Illustrative sample only. Fictional household. Abbreviated findings. Not a real assessment — and never a substitute for a principal-led engagement.

Request private proposal Engagement overview
TargetProof
Confidential · Client private
Sanctuary Framework · SN001

Family Threat Model Report

NIST CSF 2.0 household-applied · One integrated picture of posture across people, institutions, and lifestyle.

Household
Northridge Family Office
Assessment date
Illustrative · 2026
Assessor
Thomas M. Stone, Principal
Custody
Client retains model · TargetProof keeps no copy
01 · Executive brief

Where you stand

62%
Maturity
148/156
Controls scored
19
Gaps
34
Partial

Northridge presents as a sophisticated household with strong counsel relationships and modern estate systems — yet several high-value surfaces remain outside coordinated control: wire authority, household staff access, multi-property networks, and the principal’s personal device stack.

Top risks (plain language)

  • Business-email-compromise style diversion of high-value wires remains plausible without dual-control discipline.
  • Estate integrator and IoT access paths are broader than the family office assumes.
  • Personal devices and cloud accounts for the principal sit outside enterprise-grade MFA and recovery controls.
  • Public and philanthropic visibility enables targeted social engineering of staff and family.
  • No single living playbook ties cyber, physical, and human response when something goes wrong.

Residual risk stance (illustrative): Accept residual risk on low-impact lifestyle systems after roadmap execution; do not accept residual risk on wire, identity, or principal account recovery until high-priority gaps are closed.

02 · Scope & context

What we assessed

One-day principal-led onsite engagement across the primary residence and agreed family-office touchpoints. Intake structured before scoring.

In scope (illustrative)

  • Primary residence (Atlanta metro) · guest house · home office
  • Family office coordination surface (finance, EA, outside counsel liaison)
  • Principal + spouse devices and primary cloud identities
  • Household staff access patterns (not full HR review)
  • Known travel profile and public philanthropy calendar (high level)

Out of scope this cycle

  • Secondary residences (flagged for follow-on probes)
  • Operating company IT environments
  • Full OSINT deep-dive (recommended as SN002 if prioritized)
03 · Threat context

What can go wrong here

Spectrum themes highlighted from intake — not a generic scare list. Themes are illustrative and abbreviated for this sample.

  • Wire & payment diversion — vendor change, real-estate close, philanthropic pledges
  • Impersonation of counsel / family — email, SMS, and deepfake voice risk to staff
  • Device & account takeover — SIM, recovery email, password reuse on principal stack
  • Integrator & IoT path — cameras, HVAC, access systems with shared credentials
  • OSINT-enabled targeting — public events, giving, property records

Each theme maps to Govern → Recover controls scored during the onsite day.

04 · Maturity by function

NIST CSF 2.0 · household view

Weighted maturity across Govern through Recover after scoring (illustrative percentages).

Govern
58%
Identify
64%
Protect
71%
Detect
52%
Respond
48%
Recover
55%

Protect is relatively strong (endpoint tools, some MFA). Detect and Respond lag — typical when households buy tools but never rehearse incident roles.

05 · Cross-cut dimensions

People · Institutions · Lifestyle

Adversaries do not respect silos. Every control is tagged across these three lenses.

People

8 gaps · 11 partial · in place

Staff verification rituals incomplete. Principal MFA uneven. Family travel devices weakly covered.

Institutions

6 gaps · 12 partial · in place

Wire dual-control not enforced with banks. Vendor offboarding after FO staff change is ad hoc.

Lifestyle

5 gaps · 11 partial · in place

Event and philanthropy exposure unmonitored. Secondary properties not yet probed.

06 · Priority findings

Risk-ordered gaps

Control IDs shown for traceability. Full statements and verify scripts remain in the private Sanctuary Model — not published in this sample.

ID Finding (abbreviated) Sev Path
GV.RM-xx No written security authority for household/FO decisions; exceptions undocumented. High SN010 Governance
PR.AA-xx Principal financial accounts lack consistent phishing-resistant MFA and recovery ownership. High SN003 Identity
PR.AA-xx Wire change requests accepted without dual-channel verify with known bank contacts. High SN003 / process
ID.AM-xx Incomplete inventory of cameras, access panels, and integrator accounts across estate systems. High SN004 Network & IoT
DE.CM-xx No continuous watch on credential dumps or domain lookalikes for principal brands/entities. Med SN002 / SN008
RS.MA-xx Incident roles exist informally; no 24/7 contact tree or tabletop in last 24 months. Med SN007 Playbooks
PR.AT-xx Household staff training is annual generic video — not role-specific social engineering drills. Med SN005 SE Defense
RC.RP-xx Backups exist for FO files; restore tests for principal cloud identity recovery not evidenced. Med SN011 Recovery

Remediation paths are optional Sanctuary services — selected and sequenced by the family, not automatic upsell.

07 · Remediation roadmap

30 · 90 · 180 days

30 days

Stop the bleed

  • Wire dual-control with banks and FO
  • Phishing-resistant MFA on principal finance & email
  • Integrator credential reset + inventory pass
  • Written security authority (who decides)
90 days

Raise the floor

  • Estate network segmentation plan (SN004)
  • Staff role drills (SN005)
  • Footprint reduction for public surfaces (SN002)
  • Draft crisis contact tree
180 days

Make it durable

  • Tabletop + living playbooks (SN007)
  • Restore tests & recovery proof (SN011)
  • Optional continuous monitoring (SN008)
  • Annual review cycle / stewardship
08 · Review & residual risk

Did we do enough?

The Family Threat Model ends with an explicit review — not an implied “you’re secure.” Residual risk is accepted or deferred in writing by the principal (or designated authority).

  • Accept (illustrative): Lifestyle IoT in guest cottage after inventory and guest VLAN — low impact if segmented.
  • Do not accept yet: Wire authority, principal identity recovery, unmonitored integrator access.
  • Next cycle: Secondary residences; operating company boundary review.

Effectiveness and residual-risk fields live in the private model and are revisited at annual stewardship.

09 · The living model

Report + USB — what you keep

The printed (or PDF) report is the board-ready artifact for counsel and family leadership. The Sanctuary Model on private USB is the living system: encrypted vault, full control scores, threat spectrum, roadmap, and guided assistant — running only on devices you control.

  • Unlock with your vault password · no TargetProof cloud login
  • Update scores as gaps close · re-export backups you hold
  • TargetProof keeps no copy of assessment data unless you separately authorize support access

This web page is an illustrative sample for evaluation only. Your engagement produces a report and model scoped to your household.

Your household. Your report.

One day onsite. A private Family Threat Model Report and Sanctuary Model you keep. Engagements begin with a confidential briefing — private proposal, never a public price list.