The cybersecurity discussion that most divorce financial professionals have heard is about protecting the practice — FTC Safeguards, E&O insurance, ransomware preparedness. The cybersecurity discussion that almost no one has with clients is about protecting the client during the separation period itself. Divorcing individuals are statistically more vulnerable to both physical and digital theft than the general population, and the elevated risk extends through the entire separation process and into the post-divorce adjustment period. A client who emerges from a divorce financially intact but with their identity compromised, their accounts drained, and their credit destroyed has lost much of what the divorce was supposed to preserve.

The research literature on the elevated risk is consistent. Separation and divorce produce sustained psychological stress, including significantly increased risk of depression and other forms of distress. The same research that documents the elevated psychological vulnerability also documents correlations between psychological distress and exposure to theft — both physical theft and digital theft. The mechanism includes both the divorcing individual’s reduced vigilance during a period of acute distress and the structural changes (new addresses, new accounts, disrupted household security routines) that create vulnerabilities the prior household arrangement did not.

What follows is a working guide for Divorce Financial Coaches, family lawyers, and divorce coaches on the security awareness conversation they should be having with clients during separation. It covers why divorcing clients are at elevated risk, what security awareness actually means in practical terms, the three factors that determine whether security awareness translates into secure behavior, the specific vulnerabilities the separation period creates, and the operational steps clients can take to protect themselves through the transition.

Why separation increases vulnerability.

Research has shown that separation and divorce have strong negative consequences for the mental and physical health of both spouses, including increased risk of psychopathology. The increased psychological vulnerability — depression, anxiety, situational disorders, in some cases more severe psychological conditions — produces concrete behavioral changes. Clients become less attentive to email, less careful about clicking links, less rigorous about verifying communication, less attentive to bank and credit card statements, and less consistent about applying their normal security habits.

Multiple studies have documented correlations between psychopathology and theft crime, with mechanisms including interpersonal and affective traits, mental health predictors like depression and psychoticism, and comorbid disorders like bipolar disorder and addictive behavior. The research does not suggest that divorcing individuals become criminals; it suggests that the population intersection of psychological distress and elevated theft risk is real. Divorcing individuals are more likely to be victims of theft (both physical and digital) than the general population.

The structural changes during separation amplify the elevated risk. New addresses produce mail-delivery confusion that creates opportunities for identity theft. The split of household financial accounts produces a period during which neither spouse may be monitoring certain accounts effectively. Joint passwords and security questions that both spouses knew become vulnerabilities — one spouse may have malicious intent, may share passwords with someone who does, or may simply have stored passwords insecurely. The household-level security routines that worked because both spouses were paying attention may continue to be assumed when in fact no one is actually paying attention to a given account.

The elevated risk extends to financial accounts specifically. Approximately ninety-five percent of payments in the United States are now digital, according to the World Bank Group’s 2022 research. McKinsey & Company’s 2022 research suggests that the percentage of U.S. adults using digital payments is approximately eighty-nine percent. The shift to digital financial activity means that financial security is primarily a function of digital security. A client whose digital security degrades during the divorce period has effectively lost the security of their financial accounts.

What security awareness actually means.

Security awareness is defined in the technical literature as the individual’s ability to recognize and avoid actions that threaten cybersecurity and to act wisely — based on informed knowledge — and responsibly to improve cyber safety. The definition has three components: recognizing threats, avoiding actions that produce vulnerability, and acting positively to improve security.

Research consistently shows the critical role of security awareness in promoting good security practices. A 2019 study found that 61.2% of the variability in security behavior could be explained by threat awareness and countermeasure awareness — the two components at the core of security awareness. The implication is that the practical difference between secure behavior and insecure behavior is largely the question of whether the individual is aware of the relevant threats and of the available countermeasures.

Security awareness is the upstream factor that drives the downstream behaviors. Awareness produces the willingness to adopt protective technologies (multi-factor authentication, strong passwords, virtual private networks, encrypted communication). Awareness produces the discipline to verify communications before acting on them. Awareness produces the recognition of suspicious activity in time to respond before damage compounds. Without awareness, even the best security technologies sit unused and the most rigorous security policies are violated routinely.

The motivation problem — why awareness alone is not enough.

Security awareness does not automatically produce secure behavior. The gap between knowing and doing is significant in cybersecurity as in most other domains of human behavior. The Protection Motivation Theory (PMT) framework, originally developed for health risk prevention and subsequently applied to digital security, specifies three components that determine whether awareness translates into action: the impact of the event, the probability of the event transpiring, and the efficacy or self-perceived ability of the individual in protecting themselves from the event.

Applied to divorcing clients, the three components break down as follows. The impact of an identity-theft or account-compromise event during separation is substantial — financial loss, credit damage, prolonged disruption to the already-stressed divorce process, potential exposure of sensitive information to the other party. Most clients understand the impact intellectually but underestimate it emotionally.

The probability of an attack during separation is meaningfully higher than during periods of stable household operation, although most clients do not know this. Most people hold two errant views: that they are not the target of any attacker, and that they know enough about security. Both views are demonstrably wrong, particularly during separation.

Self-efficacy — the client’s perceived ability to protect themselves — is often low during the divorce period because the client is dealing with so much else. The client may believe security is something they should be doing but feel they cannot take on more in the current period. The self-efficacy problem is the most common reason that security awareness fails to produce secure behavior during separation.

The practitioner’s role in addressing the motivation problem is to make the security actions feel both important enough to do and feasible enough to actually do. Important without feasible produces guilt without action. Feasible without important produces casual response to a serious threat. Both important and feasible is the combination that produces actual security improvement.

The three pillars of security awareness for divorcing clients.

The development of security awareness for divorcing clients comes down to three operational factors.

First, the client must understand that security awareness is important specifically during the separation period. The general statement that security matters is not enough; the client needs to recognize that their personal risk profile during separation is elevated and that the actions they would normally rely on (the other spouse handling security, the household routine providing protection, the established habits being adequate) are no longer sufficient. The framing of “this is the period during which you specifically are at elevated risk” produces a different response than the general security-matters framing.

Second, the client must use reliable sources to gain security awareness. The internet has substantial content about cybersecurity, much of it produced by marketing teams selling products rather than by qualified educators. The client should rely on research-based sources — government resources from the Cybersecurity and Infrastructure Security Agency, established educational programs from credentialed bodies, materials from professional cybersecurity organizations — rather than blog posts and YouTube videos of unknown provenance. Practitioners can point clients to specific reliable sources.

Third, the client must implement changes in their practices and processes. Awareness without implementation produces no security improvement. The implementation needs to be concrete: new passwords on every account, multi-factor authentication enabled where available, account alerts configured, monitoring services subscribed to, specific behaviors changed. The client cannot just “be more careful” — they need to make specific operational changes to their digital and financial life.

What clients should learn about security.

A working security education for divorcing clients should cover three domains.

Security concepts. The client should understand the principles of digital security and the common threats they may face. The threats most relevant during separation include phishing (deceptive communications designed to trick the recipient into disclosing credentials or installing malicious software), credential stuffing (the use of stolen credentials from one breach to attack other accounts), account takeover (gaining control of an account through compromised credentials), identity theft (using personal information to open new accounts or commit fraud in the client’s name), business email compromise (impersonating a trusted contact to direct the recipient to transfer funds or provide sensitive information), and physical theft from disrupted households or unsecured new addresses.

Security solutions. The client should understand the conceptual workings of available security tools and technologies — what they do, what they protect against, where they fall short. Multi-factor authentication adds a verification step beyond the password. Virtual private networks encrypt internet traffic from the device to a remote server. Password managers generate and store strong unique passwords for each account. Encrypted email services prevent interception of email contents. Credit monitoring services alert to changes in credit reports. Identity protection services monitor for use of personal information in fraudulent contexts.

Secure actions. The client should develop practical abilities in the use of security tools and technologies. The conceptual understanding without the practical skill produces clients who know they should use a password manager but never set one up. The practical skill development requires actually walking through the setup of the protective tools, not just describing them.

Specific vulnerabilities the separation period creates.

Seven specific vulnerabilities recur in the separation period. Each warrants explicit attention in the security conversation with the client.

Shared passwords. Joint accounts, shared streaming services, joint cloud storage — every account where both spouses knew the password is now a vulnerability. Each password should be changed, and the client should consider whether the account itself should be transitioned to sole ownership or closed. The other spouse may not have malicious intent, but they have the credentials and they have access. Future use of that access by them, by someone they share credentials with, or by someone who compromises their account, is now a vector for damage.

Security questions with answers the other spouse knows. Mother’s maiden name, first pet’s name, name of first school, address of first home — the standard security questions used by banks and other services typically have answers that a long-married spouse knows. These are no longer secure for the divorcing client. Most services allow security questions to be changed; the client should update them to questions with answers the other spouse does not know, or use random strings stored in a password manager.

Mail delivery to the marital home. Bank statements, credit card statements, brokerage statements, tax documents, and other financial mail typically arrives at the marital home. After separation, the client may have moved out but the mail continues to arrive at the marital home, where the other spouse has access. The client should change the address of record on every account to their new address, and should consider going paperless for accounts that support it.

Devices and accounts the other spouse may have access to. Shared tablets, family computers, family iCloud or Google accounts, family email accounts. Each may have lingering access for the other spouse even after physical separation. The client should audit every device and every account they use and remove access for the other spouse explicitly.

Information shared with the other spouse over years. Social Security number, date of birth, driver’s license information, bank account numbers, passwords (even if changed), prior addresses, family member information. The other spouse has this information whether or not they choose to use it. The client cannot un-share the information but can take protective measures — credit freezes at the three bureaus, identity protection monitoring, careful attention to new account opening alerts.

New accounts the client opens during the separation period. Each new bank account, credit card, brokerage account, and online service the client opens during separation produces a new credential to manage. The client should use a password manager to generate and store unique strong passwords for each, and should enable multi-factor authentication on every account that supports it.

Direct interactions with the legal and financial professionals on the case. Email exchanges with the lawyer, the Divorce Financial Coach, and other professionals contain sensitive personal and financial information. If any of those professionals is compromised, the client’s information is exposed. The client should engage with professionals who use secure communication channels and who can demonstrate appropriate handling of client information.

Practical actions for the separation period.

Six concrete actions produce meaningful security improvement during separation.

First, change every password on every financial account. Use a password manager (1Password, Bitwarden, and Dashlane are mainstream options) to generate strong unique passwords for each account and store them securely. The same password should never be reused across accounts, particularly financial ones. The change should happen as soon as separation is contemplated, not after it is completed.

Second, enable multi-factor authentication on every account that supports it. The authentication should use an authenticator app (Google Authenticator, Microsoft Authenticator, Authy) or a hardware key rather than SMS where possible — SMS-based authentication is vulnerable to SIM-swap attacks. The setup takes minutes per account but produces substantial security improvement.

Third, pull credit reports from all three bureaus and place security freezes on each. Credit freezes prevent new accounts from being opened in the client’s name without the client first unfreezing the credit. The freezes are free under federal law, can be lifted temporarily when the client needs to apply for new credit themselves, and prevent most forms of new-account identity theft. The freezes should remain in place throughout the separation period and beyond.

Fourth, subscribe to identity monitoring and credit monitoring services. The monitoring detects new accounts opened in the client’s name, changes to credit reports, use of the client’s personal information in suspect contexts, and other indicators of identity theft. Free services from each credit bureau provide basic monitoring; paid services aggregate across bureaus and provide more comprehensive monitoring. Either is meaningfully better than no monitoring.

Fifth, update addresses of record on every account to the client’s new address (not the marital home). The update applies to bank accounts, credit cards, brokerage accounts, insurance policies, employer records, IRS records, Social Security Administration records, driver’s license, vehicle registration, and any other account where mail might be delivered. The address change at the United States Postal Service through their official process should be a first step but should be supplemented by direct updates to each account.

Sixth, use encrypted communication channels for sensitive information. Secure messaging apps (Signal, encrypted iMessage between Apple devices) are appropriate for sensitive conversations. Encrypted email services (ProtonMail, Tutanota) are appropriate for sensitive email correspondence. The client should avoid sending sensitive information (account numbers, Social Security numbers, copies of financial documents) over unencrypted email or text message.

The role of the practitioner.

The Divorce Financial Coach, family lawyer, and divorce coach are not typically the right professionals to provide deep technical security education. The role they are well-positioned to play is to surface the importance of security awareness during separation, to point clients to reliable educational resources, and to ensure that the operational practice they themselves use does not introduce vulnerabilities for the client.

The reliable educational resources include the Cybersecurity and Infrastructure Security Agency’s consumer-facing resources at cisa.gov, the National Institute of Standards and Technology’s consumer guidance, the Federal Trade Commission’s identity theft resources at IdentityTheft.gov, and structured educational programs that have been independently validated. Specific certification programs that focus on consumer-level security awareness — including the CyberSecure certification developed by the American Academy of Cybersecurity Professionals based on extensive research — provide structured education for clients who want a deeper engagement than the general guidance provides.

The practitioner’s own operational practice matters because the practitioner is handling client information that is itself sensitive. A practitioner whose own communication channels are insecure, whose document handling is loose, or whose security posture is weak produces vulnerability for the client regardless of what the client does on their own side. The companion piece on cybersecurity and FTC Safeguards for Divorce Financial Coaches addresses the practice side in depth.

How VennBoard supports secure client engagement.

The practical translation of security awareness into protected client engagement requires infrastructure. The practitioner cannot just intend to communicate securely; they need the tools that support secure communication. The client cannot just intend to handle documents carefully; they need the tools that support careful document handling.

VennBoard provides a secure shared workspace between the practitioner and the client. Documents upload to the matter workspace rather than being attached to email; the workspace uses encryption in transit and at rest, with role-based access controls and audit logging. The matter communications channel between practitioner and client lives inside the workspace rather than in email, eliminating one of the most common vectors for compromise. Multi-factor authentication is enforced for practitioner access, and the platform supports it for client access as well.

Two operational features matter most for client-side security. The immutable messaging log captures all practitioner-client correspondence within a secure platform rather than across mixed channels (some email, some text, some calls), reducing the surface area where compromise can occur. And the audit logging of all document access produces visibility into whether the client’s documents have been accessed by anyone other than the authorized parties, providing both reassurance and the detection capability that supports an effective response if compromise does occur.

Security awareness without supporting infrastructure produces guilt without protection. VennBoard exists to make the secure version of the engagement operationally simple enough that clients and practitioners can actually use it consistently. Professional walkthrough at VennBoard.com, product detail at VennBoard.com.

Bring VennBoard into your practice.

One workspace for cases, clients, and the professionals you work alongside — built for divorce professionals — including divorce financial coaches, mediators, attorneys, and adjacent practitioners.