Skip to main content
Greyveil Company Logo

Head Down, Guard Down

What next-generation digital fluency means for family office security, and why “post less” is not a security programme

Daniel Goodbody

Managing Director, Greyveil Ltd

Fluency is not the same as literacy

A common assumption inside family offices is that the younger generation, having grown up with the technology, understands it. They are fluent. They move between platforms, devices and identities with an ease that their parents find remarkable and their advisers find slightly unsettling.

Fluency is not the same as literacy. Speaking a language perfectly does not mean understanding what you are giving away when you speak it.

The generation now moving into family office governance, the twenty and thirty year olds who will in time hold the trusteeships, the board seats and the control of the structures, carry a device that is simultaneously their social life, their financial access, their identity document and, increasingly, the single most productive reconnaissance asset available to anyone who wishes their family harm. That is not a moral observation about young people. It is a structural observation about how the technology works, and it applies with equal force to a fifty-five year old principal who has recently discovered short-form video.

What leaks is the pattern, not the post

Most family office conversations about social media get stuck on the individual post. Should she have geotagged the villa. Should he have filmed inside the aircraft. Those are reasonable questions, and they miss the mechanism.

A party conducting target research is rarely looking for a single catastrophic disclosure. They are assembling a pattern. Which gym, which mornings. Which coffee shop before which office. Which lounge, which route, which fixed point in the week that never moves. Individually, none of it is sensitive. Aggregated across eighteen months of posts, across the subject’s own account and the accounts of five friends who tag them, it produces something that no surveillance team could build cheaply or safely: an accurate, dated, corroborated pattern of life, assembled voluntarily by the subject and available at no cost.

Three factors amplify this.

•     Third-party posting. An individual can lock their own account down completely and remain fully exposed through friends, partners, classmates, private staff and event photographers who have not.

•     Metadata and inference. Images carry embedded location, timestamp and device data unless it is stripped, and even where a platform removes it, background detail, signage, reflections, shadow angles, hull names and aircraft registrations frequently resolve a location without any metadata at all.

•     Persistence. Content is archived, scraped and resold within minutes. A post deleted after an hour is not a post that did not happen.

Academic literature has described this for more than a decade under the term cybercasing: the use of publicly posted, location-bearing content to plan a physical crime against the person who posted it. What has changed is not the technique. It is that the volume of available material, and the tooling for sorting it, has made the technique cheap enough for ordinary acquisitive criminals rather than only for capable and motivated adversaries.

The cyber picture: the personal device as the softest edge

Family offices have become measurably attractive targets. Deloitte’s Family Office Cybersecurity Report 2024 found that 43% of family offices globally had experienced a cyberattack in the preceding twelve to twenty-four months, rising to 62% among those with assets under management above one billion US dollars. Phishing was the vector in 93% of cases. Against that, nearly a third of respondents had no cyber incident response plan of any kind, and only around a quarter described their plan as robust.

What is discussed less often is where the attack surface actually sits. A well-run family office may have hardened its servers, its email, its vendor onboarding and its payment authorisation chain. It has almost certainly done none of that to the personal handset of the principal’s twenty-four year old daughter, which sits entirely outside the managed estate, runs whatever the app store offered that week, is signed into the family’s shared cloud storage, holds photographs of documents taken for convenience, and contains a group chat in which the family discusses travel dates in plain language.

Voice and likeness as raw material

Publicly posted video is training data. Contemporary voice cloning requires only a few seconds of clear audio, and the FBI has issued repeated public warnings about AI-enabled virtual kidnapping, in which offenders harvest a voice sample and corroborating detail from social media, then telephone a family member with a cloned distress call and a demand for immediate, untraceable payment. The widely reported 2024 case in which a finance employee in Hong Kong transferred approximately twenty-five million US dollars following a deepfake video conference is the same technique applied to a corporate authorisation chain rather than to a parent.

Stated bluntly: a next-generation family member with an active public video presence is publishing, at scale and in high fidelity, the raw material for an attack on their own family’s treasury function and on their parents’ emotional decision-making under pressure.

Device compromise as physical compromise

Mobile phone theft in the United Kingdom is an organised, industrial-scale enterprise rather than opportunistic street crime. The Metropolitan Police recorded in the order of seventy thousand mobile phone thefts in London during 2025, a reduction on the previous year but still a phone taken every few minutes, and a single major investigation in the same period identified a network trafficking tens of thousands of stolen United Kingdom handsets overseas.

The security consequence for a family office is not the loss of a handset. It is that an offender who has watched a passcode being entered before taking the device holds, for a window of time, an authenticated identity. Messages. Mail. Cloud photographs, including the photographed documents. Banking and brokerage applications. Home camera feeds. Location history, which is to say the residence. And the ability to reset the credentials protecting everything else. The chain runs from a street theft outside a restaurant to the family’s residential security posture in well under an hour.

Inherited trust

Attackers increasingly target the least-defended member of a group in order to reach the best-defended one. A compromised next-generation account is valuable less for what it contains than for the credibility it lends to the next message. A request arriving from a known family account, in known family idiom, referencing a real event that genuinely happened last weekend, defeats most people’s scepticism, including the scepticism of experienced finance staff who have been trained to watch for exactly this.

The physical picture: attention is a finite resource

Attention is the primary instrument of personal security. It is also the resource that a smartphone is designed, with enormous commercial skill and considerable behavioural science behind it, to consume completely.

The observable behaviour is familiar to anyone who has walked through a European city centre. Head down, both ears occluded, walking at pace. Sitting with the back to the door and the phone face up on the table in view of the street. Standing stationary on a pavement, absorbed, working out a route. None of this is reckless. All of it is entirely ordinary. Each of it degrades personal security in a specific way.

Reduced detection

At the individual level, counter-surveillance awareness requires nothing exotic. It requires looking up often enough to notice the same face twice, the vehicle that has now passed three times, the person who adjusted their pace when you adjusted yours. An absorbed subject does not notice the approach, the loiter or the repeat. The interval between recognising that something is wrong and that thing happening is where every personal safety decision lives, and for a great many people it is now spent looking at a screen.

Favourable target selection for the offender

From the offender’s perspective, the absorbed subject is preferable in every respect. They are stationary or predictable. They will not make eye contact and are unlikely to identify anyone afterwards. They have advertised the value of the device itself. Their reaction time is measured from the moment of contact rather than from the moment of approach, which is the difference between a completed offence and an aborted one. Target selection is not random. It is a rapid rational assessment made in a few seconds, and the head-down posture answers most of the offender’s questions in the offender’s favour.

Loss of the threshold habit

The highest-risk moments in an otherwise unremarkable day are transitions. Leaving a residence. Entering or leaving a vehicle. Arriving at a venue. Moving through a hotel entrance. These are the moments on which hostile advance work concentrates, and they are precisely the moments at which a phone is most likely to be in the hand, because they are the natural pauses in a day. A protection team can manage the vehicle and the venue. It cannot manufacture the principal’s attention for them.

Predictability and duration

Posting in real time discloses more than location. It discloses duration. Somebody who posts from a table is stating that they are seated, static, distracted and likely to remain so for some time. That is the difference between an adversary knowing where somebody was and knowing where somebody currently is and for how long.

Where the two pictures meet

Treating cyber exposure and physical exposure as separate disciplines is the error that produces most of the residual risk in this area. In practice they form a single chain.

Open-source research identifies the subject and establishes the pattern. The pattern supports a physical approach, whether that is a street robbery, a burglary timed to a known absence, an intrusive photographer or something considerably more serious. The physical event delivers a device. The device delivers credentials, travel plans and the residential address. The credentials support the next social engineering attempt against the family office itself. Publicly reported cases in the United States, in which organised burglary crews used professional athletes’ publicly posted schedules and social content to time entries into their homes, are simply this chain executed competently by people who were not, in any technical sense, sophisticated.

The right question for a family office is therefore neither “is our IT secure” nor “does the principal have a driver”. It is whether anyone has examined the whole footprint as a single connected system, including the members of the family who are not on the payroll and have never been briefed.

The generational dynamic, and why prohibition fails

The instinctive institutional response is restrictive. Post less. Better still, do not post. It very rarely works, for four reasons worth stating plainly.

1.     It is unenforceable against adults. A twenty-six year old with independent means will not comply with a policy they did not help write and cannot see the logic of.

2.     It attacks something load-bearing. For this generation, digital presence is not vanity. It is professional infrastructure. Founders raise, artists exhibit, philanthropists convene and investors source deal flow through these channels. Instructing a next-generation family member to disappear online carries a real and quantifiable career cost, and they know it even if their advisers do not.

3.     It drives behaviour out of sight. Prohibition does not produce silence. It produces secondary accounts that the family office does not know exist, cannot review and cannot protect.

4.     It frames security as an imposition by the previous generation, which converts an operational conversation into a family dynamics conversation. Once that conversion has happened, the security argument has already been lost regardless of its merits.

There is a further point that family offices are often reluctant to acknowledge. A material share of the exposure attaching to the next generation was created by the generation before it. Parents post about their children. Family offices publish leadership pages with photographs. Philanthropic vehicles publish trustee lists, event galleries and named attendee photography. Exposure is a family-level property. It is not a young person’s character flaw.

What proportionate looks like

The objective is not silence. It is the removal of precision and predictability from published material, and the restoration of a modest amount of attention at the moments where attention actually matters. The principles below hold up in practice because they cost the individual very little.

Assess before advising

A structured exposure assessment of the family’s actual, current, aggregate digital footprint, conducted transparently and with consent, establishes what is genuinely available rather than what everyone assumes is available. Almost every family is surprised by the result, and in most cases the surprise concerns something a third party published rather than anything they posted themselves.

Delay rather than deny

The single highest-yield change available, and the one with the lowest cost to the individual, is the shift from live posting to posting after departure. It removes essentially all real-time targeting value while leaving the content, the audience, the engagement and the social function completely intact. It is also easy to agree to, precisely because nobody is being asked to give anything up.

Separate the identity from the routine

Content showing the person is far lower risk than content showing the person’s routine. Faces, food and friends are usually fine. Front doors, gates, driveways, aircraft registrations, hull names, distinctive street furniture, school uniforms and the same location at the same time each week are not.

Agree a verification protocol at family level

A pre-agreed challenge phrase, and a standing family rule that no urgent financial instruction or emergency claim is ever actioned on the strength of a voice or a video without an out-of-band callback to a known number, costs nothing and defeats the great majority of synthetic media attacks. It belongs alongside the family office’s payment authorisation controls, not in a separate conversation about the children.

Treat personal devices as in scope

Not through surveillance, which is legally fraught under UK data protection law and corrosive to the relationship in any event, but by making baseline device hygiene a condition of access to family systems, and by providing that hygiene as a service rather than mandating it as a rule.

Teach attention rather than abstinence

The practical request is narrow and therefore achievable. Not “use your phone less”, but not in a doorway, not during the first and last thirty seconds of any movement, not with both ears covered while walking, and not face up on the table beside the window. Framed as competence rather than restriction, this is generally accepted without argument, because it is manifestly reasonable and because it is finite.

Bring the next generation into the design

Security measures that the protected population helped to write are complied with. Measures imposed on that population are negotiated around, quietly and continuously. This is not a soft cultural point. In our assessment it is the single largest determinant of whether a family security programme functions at all.

Extend the briefing to the periphery

Friends, partners, private staff, tutors, personal assistants and household teams generate a substantial proportion of the aggregate exposure and are almost never briefed on any of it. They are also, in most families, the people with the least reason to think of themselves as relevant to security.

The wider point

At Greyveil we describe our approach as Behavioural Protective Intelligence. The hierarchy is straightforward. Technology records what happened. Protective intelligence anticipates what might happen. Behavioural intelligence reads intent and pattern, and it reads them on both sides of the equation: the behaviour of a hostile party, and the behaviour of the people being protected.

The second half of that is the part most commonly left out of the analysis. A family’s own routine behaviour, what it publishes, when it publishes it, where it is predictable and where its attention goes, is not context surrounding the risk picture. It is a variable inside it, and it happens to be the variable over which the family has the most direct and immediate control.

The next generation is not a security problem to be managed. They are, in most cases, considerably more capable with the technology than the people advising them, and they respond well to being addressed as adults with agency rather than as liabilities. What they have generally not had is anybody willing to explain, without alarm and without moralising, what the technology does with what they give it, and what a competent hostile party can assemble from eighteen months of entirely ordinary posts.

That conversation is overdue in most family offices. It costs very little to have. It is also, consistently, the point at which the next generation begins to take the rest of the security programme seriously, because for the first time the programme is about their world rather than their parents’.

Daniel Goodbody is Managing Director at Greyveil Ltd, an intelligence-led protective security firm working with private clients, family offices and corporate principals. Greyveil’s practice is built on Behavioural Protective Intelligence and a single organising principle: protect the whole footprint.

enquiries@grey-veil.com | grey-veil.com |  Quietly in control.

GREYVEIL LTD  ·  PRIVATE SECURITY SERVICES  ·  SPECIAL PROJECTS

enquiries@grey-veil.com   ·   grey-veil.com

SHARE THIS POST
Greyveil Company Logo
Intelligence-led protection for principals, family offices, and enterprises.
Seven disciplines, one discreet relationship.
© 2026 Greyveil Ltd
Quietly in control