Skip to main content
Greyveil Company Logo

Inside the Routine

Why the household team, not the technology, is where family security is usually won or lost

Daniel Goodbody

Managing Director, Greyveil Ltd

Second in a series on the family office security footprint

The number nobody has counted

A family office will usually describe its protected population in terms of the family. Four adults, three children, two residences, a yacht.

A competent hostile party counts differently. They count everybody who holds a key, an alarm code, a diary, a set of car keys, a cleaning rota or a strong opinion about the family. In most established households that number sits somewhere between twenty and eighty people, and in almost every case nobody has ever written it down on a single page.

The gap between those two counts is where a substantial proportion of residential and personal security risk actually lives. It is not glamorous, it does not benefit from new equipment, and it is consistently the last thing a family office examines. Insurance-sector analysis of high value residential losses now describes the same picture from the other direction: burglary in this segment is intelligence-led rather than opportunistic, offenders conduct extended reconnaissance, occupancy is no longer a reliable deterrent, and the intelligence itself is assembled from social media, casual photography inside the home, household staff routines and informal conversations about travel plans.

Note what appears in that list alongside the technology. Routines. Conversations. People.

Four rings of access

Ask a house manager to list everyone with routine access to a principal residence and the list assembles itself into four distinct rings.

The first is directly employed household staff: house manager, personal assistants, nannies or governesses, chefs, drivers, housekeepers, estate and grounds staff, and any directly employed security personnel. This ring is normally screened, contracted and insured.

The second is engaged but not employed: tutors, physiotherapists, personal trainers, therapists, music teachers, stylists, dog walkers. Regular attendance, frequently unaccompanied, often alone with children, and typically engaged on the strength of a recommendation from someone the family trusts.

The third is contracted services: cleaning companies, pool and garden maintenance, heating and air conditioning engineers, audiovisual and alarm technicians, window cleaners, pest control, florists, couriers and deliveries. Here the family contracts a company rather than a person. The company rotates its people, and the family’s screening covers none of them.

The fourth is transient and professional: architects, interior designers, art handlers, removals crews, insurance surveyors, valuers, event photographers, agency temporary cover for annual leave, and the former employee who left eighteen months ago and whose code was never changed.

Only the first ring is normally managed as a security population. The other three account for most of the traffic through the door.

What the household actually knows

Household staff hold better intelligence on a principal than any commercial due diligence provider could assemble at any price, and they hold it without any contract that reflects the value of what they are carrying.

They know the true daily pattern, which no document captures accurately. They know which nights the house is empty and which nights it is not, usually before the family office does. They know health, medication, marital condition, financial strain and the substance of the arguments. They know where the safe is, when the alarm is genuinely set and when it is not, where the cameras do not reach, who holds which key, and how key custody works in practice as distinct from how it is written down. They know travel dates first, because somebody has to pack.

The family office holds the sanitised version. The household holds the operational truth. A security programme that briefs the former and not the latter is protecting the wrong document.

Four failure modes

Insider threat is a lazy phrase for this, because it implies one category of person acting with one kind of intent. In household environments the failures divide fairly cleanly into four, and only one of them involves a bad actor.

The corporate data supports the emphasis, even allowing for the difference in setting. Verizon’s 2025 Data Breach Investigations Report, drawing on more than twenty-two thousand incidents, found the human element present in 60% of breaches and third-party involvement doubling to 30%. In EMEA specifically, 29% of breaches originated with internal actors, against 5% in North America. Households are not enterprises, but the ratio of human failure to technical failure is not materially different, and households have almost none of the compensating controls.

Deliberate recruitment or coercion

Somebody is approached, paid, pressured or romanced for information. This is the version everybody imagines and it is the least common of the four, though it certainly happens, and it is cheap for the adversary. A schedule is worth far less to the person selling it than to the person buying it. Recurring shapes include placement through agencies, approaches to junior staff outside working hours, and leverage applied through debt, addiction or immigration status.

Disclosure without malice

This is the common one by a very wide margin. Staff talk. To partners, to friends, to family, to staff at other houses, and to the professional communities they belong to. This is not disloyalty. It is the ordinary human need to say something interesting about your day to somebody who will be impressed by it. A person who works in a remarkable environment and is contractually forbidden from mentioning it to anyone is being asked to carry something genuinely difficult, and most people carry it imperfectly. Any control that does not begin from that understanding will fail.

Process drift

The code that was never changed after the last departure. The key that was never returned. The gate propped open for a delivery and left that way. The contractor admitted because he had a van, a clipboard and a plausible manner. The alarm left unset because the family were due back within the hour, and then were not. Household security does not usually fail through breach. It erodes through convenience, one entirely reasonable shortcut at a time, and the erosion is invisible until it is tested.

Grievance

A substantial share of deliberate insider incidents are preceded by a documented human resources failure: a dismissal handled without dignity, unpaid overtime, an accusation made and never withdrawn, a humiliation in front of guests. Where that is the antecedent, the security failure was created by a management decision taken months earlier. This is the point at which security stops being a security function and becomes an employment one, and it is the reason the two should not sit in separate conversations.

The digital layer

Everything in the previous article in this series about the family’s own digital footprint applies to the household as well, with two aggravating features.

The first is that staff have less reason to think of themselves as security-relevant, and therefore post more freely. Kitchen photographs. The view from the drive. A boarding pass. Off to Sardinia for three weeks, back in September. None of it is malicious and all of it is targeting material, particularly because it corroborates: it independently confirms what a hostile party had already inferred from the family’s own accounts.

The second is aggregation. There are genuine professional communities among private staff, and they are valuable ones. Nannies, chefs, estate managers and drivers all have networks, frequently on messaging platforms, spanning many households. They exist for legitimate reasons including safety, mutual support, standards and recruitment. They are also an uncontrolled layer in which information concerning many different principals sits together in one place, on personal devices, with no retention policy and no reliable knowledge of who has been added to the group.

Two further items are worth naming because they are so easily corrected and so rarely addressed. Employment history published on professional networking platforms that identifies the family, or an identifiable role at an identifiable address, is the single easiest open-source route into a household’s composition. And recruitment advertising, written in good faith by agencies, routinely publishes a complete targeting package: a private family in a named area, six bedrooms, two children aged four and seven, one dog, live-in accommodation, frequent international travel, discretion essential.

Vetting is a photograph, not a film

Pre-employment screening captures a moment. In the United Kingdom, BS 7858 sets out the code of practice for screening individuals working in secure environments, and it is a sound baseline. Greyveil screens to and complies with that standard as a matter of policy.

Circumstances change after the photograph is taken. Debt arrives. A relationship ends. A dependency develops. A new partner asks interested questions. A family member overseas becomes leverage. Somebody screened impeccably in 2019 may be in an entirely different position today, and in most households nobody has looked since.

Three practical gaps follow. Cadence: most households conduct no screening at all after the point of hire. The agency gap: an agency’s checks are the agency’s checks, conducted to the agency’s standard for the agency’s commercial purposes, and are not a substitute for the family’s own assurance. And the contractor gap: the cleaning company rotating four different people through the house in a month has performed whatever screening its own business model supports, and the family has visibility of none of it.

Why equipment does not solve this

Households tend to respond to this problem by buying things. More cameras, better access control, an audit trail on every door. That equipment is useful, and it is not an answer, for a straightforward reason.

Cameras record the household. They do not manage it. An access log establishes afterwards that a door was opened at 14:42. It establishes nothing about the fact that the person who opened it has become withdrawn, has stopped taking scheduled leave, has developed an interest in the diary that sits outside their function, or has been asking other staff questions they would not put to the principal.

Those are behavioural signals, and they matter because they are available early and cost nothing to observe. They also require somebody to be paying attention, which in most households is nobody’s defined responsibility. It is worth being precise about what this is not. It is not surveillance of staff, which is legally fraught under UK data protection law and corrosive of exactly the trust a household depends on. It is management attention, exercised openly, by a named person, as an ordinary part of running a household properly.

What proportionate looks like

Build the list

An access register recording every individual with a key, a code, or routine unescorted presence, refreshed quarterly, on a single page. Most families have never seen this and find the number genuinely startling. It is the cheapest intervention available in this entire domain and it typically generates three or four immediate corrections on the day it is first produced.

Contract confidentiality properly

Household confidentiality provisions are frequently inherited from a template written for an office. They should be specific and proportionate, address social media and photography explicitly, survive the end of the engagement, and be capable of enforcement. This is legal territory and should be treated as such rather than drafted by a security provider.

Brief the household on why, not only what

People protect what they understand. A housekeeper who understands why the gate matters closes the gate. A driver who understands why route variation matters varies the route. A prohibition issued without a reason is complied with only for as long as somebody is watching, and household staff are unsupervised for most of their working lives.

Fix the recruitment advertising

No role should be advertised in terms that describe the household, its composition, its location or its travel pattern. This sits entirely within the family’s control and is given away repeatedly, in public, at no cost to the adversary.

Rescreen on cadence and on trigger

A defined interval, plus rescreening at role change, at promotion into greater access, and at any material change in circumstances the individual has themselves disclosed. Consent-based, transparent, and written into the engagement at the outset rather than introduced later, because introduced later it always reads as an accusation.

Control the contractors

Named individuals rather than named companies. Escorted access as the default rather than the exception. Supervision for works in sensitive areas. And, wherever it can be arranged, trades work scheduled against family presence rather than in parallel with it.

Treat offboarding as a security event

Codes, keys, fobs, devices, cloud accounts, shared calendars, group memberships and vehicle access, all closed on the same day, against a checklist, every time, including for a departure that was entirely amicable. And conducted with dignity, because the manner of an exit is itself a risk variable and one of the few that management controls completely.

Name one accountable person

Usually the house or estate manager. Give them authority to match the responsibility, and the time to exercise it. Distributed accountability for household security means no accountability for household security.

The wider point

There is a way of writing about private staff that treats them as a population to be contained. It is unpleasant, and it is also counterproductive, because it destroys the thing that is actually valuable here. The household is not primarily a threat. It is the largest under-used security asset a family already employs and already pays for.

Twenty people who live inside the routine know precisely what normal looks like in that house. They notice the van parked on the lane three mornings running. They notice the man who asked slightly too many questions at the school gate. They notice that the delivery driver was not the usual delivery driver, and that he took an interest in the side gate. No camera system generates that at any price, and no external provider can install it. It exists already. In most households it is not briefed, not asked, not listened to and not thanked, and so it goes unreported.

At Greyveil we describe our approach as Behavioural Protective Intelligence. Technology records what happened. Protective intelligence anticipates what might happen. Behavioural intelligence reads intent and pattern. In a household environment the third of those is not a specialist capability bolted on from outside. It is the household itself, properly briefed, properly contracted, properly led, and treated as part of the protective system rather than as a liability sitting inside it.

Protect the whole footprint. The footprint includes the people who make it work.

Daniel Goodbody is Managing Director at Greyveil Ltd, an intelligence-led protective security firm working with private clients, family offices and corporate principals. Greyveil’s practice is built on Behavioural Protective Intelligence and a single organising principle: protect the whole footprint.

enquiries@grey-veil.com | grey-veil.com |  Quietly in control.

GREYVEIL LTD  ·  PRIVATE SECURITY SERVICES  ·  SPECIAL PROJECTS

enquiries@grey-veil.com   ·   grey-veil.com

SHARE THIS POST
Greyveil Company Logo
Intelligence-led protection for principals, family offices, and enterprises.
Seven disciplines, one discreet relationship.
© 2026 Greyveil Ltd
Quietly in control