Cyber security for construction companies is not a theoretical problem. Construction consistently ranks among the most targeted industries for ransomware and payment fraud in Australia, and the attackers are not targeting the tier-one builders. They are targeting the mid-sized firms: enough money moving through the accounts to be worth the effort, rarely enough security to stop them.
We provide managed IT and security for construction and property businesses in Brisbane, so this post is written from what we see on real sites and in real head offices: why the industry is attractive to attackers, the two attack types that do the damage, and the practical checklist that closes most of the risk.
Why are construction companies a cyber target?
Five structural features of the industry make it attractive:
- Large payments are normal. Progress claims, supplier invoices, and subcontractor payments move six and seven figure sums between parties who often know each other only by email. Redirecting a single invoice can be worth more to an attacker than a month of ransomware operations.
- Project data is valuable and time-critical. Tender documents, CAD files, cost schedules, and programme data are commercially sensitive. Encrypt them mid-project and the pressure to pay is immediate.
- The supply chain is the attack surface. A mid-sized project can involve dozens of subcontractors, consultants, and suppliers, each emailing documents in and out of your environment. Every one of them is a potential entry point, and almost none of them have had their security checked by anyone.
- IT investment lags revenue. A firm can grow from 20 to 120 staff on the back of won work while still running the server, the shared drive, and the IT habits of the 20-person version of itself. Attackers can smell this from the outside: exposed services, ageing mail configurations, no MFA.
- Downtime is intolerable. When systems are down, sites still cost money every day. Attackers price their ransom against your daily burn rate, and in construction that rate is high.
What attacks actually hit construction firms?
Payment redirection fraud (business email compromise)
This is the attack that costs Australian construction businesses the most money. An attacker compromises an email account somewhere in the payment chain, or registers a lookalike domain, then sends a convincing "our bank details have changed" email before a large payment. The fraud surfaces weeks later when the real supplier chases the unpaid invoice. By then the money has been moved through mule accounts and is gone.
The defence is process as much as technology: multi-factor authentication on every email account, and a hard rule that any change of payment details is verified by phone to a number you already had on file. Not the number in the email signature. The one in your system from before the email arrived.
Ransomware
Ransomware protection for construction starts with knowing how it gets in: a phishing email, an unpatched system, or stolen credentials without MFA. Once inside, the attacker encrypts project files, drawings, and the accounting system, then demands payment against your programme deadlines. Recovery for an unprepared business is typically measured in weeks. On an active project that means missed milestones, subcontractor disputes, and liquidated damages clauses coming into play before you have paid a cent in recovery costs. We cover the wider numbers in The Real Cost of Ransomware in Australia.
What does practical construction cybersecurity look like?
A construction business does not need an enterprise security program. It needs the right controls implemented properly and kept running. This checklist closes most of the real-world risk:
- Multi-factor authentication everywhere. Email, accounting software, project management tools, and remote access. No exceptions for directors or estimators. MFA alone defeats most account compromise.
- Payment verification process. Written into the accounts procedure: bank detail changes are confirmed by phone to a known number before the next payment runs. This one habit defeats most invoice fraud.
- Endpoint protection on every device. Including the site laptops, the ute-mounted tablets, and the estimator's home machine. The office workstations are usually the best-protected devices in a construction business, and the least attacked.
- Patching that includes site equipment. Unpatched software is the most common ransomware entry point. Site devices that rarely visit the office still need to update, which is what remote management tooling is for.
- Backups you have actually tested. Offline or immutable, covering project data and the accounting system, and restore-tested on a schedule. An untested backup is a hope, not a control.
- Email filtering tuned for payment fraud. Flag lookalike domains, external senders impersonating internal names, and payment detail change requests.
- Staff training with construction scenarios. Train the accounts team on invoice fraud and the project team on phishing. Generic training washes off; scenarios that look like a subcontractor variation claim stick.
What about the site side of the business?
Construction cybersecurity guides written for office businesses miss the half of the company that works outdoors. Site environments have their own risk profile:
- Site internet is often improvised. A 4G dongle from the nearest servo, a consumer router with the default password, or the sales office sharing an unsecured connection with the public. Site connectivity should be planned and secured like any other office, and for remote sites, options like Starlink with proper firewalling make that achievable almost anywhere.
- Devices travel and disappear. Laptops and tablets move between utes, site sheds, and homes. Every one should be encrypted, protected, and remotely wipeable, because eventually one gets left on a roof rack.
- Shared logins creep in. One tablet, five users, one password taped to the shed wall. Shared credentials make it impossible to know who did what, and they never get changed when someone leaves the project.
None of this requires site staff to become security experts. It requires the IT setup to assume site conditions rather than office conditions.
What should you do if it happens anyway?
No control set reduces the risk to zero, so the last control is knowing what you will do on the bad day. For payment fraud: the moment it is discovered, call your bank's fraud line, because recovery odds drop by the hour, then report through ReportCyber and notify the other party in the payment chain, whose systems may be the ones compromised. For ransomware: isolate affected systems, do not pay before getting advice, and work the recovery from your tested backups. If personal information was involved, the Notifiable Data Breaches scheme may require you to notify the OAIC and affected individuals.
All of that goes far better when it was written down as an incident response plan before it was needed. That plan is one of the controls SMB1001 Gold requires, which is not a coincidence.
How do compliance and SMB1001 fit in?
Cybersecurity questions are appearing in tender and prequalification paperwork across the industry. Principals and government clients want evidence that security is managed, not asserted. For most SMB construction firms, full ISO 27001 is more than the requirement calls for. SMB1001 Gold certification covers 27 practical controls, including everything on the checklist above, and gives you a recognised certificate to attach to the tender response. It also reads well to your insurer at renewal time.
We run managed IT for construction businesses across South East Queensland, from head office to site connectivity. For one property development client that meant standing up secured Starlink internet for a coastal sales office no fixed connection could reach, firewalled and managed like any other site. You can see how we work with the industry on our managed IT services for construction page.
If you want a straight answer on where your business stands, book a discovery call. We will start with a gap assessment, not a sales pitch.

