Industries in Focus

Digital Real Estate Industry: PropTech Risks and Protection Concepts

Digital Real Estate Industry: PropTech Risks and Protection Concepts

Digital Real Estate Industry: PropTech Risks and Protection Concepts

Last updated:

8 min.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

Based on the research work of Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann

For a long time, the real estate industry was considered a digital laggard – and therefore, so went the assumption, of little interest to cybercriminals. This assumption is dangerously false. With the rapid digitalization of the sector, the rise of PropTech platforms, and the networking of entire buildings, the real estate industry has transformed into an attractive target for attack. Teichmann has systematically analyzed the specific cyber risks of this sector and the appropriate protection concepts (Teichmann, Digitale Immobilienwirtschaft (PropTech) – Cyber-Bedrohungen und Schutzkonzepte, InTeR 2025, pp. 109–116).

The numbers speak a clear language

The threat landscape in the real estate industry has reached a dimension that many market participants have not yet realized. Now, 93 percent of real estate companies attach high relevance to cybersecurity. More than half of the surveyed companies have already experienced cyberattacks on their own systems or those of their IT service providers. Large real estate corporations must expect an average of over 280 cyberattacks per year (Teichmann, InTeR 2025, pp. 109–116).

Particularly revealing is the gap between awareness and preparation: Although around 51 percent of real estate companies have now established a cybersecurity strategy – almost 80 percent do not possess a comprehensive strategy for protecting their building technology. Exactly here, at the interface between classical IT and networked building infrastructure, lies the greatest and least understood vulnerability (Teichmann, InTeR 2025, pp. 109–116).

Where the new attack surfaces emerge

Teichmann identifies three central areas in which the digitalization of the real estate industry creates new vulnerability points.

PropTech platforms and digital marketplaces process highly sensitive data – customer and contract data, payment information – and are accessible via the Internet. The problem: Startups often prioritize rapid market entry and growth, while IT security is initially not the main focus. Insufficiently protected web applications thus become targets for SQL injection attacks, data leaks, or account takeovers. Added to this are fraud scenarios such as fake advertisements or the manipulation of payment flows (Teichmann, InTeR 2025, pp. 109–116).

Cloud-based management systems offer high efficiency but create critical dependencies: The security of the data lies largely in the hands of the cloud service provider. Misconfigurations or vulnerabilities in cloud environments can allow attackers access to extensive data sets. Data-driven platforms that generate real estate valuations using big data and AI also aggregate large amounts of data about objects, users, and transactions – concentrated data pools that represent a lucrative target (Teichmann, InTeR 2025, pp. 109–116).

Perhaps the most underestimated danger lies in the building technology itself. In modern buildings, heating, ventilation, air conditioning, elevators, lighting, access controls, and video surveillance are digitally networked and often controllable remotely. Every additional IoT device is a potential entry point. Many of these devices use outdated building automation protocols such as BACnet or KNX, which are often neither encrypted nor authenticated. To make matters worse, responsibility for IT security and building technology is often separated in practice – safety officers sometimes do not even know which systems are online in the first place (Teichmann, InTeR 2025, pp. 109–116).

The consequences of a successful attack on building technology range from manipulating the climate control to physical damage and attacks on security systems such as alarm sensors and electronic locking systems – which could enable hackers to facilitate break-ins or unauthorized access.

The legal dimension

Several overlapping regulations apply to the real estate sector. The GDPR obliges all companies processing personal data of tenants, buyers, or interested parties to implement appropriate technical and organizational protective measures. Data breaches must be reported within 72 hours.

NIS-2 covers larger real estate companies, and particularly those operating critical infrastructures or reaching a relevant dimension as digital providers. The Cyber Resilience Act affects manufacturers of connected building technology: Smart building components and IoT devices must meet CRA requirements starting in 2027. This shifts part of the responsibility from the operators to the technology manufacturers – but does not exempt the operators (Teichmann, InTeR 2025, pp. 109–116).

Cyberattacks on real estate transactions: A distinct threat

Particularly insidious is the so-called Payment Diversion Fraud: Attackers compromise communication via email between buyer, seller, agent, and notary, and slip in fake payment instructions with modified account details at the crucial moment. The buyer transfers the purchase price – to the fraudsters. Since real estate transactions often involve six- or seven-figure amounts, the damage in successful cases is enormous. Protection lies in clear processes: Payment details are never transmitted and accepted solely by email, but are always verified via a second, independent channel (Teichmann, Cyberangriffe auf Immobilientransaktionen – Betrugsmaschen und Absicherung von Kaufprozessen, Swiss Real Estate Journal 2025, pp. 4–11).

Protection concepts: What real estate companies must do

On a technical level, this includes: encryption of sensitive data, multi-factor authentication for all critical systems, regular security updates, and – particularly important for building technology – network segmentation. Building automation systems should be strictly separated from the general corporate IT.

On an organizational level, merging responsibility is crucial. The artificial separation between IT security and building technology must be abolished. A central office is needed that knows which devices are online and which vulnerabilities exist.

On a legal level, contracts with PropTech providers, cloud service providers, and technology manufacturers must contain security requirements, auditing rights, and liability regulations. Anyone integrating insecure third-party components shares liability in case of damage (Teichmann, InTeR 2025, pp. 109–116).

Conclusion: The built world becomes part of cyberspace

The digitalization of the real estate industry is irreversible – and with it the merging of physical buildings with cyberspace. Anyone operating a networked building is operating an IT system that can be attacked. The good news: The protection concepts are known and implementable. The bad news: Almost 80 percent of the industry has not yet implemented them for their building technology. Those who take the lead here not only protect their company but also gain a real competitive advantage in an industry that is only just beginning to take the issue seriously.

All source citations refer to published scientific papers by Dr. iur. Dr. rer. pol. Fabian M. A. Teichmann. The complete bibliography is documented in the list of publications (as of May 2026).

Dr. Dr. Fabian Teichmann is a lawyer, researcher, and one of the leading experts on cybersecurity compliance in the German-speaking region. He advises companies on NIS2 and KRITIS and has published over 200 academic papers.

Share

We use cookies to improve your experience. By continuing, you agree to our cookie policy.