The construction industry is more digital and interconnected than ever before. Cloud platforms, Internet of things (IoT) devices, building information modelling (BIM), and mobile collaboration speed up planning, execution, and construction logistics. At the same time, new dependencies on digital supply chains, external service providers, and shared platforms are being created. Cybersecurity thus becomes a management responsibility: Construction companies must not only protect individual IT systems but also ensure the resilience of their entire core business.
We’ll show where the risks lie, why BIM, IoT, and cloud are crucial for cybersecurity, and which security measures are effective at the technical, organizational, and strategic levels.
The construction industry is an attractive target for cyberattacks, as an incident rarely affects just a single system. Multiple partners, digital interfaces, and enormous time pressure increase the attack surface. As a result, security measures are sometimes neglected in day-to-day project work, and warning signs are recognized too late.
The attackers' goals vary. The main focus is on extortion through data encryption, as well as the theft of technical documentation, processes used, or sensitive information about suppliers and investors.
The consequences can be severe. Due to the close interconnectedness of the companies involved and the economically synchronized nature of their operations, disruptions spread rapidly and cause major financial damage. In some cases, such an incident jeopardizes the financial stability of entire companies.
The interconnected ecosystem on which modern construction projects are based enables efficient collaboration. However, as mentioned, it increases dependence on digital interfaces and external partners.
Therefore, the following aspects are particularly important to consider when it comes to supply chains:
The operational risk arises outside the company
Cyberattacks are increasingly targeting service providers, software vendors, and other partners within the value chain. For construction companies, it usually doesn't matter where the incident occurred. What matters is whether project data, communication channels, or business-critical systems remain available.
Risks are spread along the project chain
BIM platforms, cloud services, and project environments help connect numerous companies. If a central platform becomes unavailable, planning, documentation, coordination processes, etc. may all be affected at the same time.
Technical failures can have the same consequences as cyberattacks
Like attacks, technical disruptions at cloud providers or software service providers can have a massive impact on business operations. This can result in limited access to project data, communication failures, and the shutdown of digital processes.
The main challenge, therefore, is not limited to protecting one's own IT systems. Construction companies must also manage the resilience of their digital supply chain. Decisions regarding suppliers, cloud strategies, emergency planning, and operational risks are thus a management responsibility.
Phishing and social engineering
Attackers use fake e-mails, invoices, or project documents to steal login credentials or redirect payments. Mobile teams, external partners, and time-sensitive projects make the construction industry particularly vulnerable to such attacks.
Third parties and supply chains
Because the parties involved work so closely together, security vulnerabilities at one partner can affect the others. This can lead to project delays, data leakage, and service interruptions.
Cloud and platforms
BIM, ERP, and collaboration platforms are increasingly being operated in the cloud. If misconfigurations, compromised user accounts, or outages at external providers occur, this impacts access to business-critical information. Among other things, this may result in limited availability of project data or delays in planning and execution.
AI-assisted attacks
Generative AI makes it possible to create convincing phishing messages, forge documents, or manipulate audio and video content. AI reduces the effort required by attackers while making it more difficult to detect fraudulent attempts. This increases the risk of CEO fraud and social engineering attacks.
If a company wants to ensure cybersecurity, it must secure its entire digital value chain: from employees and project partners to BIM, cloud, and IoT platforms.
AI changes the way companies plan, communicate, and make decisions. This presents a twofold challenge for construction companies: While AI makes processes more efficient, it also helps attackers exploit vulnerabilities.
In addition to the phishing attacks and manipulated audio and video content mentioned above, AI contributes to risks through:
Uncontrolled use of AI tools
If employees use public AI services to create texts, analyses, or project documents and, in doing so, disclose confidential data, this leads to additional data protection and security risks.
Faster cyberattacks
AI helps attackers automate research, preparation, and social engineering, enabling them to carry out attacks more quickly, with greater precision, and at a lower cost.
BIM, IoT, and the cloud are now part of construction companies' DNA. It is precisely their function as core elements that makes them vulnerable.
BIM has established itself as a central information platform. In Switzerland, information management processes are increasingly based on the SN EN ISO 19650 series of standards, the adoption of which is promoted by organizations such as KBOB.
BIM consolidates sensitive information in a central location. An attack can therefore compromise the information foundation of an entire project. The main areas of concern are the large number of user groups, the dependency on cloud services, and the multiple interfaces along the digital supply chain.
Experience shows that attacks typically exploit known vulnerabilities in processes and identities, such as compromised user accounts, phishing, social engineering, or ransomware.
The IoT includes networked sensors, machines, vehicles, and systems that collect, exchange, and automatically process data. In the construction industry it supports, e.g., machine monitoring, access control, energy optimization, and predictive maintenance.
As a key component of digital transformation, the IoT directly connects the digital world with physical processes on the construction site. Security incidents can therefore affect the availability of equipment and machinery, as well as operational processes. Particularly critical factors include the large number of connected devices, weak login credentials, delayed security updates, and poorly protected data transmissions.
As with BIM, attacks on the IoT typically exploit known vulnerabilities. Gateways for such attacks are, e.g., unpatched devices, compromised remote maintenance access, or default passwords.
Cloud platforms manage BIM data, project documents, ERP systems, and collaboration and communication solutions, enabling real-time collaboration across multiple locations.
As BIM, cloud platforms consolidate business-critical information. Security incidents therefore disrupt entire project and business processes. Other risk factors include dependence on external service providers, the large number of external platform users, and complex access control structures.
In cloud environments, attackers primarily target identities and access rights, e.g., login credentials are stolen or interfaces are exploited.
Construction companies respond best to the risks of digital transformation by implementing measures on multiple levels. The focus is on technical, organizational, and strategic approaches that protect systems and ensure business continuity.
Technical measures are most effective when their benefits become apparent in day-to-day project work. In the construction industry, this means controlling access, keeping systems separate, protecting data, and more.
Recommended measures:
Firewalls and antivirus software
They form the basis and are reinforced by clear access rules, ongoing monitoring, and other protective measures. The goal is a seamless chain of protection that serves as the first line of defense against attackers, especially in project environments with many end devices.
Network segmentation
Network segmentation ensures that not all systems are directly connected to one another. If one fails, the damage is limited. This is especially crucial in construction projects involving many partners.
Multi-factor authentication (MFA) for cloud or other shared platforms
MFA protects access even if a password falls into the wrong hands. This is essential for cloud-based platforms and collaborative project systems, since people typically work together remotely in these environments.
Encryption of data at rest and in transit
Data should always be encrypted, both at rest and in transit. This ensures that construction plans, contracts, and technical documents remain protected even if devices are lost or data is intercepted.
Software updates and security patches
Regular updates and prompt patches provide protection against attacks exploiting known vulnerabilities, which is especially vital for distributed projects.
In addition, it is advisable to keep systems up to date or replace them as needed, authenticate e-mails to make it more difficult for attackers to send fraudulent messages, and monitor network traffic to detect unusual behavior early on.
Organizational measures ensure that responsibilities are clearly defined, processes run smoothly, and there is no need to improvise in an emergency. These measures, along with technical solutions, are key to ensuring security.
Recommended measures:
Awareness trainings for employees
Employees are often the first target of an attack. That is why awareness training should be routine: regular sessions with real-world examples that clearly illustrate the risks of manipulated attachments, for example.
Ongoing risk assessments and audits
Risks change as new partners, systems, and attack patterns emerge. That is why recurring risk assessments are needed – ones that not only examine internal processes but also take into account service providers, platform providers, and subcontractors.
Emergency and recovery plan for cyber incidents
A cyber incident becomes particularly costly when a company has to improvise. An emergency and recovery plan defines which systems are business-critical, who makes decisions, how communication is handled, and which processes must be restored first.
Clear contractual requirements for partner companies
Many risks arise at the interfaces with partners. That is why contracts should include clear information security requirements, covering topics such as reporting obligations, patch management, access control, and incident response.
A joint approach to incident response
The response to an incident must be coordinated among all parties involved so that reports, escalations, and immediate actions take effect right away. Clear communication processes and designated points of contact are particularly important.
Strategic measures address issues where cybersecurity becomes a management responsibility. What matters is how resilient the company is overall, how dependent it remains on individual partners, and how consistently management oversees cybersecurity.
Recommended measures:
Diversification of supply chains
Companies should rely on multiple partners, alternative processes, or workarounds for key services. After all, if one partner becomes unavailable, the entire project could come to a standstill.
Make cybersecurity a priority
Cybersecurity must be treated as a business-critical issue. This requires resources, expertise, and clear responsibilities, e.g., regarding personnel, external support, technical development, and the ongoing improvement of the security architecture.
Make cybersecurity a management responsibility
When cybersecurity is embedded at the executive level, risks are identified earlier, measures are approved more quickly, and responsibilities are more clearly defined. This enables a holistic approach that goes beyond individual projects.
Digitalization has made the construction industry more efficient and more interconnected. The flip side of the coin: Cyberattacks have become a direct risk factor for project schedules, costs, and reputation. In addition to large-scale attacks, everyday threats such as phishing and unclear responsibilities are particularly dangerous.
Clear technical, organizational, and strategic measures can significantly mitigate the cyber threat. The key is the ability to identify, prioritize, and effectively manage risks across the entire digital supply chain. In short: a holistic approach to strengthening resilience.
Companies that identify their digital risks early on and take targeted measures to minimize them increase their security, build trust with clients and partners, and ensure their long-term competitiveness.