Construction Cyber Security Checklist: Protecting Project Data, Email and Remote Access

Construction Cyber Security Checklist: Protecting Project Data, Email and Remote Access

There is a version of this story doing the rounds of almost every contractor in the country. An email arrives from a subcontractor you have worked with for years, with the same signature block, the same project reference and the same slightly abrupt tone as always. 

It mentions that their bank has changed and asks for the next valuation to be paid to a new account. Someone in accounts updates the supplier record, the payment goes out on Friday, and three weeks later the real subcontractor rings up, cheerfully at first, to ask when they might expect their money.

Nobody did anything wrong, exactly. 

The email came from an address that looked right, or from an account that genuinely was right and had been sitting in a criminal’s hands for a fortnight while they read the correspondence and learned the payment cycle. It arrived in the middle of a busy week, referenced a real project and a real invoice, and asked for something suppliers do occasionally ask for. It slipped through because nothing in the process required anyone to actually pick up the phone.

What’s being done about it?

The National Crime Agency takes this seriously enough to have partnered with the National Federation of Builders on a campaign aimed at construction finance teams, and its figures explain why. Invoice fraud cost victims almost £4m in September 2025 alone across 83 reported cases, and construction and manufacturing between them accounted for a quarter of all reported invoice fraud in 2024/25, more than any other sectors. Fraud is not the whole picture either: the government’s Cyber Security Breaches Survey for 2025/26 found 43% of UK businesses hit by a breach in the previous year, rising to 65% of medium-sized and 69% of large firms, which is where most main contractors sit. 

Sector research is bleaker still, with QBE putting the average construction ransomware incident at 24 days of downtime and European data for early 2026 placing construction and manufacturing above financial services as the most-attacked sectors of all. Attackers have simply worked out what everyone in construction already knows, which is that a project sitting idle still costs money every day, and a business losing money every day makes for a motivated payer.

What follows is a checklist built around how contractors actually operate, across offices, sites, vans and a constantly shifting cast of third parties, rather than around the tidy corporate network construction firms do not have. Almost all of it maps onto Cyber Essentials, increasingly a prequalification requirement in its own right, so the compliance benefit arrives alongside the security one.

Why construction is a target

A live project generates an enormous amount of information others would like to have, from drawings and BIM models useful to a competitor bidding the same job, to tender pricing, to the valuations that map your cash flow, to subcontractor bank details. By the nature of the work it is shared with dozens of organisations you do not control, and every emailed copy becomes one more place it can leak from.

The industry is also distributed in a way that predates anyone calling it hybrid working. Head office has a proper network and a firewall, but the site cabin has a 4G router someone set up in a hurry on day one, a shared laptop and whatever devices the team happened to bring, while the contracts manager works from a car park and the quantity surveyor from home broadband at the weekend.

The old assumption that you protect the office and everything inside it is safe describes a way of working the industry abandoned long ago. Your perimeter now effectively includes your supply chain as well, because the security posture of a fifteen-person groundworks firm is rarely the equal of yours, and compromising a small supplier to reach a large contractor has become a well-worn route in.

Email and payment fraud

Construction runs on email more heavily than almost any other sector, which makes the mailbox both the richest source of intelligence about a business and the most convenient place to attack it. Two patterns account for most of the losses. The first is supplier impersonation, where a message claiming bank details have changed arrives either from a lookalike domain with a single character altered or from the supplier’s own genuine but compromised account. The second is executive impersonation, where an urgent, confidential payment request appears to come from a director who happens to be travelling, aimed at someone junior enough to feel uncomfortable questioning it.

A well-configured mail environment removes much of the raw material these attacks rely on. SPF, DKIM and DMARC should be implemented and moved to an enforcing policy rather than left indefinitely in monitoring mode, alongside advanced phishing filtering, external-sender warnings and alerts on suspicious mailbox activity such as newly created forwarding rules. Most of this is already present in the Microsoft 365 licences contractors hold and has simply never been switched on.

The control that actually prevents the loss, though, costs nothing but discipline. Any request to change bank details or make an unusual high-value payment should be verified by voice, on a number you already hold from the contract or your own records, and never one supplied in the email making the request. There can be no exceptions for urgency, seniority or a familiar name, precisely because urgency and seniority are the levers the attack pulls, and a five-minute phone call is a rounding error set against a diverted valuation.

Multi-factor authentication and identity

Passwords fail for reasons no complexity policy can fix, being reused across sites, harvested by convincing phishing pages and dumped in breaches from services nobody remembers signing up to. And once a criminal holds a working password for a mailbox they need no malware at all, only the patience to log in and read. 

Multi-factor authentication is the single most effective control on this entire list, defeating the overwhelming majority of account-compromise attempts, including the ones that lead to invoice fraud, and it is included in licences most contractors already pay for.

If you can’t enable it everywhere at once, sequence it by damage potential, starting with email, then finance systems, then cloud file storage and remote access, and prefer authenticator-app prompts or hardware keys to SMS codes, which can be diverted through SIM swapping. 

Administrative accounts deserve the most care of all, because they can create users, alter permissions and switch off the very controls that would otherwise reveal an intruder. If your outsourced IT provider holds administrative access to your tenant, as they almost certainly do, their security has become yours, and it is worth asking how it is protected.

Secure remote access and site networks

Since most of the workforce connects from somewhere other than head office, remote access is not an edge case in construction. The most common serious incident in smaller firms is a service published straight to the internet, whether remote desktop, a management interface or an ageing file server, protected by nothing more than a password, and automated scanning finds these exposures within hours. 

Nothing internal should be directly reachable from the internet; access belongs behind a properly configured VPN or an identity-aware gateway with multi-factor authentication in front of it, supported by conditional access so business data can only be reached from devices the business manages, encrypts and patches.

The site network deserves the same seriousness, because a network that connects to your business systems is part of your business network no matter how temporary it feels. That means business-grade equipment rather than the router that came free with a consumer broadband deal, central cloud management so one team can see and update every site without driving to each one, and a genuinely separate guest network so subcontractors and visitors never share the connection that holds your project files. 

Segmentation matters too, particularly for the IoT devices such as cameras, sensors and telematics that are rarely patched and often shipped with weak defaults, since a compromised camera that can reach your finance server is not really a network at all. Throughout, it pays to design for the connectivity you actually have, favouring offline file sync and authenticator apps that work without a signal over controls that get circumvented the moment they demand a stable connection nobody can guarantee.

Project files, supplier access and backups

Access to project files should follow role and current involvement, built around groups rather than individuals so that adding someone to a job grants what they need in one action and removing them revokes it just as cleanly. The default should be narrow, because the alternative, where everyone internally can see everything, means a single compromised account exposes every tender the firm holds. 

Sharing by controlled link rather than attachment also brings an operational dividend: issue a link to the drawings folder and the subcontractor always sees the current revision, whereas email a PDF and you have all but guaranteed someone eventually builds from an old one. 

External parties should be given named accounts rather than shared logins, held to multi-factor authentication and least privilege, and granted access that is time-limited so it expires with the subcontract, and practical completion ought to trigger an access review as reliably as it triggers a snagging list.

Backups determine whether a ransomware incident is a difficult fortnight or an existential event, and it is worth knowing that crews now hunt for backups before they encrypt anything, because a business that can restore is a business that does not pay. They therefore need genuine separation from live systems, held as offline or immutable copies with their own credentials and at least one copy off-site, and, in the step most often skipped, restored on a regular schedule, since an untested backup is only a hypothesis. Microsoft 365 data is yours to retain and restore rather than Microsoft’s, incidentally, and the default retention windows are shorter than most people assume.

People and keeping it working

Most incidents begin with a person rather than a firewall, so training earns its keep only when it is built from the firm’s own world, showing people what a fraudulent bank-details request looks like or how a fake Microsoft 365 login page appears on a phone in poor light on site, and it has to reach site teams as well as office staff. 

Reporting should be trivially easy and explicitly free of blame, because in the invoice-fraud cases where money is recovered, recovery almost always comes down to someone raising the alarm within hours. Behind that sits a simple incident plan setting out who can disconnect a system, how the firm communicates if email is compromised and how live projects keep moving, rehearsed once a year so it is a genuine capability rather than a document nobody has opened.

None of this holds still on its own, because access lists drift, new sites appear, suppliers change, and phishing has grown far more convincing since generative AI removed the spelling mistakes that used to give it away. The firms that stay secure are the ones that build a rhythm, reviewing patching and accounts monthly, access and backups quarterly, and the whole picture against Cyber Essentials once a year, each review owned by a named person. Since very few contractors can justify round-the-clock monitoring in-house, and most ransomware is deployed out of hours precisely because nobody is watching, this is often where managed security services earn their place, and for most firms the realistic choice is not between in-house and managed but between managed and hoping.

The construction cyber security checklist at a glance

  • Verify payments by voice on a known number before any bank-detail change. It’s the single cheapest defence against invoice fraud.
  • Enforce MFA on email, finance, file storage and remote access; admin accounts first; app or key rather than SMS.
  • Lock down email: SPF, DKIM and DMARC enforcing, phishing filtering, external-sender warnings, forwarding-rule alerts.
  • Expose nothing to the internet: access via VPN or gateway with MFA, from managed devices only.
  • Secure the site network: business-grade kit, central management, separate guest Wi-Fi, segmentation for IoT.
  • Control file access by role and project, share by link, remove access at completion, expire external links.
  • Manage supplier access: named accounts, least privilege, time-limited, reviewed.
  • Protect backups: immutable, off-site, separately credentialled, and tested (including your Microsoft 365 data).
  • Train everyone, including site, and make reporting blame-free.
  • Keep a review rhythm with named owners, and buy monitoring you cannot staff.

Building cyber resilience across every project

Strip away the acronyms and construction cyber security comes down to a small number of unglamorous habits: knowing what you hold, controlling who can reach it, putting a second factor in front of every account that matters, verifying money before it moves, keeping backups you have actually tested, and making sure people know what to do when something looks wrong. 

The economics are unusually clear-cut in this sector, because a single diverted valuation, or one project sitting idle for three weeks while systems are rebuilt, will comfortably exceed several years of sensible security investment, and unlike almost every other risk on a construction project this one arrives without a programme, a warning or a variation.

The reassuring part is that attackers are, for the most part, not doing anything clever. They are trying passwords that have already leaked, sending emails that look like invoices, and waiting for someone to be busy. Cyber threat prevention in this industry is largely a matter of making the ordinary things difficult.

At Utilize, we help construction businesses across Essex, London and the South East build practical, proportionate security around the way contractors actually work, securing Microsoft 365 tenants, rolling out MFA and identity controls, designing site networks that are part of the plan rather than an afterthought, managing patching across scattered estates, achieving and maintaining Cyber Essentials, and providing the monitoring most firms cannot staff internally. If you would like to know how your business measures against this checklist, talk to our team, or enquire about an IT security audit to find out where the gaps are. 

Take a look at our dedicated IT Support for Construction page for industry-specific advice and services.