How to implement cyber security for property management in 4 phases

Start with a four-phase plan: immediate fixes, monthly hygiene, quarterly risk reviews and an annual audit. Use standards such as Cyber Essentials and practical tools like MFA and managed backups; most offices can reach a resilient baseline in 4 phases without huge disruption.

First week

In the first week you want to stop obvious risks and establish a clear owner for IT security. Begin with an asset inventory (list every PC, NAS, router and cloud account) and identify who has admin access. Put multi-factor authentication (MFA) on all email and property-management system logins immediately and force a password reset for accounts that use shared credentials.

Quick checklist:

  • Inventory: capture devices, cloud services and admin users.
  • Backups: verify at least one recent restore of tenant records.
  • Access: enable MFA and remove unused admin accounts.
  • Patch simple endpoints: ensure Windows and commonly used SaaS apps are up to date.

Those items remove the highest-return exposures in minutes to days and give you a defensible starting point for the next month.

First month

During month one convert the quick fixes into repeatable controls. Configure automated patching on workstations, enforce endpoint encryption on laptops used off-site, and centralise log collection for sign-in failures. Put clear rules in place for contractors and maintenance staff: temporary accounts, time-limited access, and forgotten credentials handled by IT rather than being shared.

Train the team with a focused session (30–60 minutes) that covers phishing recognition, secure file transfer of tenancy documents, and how to report a suspected breach. Create a short incident contact list so everyone knows who to call when access fails or a suspicious invoice arrives. Consider running a basic phishing simulation or third-party check to see if staff act on suspicious emails.

First quarter

In the first three months you should move from hygiene to risk reduction. Run a formal risk review: map the highest-value data (tenancy agreements, passport scans, bank details) and where it sits. Adopt a single-data-flow model so that the fewest systems hold personal data and everything else accesses a protected service.

Introduce controls that scale: role-based access, regular privilege reviews, and VPN or secure remote access for staff working off-site. If you do not have in-house security expertise, schedule a managed cyber security review — a short engagement that will produce prioritized actions and evidence for boards or landlords. For guidance on handling personal data incidents, consult ICO’s guidance on data breaches.

First year

Across the first year your focus is verification and continuity. Perform an annual audit of controls, update your supplier contracts to include security expectations, and test your disaster recovery by restoring a property-management database from backup. Aim to achieve or maintain Cyber Essentials certification where appropriate; it gives a clear checklist and helps with tendering and landlord confidence.

Set a calendar for recurring work: quarterly access reviews, biannual tabletop exercises for incident response, and an annual penetration test on externally facing systems. Track security tasks in a simple register so directors can see progress and residual risk.

What to watch for next

After the first year watch for three common shifts: (1) suppliers introducing new integrations that widen your attack surface; (2) staff churn creating orphaned accounts; and (3) regulatory changes around tenant data. Maintain an issues log and budget for replacing unsupported systems. The immediate next step is to schedule your quarterly risk review and an annual restore test — that protects time, reputation and rental income. (See our cyber security guide.)

Related reading

FAQ

Can a small property manager achieve Cyber Essentials quickly?

Yes — many small teams can meet the standard by addressing the basic controls (patching, MFA, admin separation) within a few weeks to a few months depending on staff availability and legacy systems.

How soon must I report a tenant data breach to the regulator?

If the breach meets the GDPR threshold you must notify the ICO within 72 hours of becoming aware, and document decisions even when no report is required.

What is the minimum I should spend on cyber security upgrades?

There is no universal figure; expect to budget for a small capital uplift (for devices and backups) plus an ongoing support cost, and plan for priority fixes first rather than a single big investment.

Who should I call first if systems stop working after hours?

Use your incident contact list: the first calls are to your IT support or managed provider for containment, then to your insurer if affected systems cause financial loss, and to landlords or tenants only on clear advice.