Lettings sector briefing

The technology problems that actually bite independent lettings agents

A plain-English briefing on where IT goes wrong in a small agency, what it costs when it does, and what the fix usually looks like. Written for independent agents and small branch networks — the ones without an IT department.

Written for agencies without an IT department
Every figure sourced and linked
Downloadable as a PDF

Most writing about technology in the property sector is aimed at corporate agencies with a head office and an IT manager. That is not much use if there are four of you, the CRM is whatever you signed up to in 2016, and IT is whoever is least busy that day.

So this is the independent version. Nine problems I keep finding, why each one lands harder on a lettings agent than it would on any other business of the same size, and what a sensible fix looks like. No products, no scare stories, and every figure attributed so you can check it.

The briefing

Nine problems, and what each one really costs.

Problem 1 of 9

The deposit that goes to somebody else’s account

A tenant has been approved and is about to move in. They get an email that looks exactly like the last six — your branding, your negotiator’s signature, the right property address — with the account details for the deposit and first month’s rent. They pay. You find out on move-in day.

This is the single most damaging thing that happens to small agencies, and it usually does not involve breaking into your systems at all. Either the attacker is in the tenant’s own mailbox reading the thread, or they have simply registered a domain one character different from yours and copied your signature block off your website. The tenant has lost money they had saved for a year, they blame you, and the complaint goes to your redress scheme. Reported rental fraud is getting less frequent and considerably more expensive, which is what you would expect if criminals are moving from scattergun fake listings to patient, targeted interception.

£3,138

average loss per reported rental fraud in 2025/26, up 46% on the previous figure — 4,092 reports and £12.84m lost in total, even as the number of reports fell

Letting Agent Today, August 2026 — Action Fraud and Metropolitan Police rental fraud figures analysed by Just Landlords: 4,092 reports and £12.84m lost in 2025/26, an average of £3,138 per report, up 46%
What good looks like
  • Multi-factor authentication on every mailbox, with legacy authentication switched off so it cannot simply be walked around
  • Alerting on new mailbox forwarding and inbox rules — the first thing an intruder sets up, and the thing that keeps them invisible
  • SPF, DKIM and DMARC set to reject, so that somebody else cannot send email as your domain
  • Registering the obvious look-alike domains yourself, which costs about as much as a tank of fuel
  • Bank details given once, on paper or in the portal, with a line in every email saying they will never change — and a phone check on any message that says otherwise
Problem 2 of 9

You are holding a filing cabinet full of passports

Right to rent checks mean copies of passports, visas and share codes for every adult in every managed property, plus the ones who applied and were not successful. They are scanned, emailed to the branch, and saved wherever there was room.

The document set exists because the law requires it, and the penalties for getting the check wrong are now serious money rather than a slap: since 13 February 2024 a first breach can cost up to £5,000 per lodger and £10,000 per occupier, rising to £10,000 and £20,000 for a repeat. So you must keep the evidence. But keeping it turns a four-person agency into a warehouse of the exact documents used to open bank accounts and take out credit in someone else’s name — including for applicants who never became tenants and have no idea you still hold them. The failure I find is never a decision. It is an email attachment nobody deleted, a shared folder everybody can open, and a scan-to-email folder on the office printer that has been filling up since 2019.

Up to £10,000

civil penalty per occupier for a first breach of the right to rent rules since 13 February 2024, rising to £20,000 for a repeat breach

Home Office — right to rent: landlords’ code of practice and civil penalty scheme (up to £5,000 per lodger and £10,000 per occupier for a first breach from 13 February 2024, £10,000 and £20,000 for repeat breaches)
What good looks like
  • One place identity documents live, with a folder permission that is actually restrictive rather than nominally so
  • Scan-to-email and scan-to-folder on the office printer cleaned out and pointed somewhere sensible
  • A retention rule for unsuccessful applicants, applied automatically — you almost certainly do not need to keep them
  • Encryption on every laptop and phone that has ever opened one of these
  • Knowing who can open that folder today, and being comfortable with the list
Problem 3 of 9

You hold other people’s money in a system you have never questioned

Rent comes in, deductions come off, landlord payments go out, deposits sit in a scheme, and the whole thing is reconciled in the property management software by one person who knows how it works.

You have been legally required to belong to an approved client money protection scheme since 1 April 2019, and a local authority can impose a financial penalty of up to £30,000 for not being in one. That is the floor, not the risk. The real exposure is that client money moves on instructions produced by software, sent by email, and authorised by whoever is at the desk — and if someone is reading your mailbox, all three of those are compromised at once. The deposit side has its own trap: the legal duty to protect a deposit within 30 days sits with the landlord, not with you, so when it is missed because of something at your end the landlord takes the penalty of between one and three times the deposit and then takes their portfolio somewhere else.

What good looks like
  • Named logins with MFA on the property management system and the banking platform, never a shared branch account
  • Separation between the person who sets up a payee and the person who releases the payment, even in a very small office
  • Alerting on changes to landlord bank details in the CRM, because that is the quiet version of the same fraud
  • A reconciliation somebody other than the usual person has looked at within the last year
  • A written check on deposit registration deadlines that does not depend on one diary
Problem 4 of 9

The referencing file nobody meant to keep

A tenancy application generates an employer reference, a previous landlord reference, a credit check, three months of bank statements, and a guarantor’s details. Multiply by every applicant for every property since you opened.

Tenants and guarantors did not choose you — they chose a house — and you now hold the financial history of people who have no relationship with you at all. Most agencies have no retention position on this whatsoever, which means the oldest and most sensitive material is also the least protected and the most likely to be sitting in a mailbox rather than a system. It is worth knowing that the ICO does fine small firms for this kind of thing, and does not need a headline-sized breach to do it.

What good looks like
  • A retention schedule for applicant and guarantor data, written down once and then applied automatically
  • Referencing collected through the referencing provider’s portal rather than as email attachments
  • Bank statements and payslips deleted once the decision is made, not archived by default
  • Sensitive documents shared by link with an expiry, not attachments that live forever in two mailboxes
Problem 5 of 9

The Renters’ Rights Act has turned your records into evidence

Phase 1 came into force on 1 May 2026. Every tenancy is periodic, no-fault eviction is gone, and possession now depends on establishing a ground — which means it depends on what you can prove.

Before, a landlord who wanted the property back could serve a section 21 notice and largely avoid the argument. Now the argument is the process, and the argument is won or lost on records: the notices you served, the dates you served them, the rent account, the repairs you logged and when, the correspondence. An agency whose evidence is spread across a CRM, a personal inbox and a WhatsApp thread is going to lose cases it should win, and the landlord will conclude that the agent is the problem. More is coming: Phase 2 from late 2026 brings the private rented sector database and the landlord ombudsman, though registration is being rolled out region by region and landlords are not expected to be required to join until 2028. This is a records problem long before it is a software problem.

What good looks like
  • Everything about a tenancy in the tenancy record — including emails — rather than in whoever handled it
  • Repairs and maintenance logged with dates at the time, because a contemporaneous note is worth ten reconstructed ones
  • Retention long enough to cover a dispute that surfaces years later, applied automatically
  • A test worth running: pick a managed property and try to assemble its complete history in ten minutes
Problem 6 of 9

If you also do sales, you are AML-supervised — whatever the value

Most independents do both. The lettings side feels like the regulated one because of deposits and client money, and the sales side feels like the simpler half.

It is the other way round. Any business carrying out estate agency work must register with HMRC for money laundering supervision regardless of transaction value, whereas letting agency work is only caught where an individual tenancy is at or above the €10,000-a-month threshold — which almost none of yours will be. So the sales desk you think of as the straightforward one is the part that obliges you to run customer due diligence, keep the records, do the risk assessment and appoint a nominated officer. And AML records are, by their nature, exactly the identity documents from problem 2 — held for longer, under a legal duty, in the same shared folder.

What good looks like
  • Knowing which of your activities are registered with HMRC and which are not — a five-minute check that is occasionally a nasty surprise
  • Due diligence records stored deliberately, with a retention clock, rather than in the matter email thread
  • Access to AML files restricted to the people who need them, not to everyone with a network login
Problem 7 of 9

You cannot be offline, because a broken boiler does not wait

The CRM is unavailable, or the office internet is down, on a Friday afternoon in February. There are viewings booked, a contractor waiting for a purchase order, and a tenant with no heating.

Other businesses that lose a day lose a day’s turnover. You lose your ability to discharge a legal duty to keep a property fit to live in, on the day the duty is most obviously engaged — and the tenant’s account of it will be that the agent did nothing. Bear in mind too that the standard ransomware playbook is to encrypt on a Friday evening, when nobody is watching. If the property management system, the keys register and the contractor list are all on one machine in the back office, that machine is the agency.

What good looks like
  • Working from cloud services, so any device in any location gets you back to work
  • Getting the box in the back office out of the critical path — most agencies this size should not have a server any more
  • A spare, pre-built machine that can be in someone’s hands the same day rather than the same fortnight
  • Contractor and key-holder details reachable from a phone, because that is what you will actually have
  • Knowing in advance who you ring, what comes back first, and roughly how long it takes
Problem 8 of 9

The branch login, and the negotiator who left in March

One CRM login the whole office uses, one portal account for Rightmove, one email password everyone knows, and a staff list that turns over faster than any other part of the business.

Lettings has more people coming and going than almost any comparable trade, and shared logins mean nothing is ever really removed when they go. You also lose attribution: when a landlord’s bank details are changed, a deposit is registered late, or a tenant’s documents are downloaded, you cannot say who did it. The way in is rarely clever. The ICO fined a small professional firm £60,000 after attackers reached its network through an infrequently used administrator account that had no MFA on it — a forgotten login, not a sophisticated attack.

£60,000

ICO fine against a small professional firm in April 2025 after attackers accessed its network through an infrequently used administrator account with no multi-factor authentication

ICO — professional firm fined £60,000 in April 2025 following a cyber attack that reached its network through an infrequently used administrator account without MFA
What good looks like
  • Named accounts for every person on every system, including the portals — no exceptions for convenience
  • A leaver checklist that runs on the day they leave, covering the CRM, the portals and the banking platform, not just email
  • An audit of accounts nobody uses, because the dormant one is the one that gets you
  • A password manager, so that “everyone needs to know it” stops being an argument
Problem 9 of 9

Your supply chain is a lot of small businesses and a lot of email

Contractors, the inventory clerk, the referencing provider, the deposit scheme, the conveyancer on the sales side, and every landlord’s personal webmail.

Confidential material moves between all of them constantly, mostly by email, and their security is not something you control. A landlord with a compromised personal email account is a genuine route into your rent payments, and neither of you will spot it quickly. This is also the mechanism behind problem 1: the attacker does not need to be in your systems if they can be in the mailbox of someone who emails you every week. The same pattern that hits conveyancing on completion day hits you on move-in day, for smaller sums and far more often.

What good looks like
  • Know who holds your tenant and landlord data and on what basis — a short list, kept current, is enough
  • A straight question to contractors and clerks about MFA, and a data processing agreement where one belongs
  • Secure file transfer for anything sensitive, instead of attachments and hope
  • The out-of-band verification habit again, because it remains the only thing that reliably beats a convincing email
Where to start

Seven questions worth asking on Monday morning

You do not need a consultant to work through these. If the answer to any of them is “I am not sure”, that is where I would start.

  1. 1Is MFA on every account — the CRM and the portals as well as email?
  2. 2Does anyone still share a login, and what would you do on the day that person leaves?
  3. 3Are there mailbox forwarding rules that nobody in the office put there?
  4. 4Is your DMARC record set to reject, or is it sitting on “none” and doing nothing?
  5. 5Where do right to rent documents actually live, and who can open that folder?
  6. 6Has anyone ever restored a file from your Microsoft 365 backup — and is there one at all?
  7. 7If the office were unavailable on Monday, how would you reach the contractor list?

Which of these actually apply to you?

None of this needs a large project. Most of it is configuration that should have been set correctly on day one, plus two or three habits that have to be agreed rather than bought.

If you would like a second opinion, I will spend half an hour on your setup and tell you which of these actually apply to you. Not a report full of red traffic lights designed to sell you something — just a straight answer about where you stand.

Worried about payment diversion, or where your tenant ID documents live? Cyber security for lettings agents →

Sources

Everything above, where it came from.

A few figures that circulate widely in property-sector marketing are deliberately absent: a £4.1bn tenancy fraud total extrapolated by a company that sells referencing, an Action Fraud rental fraud figure from 2018 still being quoted as current, and a breach statistic attributed to the government survey that does not match it. If anything here does not hold up, tell me and I will correct it.

  1. 1.Letting Agent Today, August 2026 — Action Fraud and Metropolitan Police rental fraud figures analysed by Just Landlords: 4,092 reports and £12.84m lost in 2025/26, an average of £3,138 per report, up 46%
  2. 2.Home Office — right to rent: landlords’ code of practice and civil penalty scheme (up to £5,000 per lodger and £10,000 per occupier for a first breach from 13 February 2024, £10,000 and £20,000 for repeat breaches)
  3. 3.GOV.UK — mandatory client money protection for property agents: enforcement guidance, including financial penalties of up to £30,000 for failing to belong to an approved scheme
  4. 4.The Client Money Protection Schemes for Property Agents (Requirement to Belong to a Scheme etc.) Regulations 2019, in force 1 April 2019
  5. 5.Housing Act 2004, section 214 — the court may order the landlord to pay the tenant between one and three times the amount of the deposit
  6. 6.GOV.UK — guide to the Renters’ Rights Act 2025, including the phased implementation and the private rented sector database
  7. 7.GOV.UK — money laundering supervision for estate agency businesses: registration is required for any estate agency work under the Estate Agents Act 1979, regardless of transaction value
  8. 8.GOV.UK — money laundering supervision for letting agency businesses: caught where an individual tenancy is at or above the €10,000-a-month threshold
  9. 9.ICO — professional firm fined £60,000 in April 2025 following a cyber attack that reached its network through an infrequently used administrator account without MFA
  10. 10.Propertymark — tips to help prevent and prepare for cyber attacks
  11. 11.DSIT — Cyber Security Breaches Survey 2025/26 (43% of businesses identified a breach or attack; phishing 38%, impersonation 12%)
  12. 12.IASME — changes to Cyber Essentials from 26 April 2026 (Requirements v3.3)
Get in touch

Half an hour, and a straight answer.

Tell me roughly how many of you there are, how many properties you manage, what your CRM is, and which of the nine above made you wince. I’ll come back within one working day. I work with small businesses across Lancashire and the North West, and I am the person you will actually speak to.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.