Disaster recovery for property management companies is almost always discussed as an IT subject and filed away as one. It is not an IT subject. It is a question about what happens to four hundred tenancies, forty landlords and one client money account on the Tuesday morning when nothing loads, nobody can see a tenancy agreement, and the phones ring anyway.
Ask most managing agents what their plan is and the answer is “we have backups”. That answer describes a copy of some data somewhere. It does not describe how long the business is down, what work is lost, who tells the tenants, or which statutory deadline quietly expires while the restore runs. Real disaster recovery for property management is the difference between those two things, and this guide walks the whole dependency chain from the property CRM outwards to show where the difference actually bites.
The chain matters because it is how the damage propagates. Disaster recovery for property management is best understood as a sequence rather than a checklist: the CRM goes, then the rent system, then email, then tenant communication, then contractor scheduling, then the files that prove any of it happened. Each step compounds the last.
This article sits alongside our IT support guide for property management companies, the twenty-control cyber security checklist for managing agents and our Microsoft 365 setup guide for property firms. Those cover the support model, the security baseline and the platform build. This one covers the failure case: what breaks, in what order, and what it takes to get it back. Good cybersecurity reduces how often you need this plan. It never removes the need for one.
Every figure quoted here is sourced and dated. Where a number is our own arithmetic on a stated assumption, we say so, because disaster recovery for property management is a subject where invented statistics do real harm.
Table of contents
- What Disaster Recovery for Property Management Actually Means
- Hour One: The Property CRM Is Unavailable
- Hour Two: The Rent System Is Unavailable
- Hour Three: Email Is Unavailable
- Tenant Communication Stops — and the Clock Does Not
- Contractor Scheduling Stops and Compliance Dates Slip
- Files Are Unavailable: Certificates, Agreements and Evidence
- Backup: The Foundation of Disaster Recovery for Property Management
- RTO and RPO: Setting Recovery Targets System by System
- Recovery Testing: Proving Disaster Recovery for Property Management Works
- What Disaster Recovery for Property Management Costs
- How Managed IT Delivers Disaster Recovery for Property Management
- Disaster Recovery for Property Management: Frequently Asked Questions
- References
What Disaster Recovery for Property Management Actually Means
The words get used loosely, so it is worth being precise before anything else. Backup is a copy of data. High availability is redundancy that stops a single component failure becoming an outage. Disaster recovery is the documented, tested process of getting a defined set of business services back to a defined state within a defined time. Disaster recovery for property management is the third of those, scoped to the systems a managing agent cannot trade without.
The scope is a chain, not a list
Most plans fail because they treat systems as independent items on an inventory. In a property business they are not independent. The CRM holds the tenancy record. The rent system depends on knowing which tenancy is which. Email carries every instruction to and from landlords and contractors. The document store holds the evidence that any of it happened. Knock out the first link and the rest degrade in a specific, predictable order — which is exactly why disaster recovery for property management has to be designed as a chain.
Scoping disaster recovery for property management therefore starts with the dependency map, not with the server list. Draw which system feeds which, mark the ones with an external deadline attached, and the recovery priorities write themselves.
Availability is a legal requirement, not just a commercial one
Article 32(1)(b) of the UK GDPR requires the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services. Article 32(1)(c) requires the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident. Article 32(1)(d) requires a process for regularly testing and evaluating those measures. A managing agent holding tenant data has an availability duty in law, and the ICO’s own security guidance says both controllers and processors need resilience, restoration and regular testing.
What “the systems” actually are
| System | What stops immediately | Who notices first | Realistic tolerance |
|---|---|---|---|
| Property CRM | Tenancy lookup, viewings, applications | Negotiators, within minutes | Hours |
| Rent and client accounting | Receipting, landlord payouts, arrears | Accounts, same day | Hours |
| Email and calendars | Every external instruction | Everyone, within minutes | Minutes |
| Maintenance and repairs portal | Job raising, contractor dispatch | Tenants, within an hour | Hours |
| Document store | Certificates, agreements, evidence | Property managers, same day | Hours |
| Telephony | Inbound tenant contact | Reception, within minutes | Minutes |
| Identity and sign-in | Access to all of the above | Everyone, immediately | Minutes |
The three ways property firms actually go down
Cyber attack is the headline, but it is not the most common cause. The Cyber Security Breaches Survey 2025/2026 found phishing was by far the most prevalent attack type, hitting 38% of businesses, while ransomware fell to 1% from 3% in each of the two preceding years.
The other two causes are duller and more frequent. Supplier outage is the first: your cloud CRM or portal provider is down and you can do nothing but wait. Self-inflicted loss is the second: somebody deletes a site, a migration goes wrong, or a mailbox is emptied on a leaver’s last day. A plan for disaster recovery for property management has to cover all three, because only one of them is a security problem. Building disaster recovery for property management around ransomware alone leaves the two likelier scenarios unhandled.
Hour One: The Property CRM Is Unavailable
Start the clock. The property CRM — Reapit AgencyCloud, Alto, Street, Jupix, or whichever platform runs the business — stops responding. Nothing has been lost. Nothing can be reached either.
What is inside the CRM that nothing else holds
The CRM is the index of the business. It knows which tenant is in which property, under which tenancy type, at which rent, with which landlord, on which renewal date, with which deposit in which scheme. Very little of that lives anywhere else in a usable form. Spreadsheets carry fragments. Memory carries more than most managers admit. When it goes, the firm loses its map before it loses any of the territory, which is why every credible approach to disaster recovery for property management treats the CRM as the first system to plan around.
The first sixty minutes
Negotiators cannot confirm availability, so viewings are booked blind or not at all. Property managers cannot check a tenancy start date before answering a tenant question. Nobody can raise a works order against a property because the property record is the anchor the works order attaches to. Applications in progress stall mid-referencing. Within an hour the firm is running on whatever individual staff happen to know, which is the definition of key-person risk arriving all at once. Good disaster recovery for property management is designed to shorten exactly this hour.
Why “it is the vendor’s problem” is not a plan
Most UK property CRMs are now cloud-hosted, and the honest position is that you cannot recover somebody else’s SaaS platform. Reapit’s last publicly acknowledged outage was logged on 23 April 2026, and Alto now sits inside Alto Software Group, which Houseful spun out as a standalone business in January 2025. Neither fact helps you at 09:15. What helps is having decided in advance what the firm does while a supplier recovers — and that decision belongs in your plan for disaster recovery for property management, not the vendor’s.
The offline pack that actually works
The single highest-value, lowest-cost control here is a daily export. A scheduled extract of active tenancies, contact numbers, rents, deposit scheme references, landlord contacts and current works orders, written to a location that is not the CRM and not the same identity provider, turns a total blackout into a bad but workable day. It costs almost nothing. Very few firms have one, and every firm that has ever lost a CRM for a day wishes it had. If you take one action from this guide to disaster recovery for property management, take this one.
Hour Two: The Rent System Is Unavailable
The rent and client accounting system is where disaster recovery for property management stops being an inconvenience and starts being a regulatory matter, because the money in that system is not yours.
Client money changes the stakes
Client money protection has been a legal requirement for letting agents in England, Scotland and Wales for years, delivered through approved schemes run by Propertymark, RICS and safeagent. Those schemes exist because agents hold rent, deposits and float on behalf of other people. An outage does not put that money at risk in the way misappropriation does, but it does stop you evidencing where it is, reconciling it, or moving it on time — and reconciliation you cannot perform is a control you cannot demonstrate. That is the specific reason disaster recovery for property management differs from generic small-business continuity advice.
What actually stops
Rent receipting stops, so incoming payments accumulate unmatched in the client account. Landlord payment runs stop, which is the one delay landlords notice within twenty-four hours. Arrears chasing stops, and arrears cases are time-sensitive by nature. Deposit registrations stop, and that one has a statutory clock attached. Contractor invoice payments stop, which is how an outage turns into contractors declining your next job.
The deposit clock does not pause for your outage
Where a deposit is taken for an assured shorthold tenancy it must be protected in an authorised scheme and the prescribed information served on the tenant within 30 days of receipt. Miss it and the court can order a penalty of between one and three times the deposit under section 214 of the Housing Act 2004, and a tenant has six years to bring the claim. No statute, scheme or ombudsman makes an allowance because your systems were down. This is the single clearest argument for treating disaster recovery for property management as a compliance control rather than an IT nicety.
Reconciliation debt is the hidden cost
The restore is not the end of it. Every payment that arrived during the outage still has to be matched, every landlord statement regenerated, and every arrears position recalculated against the correct dates. Firms consistently underestimate this. A four-hour outage during a rent-run week can produce two days of accounts work, and that work lands on the same team that is also answering the phones about it. Any honest costing of disaster recovery for property management counts that catch-up labour, not just the restore itself.
Hour Three: Email Is Unavailable
Email is the failure that multiplies every other one, because email is where the property business actually happens.
Everything external arrives here
Landlord instructions, tenant complaints, contractor quotes, referencing results, solicitor correspondence, portal enquiries, deposit scheme notifications and bank alerts all arrive by email. When it is down, the firm is not just unable to send — it is unable to know what it has been asked to do. Work continues to be requested and none of it is visible. That backlog is invisible during the outage and overwhelming after it, and it is why disaster recovery for property management gives email the shortest recovery target of any system.
The 93-day and 14-day defaults nobody reads
Microsoft’s built-in retention is not a backup, and the numbers matter. Items deleted from a SharePoint or OneDrive site are held across the first- and second-stage recycle bins for a total of 93 days, after which they are permanently deleted; that window is not configurable. In Exchange Online the default deleted item retention is 14 days, with recovery from the Recoverable Items folder for a limited further period. Those defaults protect against a user error noticed quickly. They do not protect against a deletion noticed in month four, and they do not restore a tenant’s mailbox to a point in time.
Impersonation risk peaks during an outage
There is a second-order effect worth naming. When your email is down and everyone knows it, a fraudulent message claiming to be from your firm — with new bank details for a rent payment or a deposit return — is far more likely to be believed. Outages are a social engineering opportunity, which is why the communications plan matters as much as the technical one, and why disaster recovery for property management should be written alongside your fraud controls rather than separately from them.
What good looks like
A firm with a mature approach keeps a second, independent channel that does not depend on the same identity provider or the same domain: a pre-agreed SMS or WhatsApp broadcast list for landlords, a status page on separately hosted infrastructure, and a small set of mobile numbers already published to key contractors. None of that is expensive. All of it has to exist before the day it is needed, which is the recurring theme of disaster recovery for property management — the cheap controls only work if they predate the incident.
Tenant Communication Stops — and the Clock Does Not
Every outage becomes a tenant experience problem within about two hours, and tenant experience problems become complaints, which have their own timescales and their own regulators. This is the point where disaster recovery for property management stops being measured in systems restored and starts being measured in relationships kept.
The complaint escalation path is unforgiving
Letting and managing agents in England must belong to a government-approved redress scheme. A complaint that is not acknowledged and handled inside the scheme’s timescales escalates whether or not your systems were working. Under the Renters’ Rights Act 2025 — whose main provisions commenced on 1 May 2026 — a Private Rented Sector Database is being introduced with registration rolling out from late 2026, and a Landlord Ombudsman follows behind it. The direction of travel is more recorded obligations with more defined timescales, not fewer.
Vulnerable tenants and emergency repairs
Not every stopped conversation is equal. A tenant reporting no heating in January, a suspected gas leak, a lone occupant with mobility needs, or a safeguarding concern cannot be told to email again tomorrow. Any credible plan for disaster recovery for property management names an emergency contact route that works when the main systems do not, and makes sure the out-of-hours provider has a copy of it.
The message you send matters more than the outage
Tenants forgive outages. They do not forgive silence. A single honest message — we have a system failure, repairs reported today are logged manually on this number, emergencies call this number — converts an outage from a trust event into an operations event. Draft it now, keep it in a document that is not in the affected system, and give two named people the authority to send it without waiting for a management meeting. Communication templates belong in the disaster recovery for property management plan itself, not in someone’s head.
Contractor Scheduling Stops and Compliance Dates Slip
The repairs supply chain is the part of the chain that firms notice last and regret longest, because its damage is deferred. Plans for disaster recovery for property management routinely stop at the office door and forget the contractors entirely.
Fixflo, works orders and the dispatch gap
Repairs platforms such as Fixflo sit between tenant reports and contractor dispatch and integrate with the major CRMs; Fixflo alone reports covering well over a million and a half UK rental units. When the repairs platform or the CRM behind it is unavailable, jobs are not merely delayed — they are undocumented. Tenants report faults by phone that never get logged, contractors attend without a works order, and the audit trail that proves you responded promptly develops a hole exactly where you will later need it.
Statutory inspections do not reschedule themselves
Gas safety checks are annual. Electrical installation condition reports run on a five-year cycle for rented properties. Fire risk assessments, legionella assessments and alarm testing all sit on their own cadence, tracked in the same systems that just went down. A three-day outage in the wrong week means certificates expire before the reminder ever fires. That is why disaster recovery for property management must include the compliance diary as a recovery priority, not treat it as ordinary data.
Contractors are a supply chain, and supply chains have memory
An unpaid contractor invoice and a cancelled appointment cost you goodwill you will need at the next emergency call-out. Small firms remember which agents pay late and which ones wasted their morning. The commercial damage from a three-day outage often shows up two months later as slower response times on your own jobs, and it never appears in the incident report. Costing disaster recovery for property management purely on restore time misses this entirely.
| Outage length | Tenant impact | Landlord impact | Compliance impact |
|---|---|---|---|
| Under 2 hours | Slow answers | None visible | None |
| 2–8 hours | Repairs unlogged | Queries unanswered | Diary reminders missed |
| 1–2 days | Complaints begin | Payment run delayed | Deposit deadlines at risk |
| 3–5 days | Redress referrals | Instructions withdrawn | Certificates lapse |
| Over a week | Media and review damage | Portfolio moves | Reportable failures |
Files Are Unavailable: Certificates, Agreements and Evidence
The document store is the last link in the chain and the one that carries the legal weight, because documents are how a property firm proves what it did. Everything else in disaster recovery for property management is about trading again; this part is about defending yourself afterwards.
Documents are evidence, not just files
A gas safety record is not a PDF. It is the evidence that you complied. Right to Rent check copies must be retained for the duration of the tenancy and at least a further year. Tenancy agreements, prescribed information, deposit certificates, service charge accounts, Section 20 consultation records and the proof that the Renters’ Rights information sheet was served on existing tenants by 31 May 2026 all have to be producible on demand, sometimes years later. Losing them is not an inconvenience; it is the loss of your defence.
Ransomware attacks the evidence first
Attackers understand this. Sophos surveyed 2,158 IT and cybersecurity leaders in 17 countries whose organisations were hit by ransomware in the preceding twelve months and found that 56% of attacks succeeded in encrypting data, up from 50% the year before. Encrypted evidence is unavailable evidence. That is why the NCSC’s guidance on ransomware-resistant backups is explicit that attackers deliberately target connected backup devices and cloud backup locations to make recovery harder, and why disaster recovery for property management has to assume the attacker reaches the backups too.
The shared-drive problem
Many property firms still keep working documents on a mapped drive or an unmanaged file server, sometimes alongside a cloud store that holds a different, older copy. Two partial truths are worse than one. Consolidating the document estate is not a disaster recovery task in itself, but it is a prerequisite, because you cannot define a recovery point for data you cannot enumerate. Firms that skip this step end up with a disaster recovery for property management plan that protects the tidy half of the estate and quietly ignores the rest.
Backup: The Foundation of Disaster Recovery for Property Management
Backup is where every discussion of disaster recovery for property management should start, and where most of them stop. It is necessary. It is not sufficient. Here is the part that matters.
The 3-2-1 rule, and why the NCSC still leads with it
The NCSC’s guidance describes the 3-2-1 rule as the most common method of building resilient backups: at least three copies, on two devices, with one held offsite. Its blog on offline backups is blunt about the reason — the NCSC has seen numerous incidents where ransomware encrypted not just the data on disk but the connected USB drives, network storage and cloud storage holding the backups. A backup that is permanently reachable from the network is a backup an attacker can reach too. Applied to disaster recovery for property management, the third copy is usually the one that saves the tenancy files.
Microsoft 365 is not backed up for you
This is the single most common misconception in the sector, and it undermines more disaster recovery for property management plans than any other assumption. Microsoft operates a shared responsibility model: it guarantees the availability of the service, not the recoverability of your content after you delete or corrupt it.
Beyond the 93-day recycle bin window in SharePoint and OneDrive and the default 14-day deleted item retention in Exchange, there is no point-in-time restore of your tenancy files unless you have bought one. Microsoft 365 Backup exists as a first-party option priced at around $0.15 per gigabyte per month with restore points taken roughly every ten minutes, and there is a mature third-party market alongside it.
| Capability | Built-in Microsoft 365 | Dedicated backup |
|---|---|---|
| Recover a file deleted yesterday | Yes, recycle bin | Yes |
| Recover a file deleted 6 months ago | No | Yes |
| Restore a whole site to a point in time | Limited | Yes |
| Restore a leaver’s mailbox after licence removal | Only if placed on hold | Yes |
| Recover from mass malicious deletion | Partial, within 93 days | Yes |
| Copy an attacker with your credentials cannot delete | No | Yes, with immutability |
| Export for a legal or regulatory request | Via eDiscovery | Yes |
Backups are working better — for the firms that have them
There is genuinely good news in the data. Sophos found backup-based recovery jumped to 66% of encrypted-data cases in 2026, up twelve percentage points on the previous year, while 48% of encrypted victims paid a ransom and the median payment fell to $769,000. Average recovery cost still reached $1.7 million per incident, up 11% year on year. Read those together and the message is simple: backups now work often enough to be the primary recovery route, and recovery is still expensive enough that you want it to be fast.
Immutability is the control that changes the outcome
If one technical change is worth making this quarter, make backups immutable. An immutable copy cannot be altered or deleted for a defined retention window, even by an administrator account, even by an attacker holding valid credentials. It is the difference between a backup that survives a compromise and a backup that is deleted as step one of the attack. Any serious specification for disaster recovery for property management now includes immutability, multi-factor authentication on the backup console, and alerting on backup job failure.
RTO and RPO: Setting Recovery Targets System by System
RTO and RPO are the two numbers that turn a vague intention into a plan you can buy, build and test against. Without them, disaster recovery for property management is a conversation; with them, it is a specification.
The definitions, plainly
Recovery Time Objective is how long a service may be unavailable before the consequences become unacceptable. Recovery Point Objective is how much recent data you can afford to lose, measured backwards from the moment of failure. If your RPO is 24 hours and you fail at 16:00, you accept losing a day’s work. Stating both numbers per system is the entire discipline of disaster recovery for property management; everything else is engineering to meet them.
Property firms need different numbers for different systems
The mistake is setting one target for the whole business. Email and telephony need to come back in minutes because they are how tenants reach you. The rent system needs to come back within hours because payment runs and deposit deadlines are date-bound. The marketing website can wait a day. A single blanket target either overspends on things that do not matter or underprotects the ones that do, and that per-system judgement is the core of practical disaster recovery for property management.
| System | Suggested RTO | Suggested RPO | Why |
|---|---|---|---|
| Identity and sign-in | 1 hour | 15 minutes | Gates every other system |
| Email and telephony | 2 hours | 15 minutes | Only inbound tenant route |
| Rent and client accounting | 4 hours | 15 minutes | Client money, dated deadlines |
| Property CRM | 8 hours | 1 hour | Index for all operations |
| Document store | 8 hours | 1 hour | Compliance evidence |
| Repairs and contractor portal | 24 hours | 4 hours | Phone workaround exists |
| Marketing website and portals | 24 hours | 24 hours | Revenue impact is delayed |
Write the targets down and get them agreed by the business
The numbers are a business decision wearing technical clothing. The person who should sign them off is the director who will be asked by a landlord why the payment run was late, not the person who administers the servers. Put the agreed table in the plan, review it annually, and use it as the specification when you buy backup, replication or a managed service. Without agreed targets, disaster recovery for property management is an opinion. With them, it becomes something you can hold a supplier to.
Recovery Testing: Proving Disaster Recovery for Property Management Works
An untested plan is a hypothesis. Testing is the step everyone skips, and it is also the step that UK GDPR Article 32(1)(d) explicitly requires — a process for regularly testing, assessing and evaluating the effectiveness of your measures.
Three levels of test, in increasing order of honesty
A tabletop exercise walks the management team through a scenario in a room, and is worth doing quarterly because it costs an hour and exposes decision-making gaps. A component restore actually recovers something — a mailbox, a site, a database — and proves the backup is readable rather than merely green in a dashboard. A full failover test brings the priority systems up in the recovery environment and has real users work in it. Only the third one tells you your RTO is real, and only the third one turns disaster recovery for property management from a document into a demonstrated capability.
| Test type | Frequency | Effort | What it proves |
|---|---|---|---|
| Tabletop exercise | Quarterly | 1–2 hours | People know their roles |
| Spot file or mailbox restore | Monthly | 30 minutes | Backups are readable |
| Full site or database restore | Half-yearly | Half a day | Restore speed is measurable |
| Failover with real users | Annually | 1–2 days | RTO is achievable in practice |
| Supplier outage simulation | Annually | Half a day | Manual workarounds function |
What a property-sector test should actually include
Restore a tenancy file from six months ago and time it. Recover a departed property manager’s mailbox and confirm the landlord correspondence is intact. Reissue a gas safety certificate from the document store. Run a rent reconciliation from the recovered accounting data and confirm it balances. Send the tenant holding message through the alternative channel to a test group.
Those five tasks exercise the whole chain, and each one maps to a real obligation. Anything less is testing the technology while ignoring the business. A test script for disaster recovery for property management should read like a week in the life of the firm, not like a storage vendor’s checklist.
Record the result, including the failures
The test log is the evidence. Record what was restored, how long it took against the stated RTO, what did not work, and what changed as a result. Regulators, insurers and increasingly landlords’ own due diligence questionnaires ask for exactly this evidence of disaster recovery for property management. A test that found three problems and fixed them is a better artefact than a test that reported everything perfect, and any honest programme produces the former far more often than the latter.
Test the humans, not just the systems
The most common failure in a real incident is not technical. It is that the person with the recovery credentials is on holiday, the runbook lives in the system that is down, or nobody is willing to declare the incident. Print the plan. Store credentials in a way that survives the loss of your identity provider. Name a deputy for every role. Decide in advance who has authority to say the words “we are invoking the plan”. Disaster recovery for property management fails on people far more often than it fails on technology.
What Disaster Recovery for Property Management Costs
Cost is where most conversations stall, usually because the question is asked without a comparison. Nobody can say whether disaster recovery for property management is expensive until they price the alternative.
The comparison that matters
Set the annual cost of protection against the cost of one bad week. Sophos puts average ransomware recovery at $1.7 million per incident across surveyed organisations, and that figure excludes the client money reconciliation, the redress complaints and the landlord instructions that a UK managing agent would lose on top. Even discounted heavily for a smaller firm, the arithmetic rarely favours doing nothing.
Meanwhile first-party backup for Microsoft 365 sits at roughly $0.15 per gigabyte per month, so protecting 500 GB of tenancy documents is a line item of about $75 a month. Set against that, the entry-level tier of disaster recovery for property management costs less than one negotiator’s mobile phone contract.
The three cost tiers in practice
| Tier | What you get | Typical RTO | Suits |
|---|---|---|---|
| Backup only | Immutable copies, manual restore | 1–3 days | Under 10 staff, fully cloud |
| Backup plus documented plan | Targets, runbooks, tested restores | 8–24 hours | 10–50 staff, mixed estate |
| Managed disaster recovery | Replication, failover, 24/7 response | 1–8 hours | 50+ staff or block management |
Where firms waste money
Two patterns recur. The first is paying for replication of systems that could tolerate a day’s outage while leaving the document store on a single copy. The second is buying a premium backup product and never testing a restore, which purchases the invoice rather than the outcome. Spend in the order the chain fails: identity, email, rent, CRM, documents. That ordering is the cheapest useful thing in this entire guide to disaster recovery for property management.
How Managed IT Delivers Disaster Recovery for Property Management
This is the point where the topic connects to the wider support model, because a plan nobody owns is a document, not a capability. Delivered properly, disaster recovery for property management is an ongoing service rather than a project with an end date.
What has to be somebody’s job
Backups have to be monitored daily, because backup jobs fail silently and a dashboard nobody reads is not monitoring. Restores have to be tested on a schedule. Targets have to be reviewed when the business changes — a new block management contract or a CRM migration changes the whole calculation. Someone has to be reachable at 07:00 on a Monday with the authority to act. In a firm of thirty people that is not a spare-time responsibility, which is why disaster recovery for property management is normally delivered as part of managed IT services rather than as a product you buy once.
| Responsibility | In-house only | With a managed provider |
|---|---|---|
| Daily backup verification | Often skipped | Monitored and reported |
| Restore testing | Ad hoc | Scheduled and evidenced |
| Out-of-hours response | One person’s mobile | Rota with escalation |
| Vendor liaison during outage | Whoever is free | Named escalation path |
| Plan review after change | Rarely happens | Part of service review |
| Evidence for insurers and landlords | Reconstructed later | Maintained continuously |
A 90-day starting plan
In the first thirty days, inventory the systems, agree RTO and RPO per system with a director, and confirm what is actually backed up — including Microsoft 365, which usually is not. In the next thirty, close the gaps: immutable backups with multi-factor authentication on the console, a daily CRM export to independent storage, an alternative tenant contact channel, and a printed runbook. In the final thirty, test — one component restore, one tabletop, and one honest write-up. Ninety days is enough to move disaster recovery for property management from “we have backups” to a defensible position.
It sits inside a wider security posture
Disaster recovery is the last line, not the only one. It works best on top of the controls covered in our cyber security checklist for managing agents, the certification path in our Cyber Essentials guide for property firms, and the fraud controls in our guide to business email compromise in property management. Cloud computing has removed a great deal of the old server-room risk and replaced it with supplier concentration risk, which is a different problem needing a different plan.
Disaster Recovery for Property Management: Frequently Asked Questions
Is our cloud CRM already covered by the vendor’s disaster recovery?
Partly, and not in the way most firms assume. The vendor is responsible for restoring their platform after their own failure. They are not generally responsible for restoring data you or a compromised account deleted, and their recovery timeline is theirs to set, not yours to negotiate during an incident. Read the contract for the stated RTO, and plan for the gap between that number and the one your business actually needs. That gap is where your own disaster recovery for property management arrangements have to do the work.
How often should we test?
At minimum: a spot restore monthly, a tabletop exercise quarterly, and a full restore of a priority system every six months. Firms managing blocks or holding significant client money should add an annual failover test with real users. The regulatory expectation under Article 32(1)(d) is regular testing, and layering monthly, quarterly and annual tests is a defensible reading of that for disaster recovery for property management at this size of firm.
What is the single most valuable thing to fix first?
Immutable, credential-separated backups covering Microsoft 365 and the document store, followed immediately by a daily CRM export. Those two changes convert the worst realistic scenario from an existential event into an expensive week, and both can usually be delivered inside a month. They are the highest-return moves available in disaster recovery for property management, and neither requires new hardware.
Do we need this if everything we use is software as a service?
Yes, and arguably more so. A fully cloud firm has less hardware to lose and more supplier dependency to manage, and supplier outages are the failure mode you cannot fix with your own engineering. Disaster recovery for property management in a software-as-a-service estate shifts from restoring servers to maintaining independent copies, alternative channels and documented manual workarounds.
Who should own the plan?
A named director owns it, with a named deputy. A provider or internal team operates it. Keeping ownership of disaster recovery for property management at board level is what stops the plan going stale after the next CRM change, and it is what regulators, insurers and institutional landlords expect to see when they ask.
References
Cyber Security Breaches Survey 2025/2026
Sophos: The State of Ransomware 2026
NCSC: Ransomware-resistant backups
NCSC: Offline backups in an online world
NCSC 10 Steps to Cyber Security: Data security
The Housing (Tenancy Deposits) (Prescribed Information) Order 2007
GOV.UK: Tenancy deposit protection
Propertymark: Client Money Protection
RICS Client Money Protection Scheme
Microsoft Learn: SharePoint data deletion
Microsoft Learn: OneDrive retention and deletion
Microsoft Learn: Retention for SharePoint and OneDrive
NRLA: Renters’ Rights Act commencement confirmed