Management consultants KPMG reported in 2018 that approximately one third of real estate firms had experienced a cybersecurity attack in the previous two years.
What’s more, the same study revealed that only around 50% of firms felt they were fully equipped to tackle or prevent such breaches – particularly amongst online operators. In light of these statistics, it’s clear that cyber attacks remain a very real threat to the property industry, perhaps more acutely amongst the online transactional space such as auctions.
The sector is particularly attractive to cyber criminals thanks to the large sums that are transferred when purchasing or renting property, along with the necessity for personal and financial details to be accessed regularly by professionals in the field.
With an increasing proportion of the processes involved in property transactions being undertaken remotely, the need to strengthen the security of the networks and infrastructure involved becomes all the more urgent.
This article explores the main cyber-related risks to real estate businesses and their clients, and discusses what businesses in the sector can do to counteract them.
Threats to cyber security in real estate
Phishing – or, more specifically, “business email compromise” – is one of the greatest risks to the online security of most property firms.
In order to utilize this technique, cyber criminals pose as another legitimate business or client and set up a transaction whereby their target is to transfer funds to them as part of a bogus arrangement.
Other email-related threats include malicious attachments, while Trojans, ransomware and compromised landing pages can also lead to serious data breaches in real estate firms.
If your company is the target of a major breach, or if it is found to have insufficient cybersecurity measures in place, it faces large fines and even enforced closure. What’s more, public trust in your brand may diminish significantly.
Most importantly, your company has a duty to protect the interests of all its clients, stakeholders and partners – which makes it vital that you properly implement suitable measures to defend their data against theft or loss.
Protecting your company and clients
To make sure all data handled by your company is safe and secure from cyber threats, your first port of call should be to install sophisticated anti-virus software that meets all of your unique requirements.
This software should have the capacity to block malware and ransomware, prevent unauthorized access to cameras and other recording devices and tackle instances of phishing.
It should also guard against malicious tracking software and impose browsing restrictions to prevent employees from visiting compromised websites.
You need to consider how employee passwords and permissions are managed too, in order to crack down on unauthorised access.
Many firms also opt for in-depth cybersecurity testing, undertaken by specialist service providers, which usually consists of vulnerability scanning approaches, penetration testing methods and a detailed risk assessment along with other techniques.
Furthermore, it is vitally important for any real estate firm to implement extensive cyber security training for employees. This may involve tips on how to recognise phishing scams, how to create secure passwords, how to avoid malicious web pages and more besides.
Finally, is it vital that your organization invests in sufficient Cyber Liability Insurance. This will cover you should a data breach or cyber attack occur, resulting in financial losses.
By taking all the steps you can to prevent a cyber attack, you will be keeping client and stakeholder data safe as well as preventing your company from prosecution, potential fines and a loss of public trust.
Following the information above will help you to better understand your current position and enable you to take suitable steps to defend your business.

