The Six Domains of Protection for High-Net-Worth Individuals

Written by Fabian RaemyReviewed by Jake JohnsonPublished July 29, 2026Last updated on August 10, 202619 min read
The Six Domains of Protection for High-Net-Worth Individuals
The Takeaway

Most protection plans handle one domain at a time. The gaps between them are where wire fraud, doxxing, and impersonation attacks actually happen…

High-net-worth individuals face six categories of risk that need to be managed as one connected system, not six separate projects: Digital Security, Privacy & Data, Identity & Finance, Residential, Travel & Mobility, and Family & Lifestyle. Each domain covers a distinct slice of exposure, from personal devices and email to public property records, wire transfer protocols, home networks, travel patterns, and household staff. The framework matters because of aggregation: a home address pulled from a property record, a spouse's name from a data broker profile, and a company role from a board filing cost an attacker nothing to combine, and combined they are often enough to stage a convincing wire fraud attempt or a targeted approach. Protecting one domain while leaving the other five open is exactly the gap a patient attacker is looking for.

Key Takeaways

  • Coordinated protection for high-net-worth individuals rests on six domains, Digital Security, Privacy & Data, Identity & Finance, Residential, Travel & Mobility, and Family & Lifestyle, because attackers routinely chain weaknesses across more than one domain to build a single attack.
  • Vendor email compromise now drives 61% of all business email compromise attacks, according to Abnormal AI's 2026 Attack Landscape Report, so the wire fraud attempt that succeeds usually looks like ordinary business, not an obvious scam.
  • Traditional identity fraud cost U.S. consumers $27.3 billion in 2025, with account takeover victims climbing to 6 million and new-account fraud victims climbing to 5.4 million, according to Javelin Strategy & Research's 2026 Identity Fraud Study.
  • Seventy-four percent of family businesses worldwide faced at least one cyberattack in the past two years, and only 43% describe their cybersecurity strategy as one that has never failed, according to Deloitte Private's 2026 Family Business Cybersecurity report.
  • Batten Black maps all six domains together through one dedicated advisor, closing the specific gaps between domains where most of these incidents actually originate.
$27.3BLost to identity fraud in the U.S., 2025
74%Family businesses attacked in the past 2 years
61%Of BEC attacks now start as vendor email compromise
41%Of executives targeted by deepfake impersonation

A founder who just closed a funding round, an executive promoted into the C-suite, a family that sold a business three years ago and has quietly built a portfolio of properties since. Each of these people carries more public surface area than they realize, and almost none of it was ever meant to be assembled into a single picture. A property record here, a board filing there, a spouse's tagged vacation photo somewhere else. Individually harmless, together a dossier.

Most security advice still concentrates on one domain at a time. A cybersecurity consultant hardens accounts and devices, a home security company installs cameras and access control, and a travel risk firm briefs an executive before a trip. Each does its own job well, and each stops precisely at the border of the next domain, which is exactly where an attacker's research does not stop.

The result is a familiar pattern among people with real assets to protect: a hardened corporate network paired with an unredacted property record, a strong home alarm system paired with a router anyone on the street can reach, a well-briefed business trip paired with a public calendar that tells a stranger exactly when the house will be empty. The gaps are rarely inside a single domain. They sit between them.

What "Six Domains" Means, and Why the Old Playbook Doesn't Cover It

For decades, protective security for wealthy families was framed almost entirely around physical layers: the property perimeter, the shell of the house, the interior "safe room," each reinforced with fences, cameras, and trained personnel. That model made sense when the primary threat was a physical intrusion and the primary tool was a guard force. It says almost nothing about a spoofed vendor email, a deepfaked voice call, or a data broker profile that hands a stranger your spouse's name and your children's school.

The threats that most commonly affect executives, founders, and wealthy families today are not physical confrontations. They are wire fraud built from a researched profile, identity theft that takes months to unwind, and impersonation attacks that use publicly available information a stranger should never have had access to. A perimeter fence does nothing to stop any of them.

Six domains replaces the old physical-only model with a framework built for how people are actually targeted now: Digital Security, Privacy & Data, Identity & Finance, Residential, Travel & Mobility, and Family & Lifestyle. Physical security still matters and lives inside the Residential domain, but it is one piece of six, not the whole picture. The domains are not independent categories to check off one at a time. They describe a single attack surface, viewed from six angles, and a strategy that treats them as unrelated leaves the connections between them completely unmanaged.

The Six Domains of High-Net-Worth Protection

Each domain below covers a distinct category of exposure. Read individually, none of them looks alarming on its own, which is exactly the problem: an attacker rarely needs to breach anything technical when the pieces they need are already sitting in six separate, unguarded places.

Select a domain to see what it covers

Digital Security

This domain covers personal devices, email accounts, and communications, the layer most people assume is already handled by whatever their employer's IT department provides. It usually isn't. Corporate security protects corporate accounts. It has no visibility into a personal Gmail account, a home Wi-Fi router, or a personal phone number that ends up in a breach dataset.

Personal email is still the most common entry point to financial accounts, legal systems, and family communications, because it is rarely monitored with the same rigor as a corporate inbox. Deloitte Private's 2026 Family Business Cybersecurity report found that 74% of family businesses worldwide faced at least one cyberattack in the past two years, with 33% hit two or more times, and only 43% describe their cybersecurity strategy as one that has never failed them. Separately, J.P. Morgan Private Bank's 2026 Global Family Office Report found that 32% of family offices now cite cybersecurity as their single greatest service gap, ahead of nearly every other operational concern. If your needs are still at the consumer-basics stage, a password manager and a VPN are a reasonable place to start, and Batten Cyber covers that ground well; six-domain coordination becomes necessary once a public profile raises the stakes beyond what those tools were built to handle.

Privacy & Data

This domain covers what is publicly findable about a person: property records, court filings, data broker listings, and breach exposure. None of it requires hacking, only a search engine and patience. More than 500 data brokers are registered in California alone, and the state's new Delete Request and Opt-Out Platform, live since January 2026, only binds brokers registered there. Anyone with a national footprint remains exposed everywhere else.

The mechanism matters more than the volume: a determined actor does not need to breach anything to build a target profile, only to aggregate what is already public. Removing a listing from one broker rarely stays removed. Data gets re-scraped, re-sold, and re-published, which is why one-time removal requests are structurally weaker than an ongoing, coordinated program, a distinction covered in more depth on our doxxing protection page.

Identity & Finance

This domain covers identity exposure, credit and account access, and the wire transfer and business email compromise protocols that stop a fraudulent instruction before money moves. It is the domain with the clearest dollar figures attached to it, and the numbers have not improved.

Javelin Strategy & Research's 2026 Identity Fraud Study found that traditional identity fraud cost U.S. consumers $27.3 billion in 2025, with account takeover victims rising to 6 million (up 18% from 2024) and new-account fraud victims rising to 5.4 million (up 31%). Sixty-four percent of fraud and identity professionals surveyed named AI-generated deepfakes as a top threat for the year ahead. On the business email side, Abnormal AI's 2026 Attack Landscape Report found that vendor email compromise now accounts for 61% of all business email compromise attacks, meaning the fraudulent wire request that gets paid usually arrives disguised as a routine vendor update, not as an obvious scam.

Residential

This domain covers each property a family owns: access control, perimeter integrity, and increasingly, the home network that every smart device in the house connects to. A smart lock, a camera system, and a router are all entry points now, not just conveniences, and few residential security plans treat them that way.

Research commissioned by BlackCloak from the Ponemon Institute has repeatedly found that home environments sit largely outside corporate visibility, with only a minority of organizations assessing the digital risk tied to an executive's home network. A property can have a monitored alarm system and an unmonitored router on the same wall, and the router is usually the easier way in. Residential protection has to account for both the physical perimeter and the digital one behind it.

Travel & Mobility

This domain covers pre-travel exposure, destination-specific risk, and the predictability that comes from a visible routine. A public calendar entry, a conference speaking slot, or a geotagged post from an airport does not need to be paired with anything sophisticated to become useful information. It tells a stranger where a person will be, and just as usefully, where their home will be empty.

Executives and principals with international footprints carry an additional layer of exposure most domestic-only security plans never address: destination-specific legal, political, and criminal risk that changes by country and by season. A briefing that covers where to stay says nothing about who might already know you're coming.

Family & Lifestyle

This domain covers the visibility of a spouse, children, and household staff, each of whom represents a separate entry point that does not require touching the principal directly. A child's school, a household manager's email, or a spouse's public social media account can open a path into a family's life that a principal's own security does the most to close everywhere else.

Deepfake-enabled impersonation is now the sharpest edge of this domain. BlackCloak's Ponemon-backed research found that deepfake impersonation attacks against executives rose from 34% of respondents reporting an incident in 2023 to 41% in 2025, and a newer Ponemon-commissioned study found that 42% of respondents say an executive or board member has already been targeted by a fake image or video, with 59% saying such attacks are very or highly difficult to detect. A cloned voice calling a family member with an urgent, plausible request is no longer a hypothetical.

Domain What It Covers If Left Unaddressed 2026 Data Point
Digital Security Devices, email, accounts, communications Account takeover, credential compromise 74% of family businesses attacked in past 2 years (Deloitte)
Privacy & Data Property records, data brokers, breach exposure Social engineering built from public data 500+ data brokers registered in California alone
Identity & Finance Identity exposure, wire protocols, BEC defenses Wire fraud, account takeover $27.3B lost to identity fraud in 2025 (Javelin)
Residential Access control, perimeter, home network Physical intrusion, network compromise Home networks remain largely outside corporate visibility
Travel & Mobility Pre-travel exposure, destination risk, pattern visibility Predictable routines, staged approaches Public schedules routinely expose travel windows
Family & Lifestyle Family visibility, staff, children's exposure Impersonation, indirect access to the principal 41% of executives targeted by deepfake impersonation (BlackCloak/Ponemon)

Why the Six Domains Cannot Be Assessed in Isolation

Consider an illustrative composite: a biotech founder, six months past a Series C announcement that put her name, her company, and her hometown into a wave of press coverage. Nothing about what happens next requires a data breach.

A data broker profile surfaces her home address, pulled from a county property record filed the year she bought the house. A separate broker links her name to her spouse's, whose own social media account is public and tags their children's school by name. Her company's funding announcement is still indexed with her title and a rough estimate of her equity stake. None of this required hacking anything, only combining three unrelated, freely available sources.

  1. 01
    Property record County filing
  2. 02
    Data broker profile Spouse & home address
  3. 03
    Funding announcement Title & equity stake
  4. 04
    Tagged social post Children's school
  5. !
    Exploitable profile Enough to attempt a wire fraud request or a targeted approach

Four unrelated, public data points. In sequence, they build a single exploitable profile.

The exploitation step is where the domains collide. An attacker with her name, her spouse's name, her home address, and a plausible reason to know her company's finances can now attempt a wire fraud request that looks like it came from her own attorney, or place a call to her assistant using a cloned voice built from a five-minute conference recording. In organizations the size of a typical family office, VIP impersonation already drives 43% of internal impersonation attempts, according to Abnormal AI's 2026 research, precisely because a principal's authority is highly visible and rarely double-checked.

Illustrative composite. All names and details are fictional.

This is the mechanism that a domain-by-domain approach misses. Three specialists, each doing their job well, would each have seen only a fraction of the picture:

  • A digital security consultant would have hardened her email and never seen the property record.
  • A home security company would have secured her house and never seen the data broker listing.
  • A travel risk firm would have briefed her next trip and never seen any of it.

Each was doing exactly what it was hired to do, and none of them was hired to see the whole picture.

Batten Black exists specifically to close that gap. Rather than coordinating separate vendors across six unrelated relationships, a single dedicated advisor holds the full exposure picture, prioritizes what matters most, and coordinates remediation with qualified specialists across every domain, one advisor, six domains, no gaps between them.

Book a Confidential Assessment Discreet. No obligation. Initial findings are typically delivered within two weeks.

Batten Black vs. the Alternatives

Most protection is still sold in pieces: an IT or corporate security team that stops at the edge of the office network, a monitoring platform that alerts after something has already gone wrong, or a close protection officer built for physical proximity risk rather than the digital and financial threats that affect far more high-net-worth individuals day to day. None of these is a bad option for what it is built to do. None of them was built to see all six domains at once.

Batten Black
IT / Corporate Security
Personal digital security
Full scope
Work accounts only
Data broker removal
Coordinated program
Out of scope
Residential security
All properties
Out of scope
Travel risk advisory
Pre-travel briefing
Out of scope
Family & staff risk
Full household
Out of scope
Dedicated human advisor
One named advisor
Team or ticket queue
Wire fraud / BEC protection
Structured protocol
Corporate accounts only
Batten Black
Monitoring Platform
Personal digital security
Full scope
Alerts only
Data broker removal
Coordinated program
Partial, automated
Residential security
All properties
Out of scope
Travel risk advisory
Pre-travel briefing
Out of scope
Family & staff risk
Full household
Out of scope
Dedicated human advisor
One named advisor
Automated
Wire fraud / BEC protection
Structured protocol
Alerting only
Batten Black
Close Protection
Personal digital security
Full scope
Out of scope
Data broker removal
Coordinated program
Out of scope
Residential security
All properties
Physical perimeter only
Travel risk advisory
Pre-travel briefing
Travel escort
Family & staff risk
Full household
Principal only
Dedicated human advisor
One named advisor
Named officer
Wire fraud / BEC protection
Structured protocol
Out of scope

A consumer identity protection subscription and a good home alarm system both have their place. Neither talks to the other, and neither was designed to notice that a wire fraud attempt and a spouse's public social media account might be connected. That connective layer, the advisor who holds the whole picture, is the actual gap in the market. Our Client FAQ walks through how this compares to specific alternatives, including digital-only platforms and close protection firms, in more detail.

When to Reassess Across All Six Domains

Exposure is not static. A single event can shift a person's risk profile overnight, moving them from a low-visibility private individual to a findable, financially visible target in the space of a news cycle. A handful of triggers are worth watching for specifically:

  • A liquidity event. A funding round, acquisition, or IPO puts a name, a net worth estimate, and a company in the same headline at the same time. Exposure after a liquidity event tends to spike far faster than most founders expect.
  • A new property purchase. Every additional address is a new public record, a new perimeter to secure, and a new data point that links back to the rest of the family.
  • A promotion, board appointment, or public role. New titles come with new public filings, new press mentions, and often a new corporate profile that did not exist the year before.
  • A change in family visibility. A child starting at a new school, a spouse launching a public-facing project, or a family member gaining a social media following all expand the household's attack surface.
  • A data breach at any company holding personal information. Breach datasets circulate for years, and a breached password reused elsewhere is still one of the most common paths to account takeover.

Family offices carry a version of this same challenge multiplied across principals, entities, and staff. Family office structures often have more exposed surface area than any single principal realizes, simply because the entities, properties, and household staff involved each add their own public footprint.

Quick Check: How Many Domains Do You Currently Have Covered?

Select what's currently addressed. This isn't a full assessment, just a starting picture.

0 of 6 domains currently addressed

Not yet addressed: Digital Security, Privacy & Data, Identity & Finance, Residential, Travel & Mobility, Family & Lifestyle.

Book a Confidential Assessment

Why Batten Black Coordinates Protection Across All Six Domains

Most high-net-worth individuals do not have a security problem in any one domain. They have six partial solutions that were never designed to talk to each other, and a growing public footprint that none of those solutions was built to see in full. That gap, not any single vulnerability, is what a coordinated attack actually exploits.

Batten Black was built around that specific gap. One dedicated advisor maps the full exposure picture across Digital Security, Privacy & Data, Identity & Finance, Residential, Travel & Mobility, and Family & Lifestyle, then coordinates remediation with qualified specialists and maintains ongoing oversight as circumstances change. You are not managing six vendor relationships. You have one advisor who already knows the full picture and who is accountable for keeping it current.

Book a Confidential Assessment Discreet. No obligation. Initial findings are typically delivered within two weeks.

Frequently Asked Questions About the Six Domains of Protection

What Are the Six Domains of Protection for High-Net-Worth Individuals?

Digital Security, Privacy and Data, Identity and Finance, Residential, Travel and Mobility, and Family and Lifestyle. Together they cover devices and accounts, public data exposure, financial and identity fraud, home and property, travel patterns, and household or family risk. Coordinated protection treats these as one connected picture rather than six separate problems.

Why Isn't a VPN or Antivirus Software Enough for a Wealthy Family?

A VPN and antivirus address a narrow slice of digital risk. They do nothing about a public property record, a data broker profile, a spoofed wire transfer request, or a child's exposed school affiliation. Wealthy families face threats that cross domains, and single-purpose tools were never built to see the whole picture.

How Is a Six-Domain Assessment Different From Hiring Separate Specialists?

Separate specialists each see one slice of the risk and rarely communicate with one another. The gaps between their work, not the work itself, are usually where an attacker gets through. A coordinated assessment maps all six domains together and assigns one advisor to hold the full picture.

Do I Need All Six Domains Addressed, or Just the Ones That Feel Urgent?

Most people underestimate at least one domain, often privacy and data or family and lifestyle, because the risk feels abstract until it is exploited. An assessment across all six domains typically reveals connections a person would not have found by focusing only on the domain that worries them most.

What Life Events Should Trigger a New Security Assessment?

A liquidity event, acquisition, or IPO, a new property purchase, a promotion or board appointment, a divorce or public family change, and a data breach at a company holding personal information all shift exposure quickly. Any of these is a reasonable prompt to reassess across all six domains.

Is This Only Relevant for People Who Have Already Had an Incident?

No. Most people who experience a serious incident, such as wire fraud or a doxxing attack, had no prior incident to warn them. Structured protection works best before an event, not in response to one, because recovery from identity theft or wire fraud is slow and often incomplete.

How Long Does a Six-Domain Assessment Take?

A thorough assessment covering all six domains typically takes about two weeks to produce initial findings, followed by a prioritized remediation plan. Some elements, like data broker removal, continue as ongoing processes rather than one-time fixes, with periodic reassessment as circumstances change.

Sources Used for This Article

  • Javelin Strategy & Research: "2026 Identity Fraud Study: The Illusion of Progress" - javelinstrategy.com/whitepapers/2026-identity-fraud-study-illusion-progress
  • Deloitte Private: "Family Business Cybersecurity, 2026" - deloitte.com/global/en/about/press-room/family-business-cybersecurity-2026.html
  • J.P. Morgan Private Bank: "2026 Global Family Office Report" - privatebank.jpmorgan.com/nam/en/insights/reports/2026-family-office-report
  • Abnormal AI: "2026 Attack Landscape Report" - abnormal.ai/newsroom/press-releases/2026-attack-landscape-report
  • BlackCloak / Ponemon Institute: "Digital Executive Protection Report 2025" - blackcloak.io/news-media/ponemon-institute-report-escalating-attacks-targeting-corporate-executives-point-to-urgent-need-for-digital-executive-protection
  • IAPP: "CPPA Board Approves Data Broker Regulations" - iapp.org/news/a/cppa-approves-data-broker-regulations

Related

Fabian Raemy
Fabian Raemy
Editor - Batten Black

Fabian Raemy is the editor of Batten Black, covering cybersecurity, home protection, and emergency preparedness with a research-first approach grounded in real-world risk analysis.

Jake JohnsonReviewed for accuracy by Jake Johnson, Co-Founder & Chief Operating Officer, Batten prior to publication.

Get Started

Your exposure is real, whether you've assessed it or not.

A confidential assessment maps it across every domain and shows you exactly what to do next.

Book a Confidential Assessment