Cyber Security in the Built Environment: Protecting projects, data, and digital assets
[edit] About
Cyber Security is not just an IT issue; it is a business issue. This is a practical technical information sheet suitable for built environment professionals. This publication will help professionals understand and manage cyber security risks, protect projects, data and digital assets.
Read more of our Technical Information Sheets here.
[edit] Summary
This practical technical information sheet helps construction firms and built environment professionals understand and manage today’s most common cyber risks, from ransomware and phishing to payment fraud.
It explains how attacks happen and what simple, effective steps professionals can take to prevent them.
With clear advice on Cyber Essentials, staff training, incident response, and recovery, it shows how to build resilience without unnecessary complexity.
It is designed to help professionals and their firms protect their projects, their data and their reputation.
[edit] Contents
- Cyber Security in the Built Environment: Protecting projects, data, and digital assets
- Why cyber security matters in construction
- What do cyber incidents cost construction firms?
- Aim and Scope
- Proportionality and risk
- Understanding cyber security basics
- What is cyber security?
- Cyber security vs IT security
- The construction sector’s unique cyber risk profile
- The current threat landscape
- Ransomware
- Phishing emails
- Business email compromise (BEC)
- Dark web and credential theft
- Insider threats
- Supply chain vulnerabilities
- Assessing threats: ease, likelihood, and impact
- Secondary impacts of cyber incidents
- Real-world examples: cyber incidents and their impacts
- Core defence measures
- Cyber Essentials (and Cyber Essentials Plus)
- Strong authentication and access control
- Defences against phishing and BEC
- Data and device protection
- Backup strategy
- Dark web monitoring
- Supply chain security
- Cyber Security checklist for construction projects
- Site-specific measures
- Quick wins
- Measuring effectiveness
- Common pitfalls to avoid
- Building cyber awareness and culture
- Staff cyber security training
- Phishing simulations and practical exercises
- Embedding a ‘report, don’t blame’ culture
- Creating and using a clear cyber security policy
- A simple cyber security policy: what to include
- Leadership and culture
- Measuring awareness and culture
- Common pitfalls to avoid
- Testing, monitoring and continuous improvement
- Penetration testing
- Vulnerability scanning versus pen testing
- Security Operations Centres (SOCs)
- Centralised logging and visibility
- Regular audits and reviews
- Continuous improvement
- Measuring success
- Common pitfalls to avoid
- Responding to incidents and recovering quickly
- Preparing for incidents: incident response planning
- Incident response in practice
- Disaster recovery and DRaaS
- Legal, regulatory and communications considerations
- Post-incident review and learning
- Common pitfalls to avoid
- Building a sustainable cyber security strategy
- Making the business case for cyber security
- Building a practical cyber security roadmap
- In-house vs outsourced cyber security: choosing the right model
- Using external support effectively
- What makes a strategy sustainable
- Common strategic pitfalls to avoid
- Senior management checklist: building and maintaining cyber security
- Conclusion and next steps
- A practical action plan
- Embedding cyber security into everyday business
References
Further reading
About the Author
CIOB members can access Technical Information Sheets for FREE and receive a 20% discount on our Codes and Guides. Your discount codes are in the members’ portal. ↗ If you experience difficulties accessing the portal, contact lis@ciob.org.uk.
Featured articles and news
New Scottish and Welsh governments
CIOB stresses importance of construction after new parliament elections.
The sad story of Derby Hippodrome
An historic building left to decay.
ECA, JIB and JTL back Fabian Society call to invest in skills for a stronger built environment workforce.
Women's Contributions to the Built Environment.
Calls for the delayed Circular Economy Strategy
Over 50 leading businesses, trade associations and professional bodies, including CIAT, and UKGBC sign open letter.
The future workforce: culture change and skill
Under the spotlight at UK Construction Week London.
A landmark moment for postmodern heritage.
A safe energy transition – ECA launches a new Charter
Practical policy actions to speed up low carbon adoption while maintaining installation safety and competency.
Frank Duffy: Researcher and Practitioner
Reflections on achievements and relevance to the wider research and practice communities.
The 2026 Compliance Landscape: Fire doors
Why 'Business as Usual' is a Liability.
Cutting construction carbon footprint by caring for soil
Is construction neglecting one of the planet’s most powerful carbon stores and one of our greatest natural climate allies.
ARCHITECTURE: How's it progressing?
Archiblogger posing questions of a historical and contextual nature.
The roofscape of Hampstead Garden Suburb
Residents, architects and roofers need to understand detailing.
Homes, landlords. tenants and the new housing standards
What will it all mean?




















