Family Threat Model Report
NIST CSF 2.0 household-applied · One integrated picture of posture across people, institutions, and lifestyle.
Where you stand
Northridge presents as a sophisticated household with strong counsel relationships and modern estate systems — yet several high-value surfaces remain outside coordinated control: wire authority, household staff access, multi-property networks, and the principal’s personal device stack.
Top risks (plain language)
- Business-email-compromise style diversion of high-value wires remains plausible without dual-control discipline.
- Estate integrator and IoT access paths are broader than the family office assumes.
- Personal devices and cloud accounts for the principal sit outside enterprise-grade MFA and recovery controls.
- Public and philanthropic visibility enables targeted social engineering of staff and family.
- No single living playbook ties cyber, physical, and human response when something goes wrong.
Residual risk stance (illustrative): Accept residual risk on low-impact lifestyle systems after roadmap execution; do not accept residual risk on wire, identity, or principal account recovery until high-priority gaps are closed.
What we assessed
One-day principal-led onsite engagement across the primary residence and agreed family-office touchpoints. Intake structured before scoring.
In scope (illustrative)
- Primary residence (Atlanta metro) · guest house · home office
- Family office coordination surface (finance, EA, outside counsel liaison)
- Principal + spouse devices and primary cloud identities
- Household staff access patterns (not full HR review)
- Known travel profile and public philanthropy calendar (high level)
Out of scope this cycle
- Secondary residences (flagged for follow-on probes)
- Operating company IT environments
- Full OSINT deep-dive (recommended as SN002 if prioritized)
What can go wrong here
Spectrum themes highlighted from intake — not a generic scare list. Themes are illustrative and abbreviated for this sample.
- Wire & payment diversion — vendor change, real-estate close, philanthropic pledges
- Impersonation of counsel / family — email, SMS, and deepfake voice risk to staff
- Device & account takeover — SIM, recovery email, password reuse on principal stack
- Integrator & IoT path — cameras, HVAC, access systems with shared credentials
- OSINT-enabled targeting — public events, giving, property records
Each theme maps to Govern → Recover controls scored during the onsite day.
NIST CSF 2.0 · household view
Weighted maturity across Govern through Recover after scoring (illustrative percentages).
Protect is relatively strong (endpoint tools, some MFA). Detect and Respond lag — typical when households buy tools but never rehearse incident roles.
People · Institutions · Lifestyle
Adversaries do not respect silos. Every control is tagged across these three lenses.
People
Staff verification rituals incomplete. Principal MFA uneven. Family travel devices weakly covered.
Institutions
Wire dual-control not enforced with banks. Vendor offboarding after FO staff change is ad hoc.
Lifestyle
Event and philanthropy exposure unmonitored. Secondary properties not yet probed.
Risk-ordered gaps
Control IDs shown for traceability. Full statements and verify scripts remain in the private Sanctuary Model — not published in this sample.
| ID | Finding (abbreviated) | Sev | Path |
|---|---|---|---|
| GV.RM-xx | No written security authority for household/FO decisions; exceptions undocumented. | High | SN010 Governance |
| PR.AA-xx | Principal financial accounts lack consistent phishing-resistant MFA and recovery ownership. | High | SN003 Identity |
| PR.AA-xx | Wire change requests accepted without dual-channel verify with known bank contacts. | High | SN003 / process |
| ID.AM-xx | Incomplete inventory of cameras, access panels, and integrator accounts across estate systems. | High | SN004 Network & IoT |
| DE.CM-xx | No continuous watch on credential dumps or domain lookalikes for principal brands/entities. | Med | SN002 / SN008 |
| RS.MA-xx | Incident roles exist informally; no 24/7 contact tree or tabletop in last 24 months. | Med | SN007 Playbooks |
| PR.AT-xx | Household staff training is annual generic video — not role-specific social engineering drills. | Med | SN005 SE Defense |
| RC.RP-xx | Backups exist for FO files; restore tests for principal cloud identity recovery not evidenced. | Med | SN011 Recovery |
Remediation paths are optional Sanctuary services — selected and sequenced by the family, not automatic upsell.
30 · 90 · 180 days
Stop the bleed
- Wire dual-control with banks and FO
- Phishing-resistant MFA on principal finance & email
- Integrator credential reset + inventory pass
- Written security authority (who decides)
Raise the floor
- Estate network segmentation plan (SN004)
- Staff role drills (SN005)
- Footprint reduction for public surfaces (SN002)
- Draft crisis contact tree
Make it durable
- Tabletop + living playbooks (SN007)
- Restore tests & recovery proof (SN011)
- Optional continuous monitoring (SN008)
- Annual review cycle / stewardship
Did we do enough?
The Family Threat Model ends with an explicit review — not an implied “you’re secure.” Residual risk is accepted or deferred in writing by the principal (or designated authority).
- Accept (illustrative): Lifestyle IoT in guest cottage after inventory and guest VLAN — low impact if segmented.
- Do not accept yet: Wire authority, principal identity recovery, unmonitored integrator access.
- Next cycle: Secondary residences; operating company boundary review.
Effectiveness and residual-risk fields live in the private model and are revisited at annual stewardship.
Report + USB — what you keep
During the onsite day, TargetProof runs the Sanctuary Model on a dedicated tablet we bring — we do not need to use household computers. Assessment data and this report write to a private USB key prepared for your household.
Before we leave, we review findings with you so next actions are clear. You keep the USB. Working session state is cleared from the tablet; TargetProof does not retain a cloud or office copy unless you later choose to share material for authorized support.
The report is the board-ready artifact for counsel and family leadership. The Sanctuary Model on the same USB is the living system: encrypted vault, full control scores, threat spectrum, roadmap, and guided assistant.
- Unlock with your vault password · no TargetProof cloud login
- Update scores as gaps close · re-export backups you hold
- Tablet retains none of your assessment data after handoff
This web page is an illustrative sample for evaluation only. Your engagement produces a report and model scoped to your household, delivered the same day.