A supplier’s bank details can be changed by email, and a payment can go to a fraudster. Ransomware can lock programmes, drawings and BIM files before a key deadline.
Do construction SMEs need cyber cover?
Most construction SMEs in England should assess cyber cover separately, particularly when they use project email, digital payments, BIM or cloud systems.
The real problem is not simply a hacked laptop. It is the cost of halted work, false payments and lost project data.
Which policies leave a cyber gap?
Public liability insurance normally covers injury or property damage caused to others. It will not normally repay money sent after a spoofed supplier email.
Professional indemnity insurance may cover a claim about negligent design or advice. It does not replace forensic work, ransomware support or the restoration of encrypted estimating files.
When is exposure highest?
Risk can be high in smaller firms where people share accounts. It also rises when staff have broad access rights.
One office manager may approve payments alone. A compromised mailbox can then reach suppliers, subcontractors, tender contacts and finance records.
As a result, a single mailbox can affect an entire project team.
Where construction cyber losses start
Construction cyber losses often start in project email, BIM access and estimating tools. They can also start with site tablets or supplier-payment instructions.
| Workflow | Loss to insure | Common gap | Useful claim evidence |
|---|
| BIM or CDE | Data restoration and business interruption | Cloud-provider outage not included | Provider notice, programme, timesheets |
| Project email | Forensics and breach response | Social engineering sub-limit | Email headers, login logs |
| Supplier payments | Funds transfer fraud extension | No cover for voluntary transfer | Invoice, call record, bank trace |
| Site tablets and laptops | Ransomware response and restoration | Unsupported or unpatched systems | Asset list, backup test, incident log |
Could BIM downtime stop a job?
Business interruption means lost income or extra cost after an insured disruption. A policy may require disruption to your own system.
Cover for a CDE, cloud host or software provider may need separate contingent-business-interruption cover. Think of it as cover for a key supplier’s digital failure.
Is a bank-detail email fraud insured?
Supplier impersonation is often called business email compromise. A criminal copies a real supplier thread and changes the sort code and account number.
They may then pressure the accounts team to pay quickly.
A £1 million overall limit can still contain a much lower fraud sub-limit. Ask for the limit, excess and covered payment-deception definition in writing. Do this before comparing quotations.
What happens after site ransomware?
A realistic case involves a subcontractor’s estimator opening a false document-sharing link. The mailbox then sends fake payment instructions.
The shared pricing drive is then encrypted. A cyber policy may fund forensic work and restoration.
Equipment replacement and the false transfer depend on separate insuring clauses.
A lost drawing or employee record can create a data-protection incident as well as an operational problem.
Where personal data may have been accessed, assess the facts quickly with incident-response advisers. Then decide whether the Information Commissioner’s Office or affected people need notice.
Cyber cover can include forensic work, legal advice and breach notification. It may also include credit monitoring and public-relations support.
Policy wording and limits decide what is available.
Cyber cover does not remove the firm’s GDPR duties. Deliberate misconduct, known incidents or poor security may be excluded.
Keep a clear record of the data involved. Record who had access and the steps taken to contain it.
Which controls improve cyber quotes?
Construction SMEs can improve their cyber risk position with multi-factor authentication. Recoverable backups and payment checks also help.
Which checks do insurers ask for?
Insurers commonly ask if MFA protects email, remote access and cloud services. They also ask about administrator accounts.
They may ask about patching, endpoint detection and response, and encryption. They may also check whether leavers’ or subcontractors’ accounts are removed.
A practical pre-quote control path
1. Lock access
MFA on email and CDE
2. Test recovery
Restore a project folder
3. Check payments
Independent call-back
4. Save proof
Keep logs and test dates
How should payment changes work?
Every changed bank detail should trigger a call-back. Use a telephone number already held in a trusted supplier record.
Do not call the number in the change request. That number may belong to the criminal.
What must happen on day one?
Isolate affected devices and preserve emails. Call the insurer’s incident-response number promptly.
Do not appoint a recovery firm before checking consent terms. Some policies only pay approved costs.
Choose wording before choosing a price
The right cyber policy covers your real digital work. It is not always the policy with the largest headline limit.
This approach matters less if a construction business stores no digital data, takes no electronic payments and uses no email, cloud systems or technology to operate. This does not replace advice from a qualified broker, insurer or adviser. Seek advice when public contracts, client requirements or an active claim are involved.
There is no single UK price for construction cyber insurance. Insurers rate turnover, claims history, users, payment volumes and data held.
They also assess reliance on BIM, estimating software and a common data environment. These systems can stop work when they fail.
A contractor with MFA can present a stronger risk. Tested offline backups and a documented supplier call-back process also help.
Shared email accounts and untested recovery plans can weaken the case.
When comparing SME cyber cover, look beyond the annual premium. A lower-priced policy may have a high excess.
It may also have a short business-interruption period. Its funds transfer fraud sub-limit may be small.
Ask for each figure beside the overall limit.
What people ask
What does cyber insurance cover for builders?
Cyber insurance can cover incident response, forensic work, data restoration and selected business interruption costs. Cover for extortion, client claims and regulatory costs depends on terms, exclusions and sub-limits.
Does public liability cover cyber fraud?
Public liability insurance does not usually cover cyber fraud or a fake supplier payment. It normally covers third-party injury or property damage, not a deceptive electronic transfer.
Is supplier bank-detail fraud covered?
Supplier bank-detail fraud may be covered only with social engineering or funds transfer fraud cover. Check the fraud definition, sub-limit, excess and payment checks before relying on it.
How much does cyber insurance cost in the UK?
Cyber insurance costs vary because insurers assess turnover, users, payment volumes and security controls. BIM reliance, claims history and the policy limit can also change the price.
Is cyber insurance compulsory in England?
Cyber insurance is not generally compulsory in England for construction SMEs. A client contract, public tender or finance agreement may still require it.
Does a GDPR report mean insurance will pay?
A GDPR report does not guarantee that insurance will pay. Payment depends on the policy terms, exclusions, limits and the facts of the incident.
What is the first action after ransomware?
The first action after ransomware is to isolate affected systems and contact the insurer’s response service. Preserve evidence and avoid deleting files. Do not hire recovery firms without checking policy consent.
Do subcontractors create cyber risk?
Subcontractors can create cyber risk when they access project email, BIM or shared files. Remove their access when work ends and check their accounts regularly.
The practical cover decision
The essentials:- Public liability, professional indemnity and contract works cover losses that differ from cyber insurance.
- Supplier-payment deception needs a specific fraud extension in many policies.
- Cloud and BIM downtime need clear business-interruption wording, not assumptions.
- MFA, tested isolated backups and independent payment call-backs improve resilience and quote quality.
- Prompt insurer notification protects access to approved incident-response support.