Protecting your assets is a central part of any wealth management strategy. While most of us may plan for the usual threats, taking precautions such as installing home-security systems and working with trusted advisers, not all of us are vigilant about the possibility of cybercrime.
Cyber crime in the UK is estimated at £27 billion per year. There were some 1.23 million instances of "computer misuses" in the 12 months ending July 2018, according to the Office for National Statistics. And, according to the Cyber Security Breaches Survey 2018, two out of five businesses experienced a cyber attack in 2017.
In a 2017 Campden Research study, 38 percent of ultra-high-net worth (UHNW) families, family offices and family businesses internationally, with an average wealth of US$1.1 billion (£830.4 million), reported they didn't have a cyber security plan in place.
If you fall into that category, you could potentially be more vulnerable to an attack by savvy cyber thieves.
"Hackers that target high-net-worth individuals (HNWIs) have done their homework," says Stacy Bertrand, manager of information security strategy and metrics at City National Bank, an RBC company. "They know they have money and that they have something to steal."
But it's not just financial resources that make these families more vulnerable to a cyberattack. It's also often their public status and lifestyle choices that may make them more susceptible.
Lifestyle cues used for social engineering attacks
Social engineering involves the use of public records and social media to mine your information. Hackers can gain clues about wealth, property ownership and investments by analysing public records, such as the Land Registry and Companies House, and gain further detailed insight by scanning through details that individuals chose to share on social media.
As cybercriminals expect a higher pay-off when attacking high-net-worth individuals, they invest greater resources in attacks. “We are seeing the use of increasingly sophisticated techniques and tools comparable to those used by intelligence agencies and in corporate espionage," says Mohammed Marikar, Director of Intelligence & Automation at RBC in London. “The personal information gained is then used to mount further attacks against the victim, close friends and family, and members of their financial team. While failing to install security updates on your smartphone makes you more vulnerable, extracting information through plain old telephone impersonation is still very common."
Setting ground rules for social media use with your family members can be an effective way to combat the social engineering threat. For instance, you may wish to restrict the types of photos or location information shared through social media, or insist family members use privacy settings to restrict visibility to family & friends, or require new followers to be approved. “But don't let your privacy settings lull you into a false sense of security," says Marikar. “Your information is only as secure as your least-secure contact.'
There are indications UK citizens aren't taking the threat seriously enough. According to the 2018 government report “A Call to Action: The Cyber Aware Perception Report", a large section of the public and small business community underestimate the risk of cyber crime and don't feel there's much they can do about it. As as a result of this, millions are leaving themselves vulnerable to cyber attack.
Public status adds risk
In general, says Bertrand, high-net-worth individuals (HNWIs) are more searchable online. Someone who owns a company, holds a C-suite position, frequently makes large donations to charity or is a public figure has a highly-visible online presence, making it easier for cyber thieves to profile them as potential victims.
"Hackers are able to perform sophisticated spear-phishing attacks with the information they receive from searching the internet," says Bertrand. Spear-phishing involves the use of fake emails which lure you into clicking a link, downloading a file or sharing sensitive personal or financial information that can be easily exploited.
Phishing emails can be used to infect computers with malware and to guard against this type of risk, it's always best to take the "better safe than sorry" approach and pick up the phone to verify the email is actually coming from the person you believe it is.
Lack of centralisation can make cyberattacks easier
Having a broad network of people who aid in managing your wealth can also be a boon for hackers.
"Typically, clients we work with have a financial team," says Bertrand. "Because more people are potentially involved managing various aspects of your financial plan, hackers have more wiggle room to build convincing stories that do not need to be verified."
Bertrand offers two tips for protecting yourself when you have a larger team, or widespread assets.
First, "high-net-worth individuals need to develop a 'trust but verify' process," she explains. "This means that people or companies who work with these individuals need to know what they're allowed to approve and what they need to call and verify." In the best-case scenario, employees should verify all emails and phone calls with you prior to transferring money.
The second tip is to understand where your assets are held. You don't necessarily need to aggregate all your assets in one place but you should have visibility and transparency with regard to where your accounts are located and what's in them.
High-net-worth households have the means to pay
The use of ransomware—a software program which blocks access to systems or data until a ransom is paid—also poses a threat to HNWIs and, while businesses are often the target, individuals and family offices aren't immune.
Because HNW households have the resources to pay the ransom, cyber thieves are betting many of these individuals would prefer to pay up rather than dealing with a locked computer.
Preventing ransomware begins with protecting your personal and financial details and ensuring basic security practices are followed down the line by employees and any other individuals who have access to your information.
Luxury locations are a target for wireless spoofing
When you're traveling, you may find yourself using public and open wireless networks or hotspots to get online. But these networks are particularly unsecured, even when they require a password. Hackers are taking advantage of this fact and targeting luxury hotels and airport lounges where they know HNWIs will be using their laptops and phones.
Never log in to password-protected websites that contain sensitive data, such as your bank accounts, social media channels or email, when using public Wi-Fi. If you need to use a Wi-Fi hotspot, consider using a virtual private network (VPN) to secure your connection.
Recognising and understanding the various ways in which you may be a target of cyber fraud is an important step in protecting your assets. With this knowledge you can have a conversation with the professionals who are managing your assets to ensure they're properly equipped to identify and handle a cyber threat. You'll also be able to take your own precautions so you don't unknowingly make it easy for a cyber thief to target you.
This article originally appeared on CNB.com. City National Bank is an RBC company. This report is for general information and education only and was compiled from data and sources believed to be reliable. City National Bank does not warrant that it is accurate or complete, nor does City National Bank represent that the information provided, if followed, will provide a complete safeguard of your information. City National Bank maintains security procedures designed to help prevent unauthorized access to your accounts and your information.