Cyber exposure in construction: when the ground keeps shifting

Bricks, mortar and malware: why cyber risk is now a real problem for UK construction firms

In 2025, engineering contractor Morrisroe confirmed it had been hit by a cyberattack. A year before that, the Construction Industry Council was hit too. Neither made front-page news, but they fit a pattern that goes back further: Bouygues UK, Bam and Interserve were all targeted by hackers within the same four months back in 2020. Construction firms have been a target for a while. What's changed is how often, and how fast, these attacks are now happening.

That change shows up clearly in the numbers. In the first three months of 2026, the UK was the most-attacked country in Europe for ransomware (attacks where criminals lock your systems and demand payment to unlock them). Across Europe, construction and manufacturing overtook financial services as the two most-targeted industries. Many people still think of construction as a hands-on, site-based business rather than a target for hackers. That's no longer true. Cyber risk is now a boardroom issue, not just something for the IT team to worry about.

A sector squarely in the crosshairs

The UK numbers make the scale of the problem clear. The National Cyber Security Centre recorded 204 major, nationally significant cyberattacks in the year to September 2025. That's more than double the 89 recorded the year before, or around four serious attacks a week across the UK economy. Separately, City of London Police's fraud reporting service recorded 323 UK businesses hit by ransomware between April 2025 and March 2026.

Construction is being hit especially hard. In September 2025 alone, there was a sharp rise in ransomware activity, with 562 attacks made public. Construction and engineering were the single most affected industry, making up more than one in ten of all victims.

When the site goes dark: project interruption

A construction site can't just pause for a week. UK-specific data shows just how exposed the sector really is: construction is now the most frequently attacked industry in the country by number of incidents recorded, and a single ransomware attack disrupts a UK construction business for an average of 24 days. Most firms can't absorb anywhere near that length of disruption. Losing access to project files, drawings or subcontractor communications for even a few days can cause real problems on site, and the longer the outage runs, the more it costs in slipped programme dates, idle subcontractors and damaged client relationships.

This is exactly the risk that business interruption insurance should be built to cover, in a way that reflects how construction firms operate and get paid. The insurance market has responded with construction-specific policy extensions that go beyond a standard, office-based business interruption structure, including cover for the cost of restoring a project disrupted by a cyber event, and, in some policies, cover for lost income if a firm is unable to submit a tender because of an incident. Firms that put the right cover in place can better protect themselves against the knock-on effects of a serious outage, such as penalty payments for missing deadlines and subcontractors walking off the job. Cyber security should be viewed as a project risk, in the same way as safety or supply chain issues, and planned for in the same way.

The subcontractor chain: third-party exposure

Construction relies on a long chain of contractors, subcontractors, architects, engineers and suppliers, all sending each other invoices, drawings and bank details, often working quickly under pressure. That chain has become a favourite target for criminals. One common trick is called business email compromise: a subcontractor's email account is hacked, and the attacker uses it to ask for a change of bank details or an urgent payment. Single losses of £150,000 or more from incidents like this are now common on major UK construction sites.

The risk doesn't stop at your own company's front door. If a subcontractor is hacked, or a shared online drive or scheduling tool goes down, it can bring your project to a halt just as badly as if your own systems were attacked. That's why cover exists for this kind of "knock-on" risk too – contingent business interruption cover protects you against losses caused by someone else in your supply chain being attacked, not just an attack on your own systems.

Sensitive by nature: people, plans and data

Construction firms hold a lot of valuable information: staff personal details and payroll data, client contracts, tender documents, and increasingly detailed digital building plans and CAD drawings. These plans have real value to competitors bidding for similar work. Both the Construction Industry Council's 2024 incident and Morrisroe's 2025 attack show that even large, well-known firms aren't safe from this.

An incident like this brings a familiar set of costs: telling everyone affected that their data has been exposed, potential fines or regulatory scrutiny (which matters more now given the data rules introduced under the Building Safety Act), damage to client relationships, and, if design plans are stolen, a real loss of competitive edge on future bids. A well-built cyber insurance policy is designed to cover exactly this: the cost of dealing with data being exposed, telling people about it, and any claims that follow from personal or commercial information getting out.

Why this matters now

Construction is going through one of its biggest technology shifts yet. Connected machinery, tracking devices, drone surveys and cloud-based building plans are changing how projects get delivered, but each of these is also a new way in for attackers, which the incident numbers above help explain.

At the same time, there's growing commercial pressure to prove your cyber defences are up to scratch. Cyber Essentials, a government-backed cyber security certification, is now effectively required to bid for UK public-sector work and major framework contracts. That's a clear sign that clients and regulators now see this as a real business issue, not just a technical detail.

A cyber-attack on a construction firm rarely makes dramatic headlines, but the costs and disruption are just as real as any other major risk. The firms that plan for this now, rather than waiting for it to happen, will be the ones still on schedule when it counts.
 

If you’d like to discuss how cyber exposure in construction could impact your business or explore insurance solutions to safeguard against these risks, please reach out to Daniel Lewsley.


References

Morrisroe cyberattack; Construction Industry Council incident (Oct 2024); Bouygues UK/Bam/Interserve (2020); construction's lowest cyber-preparedness confidence (74%) among nine sectors surveyed — Construction News: https://www.constructionnews.co.uk/sections/data/construction-least-prepared-industry-for-cyber-threats-poll-finds-06-05-2026/

UK as most-attacked European country for ransomware, Q1 2026; manufacturing/construction overtaking financial services — Cyble: https://cyble.com/press/uk-leads-europe-ransomware-attacks-cyble-q1-2026-report/

 NCSC nationally significant attacks (204 vs 89); construction as most frequently attacked UK sector by incident volume; 24-day average operational downtime per ransomware incident — Insurance Business UK: https://www.insurancebusinessmag.com/uk/news/cyber/cyber-threats-putting-uk-construction-projects-at-risk-insurer-warns-574224.aspx

September 2025 ransomware resurgence (562 attacks; construction/engineering as most-affected sector, 11.4% of victims); Beazley Spotlight on Cyber Threats & Tech Advances 2026 survey data — Planning, Building & Construction Today: https://www.pbctoday.co.uk/news/digital-construction-news/cyber-risk-in-construction-why-confidence-may-be-sectors-biggest-vulnerability/162777/

City of London Police / Report Fraud ransomware statistics (323 victims, £270k average loss) — Infosecurity Magazine: https://www.infosecurity-magazine.com/news/over-300-uk-firms-hit-ransomware/
(primary source: https://www.cityoflondon.police.uk/news/city-of-london/news/2026/june/dont-pay-the-ransom-warning-to-organisations-to-protect-themselves-from-ransomware-attacks-as-more-than-320-businesses-affected-last-year)

UK business email compromise losses on construction sites (single losses of £150k+ common on major sites) — Connection Technologies: https://connection-technologies.co.uk/blog/cyber-security-for-construction-uk-2026

UK construction risk profile — BEC, sensitive data, Building Safety Act, broad attack surface — SentinelOne: https://www.sentinelone.com/blog/building-up-to-code-cybersecurity-risks-to-the-uk-construction-sector/

Cyber Essentials as a bidding condition for public-sector/Tier-1 frameworks (PPN 014, Feb 2025) — First Stop IT:
https://www.firststopit.co.uk/it-support-for-construction/cyber-security-for-construction-companies/

Daniel Lewsley

Divisional Director
Photo of Daniel Lewsley