Construction wasn't built for cyber risk, but criminals have found the cracks, QBE expert says

Kyle Gray of QBE Canada says ransomware attacks now target construction's tight timelines and sprawling networks of subcontractors, not just its data, and criminals know exactly how much a delay is worth

Construction wasn't built for cyber risk, but criminals have found the cracks, QBE expert says

Construction & Engineering

By Branislav Urosevic

Construction was never thought of as a prime target for cyber attacks, but that has changed as ransomware has shifted from stealing data to stopping work, according to Kyle Gray (pictured), technical underwriter team lead, cyber at QBE Canada.

The industry's exposure traces back to a broader evolution in cyber risk itself, Gray said. "In the origination of cyber, it was much about privacy insurance, and it's really shifted into being much more of an operational disruption," he said. Construction projects and construction entities, he added, carry "the potential for massive operational disruption."

Three characteristics make the industry especially exposed, in his telling. The first is time. Construction projects run on tight timelines and need to be finished by a set date, Gray said, so any delay can be substantial and impactful. The second is the industry's growing dependence on technology: operations that were once heavily manual now rely on digital platforms and computer technology for communication and other applications. The third is structural – a broad and fragmented attack surface.

"There are so many subcontractors, suppliers, individuals and entities involved in the process," Gray said. "There are so many users, there are so many companies, there are so many platforms that are accessed in a construction project. So that really makes the potential entry points expand substantially."

Asked what an attack typically looks like in practice, Gray said most are rooted in lost or weak credentials somewhere across that supply chain. One person clicking a phishing link, or reusing a password, gives attackers initial access, he said – which they then use to move toward more privileged credentials with access to IT platforms, where they can do more damage.

The single biggest vulnerability enabling that entry, in his assessment, is remote access – a weakness not unique to construction, but one the industry's structure amplifies. The many companies and people who need access to a project's platforms are not sitting in one office behind one protected network, Gray said. They are geographically distributed across companies and regions, and that remote access allows cyber criminals to use stolen credentials to enter a network from anywhere, including a foreign country.

The reliance on shared platforms has widened those vulnerabilities further, he said. Where a critical document might once have been printed and stored in a filing cabinet 30 years ago, it now has to be accessed digitally.

"Every new connection across the contractor and supplier network can become an entry point for a cyber criminal," Gray said. As project complexity grows and more people get involved, he added, the attack surface expands with it.

For a construction company, the disruption starts with the basics. Losing access to email and communication tools alone raises the question of how a firm coordinates its subcontractors, Gray said. From there, attacks can progress to the shared digital platforms construction now runs on, including document repositories that can be held for ransom.

"If you need to access some critical blueprints or something specific to move forward with the physical construction, you need to access that digital document on the platform," Gray said. "If you're unable to access that digital document, it can create a lot of disruption in the manual process."

The current surge in attacks, he said, comes down to a mutual recognition of what continuous operation is worth. Cyber criminals have realized that a construction company facing lost income for every day of delay is more likely to address a ransomware demand quickly, and potentially pay.

"That recognition of the value of their systems and the value of their continuous operations has led cyber criminals to recognize the value in attacking those companies, and that's really given a rise to the attacks," Gray said. "It's really as simple as, I think, that the criminals are chasing where they can access the funds."

Asked whether the built-in urgency of a construction project works in the attackers' favour, Gray agreed. Criminals thrive on urgency and actively exploit it in their attacks, he said.

The takeaway, in his framing, is that the industry's old self-image no longer matches its risk profile. Construction may not have traditionally thought of cyber insurance, or been a target of cyber criminals, Gray said – but that has evolved with the shift toward operational disruption, and the industry has recognized it is not immune to the digital impact of an attack.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!