← Blog

Blog  ·  June 2026

Ten Digital Habits to Never Normalize

The things we ask every client to stop doing, drawn from what goes wrong in private households, not from a textbook.

Most of the loss we see in private households does not come from sophisticated hacking. It comes from ordinary habits that everyone around the principal has quietly accepted as normal: convenient, familiar, and far more dangerous than they look. The list below is not theoretical. Each item is something we have watched cause real harm, and each one is avoidable.

1. Never move money on the strength of an email, a text, or a voice alone.

A wire, an investment transfer, a vendor payment, a property closing, a disbursement from the family office: confirm every one of them through a second channel you set up in advance, using a number you already have, never one supplied inside the request. The largest reported fraud losses in the country last year came from investment scams and from schemes that simply convince someone to move money. The mechanics are rarely technical. The message is just convincing, and the timing is urgent.

2. Never let a text message be the last lock on your most important accounts.

A code sent by SMS is better than nothing, but it can be intercepted or redirected through a SIM swap, and it does nothing to stop a well-built impersonation. Federal guidance is now explicit that text-message codes are not sufficient for people likely to be targeted. For primary email, banking, and investment platforms, use an authenticator app or a physical security key.

3. Never let one email account quietly run your entire financial life.

Primary email is usually the master key: it resets the passwords for banking, investments, cloud storage, travel, and legal documents. Whoever controls that inbox controls everything downstream of it. It deserves your strongest protection, and it should not be the same address you hand out at every counter and sign-up.

4. Never keep passwords in Notes, a spreadsheet, a photo, the browser, or a shared family document.

These are the first places an intruder looks and the easiest to copy all at once. The standard is a dedicated password manager, paired with a deliberate recovery plan and a documented way for the right person to gain access in a true emergency.

5. Never treat a spouse, assistant, house manager, bookkeeper, or advisor login as low-risk.

The people closest to your affairs are among the most common ways in, not because they are untrustworthy, but because their devices, inboxes, and recovery settings are rarely held to the same standard as yours. Their security is your security. Extend the same protections to everyone who touches the household.

6. Never act on urgency.

Pressure is the tell. Legitimate institutions do not require you to approve a login, release a payment, or sign a document within the next five minutes. Today's scams manufacture that urgency with fabricated documents, cloned voices, and convincing video. A pause to verify costs nothing. Acting in the moment is where the loss happens.

7. Never spread your private phone number and email across everything.

Charities, clubs, property records, political donations, company filings, social accounts, and old data breaches assemble over the years into a map, one that tells a stranger how to reach you and who you are connected to. The fewer places your private details appear, the smaller and less useful that map becomes.

8. Never ignore your account recovery settings.

A strong password protects nothing if the recovery email is an address you abandoned, the backup phone is a number you no longer hold, or the trusted contact is someone whose own account is weak. Attackers go around the front door through recovery far more often than they go through it. Check the back door yourself.

9. Never assume the phone in your pocket is the safe device.

It is now where most scams land, whether a text, a call, or a message inside an app, and people are measurably more likely to fall for them on a phone than at a desk. Verizon's most recent breach report found that scams delivered to mobile devices succeed at a notably higher rate than the same attempts sent by email. Give your phone the caution you give your computer, not less.

10. Never wait until something has happened to decide who to call.

The worst moment to assemble a response is in the middle of a compromised inbox, a fraudulent wire, a SIM swap, or an extortion attempt. Decide now who you call, in what order, and what the first hour looks like. That one decision, made in advance, is the difference between an incident and a disaster.

None of this requires technical skill. It requires deciding, once, that a handful of ordinary conveniences are not worth the exposure they create, and then holding everyone who touches your affairs to that same line.

If your family does not yet have a name to call when one of these comes up, that is the gap worth closing before a trigger forces the question.

← Blog