Most finance leaders and property teams assume they’re in decent shape with cybersecurity. Rent payments are encrypted, cameras are online, vendors pass their audits, and the insurance policy is paid up. On the surface, everything looks fine.
But there’s a quiet shift happening in the background – one that most organizations haven’t been told about.
You may already be out of compliance with federal law, and no one has notified you.
Not your carrier.
Not your vendors.
Not the government.
And yet the expectations have changed.
The FTC Now Treats Cybersecurity as a Business Practice – Not an IT Problem
For years, cybersecurity was treated like a technical domain. Firewalls, antivirus, backups – all the usual suspects. But the Federal Trade Commission has reframed the conversation.
Weak cybersecurity is now considered an unfair business practice.
That means things like:
- Outdated or missing policies
- No multi-factor authentication
- Unencrypted personal data
- No employee training
- No documented risk assessments
These are no longer viewed as operational oversights. They are compliance failures. That last point – employee training – is one of the most overlooked gaps, and it’s where finance team cybersecurity training becomes a direct compliance requirement, not just a best practice.
And the FTC doesn’t enforce this the way most people imagine. There’s no inspector knocking on your door. The enforcement shows up after a breach – through the attorneys representing tenants, residents, vendors, or employees whose data was exposed.
This shift is subtle, but it is significant. It means cybersecurity is no longer judged by whether you bought the right tools. It is judged by whether you acted reasonably as a business.
How the FTC’s Cybersecurity Enforcement Standards Evolved
The FTC’s stance didn’t change overnight. It evolved over years of cases where organizations failed to protect personal information and then struggled to defend their decisions.
A few patterns kept showing up:
- Companies had policies, but they were outdated or ignored
- Staff had access they didn’t need
- Systems storing personal information weren’t protected with MFA
- Vendors were connected to sensitive systems without oversight
- Leadership assumed IT or a third party was handling everything
In case after case, the FTC concluded that these weren’t technical mistakes. They were business failures.
The pattern of assuming someone else is managing the risk is especially pronounced when it comes to emerging technology – a dynamic explored in depth for organizations where leadership assumed IT or a third party was handling AI oversight.
Property management organizations are especially exposed because they handle a wide range of personal data. Applications, access control, camera footage, maintenance systems, HR platforms – all of it contains information that must be protected.
The FTC’s position is simple. If you collect it, you are responsible for safeguarding it.
What Happens After a Breach Isn’t Technical – It’s Legal
When data is compromised, the questions come fast and they’re not about software:
- What policies were in place
- When were they last updated
- What training did staff receive
- What evidence shows you were maintaining reasonable safeguards
If you can’t produce documentation, you’re exposed – not because you were negligent, but because you can’t demonstrate that you were acting responsibly.
This is where many organizations are caught off guard. They assume that having antivirus or a firewall is enough. But when attorneys get involved, they are not looking for tools. They are looking for proof of responsible behavior.
What ‘Reasonable Safeguards’ Actually Mean Under FTC Standards
Reasonable safeguards do not mean perfection. They do not mean enterprise-level cybersecurity. They do not mean hiring a CISO or building a security department. Building reasonable safeguards starts with understanding what leadership is actually responsible for putting in place.
Reasonable means:
- You understand where your risks are
- You have policies that reflect how your organization actually operates
- You train people on the basics
- You use common protections like MFA and encryption
- You review things periodically
- You document what you do
Courts and regulators consistently look for the same thing: evidence that leadership took cybersecurity seriously and made informed decisions.
Reasonable safeguards are about posture, not perfection.
Real-World Scenarios That Create Compliance Gaps
Most compliance gaps don’t come from dramatic failures. They come from everyday operations.
A few examples:
- A terminated employee still has access to the maintenance system because no one removed their login.
- A vendor portal stores tenant information but doesn’t require MFA.
- A camera system is running outdated firmware because the update requires downtime.
- A leasing agent uses a personal device to access applications during a busy season.
- A policy exists, but no one remembers the last time it was reviewed.
None of these situations feel catastrophic in the moment. But in a breach investigation, they become central questions.
These are the kinds of gaps that create legal exposure, not because they are unusual, but because they are common.
What Carriers Look for When You File a Cyber Claim
Cyber liability policies often include exclusions tied to federal law.
If you’re found to be out of compliance, the carrier can deny the claim.
This is where the real financial risk sits. Understanding the full costs and risks of non-compliance makes clear why alignment with policy requirements isn’t optional.
Most leaders assume the policy is the backstop.
It is – until it isn’t.
Carriers increasingly ask for documentation after a breach. They want to see:
- Policies
- Training records
- Risk assessments
- Evidence of MFA
- Evidence of encryption
- Evidence of patching
If you cannot produce these, the carrier may determine that you were not meeting the minimum requirements of the policy.
This is not about blame. It is about alignment.
What Documentation Actually Looks Like
Documentation does not need to be complicated. It does not need to be a binder full of legal language. It does not need to be perfect.
It simply needs to exist and reflect reality.
Examples of documentation that matter:
- A risk assessment completed within the last year
- Policies that match your actual workflows
- A record of staff completing security training
- A list of systems that store personal information
- Notes from periodic reviews or updates
- A simple log of decisions made about cybersecurity
How to Prove Responsible Behavior Before a Breach Occurs
Documentation is the difference between saying you acted responsibly and proving it.
Why This Matters for Property Teams
Property management has become a data-heavy business:
- Tenant applications
- Access control systems
- Camera footage
- Vendor portals
- Maintenance platforms
- HR and payroll systems
Every one of these systems holds personal information.
Every one of them creates exposure if it’s not protected.
Leadership Owns Cybersecurity Compliance – Not Just IT
And because the FTC now treats cybersecurity as a business practice, the responsibility sits with leadership – not just IT. This is the mindset shift many organizations are still catching up to.
That shift extends beyond the IT department – responsibility sits with leadership at every level, including the financial leaders who control budgets and risk decisions.
This is the mindset shift many organizations are still catching up to.
The Goal Isn’t Perfection — It’s Defensible Compliance
You don’t need to panic.
You don’t need a binder full of policies.
You don’t need a massive overhaul.
But you do need awareness.
The rules have shifted quietly, and the expectations have shifted with them.
If you haven’t reviewed your cybersecurity posture in a while, you may be out of alignment without realizing it.
The goal isn’t perfection.
The goal is defensibility – being able to show that you’re taking reasonable, documented steps to protect the people who trust you with their data.
That’s what keeps you compliant.
That’s what keeps you covered.
And that’s what keeps a breach from turning into a business-level crisis.
Frequently Asked Questions
What does the FTC consider an unfair business practice when it comes to cybersecurity?
Weak cybersecurity is now considered an unfair business practice. That means things like outdated or missing policies, no multi-factor authentication, unencrypted personal data, no employee training, and no documented risk assessments. These are no longer viewed as operational oversights. They are compliance failures.
What do 'reasonable safeguards' actually mean under FTC cybersecurity standards?
Reasonable safeguards do not mean perfection. They do not mean enterprise-level cybersecurity. Reasonable means: you understand where your risks are, you have policies that reflect how your organization actually operates, you train people on the basics, you use common protections like MFA and encryption, you review things periodically, and you document what you do.
What documentation do you need to prove cybersecurity compliance after a breach?
Documentation does not need to be complicated. It simply needs to exist and reflect reality. Examples of documentation that matter include: a risk assessment completed within the last year, policies that match your actual workflows, a record of staff completing security training, a list of systems that store personal information, notes from periodic reviews or updates, and a simple log of decisions made about cybersecurity.