You protect your clients' money. Make sure your inbox isn't the weak point.
You already protect your clients’ money. The weak point usually isn’t the client account — it’s the inbox the payment instructions travel through.
No regulator tells a lettings agent how to secure its email or its tenant records. That is exactly why it tends to be the thing nobody has looked at.
Five risks, in the order they bite
None of these are exotic. They are the ordinary consequences of a busy branch, a lot of logins and a mailbox that everything passes through.
Payment diversion
A spoofed or compromised mailbox redirects rent, a deposit return or a landlord payment. It is the one that costs real money on the day it happens, and the one your CMP scheme will ask hard questions about afterwards.
Tenant documents, held in bulk
Passport and right-to-rent scans, bank details and references — for every tenant you have ever referenced, not just current ones. Most agencies hold far more of this than they realise, for far longer.
Portal sprawl and shared logins
Property portals, deposit schemes, referencing providers, management software, the bank. A dozen logins, often shared around the branch because that was simplest when there were three of you.
Busy-branch habits
Shared inboxes nobody owns, passwords on a note, MFA switched on for some people, personal phones picking up work email. None of it is negligence — it is what happens when the branch is busy and nobody is responsible for saying no.
Being asked for records, quickly
Councils have new investigatory powers, a property database is coming, and a landlord ombudsman after it. The question is less whether you hold the records and more whether you can produce them without a week of searching.
Payment diversion rarely looks like an attack. It looks like an ordinary Tuesday.
- 1A landlord emails about a deposit return. The thread sits in a shared inbox that three people use and nobody owns.
- 2Somewhere in the chain — your mailbox, the landlord’s, a contractor’s — someone has been reading for a fortnight. There is a forwarding rule nobody set up.
- 3The reply arrives in the right thread, from the right address, at the right moment. New account details: "our bank changed last month".
- 4Nothing looks wrong, because nothing is wrong except the destination.
The defence is not a cleverer inbox. It is a rule that the account details never change on an email — they change on a phone call to a number you already hold, checked by a second person, and written down.
The paperwork is getting more visible
None of this asks anything of your IT directly. What it does is raise the cost of not being able to find things.
Councils have new investigatory powers
Local councils gained expanded investigatory powers and civil penalties, along with a new duty to report on their enforcement activity. In practice that means a request for documents is more likely than it used to be, and slower is worse.
The main tenancy reforms
The core reforms took effect, including the end of no-fault evictions and the move to assured periodic tenancies. More tenancy changes mean more records that have to be right and findable.
The Private Rented Sector database
The government expects rollout to begin from late 2026. Dates for this phase are an expectation rather than a fixed commitment, so treat the timing as indicative.
The landlord ombudsman
Mandatory landlord membership of an ombudsman scheme follows the database, and the government expects this to be in 2028.
Dates from the Renters’ Rights Act implementation roadmap. The first two are in force. The database and the ombudsman are the government's stated expectation rather than fixed commitments, so treat that timing as indicative.
What already applies to your agency
Worth being precise about this, because it is often blurred by people selling security. These are real obligations. None of them tells you how to configure your IT.
Client Money Protection is mandatory in England
Since 1 April 2019, property agents in England holding client money must belong to an approved client money protection scheme. The regulations also require the membership certificate to be displayed in the office and on the website. Source.
Redress scheme membership is required
Agents must belong to a government-approved redress scheme — The Property Ombudsman or Property Redress. Source.
Propertymark membership is voluntary
Agents join voluntarily. Members who handle client money are covered by CMP and have their client account inspected annually. Nothing in that inspection sets an IT requirement — but an agency that has lost money to a diverted payment will find it a more searching conversation. Source.
UK GDPR applies to tenant and landlord data
ID documents, right-to-rent evidence, bank details and references are personal data, and some of it is sensitive. How long you keep it, and who can reach it, are your decisions to make and to be able to explain.
Some agents fall under HMRC anti-money-laundering supervision
Where it applies, it brings identity verification and record-keeping duties. Whether it applies to your agency is a question for your own advisers rather than for us.
Three stages, and you can stop after any of them
Most agencies start with the check. It is a small commitment on purpose — until somebody has looked at your mailbox and your logins, neither of us can honestly say what the rest would involve.
Agency Security Check
Find out where the money could go wrong.
A review of the places an agency actually gets caught: the mailbox, the logins, and the tenant documents nobody has looked at since they were uploaded.
- Microsoft 365 and email security review — MFA, mailbox rules, forwarding, admin accounts
- SPF, DKIM and DMARC check on your domain
- Inventory of portal and third-party logins, with a shared-credential risk review
- Where tenant ID documents live, who can reach them, how long they are kept
- Cyber Essentials gap analysis
- Written report with RAG findings and a prioritised action plan
Client Money Protected
Close the gaps and write down the rule.
Everything in the check, then the work to fix it — including the one procedure that stops payment diversion better than any piece of software.
- Everything in Agency Security Check
- MFA and Conditional Access, Defender, Intune device compliance
- Risky mailbox rules and external forwarding found and removed
- Managed Bitwarden rolled out for every portal login
- A written bank-detail change verification procedure, adopted by the branch
- SharePoint structure for tenancy records — per-property folders, retention labels on ID documents, restricted access
- Cyber Essentials submission support
- A staff session on payment diversion and phishing
Agency Managed
Keep it that way.
Staff change, portals get added, and retention quietly stops happening. This keeps the controls running and the records in order without anyone having to remember.
- Ongoing management of Defender, Intune, patching and Microsoft 365 backup
- Annual Cyber Essentials renewal support
- Periodic check of retention and access on tenant documents
- A quarterly security summary for the director or branch manager
- Optional: external security monitoring, managed password manager, same-day device replacement
Everything is quoted in writing before any work starts, and no VAT is chargeable — the figure quoted is the figure you pay. Cyber Essentials certification fees are set by the certification body and passed through at cost.
The same care, without the scaffolding
Regulated-profession security background
Before founding Lewis McKee Consulting I worked in information security across the legal sector, including securing systems at five top-100 law firms and rewriting firm policy sets to meet Lexcel requirements aligned with ISO 27001. Lettings agents hold the same kind of information with none of the same scaffolding around it.
Microsoft stack, properly configured
Microsoft 365, Entra ID, Intune and Defender — configured and managed, not merely licensed. Most of what stops payment diversion is already in the licence you pay for and switched off.
Managed password manager
Bitwarden, deployed per person with individual vaults, so the portal logins stop being a shared note and start being something you can revoke when someone leaves.
Lancashire, and one person
Based in Chorley, working with small businesses across Lancashire and the North West. You deal with me, not a ticket queue.
The pieces that do the actual protecting
External Security Monitoring
Continuous monitoring of your domain, DNS, certificates and email authentication — the SPF, DKIM and DMARC records that make your address harder to spoof.
Cyber Essentials
Not required for lettings agents by anybody. Still the cheapest way to prove to a landlord, insurer or franchisor that you take this seriously.
Microsoft 365 Backup
Backup with tested restores — because a deleted tenancy folder is a problem you want to solve in minutes.
Patch Management
Managed patching to a defined timescale, with the monthly report that shows it happened.
IT support for lettings agents
A free briefing on the nine technology problems that actually bite small agencies. Every figure sourced.
Managed IT Support
The ongoing support plan Agency Managed sits alongside.
Common questions
Is Cyber Essentials required for lettings agents?+
No. No regulator or professional body requires lettings agents to hold Cyber Essentials, ISO 27001 or any particular IT control — not Propertymark, not your CMP scheme, not a redress scheme, not HMRC, and not the Renters’ Rights Act. It is still worth having, for reasons that have nothing to do with compliance: it forces the basics into place, it is something concrete to show a cautious landlord or a corporate client, and insurers increasingly ask cyber questions at renewal. Buy it because it is useful, not because someone made you.
We use cloud property software — isn’t security their job?+
Partly, and they generally do their half well. Your software provider secures their platform; they do not secure your mailbox, your passwords, your devices or who in your branch can see what. Almost every incident that hurts a lettings agency happens on your side of that line — a compromised inbox, a shared login, a forwarding rule. Those are yours, and they are the ones this service addresses.
How should we store tenant ID documents, and for how long?+
The principle is straightforward: keep them somewhere access-controlled rather than in a mailbox or a shared drive everyone can reach, know who can see them, and delete them when you no longer need them. The period itself is a decision for your agency with your own legal advice — it depends on the tenancy, on right-to-rent evidence, and on whether anti-money-laundering supervision applies to you. The ICO publishes guidance on retention that is worth reading. What I can do is build the structure so that whatever you decide is actually enforced rather than aspirational.
We’re a two-person agency — is this overkill?+
The work scales down; the exposure does not. Two people can hold a client account, a dozen portal logins and identity documents for several hundred tenants. A diverted deposit costs the same whether there are two of you or twenty, and a small agency has less slack to absorb it. For an agency your size the check is a short job and most of the fixes are configuration in a tenant you already pay for.
Do you replace our existing IT support?+
Not necessarily. The check works perfectly well alongside whoever you have — it is a review, not a takeover, and a good share of what it finds is something your current provider can fix once somebody has pointed at it. The report tells them exactly what. If you would rather I did the remediation, that is a separate conversation after you have seen the findings.
What happens if we’ve already lost money to a diverted payment?+
Contact your bank immediately — speed is the only thing that recovers funds — then preserve the emails rather than deleting them, report it to Action Fraud, and consider whether personal data was involved, because that may bring a 72-hour reporting obligation to the ICO. Tell your CMP scheme and your insurer, checking the notification terms rather than assuming. We can help with the technical side of working out what happened and closing the route, and that work is usually urgent rather than scheduled.
Check the inbox before it costs you a deposit
A fixed-fee agency security check looks at your email, your logins and your tenant documents, and tells you plainly where the exposure is.
Book an agency security checkBook an agency security check.
Tell me roughly how many of you there are, which property software you run, and whether you hold client money. I'll come back within one working day with a straight answer on what is involved and what it costs.