Portfolio Cybersecurity
Security for property companies as a portfolio: identity, email, endpoints, vendors and building systems, ranked by what would hurt the most.
What Portfolio Cybersecurity means in practice
Portfolio Cybersecurity applies a consistent security baseline across head office, site offices, building systems and third-party vendors, with attention to the fraud patterns that target property and finance teams.
Property firms move large payments, hold identity documents and run building systems that can be reached from the same accounts. Attackers know it. A baseline that covers payment-change fraud, multi-factor authentication, endpoint protection and vendor access closes the doors that matter most.
Faults this removes
- Payment-change requests approved over email without call-back
- Shared accounts at site offices and front desks
- Contractor and vendor access that was never removed
- Building systems reachable from the office network
- No tested incident plan covering rent collection and building operations
Scope of work
- Multi-factor authentication and conditional access across the tenant
- Payment-change and wire-fraud controls with call-back procedure
- Endpoint detection on office and site laptops
- Vendor and contractor access register with expiry dates
- Separation between office, building and tenant networks
- Incident playbook covering rent, access control and emergency contacts
Typical platforms
- Microsoft Defender
- Microsoft Entra ID
- Fortinet
- DNS filtering
- Email security gateways
The first thirty days
In the first week we gather access, documentation and contacts, then complete a survey of the properties in scope. Weeks two and three are for design and approval of any change windows. The fourth week is for implementation and testing, with a handover meeting at the end. For larger portfolios we sequence buildings in waves so the first becomes a template for the rest of portfolio cybersecurity.
What it costs
Portfolio Cybersecurity is quoted as a fixed-scope project, from $2,500, or delivered inside a managed agreement at $89 to $199 per user each month. Portfolio advisory work starts from $1,500 per month and security assessments from $1,900. Building count, suite count and after-hours coverage move the price within those ranges. A 10% launch discount applies, GST is added at 5% and there is no lock-in.
How Portfolio Cybersecurity is delivered
Every engagement starts with a free 30-minute call, then a survey of the buildings involved: what is installed, who maintains it, how it is networked and where it fails. We write a fixed-price scope for portfolio cybersecurity listing outcomes, responsibilities, assumptions and exclusions. Work is scheduled around occupancy, with a written rollback for each change. At handover you receive drawings, credentials in a vault you control and a short runbook. Target: multi-factor authentication on every account, a vendor-access register reviewed quarterly and a rehearsed incident playbook.
Keeping the building and its data safe
Any system that touches doors, cameras or tenant data is a target. In portfolio cybersecurity work we separate it from the office network, remove default credentials, patch on a schedule and record every administrative account. Vendors are given time-limited access with an audit trail. We also write down who is allowed to do what, because unclear authority is how most property incidents begin.
Who this service is built for
Portfolio Cybersecurity is most often requested by commercial landlords, property management companies and facilities teams, although the underlying work is similar for any property team. The pattern we see is a building or portfolio that has outgrown informal arrangements: one technician who knows everything, a vendor who is hard to reach or a system installed years ago that nobody has reviewed. If that sounds familiar, portfolio cybersecurity is a sensible starting point.
Service targets and reporting
Where portfolio cybersecurity is delivered as an ongoing service, we publish targets: 24/7 monitoring on managed infrastructure, a 15-minute response target on priority tickets and a monthly report that shows what changed, what failed and what is coming up for renewal. Targets are objectives supported by process and escalation, not guarantees. Target: multi-factor authentication on every account, a vendor-access register reviewed quarterly and a rehearsed incident playbook.
Working with the rest of the property technology stack
Good portfolio cybersecurity depends on its neighbours: Helpdesk for PM Teams, vCIO for Property Companies and Intercom & Visitor Management. During scoping we identify the systems that share a network, an account or a data feed with it and confirm the dependencies. That prevents the familiar pattern where a well-run project is undone by an unrelated vendor's change the following month.
Frequently asked questions
How is the result of portfolio cybersecurity measured?
Target: multi-factor authentication on every account, a vendor-access register reviewed quarterly and a rehearsed incident playbook. Results are reported monthly and reviewed with you each quarter.
Do we need to sign a long-term contract?
No. After onboarding the service is month to month with no lock-in, and you keep ownership of your documentation, configurations and data.
What is included in Portfolio Cybersecurity?
Core deliverables include multi-factor authentication and conditional access across the tenant, together with drawings, documentation and a handover session. Exact scope is confirmed in a written, fixed-price proposal before work begins.
How much does portfolio cybersecurity cost?
Projects start from $2,500 and ongoing support from $89 to $199 per user per month. vCIO retainers begin at $1,500 per month and security assessments at $1,900. Building count and complexity set where a quote lands; a 10% launch discount applies and GST is extra.
Which tools and platforms are involved in portfolio cybersecurity?
Typical platforms include Microsoft Defender, Microsoft Entra ID, Fortinet, DNS filtering and Email security gateways. We use mainstream, supported technology that fits your existing investments, and we record every device and licence in an asset register delivered at handover.