Construction & site tech cover can and should protect drones, CCTV, IoT sensors, telematics and 3D printers. Declare high-value kit on the proposal form. That helps underwriting and avoids disputes later.
Why construction & site tech cover differs
In the context of construction, site tech is a cyber-physical risk. Cyber policies normally cover data loss, privacy incidents and IT interruption. Site tech cover must also cover attacks that affect physical control systems, telemetry or remote devices.
Insurers split risks because causes and costs differ. Physical damage often sits with material damage or plant insurance. Cyber carriers add sublimits or exclude physical damage caused by cyber events.
According to the UK Government Cyber Security Breaches Survey 2023, 39% of businesses reported a cyber incident in the prior 12 months. DCMS Cyber Security Breaches Survey 2023
Declare connected equipment early on proposals. That affects premium and whether the insurer will accept cyber-physical exposures.
Take a short pause and check your documents.
💡 Advice
List serial numbers and estimated values for high-value kit on the proposal form. Photographs speed underwriting reviews.
Common cyber risks for construction sites and tech
In the context of site tech, common cyber threats include ransomware, business email compromise and firmware attacks on IoT. These attacks can lock data or corrupt telemetry. These can cause delays and rework.
They can also cause funds transfer fraud when payment approvals move by email. Another common risk is loss of remote control. GPS spoofing or signal jamming can disrupt drones or telematics.
Interruption to telematics can delay logistics. That can lead to liquidated damages claims on contracts. Another risk is data breach from mobile devices used on site.
CAD files, BIM models and client data may be held on tablets or cloud drives. Insure both data restoration and privacy liabilities for those assets.
According to the Allianz Risk Barometer 2024, cyber incidents remain a top business risk worldwide. Allianz Risk Barometer 2024
Construction & site tech cover versus public liability insurance
Construction & site tech cover differs from public liability because the trigger is cyber, not negligence causing bodily injury. Public liability covers injury or property damage to third parties from site operations. It normally does not cover data loss or ransomware.
If an attacker takes control of CCTV and that directly causes an injury, liability questions become complex. Some insurers will refuse physical injury claims if the proximate cause is a cyberattack. Only a cyber policy then covers the cyber root cause.
When site tech creates a foreseeable risk to the public, the contractor needs both covers. Contractors also need clear contractual allocation of responsibility. The preferred approach is a combo of material damage, public liability and a cyber wording that declares site kit.
Sample clause to include in contracts
"The contractor shall maintain cyber insurance that expressly covers connected site equipment, including drones and telematics, with declared limits and incident response provisions. The contractor will provide evidence of cover on award of contract."
What SMEs need in cyber cover for sites
SMEs should seek cyber terms that explicitly mention connected equipment and cyber-physical incidents. A policy that only covers servers and office IT will leave gaps for on-site kit.
Key cover elements to require are incident response costs, data restoration and business interruption for project delay. Also ask for fraud and funds transfer coverage and contingent supply chain interruption. Ensure the wording names devices where possible.
Practical controls insurers typically expect are network segmentation, MFA for remote access, patching schedules and physical security for portable devices. Document these controls in the proposal form and on-site handover packs.
Declare portable and high-value assets. Failure to declare drones, 3D printers or telematics often leads to claim denial.
Beyond MFA and segmentation, technical measures for site tech should be specific and testable. For BIM and project files: enforce access controls, versioned check-ins and encrypted backups off-site. Maintain immutable snapshot retention for the critical project phase.
For OT and telemetry: use VLAN separation with strict ACLs, deny-by-default firewalls and jump hosts for remote access. Use certificate-based authentication and rotate per-device credentials on a schedule.
For drones and telematics: mandate signed firmware, geofencing and certificate pinning for telemetry endpoints. Require OTA update policies that need cryptographic validation and centralised fleet management with tamper-evident logs.
For mobile devices and tablets: deploy MDM with full-disk encryption, remote wipe and EDR agents. Run regular compliance scans. Finally, test incident playbooks on-site with tabletop and live recovery drills.
Record RTO and RPO metrics for critical site tech and add those metrics to the proposal. That helps demonstrate control maturity to underwriters.
Take a short pause and check your documents.
Policy limits, excesses and GDPR fines for site tech cover
In the context of site tech, insurers commonly apply sublimits for electronic equipment and data restoration. Incident response and legal costs normally sit within the main cyber limit. Insurers may apply a separate sublimit for equipment replacement or device forensics.
Always confirm in writing whether data restoration and response sit inside the main limit or inside a named sublimit. Premiums vary by turnover, declared site tech exposure, sector and controls. Indicative SME market bands typically range from several hundred to a few thousand pounds annually.
Expect higher premiums if extensive site tech is declared. GDPR fines are a separate exposure. Insurers may limit or exclude regulatory fines for gross negligence.
SMEs should budget for uninsured fines and seek legal advice quickly on breach notification. A practical rule: match your business interruption sum insured to likely contract losses. Liquidated damages on a delayed project can exceed pure IT losses by multiples.
When negotiating limits and sublimits for site equipment, expect a layered structure rather than a single omnibus limit. A practical market example: a policy may offer a £1m main cyber limit that covers legal costs and incident response. The same policy may show an equipment/data sublimit from £25,000 to £250,000 for device forensics or replacement.
Excesses for equipment claims commonly sit between £1,000 and £25,000 depending on item value. Some carriers apply a per-claim excess for cyber-physical losses. Exclusions that commonly affect site tech include theft without evidence of forcible entry and wear and tear.
Pre-existing vulnerabilities not disclosed are often excluded, and physical damage is usually excluded unless an endorsement is purchased. Practical tip: obtain the insurer’s schedule of sublimits and excesses in writing. Map each declared item to whether it sits inside the main limit, a sublimit or is explicitly excluded.
That mapping is crucial when you quantify likely contract liquidated damages versus insurable IT restoration costs.
Cases and exceptions
A typical claim involved a regional contractor. An attacker encrypted BIM files and telematics data. Incident response and recovery costs were £42,000.
Project delay and subcontractor overrun costs reached £115,000. The insurer paid data restoration and response but declined physical plant damage under the cyber policy. The contractor recovered larger plant losses via material damage cover after argument with insurers.
This shows that cyber cover often pays for response and data restoration, not physical repair. It also shows the need for both cyber and material damage policies with aligned triggers.
This guidance does not apply when a business has no connected site equipment. It also does not apply to large contractors with bespoke, layered policies already in place.
⚠️ Attention
If the insurer explicitly covers plant and machinery under a material damage policy, do not assume cyber cover is necessary for physical repair. Check the exact wording first.
How to apply construction & site tech cover in practice
Start with a pre-bind checklist and a declared schedule for high-value kit. Make the schedule part of the proposal form. Give the broker photos and values.
That speeds placement and reduces dispute later. Insist on incident response retention limits and an approved panel of forensic providers. Having a named incident responder in the policy avoids delays in getting a forensics team to site.
For telematics and drone exposures, require secure remote access, MFA and encrypted telemetry. Use VLANs or separate networks for OT and IT where possible. Document patching windows for contract compliance.
Declare connected kit clearly on the proposal form today.
Pre-bind checklist for construction & site tech cover
- Business overview and turnover
- List of connected equipment with serial numbers and values
- Network architecture diagram for on-site connectivity
- Remote access and maintenance arrangements
- Evidence of backups and restoration test results
- Supply chain and subcontractor cyber controls
Practical checklist buying construction & site tech cover
When buying cover, follow a simple procurement workflow. Collect kit data, map likely interruption scenarios and quantify likely delay costs. Present this to the broker to shape the insurer response.
Ask for sample policy wordings and specific responses to cyber-physical triggers. Do not accept a generic cyber wording that omits site kit.
Below is a short policy clause a buyer can request in writing.
"This policy extends to loss or damage directly resulting from a malicious cyber attack on declared site-based connected equipment, including costs of data restoration and business interruption up to the stated sublimit. Physical repair costs remain subject to material damage policy unless expressly endorsed."
| Criterion |
Cyber-only with site tech declared |
Combined cyber and material damage |
When to choose |
| Physical repair |
Usually excluded or sublimited |
Included if endorsed |
Choose combined for high plant risk |
| Data restoration and response |
Included in main limit |
Included with larger combined limits |
Choose either if response speed matters |
| Premium cost |
Lower initial premium |
Higher premium but fewer gaps |
Choose combined for critical kit |
The table shows the trade-off between cost and gap exposure. For SMEs with expensive connected kit, combined or endorsed cover is often better.
Ask early for named policy documents and specific endorsement titles, and insist these are attached to the quote. Useful items to request from a broker are:
- the full policy wording or sample wording often titled ‘Cyber and Technology Policy Wording’ or ‘Cyber-Physical Endorsement’
- the exact proposal form and any equipment declaration schedule template
- any cyber-physical endorsement wording examples such as ‘Cyber-Physical Equipment Endorsement’, ‘Declared Site Kit Schedule’ or ‘Data Restoration Sublimit Endorsement’
If a carrier will not provide wording, ask for a redacted precedent or an insurer market wording. Keep the returned documents with contract paperwork. Ensure the contract’s insurance clause cites the exact endorsement name and policy number so clients or auditors can verify cover quickly during a claim.
Step-by-step claims workflow for on-site cyber incidents
-
Isolate the affected systems and preserve evidence. Do not power down devices unless advised. Contact the insurer and the named incident responder immediately.
-
Instruct forensic IT and mobility experts to secure telemetry and logs. Capture drone flight logs, telematics snapshots and CCTV footage.
-
Notify affected parties and regulators if personal data is involved. Work with legal counsel for notification timelines.
-
Quantify business interruption losses and capture subcontractor costs and demobilisation expenses. Provide evidence to the claims team promptly.
-
Agree remediation and recovery plan with insurers. Keep contemporaneous records of decisions and costs.
Take a short pause and check your documents.
What is often confused with construction & site tech cover
The difference between plant insurance and cyber insurance confuses many contractors. Plant cover pays for theft and physical damage. Cyber cover pays for incident response, data restoration and some interruption caused by a cyber event.
Another confusion is assuming small portable devices are covered automatically by a main cyber policy. Many policies exclude portable equipment unless declared. Check the equipment schedule.
Also, funds transfer fraud is often overlooked. Contractors should ensure the policy covers business email compromise and transfer fraud. These risks can directly affect project cashflow.
Practical buyer's guide: Construction Sites Cyber Insurance
A compact, practical comparison to help site managers buy the right Construction Sites Cyber Insurance without wading through jargon.
Compare policy features & typical premiums
Key covers to compare:
- First‑party: system restoration, data recovery, business interruption (including BIM/plant control loss), cyber extortion.
- Third‑party: liability for data breaches, contractual losses, regulatory costs (may be limited).
- Ancillary: crisis PR, legal support, forensic investigation, social‑engineering fraud cover.
Typical annual premiums (very approximate):
- Micro/subcontractors (turnover <£2m): £500–£2,000.
- SME contractors (£2m–£20m): £2,000–£10,000.
- Large contractors: £10,000+.
Note: premiums vary with turnover, supply‑chain exposure, security posture and chosen limits/excesses.
Common exclusions and limits to watch
Watch for exclusions/limitations such as:
- Physical damage to plant (usually outside cyber cover).
- Contractual penalties and liquidated damages.
- Pre‑existing incidents and failure to follow agreed security protocols.
- Sub‑limits for cyber extortion, forensic costs or regulatory fines — check whether GDPR fines are covered.
Also check retroactive dates, aggregate limits and whether dependent third‑party failures are included.
Real‑world claims and a quick checklist
Examples:
- Ransomware halted site management servers; ransom £75k, recovery/BI costs circa £150k — insurer covered restoration and BI.
- Email compromise led to fraudulent supplier payment £200k; settlement depended on specific social‑engineering cover.
Checklist for site managers:
- Identify critical digital assets and suppliers.
- Confirm sums insured for BI, extortion and legal costs.
- Verify exclusions and sub‑limits (GDPR, social engineering).
- Ensure tested backups, MFA, incident response plan and staff training are in place.
- Notify broker/insurer about unique risks (remote access, telematics, BIM).
Frequently asked questions
Is cyber insurance mandatory in the UK?
No. Cyber insurance is not legally mandatory in the UK for most SMEs. Some clients and major contractors may require it under contract terms. Review contract requirements before bidding.
What does cyber insurance not cover?
Policies commonly exclude unreported vulnerabilities, dishonest acts by management and physical damage unless endorsed. Expect sublimits for equipment and limits on regulatory fines in some wordings.
How much is cyber liability insurance UK?
Premiums vary by turnover, exposure and declared kit. Market ranges are roughly £300 to £3,500 annually for SMEs with standard exposures. High tech or declared plant increases premiums.
What insurance covers cyber attacks?
Cyber policies from specialist insurers cover cyber attacks. For physical repair after a cyber event, material damage or plant insurance may apply if endorsed. Use both where site tech is critical.
Is Construction & site tech cover mandatory?
No. It is not legally mandatory. It is often commercially required by clients or lenders for project work. Contractors should check contract clauses and procurement documents.
What if a subcontractor causes the cyber incident?
The primary contractor may be held responsible under contract. Use supply chain clauses to require subcontracts to carry minimum cyber controls and proof of insurance. Retain evidential logs for claims.
Conclusion
Construction & site tech cover should form part of a contractor's insurance mix when connected equipment is used on site. Policies vary widely, so declare kit and ask for endorsements that cover cyber-physical triggers. Align cyber and material damage wordings and use a pre-bind checklist. Demand sample policy wording and ensure contract clauses push controls down the supply chain. For brokers and insurers, present clear schedules and documented controls to speed placement.
UK Government Cyber Security Breaches Survey 2023