A real estate agency does not feel like a cyber target. The day runs on listings, inspections, and phone calls, not passwords and backups, and security tends to mean the alarm code and the key safe.
The trouble is that an agency sits on top of large property payments and a deep pool of personal data, from rental applications to trust account records. To an attacker chasing money or identities, that is a rich and often lightly defended target. If you have read our overview of IT for real estate agencies, this is the practical companion: the seven gaps we find most often when we look properly, and how to close each one.
Gap 1: Deposit and Settlement Payment Redirection
The single biggest cyber risk in real estate is payment redirection. Deposits, settlement funds, and rental bonds are large, time-pressured transfers, and the parties often communicate by email under deadline. That is exactly the situation attackers exploit.
An attacker who gets into one mailbox can watch a settlement progress and then send a convincing email, seemingly from the agency or the solicitor, asking the buyer to send funds to a new account. Because it lands at the right moment from a familiar name, it works, and the money is usually gone before anyone notices. This pattern, business email compromise, causes the most damage in this sector. The defence is a second verification step on every mailbox plus an ironclad rule: payment details are confirmed by a phone call to a known number, never trusted from an email alone.

Gap 2: Applicant PII Sprawling Through Inboxes
Rental applications are a goldmine of personal data: payslips, bank statements, identity documents, references, and addresses. Most of it arrives by email and simply stays there, scattered across agents’ inboxes and forwarded around the office, long after the property is leased.
That is sensitive data sitting unprotected in dozens of mailboxes, and a single compromised account exposes all of it. The fix is to stop sensitive documents living in email indefinitely: move them into a controlled system, restrict who can see them, and clear out applicant data you no longer need. Knowing where this information sits is the first step to protecting it.
Gap 3: Trust Accounting Access
The trust account is the most tightly regulated and most valuable system in the agency, holding rental bonds, deposits, and landlord funds. The logins that touch it deserve the strongest protection you have, and too often they get the same single password as everything else.
We routinely find trust accounting access shared between staff or left active for people who have moved on. The fix is one named login per person, a second verification step on every account that can move money, and access removed the day someone leaves. Who can authorise a payment should be a short, current list, not a question nobody can answer.
Gap 4: Rent-Roll and CRM Logins Without MFA
The rent roll and the CRM are the commercial value of the agency: every landlord, tenant, vendor, and buyer relationship lives in there, usually in a cloud platform reached with a single password. If that login leaks, an attacker has your entire client base.
Multi-factor authentication means a login needs your password plus a prompt on your phone, so a stolen password is not enough on its own. This single control blocks most account takeovers, and it is the one we most often find missing from the rent-roll and CRM platforms specifically. The fix is to enforce that second step on every cloud system that holds client data, not just on email.
Gap 5: Agents’ Mobile Devices
Real estate is a mobile business. Agents work from cars, open homes, and cafes, with the CRM, email, and client documents all on a phone or tablet that travels everywhere. That mobility sells properties, and it widens the attack surface.
A phone left in a car or lost at an inspection is a way into your systems if it is not set up properly. The fix is that the basics travel with the device: a screen lock and encryption so a lost phone is not a breach, the ability to remotely wipe a device that goes missing, and accounts protected so a single stolen password does not open the door.
Gap 6: Ex-Agent Access Not Removed
Real estate has high movement: agents change agencies, property managers come and go, and casual staff cover busy periods. Each departure is a small security event, and the records the agency keeps are sensitive in their own right.
The common gap is access that never gets switched off. A departed agent still has a login to the CRM, the rent roll, or the shared drive, sometimes taking client relationships with them, sometimes leaving a door open for an attacker. The fix is access granted by role when someone starts, reviewed regularly, and removed promptly on their last day, not weeks later.
Gap 7: Backups That Have Never Been Tested
Your rent roll, trust records, property files, and CRM all live in systems you assume are backed up. The dashboard is green, so everyone relaxes. Then a system fails or ransomware hits, someone tries to restore, and the copy is incomplete or was never really running.
A backup nobody has restored from is a guess, not a safety net. The fix is to test restores on a schedule and keep at least one copy an attacker cannot alter or delete, so that if the worst happens, your rent roll and compliance records come back in hours, not weeks.
Closing the Gaps
None of these are exotic, and none require pulling your agency apart. They are the everyday shortfalls that turn a preventable incident into a real one, and every one maps to the basics in Essential Eight, the baseline set of controls published by the Australian Cyber Security Centre. Close them in priority order and you significantly reduce your risk without disrupting the way the office runs.
The hard part is knowing which apply to you, because most stay invisible until someone looks. That is the value of an honest assessment.
Where to Start
If you recognised your agency in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.
Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.
We are a Sydney-based team in Bella Vista, and we help real estate agencies across the metro area close these exact gaps and keep them closed, with managed IT that treats security as ongoing rather than a one-off. No jargon, no scare tactics, just the basics done properly.