00:00
Sorry, no results.
Please try another keyword
By Katherine Allan, General Manager Henzells Agency
I used to think of cyber security as something that largely sat with IT. I don’t anymore.
The way we conduct real estate has fundamentally changed. More information and money move electronically, while scammers have become increasingly sophisticated in targeting the way agencies work. We’ve all seen suspicious emails and attempted scams designed to look like they’ve come from legitimate clients, suppliers or staff. Some are very convincing.
What I’ve come to realise is that scammers don’t necessarily need to understand cyber security to target an agency. They need to understand how we work.
That changed my thinking. Cyber security is no longer an “IT issue” sitting in the background, it’s a genuine business risk alongside trust accounting, workplace safety, privacy and legislative compliance.
Think about how much information passes through an agency today. We hold and exchange identification documents, financial information, contracts, tenancy information, bank details and other highly personal data, while significant amounts of money can change hands during a property transaction. Twenty years ago, nowhere near this volume of sensitive information was moving electronically through real estate agencies, and our responsibility has changed with it.
The risk is reflected in the latest Australian Signals Directorate Annual Cyber Threat Report. Business email compromise (BEC) fraud resulting in financial loss was one of the top three self-reported cybercrime threats among Australian businesses, accounting for 15% of reported threats. For real estate agencies, where sensitive information and significant sums of money move through everyday transactions, a compromised email or fraudulent payment request can have serious consequences.
The introduction of AML/CTF obligations has also reinforced that shift. With agents now undertaking more formal identity verification and due diligence, we need to be increasingly conscious of how information is collected, accessed, stored and protected. For me, it reinforces that compliance and cyber security can no longer be treated as separate issues, they are increasingly interconnected.
Clients trust us not only with one of the biggest financial milestones of their lives, but also with their personal information and the integrity of their transactions. My thinking has shifted from cyber security being about protecting our systems to protecting our clients, our people, our reputation and ultimately the business itself.
One of the greatest risks in real estate is familiarity. We receive hundreds of emails and requests, and people naturally become accustomed to processing them quickly. An email can look completely legitimate because it’s part of an existing thread with a client you’ve been communicating with. A request for updated bank details or an urgent document can feel routine simply because it fits the conversation you’re already having.
That’s what makes familiarity so powerful. When something looks and feels like a normal part of our day-to-day work, we’re less likely to stop and question it. Over time, that creates complacency. Email compromise and changes to payment instructions are obvious risks, but so is the everyday handling of identity documents and personal information. With agencies handling an increasing volume of highly sensitive information, the consequences of getting something wrong can be significant.
That’s why we need to look beyond whether something looks legitimate and ask whether it makes sense, whether we’ve independently verified it and whether there’s a more secure way to handle it. Familiar doesn’t necessarily mean safest.
One of the biggest lessons for me has been that good cyber security isn’t created by technology alone; it comes from the way an agency operates.
For us, that has meant becoming more deliberate about how information is handled and how requests are verified. We consider where sensitive information is shared, how it is protected and whether there is a more secure way to manage it. Where appropriate, we use secure technology rather than relying solely on email, while also strengthening our internal cyber and privacy procedures, enabling two-factor authentication across our platforms and introducing additional protections around electronic payments.
But technology and processes only go so far. People also need to understand the risks and feel empowered to question something that doesn’t look right. You don’t need every staff member to become a cyber security expert, but everyone needs to understand that they have a role to play. For me, that means making it acceptable to pause and question something rather than automatically following a familiar process. If a request seems unusual, payment details change or something doesn’t quite make sense, stop and verify it through a trusted channel.
Taking two minutes to verify a request may seem inconvenient when you’re trying to keep a transaction moving but compared with the potential financial and reputational consequences of getting it wrong, it is time very well spent. Cyber security needs to be built into the way an agency works, rather than treated as a procedure sitting in the background. For me, that’s part of what professionalism looks like today.
Trust has always been fundamental to real estate, and cyber security is now part of that.
Clients aren’t just trusting us with their property. They’re trusting us with personal information, financial details and transactions involving significant amounts of money. Agencies that take that responsibility seriously have an opportunity to build stronger trust with clients and differentiate themselves in a competitive market.
That means making security part of the way you operate, not simply something you address when a threat emerges. It can be reflected in the technology you use, the processes you put in place and the way you communicate with your people and clients.
For me, that’s where cyber security becomes more than risk management. It’s part of the standard of service an agency provides, and another way to demonstrate why clients can trust you.
Katherine Allan is General Manager at Henzells Agency, having joined the business in 2005 as a part-time administration assistant. With extensive experience across the agency, Katherine brings a practical understanding of the people, processes and challenges that shape modern real estate. She also serves as Henzells Agency’s AML Compliance Officer, leading the agency’s approach to AML/CTF compliance. Katherine’s contribution to the business has been recognised through several awards, including the Bevan Henzell Award and inaugural Henzells Agency Award.