The property management sector is becoming increasingly digital. Building management systems, access control, CCTV, smart meters, tenant portals and cloud-based property management platforms now underpin the day-to-day operation of residential and mixed-use developments. While these technologies create efficiencies, they also introduce a significant and rapidly evolving cyber risk landscape. For professional indemnity (PI) insurers, the challenge is no longer confined to data breaches; cyber incidents can now lead directly to regulatory failures, tenant complaints, operational disruption, and professional negligence claims.
The introduction of the Renters’ Rights Act further amplifies these exposures. The legislation is designed to improve transparency, strengthen tenant protections, and enhance regulatory oversight through measures including a Private Rented Sector database (often referred to as the Property Portal) and a mandatory landlord ombudsman scheme. The reforms create new compliance obligations for landlords, managing agents, and property professionals, many of which rely on the accurate collection, storage, and transmission of digital information.
From a PI insurer's perspective, this creates a convergence between cyber risk and professional liability. Historically, cyber events may have been viewed primarily as a matter for standalone cyber insurance. Increasingly, however, a cyber incident can trigger allegations that a property manager failed to perform professional services with reasonable skill and care. For example, a ransomware attack affecting a property management platform could result in lost tenancy records, missed compliance deadlines, or failures to provide statutory information. If tenants or landlords suffer financial loss as a consequence, claims will be directed at the managing agent employing or managing the technology rather than the technology provider, leaving the agent to seek a recovery, which is likely to be legally and contractually difficult.
The industry's growing reliance on operational technology (OT) presents an additional challenge. Modern buildings frequently connect HVAC systems, lighting controls, lifts, access systems, and CCTV networks to central management platforms. According to RICS, 27% of facilities teams reported experiencing a building cyber incident within the previous 12 months, highlighting the increasing frequency of attacks targeting smart buildings and connected infrastructure. A compromise of these systems can lead not only to data loss but also to physical disruption, tenant dissatisfaction, and business interruption.
The Renters’ Rights Act increases the significance of these risks because it places greater emphasis on accountability, transparency, and tenant redress. The Property Portal and ombudsman framework are intended to make compliance information more accessible and to provide tenants with clearer routes to challenge landlords and agents. Where property managers are responsible for maintaining records, uploading information, or evidencing compliance, any cyber event that affects data integrity or availability may expose firms to allegations of regulatory non-compliance or maladministration.
Supply chain risk is another key area of concern. Property managers rely heavily on third-party software vendors, building system integrators, managed service providers, and specialist contractors. The widely reported Johnson Controls ransomware incident demonstrated how an attack on a major building technology provider can have downstream consequences across multiple customer estates. For insurers, this highlights the potential for aggregation risk, where a single compromise at a common supplier creates losses affecting numerous insureds simultaneously.
The regulatory environment is also becoming more demanding. The UK's Product Security and Telecommunications Infrastructure (PSTI) regime, which came into force in April 2024, introduced mandatory baseline security requirements for many internet-connected devices, including controls on default passwords and vulnerability management. Property managers procuring smart devices for residential developments are increasingly expected to understand and manage these requirements. A failure to do so may not only increase cyber vulnerability but could also form part of a broader professional negligence allegation following a security incident.
For PI insurers, underwriting considerations should therefore extend beyond traditional questions around professional competence and claims history. Increasing attention should be paid to cyber governance, supplier oversight, incident response planning, data backup arrangements, and the segregation of operational technology from corporate IT networks. Particular scrutiny may be warranted for firms managing large residential portfolios, student accommodation, build-to-rent schemes, or highly connected smart buildings, where cyber exposure and regulatory obligations intersect most clearly. Furthermore, PI insurers should review the scope of their cyber-related exclusions to ensure that their exposure remains aligned with their underwriting intent.
Risk management measures can significantly reduce exposure. Property management firms should maintain comprehensive asset inventories, implement multi-factor authentication, regularly test backups, conduct supplier due diligence, and develop incident response procedures that address both cyber and regulatory consequences. Equally important is ensuring that staff understand their obligations under the Renters’ Rights framework and can continue to meet key compliance requirements during a systems outage. Careful thought should also be given to supplier contracts, to properly delineate risk/responsibilities around system failure, which might then be usefully carried into professional service terms and conditions to mitigate exposure risk.
For professional indemnity insurers, the key message is that cyber risk is no longer a standalone technology issue. The combination of increasingly connected buildings, greater reliance on digital property management systems and the enhanced transparency requirements introduced by the Renters’ Rights Act means that cyber incidents are more likely to translate into professional liability claims. As a result, cyber resilience is becoming a core indicator of professional risk quality within the property management sector, and insurers that incorporate cyber maturity into their underwriting and risk management strategies will be better positioned to respond to the evolving claims landscape.