Cybersecurity in real estate and mortgages: the 2026 market
Real estate is going digital fast. Discover the key cybersecurity sub-markets, from mortgage data and payment fraud to proptech and smart buildings.

For a long time, real estate was seen mainly as a physical sector. A building consisted of land, bricks, installations and lease contracts. A mortgage file consisted of documents, valuations and financial calculations. That picture no longer holds.
The modern real estate chain runs on data, software and digital connections. Agents work with cloud CRMs and housing platforms. Mortgage advisers process income data, identity documents and bank statements. Property managers connect tenant portals to payment providers. Buildings contain connected cameras, access systems, EV chargers, elevators and climate installations. Proptech companies continuously exchange data through APIs with banks, valuers, municipalities and other suppliers.
That makes cybersecurity for real estate and mortgages not a small technical niche, but a broad growth market. Not because every organisation needs its own complete security platform, but because the sector combines large money flows, sensitive personal data, fragmented IT landscapes and increasingly digital building systems.
Real estate has an attractive risk profile for attackers
Cybercriminals usually do not look for the most advanced sector, but for the best combination of value and vulnerability. Real estate meets both conditions.
In a property transaction, large amounts are transferred within a short period. At the same time, buyers, sellers, agents, mortgage advisers, notaries, valuers and banks communicate through different systems and email accounts. One compromised mailbox or one convincing lookalike domain can be enough to change payment instructions.
The numbers illustrate the scale. The FBI Internet Crime Complaint Center recorded more than $275 million in reported losses in the real estate category for 2025. Business Email Compromise, where criminals take over or imitate business communication, caused more than $3 billion in reported damage across all sectors. These figures only cover reports in the United States and are therefore not a full global market measurement. They do show why property transactions are an attractive target.
Source: FBI IC3 Annual Report 2025
The building itself is becoming part of the digital risk too. Research by the Royal Institution of Chartered Surveyors found that 27% of surveyed facility managers and service providers reported that their building had faced a cyberattack in the previous twelve months, compared with 16% a year earlier. RICS names building management systems, cameras, IoT devices and access control among the risk areas.
Source: RICS, Digital risks in buildings
Real estate cybersecurity is not one market
Anyone talking about “the real estate cybersecurity market” is in fact combining several sub-markets. Each sub-market has different risks, buyers and solutions.
| Sub-market | Primary risk | Typical buyers |
|---|---|---|
| External attack surface | Unknown domains, subdomains, IP addresses, open ports and vulnerabilities | Real estate firms, mortgage organisations, proptech and software vendors |
| Transaction and payment security | Email fraud, identity fraud and altered payment instructions | Agents, notaries, title and escrow companies, mortgage advisers |
| Mortgage and customer data security | Theft or unauthorised access to financial and personal data | Banks, lenders, servicers, advisers and platforms |
| Proptech, cloud and API security | Vulnerable applications, integrations, cloud configurations and suppliers | Proptech companies, data providers and real estate platforms |
| Smart building and OT security | Disruption or takeover of physical building systems | Property owners, managers, housing associations, hospitals and data centres |
| Portfolio and property management security | Fragmented security across many properties, offices and suppliers | Institutional investors, REITs, housing associations and property managers |
| Supply chain and compliance risk | One weak supplier grants access to data or systems across the chain | Banks, large real estate organisations, governments and critical organisations |
| AI and data governance | Employees share sensitive data with uncontrolled AI tools | Virtually every professional party in the real estate and mortgage chain |
1. External Attack Surface Management
Many organisations do not know exactly which digital assets are reachable from the internet. Alongside the main website there are often subdomains, test environments, customer portals, APIs, old campaign sites, cloud servers and admin environments. Some of these were once set up by a supplier or former employee and then dropped out of sight.
That makes the external attack surface dynamic. An annual audit or penetration test remains valuable, but only gives a snapshot. The environment can change again the next day through a new release, a cloud configuration or a temporarily opened admin port.
External Attack Surface Management therefore focuses on continuously:
- discovering externally reachable assets;
- identifying technologies in use and open services;
- detecting and prioritising vulnerabilities;
- delivering technical evidence and remediation advice;
- verifying that a finding has actually been fixed.
For real estate organisations with multiple brands, projects, locations and suppliers, that automatic inventory is exactly what matters. The first security question is not “which vulnerability should we fix?” but “do we actually know everything that is online on behalf of our organisation?”
2. Securing property transactions
Transaction security focuses on the moments when money, documents and instructions move between parties. The main threats are Business Email Compromise, domain impersonation, account takeover, identity fraud and social engineering.
This sub-market is about far more than email filtering. Effective protection combines:
- strong authentication and access control;
- secure portals for documents and payment instructions;
- independent verification of bank account changes;
- monitoring of lookalike domains and digital impersonation;
- logging and auditable approval processes;
- training for employees and consumers.
The business case is relatively simple: a single prevented fraudulent payment request can justify a multi-year investment in security.
3. Securing mortgage and customer data
A mortgage file contains almost everything a criminal needs for identity or financial fraud: name, address, income, employer, bank account, assets, debts, tax information and identity documents.
That is why cybersecurity in the mortgage sector is shifting from an IT responsibility to a board-level and compliance matter. In the United States, mortgage lenders and mortgage brokers fall explicitly under the FTC Safeguards Rule. It requires an information security programme, risk assessments, multi-factor authentication, monitoring or periodic penetration testing and vulnerability scanning, supplier oversight and an incident response plan.
Source: Federal Trade Commission, Safeguards Rule
Chain partners are raising their requirements too. Fannie Mae requires certain sellers, servicers, multifamily lenders, technology providers and document custodians to meet additional information security and resiliency requirements. Cyber incidents in scope must be reported within 36 hours.
Source: Fannie Mae Information Security and Business Resiliency Supplement
Although these US rules do not apply directly to European companies, they show where the market is heading: financiers, insurers and platform partners want demonstrable evidence that security measures do not just exist on paper, but are actually implemented and tested.
4. Proptech, cloud and API security
The real estate sector uses increasingly specialised software for valuations, property data, transactions, leasing, maintenance, energy, financing and customer communication. These solutions rarely operate in isolation. Data is shared with other platforms and data sources through APIs.
As a result, risk shifts from a single corporate network to an ecosystem of connected applications. Key questions include:
- secure software development;
- protection of APIs and authentication keys;
- cloud configuration and access rights;
- separation of customer environments;
- timely patching of components;
- control over test, staging and admin environments;
- oversight of external software suppliers.
For proptech companies, demonstrable security is also becoming a commercial requirement. Banks, governments and institutional real estate parties are less likely to admit a supplier into their chain when it cannot provide insight into vulnerabilities, incidents and remediation processes.
5. Smart building and OT security
A modern building contains Operational Technology: systems that monitor or control physical processes. Think of climate control, elevators, lighting, access control, cameras, fire safety, energy management, solar panels and charging infrastructure.
These systems have a different risk profile than regular office IT. They often have a long lifespan, sometimes run on outdated software and cannot always be patched or taken offline easily. Moreover, a cyber incident can cause not only data loss but also physical disruption, unsafe situations or a halt to business operations.
This sub-market therefore requires specialised OT knowledge, network segmentation, asset inventory, secure remote access, continuous monitoring and clear agreements between owner, manager, installer and technology supplier.
6. Securing entire real estate portfolios
An institutional owner or property manager sometimes manages dozens or hundreds of assets. Every building can have its own suppliers, local networks, tenant portals and technical installations. Mergers, acquisitions and changes of manager make the landscape even more complex.
The commercial opportunity here is central visibility: one security model for the entire portfolio, with uniform minimum requirements and local exceptions where needed. That includes not only technology, but also supplier management, incident procedures, insurance requirements and reporting to the board and investors.
Over time, digital resilience may even influence due diligence and valuation. A building with unmanageable legacy systems, insufficient documentation or unclear data ownership can carry higher future costs and operational risks.
7. Supply chain security and new regulation
Real estate is a chain market. An organisation can have its own security in order and still be exposed through a software supplier, installer, valuer, manager or marketing agency.
In the Netherlands, the Cyberbeveiligingswet, which implements the European NIS2 Directive, takes effect on 15 August 2026. The law does not automatically apply to every real estate company, but it does affect more than 8,000 Dutch organisations in essential and important sectors. Organisations in scope must also manage risks in their direct supply chain. As a result, real estate, technology and data suppliers can indirectly face stricter security requirements.
Source: Dutch National Cyber Security Centre (NCSC) — Cyberbeveiligingswet and suppliers
8. Safe use of AI
AI creates a new sub-market that cuts across all other categories. Employees use generative AI for customer communication, document analysis, valuations, credit preparation and reporting. Without clear guardrails, personal data, financial data, contracts or internal instructions can end up in uncontrolled applications.
AI also makes attackers more productive. Phishing messages become more convincing, domains and websites can be cloned faster, and social engineering can be personalised at scale.
The security question therefore shifts from “may employees use AI?” to “which data may be processed through which model, under what technical and organisational conditions?”
Will this become a large standalone market?
Underlying demand will become large, but the market will probably not be dominated by one category of companies labelled “real estate cybersecurity”.
Large general cybersecurity vendors will keep supplying the base technology for identity, endpoint security, network security, cloud security and monitoring. Specialised providers add sector knowledge, integrations, implementation and auditable processes on top.
The winners will likely be the parties that combine three elements:
- strong cybersecurity technology;
- knowledge of real estate, mortgage and building processes;
- a recurring service that keeps risks continuously visible and manageable.
The market therefore resembles cybersecurity in healthcare or industry. The technology is partly generic, but the application, regulation, risks and accountability lines are sector-specific.
From periodic checks to continuous visibility
A key problem within real estate organisations is that digital environments change faster than traditional control cycles. New projects get their own website. Suppliers open temporary environments. Applications move to the cloud. Subdomains stay alive after a project ends. A misconfiguration can go unnoticed for months.
Within our cybersecurity proposition we use HaxUnit to keep this outside layer continuously visible. Starting from one or more of your own domains, the platform automatically maps externally reachable subdomains, IP addresses, open ports and technologies in use. Discovered assets are then checked for vulnerabilities. Findings come with priority, evidence and reproduction steps, after which an organisation can have a fix retested.
No agent or code installation is required. HaxUnit looks at the organisation the way an external attacker can: from the public internet.
According to current platform data, more than 75,000 assets have been discovered, more than 10,000 vulnerability scans performed and more than 5,000 findings prioritised. Explore HaxUnit
HaxUnit does not replace a complete cybersecurity programme. Organisations still need strong authentication, employee awareness, secure backups, endpoint security, supplier management, incident response and, where relevant, penetration testing or specialised OT security. But it fills a crucial gap: continuously knowing which digital assets are visible and where new weaknesses appear on the outside.
The first step is knowing what is visible
For many real estate and mortgage organisations, cybersecurity does not have to start with a lengthy advisory programme. A practical first step is mapping the external attack surface.
Which domains and subdomains are active? Which systems respond from the internet? Which technologies are used? Are there legacy environments, publicly accessible admin panels or known vulnerabilities?
With the free HaxUnit scan, an organisation can check one of its own domains and up to 100 discovered assets once. That quickly creates a first picture of what attackers can see from the outside.
Start the free cybersecurity scan on HaxUnit.com
Sources
- FBI Internet Crime Complaint Center — 2025 Annual Report
- Royal Institution of Chartered Surveyors — Digital risks in buildings
- Federal Trade Commission — Safeguards Rule
- Fannie Mae — Information Security and Business Resiliency Supplement
- NCSC — Cyberbeveiligingswet effective from 15 August 2026
- NCSC — Cyberbeveiligingswet and suppliers
- HaxUnit — Continuous Vulnerability Monitoring
How secure is your organisation?
We map your attack surface and help you close the gaps in your security and infrastructure.
Explore CybersecurityFrequently Asked Questions
Have questions about this topic? Here are the most frequently asked questions.



