










Ransomware encrypting HMS locks out rent collection, repairs, and tenancy records. Emergency repairs cannot be dispatched. Vulnerable tenants cannot be contacted. Double-extortion threatens to leak domestic abuse and safeguarding data. Post-merger integration creates temporary vulnerability windows.
BEC intercepting multi-million-pound new build invoices between HA and construction contractors. Finance team payment diversion on supplier invoices. Phishing targeting housing officers and contact centre agents trained to be helpful. CEO fraud exploiting trust-based culture.
Connected fire alarms disabled in tower blocks with criminal liability. Door entry, CCTV, and damp sensors exploited. Golden Thread data compromised. BMS attacks on heating in sheltered schemes housing vulnerable elderly residents.
Tenant portals vulnerable to OWASP Top 10 attacks. Breach reveals empty properties enabling burglary. Repairs operative device theft exposes access codes and vulnerability flags with physical safety consequences.
Contractors with remote access breached first providing backdoor to core networks. Portals exposing tenant addresses and vulnerability information. Supply chain pivot to reach finance and housing management.
Housing officers accessing abuse survivor addresses without authorisation. Mental health referrals and children's safeguarding files exposed. Orphaned accounts from turnover. Right to Rent immigration documents. ASB witness statements.
Cyber disrupting rent collection is a reportable breach
Strengthened RSH powers, consumer standards on tenant safety
Golden Thread of digital building safety for high-rise blocks
Connected fire and evacuation system protection
Article 9: health, domestic abuse, ethnicity, criminal records
Required by Homes England and local authorities for funding
Comprehensive resilience for housing providers
Severe Maladministration for prolonged service failures
Rent payments via portals, telephone, and in-person
High-liability passport, visa, and biometric storage
HMS assessments (Civica, Aareon, MRI Software, NEC). Tenant portal and mobile app testing. Repairs scheduling security. API and authentication reviews. PCI DSS for rent payments.
Damp/mould sensor, fire alarm, door entry, and CCTV assessments. BMS reviews for sheltered schemes. Golden Thread data integrity. Fire Safety Regulations compliance.
Penetration testing across offices, depots, and schemes. Active Directory reviews. Segmentation between IT, HMS, and building IoT. Post-merger integration security.
M365 assessments for BEC and development invoice fraud. DMARC, DKIM, SPF reviews. MFA and conditional access for housing officers and contact centres.
CE+ and ICA certification as an authorised body. Gap analysis and remediation. RSH expectations, Homes England funding, and local authority contract eligibility.
RSH governance support with risk registers and board reporting. UK GDPR and safeguarding gap analysis. Phishing simulations for housing officers, finance, and repairs staff. Incident response with 72-hour reporting and tenant communications.
Test your multi-site housing network across offices, depots, and schemes to identify vulnerabilities before attackers reach HMS and tenant data.
View serviceTest tenant self-service portals, repairs platforms, and HMS web interfaces for OWASP Top 10 vulnerabilities exposing tenant records.
View serviceAssess cloud environments hosting HMS, financial systems, and tenant data for misconfigurations exposing rent accounts and safeguarding records.
View serviceAudit Civica, Aareon, MRI Software, Totalmobile, and the third-party platforms your housing operations depend on.
View serviceAlign controls with RSH governance standards, Building Safety Act, Social Housing Regulation Act, and UK GDPR obligations.
View serviceAchieve CE+ to meet RSH expectations, Homes England funding requirements, and local authority contract eligibility.
View servicePhishing simulations for housing officers, finance teams, and repairs staff covering BEC on development invoices and CEO fraud.
View serviceTest tenant mobile apps, repairs operative field tools, and contact centre applications for critical vulnerabilities.
View serviceHarden M365 against BEC targeting finance teams handling multi-million-pound development and contractor invoices.
View service
Most SMBs and mid-market firms have “silent” gaps in their people, process and tech controls implementation. Take the 90-second maturity audit to see your percentile rank.