In UK construction, the biggest losses often start with a supplier, subcontractor or shared platform rather than a direct attack on your own office. One wrong bank detail, a compromised inbox or a BIM login can lead to a payment scam, data breach or costly delay before anyone agrees who is responsible.
Cyber insurance for UK construction firms using subcontractors: liability gaps are common when fraud, data breaches or disruption involve multiple parties. The real question is whether your policy, public liability, professional indemnity and contracts all match up, including exclusions, sub-limits, indemnities and supplier security requirements.
Is the gap yours or the subcontractor’s?
For a main contractor, the gap is usually between what happened and who is legally on the hook. If a subcontractor’s mailbox is used to change bank details, the loss may sit with the contractor, the subcontractor, or neither fully, depending on control, contract wording, and the policy trigger.
The first question is not whether there was a cyber event. It is who controlled the account, who handled the data, and who agreed to carry the risk. That matters because a construction firm in England may face vicarious liability for some acts of a subcontractor, but not for every digital mishap.
Golden answer: who pays first?
The first payer is usually the party named in the contract, then the insurer that matches that type of loss. If the contract says you must indemnify the client for supplier error, your insurer may still ask whether that is a pure loss or a contractual liability.
That is why insurers look closely at indemnities, sub-limits, and notification duties. A policy with £100,000 of data breach cover can still leave you short if the real cost is £180,000 after forensics, legal help, client notices, and project delay.
Vicarious liability is when one party may be held responsible for another party’s acts. In construction, it can matter when a subcontractor acts under your control, but it does not replace contract wording or insurance wording.
The consensus view from the National Security Centre is that supply chain controls are part of basic hygiene, not an optional extra. That fits construction well, because one weak login can open shared files, payment data, and project records in one go.
Contract terms that override assumptions
A subcontract can say one thing while the cyber policy says another. If the contract makes you responsible for a supplier’s security failure, but the policy excludes liability you assumed by contract, the gap can be real and expensive.
The Insurance Act 2015 also matters because material facts must be disclosed fairly. If you use dozens of subcontractors, shared credentials, or remote payment approvals, an insurer may want to know that before it prices the risk.
In practice, the liability split in a UK construction chain depends on who had control, who approved the payment, and what the subcontract says about data handling and fraud. If a subcontractor’s account is compromised and the main contractor’s finance team authorises the transfer, the loss may not sit neatly with one party. A client may pursue the main contractor under the headline contract, while the main contractor seeks recovery from the subcontractor under indemnity wording.
That is why firms should map liability for supplier breach, payment fraud and delay before works start, then test whether the policy, crime cover and contractual liability wording line up with the actual flow of money and information.
Which policies respond to one cyber incident?
One incident can touch several policies, but each responds to a different kind of loss. Cyber insurance usually handles response costs, data breach work, and sometimes business interruption, while public liability and professional indemnity often answer different questions about injury, property damage, or professional advice.
That split matters in construction because many losses are mixed. A hacked BIM file can create project delay, a bad design decision, and a data breach at the same time. If you assume one policy will catch all three, you can end up paying the excess twice and still face an uncovered claim.
Cyber vs public liability cover
Cyber insurance is about digital events. Public liability insurance is about injury or property damage to other people. If a subcontractor’s compromised account leads to a site error but no physical damage, public liability may not help at all.
A common edge case is this: a fraudulent payment instruction causes financial loss, but no fire, no collapse, and no injury. That looks like cyber or crime cover, not public liability. The error most firms make is expecting the broadest policy to act like a universal backstop.
Professional indemnity insurance, or PI, covers claims about bad advice or poor professional service. If a BIM modeller uses wrong data and the project suffers design rework, PI may matter more than cyber cover.
But PI can also exclude pure cyber events or losses arising from a subcontractor’s computer misuse unless the wording is wide enough. The Financial Conduct Authority has long pushed clear product wording across financial lines, and that same clarity is what buyers need from insurance brokers in construction.
Contract liabilities and exclusions
Contractual liability is the risk you take on by promise, not by law alone. If your contract says you will carry all supplier losses, your insurer may treat that as an assumed liability and narrow the response.
That is where exclusions bite. Many cyber policies exclude bodily injury, property damage, fines in some cases, and losses caused by failure to maintain minimum security. Others cap social engineering or funds transfer fraud at £25,000 to £100,000, which is low if payroll or supplier runs are monthly.
The sub-limit trap on fraud
The sub-limit trap is simple: the headline limit looks large, but the bit you need is small. A £1m cyber policy with a £25,000 fraud sub-limit may still leave most of a fake invoice loss uninsured.
This is where construction bites hardest. Payment runs, retention releases, and supplier changes happen under pressure, often at month end. If the policy only covers a narrow type of social engineering and only after a strict verification step, the real cover can be far less than expected.
Construction claims often sit across several policies at once, so the real issue is how they interact rather than whether one policy exists. Public liability usually responds to injury or property damage, professional indemnity to design or advisory failures, and cyber insurance to response costs, forensic work, data breach cover and some business interruption. For example, a hacked shared platform could cause delayed steel deliveries, corrupted BIM files and a customer data breach in the same week. In that case, PI may be relevant to the design impact, cyber cover to incident response, and public liability only if there is physical damage or injury.
The buyer needs to check whether contractual liability is carved back, whether there is overlap or double excess, and whether silent cyber exclusions shift the loss elsewhere.
Where subcontractor fraud breaks cover
The most common losses are payment redirection, fake invoice changes, stolen email access, and impersonation of a known supplier. These are not rare edge cases. In mixed contractor-supplier chains, they are often the first cyber claim anyone sees.
The Association of British Insurers has repeatedly treated fraud and third-party loss as a wording issue, not a one-size-fits-all cover. That matters because the same facts can fall under cyber crime, computer misuse, or simple invoice fraud, and the label changes the response.
Payment redirection in practice
A payment redirection scam is when someone changes bank details so money goes to the wrong account. It can happen after one spoofed email, one copied thread, or one fake domain name that differs by a single letter.
A typical case runs like this: the subcontractor asks for a bank change, the finance team trusts the email, and £38,000 disappears within minutes. Recovery can take days, but the insurer may still deny part of the claim if verification rules were not followed.
Access credentials and impersonation
Stolen credentials can be worse than a single fake invoice because they unlock shared tools. If a subcontractor’s login gets reused across project systems, the attacker may reach drawings, timesheets, or payment approvals.
The Computer Misuse Act 1990 matters here because unauthorised access is not a soft issue. It is a legal one. Insurance may cover the clean-up, but it will not stop the breach, and it may not cover deliberate misuse by someone inside the chain.

Shared BIM, cloud folders, and remote access create one project-wide doorway. If one subcontractor account is weak, the whole job can be exposed. That is why supply chain risk in construction is not just about money, but about access.
The National Cyber Security Centre’s small business guidance makes the same point in plain terms: control access, use strong authentication, and limit what each user can see. In construction, that means treating every subcontractor account like a site key, not a shared spare key under a flowerpot.
BIM access is not neutral
BIM access is powerful because one model can hold design data, naming rules, and project history. If a subcontractor can edit or export too much, a cyber event can turn into a design and delay issue fast.
The practical control is simple. Give the subcontractor the least access needed, time-limit it, and remove it when the package ends. Many claims start because old accounts were never closed.
Remote logins and device controls
Remote logins are useful, but they widen the door. If a subcontractor uses a personal laptop, old antivirus, or no screen lock, your project inherits that weak point.
The Information Commissioner’s Office expects proportionate security under UK GDPR and the Data Protection Act 2018. For construction firms, that usually means MFA, device rules, and clear incident reporting times, not a vague promise to “be careful”.
Shared templates and cloud folders
Shared folders are where mistakes spread. One wrong upload can expose invoices, passports, site records, or employee data across the whole team.
This is where business interruption can also appear. If the cloud folder is locked for 48 hours, work may slow even if no data was stolen. That is why cyber wording should be checked for system outage, not only for theft of information.
What contracts must say before work starts
Contract wording is the front line, because it decides who must do what after a breach. If you wait until after the incident, the position is already weak. Cyber insurance can help, but it cannot rewrite a bad subcontract.
As Peter White, with over 12 years of experience helping UK small and medium-sized businesses navigate the world of cyber insurance, I first look at three things: the indemnity, the security schedule, and the notice clause. When those three do not match the policy wording, the claim often becomes slower and smaller than expected.
Indemnities that actually work
A useful indemnity says who pays for a breach caused by that party, what losses count, and whether indirect losses are included. A vague promise to “hold harmless” can be too soft to matter when the money is already gone.
A good test is whether the clause covers breach response, third-party claims, and reasonable recovery costs. If it only covers direct loss, you may still pay for forensics, lawyers, and rerouting payments yourself.
Minimum security standards
Minimum security standards should not be a slogan. They should name multi-factor authentication, password rules, device patching, and how accounts are removed after the job ends.
Construction firms often miss that the standard must match the way the subcontractor really works. If they access BIM from site, mobile use and lost-device reporting matter more than an office firewall no one checks.
Incident notice deadlines
Incident notice deadlines are the timer on the claim. Some policies want notice within 24 to 72 hours, and some contracts want breach notice even faster.
That sounds strict because it is. If a subcontractor waits three days before saying their mailbox was hit, the delay can make both the insurer and the client harder to satisfy. The safest rule is to set the subcontractor’s notice window shorter than the policy window.
The clause everyone misses
The clause most teams miss is the one about systems they are allowed to use. If a subcontractor may only use approved portals and still sends files by personal email, the contract and reality no longer match.
That mismatch matters because insurers and clients both ask what controls were actually in place. A paper policy is not a control. A working process is.
Common questions
What does cyber insurance cover for construction
It usually covers incident response, forensic work, notification costs, and some data breach liabilities. Many policies also include limited business interruption, but the sub-limit may be much lower than the main policy limit.
Is cyber insurance mandatory for contractors in
No, not as a general rule in England. Some clients, frameworks, or funding bodies may require it, and those requirements can be more specific than the market norm.
Does public liability insurance cover cyber
Usually no, unless the cyber event causes bodily injury or property damage and the wording is broad enough. A pure payment fraud or data breach normally sits outside public liability.
Does UK GDPR change who is liable?
Yes, because it can make the controller or processor responsible for failing to protect personal data. That does not always mean the subcontractor pays first, because the contract and insurance wording still decide the money path.
When should a subcontractor be told about cyber
Before work starts, not after the first shared file or payment run. A 24 to 72 hour notice duty, plus MFA and device rules, is a common starting point for higher-risk packages.
What is the biggest cover gap in supplier fraud?
The biggest gap is often the fraud sub-limit, not the headline cyber limit. A £1m policy with a £25,000 social engineering cap can leave most of a payment loss uninsured.
Can one incident hit several policies at once?
Yes, and that happens often in construction. A breach can trigger cyber response costs, a PI claim for design error, and a contract dispute over delay, so the wording must be checked together.
What to do next
The safest move is to read the policy, the subcontract, and the supplier controls as one package. If any one of them assumes a different story about liability, fraud, or notice, the gap is already there.
For a UK construction firm using subcontractors, the practical target is simple: make sure the party who can cause the loss is named in the contract, and make sure the policy you buy actually pays for that type of loss. If those two do not match, cyber insurance can look strong on paper and still fail when you need it most.