Security for a director exposed to crypto-assets involves accounts, personal information, family and business continuity. Digital and physical risks can overlap. Neither a hardware wallet nor an intermediary company guarantees a person’s safety.
Begin by reducing unnecessary public information, securing access and organising an incident response. In an immediate emergency in France, contact the police on 17 or 112. People’s safety takes priority over assets.
1. Check what is actually public
Search for your name, company and contact information in sources you use publicly: websites, directories, social profiles and accessible company records. Identify information that no longer needs to be public and request correction from the relevant website operator. Removal from a register does not automatically remove copies elsewhere.
Avoid publishing balances, account screenshots, identity documents or real-time travel details. A business can explain its activity without disclosing a director’s personal wealth. The aim is to limit exposure while continuing to provide information required by law.
2. Use existing home-address protection procedures
Following the decree of 22 August 2025, procedures allow requests to mask home addresses in the French trade register and to file or replace certain documents with a redacted public version. You do not have to wait for a new bill to check eligibility. INPI explains the available steps and documents covered.
The RNE national business register does not disclose representatives’ home addresses. A business address that is also a home address is a separate issue: relocating the registered office may be considered, but it is not the only procedure and does not erase internet history. Authorised authorities retain access to complete information. Consult INPI’s procedures, in French.
3. Secure accounts and verify unusual requests
Use unique passwords, stronger authentication where available and maintained devices. Prioritise the email account used to recover other accounts. Restrict permissions to those who need them and revoke access that is no longer required.
Knowing your identity, address or platform does not prove that a caller represents a legitimate service. Verify unusual requests using official contact details obtained independently of the message. Never give a recovery phrase or validation code to someone who contacts you.
Cybermalveillance.gouv.fr describes impersonation and fraud risks following crypto-sector data breaches. Keep suspicious messages and follow instructions from the provider reached through its official channel. Read the French public cyber-assistance recommendations.
4. Agree simple procedures with family and colleagues
Family members and colleagues should know a reliable way to contact you and what to do with an unusual request. An alleged emergency, changed bank details or a request to travel warrants independent verification. Nobody should feel obliged to handle a worrying situation alone.
Within the business, specify whom to alert and which actions to suspend when in doubt. A simple periodic exercise helps check that contact details and responsibilities remain current. It does not require sharing every detail of asset custody with everyone.
5. Plan continuity without concentrating every permission
If one person alone can access business assets, their unavailability may interrupt operations. Arrange suitable delegations, a recovery process and approvals proportionate to transactions. Their design must balance continuity, confidentiality and control over authority.
Multiple approvals, withdrawal restrictions or professional custody may reduce certain operational risks. They should be designed and tested with competent specialists. None makes a physical threat ineffective, and a technical setup should not be presented as a guarantee of personal protection.
What the company should document
- An inventory of business accounts and wallets, without collecting their secrets in the accounting file.
- Authorised people, approval levels and procedures when a colleague leaves or becomes unavailable.
- A backup and recovery process whose operation is checked periodically.
- Official provider contact details and the people to involve during an incident.
- Decisions and supporting records for business security expenditure.
Company payment of an expense protecting a director or family member personally requires legal, tax and social analysis. A bill under discussion does not make that expenditure automatically deductible or consistent with the company’s interests.
If information has already leaked
Identify the affected information from official communications, secure exposed accounts and remain alert to unusual requests. Keep evidence and contact the competent authorities if an offence occurs. A business responsible for a personal-data breach must also assess its documentation, CNIL notification and individual-information obligations according to the risk.
The French data protection authority explains how to assess a breach and when notification is required, including the 72-hour deadline where applicable. Read CNIL’s breach notification procedure, in French.
Frequently asked questions
Does a security risk remove an asset-reporting obligation?
No. Data-protection steps must work alongside filing obligations. Omitting a tax declaration is not a security measure.
Is a hardware wallet sufficient?
It addresses some custody risks, depending on its use. It does not alone protect personal information, email accounts, family or business continuity.
Does the firm provide physical-security audits?
Our role concerns business organisation, documentation and the accounting implications of transactions, within the agreed engagement. Cybersecurity and physical-protection audits require the relevant specialists.
Discuss business account organisation, responsibilities and records with the firm. For a threat or ongoing incident, contact emergency services or the relevant provider directly.
