss.

How does this help with my fiduciary exposure?

By making oversight demonstrable. Privileged actions are logged with timestamps, access to client material is recorded, security settings are enforced and re-checked automatically, and reviews are written up in a form a trustee or auditor can read. That does not remove liability, but it answers the question a court or regulator asks first: what did you have in place, and how do you know it was working?

Can you help show regulators we’re compliant?

We can produce the evidence: control documentation, access and change records, backup and restore results, incident reports, and a mapping of your controls to the framework you are measured against, whether that is GDPR, another national data-protection regime, or sector rules that apply to you. We are not a law firm and do not certify compliance; the assessment of whether you meet an obligation stays with your counsel and, where relevant, your auditor.

How are global operations protected?

Insight maps where data actually goes, including the transfers nobody documented. Revive puts storage in the locations you have chosen and restricts what may move between them. Fortify then monitors continuously regardless of time zone, so a weekend in one region is still covered.

We move data across borders. How is it kept safe?

Transfers are encrypted in transit, restricted to the systems and regions you approve, and logged. Where a jurisdiction requires data to stay in place, the storage is configured so that it cannot move, which is more reliable than asking people to remember. The legal basis for each transfer is documented so it can be produced later.

Regulations keep changing. How do you keep up with them?

We monitor regulatory changes in the jurisdictions where you operate and flag the ones that affect your setup, with the specific change we would recommend. What we do not do is claim that software keeps you compliant: the judgment stays with your counsel, and our part is making sure the technical side follows.

What the work covers

Isn’t this just dressed-up IT work?

Ordinary IT support fixes what breaks. The work here is different in three ways: it starts from an assessment of risk rather than a list of tickets, it is delivered by senior people who can talk to trustees and principals as well as engineers, and it produces evidence of oversight that governance can use. If what you need is a service desk, a good managed IT provider will be cheaper and perfectly adequate.

Do you replace my IT team?

No. Where there is an internal team, we work alongside it, usually on the areas it has no time or specialist cover for: security operations, vendor oversight, architecture decisions and preparing for audits. Where there is no internal team, Guardian can be the whole IT function for a small office.

What if my systems are old but essential?

That is the common case, and Revive is built for it. Some systems can be replaced; others have to be contained, which means restricting what can reach them, encrypting what they store, monitoring them closely, and having a tested way to restore them. Either way, the change is staged so each step can be reversed, and nothing is retired until what replaces it works.

Can you advise during case prep or trust structuring?

Yes, on the technology side: secure document handling, encrypted communication with the parties involved, controlled access for experts and co-counsel, and records that stand up if the handling of evidence is questioned. We take no position on the legal strategy itself.

Which frameworks and tools do you work with?

Our practices follow ISO/IEC 27001, the NIST Cybersecurity Framework and CIS Controls. We are vendor-neutral: where a licensed third-party tool is the right answer for monitoring, backup, secure communication or AI, we select it, integrate it, and tell you what it costs. You are not buying a resold platform.

How do you keep alerts from being noisy?

Alerts come to us, not to you. We triage them and contact you when something needs a decision or when you should know. Routine detail stays in the reporting you receive periodically, so the exception is visible rather than buried.

What is your incident-response plan?

There are written playbooks for the incident types you are most exposed to, agreed before anything happens: who is called, in what order, what gets contained first, and what gets preserved for later investigation. During an incident you get short factual updates, not technical noise. Afterwards you get a written account of what happened, what was done, and what changed as a result.

Families, households and private clients

How do you keep us safe from reputation attacks?

Sovereign monitors for your family’s details appearing in breach data, credential markets and impersonating profiles, and we act on what turns up: password resets, takedown requests, and coordination with your legal advisers where content has to be removed. What we cannot do is control what is legitimately published about you; that is a matter for your counsel and communications advisers, and we work alongside them.

How do you protect my family while we travel?

Sovereign covers travel: devices configured for the trip, separate networks and secure connectivity rather than hotel or public Wi-Fi, reduced data on the devices that travel, and a number to call in a different time zone. For sensitive trips we prepare in advance and check the devices again on return.

How do you reduce what is publicly available about us?

We inventory what is publicly available about the family and household, submit removal requests to data brokers and search services, tighten the settings on the accounts you keep, and then monitor for new appearances. Reduction is achievable and worth doing; complete removal is not, and any provider promising it is overstating.

How do you involve the next generation?

Practical sessions rather than lectures: recognizing the approaches aimed at them, handling passwords and devices, understanding what their exposure means for the wider family, and, where they are taking on responsibility, how the governance and records work. Pace and content are agreed with the family.

Engagement and commercials

How can I justify the spend to stakeholders?

Start with Insight. It produces a ranked list of exposures, the cost of dealing with each, and what it would take to leave them as they are. That gives a CFO or board chair a comparison rather than an appeal to fear. Most clients then phase the work, doing containment first and larger change over a longer period.

How fast can you start?

A first conversation can usually happen within a few days, and an Insight assessment typically takes two to four weeks from the point where scope and access are agreed. If you are dealing with a live incident, say so when you contact us: that is handled differently and immediately.

Do you only do one-off jobs or longer partnerships?

Both. Many clients start with Insight as a defined piece of work with no commitment beyond it. From there some take the findings to their own team or provider, and others continue with Revive, Fortify or Guardian. Sovereign and Ark can be arranged on their own.

How is pricing set up?

Project work such as Insight and Revive is a fixed fee for an agreed scope. Ongoing services such as Fortify, Guardian and Sovereign are monthly. Ark combines a project fee with monthly custodial maintenance. The configurator shows indicative starting prices so you can gauge the order of magnitude; the final figure follows a scoping conversation. Licensed third-party software and travel are passed through and shown separately.

What if leadership changes?

Everything is documented so the arrangement does not depend on one person: current configuration, access records, decisions taken and why, and the roadmap. When a principal, executive or trustee changes, we brief the incoming person and re-confirm who is authorized to instruct us.

Can you promise no breaches?

No, and you should be wary of anyone who does. What we commit to is reducing the exposure you have, detecting problems early, containing them quietly, having a tested way to recover, and showing you the evidence for each of those. Where we cannot deliver something, we say so rather than covering it with a service description.