Security awareness training for property developers is practical coaching that teaches the people who move deposits, progress payments and settlement funds to verify every bank-detail change and payment request before money leaves the account. Property developers handle large, infrequent transfers between many outside parties — agents, solicitors, conveyancers, builders, consultants and lenders — and that mix is exactly what payment-redirection fraud depends on.
A developer's exposure differs from an ordinary office. Deals run on email with tight settlement deadlines, project teams change constantly, and one wrong transfer can be hundreds of thousands of dollars. Training has to be built around those moments rather than around generic password advice.
Why this matters for property developers
The Australian Cyber Security Centre has issued a specific alert about property-related business email compromise, describing cybercriminals who impersonate parties to a transaction, such as real estate agents or conveyancers, and insert illegitimate bank details for settlement or rental payments. It notes that victims often do not notice for weeks, until someone follows up on a missing payment.
PEXA, the electronic settlement platform, has published research showing that 97% of Australians who had bought a property in the last year or intended to buy in the next failed to spot dangerous scam markers in property transaction emails, even though most believed they could. PEXA also describes a Western Australian buyer who lost $732,000 after scammers intercepted emails between her and her settlement agent. The scam message came from a generic Hotmail address using the agency's name.
On the national picture, ASD's Annual Cyber Threat Report 2024–25 lists business email compromise fraud resulting in financial loss at 15% of business cybercrime reports, and ACSC's earlier 2020–21 report put the average loss per successful event above $50,600. Developers sit above that average because their transfers are larger.
How to train a property development team
1. Map where money leaves the business
List every payment type: land deposits, builder progress claims, consultant invoices, authority fees, trust account transfers and loan drawdowns. Mark who can approve each, who can change supplier bank details, and which inbox receives the instructions. Training goes where the money moves.
- Deposit and settlement transfers
- Progress claim payments to builders
- Supplier and consultant invoices
- Changes to saved payee details
- Requests from a lender or solicitor to update accounts
2. Set one rule for bank-detail changes
Any new or changed bank detail is verified by phone on a number from your own records, not from the email requesting the change. PEXA's guidance is explicit: do not use email to exchange bank account details as part of settlement; confirm them verbally by phone or in person. Write the rule down and make it apply to everyone, including directors.
3. Teach the five warning signs
- A slightly altered sender address, such as a changed letter or extra punctuation
- A generic free-mail address using a company name
- Urgency, especially threats of forfeiture or penalties
- Revised bank details arriving late in the transaction
- A request to keep the change confidential or skip the usual approval
These are the markers PEXA's research found most people overlook.
4. Separate approval from instruction
The person who receives a payment request should not be the only person who can release it. Require a second approver above an agreed threshold. Fraudsters rely on a single busy person acting alone before settlement.
5. Rehearse with realistic simulations
Build a phishing simulation around a settlement-week scenario: a solicitor emailing new bank details, a builder's updated invoice, a lender's urgent query. The goal is to see who verifies before paying. Cyber Aware auto-enrols anyone who clicks into a short follow-up lesson, so coaching happens at the moment it matters.
6. Cover the whole project chain
Developers share information with many outside firms. Agree a standard verification step with your solicitor, conveyancer and key suppliers, so they also call back before acting on emailed changes. Include contractors and project managers in the training, not only head-office staff.
7. Add executive-level rehearsal
Directors approve the largest transfers and are impersonated most often. A smaller, targeted program for them is worth running; see our guide to whaling simulations for executives.
Training options compared for property developers
| Option | Best for | Strength | Limitation |
|---|---|---|---|
| Annual group briefing | Basic awareness | Low cost and quick | Not tied to settlement scenarios |
| Role-based short modules | Finance, project and admin staff | Matches payment workflows | Needs a platform and scheduling |
| Settlement-themed simulations | Testing verification habits | Measures real behaviour | Email-only unless extended |
| Written payment-change policy with sign-off | Everyone who handles money | Free and enforceable | Ignored without rehearsal |
A written policy, short modules and settlement-themed simulations together cover the gaps in each. Cyber Aware training delivers short, story-driven modules that suit project teams who cannot sit through long courses.
Common mistakes property developers make
- Treating fraud as a head-office problem. Site managers and project coordinators often receive invoices directly.
- Verifying by replying to the same email. If the mailbox is compromised, the reply goes straight to the attacker.
- Relying on the settlement platform alone. The ACSC notes that PEXA itself remains secure, but fraudulent bank details entered into it by a deceived agent still send funds to the wrong account.
- No second approver. One person with full control is the failure point.
- Training once, then never again. Teams change per project; new starters need coverage within their first weeks.
Measuring progress
Watch two numbers: how many suspicious payment requests get reported, and how many simulated requests get acted on. Reports should rise as clicks fall. Cyber Aware's human risk reporting combines those results into a per-learner score, which helps you see whether finance and project staff are actually improving.
FAQ
Why are property developers a target for payment fraud? They make large, time-pressured transfers to many external parties by email. Scammers impersonate agents, solicitors or builders and slip in fraudulent bank details, hoping one busy person pays before checking.
What is the most important control for a property developer? Verify every bank-detail change by phone using a number from your own records. Never use contact details included in the email requesting the change.
Does using PEXA stop payment redirection scams? Not by itself. The ACSC notes that PEXA remains secure, but a settlement agent who enters fraudulent bank details supplied by an impersonator still sends funds to the criminal.
How often should property development staff be trained? Run short refreshers through the year and train new project staff within their first weeks, since project teams change often.
Should contractors and project managers be trained too? Yes. They receive and forward invoices and bank changes, so they are part of the payment chain.
One last thing
Ask your solicitor or conveyancer today how they confirm bank details with you. If the answer is email, agree a phone call-back as the standard for every future deal.