Family Threat Model Report
NIST CSF 2.0 household-applied · One integrated picture of posture across people, institutions, and lifestyle.
Where you stand
Northridge presents as a sophisticated household with strong counsel relationships and modern estate systems — yet several high-value surfaces remain outside coordinated control: wire authority, household staff access, multi-property networks, and the principal’s personal device stack.
Top risks (plain language)
- Business-email-compromise style diversion of high-value wires remains plausible without dual-control discipline.
- Estate integrator and IoT access paths are broader than the family office assumes.
- Personal devices and cloud accounts for the principal sit outside enterprise-grade MFA and recovery controls.
- Public and philanthropic visibility enables targeted social engineering of staff and family.
- No single living playbook ties cyber, physical, and human response when something goes wrong.
Residual risk stance (illustrative): Accept residual risk on low-impact lifestyle systems after roadmap execution; do not accept residual risk on wire, identity, or principal account recovery until high-priority gaps are closed.
What we assessed
One-day principal-led onsite engagement across the primary residence and agreed family-office touchpoints. Intake structured before scoring.
In scope (illustrative)
- Primary residence (Atlanta metro) · guest house · home office
- Family office coordination surface (finance, EA, outside counsel liaison)
- Principal + spouse devices and primary cloud identities
- Household staff access patterns (not full HR review)
- Known travel profile and public philanthropy calendar (high level)
Out of scope this cycle
- Secondary residences (flagged for follow-on probes)
- Operating company IT environments
- Full OSINT deep-dive (recommended as SN002 if prioritized)
What can go wrong here
Spectrum themes highlighted from intake — not a generic scare list. Themes are illustrative and abbreviated for this sample.
- Wire & payment diversion — vendor change, real-estate close, philanthropic pledges
- Impersonation of counsel / family — email, SMS, and deepfake voice risk to staff
- Device & account takeover — SIM, recovery email, password reuse on principal stack
- Integrator & IoT path — cameras, HVAC, access systems with shared credentials
- OSINT-enabled targeting — public events, giving, property records
Each theme maps to Govern → Recover controls scored during the onsite day.
NIST CSF 2.0 · household view
Weighted maturity across Govern through Recover after scoring (illustrative percentages).
Protect is relatively strong (endpoint tools, some MFA). Detect and Respond lag — typical when households buy tools but never rehearse incident roles.
People · Institutions · Lifestyle
Adversaries do not respect silos. Every control is tagged across these three lenses.
People
Staff verification rituals incomplete. Principal MFA uneven. Family travel devices weakly covered.
Institutions
Wire dual-control not enforced with banks. Vendor offboarding after FO staff change is ad hoc.
Lifestyle
Event and philanthropy exposure unmonitored. Secondary properties not yet probed.
Risk-ordered gaps
Control IDs shown for traceability. Full statements and verify scripts remain in the private Sanctuary Model — not published in this sample.
| ID | Finding (abbreviated) | Sev | Path |
|---|---|---|---|
| GV.RM-xx | No written security authority for household/FO decisions; exceptions undocumented. | High | SN010 Governance |
| PR.AA-xx | Principal financial accounts lack consistent phishing-resistant MFA and recovery ownership. | High | SN003 Identity |
| PR.AA-xx | Wire change requests accepted without dual-channel verify with known bank contacts. | High | SN003 / process |
| ID.AM-xx | Incomplete inventory of cameras, access panels, and integrator accounts across estate systems. | High | SN004 Network & IoT |
| DE.CM-xx | No continuous watch on credential dumps or domain lookalikes for principal brands/entities. | Med | SN002 / SN008 |
| RS.MA-xx | Incident roles exist informally; no 24/7 contact tree or tabletop in last 24 months. | Med | SN007 Playbooks |
| PR.AT-xx | Household staff training is annual generic video — not role-specific social engineering drills. | Med | SN005 SE Defense |
| RC.RP-xx | Backups exist for FO files; restore tests for principal cloud identity recovery not evidenced. | Med | SN011 Recovery |
Remediation paths are optional Sanctuary services — selected and sequenced by the family, not automatic upsell.
30 · 90 · 180 days
Stop the bleed
- Wire dual-control with banks and FO
- Phishing-resistant MFA on principal finance & email
- Integrator credential reset + inventory pass
- Written security authority (who decides)
Raise the floor
- Estate network segmentation plan (SN004)
- Staff role drills (SN005)
- Footprint reduction for public surfaces (SN002)
- Draft crisis contact tree
Make it durable
- Tabletop + living playbooks (SN007)
- Restore tests & recovery proof (SN011)
- Optional continuous monitoring (SN008)
- Annual review cycle / stewardship
Did we do enough?
The Family Threat Model ends with an explicit review — not an implied “you’re secure.” Residual risk is accepted or deferred in writing by the principal (or designated authority).
- Accept (illustrative): Lifestyle IoT in guest cottage after inventory and guest VLAN — low impact if segmented.
- Do not accept yet: Wire authority, principal identity recovery, unmonitored integrator access.
- Next cycle: Secondary residences; operating company boundary review.
Effectiveness and residual-risk fields live in the private model and are revisited at annual stewardship.
Report + USB — what you keep
The printed (or PDF) report is the board-ready artifact for counsel and family leadership. The Sanctuary Model on private USB is the living system: encrypted vault, full control scores, threat spectrum, roadmap, and guided assistant — running only on devices you control.
- Unlock with your vault password · no TargetProof cloud login
- Update scores as gaps close · re-export backups you hold
- TargetProof keeps no copy of assessment data unless you separately authorize support access
This web page is an illustrative sample for evaluation only. Your engagement produces a report and model scoped to your household.