As the construction industry’s digital transformation continues apace, businesses must ensure they build in the essential safeguards against threats. Tim Clark reports
In February of this year, UK engineering firm Arup fell victim to a deepfake scam.
An employee in Hong Kong was duped into sending £20m to people posing as senior managers at the company. The fraud was sophisticated and targeted, and used AI to help emulate Arup’s chief financial officer (CFO) on a video call. The £20m was transferred over to another bank account.
It isn’t the first time Arup has been targeted. In 2021 Arup staff had their personal details stolen, including bank details, names and addresses, after a third-party payroll provider was targeted.
Since the turn of the decade it has become clear that the construction sector has been viewed by many as a weak spot for cyber threats, driven by its growing reliance on digital technologies, connected systems, and complex supply chains.
Arup is not alone. It’s not just any financial loss from a hacking scam that can affect a company.
Architecture practice Zaha Hadid (ZHA) was victim of an attempted cyber attack in 2021 with hackers attempting to break into the company’s servers, encrypt data and hold the company to ransom.
It isn’t just the disruption; data breaches can incur heavy fines, under the UK Data Protection Act 2018 (up to £17.5m or 4% of annual global turnover). Only last month, Sellafield was fined over £330,000 for data breaches.
As more and more construction firms turn to digital solutions, the threat of cyber security problems has also grown. So much so that the government’s own intelligence unit, GCHQ has launched a series of cyber-security initiatives targeted specifically at construction. The main aim is to increase cyber resilience in the sector.
Soft target
The construction industry is often viewed as a “soft target” for cybercriminals due to its relatively slower adoption of cybersecurity practices compared to other sectors.
The National Cyber Security Centre (NCSC), part of GCHQ, published its first specific cybersecurity guidance for construction firms in early 2022.
In it, the Chartered Institute of Building (CIOB) chief executive Caroline Gumble, highlighted that online security, and the impact of successful phishing, hacking or scam attempts cannot be over-stated.
“They can have a devastating impact on financial margins, the construction programme, business reputation, supply chain relationships, the built asset itself and, worst of all, people’s health and wellbeing,” she said.
“Understanding the digital aspects of a business (and then minimising and managing the risks presented) is therefore of prime importance.”
The issues for construction are two-fold. The first is integrating new technology into the sector such as digital twins, AI, robotics and drone use, using vast amounts of data, just as cyber security threats are becoming more sophisticated, leaving many firms exposed to accidentally breaching security on specific projects.
The other issue is that many construction projects can be considered critical national infrastructure (CNI) such as Hinkley Point C, defence projects, or rail and road infrastructure.
A recent report by defence contracting firm Thales, which looked at cyber security threats globally, found that 93% of global firms it studied had seen an increase in cyber security threats.
The report cited the use of IoT (Internet of things), and 5G environments which “are increasingly used for critical infrastructure, including smart city initiatives” as one aspect of the problem.
It stated: “Forty-four (44%) percent of public sector respondents already cite security concerns as the number one inhibitor of IoT initiatives.”
The report found that almost a quarter, 24% of CNI organisations reported that they had suffered from a ransomware attack in the past year, with over one in 10, 11% paying the ransom.
Writing in Smart Infrastructure, Tony Burton, managing director of cyber security and trust at Thales UK said that the rise in cyber attacks coincided with the digitisation of power grids in recent years.
“While this shift allows for better monitoring, optimisation, and management of energy usage amidst ongoing energy, environmental, and cost of living crises, it also introduces significant risks,” he said.
“The digitisation of power grids has expanded the attack surface, providing cybercriminals with numerous entry points through smart grids’ various interconnected and interdependent digital systems.”
According to Burton, human error accounted for 34% of cyber security threats, vulnerabilities another 31%, and a failure to apply what is known as multi-factor authentication another 20%.
The NCSC report added that, fairly or unfairly, construction businesses are seen by cyber criminals as an easy target, many of which have high cash-flows.
It stated: “Perhaps understandably, smaller and mid-sized businesses have a ‘we’re only a small business, it won’t happen to us’ attitude towards cyber security, and are reluctant to invest time, money, and training into what they perceive an unlikely threat.”
The extensive use of sub-contractors is also highlighted as a problem, making such supply chains “attractive target for spear phishing, which is when attackers send a targeted email that’s pretending to be from a legitimate organisation, in an attempt to trick the construction supply chain”.
The NCSC also stresses the importance of securing Building Information Modelling (BIM) platforms. Although BIM has established itself an essential tool for collaboration, its use in sharing detailed blueprints and sensitive project data makes it a potential target for cyber-attacks.
Protecting these systems from unauthorised access and ensuring the integrity of shared data is crucial for safeguarding ongoing projects and avoiding costly disruptions.
Defence of the digital realm
What can construction firms do to tackle the problem? Keeping on top of cyber security threats and ensuring they meet compliance is key.
Of the firms involved in critical infrastructure, only 17% of those that ensured they were compliant had a history of successful data breaches. Only 2% of those were in the last 12 months.
In addition to the NCSC’s guidance, the National Protective Security Authority (NPSA) is a key source for construction firms looking to understand and protect themselves from cyber security threats.
The NPSA has developed a set of non-mandatory recommendations aimed specifically at construction joint ventures, which are common within the industry due to the scale and complexity of many projects.
The guidance emphasises the importance of including security representation at the board level, ensuring that cybersecurity considerations are integrated into decision-making processes.
Joint ventures, which involve the collaboration of multiple firms with varying levels of cybersecurity maturity, are also seen as particularly vulnerable to attacks. By adopting the NPSA’s best practices, these collaborations can better protect sensitive project information and reduce their exposure to cyber threats.
One of the key recommendation from the NPSA is the establishment of clear data governance frameworks.
This includes setting clear protocols for data sharing, defining access controls, and ensuring that all partners adhere to the same standards of data security. By implementing consistent security measures across all stakeholders, joint ventures can reduce the risk of data breaches and enhance the overall resilience of their projects.
The government has also taken the growing cybersecurity threat seriously. In July 2024, the government announced it will look to pass a Cyber Security and Resilience Bill in 2025, which aims to strengthen the UK’s overall cyber defences.
The proposed bill aims to update existing regulations, expand the remit of current frameworks, and enhance reporting requirements for businesses, including those within the construction sector.
For the construction industry, the implications of the Cyber Security and Resilience Bill are significant. The bill seeks to ensure that businesses handling critical infrastructure or providing essential digital services meet stringent cybersecurity standards.
Construction firms working on CNI projects – such as roads, railways, and utilities – are expected to align their practices with the new requirements.
How firms are expected to meet this target, and just how many will be successful remains to be seen.
One of the key components of the bill is an emphasis on incident reporting. Construction firms will be required to report significant cyber incidents, which will help authorities identify emerging threats and take action to mitigate risks.
This move is expected to improve industry-wide awareness of cyber threats and encourage firms to take proactive measures to protect their assets and data.
Security skills
If the sector is to be at the forefront of tackling cyber security then the workforce will need to be trained.
One initiative run by De Montfort University in the East of England is known as CyberFirst. Fast Track to the Future.
The programme provides training on key areas such as threat identification, incident response, and best practices for safeguarding digital assets. By improving the cybersecurity knowledge of construction professionals, it is hoped that the programme will build a more resilient workforce capable of identifying and mitigating cyber threats.
Addressing weak links in supply chain security is also essential. Construction projects often involve numerous suppliers, subcontractors, and third-party vendors, all of whom have varying levels of cybersecurity maturity. This fragmented supply chain creates an extensive attack surface that cybercriminals can exploit.
Ensuring that subcontractors sign up to industry-recognised cybersecurity standards such as Cyber Essentials is a good first step, including cybersecurity requirements in contracts with third-party vendors is another.
Furthermore, firms can implement continuous monitoring and regular audits of their suppliers’ cybersecurity practices to ensure ongoing compliance.
The cyber security threat for UK firms is real, and growing. Construction firms are better to be switched on to the problem, than finding themselves locked out.
Read next: New CEO for Ferrovial’s digital infrastructure division
Are you a building professional? Sign up for a FREE MEMBERSHIP to upload news stories, post job vacancies, and connect with colleagues on our secure social feed.


