TL;DR
Deepfakes, phishing and social engineering make a payment instruction a governance event. Before a family office moves money on a changed instruction, it should use a pre-agreed confirmation route, separate preparation from approval, keep an exception record and know how to contain a suspected impersonation.

A family office often treats a payment as a treasury routine: an invoice arrives, a known adviser sends a change of bank details, a family member asks for urgency, and someone confirms that the account has funds. That routine is exactly why it deserves a controlled interruption. The risk is not limited to an unfamiliar sender. A familiar name, a plausible voice note or a convincing video call can create pressure to bypass the part of the process that establishes who is really asking.

Clearview Publishing’s July 2026 Family Wealth Report cybersecurity resource identifies deepfake impersonation, AI-powered phishing, social engineering, identity theft, ransomware and data-privacy breaches among the issues confronting family offices. It is a useful prompt, but it does not establish a reported incident rate for any particular Asian family office. Deloitte’s separate 2023 survey of 354 single family offices is historical context, not a 2026 forecast: it found that 43% globally had experienced a cyberattack in the preceding 12 to 24 months, while 31% said they had no cyber incident-response plan. The sensible conclusion is not to assume an attack is imminent. It is to ensure that a hurried instruction cannot become authority on its own.

Start with the instruction, not the sender

A request to add a beneficiary, change settlement details, release a distribution or alter an adviser’s payment account should be classified as a change event. The message itself can begin the workflow; it should not complete it. A staff member needs a short record of what changed, which legal entity will pay, who benefits, the amount and currency, and whether the request is ordinary or exceptional under the family’s existing mandate.

This prevents two common shortcuts. The first is treating an email thread as proof of identity. The second is allowing the person who assembled the payment to be the only person who decides whether the instruction is genuine. Neither shortcut becomes safe because the sender is familiar or the amount is small.

Use an independent confirmation route

For a new or changed instruction, the verifier should contact the purported requester using a route that was recorded before the request arrived: for example, a telephone number in the approved adviser record, a secure portal already in use, or a known internal contact. The verifier should not use a number, meeting link or account detail embedded in the new message. The point is not to create friction for its own sake. It is to avoid letting a potentially compromised communication channel nominate its own verifier.

The confirmation should establish the narrow facts that matter: did the requester make this change; what account or beneficiary is intended; which entity is paying; and what authority applies. A call back is evidence of a check, not a substitute for a mandate, bank requirement or sanctions screening. Those remain separate workstreams.

Separate preparation, approval and release

A practical drill assigns three distinct actions. The preparer records the instruction and supporting documents. A verifier performs the independent confirmation. The authorised approver decides whether the payment is within mandate and whether any exception can proceed. In a compact office, one individual may perform more than one role only if the family’s controls expressly allow it and an independent review is added at the point of greatest risk.

The record should show the time of the request, the confirmation route used, the person who verified it, the decision-maker, the entity, the account-change status and any escalation. This is deliberately simpler than a full technology programme. It lets the office reconstruct why it acted if a family member, auditor, bank or insurer later asks what happened.

Rehearse containment before a real incident

IFC Review’s June discussion of Singapore family-office risks recommends staff training, secured infrastructure, audits and an incident-response plan. Those are necessary foundations. The missing operating question is what happens in the first minutes after a verifier suspects an impersonation. The office should know which pending payment can be paused, who owns the bank conversation, who preserves the message and call records, which access credentials may need review, and who may brief the principal without spreading unverified details.

That response should be tested with a benign scenario. One person sends a mock request to change a long-standing service provider’s account; the verifier follows the known route; the approver checks the exception record; and the team notes where the process stalled. The exercise is not an accusation against staff or advisers. It is a way to find a contact list that is out of date, a mandate that is unclear, or a payment platform that offers no workable hold point.

Keep the scope honest

This drill is a governance aid, not a claim that every payment must take the same path. Families have different banks, entities, mandates, jurisdictions and service providers. It does not replace legal, tax, regulatory, banking, sanctions or cyber-security advice. What it does provide is a disciplined boundary: urgency, familiarity and a convincing digital identity are not reasons to weaken the evidence of authority.

For an office managing multi-generational wealth and sensitive personal data, that boundary is worth making visible. It turns a vague instruction to “be careful with cyber risk” into a repeatable question: how do we know this instruction is authentic, authorised and still safe to release?

Frequently Asked Questions

What should trigger a family-office payment-verification drill?

Use the drill when payment details, a beneficiary, settlement instructions, an adviser account or an approval route is new or changed. The request should begin a documented workflow rather than serve as identity proof by itself.

Does a video call or voice note prove that a payment request is genuine?

No. A convincing digital identity can still be manipulated. Confirm the instruction through a contact route recorded before the request and check the relevant mandate and bank controls separately.

What did Deloitte’s family-office cyber survey actually measure?

Deloitte surveyed 354 single family offices between September and December 2023. Its results are historical context, not a current Asia-wide incident rate or a prediction about an individual office.

Is this drill a regulatory requirement?

No. It is an internal governance aid. Each family office should align its processes with its mandates, bank arrangements, jurisdictions and professional legal, regulatory, tax and cyber-security advice.

Source note

Primary source: Clearview Publishing, Family Wealth Report Family Office Cybersecurity Post-Forum Report 2026, published 9 July 2026. Independent survey context: Deloitte Private, The Family Office Cybersecurity Report, 2024. Competitor coverage: IFC Review, Singapore: Family Offices – The Risks Are Real.