The ITRE Review / Property management

Cybersecurity for Property Managers: Protecting Tenant and Owner Data

What property management firms should secure first: tenant information, trust funds, building systems and the vendors that touch them.

A property manager holds a remarkable amount of sensitive information: leases, income details, identification, bank accounts, key codes and the keys to the buildings themselves. It also moves money for owners. Attackers know this. The good news is that a short list of controls removes most of the risk. This article sets out a priority order for firms managing rental, commercial and mixed portfolios.

Start with identity and email

Nearly all serious incidents begin with a stolen password. Require multi-factor authentication for every employee and for every access to the property-management platform, the accounting system and the banking portal. Disable older sign-in methods and review administrator accounts quarterly.

Email deserves the same attention as the platform, because owner statements, vendor invoices and tenant correspondence all travel there. Alerts on forwarding rules and unusual sign-ins provide an early warning.

Protect the money

Vendor invoices and owner distributions are frequent targets for fraudulent changes to banking details. Establish a rule that any change of payee details is verified by calling a known number, with two people involved for large payments. Record the verification in the accounting system.

Segregation of duties is a classic control that still works: the person who sets up a vendor should not be the person who approves payments to it.

Tenant and owner information

Apply the principle of least access. A leasing agent needs applicant records, a maintenance coordinator needs unit access details, and neither needs banking information. Configure roles in the property-management platform accordingly and review them when staff change position.

Retention matters too. Applications from unsuccessful applicants, expired leases and old maintenance records should be kept for defined periods and then disposed of. BC's Personal Information Protection Act expects personal information to be kept no longer than needed.

Building systems and vendors

Smart locks, cameras, access control and building automation connect to the same networks as office computers. Separate them on their own network segments, change default passwords and keep firmware updated. Ask vendors who remotely maintain these systems how they authenticate and log their access.

Maintain a register of vendors who hold your data or have access to your systems, including software platforms, banking services and contractors. Review it annually and remove those no longer needed.

Backups and recovery for a portfolio

Ensure that the property-management platform's data, accounting files and tenant documents are backed up in a way that you control. Some cloud platforms back up their own systems but do not guarantee recovery of an item you accidentally deleted.

Agree how quickly each system must be restored and test it. A month-end failure that stops rent reconciliation is a business interruption, and a rehearsal beforehand makes the real event manageable.

Common mistakes we see

The first mistake is to treat the property-management platform as the vendor's problem. The vendor secures its own infrastructure, but your firm controls who has access, how passwords are protected and what is exported to spreadsheets. The second is the exported spreadsheet itself: rent rolls and tenant lists emailed around the office are unprotected copies.

Firms also share accounts, particularly for after-hours maintenance, so nobody can say who did what. Individual accounts and a documented emergency process are better. Finally, many firms never test whether they can recover the platform's data or their accounting files. A tested restore is the cheapest insurance you can buy.

Checklist to take to your next meeting

  • Multi-factor authentication on platform, accounting, banking and mail
  • Call-back verification for any change of payee details
  • Role-based access in the property-management platform, reviewed quarterly
  • Separate network segments for building systems
  • Vendor register reviewed annually
  • Tested restore of accounting and tenant records

Where this fits in your technology plan

Guidance works best as part of a coordinated programme rather than a one-off fix. These ITRE services address the subject directly.

  • 01Office Network & Wi-Fi

    Office Network and Wi-Fi covers design, installation oversight and ongoing management of switches, access points, firewalls and internet connections, with separate secure and guest networks and monitoring that tells us about problems before the office does.

  • 02FINTRAC & PIPEDA Compliance IT

    FINTRAC and PIPEDA Compliance IT turns regulatory requirements into systems: where identification records live, how long they are kept, who may open them and how a compliance officer can produce them quickly. We do not provide legal advice; we build the technical controls your compliance officer and lawyer specify.

  • 03Wire-Fraud & BEC Protection

    Wire-Fraud and BEC Protection combines technical controls, such as hardened mailboxes, impersonation detection and alerting, with a written verification procedure for any change to payment instructions. It is designed for brokerages, conveyancers, developers and property managers who move large sums on short timelines.

Further reading

Take it to your next leadership meeting

Guidance is only useful when someone acts on it. If this article raised questions about your own office, development or portfolio, bring the checklist above to your next leadership meeting and assign an owner to each item. ITRE offers a free thirty-minute consultation to help you decide what to do first and what can wait.

Speak with an advisor

To discuss any of this in the context of your business, call (604) 632-4959 or write to info@SAZ.ca. You will speak with a senior advisor, and the guidance on this site is reviewed by Ali Sedighi, MBA. There is no obligation, no lock-in and no sales script.

Questions and answers

What is the biggest risk for property managers?
Fraudulent payment instructions and compromised email are the most common and costly. Strong authentication and verification procedures address both.
Do we need to separate building systems from the office network?
Yes. Locks, cameras and controls are common entry points. Segmentation limits what an attacker can reach if one device is compromised.
Can ITRE support Yardi, Buildium and AppFolio?
We provide administration, integration and user support alongside the vendors, including role reviews, report design and integration troubleshooting.
How long should we keep tenant applications?
Retention should follow your policy and legal advice. We implement schedules that reflect the periods you specify, and we log disposal.
What does a security review cost?
A property-management security assessment starts at $1,900, with a written findings report and a costed remediation roadmap.