CRE
A red-flag MSP proposal for a commercial real estate company skips multi-tenant network segmentation, ignores riser and carrier coordination, and treats physical security systems as someone else's problem. If it doesn't mention MDF/IDF management, tenant move-in/move-out support, or 24/7 on-site response, you're likely looking at a break-fix shop - and that gap costs more than any price difference.
In This Article
- Does the proposal understand multi-tenant network environments?
- Is riser management and structured cabling actually in scope?
- Who handles physical security, cameras, and building systems?
- What happens when a tenant moves in or out?
- Does the proposal include after-hours and emergency response?
- Does the proposal treat compliance as one-size-fits-all?
- Frequently Asked Questions
Does the proposal understand multi-tenant network environments?
Commercial real estate properties rarely host a single network. Tenants run their own operations, staff needs access to building systems, guests expect amenity Wi-Fi, and security systems need their own isolated pathways. A proposal that describes your environment as a single flat network - or doesn't address segmentation at all - signals that the MSP hasn't thought through how CRE properties actually work.
Look for language about tenant network isolation, separate VLANs or virtual networks for each tenant, dedicated security system segmentation, and clear demarcation between tenant-controlled and building-managed infrastructure. If the proposal uses generic small-business language without addressing multi-tenant realities, the MSP will likely create problems you discover only after move-in day.
Properties along the I-85 corridor in Norcross and greater Atlanta routinely host mixed tenant types - office tenants, flex space, light industrial users, and co-working operators - often in the same building. Each brings different connectivity expectations and different security assumptions. Commercial real estate IT isn't the same as a single-office setup, and the proposal should reflect that from the first page.
Takeaway: if the proposal doesn't describe how tenant, staff, guest, and security traffic stay separate, keep looking.
Is riser management and structured cabling actually in scope?
A building's riser - the vertical pathway that carries connectivity between floors - is where most property-wide communication problems start. Carrier handoffs, demarcation points, MDF and IDF closets, fiber backbone runs, and structured cabling paths all live here, and they affect every tenant turn-up, every move, and every service change in the building.
Red flags include a proposal that ignores riser infrastructure entirely, treats cabling as a one-time construction item rather than an ongoing managed asset, or assumes every floor's wiring is documented and labeled correctly. In older Norcross and Atlanta-area buildings, undocumented riser runs and mislabeled patch panels are common - and they turn simple tenant suite turn-ups into days of troubleshooting.
A solid proposal addresses structured cabling and low voltage services as part of ongoing operations, not just a build-out item. It includes riser audits, documentation updates after each tenant move, carrier coordination for new handoffs, and a clear process for who owns each demarcation point. Without that, you're paying for reactive troubleshooting every time a tenant requests a service change.
Takeaway: if riser management isn't in scope, the proposal is selling you a help desk, not a property-wide technology operation.
Who handles physical security, cameras, and building systems?
Modern commercial properties run more than just office networks. Video surveillance, access control, amenity Wi-Fi, guest networks, and increasingly building automation systems all sit on infrastructure that an IT provider either manages, coordinates, or ignores. A proposal that treats these as entirely separate from IT - or doesn't mention them at all - leaves gaps that show up fast when a camera goes dark, an access door sticks, or a tenant complains about dead drops in their suite.
Red flags: no mention of surveillance system maintenance, no access control management plan, no process for integrating new IoT or building system devices onto the network securely, and no thought given to how these systems connect back to the same infrastructure that carries tenant data. A vendor proposing a pure software play without physical security competence will leave you coordinating between three different vendors when something breaks.
Therese Good, who works in commercial real estate, described working with a GDS Technology technician this way: "Brian clearly explains what is happening and shows you ways to help prevent the issue from happening again. He is great to work with." That kind of preventative explanation - connecting a camera issue back to the network path, power, or configuration - is what separates a true property technology partner from a ticket-closing vendor. For properties with smart-building or IoT devices installed by different vendors over time, the proposal should also address how existing devices get secured, segmented, and brought under management. The challenges of cybersecurity for mixed-device environments are real - and they start with a proposal that acknowledges them instead of pretending they don't exist.
Takeaway: if physical security systems aren't part of the proposal, the MSP is only solving part of your building's technology puzzle.
What happens when a tenant moves in or out?
Tenant turnover is one of the most operationally intense periods in commercial real estate - and it's also when IT problems cascade fastest. A suite turn-up requires carrier coordination, cabling verification, network port provisioning, Wi-Fi validation, and often coordination with the tenant's own IT provider. A move-out requires removing access credentials, reclaiming ports and drops, updating documentation, and making sure no tenant data or access lingers.
Red flags: a proposal with no move-in/move-out process, no mention of coordinated suite turn-ups, no documentation update step, and no clear handoff or coordination protocol with tenant IT providers. If the proposal treats a new tenant as "just another ticket," you'll spend your facilities team's time chasing IT details during what should be a smooth transition.
A strong proposal describes a structured turn-up process: pre-move cabling and connectivity verification, coordinated cutover timing, post-move testing, documentation updates, and a clear point of contact who owns the sequence. It also addresses move-outs - removing access control credentials, reclaiming and testing drops, and updating network documentation so the next tenant starts from a clean slate.
Takeaway: if tenant turnover isn't a defined process in the proposal, expect your team to absorb the coordination burden.
Does the proposal include after-hours and emergency response?
Commercial properties don't stop operating at 5 p.m. Building systems fail on weekends, network outages affect tenant operations outside business hours, and security events don't wait for a help desk schedule. A proposal that only describes business-hours support - or doesn't specify what happens after hours - is telling you exactly what you'll get when something breaks at 9 p.m. on a Saturday.
Red flags: no 24/7 monitoring mentioned, no on-site response commitment for critical failures, no disaster recovery or business continuity planning tied to building operations, and no clarity on response times for urgent vs. routine issues. If the proposal is silent on after-hours coverage, assume you're paying for it separately - or not getting it at all.
Look for 24/7 cyber monitoring, defined response processes for urgent building-affecting issues, and a disaster recovery planning approach that accounts for property operations - not just file backups. Teams that have mapped what breaks when a building loses power, connectivity, or control can respond faster and more accurately, and that thinking should show up in the proposal. Our podcast episode on dependency mapping for building outages covers what to include and where the common blind spots are - if the proposal doesn't reflect this kind of operational mapping, the MSP hasn't done the groundwork that serious properties need.
Takeaway: if after-hours response isn't defined, the proposal is built for office hours, not building operations.
Does the proposal treat compliance as one-size-fits-all?
Commercial real estate properties host tenants with very different regulatory obligations. A medical office tenant in one suite may need HIPAA-ready infrastructure and data handling. A CPA firm in another may require PCI-aware practices if they process card payments on-site. A law firm may have client confidentiality expectations that shape how their environment is designed and supported. A proposal that treats compliance as a single checkbox - or ignores it entirely - misses the reality of mixed-tenant properties.
Red flags: compliance described as a one-time assessment with no ongoing support, no recognition that different tenants in the same building may have different requirements, and no ability to connect compliance needs to the actual network and infrastructure design. If the MSP can't distinguish between "we need HIPAA-ready infrastructure in Suite 200" and "the whole building needs to be HIPAA-compliant," they'll either oversell or undersell - and probably undersell the parts that matter.
GDS Technology supports IT compliance services including HIPAA, PCI, FTC, and CMMC - but the right starting point is a proposal that asks which tenants, which suites, and which obligations actually apply, rather than prescribing a single compliance package for the entire property. An honest proposal also ties compliance to concrete infrastructure decisions: segmented networks, access controls, audit logging, and documented onboarding.
Takeaway: if the proposal doesn't ask which tenants have which obligations, the compliance conversation is starting in the wrong place.
Fully managed IT for a multi-site commercial real estate portfolio typically runs $200 - $300 per user/month, with commercial access control adding $4,500 - $5,000 per door - figures that should appear as ranges tied to scope, not as single quotes that hide what's excluded.
| Proposal signal | Red flag | What a solid proposal includes |
|---|---|---|
| Network design | Single network described for the entire property; no tenant separation | Multi-tenant segmentation, guest and amenity networks, security system isolation, clear demarcation points |
| Riser and cabling | Treated as a one-time construction item; no ongoing management or documentation | Riser audits, cable labeling and documentation, carrier coordination, MDF/IDF management as ongoing assets |
| Physical security | Not mentioned, or handed off to an unrelated vendor with no coordination | Surveillance, access control, and building systems discussed as part of the same infrastructure; integration and segmentation addressed |
| Tenant turnover | No defined move-in/move-out process | Structured turn-up process, carrier and cabling coordination, post-move testing, documentation updates, access revocation on move-out |
| After-hours support | Business-hours-only coverage or no response-time commitment | 24/7 monitoring, defined urgent vs. routine response, on-site capability for critical failures, disaster recovery planning tied to building operations |
| Compliance posture | One-size-fits-all compliance language, or no compliance discussion at all | Recognition that different tenants have different obligations; ability to support HIPAA, PCI, FTC, or CMMC needs where applicable; compliance-aware network design |
Frequently Asked Questions
What should a commercial real estate company look for in an MSP proposal?
Look for a proposal that addresses multi-tenant network segmentation, riser and structured cabling management, physical security system coordination, defined tenant move-in and move-out processes, and 24/7 after-hours response. The proposal should treat your property as a mixed-use environment - not a single office - and explain how tenant, staff, guest, and security traffic stay separate and secure.
How much should a fully managed IT service cost for a CRE property?
Fully managed IT services for a comprehensive Technology Partner relationship typically run $200 - $300 per user per month, with scope varying based on cybersecurity, compliance, infrastructure, number of locations, and business requirements. Commercial access control adds roughly $4,500 - $5,000 per door installed. An honest proposal presents these as ranges tied to scope - not a single flat figure that hides what's excluded.
Why does riser management matter for multi-tenant buildings?
The riser is the vertical connectivity backbone that carries service between floors, and it touches every tenant turn-up, every move, and every carrier handoff in the building. Without managed riser documentation, labeled demarcation points, and coordinated carrier handoffs, a simple suite turn-up can turn into days of troubleshooting - and that cost shows up in your facilities team's time, not the MSP's invoice.
Do commercial real estate properties need 24/7 IT monitoring?
Yes - building systems, security infrastructure, and tenant networks don't stop operating after business hours, and outages or failures on weekends and evenings affect tenant operations directly. A property technology partner should provide 24/7 cyber monitoring and defined response processes for urgent building-affecting issues, not just a business-hours help desk that tells you to call back Monday morning.