Industry Guides
IT support for estate agents: branches, portals, AML and payment fraud
What UK estate and letting agents need from IT support: branch networks, Reapit and Alto, portal feeds, AML checks, deposit fraud, phones and backup.
By Dig IT SolutionsUpdated 8 September 20267 min read
Short answer
Estate and letting agents need IT support that keeps every branch on email, the CRM and the portals all day, protects the personal and financial data collected for AML checks, and stops the payment diversion fraud that targets deposits and completions. That means MFA everywhere, managed devices for negotiators, reliable branch connectivity and a provider who knows Reapit and Alto.
An estate or letting agency trades on speed and trust. Enquiries need answering within minutes, viewings are booked from a phone in a car, and clients hand over passports, bank statements and deposits. This guide covers what UK agencies with one branch or ten should expect from IT support, and the specific risks the sector faces.
What makes estate agency IT different
Four things set agencies apart from a typical office:
- Multiple small branches, each with a few desks, its own broadband and staff who move between them.
- Email as the deal channel. Offers, memoranda of sale, references and completion arrangements all flow through Microsoft 365, and a day without email is a day of lost instructions.
- Sensitive data collected at volume. Anti-money laundering checks mean every vendor, buyer, landlord and tenant provides ID and proof of funds. Tenancy applications add income, employer and bank details.
- Money moving on known dates. Deposits, rent and completion funds are transferred on dates that are visible in email correspondence, which is exactly what payment diversion fraud depends on.
The way we support agencies is described on our IT support for estate agents page. What follows are the standards any provider should meet.
Stopping payment diversion fraud
Payment diversion fraud is the incident that costs agencies most. The pattern is consistent: a negotiator or property manager clicks a phishing link and enters their Microsoft 365 password, the criminal reads the mailbox for weeks, identifies a tenant about to pay a deposit or a buyer about to complete, and sends an email from the real mailbox changing the bank details.
The controls are inexpensive and mostly about consistency:
- Multi-factor authentication on every account, including directors, part-timers and the shared lettings mailbox.
- Conditional access that blocks sign-ins from countries you do not operate in and from unmanaged devices.
- Alerts on new mailbox forwarding rules, which criminals use to hide their activity.
- Email authentication (SPF, DKIM and DMARC) so your domain cannot easily be spoofed, and a mail filter that flags lookalike domains.
- A written rule that bank details are never changed on the strength of an email. Confirm by phone on a number already held, and tell tenants and buyers in writing that you will never email a change of account.
- Short, regular phishing training using the real emails your filter has caught that month.
The GOV.UK Cyber Security Breaches Survey consistently identifies phishing as the most common attack type on UK businesses, and agencies are attractive because the money is large and the dates are predictable.
AML, ID checks and where the data lives
Estate agency businesses are supervised by HMRC for anti-money laundering purposes, and letting agents are supervised where rents exceed the threshold. Customer due diligence records must be kept and produced on request. Guidance is published on GOV.UK.
The IT consequence is that ID documents, proof of funds and check results need a home. In many agencies that home is a mixture of inboxes, negotiators' phones and a shared drive nobody has tidied since the branch opened. The fix is:
- Use the AML or referencing platform, or a controlled SharePoint library, as the single place for due diligence records.
- Restrict access to staff who carry out checks.
- Set retention so records are kept for the required period and then removed.
- Include that location in the backup schedule.
- Delete photos of ID from phones once uploaded, and have mobile device management in place so the phone can be wiped if lost.
The ICO's guidance for organisations applies to all of this, and a lost unmanaged phone full of passport photos is a reportable breach.
Reapit, Alto, portals and the systems around them
Most agencies run a sales and lettings CRM (Reapit, Alto, Dezrez, Jupix, Street or similar), feed listings to Rightmove, Zoopla and OnTheMarket, and use separate platforms for referencing, AML, e-signatures, property management and client accounting. Your IT provider needs to understand:
| Area | What the provider must know |
|---|---|
| CRM hosting | Cloud (most now) or a server in the head office branch, and who backs it up |
| Email integration | How the CRM files correspondence to Outlook and what breaks after updates |
| Portal feeds | That a stalled feed means properties disappear from Rightmove, and who to call |
| Phones | Whether the CRM integrates with your VoIP system for click-to-dial and call logging |
| Leavers | Every system a negotiator has access to, so all of it can be removed the same day |
The provider does not need to configure Reapit for you. They do need to own the ticket when the Outlook add-in stops working, rather than leaving the branch manager relaying messages between two support desks.
Connecting branches
A three-branch agency has three broadband lines, three routers and often three different ways of doing things. The standard to aim for:
- Business-grade broadband at each branch with a 4G failover, because a branch without internet cannot see the CRM, the diary or email.
- Cloud identity through Microsoft 365 so a negotiator logs in at any branch with the same account and sees the same files, with a VPN between branches only if a server remains in one of them.
- Wi-Fi covering the front office and meeting rooms, with a separate guest network for visiting clients.
- Central monitoring so the IT provider knows a branch is offline before the branch does.
- A single VoIP phone system across all branches, so calls can be answered from any desk or a mobile app, transferred free between branches, and reported on. With the PSTN switch-off due by January 2027 according to Ofcom, any branch still on analogue lines needs a plan.
Our multi-site connectivity service covers this pattern, and the same principles apply to any provider.
A worked example: three branches, one agency
Consider a sales and lettings agency with a head office branch and two satellite branches, twenty-two staff, Alto as the CRM, and a property management team in the head office. A sensible setup looks like this:
- Each branch has full fibre broadband and a 4G failover router, both monitored, with a business-grade firewall and two managed access points.
- Every member of staff has a Microsoft 365 account with MFA enforced, a managed laptop or desktop, and either a company phone or mobile device management on their own.
- Alto, referencing, AML and e-signature platforms are all signed into through the same identity, so a leaver is removed from everything by disabling one account.
- One VoIP system covers all three branches, with the head office receptionist answering overflow.
- Microsoft 365 is backed up independently, and the AML records library in SharePoint has restricted access and a retention policy.
- The IT provider holds a spare router and access point, and attends any branch for hardware faults.
Nothing in that list is exotic. The difference between that agency and one that suffers a deposit fraud or a lost-phone breach is that every item is applied to every branch and every person.
Negotiators on the move
Negotiators work from phones and laptops in cars, on viewings and at home. The decisions are the same as in any mobile business: managed company devices, or mobile device management on personal devices that separates work data. Either way, a lost phone should be an inconvenience rather than a breach, and a negotiator who leaves for a competitor should lose access to the CRM, email and applicant lists before they reach the door. Our onboarding and offboarding process exists because the leaver step is so often missed in agencies with high staff turnover.
Backup and continuity
Cloud CRMs are backed up by the vendor, but check retention and export terms. Microsoft 365 email and SharePoint are not backed up by Microsoft in the sense most agencies assume, and a deleted mailbox or a ransomware-encrypted SharePoint library needs an independent backup to recover from. Any server left in a branch needs daily backups with an off-site copy and at least one copy that ransomware cannot reach.
Continuity for an agency is mostly about branches: if one loses power or internet, staff should be able to work from another branch or from home within the hour. If email goes down, there should be a way to reach applicants and clients by phone from a list that is not only in Outlook.
Choosing an IT support provider for an agency
The right provider already supports agencies on your CRM, knows what a stalled portal feed costs, will set up a new branch or a new starter without drama and will remove a leaver from everything the same day. They will attend a branch when a router or a PC fails rather than insisting on remote-only support, and they will price per user or per device so that opening a branch does not mean renegotiating the contract. Agencies considering a change can read our guide to switching IT provider.
What to do next
If any mailbox in the agency lacks MFA, if ID documents live in inboxes and on personal phones, or if a branch has no failover, an independent review will show you the risk in order. Book an IT health check and we will report on every branch, prioritised by the cost of a lost deal or a data breach.

