Skip to main content

Seven Cyber Gaps in Sydney Real Estate Agencies

1 September 2026 | By Birender Chahal

A real estate agency does not feel like a cyber target. The day runs on listings, inspections, and phone calls, not passwords and backups, and security tends to mean the alarm code and the key safe.

The trouble is that an agency sits on top of large property payments and a deep pool of personal data, from rental applications to trust account records. To an attacker chasing money or identities, that is a rich and often lightly defended target. If you have read our overview of IT for real estate agencies, this is the practical companion: the seven gaps we find most often when we look properly, and how to close each one.

Gap 1: Deposit and Settlement Payment Redirection

The single biggest cyber risk in real estate is payment redirection. Deposits, settlement funds, and rental bonds are large, time-pressured transfers, and the parties often communicate by email under deadline. That is exactly the situation attackers exploit.

An attacker who gets into one mailbox can watch a settlement progress and then send a convincing email, seemingly from the agency or the solicitor, asking the buyer to send funds to a new account. Because it lands at the right moment from a familiar name, it works, and the money is usually gone before anyone notices. This pattern, business email compromise, causes the most damage in this sector. The defence is a second verification step on every mailbox plus an ironclad rule: payment details are confirmed by a phone call to a known number, never trusted from an email alone.

Two men in suits discussing data on tablet
In real estate, the settlement and the trust account are the targets.

Gap 2: Applicant PII Sprawling Through Inboxes

Rental applications are a goldmine of personal data: payslips, bank statements, identity documents, references, and addresses. Most of it arrives by email and simply stays there, scattered across agents’ inboxes and forwarded around the office, long after the property is leased.

That is sensitive data sitting unprotected in dozens of mailboxes, and a single compromised account exposes all of it. The fix is to stop sensitive documents living in email indefinitely: move them into a controlled system, restrict who can see them, and clear out applicant data you no longer need. Knowing where this information sits is the first step to protecting it.

Gap 3: Trust Accounting Access

The trust account is the most tightly regulated and most valuable system in the agency, holding rental bonds, deposits, and landlord funds. The logins that touch it deserve the strongest protection you have, and too often they get the same single password as everything else.

We routinely find trust accounting access shared between staff or left active for people who have moved on. The fix is one named login per person, a second verification step on every account that can move money, and access removed the day someone leaves. Who can authorise a payment should be a short, current list, not a question nobody can answer.

Gap 4: Rent-Roll and CRM Logins Without MFA

The rent roll and the CRM are the commercial value of the agency: every landlord, tenant, vendor, and buyer relationship lives in there, usually in a cloud platform reached with a single password. If that login leaks, an attacker has your entire client base.

Multi-factor authentication means a login needs your password plus a prompt on your phone, so a stolen password is not enough on its own. This single control blocks most account takeovers, and it is the one we most often find missing from the rent-roll and CRM platforms specifically. The fix is to enforce that second step on every cloud system that holds client data, not just on email.

Gap 5: Agents’ Mobile Devices

Real estate is a mobile business. Agents work from cars, open homes, and cafes, with the CRM, email, and client documents all on a phone or tablet that travels everywhere. That mobility sells properties, and it widens the attack surface.

A phone left in a car or lost at an inspection is a way into your systems if it is not set up properly. The fix is that the basics travel with the device: a screen lock and encryption so a lost phone is not a breach, the ability to remotely wipe a device that goes missing, and accounts protected so a single stolen password does not open the door.

Gap 6: Ex-Agent Access Not Removed

Real estate has high movement: agents change agencies, property managers come and go, and casual staff cover busy periods. Each departure is a small security event, and the records the agency keeps are sensitive in their own right.

The common gap is access that never gets switched off. A departed agent still has a login to the CRM, the rent roll, or the shared drive, sometimes taking client relationships with them, sometimes leaving a door open for an attacker. The fix is access granted by role when someone starts, reviewed regularly, and removed promptly on their last day, not weeks later.

Gap 7: Backups That Have Never Been Tested

Your rent roll, trust records, property files, and CRM all live in systems you assume are backed up. The dashboard is green, so everyone relaxes. Then a system fails or ransomware hits, someone tries to restore, and the copy is incomplete or was never really running.

A backup nobody has restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete, so that if the worst happens, your rent roll and compliance records come back in hours, not weeks.

Closing the Gaps

None of these are exotic, and none require pulling your agency apart. They are the everyday shortfalls that turn a preventable incident into a real one, and every one maps to the basics in Essential Eight, the baseline set of controls published by the Australian Cyber Security Centre. Close them in priority order and you significantly reduce your risk without disrupting the way the office runs.

The hard part is knowing which apply to you, because most stay invisible until someone looks. That is the value of an honest assessment.

Where to Start

If you recognised your agency in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.

Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.

We are a Sydney-based team in Bella Vista, and we help real estate agencies across the metro area close these exact gaps and keep them closed, with managed IT that treats security as ongoing rather than a one-off. No jargon, no scare tactics, just the basics done properly.

Birender Chahal
Founder, CIO Tech

Birender founded CIO Tech and holds an IT degree from the University of Technology Sydney. He has delivered IT projects across hotels and serviced offices, covering property management systems, guest networks, and Essential Eight hardening. More about CIO Tech.

Stop putting off IT that works

Book an IT Audit

$990 one-off. 90-day deep dive into your IT environment with a prioritised action plan.

Book IT Audit

Free IT Health Check

Takes 3 minutes. See where your IT stands and what to fix first.

Free IT Health Check

Cyber Posture Snapshot

Your details 1 / 10

How exposed is your business?

Six quick questions, two short ones to tailor the result, and you'll see where your business stands. About two minutes. Plain English, no jargon.

We'll use your email to send a copy of your result. No spam, no pushy sales calls.

Question 1 of 9

When your team logs in to email and business apps, do they need a code from their phone as well as a password?

Question 2 of 9

If a ransomware attack locked all your files tomorrow, could you restore them from a backup?

Question 3 of 9

When Microsoft or Apple release a critical security update, how fast does it land on your computers?

Question 4 of 9

How many people in your business can install software or change system settings on any work computer?

Question 5 of 9

If a staff member got a fake invoice or "urgent" email pretending to be from you right now, what would happen?

Question 6 of 9

When a staff member leaves, when does their access to email, files, and apps actually get cut off?

Question 7 of 9

How many people work in your business?

Question 8 of 9

Who looks after your IT today?

Question 9 of 9

What sort of business are you?

Tailoring your result...

Hi there, here's where your business stands.

Your Cyber Posture
Critical gaps Critical
Notable exposure Notable
Mixed picture Mixed
On the right track On track

Notable exposure

Your two biggest gaps

  1. 1
  2. 2

Where this leaves you on Essential Eight

  • MFA Multi-factor authentication
  • Backups Regular backups
  • Patching Covers 2 of 8: Patch applications + Patch operating systems
  • Admin access Restrict administrative privileges

This snapshot covers 5 of the 8 Essential Eight controls. The full IT Maturity Assessment covers all 8, plus Microsoft 365 hardening, device management, and staff training.