Construction companies should prepare for ransomware and business email compromise by putting five controls in place first: MFA, email security, endpoint protection, tested backups, and security awareness training. Together, these make it harder for attackers to get in, protect the payments that move between owners, GCs, and subs, and give you a way to recover without paying.
Why Construction Firms Are Targeted
Contractors manage payments, invoices, subcontracts, project schedules, and sensitive business information. Frequent payment requests between many parties make construction a natural target for fraud.
Common Threats
- Ransomware: Encrypts files and systems, which can stop estimating, billing, and project documentation.
- Business email compromise: Attackers take over or impersonate an email account to redirect payments or steal information.
- Credential theft: Stolen passwords give attackers a quiet way into email and project platforms.
- Invoice fraud: Fake or altered invoices and pay applications trick accounts payable into paying the wrong account.
- Phishing: The most common starting point for all of the above.
The Protection Framework
- Prevent: Block common entry points with MFA, email filtering, and patching.
- Detect: Monitor devices and accounts for unusual activity.
- Contain: Isolate affected accounts and devices quickly, starting with securing field devices and trailers.
- Recover: Restore from backups that have been tested.
- Document: Record what happened and what changed, which also supports insurance claims.
Controls to Prioritize
- MFA
- Email security
- Endpoint protection
- Backup testing
- Security awareness training
These controls map closely to the cyber insurance requirements for contractors carriers now review. Keep them current with regular cybersecurity risk and backup reviews.
Build Your Response Plan
Decide ahead of time who makes decisions during an incident, how you will communicate if email is down, and how payment changes get verified. These steps belong in your construction incident response planning.
Frequently Asked Questions
What is business email compromise?
Business email compromise is when an attacker takes over or impersonates a company email account to redirect payments, request sensitive data, or trick employees into acting.
How can contractors stop payment fraud?
Verify any change to vendor or subcontractor payment details by calling a known phone number, require approval for new payment instructions, and train accounts payable to spot pressure tactics.
Should a construction company pay a ransomware demand?
That decision should involve leadership, legal counsel, and your insurer. Tested backups and an incident response plan give you options besides paying.
How often should employees get security awareness training?
Train at least annually, with shorter refreshers and phishing simulations throughout the year, including for field staff.
Assess Your Ransomware and Email Security Risk
Find out how prepared your team is to prevent, contain, and recover from ransomware and payment fraud.