National Capital RegionVA DCJS License No. 99-613042
Deetz Consulting

File 03. Family Office

Residence, staff, and the perimeter that does not exist on the floor plan.

Why most residential security failures originate not at the gate, but in domestic staffing, vendor access, and unexamined daily routines.

January 29, 202610 min read

When a family-office principal commissions a residential security review, the document they receive most often examines the perimeter. The walk-through covers the gate, the fence line, the entry control system, the camera placement, the alarm coverage, the safe room, the panic button. Each of these elements is reviewed in turn, scored, and graded. The report is dense, photographed, and competent. It is also, in a meaningful percentage of cases, addressed to the wrong problem.

The wrong problem is not the perimeter. The perimeter is what every residential security review examines, and consequently it is what every well-resourced principal has already addressed. Walls are tall. Gates are functioning. Cameras have coverage. Alarms are monitored. The perimeter is rarely where contemporary residential security failures occur — at least not at the principal level the firm advises.

The failures occur, instead, in three places the floor plan does not show.

— I. Domestic staff.

The single highest source of residential security risk for principals at the family-office level is the domestic staff. This is not a controversial claim within the protective profession; it is the routine experience of anyone who has reviewed enough residential incidents. It is, however, deeply uncomfortable to discuss with principals, because it touches the most intimate trust relationships in their lives.

The risk is not, primarily, malicious. Staff who deliberately exploit access are real but uncommon. The risk is, far more often, structural: staff have credentialed access, intimate knowledge of routines, ongoing exposure to vendors and contractors, and the trust to be unexamined. Each of these is appropriate to their function. The aggregate of the four, applied across years of tenure, produces an information surface that any sophisticated threat actor would not have to penetrate the perimeter to acquire. The information is already outside.

Three governance practices reduce this risk without compromising the relationships of trust the principal depends on:

Initial background investigation at a level appropriate to the access granted — not the title given. A nanny with the children's daily routine and the alarm codes warrants the same diligence as a financial assistant with banking access. The two roles look different. The access profile is comparable.

Periodic re-screening on a defined cadence. Most household staff are background-checked once, at hire, and never again. The threats that develop in someone's life over five years of employment — financial distress, a new relationship, a substance issue, a vulnerability to social engineering — are not visible in the original screen.

A defined separation protocol. The departure of a household staff member is the single highest-risk operational event in residential security, and most family offices have no written procedure for it. Credentials must be changed. Access must be revoked. Communications protocols must be updated. The principal's family, who often have the relationship with the departing staff member, must be briefed appropriately. None of this is theoretical. It must be done, on a schedule, with documentation.

— II. Vendor and contractor access.

The second blind spot is the vendor footprint. A principal residence at this level is supported by an ongoing rotation of vendors — landscapers, pool service, HVAC, electricians, plumbers, deep cleaners, painters, alarm and IT technicians, deliveries, caterers for events, photographers, occasionally journalists, occasionally tutors, occasionally medical visits. The aggregate of these visits, in a typical month, produces dozens of access events. Most are repeating relationships. Most repeat relationships are not formally vetted at the level the access warrants.

The vulnerability is two-part. First, the individual technicians who arrive — even from a reputable firm — are not the people who were vetted by the firm at the corporate level. The HVAC company hired a new technician last month; the new technician now has interior access to the residence; the residence's records show only that "HVAC" arrived. Second, the operating norm in most residences is that the vendor is supervised informally by staff who are themselves doing other tasks, which means the vendor's actual access — to drawers, devices, rooms, and people — is functionally unbounded during the visit.

Three modest disciplines address this. A vendor log that records the individual present, not the firm. A standing relationship with the firms supplying recurring service that includes their commitment to provide background-screened personnel and to notify of any change. And a supervisory norm that places a single household staff member with the vendor for the duration of the visit, not as a function of distrust but as a function of operational hygiene. These three together reduce the vendor risk surface significantly. None require building a wall.

— III. Routines.

The third blind spot is the most consequential and the least addressed: the principal's own routines. A principal residence's security posture is shaped almost entirely by what the principal and their family actually do — when they arrive, when they leave, what door they use, what time the children are picked up, which staff sees what, which vendor enters during which hour, which window is left open in the summer, which delivery driver is now familiar enough not to be asked for identification.

Routines accumulate. They are not designed; they emerge. They are entirely invisible on the floor plan. They are, from a threat actor's perspective, the most useful surface a residence presents — because routines are predictable, exploitable, and almost never reviewed. A camera at the front gate captures a great deal. It does not capture the fact that the principal's morning car always leaves at 7:42, that the rear gate is opened for the gardener every Wednesday at 9:00 a.m., or that the housekeeper's shift change at 4:00 p.m. is the one ten-minute window in which the residence's entry control is operationally unsupervised.

A residential security review that does not examine the family's actual operating routines — over a sustained observation window, in conversation with the principal and the people who manage the household — has not, in any meaningful sense, examined the residence. It has examined the floor plan.

— IV. A different review.

A residential security review oriented toward the three areas above looks different from the perimeter-focused report that most family-office principals have received. It is shorter on photographs of fences and longer on conversations with staff. It includes a routines map — derived from observation and interview — that the principal can see in writing for the first time. It includes a staff access matrix that, in most cases, surfaces accumulated access privileges no one was tracking. It includes a vendor inventory the household has never previously consolidated.

None of this is exotic. It is the federal-protective discipline of advance, applied to a permanent residence rather than to a visiting venue. The discipline assumes that the perimeter has been competently addressed, then asks the harder question — which is whether the operating reality inside the perimeter is consistent with the principal's actual exposure.

In a meaningful share of the residences we have reviewed, the answer to that question is: not yet. The principal is not in danger. The arrangements have not been catastrophic. But the residence's operating reality has drifted away from its perimeter design, slowly, over years, in ways no member of the household has reviewed because the review of the perimeter was the review they were trained to expect.

The work of a credible residential security advisor is to draw the operating reality back into the perimeter's frame — and to write it down, so that the principal and the household can see it.

David O. Deetz, Jr., Founder & Principal Advisor

David O. Deetz, Jr.

Founder & Principal Advisor · Deetz Consulting, LLC

Former U.S. Secret Service Special Agent in Charge of the Inspection Division. Former Senior Director of Enterprise Corporate Security at Trellix & Skyhigh Security. U.S. Marine Corps Counterintelligence veteran with thirty-five years in protection, investigation, and corporate security across federal and private sectors.

For matters where the cost of error is not measured in dollars.