Construction does not feel like a cyber target. There is no shopfront full of card numbers and no database of medical records, so it is easy to assume the risk sits with other industries.
That assumption is exactly why building firms get caught. The sector moves large sums of money, runs on phones and tablets spread across sites, and works with a constantly changing cast of subcontractors and suppliers. For an attacker chasing a payment, that is close to ideal. If you have read our overview of IT for construction firms, this is the practical companion: the seven gaps we find most often on a Sydney building business, and how to close each one.
Gap 1: Progress-Claim and Invoice Fraud
The single biggest cyber risk in construction is not data theft. It is payment fraud. The trade runs on progress claims, supplier invoices, and large transfers between builders, subcontractors, and clients, and an attacker who gets into one mailbox can watch that conversation and strike at the right moment.
The classic move is an email that looks like it came from a real supplier, asking to update their bank details just before the next payment. Because it comes from a genuine account or a close lookalike, it passes the usual checks, and the money is often gone before anyone notices. This pattern, business email compromise, does the most damage in this sector by a wide margin. The defence is a second verification step on every mailbox plus a firm rule: any change to payment details is confirmed by a phone call to a known number, never by replying to the email.

Gap 2: Unmanaged Mobile and Site Devices
Construction is a mobile business. Project managers work from utes and site sheds, foremen use phones and tablets, and plans and photos move all day. That spread is productive, and it widens the attack surface in ways the office never sees.
Devices get lost or stolen on busy sites, and a personal phone with a work mailbox often sits outside whatever security the office has. The fix is that the basics travel with the device: a screen lock and encryption so a lost device is not a breach, the ability to remotely wipe a phone that goes missing, and accounts protected so one stolen password does not open the door.
Gap 3: Subcontractor Access Sprawl
Construction works through relationships that change constantly. New subbies onboard, projects wrap up, and crews move on. Each change quietly adds another login to a shared drive, a project folder, or a planning tool, and very few of them ever get removed.
Months later, a forgotten subcontractor account is a quiet way in, and nobody is watching it. The fix is unglamorous but effective: access granted by role and by project, reviewed regularly, and removed promptly when a subbie finishes or a job closes out. Access should expire with the relationship, not outlive it by a year.
Gap 4: Project Plans and IP Left Unprotected
Tender documents, designs, drawings, and pricing are the commercial heart of a building firm. They move between estimators, project managers, and consultants through email and shared drives, and they are worth real money to a competitor or an attacker.
The common gap is that everyone can see everything. The fix is permission-based access so sensitive tender and design files are restricted to the people working on them, not the whole company, and so that when a project ends, the access ends with it. Knowing where your most valuable documents live is the first step to protecting them.
Gap 5: Multi-Factor Authentication Missing
Almost every firm has a password on its email and systems. Very few have the second lock. Multi-factor authentication means a login needs your password plus a prompt on your phone, so a leaked or guessed password is not enough to get in on its own.
This single control blocks most account takeovers, and given that payment fraud usually starts with one compromised mailbox, it is the highest-value fix on this list. We most often find it switched on for office email but missing from remote access and from the mailboxes of site-based staff. The fix is to enforce that second step on every account that holds company data or touches money, with no exceptions.
Gap 6: Downtime With No Tested Backup
When systems go down in construction, the cost is not abstract. Crews stand idle, deliveries stall, and deadlines with penalty clauses keep moving toward you regardless. That makes recovery speed a genuine commercial issue, not just an IT one.
Backups are “running” and the dashboard is green, but a backup nobody has restored from is a guess. The fix is to test restores on a schedule and keep at least one copy an attacker cannot reach, so that if ransomware or a failure hits, you recover in hours rather than rebuilding for weeks. Keeping systems patched closes the flaws that ransomware uses to get in the first place.
Gap 7: Shared and Insecure Site Wi-Fi
Site offices and sheds often run on whatever connection is available, shared by everyone on the job and rarely set up with security in mind. Staff log in to email and project systems from public networks and open site Wi-Fi without a second thought.
An insecure network is a place where credentials can be intercepted and devices exposed. You do not need enterprise networking on every site. You need work accounts protected so a stolen password is not enough on its own, and staff who know not to log in to anything sensitive over a network they would not trust at home.
Closing the Gaps
None of these are exotic, and none require pulling your firm apart. They are the everyday shortfalls that turn a preventable incident into a real one, and every one maps to the basics in Essential Eight, the baseline set of controls published by the Australian Cyber Security Centre. Close them in priority order and you significantly reduce your risk without getting in the way of the work.
The hard part is knowing which apply to you, because most stay invisible until someone looks. That is the value of an honest assessment.
Where to Start
If you recognised your firm in more than one of these, you are normal, and you are in a good position, because every gap on this list has a clear fix.
Start by getting a clear picture of where you stand. Our IT maturity assessment takes a few minutes and shows you which controls need attention first.
We are a Sydney-based team in Bella Vista, and we work with construction and trades businesses across the metro area. We understand the way this trade actually runs, on site and on the move, and we secure it without slowing down the job, with managed IT that treats security as ongoing rather than a one-off.