Cyber security checklist templates written for a generic office do not survive contact with a lettings or block management business. The generic version assumes one building, one network, one set of laptops and a tidy boundary between staff and everyone else. A managing agent has none of that. It has branch offices, site laptops in cupboards, door-entry PCs nobody has logged into since 2019, contractors with portal accounts, landlords emailing bank details from personal addresses, and a property management platform holding passport scans for people who moved out three years ago.
That is the gap this guide closes. Below are twenty controls, grouped into five bands, written for firms that manage other people’s buildings, money and tenancies. Each one is scoped so a practice manager can score it honestly in an afternoon. Good cybersecurity in this sector is mostly unglamorous hygiene applied consistently across an estate that keeps growing sideways, and this cyber security checklist is built around that reality rather than around a network diagram.
It sits alongside our IT support guide for property management companies, our Microsoft 365 security checklist for property firms and our Cyber Essentials certification guide for managing agents. Those cover the support model, one platform and one certificate. This cyber security checklist is deliberately vendor-neutral: it works whether you run Microsoft 365 or Google Workspace, Reapit or Arthur, one office or fourteen.
Table of contents
- What a Property Management Cyber Security Checklist Has to Cover
- The 2026 Rules That Reset the Baseline
- How to Score This Cyber Security Checklist
- Cyber Security Checklist Controls 1–5: Identity and Access
- Cyber Security Checklist Controls 6–10: Devices and the On-Site Estate
- Cyber Security Checklist Controls 11–14: The Data Itself
- Cyber Security Checklist Controls 15–17: Suppliers, Contractors and Portals
- Cyber Security Checklist Controls 18–20: People, Response and Assurance
- The Full 20-Control Scorecard
- What It Costs to Close the Gaps
- A 90-Day Plan for a Mid-Sized Managing Agent
- Mistakes That Make a Cyber Security Checklist Look Complete
- Frequently Asked Questions
- References
What a Property Management Cyber Security Checklist Has to Cover
Before scoring anything, write down what you hold. Almost every firm that does this exercise finds two or three categories it had forgotten, and a cyber security checklist scored against an incomplete inventory produces a comfortable score and a false sense of safety.
The data a managing agent actually controls
You are a data controller for a richer set than most professional firms. Right-to-rent checks mean passport, visa and biometric residence permit scans. Rent collection means account numbers and sort codes for tenants and landlords. Deposits mean scheme references and dispute evidence. Repairs mean vulnerability notes, access arrangements, alarm codes and key registers. Block management adds leaseholder correspondence, service charge arrears and, increasingly, CCTV footage. Some of that is special category data under UK GDPR the moment a health condition is recorded against a tenancy.
| Data class | Typical examples | Usually lives in | Why it matters |
|---|---|---|---|
| Identity documents | Passport, visa, BRP scans | Platform, shared mailbox, phone camera roll | Identity theft; right-to-rent duty |
| Financial details | Sort codes, account numbers, statements | Accounts package, email threads | Payment diversion fraud |
| Tenancy records | Agreements, references, arrears history | Property management platform | Contractual and litigation exposure |
| Vulnerability notes | Health, disability, safeguarding flags | Repairs system, free-text notes | Special category data |
| Physical access data | Key registers, alarm and gate codes | Spreadsheets, site PCs, paper | Enables burglary and worse |
| Building systems | CCTV, door entry, smart locks | On-site hardware and vendor clouds | Rarely patched, rarely monitored |
| Landlord records | Statements, tax details, portfolios | Accounts and email | High-value fraud target |
Why the sector attracts attackers
Property firms sit on a rare combination: high-value payments, a legal duty to collect identity documents, and email as the default working tool. Criminals do not need to breach a platform when they can sit in a mailbox and wait for a completion or a deposit return.
The Information Commissioner’s Office fined the London estate agency Life at Parliament View Limited £80,000 after the data of 18,610 tenants and landlords — bank statements, salary details, dates of birth and passport copies — sat openly accessible for close to two years because an anonymous-authentication setting was left switched on during a server transfer. Any credible cyber security checklist for this sector starts from that scenario, not from ransomware. Nothing exotic caused it, and nothing exotic is required to prevent it: a cyber security checklist that catches a stray configuration setting would have caught this one.
The fraud numbers are moving the wrong way
Action Fraud recorded around 5,000 reports of rental scams in 2024, worth almost £9 million. By June 2026 the BBC put the cost of rental fraud in 2025 at £14.5 million. Most of that is impersonation rather than intrusion, which is precisely why identity and payment controls carry so much weight in the cyber security checklist scoring below.
The 2026 Rules That Reset the Baseline
Three changes landed between February and June 2026, and together they raise what a regulator would call adequate. A cyber security checklist last reviewed in 2025 is now measuring against the wrong bar.
The Data (Use and Access) Act 2025 is live
The main data protection provisions of the Data (Use and Access) Act 2025 came into force on 5 February 2026. Article 12A changes how the one-month subject access clock is calculated, Schedule 4 creates five recognised legitimate interests that need no balancing test, and Articles 22A to 22D replace the old prohibition on automated decision-making with a permission-plus-safeguards model. From 19 June 2026, new section 164A of the Data Protection Act 2018 requires controllers to acknowledge a data protection complaint within 30 days.
Cyber Essentials changed what counts as a pass
The Cyber Essentials question set moved from Willow to Danzell on 26 April 2026. Three answers now fail the whole assessment outright: multi-factor authentication on cloud services, critical and high severity updates to operating systems and firmware within 14 days, and the same 14-day rule for applications, files and extensions. Cloud services can no longer be excluded from scope. Even if you never certify, those three items are the cheapest way to sanity-check a cyber security checklist against an external standard.
Regulation is reaching your IT supplier
The Cyber Security and Resilience Bill completed its Commons stages and entered the House of Lords on 25 June 2026. It pulls managed service providers and data centre operators into statutory regulation for the first time, creates a category of designated critical suppliers, and carries penalties of up to £17 million or 4% of global turnover with incident reporting inside 24 hours. An estimated 900 to 1,100 medium and large providers would fall under Information Commission oversight. If your IT is outsourced, ask where your provider sits.
| Change | Date | What a managing agent must do |
|---|---|---|
| Renters’ Rights Act 2025 main commencement | 1 May 2026 | New notice and record trail per tenancy |
| Data (Use and Access) Act provisions | 5 Feb 2026 | Rewrite DSAR and lawful basis procedures |
| Cyber Essentials Danzell question set | 26 Apr 2026 | MFA everywhere; 14-day patching |
| Section 164A complaints duty | 19 Jun 2026 | Acknowledge complaints within 30 days |
| Cyber Security and Resilience Bill in the Lords | 25 Jun 2026 | Check your IT provider’s regulatory status |
Most firms have not done the basics
The Cyber Security Breaches Survey 2025/2026, published by DSIT on 30 April 2026 from fieldwork with 2,112 businesses, found 43% of UK businesses identified a breach or attack in the previous twelve months — roughly 612,000 organisations. Phishing hit 38% and was rated the most disruptive attack by 69% of those affected. The control adoption figures are worse than the breach figures.
How to Score This Cyber Security Checklist
Score each control 0, 1 or 2. Zero means not in place. One means partly in place, or in place for head office but not for branches, site kit or contractors. Two means in place everywhere, with evidence you could hand an auditor. Forty is the maximum for the full cyber security checklist. Anything below 26 means a serious incident is a question of timing rather than luck.
Use the honest score, not the aspirational one
The most common failure when running a cyber security checklist is scoring intent. A policy that says all devices are encrypted is not a two if nobody has checked the four site laptops. Score what you can evidence today, then re-score in ninety days. The difference between the two numbers is the only measure of progress that matters.
Score every band, not just the comfortable ones
Firms tend to score the identity band carefully and wave through the building systems and supplier bands, because nobody in the office owns them. Those are the bands where a cyber security checklist earns its keep, so give them the same scrutiny as the parts your IT provider reports on monthly.
Cyber Security Checklist Controls 1–5: Identity and Access
Identity is where most property sector incidents begin and end. If an attacker cannot authenticate, almost everything else on this cyber security checklist becomes a second line of defence rather than the first.
1. Multi-factor authentication on every cloud service
Not just email. The property management platform, the accounts package, the deposit scheme portal, the CCTV vendor console, the website CMS and the remote access tool. Cyber Essentials now fails an application outright where MFA is available and not enabled, including where it sits behind a higher licence tier. Prefer an authenticator app or a FIDO2 key over SMS. If you do only one item on this cyber security checklist, do this one.
2. Named accounts only, no shared logins
Shared mailboxes are fine; shared logins are not. A lettings@ account that six people know the password to defeats every audit trail you own, and it is the reason so many agents cannot say who accessed a file. Convert shared logins to named accounts with delegated access to the shared resource.
3. Least privilege scoped to the portfolio
A negotiator does not need the landlord bank details table. A block manager does not need the whole lettings book. Most platforms support role and branch scoping and most firms leave everyone on a default profile. Reducing this is free and it caps the blast radius of any single compromised account.
4. Leavers removed within one working day
Property firms have high turnover and a lot of casual site staff. A leaver who keeps portal access, or whose account merely sits disabled with an active app password, is a live risk. Tie the removal to the payroll process, not to someone remembering.
5. Separate administrator accounts
Whoever administers your platform or tenant should not browse the web and read email from the same identity. A separate admin account, used only for admin work, is the single cheapest control on this cyber security checklist and it costs a licence at most.
Cyber Security Checklist Controls 6–10: Devices and the On-Site Estate
The on-site estate is where property firms differ most sharply from other SMEs, and it is where a generic cyber security checklist is silent. Head office is usually adequate. The cupboard in the block is not.
6. Fourteen-day patching for operating systems and firmware
Critical and high severity updates within fourteen days, on laptops, phones, servers, routers and firewalls. This is a Cyber Essentials auto-fail and a sensible internal deadline regardless. Firmware on site routers is the item most often missed, and it is the item most likely to be scored a two on a cyber security checklist without anyone checking.
7. Patching applications, browsers and extensions
The same fourteen-day rule applies to applications, browser extensions and plug-ins. Unsupported software is treated as unpatched: an application no longer receiving security updates has to be removed or segregated from the network.
8. Every device enrolled and managed
If a device touches tenant or landlord data it should be enrolled in device management, whether it is company owned or a manager’s personal phone with the platform app on it. Enrolment is what makes encryption, screen locks and remote wipe enforceable rather than requested.
9. Building systems inventoried and segregated
Door entry PCs, CCTV recorders, intercom controllers, smart locks and lift monitoring boxes are computers. Inventory them, change default credentials, put them on a separate network segment or VLAN, and record who the vendor is. A cyber security checklist that ignores building systems ignores the devices with the longest patch gaps in the business.
10. Encryption and remote wipe as standard
Full-disk encryption on every laptop and enforced encryption on phones and tablets, with remote wipe tested at least once. A lost laptop with encryption on is an inconvenience; the same laptop unencrypted is a reportable personal data breach with a 72-hour clock attached.
| Device or system | Typical owner | Common gap | Fix |
|---|---|---|---|
| Head office laptops | IT or provider | Usually adequate | Verify encryption reporting |
| Site and branch laptops | Nobody | Unpatched, shared login | Enrol or retire |
| Manager personal phones | The manager | Platform app, no controls | App protection policy |
| Door entry and intercom PCs | Installer | Default password, no updates | Segregate and re-credential |
| CCTV recorders | Security vendor | Internet exposed | Remove public exposure |
| Site routers and firewalls | Broadband supplier | Firmware years old | Add to patch schedule |
Cyber Security Checklist Controls 11–14: The Data Itself
Access controls keep people out. This band limits what an intruder finds when they get in, which is the half of a cyber security checklist that firms consistently underweight.
11. A written data map and lawful basis register
You cannot protect what you have not listed. Record each data class, where it lives, who can see it, the lawful basis and the retention period. This is also the document that answers a subject access request quickly, which matters more now that the Data (Use and Access) Act has rewritten the timing rules. Every other entry on the cyber security checklist is easier to score once this one exists.
12. Retention and deletion that actually runs
Right-to-rent copies, deposit evidence, references and arrears history all have natural expiry points. Most platforms will report on records older than a threshold; almost nobody uses it. Deleting a passport scan you no longer need is the only control that reduces both risk and cost at the same time.
| Record type | Common practice | Better practice |
|---|---|---|
| Right-to-rent document copies | Kept indefinitely | Defined period after tenancy ends |
| Failed applicant references | Left in the mailbox | Deleted on a short cycle |
| Bank details in email | Searchable forever | Never in email at all |
| CCTV footage | Until the disk fills | Fixed retention, documented |
| Key and alarm code registers | Shared spreadsheet | Access-controlled system |
13. Backups that survive ransomware
Three copies, two media, one off-site and immutable, with a restore actually tested. Native cloud retention in a productivity suite is not a backup: it protects against user error, not against an administrator account being taken over. Test a restore of the property management platform, not just the file server.
14. Get financial data out of email
Bank details, ID scans and statements should travel through the portal or a secure transfer link, never as an attachment. Then enforce a verification rule: any change to bank details is confirmed by a call to a number already on file, never a number in the email requesting the change. This single habit prevents most payment diversion losses in the sector, and it is the cyber security checklist item that pays for itself fastest.
Cyber Security Checklist Controls 15–17: Suppliers, Contractors and Portals
Only 15% of UK businesses review supplier cyber risk at all. Property firms have more suppliers than most — contractors, platforms, deposit schemes, referencing agencies, cleaners with fobs — so this band of the cyber security checklist punches above its weight.
15. Contractor access granted narrowly and removed promptly
Contractors should see the jobs assigned to them, not the tenancy file. Give them portal accounts rather than shared logins, with an expiry date. Review the list quarterly and remove every contractor you have not instructed in twelve months. In most firms this is the longest-standing zero on the whole cyber security checklist.
16. Processor contracts and platform due diligence
Your property management platform, referencing provider and payment processor are processors under UK GDPR, which means Article 28 terms, documented sub-processors, breach notification obligations and a known data location. Ask each one where the data sits, who can access it, how they authenticate their own staff and what their breach notification timescale is. Keep the answers.
17. Tenant and landlord portals hardened
Portals are internet-facing and hold exactly the data an attacker wants. Enforce MFA for landlord accounts, rate-limit login attempts, disable account enumeration on password reset, and make sure a portal password reset cannot be triggered by an email address alone without a second factor.
Cyber Security Checklist Controls 18–20: People, Response and Assurance
18. Training aimed at the frauds this sector actually sees
Generic phishing training is better than nothing but it does not cover deposit return fraud, fake landlord instructions or a contractor invoice with altered details. Run short, sector-specific sessions and record attendance. Phishing was the most disruptive attack type for 69% of affected businesses; it is worth more than one slide.
19. A written incident response plan with the clocks in it
A quarter of UK businesses have a plan. Yours needs the ICO’s 72-hour breach notification deadline, the section 164A duty to acknowledge a complaint within 30 days, who declares an incident, who calls the insurer, who tells landlords, and what you say to tenants. Print it — a plan stored only in the system you have just lost is not a plan.
20. Independent assurance and a board-level review
Certify to Cyber Essentials, or at minimum have an external party test the assumptions in this cyber security checklist once a year. Then put the score in front of whoever runs the business, quarterly. Controls decay silently; the review is what catches the decay before an attacker does.
The Full 20-Control Scorecard
Print this table, score each row honestly and total it. The priority column is the order to fix things in if you cannot do everything at once.
| # | Control | Band | Priority | Effort |
|---|---|---|---|---|
| 1 | MFA on every cloud service | Identity | Critical | Low |
| 2 | Named accounts, no shared logins | Identity | Critical | Medium |
| 3 | Least privilege by role and branch | Identity | High | Medium |
| 4 | Leavers removed in one working day | Identity | Critical | Low |
| 5 | Separate administrator accounts | Identity | High | Low |
| 6 | 14-day OS and firmware patching | Devices | Critical | Medium |
| 7 | 14-day application patching | Devices | Critical | Medium |
| 8 | All devices enrolled and managed | Devices | High | Medium |
| 9 | Building systems inventoried, segregated | Devices | High | High |
| 10 | Encryption and tested remote wipe | Devices | High | Low |
| 11 | Data map and lawful basis register | Data | High | Medium |
| 12 | Retention and deletion that runs | Data | Medium | Medium |
| 13 | Immutable, tested backups | Data | Critical | Medium |
| 14 | Financial data out of email | Data | Critical | Low |
| 15 | Contractor access narrow and expiring | Suppliers | High | Medium |
| 16 | Processor contracts and due diligence | Suppliers | Medium | Medium |
| 17 | Portals hardened, MFA for landlords | Suppliers | High | Medium |
| 18 | Sector-specific fraud training | People | High | Low |
| 19 | Written incident response plan | People | Critical | Low |
| 20 | Independent assurance, quarterly review | People | Medium | Medium |
Reading your score
Below 26 out of 40, treat the gaps as an operational risk and start with everything marked critical. Between 26 and 33, you are in reasonable shape and the remaining work is mostly evidence and consistency across sites. Above 33, the useful next step is external validation rather than more internal effort.
Record the date alongside the number. A cyber security checklist score without a date is a claim; a dated score with a second dated score beside it is a trend, and a trend is what a landlord, an insurer or a regulator will actually accept as evidence of improvement.
What It Costs to Close the Gaps
Most of a cyber security checklist costs time rather than licences, which is the single most useful thing to tell a finance director before the conversation starts. The table below is a realistic annual view for a firm of roughly 25 to 60 staff managing a mixed lettings and block portfolio, using UK list prices excluding VAT.
| Item | Typical UK cost | Controls it closes |
|---|---|---|
| MFA and conditional access | Included in most business plans | 1, 5, 17 |
| Device management and encryption | Included at Business Premium tier | 8, 10 |
| Third-party backup for cloud data | Low per-user monthly cost | 13 |
| Cyber Essentials assessment (10–49 staff) | £440 ex VAT | 20 |
| Cyber Essentials Plus audit | £1,400–£5,000+ | 20 |
| Building systems audit and segregation | Project cost, varies by site count | 9 |
| Staff time to score and remediate | The largest single line | Most of the list |
The IASME assessment fee for Cyber Essentials is banded by size: £320 for one to nine staff, £440 for ten to forty-nine, £500 for fifty to two hundred and forty-nine, and £600 above that, each ex VAT for a twelve-month certificate. Against a regulatory ceiling of £17.5 million or 4% of turnover, and an £80,000 penalty already levied on one agency under the older regime, the arithmetic is not difficult.
The Capita case is instructive for exactly the reason it is uncomfortable. A high priority alert was raised within ten minutes of the intrusion; the device was not quarantined for fifty-eight hours. The failure was not detection, it was response — which is why control 19 sits where it does.
A 90-Day Plan for a Mid-Sized Managing Agent
| Period | Focus | Deliverable |
|---|---|---|
| Days 1–14 | Score the twenty controls; list every device and system | Baseline score and asset list |
| Days 15–30 | MFA everywhere; kill shared logins; fix the leaver process | Identity band at 2 |
| Days 31–50 | Patch schedule, device enrolment, encryption evidence | Device band at 2 |
| Days 51–70 | Backups tested; data map written; email cleanup | Tested restore report |
| Days 71–85 | Contractor access review; processor contracts; portal hardening | Supplier register |
| Days 86–90 | Incident plan; training; re-score and report | Board paper with both scores |
Ninety days is realistic because the critical items are mostly configuration rather than procurement. The building systems work in control 9 usually runs longer, so start the site survey in the first fortnight even though it finishes later. Firms that outsource this typically fold the cyber security checklist into a managed IT services arrangement so the patching and review cycles do not depend on one internal person remembering.
The re-score at day 90 is not a formality. It is the point at which a cyber security checklist stops being a document and becomes a management routine, and it is the number you take to a tender, an insurer or a landlord who asks how you look after their data.
Mistakes That Make a Cyber Security Checklist Look Complete
Scoring head office and calling it the estate
The head office network is almost always the best-controlled part of a property business and the least representative. Score branches, site kit and home workers separately on the same cyber security checklist, then take the lowest number as the real one.
Treating the platform vendor’s security as your own
Your property management platform may be well secured. That tells you nothing about the account with a weak password that can export the whole tenancy database. Vendor security and your configuration of it are different controls, and only one of them is your responsibility to get right.
Confusing a policy with a control
A retention policy nobody executes scores zero, not one. The same applies to an incident plan that has never been read aloud and a backup that has never been restored. Evidence or zero — that rule alone will change most firms’ cyber security checklist totals by several points.
Leaving the data protection paperwork out of scope
Security and data protection are scored together in practice, because the ICO assesses both after an incident. Keep the data protection documentation, the privacy notices and the compliance register current alongside the technical work rather than as a separate annual chore.
Frequently Asked Questions
How often should we re-run this cyber security checklist?
Score it quarterly and do a full evidence-backed review annually. Quarterly is frequent enough to catch drift from staff changes and new sites; annually is when you re-test backups and re-validate supplier answers.
Do we need Cyber Essentials to be secure?
No, but it is the cheapest external check that the basics are on, and a growing number of local authority, housing association and institutional landlord tenders ask for it. The certificate is evidence; this cyber security checklist is the work.
What if our IT is fully outsourced?
Send your provider the twenty controls and ask them to mark which they own, which you own and which nobody currently owns. The third column is the interesting one, and it is the reason a cyber security checklist should never be filled in by the provider alone. Also ask whether they expect to fall within the Cyber Security and Resilience Bill’s managed service provider scope.
Does the Renters’ Rights Act change our security obligations?
Not directly, but it changes the record trail. More prescribed notices, more served documents and the coming PRS Database mean more personal data moving through your systems, which raises the cost of getting controls 11 to 14 wrong.
Who should own the score internally?
An operations or compliance lead, not the IT provider. The provider implements; someone inside the business has to be accountable for the cyber security checklist number and for putting it in front of the board.
Does this replace a full risk assessment?
No. A cyber security checklist is a control baseline, not a risk assessment — it tells you what is switched on, not what would hurt most if it failed. For a managing agent the two overlap heavily, which is why the checklist is a sensible first exercise, but a firm handling client money at scale should do both.
References
ICO: Capita fined £14m for data breach affecting over 6m people
ICO: Personal data breaches — a guide
NCSC: Small Organisations Guide to Cyber Security
NCSC: 10 Steps to Cyber Security
NCSC: Cyber Essentials overview
GOV.UK: Cyber Security Breaches Survey
Data (Use and Access) Act 2025
GOV.UK: Right to rent landlords code of practice
Propertymark: The importance of effective cyber risk management