Skip to content

Industry

Construction and contractors

The office runs like any other business. Everything beyond it does not: temporary connectivity, devices that get dropped and lost, subcontractors needing project access, and a payment process that attracts more fraud than any other sector we work in.

Largest financial exposure

Payment detail fraud

not ransomware

Large payments, real deadlines, and requests that look completely ordinary. Verification by voice is the control.

Six things that differ from an office business

Construction technology environment and its distinct demands
AreaCharacteristics
Jobsite connectivityNo fibre, changing locations, weather exposedTemporary, often cellular
Mobile devicesLost, dropped and stolen far more often than office hardwareTablets and phones in the field
Project documentsVersion control failures cost real money on siteDrawings, RFIs, submittals, photos
Estimating and accountingBid deadlines are absoluteOffice based, business critical
Subcontractor accessAccess that outlives the project is the norm, not the exceptionExternal parties needing project data
Payment detail changesThe single largest fraud exposure in the sectorEmail based, high value

Five controls against payment fraud

None of these are technical. All of them are more effective than anything in the security stack at preventing this specific loss.

  • Any change to bank details is verified by voice on a number already on file, never a number in the email
  • The verification call is made to the known contact, not returned to whoever called you
  • A second approver on any payment over a set threshold, with no exceptions for urgency
  • External sender marking enabled so a spoofed internal address is visible
  • Staff trained specifically on this scenario rather than on phishing generally

Why construction is targeted

Three things make the sector attractive, and they are all structural rather than fixable.

Payments are large and irregular, so a six figure transfer to a new account does not look unusual. Timelines create genuine urgency, which is exactly the pressure a fraudulent request exploits. And projects involve many parties exchanging invoices by email, so a single compromised mailbox anywhere in the chain provides authentic context, real names and a plausible thread to reply into.

The attacker does not need to break anything. They need one mailbox and patience, which is why the defence has to be a process rule rather than a product.

Common questions

Answered before you ask.

What is the best way to get connectivity on a jobsite?

Cellular in most cases, with a proper router and external antenna rather than a phone hotspot, because the difference in reliability is substantial and the cost difference is not. Where a site runs long enough to justify it, a temporary business circuit is worth pricing. The thing worth planning for rather than improvising is what happens when coverage is poor, since that determines whether the site office can function at all.

How do we control devices that keep getting lost?

Mobile device management, which enforces encryption and a passcode, and allows a remote wipe. In construction this is not a theoretical control, it is a monthly one. A tablet left on a site is a tablet containing project documents, email and often access to your accounting system. Enrolment takes minutes per device and it is usually already included in the Microsoft licences a contractor holds.

Subcontractors need our project files. How should that work?

Through the project platform with access scoped to their project and expiring at completion, rather than through shared folders or shared accounts. The problem to design against is not malice, it is accumulation: access granted for a project three years ago that nobody revoked, belonging to a firm you no longer work with. A quarterly external access review takes an hour and is worth it.

We received an email changing a supplier's bank details. Now what?

Verify by voice on a number you already hold before doing anything else, and do not use any contact detail from the email itself. This scenario is the most expensive fraud in the sector because construction payments are large, deadlines create urgency, and the request looks entirely ordinary. No technical control reliably stops a convincing message from a genuinely compromised supplier mailbox. A verification rule applied without exception does.

Start with the payment verification process.

It costs nothing to implement and prevents the most expensive thing that happens to contractors. The assessment covers it alongside the technical review.

CallFree assessment