Cybersecurity Protocol Checklist
Endpoint & Network Security
Catalog every laptop, leasing-office iPad, self-showing tablet (Tenant Turner, Showdigs, Rently), and on-call phone that opens AppFolio, Buildium, or Yardi or stores screening reports. Personal devices used for work email count — they're the most common gap.
Tour prospects, contractors waiting in the lobby, and self-showing visitors should never share the network with the workstation running the PMS. Confirm the SSID for staff is WPA2/WPA3 with a rotating credential and the guest SSID has client isolation enabled.
AppFolio, Buildium, and Yardi run in the browser, so an outdated Chrome or Edge is the realistic attack surface, not the OS. Confirm Windows Update / macOS updates and browser auto-update are on for every machine in the inventory above.
BitLocker on Windows, FileVault on macOS. A leasing laptop with downloaded screening reports (consumer reports under FCRA) and ID scans is a reportable breach if lost unencrypted.
Access Control & Identity
AppFolio, Buildium, Yardi, and your screening provider all support MFA. Owner-payout fraud and rent-diversion fraud almost always start with a stolen PMS password — MFA on accounting and principal accounts is the single highest-leverage control here.
Leasing agents do not need the owner-banking screen. Maintenance does not need screening reports. Accounting does not need smart-lock admin. Map each PMS role to a job function and remove the defaults that grant more.
Confirm every staff departure this quarter had PMS, email, smart-lock codes (Latch, RemoteLock, August), and self-showing tech access revoked within one business day. A leasing agent who left Friday cannot have access Monday — this is the single most common audit finding.
Resident & Owner Data Protection
TransUnion SmartMove, Experian RentBureau, and RentPrep outputs are FCRA consumer reports. They live in encrypted storage in the tenant file — not in the leasing inbox, not on a desktop folder, not in shared Dropbox without per-folder access controls.
The FACTA Disposal Rule requires shredding paper consumer reports and securely wiping electronic copies once retention ends. Confirm with counsel how long your firm holds reports for denied applicants vs. signed leases — most firms land at 2-5 years post-decision.
AppFolio and Buildium back up the SaaS side. What you need to verify is the local export — rent roll, owner statements, tenant ledgers, vendor 1099 data — and that you can actually restore from it. Pull last month's backup and open it.
Incident Response Readiness
The plan must list state breach-notification timelines for every state where you operate (most are 30-60 days; some require AG notice above a threshold). Name who calls counsel, who calls the cyber insurance carrier, who notifies residents and owners.
Walk through a simulated PMS lockout with the operations lead, accounting, and IT. Rent collection halts, the tenant portal is offline, and an owner is asking why the disbursement didn't run. Document the gaps and update the plan.
If an incident occurred this quarter, determine whether SSN, DOB, financial account numbers, driver's license images, or screening reports were accessed. The answer drives state breach-notification obligations — answer conservatively with counsel.
Notification content, timing, and AG-copy thresholds vary by state. Coordinate with counsel before any letter goes out — pre-mature or off-template notifications create their own liability. Capture proof of mailing for every affected resident and owner.
Staff Security Training
The standard scam is a fake owner email asking accounting to redirect the next disbursement to a new bank account. Train accounting that any banking-change request is verified by phone using the number on the W-9 in the file — never the number in the email signature.
Use KnowBe4, Hoxhunt, or your IT provider's tool. Capture the click rate per office and per role. Repeat clickers get a one-on-one debrief, not a punitive note — the goal is reporting behavior, not zero clicks.
A one-click Report Phish button in Outlook or Gmail routing to IT. Staff need to know reports go to IT (not their direct manager) and that false alarms carry zero penalty — under-reporting is the failure mode, not over-reporting.
Vendor & Software Risk
Tier 1 — handles SSN, financial accounts, or screening reports (PMS, screening provider, payment processor, e-sign). Tier 2 — handles names and contact only (listing syndication, marketing). Tier 3 — no resident data (office supplies, IT hardware). The tier sets the review depth for the rest of this section.
AppFolio, Buildium, Yardi, TransUnion SmartMove, and Stripe publish SOC 2 Type II reports under NDA. Request annually, scan for exceptions in the access-control and incident-response sections, and note any carve-outs that affect your data.
Any plumber, electrician, or make-ready vendor with a tenant-portal login or work-order-system access needs MFA enabled, a signed NDA covering resident data, and a current general liability + workers comp COI naming the property as additional insured.
Pull the contract renewal calendar. For Tier 1 vendors, do not auto-renew without a refreshed security questionnaire and confirmation that the SOC 2 scope still covers your data flows.
Use this template in Manifestly
- Rental Payment Checklist
- Property Management Office Spring Cleaning
- Security Deposit Checklist
- Apartment Turnover Maintenance Checklist
- Annual Rental Property Inspection
- Property Inspection Checklist
- Tenant Eviction Checklist
- Tenant Move-Out Checklist
- Employee Training Checklist
- Property Maintenance Inspection Checklist
- Pet and Assistance Animal Approval Checklist
- Tenant Offboarding Checklist
- Tenant Move-In Checklist
- Lease Agreement Checklist
- Tenant Screening Checklist
- Property Manager Performance Review
- Vendor Performance Evaluation Checklist
- Tenant Onboarding Checklist
- Rent Roll Audit Checklist
- Employee Offboarding Checklist
- Service Contract Renewal Checklist
- Utility Management Checklist
- Eviction Process Checklist
- Tenant Communication Checklist
- Monthly Financial Reporting Checklist
- Capital Expenditure Planning Checklist
- Vendor Onboarding Checklist
- Roof Inspection Checklist
- Contractor Management Checklist
- Property Tax Review Checklist
- HR Compliance Checklist
- Rent Increase Notice Checklist
- Rent Collection Process Checklist
- Payroll Processing Checklist
- Property Inspection Checklist
- Emergency Contact List Maintenance
- Annual Budget Preparation Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Property Acquisition Due Diligence Checklist
- Property Showing Checklist
- Accessibility Compliance Checklist
- Tenant Eviction Checklist
- Lease Renewal Checklist
- Legal Document Storage Checklist
- Seasonal Maintenance Checklist
- Investment Analysis Checklist
- Appliance Maintenance Checklist
- Tenant Move-Out Checklist
- Move-In Package Preparation
- Property Management Staff Onboarding Checklist
- Property Management Software Implementation Checklist
- Security Audit Checklist
- Sustainable Procurement Checklist
- Water Conservation Measures Checklist
- Emergency Preparedness Checklist
- Grounds Maintenance Checklist
- Green Building Standards Checklist
- Energy Efficiency Audit Checklist
- Data Backup and Recovery Checklist
- HVAC Maintenance Checklist
- Tenant Applicant Screening
- Routine Property Inspection Checklist
- New Property Management Onboarding
- Leasing Process Checklist
- Rental Advertisement Checklist
- Annual Insurance Review Checklist
- Plumbing Maintenance Checklist
- Preventive Maintenance Checklist
- Property Risk Assessment Checklist
- Pest Control Checklist
- Property Safety Inspection Checklist
- IT Equipment Inventory Checklist
- Disaster Recovery Plan Checklist
- Move-Out Procedure Checklist
- Lease Signing Checklist
- Pool Maintenance Checklist
- Rental Market Analysis Checklist
- Electrical System Maintenance Checklist
- Common Area & Turnover Cleaning Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Tenant Screening Checklist
- New Tenant Move-In Checklist
- Real Estate Portfolio Review Checklist
- Fair Housing Compliance Audit
- Lease Renewal Checklist
- Tenant Screening Checklist
- Rental Rate Analysis Checklist
- Move-In/Move-Out Inspection Checklist
- Eviction Process Checklist
- Rental Property Inspection Checklist
- Property Maintenance Inspection Checklist
- Rent Collection Checklist
- Cybersecurity Checklist for Real Estate
- Manufacturing Cybersecurity Checklist
- Cyber Security Checklist
- Data Security Checklist
- Disaster Recovery Checklist
- Cybersecurity Incident Response Checklist
- Network Security Checklist
- IT Asset Inventory Management Checklist
- Insurance IT Security Review Checklist
- Data Security Review Checklist
- Cybersecurity Risk Assessment Checklist
- Financial Services IT Security Audit Checklist
- Cybersecurity Incident Response Checklist
- Motor Carrier Cybersecurity Protocol Checklist
- Risk Management Checklist
- Regulatory Compliance Checklist
- Quarterly Internal Control Review Checklist
- Sales Tax Reporting Checklist
- Legal Entity Management Checklist
- Employee File Audit Checklist
- Anti-Money Laundering Compliance Checklist
- SOX Compliance Checklist
- GDPR Compliance Review Checklist
- IT Security Audit Checklist
- HR Compliance Checklist
- Payroll Processing Checklist
- Building Code Compliance Checklist
- Employee Records Management Checklist
- Legal Document Storage Checklist
- Security Audit Checklist
- Property Risk Assessment Checklist
- Property Safety Inspection Checklist
- Fair Housing Compliance Checklist
- Legal Compliance Checklist for New Properties
- Lease Agreement Checklist
- Software Licensing Compliance Checklist
- PCI DSS Compliance Checklist
- Real Estate Legal Compliance Checklist
- HIPAA Compliance Checklist
- MLS Listing Review Checklist
- Real Estate License Renewal Checklist
- GDPR Compliance Checklist
- Real Estate Contract Review Checklist
- Fair Housing Compliance Audit
- Listing Agreement Intake Checklist
- ISO/IEC 27001 Compliance Checklist
- HR Compliance Checklist
- Real Estate Ethics & Compliance Review
- Brokerage Trust Account Management Checklist
- Real Estate Professional Development Checklist
- Brokerage Technology Inventory Audit
- Real Estate Website Audit Checklist
- Continuing Education Checklist
- Employee Termination Checklist
- Employee Records File Audit
- Regulatory Compliance Checklist
- Brokerage HR Policy Compliance Checklist
- Employee Handbook Annual Review
- Employee Termination Checklist
- Data Privacy Compliance Checklist
- Risk Management Checklist
- Insurance Compliance Checklist
- Complaint Resolution Checklist
- Financial Audit Checklist
- Data Security Checklist
- Risk Mitigation Checklist
- Claims Auditing Checklist
- Quarterly Industry Standards Compliance Review
- Insurance Training and Development Checklist
- Anti-Money Laundering Checklist
- Training Evaluation Checklist
- Manufacturing Regulatory Compliance Checklist
- Training Needs Assessment Checklist
- Skills Development Checklist
- Audit Preparation Checklist
- Network Security Checklist
- Employee Offboarding Checklist
- IT Asset Inventory Management Checklist
- Regulatory Reporting Checklist
- Compliance Audit Checklist
- Insurance Program Initiation Checklist
- Insurance Program Launch Project Monitoring Checklist
- Training Materials Checklist
- Quarterly Risk Monitoring Checklist
- System Backup Checklist
- Employee Benefits Checklist
- Insurance Program Launch Execution Checklist
- Insurance Marketing Campaign Checklist
- Email Compliance Checklist
- Law Firm Compliance Checklist
- Anti-Money Laundering Compliance Checklist
- Law Firm Compliance Checklist
- Professional Responsibility Compliance Review
- Data Privacy Compliance Checklist
- Law Firm Risk Management Checklist
- HR Audit Checklist
- HR Compliance Checklist
- Email Deliverability Checklist
- Law Firm Ethics Compliance Review
- Document Retention Policy Checklist
- Employee File Audit Checklist
- Law Firm Risk Management Checklist
- Cloud Security Checklist
- User Access Review Checklist
- IT Regulatory Compliance Review
- Compliance Audit Checklist
- Security Audit Checklist
- Business Continuity Checklist
- Employee Termination Checklist
- Quarterly Operations and Compliance QA Review
- Expense Management Checklist
- Advisor and Employee Onboarding Checklist
- Client Satisfaction Survey Checklist
- Operational Risk Checklist
- Know Your Customer (KYC) Checklist
- Litigation Preparation Checklist
- Contract Review Checklist
- New Hire Onboarding Checklist
- Client Onboarding Checklist
- Contract Review Checklist
- Regulatory Compliance Checklist
- Monthly Financial Reporting Checklist
- Regulatory Reporting Checklist
- Intellectual Property Management Checklist
- Internal Audit Checklist
- Lead Generation Checklist
- Annual Financial Reporting Checklist
- Annual Compliance Program Review
- Annual Risk Assessment Checklist
- Data Security Review Checklist
- Quarterly Performance Measurement Checklist
- Financial Services Project Initiation Checklist
- IT Policy Review Checklist
- Data Protection Checklist
- E-commerce Sales Tax Reporting Checklist
- Project Execution Checklist
- Project Planning Checklist
- Project Monitoring Checklist
- Financial Statement Review Checklist
- Quarterly Compliance Monitoring Checklist
- Cybersecurity Risk Assessment Checklist
- Project Closure Checklist
- Financial Services IT Security Audit Checklist
- PCI DSS Compliance Checklist
- Advisor and Staff Onboarding Checklist
- Cybersecurity Incident Response Checklist
- E-commerce Risk Management Checklist
- CRM Data Entry Checklist
- Business Continuity Plan Checklist
- E-commerce Legal Compliance Checklist
- Vendor Contract Review Checklist
- Annual Risk Management Review Checklist
- Risk Assessment Checklist
- Agency Compliance and Risk Management Checklist
- Annual School Compliance Audit
- School First Aid and Emergency Medication Audit
- Motor Carrier TSA Security Compliance Checklist
- Internal Controls Checklist
- Client Communication Checklist
- Restaurant Permit and Licensing Renewal Checklist
- New Hire Paperwork Checklist
- Restaurant Policy Update Checklist
- Restaurant New Hire Checklist
- Annual Attorney Professional Conduct Review
- International Fuel Tax Agreement (IFTA) Quarterly Filing Checklist
- Restaurant Licensing Renewal Checklist
- Marketing Strategy Checklist
- Department of Transportation (DOT) Audit Checklist
- Retail Policy Update and Compliance Checklist
Ready to take control of your recurring tasks?
Start Free 14-Day TrialUse Slack? Sign up with one click
