Real estate cybersecurity is bigger than wire fraud. A modern agent may work across email, a CRM, transaction software, cloud storage, an MLS, lockbox systems, e-signature tools, calendars, messaging platforms, marketing accounts, mobile devices, and several AI products. One old login, over-permissioned integration, shared account, or untested backup can connect more of that stack than anyone realizes.

A practical real estate cybersecurity checklist should make that system visible and give each control an owner. It should protect routine work before an incident, make unusual activity easier to detect, and tell people what to do when the normal workflow becomes unsafe.

I do not count a security policy that nobody can execute under pressure.

AI changes the exposure because many tools ask to read email, join meetings, connect calendars, ingest CRM records, browse files, create content, or act in other systems. AI can help organize approved security work. It should not receive secrets, investigate a live compromise on its own, or decide that an account, person, message, or file is safe.

What Does Real Estate Cybersecurity Cover?

Real estate cybersecurity is the operating practice of protecting the people, accounts, devices, networks, applications, data, communications, vendors, and recovery processes used to conduct real estate business. It includes prevention, but it also includes detection, response, and recovery.

NAR's cybersecurity checklist for real estate professionals addresses email, passwords, transactions, devices, networks, law, and insurance. The NIST Cybersecurity Framework 2.0 small-business guide organizes the work around six functions: govern, identify, protect, detect, respond, and recover.

That lifecycle is useful for real estate because a checklist made only of passwords and phishing warnings leaves out ownership, vendor access, monitoring, business continuity, client communication, and recovery.

This article is operational education, not legal, cybersecurity, privacy, insurance, forensic, regulatory, or incident-response advice. Use the brokerage's current requirements and qualified professionals for the actual systems and circumstances.

How This Checklist Fits the Existing Security Workflows

WorkflowQuestion it ownsRelated BrokerCanvas guide
Cybersecurity baselineAre the business systems, accounts, devices, permissions, backups, and response paths controlled?This checklist
AI data privacyShould this information enter this specific tool and workflow?AI data privacy for real estate agents
Vendor evaluationDoes the product, plan, contract, and provider meet the required standard?real estate AI vendor evaluation checklist
Wire-fraud preventionHow are funds instructions, changes, trusted contacts, and callbacks controlled?real estate wire-fraud prevention workflow
Seller verificationIs the claimant the owner or a person with verified authority to sell?seller impersonation verification checklist

The cybersecurity page is the system map. The other guides handle higher-risk decisions within that map.

Why AI Tools Need to Be Included in the Security Inventory

An AI application may look like a writing tool while holding broader permissions. A browser extension may see page content. A meeting assistant may receive audio, transcripts, participant names, and calendar details. A CRM assistant may read contacts and write notes. An automation platform may trigger messages or move data between several vendors.

For every AI tool or integration, record:

My default is simple: if an app does not need the permission, it does not get the permission.

A Practical Real Estate Cybersecurity Checklist

1. Name the Security Owner and Decision Path

Identify the person accountable for the program, the technical support provider, the broker or manager, the privacy or legal contact, the insurance contact, and the backup owner. Write down who can disable an account, disconnect an integration, preserve evidence, notify a vendor, and authorize recovery.

A solo agent still needs named external contacts and a written first-call sequence. “Call someone technical” is not an incident plan.

2. Inventory the Business Before Trying to Protect It

List business-owned and approved laptops, phones, tablets, routers, removable drives, email domains, websites, CRMs, transaction platforms, file systems, MLS and association access, lockbox tools, e-signature products, marketing accounts, calendars, messaging systems, payment services, AI tools, extensions, automations, and vendors.

Record owner, administrator, purpose, data category, criticality, login method, integrations, renewal date, and recovery contact. Include systems that are free, personally purchased, rarely used, or running under an old team member's account.

3. Classify Data and Reduce What You Keep

Separate public, internal, confidential, and restricted information using the brokerage's actual policy. Identify where client messages, contracts, signatures, identity records, transaction details, credentials, financial information, recordings, CRM notes, and MLS content are stored and copied.

Keep only what the business needs and is permitted or required to retain. The AI data privacy workflow provides the minimum-necessary decision process for prompts, files, recordings, integrations, and accidental uploads.

4. Give Every Person a Unique Account

Shared logins make it difficult to remove one person's access, attribute a change, review activity, or investigate an incident. Use unique accounts for employees, agents, assistants, contractors, vendors, and administrators wherever the system supports them.

Do not share an administrator password through email, text, a team document, or an AI chat. Use approved access and credential-management methods.

5. Use a Password Manager and Eliminate Reuse

Use long, unique credentials generated and stored through an approved password manager. Change default credentials, protect password-manager recovery, limit administrators, and define the emergency-access process.

The FTC's current small-business cybersecurity guidance recommends strong passwords, avoiding reuse, regular updates, backups, staff training, access controls, incident planning, and vendor oversight.

6. Require Strong Multifactor Authentication

Require multifactor authentication for email, file storage, CRM, transaction systems, domain and website administration, marketing accounts, remote access, password management, cloud consoles, payment systems, and other sensitive services. Start with administrators and people handling confidential information, then close the remaining gaps.

CISA advises businesses to require MFA wherever possible and use the strongest option available, with phishing-resistant methods preferred. Document backup factors and recovery so losing one device does not force the team into unsafe workarounds.

7. Apply Least Privilege to Roles and Integrations

Give people and applications only the access needed for the current job. Review administrators, delegated inboxes, shared drives, CRM roles, transaction files, calendars, contact exports, API tokens, connected apps, browser extensions, and automation credentials.

Permissions should expire when the project, role, or vendor relationship ends. A tool should not keep full inbox access because it once needed to draft one follow-up.

8. Patch and Protect Devices

Use supported operating systems and applications, automatic security updates where appropriate, screen locks, device encryption, approved anti-malware or endpoint controls, remote-lock or wipe capabilities, and separate user and administrator privileges.

Define what happens if a phone or laptop is lost, stolen, replaced, sold, or given to another person. Factory reset and disposal need an approved process; dragging files to the trash is not secure removal.

9. Secure Networks and Remote Work

Change router defaults, use current encryption, update firmware, separate guest or untrusted devices, and limit administrative access. Avoid conducting sensitive work through unknown public networks without the approved protection.

Remote work rules should cover home networks, travel, open-house devices, shared computers, printing, paper files, screens in public, charging stations, and the process for reporting a lost device.

10. Harden Email, Domains, and Recovery Accounts

Email often controls password resets for everything else. Protect the domain registrar, DNS, email administrators, recovery accounts, forwarding rules, delegated access, connected applications, and suspicious-login alerts. Configure appropriate email-authentication controls with qualified technical help.

Review new inbox rules, unexpected delegates, changed recovery methods, unknown sessions, and OAuth grants. An inbox can be compromised without immediately changing the visible password.

11. Use Approved Transaction and File-Sharing Channels

Define where contracts, disclosures, identity records, inspection materials, closing files, photos, and client communications belong. Avoid moving sensitive files through personal email, consumer file links, public AI tools, or unapproved messaging because it feels faster.

Set sharing expiration, download, external-user, forwarding, and retention controls where available. Review public or “anyone with the link” shares on a schedule.

12. Evaluate Vendors and Connected AI Tools

Review security controls, data use, retention, incident notice, subcontractors, account administration, exports, deletion, business continuity, insurance, support, and exit before granting access. Match diligence to the data and actions the vendor can reach.

The 30-question AI vendor evaluation checklist provides a procurement and pilot structure. A strong vendor does not remove the need to configure the account correctly or review permissions later.

13. Back Up Critical Data and Test Restoration

Identify the files, configurations, records, and services required to continue operations. Define backup owner, frequency, location, access, encryption, versioning, isolation, retention, and restoration order. Confirm what each cloud vendor backs up and what remains the customer's responsibility.

A backup is not proven because a dashboard says it ran. Restore a representative file or system through the approved process and document the result. The NIST small-business guide emphasizes recovery responsibilities, backup integrity, restoration priorities, communication, and after-action learning.

14. Turn On Useful Logging and Alerts

Use available alerts for suspicious logins, MFA changes, password resets, new administrators, forwarding rules, mass exports, unusual sharing, API tokens, connected applications, domain changes, and security-setting changes. Send alerts to a monitored destination that is not controlled solely by the account being watched.

Decide who reviews each alert, how quickly, what creates a hold, and when technical help is required. Logs are useful only if the organization can access and interpret them when needed.

15. Make Onboarding and Offboarding Security Events

Onboarding should create the right unique accounts, role, MFA, device controls, approved-tool access, training, and acknowledgment. Offboarding should revoke sessions, credentials, tokens, integrations, forwarding, shared links, devices, exports, group membership, recovery access, and physical access.

Do not wait for a subscription renewal or quarterly meeting to remove someone who no longer needs access.

16. Write and Rehearse the Incident and Recovery Plans

Write separate playbooks for suspicious email, account takeover, lost device, malware or ransomware, vendor breach, exposed client data, website or domain compromise, wire-fraud attempt, and unauthorized listing or seller activity. Name the first actions, decision owner, technical contact, evidence process, business-continuity path, insurer and counsel route, law-enforcement path, client-communication owner, and recovery approval.

The FTC's data breach response guide recommends securing operations, fixing vulnerabilities, working with appropriate experts, reviewing service-provider access, and building a communication plan. Actual obligations depend on the incident, data, contracts, location, and applicable requirements.

A Real Estate System Access Matrix

A simple matrix makes invisible dependencies easier to review.

SystemCritical data or actionRequired controlOwner and review
Email and domainMessages, resets, identity, domain reputationUnique accounts, strong MFA, admin separation, forwarding and recovery reviewNamed administrator; monthly exception review
CRMContacts, notes, activities, exports, automationsRole access, export limits, integration inventory, offboardingOperations owner; quarterly access review
Transaction platformContracts, signatures, dates, confidential recordsApproved accounts, MFA, matter-level access, retention, audit trailBroker or transaction owner; file review
Cloud storageClient and business files, external sharesFolder roles, expiring shares, public-link review, backup and recoveryAdministrator; monthly external-share review
AI and automation toolsPrompts, uploads, connectors, generated actionsApproved uses, minimum permissions, data rules, logs, human approval, stop controlWorkflow owner; feature and permission review
Website and marketingBrand, forms, leads, advertising, trackingAdmin MFA, least privilege, domain protection, form and script inventoryMarketing and technical owners; release review

Use the brokerage's actual systems and review cadence. The point is to expose orphaned administration, broad permissions, and recovery gaps.

What AI Can Help With Safely

With approved, non-sensitive, or synthetic inputs, AI can help:

AI can support the administrative work around security. It should not become the security authority.

What AI Should Not Do

Prompt: Build a Sanitized Security Inventory

You are helping a small real estate brokerage organize a cybersecurity
inventory from approved, non-sensitive information.

Do not request or accept:
- passwords, recovery codes, tokens, keys, account numbers, client data
- security answers, IP addresses, private URLs, vulnerability details
- live incident evidence or confidential system configurations

For each system I list, create fields for:
- business purpose
- business owner
- technical administrator
- user groups
- data categories, stated broadly
- critical actions the system can perform
- connected applications and permission categories
- authentication and MFA status
- backup, export, and recovery owner
- logging and alert owner
- vendor incident contact
- offboarding step
- last review and next review
- known / unknown / needs qualified review

Then return:
1. The structured inventory table
2. Missing owners and high-level unknowns
3. Systems that appear critical to business continuity
4. Questions for the broker, IT or security provider, privacy or legal
   reviewer, insurer, and vendor as applicable
5. A prioritized review queue based on access and business impact

Do not score a system as secure and do not invent missing controls.

Prompt: Create a Cybersecurity Tabletop Exercise

Create a fictional tabletop exercise for a real estate team using the
approved policy pasted below. This is training, not live incident advice.

Approved policy:
[paste non-sensitive policy language]

Scenario requirements:
- an agent receives a realistic password-reset message
- a mailbox rule appears unexpectedly
- a CRM integration has broader permissions than expected
- a client transaction is active
- the primary administrator is unavailable
- no money has been confirmed lost

Use fictional names, systems, domains, properties, and records. Do not
include working malicious links, usable credentials, exploit steps, or
instructions for evading controls.

Return:
1. Scenario setup
2. Eight timed developments
3. Expected pause, containment, escalation, and continuity action
4. Owner and backup owner for each decision
5. Evidence that should be preserved under approved guidance
6. Actions that would spread risk or damage evidence
7. Client and internal communication decision points
8. Recovery gates and after-action questions

Do not determine legal duties, attribute the attacker, or approve a live
response. Mark policy gaps for qualified human review.

What to Do When an Incident Is Suspected

Follow the current incident plan and qualified guidance. A practical high-level sequence is:

  1. stop unsafe activity without destroying evidence;
  2. contact the named security, IT, broker, and incident owners through known channels;
  3. isolate affected access or devices using the approved technical process;
  4. preserve original messages, logs, timestamps, alerts, devices, and actions according to guidance;
  5. protect unaffected systems and review related sessions, credentials, integrations, and recovery methods;
  6. engage counsel, insurer, privacy, vendors, financial institutions, closing partners, law enforcement, regulators, or affected parties as required;
  7. activate the business-continuity and recovery path; and
  8. maintain one verified incident timeline with decisions, owners, and communications.

Do not improvise forensic work, power down devices unless directed, delete suspicious messages, accuse a person, negotiate with an attacker, or promise that information or money is safe.

Measure Whether the Security Program Works

I count MFA coverage, revoked access, tested restores, and response time, not training slides delivered.

A 30-Day Implementation Plan

Week 1: Inventory and Ownership

List critical systems, devices, data locations, AI tools, integrations, administrators, vendors, and recovery contacts. Assign owners and pause one unknown high-access integration.

Week 2: Accounts and Access

Require unique accounts, close shared and dormant access, expand MFA, review administrators and recovery methods, and remove permissions that no longer match a role.

Week 3: Devices, Data, and Recovery

Confirm supported software, updates, encryption, device response, approved file channels, backup scope, and one representative restoration test.

Week 4: Response and Rehearsal

Finalize the contact tree and playbooks. Run one fictional email-account and connected-app tabletop, test after-hours coverage, record gaps, and assign corrections.

I would rather remove one unused integration than add another warning banner.

Common Real Estate Cybersecurity Mistakes

The Best First Step

Open a blank inventory and write down the ten systems that would stop the business or expose important client information if access were lost or misused. Name the business owner, administrator, MFA status, connected apps, backup or export path, and incident contact for each.

Then choose the highest-impact unknown and resolve it. Do not try to buy your way around an inventory you have not completed.

Final Takeaway

A useful real estate cybersecurity checklist is not a one-time technical audit. It is an operating rhythm: govern the program, identify what the business depends on, protect access and data, detect unusual activity, respond through named owners, and prove that recovery works.

AI tools belong in that inventory because they may hold data, connect systems, and take actions. They can support documentation and training, but they cannot own the security decision.

Start with visibility, reduce access, test the controls, and make the safe next action obvious before anyone is under pressure.