Real estate cybersecurity is bigger than wire fraud. A modern agent may work across email, a CRM, transaction software, cloud storage, an MLS, lockbox systems, e-signature tools, calendars, messaging platforms, marketing accounts, mobile devices, and several AI products. One old login, over-permissioned integration, shared account, or untested backup can connect more of that stack than anyone realizes.
A practical real estate cybersecurity checklist should make that system visible and give each control an owner. It should protect routine work before an incident, make unusual activity easier to detect, and tell people what to do when the normal workflow becomes unsafe.
I do not count a security policy that nobody can execute under pressure.
AI changes the exposure because many tools ask to read email, join meetings, connect calendars, ingest CRM records, browse files, create content, or act in other systems. AI can help organize approved security work. It should not receive secrets, investigate a live compromise on its own, or decide that an account, person, message, or file is safe.
What Does Real Estate Cybersecurity Cover?
Real estate cybersecurity is the operating practice of protecting the people, accounts, devices, networks, applications, data, communications, vendors, and recovery processes used to conduct real estate business. It includes prevention, but it also includes detection, response, and recovery.
NAR's cybersecurity checklist for real estate professionals addresses email, passwords, transactions, devices, networks, law, and insurance. The NIST Cybersecurity Framework 2.0 small-business guide organizes the work around six functions: govern, identify, protect, detect, respond, and recover.
That lifecycle is useful for real estate because a checklist made only of passwords and phishing warnings leaves out ownership, vendor access, monitoring, business continuity, client communication, and recovery.
This article is operational education, not legal, cybersecurity, privacy, insurance, forensic, regulatory, or incident-response advice. Use the brokerage's current requirements and qualified professionals for the actual systems and circumstances.
How This Checklist Fits the Existing Security Workflows
| Workflow | Question it owns | Related BrokerCanvas guide |
|---|---|---|
| Cybersecurity baseline | Are the business systems, accounts, devices, permissions, backups, and response paths controlled? | This checklist |
| AI data privacy | Should this information enter this specific tool and workflow? | AI data privacy for real estate agents |
| Vendor evaluation | Does the product, plan, contract, and provider meet the required standard? | real estate AI vendor evaluation checklist |
| Wire-fraud prevention | How are funds instructions, changes, trusted contacts, and callbacks controlled? | real estate wire-fraud prevention workflow |
| Seller verification | Is the claimant the owner or a person with verified authority to sell? | seller impersonation verification checklist |
The cybersecurity page is the system map. The other guides handle higher-risk decisions within that map.
Why AI Tools Need to Be Included in the Security Inventory
An AI application may look like a writing tool while holding broader permissions. A browser extension may see page content. A meeting assistant may receive audio, transcripts, participant names, and calendar details. A CRM assistant may read contacts and write notes. An automation platform may trigger messages or move data between several vendors.
For every AI tool or integration, record:
- the business owner and technical administrator;
- the exact account plan and login method;
- the users, roles, and administrators;
- the systems and data it can read, write, send, delete, or share;
- the model providers, subprocessors, extensions, and connected applications involved;
- retention, export, deletion, logging, and model-improvement settings;
- the approved use cases and prohibited information;
- how access is revoked and data is recovered or exported; and
- the incident contact and review date.
My default is simple: if an app does not need the permission, it does not get the permission.
A Practical Real Estate Cybersecurity Checklist
1. Name the Security Owner and Decision Path
Identify the person accountable for the program, the technical support provider, the broker or manager, the privacy or legal contact, the insurance contact, and the backup owner. Write down who can disable an account, disconnect an integration, preserve evidence, notify a vendor, and authorize recovery.
A solo agent still needs named external contacts and a written first-call sequence. “Call someone technical” is not an incident plan.
2. Inventory the Business Before Trying to Protect It
List business-owned and approved laptops, phones, tablets, routers, removable drives, email domains, websites, CRMs, transaction platforms, file systems, MLS and association access, lockbox tools, e-signature products, marketing accounts, calendars, messaging systems, payment services, AI tools, extensions, automations, and vendors.
Record owner, administrator, purpose, data category, criticality, login method, integrations, renewal date, and recovery contact. Include systems that are free, personally purchased, rarely used, or running under an old team member's account.
3. Classify Data and Reduce What You Keep
Separate public, internal, confidential, and restricted information using the brokerage's actual policy. Identify where client messages, contracts, signatures, identity records, transaction details, credentials, financial information, recordings, CRM notes, and MLS content are stored and copied.
Keep only what the business needs and is permitted or required to retain. The AI data privacy workflow provides the minimum-necessary decision process for prompts, files, recordings, integrations, and accidental uploads.
4. Give Every Person a Unique Account
Shared logins make it difficult to remove one person's access, attribute a change, review activity, or investigate an incident. Use unique accounts for employees, agents, assistants, contractors, vendors, and administrators wherever the system supports them.
Do not share an administrator password through email, text, a team document, or an AI chat. Use approved access and credential-management methods.
5. Use a Password Manager and Eliminate Reuse
Use long, unique credentials generated and stored through an approved password manager. Change default credentials, protect password-manager recovery, limit administrators, and define the emergency-access process.
The FTC's current small-business cybersecurity guidance recommends strong passwords, avoiding reuse, regular updates, backups, staff training, access controls, incident planning, and vendor oversight.
6. Require Strong Multifactor Authentication
Require multifactor authentication for email, file storage, CRM, transaction systems, domain and website administration, marketing accounts, remote access, password management, cloud consoles, payment systems, and other sensitive services. Start with administrators and people handling confidential information, then close the remaining gaps.
CISA advises businesses to require MFA wherever possible and use the strongest option available, with phishing-resistant methods preferred. Document backup factors and recovery so losing one device does not force the team into unsafe workarounds.
7. Apply Least Privilege to Roles and Integrations
Give people and applications only the access needed for the current job. Review administrators, delegated inboxes, shared drives, CRM roles, transaction files, calendars, contact exports, API tokens, connected apps, browser extensions, and automation credentials.
Permissions should expire when the project, role, or vendor relationship ends. A tool should not keep full inbox access because it once needed to draft one follow-up.
8. Patch and Protect Devices
Use supported operating systems and applications, automatic security updates where appropriate, screen locks, device encryption, approved anti-malware or endpoint controls, remote-lock or wipe capabilities, and separate user and administrator privileges.
Define what happens if a phone or laptop is lost, stolen, replaced, sold, or given to another person. Factory reset and disposal need an approved process; dragging files to the trash is not secure removal.
9. Secure Networks and Remote Work
Change router defaults, use current encryption, update firmware, separate guest or untrusted devices, and limit administrative access. Avoid conducting sensitive work through unknown public networks without the approved protection.
Remote work rules should cover home networks, travel, open-house devices, shared computers, printing, paper files, screens in public, charging stations, and the process for reporting a lost device.
10. Harden Email, Domains, and Recovery Accounts
Email often controls password resets for everything else. Protect the domain registrar, DNS, email administrators, recovery accounts, forwarding rules, delegated access, connected applications, and suspicious-login alerts. Configure appropriate email-authentication controls with qualified technical help.
Review new inbox rules, unexpected delegates, changed recovery methods, unknown sessions, and OAuth grants. An inbox can be compromised without immediately changing the visible password.
11. Use Approved Transaction and File-Sharing Channels
Define where contracts, disclosures, identity records, inspection materials, closing files, photos, and client communications belong. Avoid moving sensitive files through personal email, consumer file links, public AI tools, or unapproved messaging because it feels faster.
Set sharing expiration, download, external-user, forwarding, and retention controls where available. Review public or “anyone with the link” shares on a schedule.
12. Evaluate Vendors and Connected AI Tools
Review security controls, data use, retention, incident notice, subcontractors, account administration, exports, deletion, business continuity, insurance, support, and exit before granting access. Match diligence to the data and actions the vendor can reach.
The 30-question AI vendor evaluation checklist provides a procurement and pilot structure. A strong vendor does not remove the need to configure the account correctly or review permissions later.
13. Back Up Critical Data and Test Restoration
Identify the files, configurations, records, and services required to continue operations. Define backup owner, frequency, location, access, encryption, versioning, isolation, retention, and restoration order. Confirm what each cloud vendor backs up and what remains the customer's responsibility.
A backup is not proven because a dashboard says it ran. Restore a representative file or system through the approved process and document the result. The NIST small-business guide emphasizes recovery responsibilities, backup integrity, restoration priorities, communication, and after-action learning.
14. Turn On Useful Logging and Alerts
Use available alerts for suspicious logins, MFA changes, password resets, new administrators, forwarding rules, mass exports, unusual sharing, API tokens, connected applications, domain changes, and security-setting changes. Send alerts to a monitored destination that is not controlled solely by the account being watched.
Decide who reviews each alert, how quickly, what creates a hold, and when technical help is required. Logs are useful only if the organization can access and interpret them when needed.
15. Make Onboarding and Offboarding Security Events
Onboarding should create the right unique accounts, role, MFA, device controls, approved-tool access, training, and acknowledgment. Offboarding should revoke sessions, credentials, tokens, integrations, forwarding, shared links, devices, exports, group membership, recovery access, and physical access.
Do not wait for a subscription renewal or quarterly meeting to remove someone who no longer needs access.
16. Write and Rehearse the Incident and Recovery Plans
Write separate playbooks for suspicious email, account takeover, lost device, malware or ransomware, vendor breach, exposed client data, website or domain compromise, wire-fraud attempt, and unauthorized listing or seller activity. Name the first actions, decision owner, technical contact, evidence process, business-continuity path, insurer and counsel route, law-enforcement path, client-communication owner, and recovery approval.
The FTC's data breach response guide recommends securing operations, fixing vulnerabilities, working with appropriate experts, reviewing service-provider access, and building a communication plan. Actual obligations depend on the incident, data, contracts, location, and applicable requirements.
A Real Estate System Access Matrix
A simple matrix makes invisible dependencies easier to review.
| System | Critical data or action | Required control | Owner and review |
|---|---|---|---|
| Email and domain | Messages, resets, identity, domain reputation | Unique accounts, strong MFA, admin separation, forwarding and recovery review | Named administrator; monthly exception review |
| CRM | Contacts, notes, activities, exports, automations | Role access, export limits, integration inventory, offboarding | Operations owner; quarterly access review |
| Transaction platform | Contracts, signatures, dates, confidential records | Approved accounts, MFA, matter-level access, retention, audit trail | Broker or transaction owner; file review |
| Cloud storage | Client and business files, external shares | Folder roles, expiring shares, public-link review, backup and recovery | Administrator; monthly external-share review |
| AI and automation tools | Prompts, uploads, connectors, generated actions | Approved uses, minimum permissions, data rules, logs, human approval, stop control | Workflow owner; feature and permission review |
| Website and marketing | Brand, forms, leads, advertising, tracking | Admin MFA, least privilege, domain protection, form and script inventory | Marketing and technical owners; release review |
Use the brokerage's actual systems and review cadence. The point is to expose orphaned administration, broad permissions, and recovery gaps.
What AI Can Help With Safely
With approved, non-sensitive, or synthetic inputs, AI can help:
- turn an inventory template into interview questions for system owners;
- organize sanitized tool names, owners, review dates, and known controls;
- compare an approved checklist against a written procedure;
- create fictional phishing, lost-device, vendor-breach, and account-takeover exercises;
- rewrite approved security guidance into role-specific training language;
- create quiz questions from official and brokerage-approved sources;
- organize an after-action report from sanitized, verified facts; and
- identify missing owners, statuses, dependencies, and follow-up questions.
AI can support the administrative work around security. It should not become the security authority.
What AI Should Not Do
- receive passwords, recovery codes, API keys, session tokens, private keys, or live credentials;
- inspect a suspicious link, attachment, device, or account outside the approved technical process;
- declare a sender, login, file, vendor, device, or system safe;
- run autonomous remediation in live business systems without defined authority and controls;
- decide whether notification, reporting, insurance, legal, or regulatory obligations apply;
- contact an attacker, affected client, vendor, bank, insurer, or law-enforcement agency on its own;
- receive unnecessary incident evidence or confidential client data;
- replace logs, forensic preservation, qualified investigation, or restoration testing; or
- make the final decision to reconnect, restore, disclose, or resume operations.
Prompt: Build a Sanitized Security Inventory
You are helping a small real estate brokerage organize a cybersecurity
inventory from approved, non-sensitive information.
Do not request or accept:
- passwords, recovery codes, tokens, keys, account numbers, client data
- security answers, IP addresses, private URLs, vulnerability details
- live incident evidence or confidential system configurations
For each system I list, create fields for:
- business purpose
- business owner
- technical administrator
- user groups
- data categories, stated broadly
- critical actions the system can perform
- connected applications and permission categories
- authentication and MFA status
- backup, export, and recovery owner
- logging and alert owner
- vendor incident contact
- offboarding step
- last review and next review
- known / unknown / needs qualified review
Then return:
1. The structured inventory table
2. Missing owners and high-level unknowns
3. Systems that appear critical to business continuity
4. Questions for the broker, IT or security provider, privacy or legal
reviewer, insurer, and vendor as applicable
5. A prioritized review queue based on access and business impact
Do not score a system as secure and do not invent missing controls.
Prompt: Create a Cybersecurity Tabletop Exercise
Create a fictional tabletop exercise for a real estate team using the
approved policy pasted below. This is training, not live incident advice.
Approved policy:
[paste non-sensitive policy language]
Scenario requirements:
- an agent receives a realistic password-reset message
- a mailbox rule appears unexpectedly
- a CRM integration has broader permissions than expected
- a client transaction is active
- the primary administrator is unavailable
- no money has been confirmed lost
Use fictional names, systems, domains, properties, and records. Do not
include working malicious links, usable credentials, exploit steps, or
instructions for evading controls.
Return:
1. Scenario setup
2. Eight timed developments
3. Expected pause, containment, escalation, and continuity action
4. Owner and backup owner for each decision
5. Evidence that should be preserved under approved guidance
6. Actions that would spread risk or damage evidence
7. Client and internal communication decision points
8. Recovery gates and after-action questions
Do not determine legal duties, attribute the attacker, or approve a live
response. Mark policy gaps for qualified human review.
What to Do When an Incident Is Suspected
Follow the current incident plan and qualified guidance. A practical high-level sequence is:
- stop unsafe activity without destroying evidence;
- contact the named security, IT, broker, and incident owners through known channels;
- isolate affected access or devices using the approved technical process;
- preserve original messages, logs, timestamps, alerts, devices, and actions according to guidance;
- protect unaffected systems and review related sessions, credentials, integrations, and recovery methods;
- engage counsel, insurer, privacy, vendors, financial institutions, closing partners, law enforcement, regulators, or affected parties as required;
- activate the business-continuity and recovery path; and
- maintain one verified incident timeline with decisions, owners, and communications.
Do not improvise forensic work, power down devices unless directed, delete suspicious messages, accuse a person, negotiate with an attacker, or promise that information or money is safe.
Measure Whether the Security Program Works
- percentage of critical systems with a named owner and backup owner;
- percentage of users and administrators protected by required MFA;
- shared, dormant, and orphaned accounts removed;
- unknown connected applications, tokens, and browser extensions resolved;
- critical patches completed within the approved standard;
- external shares and excess permissions corrected;
- time from departure to complete access revocation;
- backup success plus documented restoration-test success;
- time from suspicious activity to escalation and containment;
- tabletop completion and expected-action accuracy; and
- time from an incident or exercise lesson to an updated control.
I count MFA coverage, revoked access, tested restores, and response time, not training slides delivered.
A 30-Day Implementation Plan
Week 1: Inventory and Ownership
List critical systems, devices, data locations, AI tools, integrations, administrators, vendors, and recovery contacts. Assign owners and pause one unknown high-access integration.
Week 2: Accounts and Access
Require unique accounts, close shared and dormant access, expand MFA, review administrators and recovery methods, and remove permissions that no longer match a role.
Week 3: Devices, Data, and Recovery
Confirm supported software, updates, encryption, device response, approved file channels, backup scope, and one representative restoration test.
Week 4: Response and Rehearsal
Finalize the contact tree and playbooks. Run one fictional email-account and connected-app tabletop, test after-hours coverage, record gaps, and assign corrections.
I would rather remove one unused integration than add another warning banner.
Common Real Estate Cybersecurity Mistakes
- Buying a tool before mapping the systems: unknown assets and owners remain unknown.
- Treating MFA as complete: shared accounts, recovery methods, forwarding, tokens, and integrations may still bypass good intentions.
- Using personal accounts for business systems: ownership and offboarding become difficult.
- Giving every app full permissions: convenience expands the impact of compromise.
- Assuming cloud means backed up: test what can actually be restored.
- Saving credentials in chat or documents: use the approved credential process.
- Sending one phishing lesson: test the hold, escalation, and recovery behavior.
- Ignoring offboarding: old users, devices, sessions, links, tokens, and exports retain access.
- Letting AI investigate the incident: protect evidence and use qualified responders.
- Measuring attendance instead of controls: verify access, backups, alerts, response, and recovery.
The Best First Step
Open a blank inventory and write down the ten systems that would stop the business or expose important client information if access were lost or misused. Name the business owner, administrator, MFA status, connected apps, backup or export path, and incident contact for each.
Then choose the highest-impact unknown and resolve it. Do not try to buy your way around an inventory you have not completed.
Final Takeaway
A useful real estate cybersecurity checklist is not a one-time technical audit. It is an operating rhythm: govern the program, identify what the business depends on, protect access and data, detect unusual activity, respond through named owners, and prove that recovery works.
AI tools belong in that inventory because they may hold data, connect systems, and take actions. They can support documentation and training, but they cannot own the security decision.
Start with visibility, reduce access, test the controls, and make the safe next action obvious before anyone is under pressure.
