Practice · Sanctuary

What is a family threat model?

A structured way for a household to see how it could be harmed, what already protects it, where the gaps are, and who owns closing each one.

A family threat model is a structured assessment of a household’s people, assets, technology, and money flows that shows how the family could be harmed, which safeguards already protect it, where the gaps are, and who in the household owns closing each one. It applies the threat modeling discipline that businesses use to protect their operations to the private family and its estate.

A family threat model (FTM) is a practice, not a product. Any household, family office, or adviser can use the approach. Sanctuary is TargetProof’s version of it.

Why a family threat model matters

At the upper end of the wealth curve, there is a gap between what you own and what you can cover. As the world turns digital, the gap becomes a wedge of risk.

Most families do not design their technology. It accumulates. A new residence brings a new network, cameras, and a smart-home system. A new assistant gets access to the calendar and the inbox. A family office adds a bank portal, a bill-pay platform, and an accounting system. Children arrive at college with phones, laptops, and social accounts. Each decision makes sense on its own. Together they form IT sprawl:

  • Residences. Several homes, each with its own internet service, Wi-Fi, security system, building controls, and vendors.
  • Devices. Phones, laptops, tablets, cameras, televisions, vehicles, and connected appliances, many shared and few inventoried.
  • Accounts. Email, cloud storage, banking, brokerage, travel, and social media, with passwords and recovery settings spread across family members and staff.
  • Staff. House managers, assistants, nannies, drivers, and contractors who need access to do their jobs and often keep it after they leave.
  • Wire authority. People who can instruct, approve, or release money, frequently by email or phone, which is exactly where impersonation and payment fraud aim.

A company of similar complexity would have an IT owner, a security program, and a budget. A household usually has goodwill and a few trusted people, each seeing part of the picture. Attackers, including those now using AI to imitate voices and write convincing messages, look for the seams between those parts. A family threat model finds the seams first.

How a family threat model works

A family threat model treats the estate the way a well-run business treats its operations: with defined roles, a clear inventory, known risks, assigned owners, and a repeatable process.

1. Identify the role players

Every household has seats, even when no one has named them. A family threat model names them and asks each seat only the questions it can answer:

  • Head of household. Sets priorities, holds final authority, and is often the most visible target.
  • Family office. Runs money movement, reporting, entities, and vendor relationships.
  • House manager. Runs the residences, staff, vendors, and physical access.
  • Executive assistant. Holds the calendar, travel, inbox, and often the passwords.
  • Technology. The in-house person, outside provider, or both, who runs devices, networks, and accounts.
  • Advisers. Wealth managers, private bankers, insurers, and attorneys who exchange sensitive information and instructions with the family.

2. Map assets and threats

Assets are what the family needs to protect: people and their safety, money and the authority to move it, private information, reputation, residences, and the systems that run daily life. Threats are the realistic ways those assets could be harmed: payment and wire fraud, email compromise, account takeover, impersonation of a family member or adviser, exposure of location and routines, insider misuse, and compromise of home networks and cameras.

3. Assess controls and gaps

For each threat, the model records which safeguards are already in place and where they fall short. A gap is any place where a realistic threat meets a missing or weak safeguard. Gaps are ranked by impact, so the most consequential fixes come first.

4. Assign owners

Every gap gets a named owner from the household’s own role players. The owner is responsible for closing it, with a clear next step and a date. A gap without an owner tends to stay open. Assigning owners is what turns an assessment into action.

5. Run it as a process

A family threat model is not a one-time report. Families change: a new home, a new hire, a departing assistant, a child leaving for school, a liquidity event, a public moment. The model is revisited on a cadence, gaps are closed and checked, and new gaps are added as the family evolves.

Built on established practice

Threat modeling is an established business discipline. Security teams use it to understand how systems and organizations can be attacked before attackers find out. A family threat model adapts that discipline, rebuilt for a household.

For structure, a family threat model can be organized around the six functions of the NIST Cybersecurity Framework (CSF), the publicly available framework from the U.S. National Institute of Standards and Technology: govern, identify, protect, detect, respond, and recover. That gives the family a common structure that advisers and insurers already recognize.

What the family gets

A family threat model should leave the family with something it can use on Monday morning and keep:

  • A Family Brief. Plain-language findings: what was found, what matters most, and who does what next.
  • Working papers. One page per owner, listing that seat’s gaps, the steps to close them, and target dates.

The family keeps both. In TargetProof’s approach, the model runs on-device during the work, nothing goes to the cloud, and TargetProof keeps no copy. The household’s map of its own vulnerabilities stays with the household. See illustrative samples.

Sanctuary: TargetProof’s family threat model

Sanctuary is TargetProof’s family threat model, delivered in two parts. The sitting scores 172 household-specific controls across People, Institutions, and Lifestyle.

The one-day sitting

A TargetProof team spends one day on site with the household. Each role player is walked through only the questions for their seat. The team maps people, money flows, devices, residences, visibility, and travel, then walks the household the way an adversary would, including the ways AI can be used against a family. By the end of the day, the IT sprawl has become one organized picture, the gaps are ranked, each has an owner, and the family has its Family Brief.

Stewardship

The sitting starts the work. Stewardship finishes it. A TargetProof consultant returns monthly, then quarterly, then twice a year, and runs the program like a project management office for the family: meeting with each gap owner, getting updates, clearing obstacles, and confirming gaps are closed. As the family evolves, Stewardship surfaces new gaps and assigns them, so the security program matures rather than going stale.

Hands-on work, only when a gap needs it

When closing a gap requires hands-on technical work, such as reconfiguring a home network or securing a device, TargetProof provides that remediation from the Sanctuary catalog. It exists to close a specific gap, not as a standing service.

Who a family threat model is for

A family threat model fits households whose complexity resembles a small company: multiple residences, household staff, a family office or outside advisers, people with authority to move money, and some degree of public visibility. Common moments to start include a new residence, a staff change, a wire or email-fraud incident or near miss, philanthropic or board visibility, travel that makes routines predictable, and succession or a next-generation handoff.

How introducers bring families in

Many families come to Sanctuary through the professionals who already serve them:

  • Private-client insurers, who want gaps found and closed before there is a claim.
  • Wealth and family-office desks, who want the household run with the same discipline as the portfolio.
  • Private banks, who see wire and impersonation risk firsthand.
  • Estate attorneys, who care about authority and continuity: who may instruct, and who acts if the head of household cannot.

The arrangement is simple. The introducer introduces. The family engages TargetProof directly and pays for the work. The introducer stays in front of the relationship, and TargetProof shares nothing beyond what the family authorizes.

Frequently asked questions

What is a family threat model in simple terms?

It is a structured way for a family to see how it could be harmed, what already protects it, where the gaps are, and who in the household is responsible for closing each one. It applies business threat modeling to the private household.

How is a family threat model different from home IT support?

IT support fixes things that break. A family threat model looks at the whole household, including people, staff, money movement, and advisers, to find where a realistic attack would succeed, then assigns owners and tracks the fixes over time. It may lead to technical work, but it starts with risk, not repairs.

Does my family need a threat model if we already have a family office?

Often, yes. A family office typically protects the money and the entities. The residences, personal devices, staff access, children’s accounts, and the paths between the family and its advisers usually sit outside that scope. A family threat model covers the whole estate and makes the family office one of the named owners.

Who should be involved in a family threat model?

The household’s role players: the head of household, the family office, the house manager, the executive assistant, whoever handles technology, and, where relevant, advisers such as wealth managers, private bankers, insurers, and estate attorneys. Each answers only the questions for their seat.

What frameworks is a family threat model based on?

A family threat model adapts the threat modeling discipline businesses already use, drawing on the established body of public threat modeling practice, rebuilt for a household. It can be organized around the six functions of the NIST Cybersecurity Framework: govern, identify, protect, detect, respond, and recover.

How long does a family threat model take?

With Sanctuary, the initial assessment is a one-day on-site sitting, and the family receives its Family Brief. Stewardship then continues monthly, then quarterly, then twice a year, until the gaps close and as new ones emerge.

Who keeps the results of a family threat model?

The family should. With Sanctuary, the family keeps the Family Brief and working papers, the model runs on-device, nothing is stored in the cloud, and TargetProof keeps no copy.

What is Sanctuary?

Sanctuary is TargetProof’s family threat model: a one-day on-site sitting that organizes and secures the household’s technology and assigns an owner to every gap, followed by Stewardship that runs the program until the gaps close.

Begin with a confidential first conversation. Confirm fit, timing, and scope. Discretion is not a feature. It is the foundation.

Family Threat Model For advisors Private briefing