Cyber security for construction: what to protect and where to start

Cyber security for construction means protecting drawings, BIM models, payroll and client data with simple, phased steps: start with Cyber Essentials, enable multi-factor authentication and secure site Wi‑Fi. Focus first on three low-cost controls to reduce common breaches and keep projects on schedule and paid on time.

Bolting on tools and hoping for no breaches

The common-but-wrong approach is to treat cyber security as a one-off IT purchase: buy a firewall, rely on basic antivirus and expect passwords to do the rest. That leaves gaps where construction workflows cross into technology — subcontractors sharing files, remote access to site cameras, or accounts created during a tender and never revoked. These failings show up as late payment requests, invoice fraud and delays when a key document becomes unavailable.

Typical mistakes include:

  • Single-factor logins for shared accounts on site tablets.
  • Unsegmented Wi‑Fi that gives guests access to project servers.
  • No routine for removing leavers from cloud file permissions.

Those are all solvable without a major CAPEX project. The short-term fixes that most teams skip are often administrative: tighten who has access to what, set sensible password policies and enforce multi-factor authentication on any account that touches payroll or payment data. For practical next steps, apply the controls in phases and document the changes so that subcontractors and site staff know the new expectations.

Layered, people-first security tuned to construction workflows

The right approach treats security as a set of overlapping layers: simple technical controls, regular staff routines, and contractual expectations for suppliers. Start by hardening entry points (VPNs, emails, file shares) and then add predictable operational routines that fit how site teams actually work.

Concretely, a layered plan looks like this:

  1. Access hygiene: centralise accounts, enforce multi-factor authentication and audit permissions monthly.
  2. Device control: require encrypted devices with automatic updates and a minimal set of applications.
  3. Network separation: separate guest/site Wi‑Fi from engineering and finance systems.
  4. People routine: short, regular training tied to real phishing simulations and simple reporting steps for suspicious messages.

For construction, the people routine is critical. In our work with contractors and specialist trades, we run phishing-simulation programmes that show how staff behaviour improves with repetition: in our experience phishing-simulation click-through rates are typically in the 15–25% range initially — after four cycles of targeted training that number drops below 5%. That illustrates two points: training genuinely works, and it only sticks when you repeat it rather than treat it as a one-off checkbox.

Two implementation examples that fit the layered model:

  • Small main contractor: implement Cyber Essentials, roll out MFA for all finance and PPM accounts, and run a one-page access register for each project. See how our cyber security services for construction map these controls to site roles.
  • Specialist subcontractor: segment design workstations from site tablets, enforce full-disk encryption and schedule a monthly permission review for cloud folders shared with clients.

For policy alignment and baseline actions, the NCSC has practical roadmaps for small organisations; follow the NCSC’s guidance on secure remote working and basic controls to match those recommendations to your project timelines. NCSC’s guidance on enterprise controls

When planning rollout, aim for a small, visible set of wins in the first 30 days (MFA, guest-network separation, and an access register). Then schedule the next layer — device management and supplier contractual clauses — over the following quarter. That rhythm keeps day-to-day operations moving while the team adapts to new routines.

Concrete examples (one-liners you can act on):

  • Issue a single managed tablet per site with enforced MFA and a restricted app set.
  • Make invoice changes reportable by email and phone verification for payments over a set threshold.
  • Include a short cyber clause in subcontractor contracts requiring patched devices and named account owners.

Start with the three low-cost controls from the opening paragraph, measure what changes, and schedule the next controls into the project plan so security becomes part of delivery rather than a last-minute task.

Related reading

FAQ

How quickly can I get Cyber Essentials certification?

Small firms that already have basic controls can typically complete the self-assessment and certification in 2–4 weeks; allow longer if you need to implement device management first.

How often should we review site access and permissions?

Review access lists at least every 3 months, and immediately after major site milestones (handover, subcontractor changes) to avoid lingering permissions for leavers.

Do I need to run phishing simulations for all staff?

Yes — run short, realistic simulations for office and site-facing staff; make them regular so outcomes feed training and are part of appraisal conversations rather than a one-off test.

Who should own cyber security on a project?

Nominate a single owner — either the site manager or an IT/security lead — who does weekly checks and escalates risks to senior management for funding or policy changes.