Illustrative sample only. Fictional household. Abbreviated findings. Not a real assessment — and never a substitute for a principal-led engagement.

Arrange briefing · $10,000 Engagement overview
TargetProof
Confidential · Client private
Sanctuary Framework · SN001

Family Threat Model Report

NIST CSF 2.0 household-applied · One integrated picture of posture across people, institutions, and lifestyle.

Household
Northridge Family Office
Assessment date
Illustrative · 2026
Assessor
Thomas M. Stone, Principal
Custody
USB you keep · tablet retains none · no cloud copy
01 · Executive brief

Where you stand

62%
Maturity
148/156
Controls scored
19
Gaps
34
Partial

Northridge presents as a sophisticated household with strong counsel relationships and modern estate systems — yet several high-value surfaces remain outside coordinated control: wire authority, household staff access, multi-property networks, and the principal’s personal device stack.

Top risks (plain language)

  • Business-email-compromise style diversion of high-value wires remains plausible without dual-control discipline.
  • Estate integrator and IoT access paths are broader than the family office assumes.
  • Personal devices and cloud accounts for the principal sit outside enterprise-grade MFA and recovery controls.
  • Public and philanthropic visibility enables targeted social engineering of staff and family.
  • No single living playbook ties cyber, physical, and human response when something goes wrong.

Residual risk stance (illustrative): Accept residual risk on low-impact lifestyle systems after roadmap execution; do not accept residual risk on wire, identity, or principal account recovery until high-priority gaps are closed.

02 · Scope & context

What we assessed

One-day principal-led onsite engagement across the primary residence and agreed family-office touchpoints. Intake structured before scoring.

In scope (illustrative)

  • Primary residence (Atlanta metro) · guest house · home office
  • Family office coordination surface (finance, EA, outside counsel liaison)
  • Principal + spouse devices and primary cloud identities
  • Household staff access patterns (not full HR review)
  • Known travel profile and public philanthropy calendar (high level)

Out of scope this cycle

  • Secondary residences (flagged for follow-on probes)
  • Operating company IT environments
  • Full OSINT deep-dive (recommended as SN002 if prioritized)
03 · Threat context

What can go wrong here

Spectrum themes highlighted from intake — not a generic scare list. Themes are illustrative and abbreviated for this sample.

  • Wire & payment diversion — vendor change, real-estate close, philanthropic pledges
  • Impersonation of counsel / family — email, SMS, and deepfake voice risk to staff
  • Device & account takeover — SIM, recovery email, password reuse on principal stack
  • Integrator & IoT path — cameras, HVAC, access systems with shared credentials
  • OSINT-enabled targeting — public events, giving, property records

Each theme maps to Govern → Recover controls scored during the onsite day.

04 · Maturity by function

NIST CSF 2.0 · household view

Weighted maturity across Govern through Recover after scoring (illustrative percentages).

Govern
58%
Identify
64%
Protect
71%
Detect
52%
Respond
48%
Recover
55%

Protect is relatively strong (endpoint tools, some MFA). Detect and Respond lag — typical when households buy tools but never rehearse incident roles.

05 · Cross-cut dimensions

People · Institutions · Lifestyle

Adversaries do not respect silos. Every control is tagged across these three lenses.

People

8 gaps · 11 partial · in place

Staff verification rituals incomplete. Principal MFA uneven. Family travel devices weakly covered.

Institutions

6 gaps · 12 partial · in place

Wire dual-control not enforced with banks. Vendor offboarding after FO staff change is ad hoc.

Lifestyle

5 gaps · 11 partial · in place

Event and philanthropy exposure unmonitored. Secondary properties not yet probed.

06 · Priority findings

Risk-ordered gaps

Control IDs shown for traceability. Full statements and verify scripts remain in the private Sanctuary Model — not published in this sample.

ID Finding (abbreviated) Sev Path
GV.RM-xx No written security authority for household/FO decisions; exceptions undocumented. High SN010 Governance
PR.AA-xx Principal financial accounts lack consistent phishing-resistant MFA and recovery ownership. High SN003 Identity
PR.AA-xx Wire change requests accepted without dual-channel verify with known bank contacts. High SN003 / process
ID.AM-xx Incomplete inventory of cameras, access panels, and integrator accounts across estate systems. High SN004 Network & IoT
DE.CM-xx No continuous watch on credential dumps or domain lookalikes for principal brands/entities. Med SN002 / SN008
RS.MA-xx Incident roles exist informally; no 24/7 contact tree or tabletop in last 24 months. Med SN007 Playbooks
PR.AT-xx Household staff training is annual generic video — not role-specific social engineering drills. Med SN005 SE Defense
RC.RP-xx Backups exist for FO files; restore tests for principal cloud identity recovery not evidenced. Med SN011 Recovery

Remediation paths are optional Sanctuary services — selected and sequenced by the family, not automatic upsell.

07 · Remediation roadmap

30 · 90 · 180 days

30 days

Stop the bleed

  • Wire dual-control with banks and FO
  • Phishing-resistant MFA on principal finance & email
  • Integrator credential reset + inventory pass
  • Written security authority (who decides)
90 days

Raise the floor

  • Estate network segmentation plan (SN004)
  • Staff role drills (SN005)
  • Footprint reduction for public surfaces (SN002)
  • Draft crisis contact tree
180 days

Make it durable

  • Tabletop + living playbooks (SN007)
  • Restore tests & recovery proof (SN011)
  • Optional continuous monitoring (SN008)
  • Annual review cycle / stewardship
08 · Review & residual risk

Did we do enough?

The Family Threat Model ends with an explicit review — not an implied “you’re secure.” Residual risk is accepted or deferred in writing by the principal (or designated authority).

  • Accept (illustrative): Lifestyle IoT in guest cottage after inventory and guest VLAN — low impact if segmented.
  • Do not accept yet: Wire authority, principal identity recovery, unmonitored integrator access.
  • Next cycle: Secondary residences; operating company boundary review.

Effectiveness and residual-risk fields live in the private model and are revisited at annual stewardship.

09 · The living model

Report + USB — what you keep

During the onsite day, TargetProof runs the Sanctuary Model on a dedicated tablet we bring — we do not need to use household computers. Assessment data and this report write to a private USB key prepared for your household.

Before we leave, we review findings with you so next actions are clear. You keep the USB. Working session state is cleared from the tablet; TargetProof does not retain a cloud or office copy unless you later choose to share material for authorized support.

The report is the board-ready artifact for counsel and family leadership. The Sanctuary Model on the same USB is the living system: encrypted vault, full control scores, threat spectrum, roadmap, and guided assistant.

  • Unlock with your vault password · no TargetProof cloud login
  • Update scores as gaps close · re-export backups you hold
  • Tablet retains none of your assessment data after handoff

This web page is an illustrative sample for evaluation only. Your engagement produces a report and model scoped to your household, delivered the same day.

Your household. Your report.

One day onsite · $10,000. A private Family Threat Model Report and Sanctuary Model you keep. Start with a confidential briefing to confirm fit and timing.