Five reasons to think cyber
Cyber security is no longer just a problem for the IT department; it’s now a contractual and operational issue too, warns Higgs legal director Scott Moncur.

The Cyber Security and Resilience (Network and Information Systems) Bill is progressing through Parliament and is expected to complete its journey later this year. It reframes the existing Network and Information Systems (NIS) Regulations 2018 and signals a significant shift in how businesses, including those in the construction industry, are expected to manage cyber risk.
The changes are not aimed at the construction industry directly, but are likely to have significant impacts on construction businesses, as lead contractors or subcontractors involved in infrastructure delivery for utilities, transport, energy, water, telecoms, data centres and defence-related projects.
While many of you won’t fall directly within the scope of the new proposed legislation, you shouldn’t assume that it has no relevance.
The UK construction industry has become increasingly exposed to cyber threats due to use of:
- BIM and digital engineering platforms;
- cloud-based project collaboration tools;
- connected plant and operational technology;
- complex supply chain ecosystems; and
- high-value payment processes and subcontractor networks.
As far back as 2022, the UK’s National Cyber Security Centre (NCSC) identified construction organisations as attractive targets for ransomware, phishing, payment diversion fraud and supply chain attacks. Construction projects involving major infrastructure assets present heightened national security and resilience concerns.
Here are five risks construction businesses should be preparing for now:
Cyber resilience scrutiny at procurement
The construction industry relies on complex supply chains and IT infrastructure. Your business will be expected to demonstrate that it can operate securely and recover quickly if something goes wrong. As threats become more sophisticated and damaging both operationally and reputationally, suppliers should expect potential customers to ask about their cyber governance and security controls as part of tender submissions.
If you demonstrate good cyber practices, you are likely to find yourself in a stronger position when competing for work.
Supply chain assurance up the agenda
One of the key themes of the new legislation is clear oversight and understanding of your supply chain cyber risk. Those businesses operating under the scope of the new Bill will be expected to understand the risks posed by suppliers and service providers. That expectation is gaining momentum through commercial supply chains.
This means you need to consider stringent due diligence and robust governance arrangements. You should expect the same level of compliance from any contractors or suppliers you use. It’s now another measure of supplier quality and stability.
Digital transformation brings new risks
The sector has undergone significant transformation in recent years, with cloud-based collaboration platforms driving efficiency and becoming more common. BIM, digital projects and connected sites are just some of the advancements we’ve seen lately – and with increased connectivity comes new vulnerabilities.
If a contractor experiences a cyber incident, it won’t just impact their systems. It could delay projects, disrupt upstream and downstream supply chain participants and impact wider communications, including with clients and suppliers, possibly affecting contractual delivery.
Your project resilience will be heavily dependent on your cyber resilience.
Consequences beyond technology: contractual changes
“The biggest message is that cyber security is the leadership team’s responsibility. Senior leaders need to understand the key cyber risks and in turn, ensure appropriate controls are in place.”
Historically, cyber clauses were often generic. Infrastructure owners should now be seeking increased contractual protections that require contractors to maintain specified cyber standards, requirements to notify your counterparty promptly, cooperate with investigations, maintain or increase cyber insurance and preventative controls. You should also mirror obligations through your own subcontractor supply chain.
This can increase your commercial and legal exposure, particularly as clients increasingly expect businesses to demonstrate robust cyber resilience. This may include requirements around:
- stronger governance and oversight;
- preventive controls and business continuity measures;
- contractual termination and step-in rights;
- responsibility for indemnity exposure arising from cyber failure;
- claims for delay or disruption;
- consequential loss allegations; and
- possible exclusion from future procurements.
Good governance = commercial advantage
Perhaps the biggest message is that cyber security is the leadership team’s responsibility. Senior leaders need to understand the key cyber risks for the business and, in turn, ensure appropriate controls are in place. They need to be satisfied that the business can respond effectively to an incident.
Clients, insurers and commercial partners want reassurance that cyber resilience is embedded within an organisation rather than treated as an afterthought.
Practical steps would include:
- reviewing cyber security policies and governance arrangements against the relevant ISO standard;
- ensuring appropriate access and authentication controls are in place;
- regularly backing up and testing critical systems;
- cyber awareness training for employees;
- developing and testing an incident response plan;
- Cyber Assessment Framework maturity assessments;
- supply chain security procedures;
- secure information management; and
- ensuring your security capability includes mapping your digital assets to those infrastructure projects directly within the scope of NIS and your clients’ projects.
Considerations in the immediate term
Although the Cyber Security and Resilience Bill is still progressing through Parliament, its message is clear. For the construction sector, this isn’t simply about preparing for future regulation – businesses should be reviewing their cyber resilience and taking action now. It’s about protecting your projects, maintaining client confidence in your operations and strengthening your commercial resilience as the industry becomes more digital.
Keep up to date with DC+: sign up for the midweek newsletter.