Spotlight on Advisory Services: Protecting Real Estate in an Era of Cyber Risk
Cyber risks and data loss should be top of mind for all business leaders today. With the rise in data breaches, cloud computing, mobile technologies, and work from home environments, keeping your information secure has become increasingly more difficult. While information technology drives your success, it also creates new vulnerabilities.
Protecting our clients’ data and business requires the right strategies combined with the best tools and the most knowledgeable professionals. In this edition of Spotlight on Advisory Services, Jigar Shah, partner in the Real Estate Industry Practice and Kevin Ricci, partner and co-practice leader of the Cybersecurity Practice, sit down to discuss the keys to strong cybersecurity in today’s world.
Jigar: What are some of the most common cybersecurity risks you see impacting real estate organizations today?
Kevin: Real estate organizations face a mix of operational and data driven threats. The most common threats include ransomware targeting property management systems, vulnerabilities in building automation and IoT devices, inconsistent security controls, and cyber exposure introduced through third party vendors. Many buildings also rely on legacy technologies that were never designed with modern security in mind, creating additional entry points for attackers.
Jigar: Real estate firms often rely on multiple third party vendors and property technologies. How do you help clients manage and reduce third party cyber risk?
Kevin: We help clients build a structured vendor risk program that evaluates each provider’s security posture, access privileges, and contractual responsibilities. This includes standardized assessments, ongoing monitoring, and reviews of third-party SOC reports and the related complementary user entity controls. Our approach gives clients visibility into their vendor ecosystem and reduces the likelihood that a supplier becomes the source of a breach.
Jigar: Can you walk us through what a typical cybersecurity risk assessment looks like for a real estate organization? What should clients expect at each stage?
Kevin: Citrin Cooperman’s proprietary SCORE Report cybersecurity risk assessments begin with discovery through discussions with our clients about their logical and physical security, cloud applications, data security and privacy, resilience, mobile devices, and other key areas of their environment. We then evaluate controls against industry frameworks and real estate specific risks. The results are presented as an intuitive deliverable that includes dashboards, benchmarking, a prioritized view of identified risks, and recommended remediations, providing the client with a practical roadmap to efficiently and effectively fortify their cybersecurity defenses.
Jigar: What types of cybersecurity incidents have you helped real estate clients address, and what lessons learned could benefit others in the industry?
Kevin: We’ve assisted clients through ransomware attacks, business email compromises, unauthorized access to building systems, and vendor related breaches. The consistent lessons are that strong access controls, end-user training, and a tested incident response plan significantly reduce impact. Another key takeaway is the importance of ongoing vendor oversight, as many incidents originate outside the organization.
Jigar: How do you approach helping a client who suspects there may be a breach or IT compromise within their systems or vendor ecosystem?
Kevin: When a client suspects a breach or compromise, we can help stabilize the situation while coordinating closely with their cyber insurance carrier and the insurer’s approved panel of incident‑response resources. We share guidance with the client through each step, providing clear, practical direction to help them make more rapid and informed decisions. After the incident is contained, we can provide post‑incident assessments to identify root causes, evaluate response effectiveness, and outline actionable improvements to strengthen security going forward.
Jigar: What cybersecurity issues are unique to real estate companies operating smart buildings, IoT enabled systems, or connected building management systems?
Kevin: Smart buildings introduce operational technology risks that differ from traditional IT. Many systems run outdated software, lack strong authentication, or are deeply interconnected, meaning a compromise in one device can affect building operations. Proper segmentation, patching, and monitoring are essential to protect both physical and digital environments. Our team of ethical hackers can use the tactics employed by criminals to root out vulnerabilities before they can be leveraged during an attack.
Jigar: What role does cybersecurity play in protecting tenant data, lease information, or other sensitive records?
Kevin: Cybersecurity is central to protecting tenant trust and safeguarding sensitive information such as PII, financial and cardholder data, and lease documents. Strong controls reduce the risk of data exposure, operational disruption, and reputational harm, factors that directly influence occupancy, investor confidence, and compliance obligations.
Jigar: Are there emerging regulatory, lender, or insurer requirements that real estate organizations should prepare for?
Kevin: Yes. Lenders and insurers increasingly require evidence of cybersecurity maturity, including risk assessments, incident response plans, and vendor management programs. Privacy regulations and critical infrastructure related requirements are also expanding. Preparing early helps organizations avoid delays in financing, underwriting, and compliance reviews.
Jigar: What differentiates our Cybersecurity Practice when working with real estate clients?
Kevin: We combine deep cybersecurity expertise with a practical understanding of real estate operations, building technologies, and vendor ecosystems. Our guidance is tailored to the realities of property management, not generic checklists. Clients value our ability to translate technical risks into business aligned recommendations and support them from assessment through implementation.
Jigar: Finally, what excites you most about the future of the practice?
Kevin: Cybersecurity is becoming a strategic differentiator in real estate, influencing asset value, tenant experience, and operational resilience. I’m excited about helping clients modernize their environments, adopt secure technologies, and build long term strategies that strengthen both security and business performance. The opportunity to elevate cybersecurity as a competitive advantage is tremendously exciting to me.
Citrin Cooperman guides our clients through identification and assessment of the risks their organizations face, in addition to providing guidance on finding the right solutions to maximize their performance and security in a technologically advanced world. For more information on how Citrin Cooperman can help ensure the safety of your real estate business, reach out to Jigar Shah or Kevin Ricci.
Latest Articles
Spotlight on Advisory Services: Protecting Real Estate in an Era of Cyber Risk
Read More
Pressure-Testing Your Construction Deal Thesis: Validating Assumptions Before You Buy
Read More
Treasury and IRS Propose Regulations on Racial Nondiscrimination Requirements for Private Schools
Read More
Part 2: Risk Management as a Value Creation Lever: Measuring Risk's Impact on Enterprise Value
Read More
