Active extortion or breach? Call +1 212 457 9797 · Beware impersonation — we e-mail only from @dilendorf.com

AI Cyberattacks and Asset Protection Trusts: Who Bears the Loss?

AI Cyberattacks and Asset Protection Trusts: Who Bears the Loss?

Asset protection trusts (domestic and offshore) were designed to keep assets away from creditors.

In 2026, a different question is becoming just as important: can the trustee protect those assets from cybercriminals?

If a criminal gains control of the trust’s bank, brokerage, or custody account, who bears the loss? Does the trustee absorb that risk, or do the beneficiaries?

These issues are best addressed in the trust agreement from the outset. Waiting for a judge or arbitrator to determine responsibility after trust assets have been compromised is a far less desirable outcome.

Why the Question Matters Now

The threat to trust accounts is no longer theoretical. The federal agencies that track the evolving AI risks are measuring the timeline in months.

On June 22, 2026, the Five Eyes cyber security agencies, led by the National Security Agency (“NSA”), warned that:

“Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years, it is months. In this environment, cyber resilience is integral to advancing business continuity, market confidence, and long-term value” ([1]). [emphasis added]

The same statement calls cyber risk “a core business risk and leadership responsibility,” and a trustee holding a family’s liquid wealth is exactly the kind of leader it is addressing ([1]).

The Federal Bureau of Investigation (“FBI”) Internet Crime Complaint Center (IC3) recorded $20.877 billion in reported losses for 2025, including $3,046,598,558 from business email compromise and roughly 4,700 account-takeover complaints totaling $359.7 million ([2]).

Family offices and investment managers are exposed for a structural reason. Form ADV (including the adviser’s business, ownership, clients ) is published on the Securities and Exchange Commission’s (“SEC”) Investment Adviser Public Disclosure website. This is a public domain of who manages significant wealth ([14]).

What New York and Delaware Law Say

Neither New York nor Delaware imposes a specific statutory duty on trustee to safeguard trust accounts against cyberattack or account takeover. Both rely on general prudence standards that written before frontier AI existed.

New York. The Estates, Powers and Trusts Law (EPTL) § 11-2.3 requires a trustee to “exercise reasonable care, skill and caution” as “a prudent investor would,” judged by “facts and circumstances prevailing at the time of the decision or action” ([3]).

The section appears to apply to investments held on or after January 1, 1995. It does not mention anything about cybersecurity standards. It just says that: “A trustee shall exercise reasonable care, skill and caution to make and implement investment and management decisions as a prudent
investor would for the entire portfolio…” ([3])

Banking Law § 100 lists a trust company’s fiduciary powers without imposing any affirmative safeguarding duty ([4]).

In our arbitration practice, a trustee has taken the position that under the NY Banking Law § 100, a trustee does not have an express duty to safeguard trust assets against a foreseeable account takeover.

New York does, however, void any attempt to exonerate an inter vivos or testamentary trustee “from liability for failure to exercise reasonable care, diligence and prudence” ([5]). But the question becomes – what’s reasonable in the agentic AI era?

Delaware. Title 12, § 3302(a) requires a fiduciary to act “with the care, skill, prudence and diligence under the circumstances then prevailing that a prudent person acting in a like capacity and familiar with such matters would use” ([6]).

The section’s history note runs from the Delaware Code of 1915 through later amendments. None of the amendments added anything relating to cybersecurity, account security, or safeguarding ([6]). A prudent-person standard that was initially drafted in 1915 now has to be applied to AI cyber threats the NSA says is measured in months.

Delaware also lets the governing instrument “expand, restrict, eliminate, or otherwise vary” a fiduciary’s “standard of care, rights of indemnification and liability,” with a floor only at “wilful misconduct” ([7]).

A settlor who signs a trust-company form without reading that clause may have waived the right to recover a negligent cyber loss.

JurisdictionStandard of careMay the instrument reduce it?Express cyber or safeguarding duty?
New York“reasonable care, skill and caution” as a “prudent investor” ([3])Not below reasonable care; exoneration void ([5])None found ([3], [4])
Delaware“care, skill, prudence and diligence under the circumstances then prevailing” ([6])Yes, down to a wilful-misconduct floor ([7])None found, including in the Qualified Dispositions in Trust Act ([6], [9])

Regulation Is Not Private Risk Allocation

A regulated trustee’s cybersecurity rules protect the institution and its regulator, not the settlor’s trust agreement. New York’s 23 NYCRR Part 500 requires every “covered entity” licensed under the Banking Law to maintain a cybersecurity program and use multi-factor authentication ([11]).

Those duties apply to the NY Department of Financial Services (“NYDFS”), not to a beneficiary, and an individual or family.

As a matter of fact, grantor, beneficiary or family can’t even asset a claim against a trustee based on alleged violation of NYDFS cybersecurity standards. Part 500 does not provide a private right of action.

A separate question is what cybersecurity requirements apply to a foreign trustee. The answer will depend on the laws and regulatory framework of the trustee’s jurisdiction. This is is one of many considerations for those evaluating offshore asset protection trusts.

The bank owes less than clients expect. Under Uniform Commercial Code (UCC) § 4A-202(b), an unauthorized wire is effective as the customer’s order if the bank’s security procedure was “a commercially reasonable method of providing security against unauthorized payment orders” and was followed in good faith ([10]).

The trustee, not the bank, is often the first and last line of defense.

A Public Yardstick for Trustee Cybersecurity

Settlors do not need to be technologists to measure a trustee.

The National Institute of Standards and Technology (“NIST”) Cybersecurity Framework (CSF) 2.0 organizes cybersecurity outcomes into six functions, “GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER,” and is “designed to be used by organizations of all sizes and sectors” ([12]).

The Cybersecurity and Infrastructure Security Agency (“CISA”) ranks multi-factor authentication types from strongest to weakest, with phishing-resistant MFA a distinct category from text-message codes ([13]).

Before signing, a settlor should ask the prospective trustee, in writing:

  1. Who bears the loss if an account is taken over despite your controls?
  2. How much cybersecurity insurance does the trustee have?
  3. Which NIST CSF 2.0 functions does your program map to ([12])?
  4. Is phishing-resistant MFA required for everyone who can move trust funds ([13])?
  5. How is a distribution request verified out of band before a wire is released?

Putting It in the Trust Agreement

If the statute is silent, then the trust agreement should define how risk of risk of loss is allocated.

Depending on the jurisdiction, a trust agreement could impose an express duty on the trustee to safeguard accounts, credentials, and digital assets. It could also place the risk of loss arising from account takeovers to the trustee (which is a reasonable approach given today’s threat environment).

It is no longer unusual for a trust to name a cybersecurity adviser together the investment adviser and administrative trustee (especially true where cryptocurrency is part of the estate).

Delaware’s directed-trust statute allows the instrument to give a person authority to direct or veto a fiduciary’s “investment decisions, distribution decisions or other decision of the fiduciary” ([8]).

The instrument should also say where a dispute will be heard.

Under the Federal Arbitration Act, a written arbitration provision in a contract involving commerce is “valid, irrevocable, and enforceable” ([15]). Settlors commonly designate American Arbitration Association (AAA) or JAMS arbitration in a U.S. venue so that a negligence claim is not litigated first in the trustee’s home forum.

Offshore Trusts Raise the Stakes

An offshore trustee can be excellent at creditor protection, but still be unexamined on AI cyber risks.

A Cook Islands trust is governed by the International Trusts Act 1984 and its amendments through 2013, published by the Cook Islands Financial Supervisory Commission ([18]). Notably, U.S. persons who fund foreign trusts must report those transactions on Internal Revenue Service (IRS) Form 3520 ([17]).

We believe many foreign trustees are still working out what the Five Eyes statement means for their business; that’s provided they’re even ware of the NSA report.

The client’s job is to know (before funding the trust) what legal mechanism operate between settlor and trustee if something goes wrong, because no one wants to litigate a negligence claim in Rarotonga.

Existing Trusts Are Not Frozen

An irrevocable trust can often be updated.

New York’s decanting statute, EPTL § 10-6.6, allows an authorized trustee to appoint principal to a new trust for the same beneficiaries ([16]).

Depending on the circumstances, decanting could be used to update a legacy trust by adding specific cybersecurity provisions and allocating the risk of cyber-related losses.

If your asset protection trust is governed by the laws of Wyoming, Delaware, South Dakota, or another jurisdiction, we can help evaluate if decanting is appropriate. Our team, which includes retired IC3 cybercrime specialists, can help structure and transfer trust assets to a new trust designed to address modern cybersecurity risks (including agentic AI cyber threats).

How Dilendorf Law Firm helps

Dilendorf Law Firm PLLC has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM, including account-takeover and SIM-swap matters involving telecommunications carriers, cryptocurrency exchanges, and trust companies. That work, carried out alongside retired law enforcement and retired IC3 specialists, informs how the firm drafts domestic and offshore asset protection trusts for the age of AI cyber risk.

The firm drafts trust instruments with express safeguarding duties, cyber-loss risk allocated to the trustee, out-of-band verification for distributions, NIST- and CISA-benchmarked security schedules, cybersecurity adviser roles, and forum clauses. It conducts written cyber due diligence on prospective trustees, decants existing irrevocable trusts, and advises family offices, wealth managers, and investment managers on evolving risks.

Contact Us

To discuss a domestic or offshore asset protection trust, contact Max Dilendorf at +1 212 457 9797 or info@dilendorf.com.

This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.

Frequently asked questions

Can my trustee be held responsible if the trust’s account is hacked?

Possibly, but only if the governing law or the instrument imposes a duty the trustee breached. New York’s EPTL § 11-2.3 and Delaware’s § 3302 impose general prudence standards judged by circumstances then prevailing, and neither mentions account security ([3], [6]). An express safeguarding duty and risk-of-loss clause in the trust agreement removes that ambiguity.

What did the NSA and Five Eyes agencies actually say in June 2026?

They said frontier AI models will transform offensive and defensive cyber capabilities and that “the timeline is not years, it is months” ([1]). The statement frames cyber risk as a leadership responsibility rather than a technical issue, which is the standard a settlor should hold a trustee to ([1]).

Does Delaware law let a trust company limit its liability for a cyber loss?

Yes, within limits. Delaware § 3303 permits the governing instrument to vary a fiduciary’s standard of care and liability, but not to exculpate the fiduciary’s own wilful misconduct ([7]). A settlor should read the exculpation clause before signing.

Will the bank reimburse the trust for an unauthorized wire?

Not necessarily. Under UCC § 4A-202(b), an unauthorized payment order binds the customer if the bank’s security procedure was commercially reasonable and was followed in good faith ([10]). The trustee’s own controls therefore matter more than most clients assume.

What does it mean for a trustee to be NIST-aligned?

It means the trustee’s program maps to the six NIST CSF 2.0 functions: GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, and RECOVER ([12]). NIST designed the framework for organizations of all sizes, so a small trust company cannot claim it does not apply ([12]).

Is a regulated trust company automatically safe?

No. Rules such as 23 NYCRR Part 500 require covered entities to maintain a cybersecurity program and use multi-factor authentication, but those duties run to the regulator ([11]). They do not allocate a cyber loss between trustee and beneficiary; only the trust agreement does that.

Can an existing irrevocable trust add cybersecurity duties?

Often, yes. New York’s EPTL § 10-6.6 allows an authorized trustee to decant principal into a new trust for the same beneficiaries ([16]), and Delaware gives broad effect to instrument terms that vary fiduciary duties ([7]). Whether a specific trust qualifies depends on its terms and jurisdiction.

How should disputes with an offshore trustee be handled?

Decide before funding. A written arbitration clause is enforceable under the Federal Arbitration Act ([15]), and settlors commonly select AAA or JAMS arbitration in a U.S. venue. Without such a clause, a negligence claim may have to be brought in the trustee’s home jurisdiction.

How does Dilendorf Law Firm approach trustee cybersecurity?

The firm has been counsel of record in more than 130 cybercrime-related arbitration matters before AAA, JAMS, and NAM and drafts domestic and offshore trusts with express safeguarding duties, risk-of-loss allocation, security schedules, and cybersecurity adviser roles. It also conducts written cyber due diligence on prospective trustees before the client signs.

Sources

[1] National Security Agency, Five Eyes Cyber Security Agencies Statement (June 22, 2026). https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/

[2] Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 IC3 Annual Report, pp. 4, 6, 8, 12, 44. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

[3] N.Y. Estates, Powers and Trusts Law § 11-2.3 (Prudent investor act). https://www.nysenate.gov/legislation/laws/EPT/11-2.3

[4] N.Y. Banking Law § 100 (Fiduciary powers). https://www.nysenate.gov/legislation/laws/BNK/100

[5] N.Y. Estates, Powers and Trusts Law § 11-1.7 (Limitations on powers and immunities). https://www.nysenate.gov/legislation/laws/EPT/11-1.7

[6] 12 Del. C. § 3302 (Degree of care; authorized investments). https://delcode.delaware.gov/title12/c033/index.html#3302

[7] 12 Del. C. § 3303 (Effect of provisions of instrument). https://delcode.delaware.gov/title12/c033/index.html#3303

[8] 12 Del. C. § 3313 (Advisers). https://delcode.delaware.gov/title12/c033/index.html#3313

[9] 12 Del. C. §§ 3570–3576 (Qualified Dispositions in Trust). https://delcode.delaware.gov/title12/c035/sc06/index.html

[10] Uniform Commercial Code § 4A-202 (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/ucc/4A/4A-202

[11] N.Y. Department of Financial Services, 23 NYCRR Part 500 (Second Amendment, Nov. 1, 2023). https://www.dfs.ny.gov/system/files/documents/2023/12/rf23_nycrr_part_500_amend02_20231101.pdf

[12] National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0 (Feb. 26, 2024). https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf

[13] Cybersecurity and Infrastructure Security Agency, More than a Password (MFA). https://www.cisa.gov/MFA

[14] U.S. Securities and Exchange Commission, Investor.gov, Form ADV. https://www.investor.gov/introduction-investing/investing-basics/glossary/form-adv

[15] 9 U.S.C. § 2 (Federal Arbitration Act). https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title9-section2&num=0&edition=prelim

[16] N.Y. Estates, Powers and Trusts Law § 10-6.6 (Decanting). https://www.nysenate.gov/legislation/laws/EPT/10-6.6

[17] Internal Revenue Service, About Form 3520. https://www.irs.gov/forms-pubs/about-form-3520

[18] Cook Islands Financial Supervisory Commission, Legislation (International Trusts Act 1984 and amendments). https://www.fsc.gov.ck/public/content.aspx?cn=legislation

Discuss Your Matter

Confidential consultations by appointment.

Call us now Request consultation