First Steps for Property Services and Information Technology
We’ve received a lot of feedback from an earlier Stirling post (Property Management, Information Technology and the New Paradigm) about the amount of work required to update Information Technology Infrastructure for today’s world. A few people keyed in on the amount of work required when their Information Technology Projects had taken a back seat to other priorities in the last five years, ten years or forever.
Some had asked for a cheat sheet on what they should do first or what questions they should be asking their property services company about their Information Technology Systems. This list is far from comprehensive – merely first steps, but if Stirling had just taken over a new property or if I was starting from scratch, this would be my initial list of things to check or you can hit your Property Services company up to find out what they were doing in regards to Information Technology:
Do I have a next generation firewall at my offices?
Are my automation systems firewalled and segmented away from my office computers (i.e. postage machines, hvac systems, video directories, card access systems)?
Not very effective anymore, but still a first step, do all my computers have anti-virus protection?
If my computers haven’t been running anti-virus, who will format the hard drive and reset it back to the factory default image, then add anti-virus protection and load all my documents back?
Do we have, at the very least, basic spam filtering to try and eliminate the ZeroHour emails and do we have Sender Policy Framework (SPF) setup?
And finally, this really isn’t about security, but to offer up some lagniappe for the New Year, check into finally getting rid of your old analog telephone system to see what features you would gain and how much you would save with a Voice over IP (VoIP) System. Check into either a legitimate cloud provider or see if your property services company can add you to their system – adding your property to their system should be simple.
Obviously this is a very basic list, but whether your property is managed by Stirling or not, feel free to shoot me an email if you have questions and I’ll try to point you in the right direction. When it comes to Internet Security, we’re all in this together.
Property Management, Information Technology and the New Paradigm
Used to be that technology was an afterthought, if it was a thought at all, when it came to property management. No one thought twice about putting file servers, telephone systems, sharing the office Wi-Fi with the public and having each management office a self-contained island unto itself. We’re long past the days, when we could put a desktop at a managed property office and simply forget that the computer was there until the computer died or a user complained. While the most important element of property management is still the right property manager, with the advent of Internet-connected building automation, Voice Over IP (VOIP), cloud offerings, server virtualization, software as a service (SaaS), desktop as a service (DaaS) and the well-publicized complete lack of security on the Internet, it’s time to pay attention to how property management offices are utilizing technology, how the offices are secured and how we are maintaining the infrastructure.
Here at Stirling we’ve taken over a lot of management contracts in the last few years and the thing that strikes us from the IT-perspective is how little attention has been paid to the automation and the office systems. Even from the large, national property service companies, we’ve seen file servers and desktops systems at managed properties that are past end-of-life such that the manufacturers are no longer providing security updates. We’ve seen automation systems, directly connected to the Internet with no firewall and still running default system credentials, leaving not only that system, but the entire office vulnerable to attack. Accounting or Point of Sale Systems on the same network as the HVAC or Automation Systems without network segmentation or firewalls is simply asking for trouble.
While other industries have been quick to embrace technology, it sometimes seems that Commercial Real Estate as an Industry has gotten a half-step or two behind where we need to be in maintaining our technology. Overhauling systems doesn’t necessarily have to be a large expense. In a lot of cases, the savings from removing the maintenance costs associated with outdated systems will go a long way towards modernizing and securing your infrastructure. Just as everyone knows and can do the calculation on a commercial real estate’s return on investment, there’s also a return or a savings with Information Technology deployed and maintained correctly.
- Still have an outdated DSL connection to the Internet? Fiber has proliferated in the last couple of years. Look at dedicated bandwidth with a Next Generation Firewall.
- Sharing your Internet with the public? Stop! Or at the very least, make sure your management office network is segmented to protect your critical systems.
- Same with automation. If your HVAC, access card or automation systems are connected to the Internet, change the default credentials and segment away from your office computers.
- Are your servers on the same network as your Wi-Fi? Segment and firewall the network so if your Wi-Fi gets hacked, they don’t have a clear path to the rest of your equipment.
- Still running Windows Server 2000 or 2003? Server 2000 was retired on July 13, 2010 and Server 2003 is ending on July 14, 2015 which means no security patches and a huge vulnerability for you. It’s time to ditch the server and connect to your back office virtually.
- Still have a Windows XP computer or a POS with embedded Windows XP? XP’s end of life was April 8, 2014, leaving your systems vulnerable. It’s time to upgrade your systems or virtualize your desktops.
- Still have an analog telephone system with roll over lines? With dedicated bandwidth and quality of service, you can take advantage of Voice Over IP – sometimes at a substantial savings to what you’re paying for your system now.
- Do you have separate banking computer that you use only for banking? Absolutely no general Internet surfing? Might want to consider dedicating a computer to banking.
- Are you setup with Positive Pay with your bank? This is an important first step.
- Still using an old POP service for email? It’s time to switch to an Exchange-style email system. Setup with your management company or contract online for hosted Exchange or Zimbra email.
Contracting with a property services firm that has a dedicated technology staff makes your life easier and allows you to take advantage of the economies of scale inherent in that relationship, but if you have the time and the wherewithal to work through the vulnerabilities, you can go a long way to securing your systems and leveraging technology for the value it will bring to your property.