Construction treats cyber as an IT problem, and that's the risk, QBE underwriter says

QBE Canada's Kyle Gray says cyber incidents cost construction firms an average of 24 days of downtime, and the fix starts with ending the IT-operations silo

Construction treats cyber as an IT problem, and that's the risk, QBE underwriter says

Construction & Engineering

By Branislav Urosevic

The biggest cyber weakness in construction may not be technical at all, but organizational: treating cyber as a back-office IT issue rather than a project risk, according to Kyle Gray (pictured), technical underwriter team lead, cyber at QBE Canada.

The cost of that mindset is measurable. QBE research found that each cyber incident in construction leads to an average of 24 days of downtime, with ransomware considered the most significant threat to the industry – 79% of senior digital risk experts surveyed by Control Risks identified it as the threat most likely to significantly impact construction sector organizations. IoT malware activity targeting the sector increased by 410% last year, and 81% of operational technology incidents involved inadequate separation from IT systems.

That last figure goes to the heart of the problem, in Gray's telling. Asked whether companies still handle cyber as a separate IT problem, he said it remains a common factor within construction – though he was careful not to single the industry out.

"I wouldn't say it's unique to construction companies either," Gray said. "It's very much just the nature of companies where there's an operational silo or an operational arm, and then there's more of the back office, which is where IT traditionally had sat – facilitating those operations as opposed to being a part of those operations."

That structure made sense when technology sat at the edges of the business. It no longer does, in his assessment. As digital, interconnected networks have expanded, Gray said, IT needs to become part of the operational team rather than a support function behind it. QBE's research points to the same conclusion from the systems side: connecting data-processing systems to systems that control physical equipment improves efficiency, but it also gives attackers new pathways into previously isolated environments.

"The risk profile of a cyber incident in construction has fundamentally changed," Gray said in the report. "Many breaches now interrupt workflows, lock out critical systems and, in some cases, affect the physical environment through connected operational technology. The line between cyber risk and operational risk has effectively disappeared."

The industry is moving, he said, just not quickly. Construction companies are improving in this area and in their cyber risk broadly, Gray said, but the shift is hard for any company to make quickly – and particularly hard for large construction firms. The visible progress is IT stakeholders and teams being involved in projects, as opposed to just the construction team.

Asked what firms and brokers should be doing differently, Gray pushed the question back a step. The change shouldn't start at the outset of a project, he said, but before it – as a shift in how a company approaches its IT security posture overall, not just for one job. That echoes the position QBE has taken formally, calling on construction firms, brokers and risk managers to integrate cyber into project risk planning from the outset, prioritizing governance, supply chain visibility and tested incident response plans.

The first step is using the support that already exists. Gray pointed to the broker conversation as the natural starting point: talking through exposures, coverages, and the potential for risk transfer, so a company actually understands what its risk is.

From there, the work becomes more granular. A big part of managing the exposure, whether on a specific project or across the company, is mapping digital dependencies, Gray said – establishing which systems the business runs on and who can get into them.

"It's very hard to protect your systems if you don't know what systems you're using or who has access to those systems," he said. Once those dependencies are identified, the focus should go to the ones critical to operations, and to protecting and securing those first.

The final piece loops back to the silo problem. Gray's advice is to involve IT teams as facilitators of the project from the start, rather than calling on them only when something has gone wrong.

"I think involving them in the project will hopefully make the project go smoother, not just from an IT perspective, but also from an efficiency perspective as well," Gray said.

For an industry built on physical work and tight deadlines, the digital layer now runs through all of it – and as the downtime numbers show, managing it after the fact is the expensive way to find out.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!