Sector study · scan of 28 September 2026
How UK Family Offices Look to an External Scan
A September 2026 baseline of 132 UK family-office websites, scanned from the outside using only what anyone on the internet can see.
81 of 128
cannot tell mail systems to refuse email forged in their name
45
publish no usable email policy at all
5
have a database product answering the internet
60.7
average exact score out of 100
What we found
Eighty-one of the 128 family offices reported, 63%, do not instruct receiving mail systems to refuse or spam-file email forged in their name, and 45 of them publish no usable instruction at all. Only 20 instruct outright refusal. A family office exists to act on written instructions to move family money, which is exactly what a payment-redirection fraud imitates. The setting costs nothing to publish, and 122 of the 128 have already done the groundwork by publishing a record naming which servers may send their mail.
Fifteen firms have a risky port answering the internet that counts against the firm. On five of them a database product was identified, and all five sit on shared hosting servers that also carry other organisations’ websites. A further 12 cases sit on shared provider addresses with nothing identified, and are reported separately because only the provider can confirm or close them. Twenty-six of the 27 cases include a file-transfer login, so most of this is one question for a handful of hosting providers.
Four firms report a software version matching a flaw on the public list of those being exploited. The one to check first is an Apache web-server flaw that can expose files and, in some configurations, allow code to run. Two are a flaw that can only take a website offline, and one concerns code delivered to visitors’ browsers. One firm is named on ransomware leak sites by three different groups. A listing is a criminal group’s own claim and needs matching to the right entity and date before anyone draws a conclusion.
Stolen passwords are the surprise. The criminal credential collections returned no staff account records and no client account records for any of the 128 firms, and just five single records for staff identities on other platforms. That reflects small offices with few staff and no client portals rather than proof of safety, and it says nothing about the personal email accounts and personal devices that family-office work often runs through.
There is good news too. No firm carries a known-breach record or a browser safety warning, certificates are in good order with a single fault across all 128, and 113 accept only modern encryption.
How to read the scores
113 firms have an exact score, averaging 60.7, against 71.2 for the UK wealth managers in our report of 1 October. Eleven reach the good band of 75 or more and 18 sit in the at-risk band below 50. Fifteen have a floor score, because their website turned an automated visitor away, which is a security control working rather than a fault. Counting those at their floor, the average across all 128 is 59.5. Four websites produced no usable score and are excluded.
What this is, and what it is not
We looked at each firm’s website from the outside, the way any client could. We did not log in anywhere, try any password or exploit anything. Nothing here means a firm has been broken into, nothing here is a compliance judgement, and the report names no firm. Many single family offices sit outside FCA regulation, and the report makes no claim about any firm’s regulatory status.
Where to start
List every system that sends email in the office’s name, then publish an email policy that moves from monitoring to spam-filing to refusal. Ask the hosting provider which ports are meant to be reachable, and close file transfer or enforce encryption on it. Confirm the software version behind any known-exploited match, starting with Apache. Publish a short vulnerability disclosure policy so anyone who finds a problem can report it privately.
Read the full report
Download the full report (PDF, 23 pages)See how a domain looks to an external scanThis analysis was produced with MyDomainRisk, a product of Huro Data Technologies Ltd, which has a commercial interest in it. It is not independent certification, an audit, or legal or regulatory advice.