The first flag is human · Property management companies

You’re sitting on more sensitive data than you think.

Social Security numbers, bank accounts, lease and payment history, sometimes health records for accommodation requests. A property manager holds resident data that rivals a financial institution's — usually with a fraction of the security budget.

It already happened to a firm your size

A property manager just found out the hard way.

In February 2026, the ransomware group Qilin claimed a breach of Castle Group, a Florida-based property management firm, after roughly five months of undetected access to its network. The exposed data: names, Social Security numbers, government ID numbers, financial account codes, and health records — the exact categories most property managers hold on every resident file.

Castle Group breach: time from access to discovery

Regulatory filings, disclosed Sept 2026

Unauthorized access ran from roughly September 2025 to February 2026 before the ransomware group publicly claimed the breach. Regulatory notification followed in August 2026; public disclosure in September 2026 — a reminder that breaches surface on the attacker's timeline, not yours.

$4.44M

global average cost of a data breach in 2025. Firms holding financial and health data in resident files sit squarely in the categories that cost the most to recover.

IBM, Cost of a Data Breach Report 2025
97%

of organizations that suffered an AI-related breach had no AI access controls in place — relevant wherever staff use AI tools to draft resident communications or screen applicants.

IBM, Cost of a Data Breach Report 2025, Jul 2025
63%

of breached organizations either had no AI governance policy or were still developing one when the breach happened.

IBM, Cost of a Data Breach Report 2025, Jul 2025
What actually goes wrong

The file cabinet moved online. The oversight didn’t.

Resident and applicant data now lives across property management software, email, shared drives, and increasingly AI tools used to draft notices or screen applications — often faster than anyone updated who can see it.

Where AI-related exposure is coming from

IBM, Cost of a Data Breach Report 2025
AI-breached orgs with no AI access controls97%
Breached orgs with no AI governance policy, or still drafting one63%
Policy-holders who also audit for unauthorized AI use34%
Source: IBM, "Cost of a Data Breach Report 2025," July 30, 2025. Shadow AI usage was associated with an average $670,000 increase in breach cost.

Applicant screening data is a target too

Background checks, income verification, and ID documents collected during leasing sit in inboxes and shared folders long after the decision is made.

A five-month dwell time is common, not rare

Attackers often sit quietly inside a network for months before anyone notices. Detection depends on someone recognizing behavior, not just a tool firing an alert.

Staff are already using AI on resident data

Drafting notices, summarizing maintenance requests, screening applicants — without a policy, that data is leaving your control in ways nobody’s tracking.

Who this is for

Holding resident data at bank-like sensitivity, staffed like a leasing office.

Property management companies

Residential, HOA, and community-association management firms

Firms managing residential portfolios, HOAs, and community associations — holding SSNs, financial accounts, lease history, and sometimes health-related accommodation records for every resident and applicant on file. You carry the exposure of a financial institution without the compliance team one usually has.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for property managers, leasing staff, and admin — how resident and applicant data actually gets exposed, plus a one-page policy for AI tool use on resident-facing work.

From $7,000Founding rate $5,000 for the first cohorts
02 · Assessment

Program Readiness & Gap Assessment

Find the gaps

2–3 weeks: review of where resident and applicant data lives, who can access it, vendor and portal account hygiene, and current AI tool usage, with a prioritized roadmap to close the gaps.

From $11,000Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

A monthly advisor for your ops team — incident-response readiness, staff training refreshers, and AI-policy tuning as new tools and portals get adopted.

From $6,000/mo6-month minimum
Let's talk

Know where your resident data actually lives?

A 20-minute call, no pitch. Tell us where you're exposed and what your insurance and vendor contracts require — we'll tell you honestly where we'd start.

Book a 20-minute call