Real estate IT security in Houston is mailbox security first. Wire fraud against a brokerage almost never starts at the title company. It starts inside a compromised agent inbox, weeks before anyone wires a dollar, and the brokerage is the least defended link in the chain.
Short version. The title company is the most regulated party at a Texas closing. Your brokerage is the least regulated, and it holds the whole email thread. Texas brokers also have to keep 4 years of that correspondence on file. Fixing this is identity work, not firewall work, and it belongs inside ordinary real estate IT services rather than a separate security project.
Ask a Houston broker where their cyber risk sits and most will point at the title company. That’s where the money moves, so that’s where the danger must be. Reasonable. Also wrong, in a very specific way.
Title and escrow is the most supervised seat at the table. Lenders audit it, underwriters push controls onto it, and the industry wrote its own security framework years ago. Your brokerage answers to none of that. Nobody audits you. What your brokerage holds instead is the complete correspondence history of every deal, sitting in mailboxes that often belong to 1099 agents who bought their own laptops, chose their own passwords, and have never once been asked by anyone to prove that either was any good.
That gap is what this post is about. What actually happens inside a compromised brokerage mailbox, what Texas law puts on the broker afterwards, what your policies will and won’t pay, and the short list of fixes that stop most of it. Written for brokers and office managers. Not for security people.
What does real estate IT security mean for a Houston brokerage?
Real estate IT security is the set of identity, email and records controls that protect transaction data and the funds moving through a deal. For a brokerage that means mailbox protection for every sponsored agent, a wire procedure clients can rely on, and safe handling of the 4 years of records the state requires you to keep.
Notice what is not on that list. No SOC. No threat hunting team. Brokerages get sold enterprise security language and then buy tools that don’t touch the way they actually lose money. The broader picture for Texas firms sits on our real estate IT services page, and the Houston service detail lives on cybersecurity services in Houston. This post narrows to the closing chain.
Why the brokerage is the soft node in a Houston closing

Houston runs a lot of transactions. Brokers closed on 35,330 single-family homes through May 2026 alone, and by July the median sale price sat at $340,000 against a record 40,750 active listings. Every one of those deals generates an email thread carrying a date, an amount, and 6 or 7 named humans. That’s a lot of email.
Now ask which party holds that thread the longest. Not the lender, who joins late and leaves at funding. Not the title company, which sees a slice. The agent holds it from the first showing to the day the keys change hands, and the broker inherits the archive afterwards. Attackers know this. They aren’t breaking into escrow accounts, they’re reading email. That’s the whole trick.
Here’s the uncomfortable comparison. Sorted by who is actually forced to do something about it.
| Party | What they hold | What forces them to secure it |
|---|---|---|
| Lender | Loan file, borrower financials, payoff figures | GLBA and federal examiners. Real supervision, real penalties |
| Title and escrow | Funds, wire instructions, identity documents | Underwriter audits, lender requirements, an industry best-practices framework |
| Brokerage | Full transaction correspondence for 4 years, contracts, client identity data | A state rule that says keep it. Nothing that says protect it |
| Sponsored agent | Live thread, client phone numbers, the closing calendar | Whatever the agent personally decided to do |
One mailbox is worth more to an attacker than most brokers assume. From a single sponsored agent’s inbox, here is what somebody walks away with.
- Exact closing date and exact dollar figure for every deal in flight
- Every party in the chain, with names, roles, phone numbers and email addresses
- Signature blocks, disclaimers and formatting that make a forged message look native
- Tone of voice for each person, which is what defeats a recipient’s instinct
- Historic client records going back years, including whatever identity documents were attached
The one-question test. Ask your brokerage this. If a sponsored agent’s email is read by someone else for 3 weeks, who would notice, and how? If the honest answer is nobody, that is your finding. You can stop reading competitor blog posts about firewalls. Start there.
How the fraud actually runs, from first login to the wire

Most agents picture a spoofed email arriving out of nowhere. That’s not it. The real sequence is slow. Patient, quiet, and dull to watch right up until the last hour. It runs roughly like this.
- Credential capture. A login page that copies a transaction-management or MLS notification. Your agent signs in, nothing appears broken, and the password is now somewhere else.
- Quiet entry. No email gets sent. The attacker creates a hidden inbox rule that forwards anything containing wire, closing, payoff or escrow to an outside address, then files those messages where the agent won’t look.
- Reading. Days, often weeks. Whoever is inside learns the closing date, the dollar figure, every party, the signature blocks, and how each person writes when they’re rushed.
- Timing. The fraudulent instruction lands hours before funding, inside the genuine thread, from either the real account or a domain 1 character off.
- Silence. By the time somebody phones, the money has moved through 2 or 3 accounts, and speed of detection is now the only variable that matters.
CertifID’s 2026 State of Wire Fraud report puts numbers on the outcome. Buyer cash-to-close fraud is the most common category at 30% of their recovery cases, with a median loss of $239,850. Seller net proceeds fraud runs a median of $343,497. Mortgage payoff fraud is the worst at $389,125. Their recovery rate is 69%, well above average. It depends almost entirely on how fast the theft is spotted. Speed is the whole game.
Nationally, it looks the same. The FBI’s 2025 Internet Crime Report logged $3.05 billion in business email compromise losses, the second largest category of any kind, and 12,368 real estate fraud complaints totalling $275.1 million. Both are climbing.
The inbox rule is the tell
Of everything in that sequence, step 2 is the one you can actually catch. A legitimate user almost never builds a rule that quietly forwards keyword-matched mail to an external address. Attackers build one nearly every time, because they need the thread without staying logged in. So look for the rule.
Microsoft 365 can alert on new forwarding rules. So can Google Workspace. Most brokerages have the license already and have never switched it on, which is a genuinely odd place for the industry to be. It costs an afternoon. It catches the phase where the attacker is present and has not yet taken anything, which is the only window in the whole sequence where nothing has been lost and everything is still recoverable. Turn it on.
What Texas actually puts on the broker afterwards

Start with retention, because brokers usually treat it as a filing chore rather than a security obligation. Under TREC Rule 535.2(h), a broker has to keep transaction records for at least 4 years from closing or termination, in a format readily available to the Commission. The list of records is explicit. It names email.
Read that as a security statement instead of an administrative one. That rule makes every Texas broker the long-term custodian of 4 years of client correspondence containing names, addresses, financial detail and sometimes identity documents. The state tells you to hold it. It never tells you how to protect it. That silence is where brokerages get comfortable. Comfort is not compliance.
Afterwards the clock gets less forgiving. Texas Business and Commerce Code 521.053 requires notice to affected individuals without unreasonable delay and no later than 60 days after you determine a breach occurred. If 250 or more Texas residents are involved, you also file with the Texas Attorney General as soon as practicable and within 30 days. Do the math. A single compromised agent mailbox holding 4 years of deals can clear 250 residents on its own.
SB 2610 counts employees, not sponsored agents
This nuance matters more to brokerages than to almost any other industry, and nobody writes about it. Texas SB 2610 took effect on 1 September 2025 and shields businesses with fewer than 250 employees from exemplary damages in a data breach suit, provided a qualifying security program was already running. The requirements scale by headcount. Under 20 employees needs documented basic controls, 20 to 99 needs CIS Controls IG1, and 100 to 249 needs a recognized framework.
Now count your brokerage properly. Sponsored agents are independent contractors, not employees. A Houston firm with 340 agents might employ 18 people. That firm sits in the smallest tier of the statute, with the lightest control set, which means the safe harbour is genuinely reachable rather than aspirational. We broke the tiers down in our Texas SB 2610 compliance guide. Worth 10 minutes.
One thing to check before your next audit. If your brokerage started collecting beneficial ownership information for the FinCEN residential real estate rule, you may still be storing it. A federal court in the Eastern District of Texas vacated that rule on 19 March 2026 and FinCEN appealed to the Fifth Circuit in May. No filing is required while the order stands, so a lot of firms are holding sensitive data collected for a mandate that currently has no effect. Decide deliberately.
What your E&O and cyber policies pay after a diverted wire
Brokers assume errors and omissions coverage catches this. It generally doesn’t. E&O responds to professional mistakes made while performing real estate services. Money stolen through a fraudulent instruction is not a professional mistake, it’s theft, and theft sits under a different policy.
Cyber policies do usually include social engineering or funds transfer fraud. Here is the catch. It is almost always written as a sublimit rather than the full limit. A policy with a $2 million aggregate might carry $100,000 or $250,000 for social engineering. Put that beside the CertifID medians above. Arithmetic gets unpleasant fast.
| Fraud type | Median loss | Typical social engineering sublimit | Uncovered |
|---|---|---|---|
| Buyer cash to close | $239,850 | $100,000 | About $140,000 |
| Seller net proceeds | $343,497 | $250,000 | About $93,000 |
| Mortgage payoff | $389,125 | $250,000 | About $139,000 |
Sublimits vary and yours may be better. Read the actual schedule rather than the summary page, and read the conditions attached to it, because most social engineering wordings only pay if a documented verification procedure was followed. If your firm has no written wire procedure, the clause that funds your recovery may be the same clause that voids it.
And the money is not the whole loss. CertifID found that 56% of consumers would not work with a real estate firm again after a wire fraud incident, even when every dollar came back. In a referral business, that number should frighten you more than the sublimit does. That’s the real figure.
The 9 controls that stop most of this, in the order I would do them

Sequence matters here more than completeness. The first 3 rows below close the mechanism described earlier. Everything below that reduces blast radius and satisfies the record duty. None of it requires a security operations center.
| # | Control | What it stops | Who does it | Rough effort |
|---|---|---|---|---|
| 1 | Phishing-resistant MFA on every mailbox, sponsored agents included | Credential capture, which is step 1 of every case | IT provider | 1 to 2 weeks |
| 2 | Alerting on new mail forwarding and inbox rules | Quiet reading phase, before anything is stolen | IT provider | Under a day |
| 3 | Block legacy authentication and enforce conditional access | Password spraying that walks straight past MFA | IT provider | 2 to 3 days |
| 4 | SPF, DKIM and DMARC set to reject on the brokerage domain | Criminals sending as your own domain | IT provider | 2 to 4 weeks |
| 5 | A written wire policy stating the brokerage never sends or confirms wire instructions | Impersonation itself, by removing the pretext | Broker | An afternoon |
| 6 | Brokerage-owned identity for sponsored agents, not personal accounts | Orphaned mailboxes and unrecoverable records after an agent leaves | Broker and IT | 1 to 2 months |
| 7 | Retention and legal hold that survive a sponsorship ending | Losing the 4 years TREC requires when an agent walks | IT provider | 1 week |
| 8 | Offboarding tied to sponsorship termination in TREC records | Former agents keeping live access to client data | Broker | Ongoing |
| 9 | One tabletop exercise a year on a diverted wire specifically | Slow detection, which is what decides whether funds come back | Everyone | Half a day |
Rows 1, 2 and 3 are Microsoft 365 or Google Workspace features you are already paying for. You already own it. That is the part brokers find hardest to believe. Your bill for closing the most common attack path is mostly configuration time, not licensing, and any competent provider should be able to give you a fixed number for it.
Honest pushback on always call to verify
I want to argue with the standard advice for a second, because it is repeated everywhere and it is only half right. Telling buyers to phone and confirm wire instructions is good practice. It also puts the last line of defense on the most distracted, least experienced person in the transaction, using a number that may itself have been swapped in the fraudulent email.
CertifID makes the same point about their own industry, noting that a spoofed number can hand you a false sense of security rather than actual protection. So keep the phone call. Keep the wire fraud warning attached at buyer representation, in print, because it is cheap and it does catch people. Just stop treating it as the control. It is the backstop. Real controls sit on the brokerage side, and they run before anyone picks up a phone.
What this costs a Houston brokerage
Brokerage IT prices per user, which raises an awkward scoping question that other industries don’t have. Do you license 18 employees or 340 agents? Most start small. Houston firms we work with typically begin with employed staff plus the transaction coordinators and any agent who touches closing correspondence, then widen the license count once the identity work has settled and offboarding is running cleanly. Our fully managed rate is $138 per user per month, co-managed is $100 for firms with someone technical in-house, and monitoring-only through our MSSP tier starts at $40.
For context on the wider relationship, we’ve been doing this in Houston since 1999, we run a team of 42, our average first response on a ticket is 5 minutes, and we back new agreements with a 120-day satisfaction promise. We’re SOC 2 Type 1 certified and an MSP 501 honoree, which matters here mostly because your own underwriter will eventually ask who touches your systems.
On proof rather than adjectives, one Texas real estate client consolidated 14 virtual machines down to 3 with us, avoided a $120,000 hardware refresh, and got the whole project delivered for roughly $20,000. Details are in the case study on that engagement. It was an infrastructure project rather than a wire fraud one, and I’d rather show you a real number from real work than a hypothetical breach cost.
If you want the broader Houston service picture, that sits under managed IT services in Houston and managed security services. Brokerages usually need less than they are quoted. Usually far less.
Find out who could read your agents’ email today
We’ll run a review of your Microsoft 365 or Google Workspace tenant, list every mailbox without MFA, surface any forwarding rules already in place, and hand you a fixed-price plan for the 9 controls above. No obligation, and you keep the findings either way.
Questions Houston brokers ask us
Is the brokerage liable when a client wires money to a fraudster?
Liability turns on facts rather than a general rule, and it usually hinges on whether the compromise happened in your systems. If the fraudulent instruction came from a hacked agent mailbox you controlled, expect a claim. Talk to counsel. Your contracts and your facts decide it, not a blog post.
Do 1099 agents have to use brokerage email?
TREC doesn’t require it. Practically though, records you cannot reach are records you cannot produce, and Rule 535.2(h) makes the broker responsible for keeping 4 years of correspondence readily available. Personal Gmail accounts leave with the agent. That is the argument that usually wins the internal debate.
Does Texas require real estate brokerages to have a cybersecurity program?
Not directly. No Texas statute orders a brokerage to run a security program. SB 2610 works the other way round. It offers protection from exemplary damages to firms under 250 employees that already had a qualifying program running before the breach, which turns the statute into a strong commercial incentive rather than a legal mandate you can be fined for ignoring.
How fast do we have to report a breach in Texas?
Within 60 days of determining a breach occurred for affected residents, and within 30 days to the Texas Attorney General if 250 or more Texas residents are involved. Both clocks start at determination, not at discovery of the original intrusion, so your logs decide how defensible that date is.
Will cyber insurance cover a diverted closing wire?
Sometimes, and rarely in full. Funds transfer and social engineering losses are normally written as a sublimit well below the policy aggregate, often $100,000 to $250,000. Many wordings also require that a documented verification procedure was followed, so read the conditions alongside the number.
What is the single fastest thing we can fix this month?
Turn on alerting for new mail forwarding rules across your tenant, then audit the rules that already exist. It takes an afternoon, it costs nothing extra on most licenses, and it targets the exact phase where an attacker is inside your email but has not yet stolen anything.
Our brokerage is small. Is any of this proportionate?
A 12-agent firm doesn’t need a security operations center, and anyone selling you one is overshooting. Rows 1 through 5 of the control table cover a small brokerage properly. The rest can wait. Add them when headcount or a client’s compliance demands justify the spend.
One last thought. This problem persists not because brokers are careless, but because the risk sits in a seam. The broker owns the records, the agent owns the device, the title company owns the money, and the seam between them is where the attacker works. Somebody has to own the seam. Usually that’s the broker. Nobody else is in a position to.









