A site office appears in March and is gone by November. It runs on a 4G router behind carrier-grade NAT, shares a switch with the perimeter cameras and the access gate, and hosts a rotating cast of subcontractors who need the project drawings today and will never be seen again. Multiply that by eleven active projects and you have the IT estate of a mid-sized construction or installation company — which is nothing like the head office and branch model that firewalls, VPN concentrators and most security architecture were designed around.
That mismatch is expensive in ways that rarely appear on an IT budget line. Construction records the highest data encryption rate of any commercial sector in ransomware incidents, above 70%, and the average operational standstill after an incident runs to 21 days. On a project with liquidated damages attached to the critical path, three weeks is not an IT problem. It is a contractual one.
This article covers why the sector attracts attention, what actually breaks when a head-office security model is stretched across moving sites, where Belgian construction firms genuinely stand under NIS2 — which is more nuanced than most vendors claim — and what an architecture built for this estate looks like.
Why attackers pick this sector
Two distinct threats, and the one that costs the most money is not the one most people expect.
Ransomware works here because operational continuity is contractually enforced. Sector reporting puts the increase in construction ransomware attacks in 2024 at 83%, with roughly 60% of firms reporting an incident within a twelve-month window. Attackers understand that a company facing daily penalties for delay has a strong incentive to pay quickly. The average direct cost of a construction breach is around €1.38 million ($1.5 million) in recovery, penalties and downtime, against a global all-sector average of ≈€4.49 million ($4.88 million).
Business email compromise and invoice fraud is the quieter and often larger loss. Construction runs on staged payments, long subcontractor chains and legitimate mid-project changes to bank details — which is precisely the environment in which a fraudulent payment instruction looks normal. The pattern is consistent: an attacker gets into a mailbox, watches the billing correspondence for weeks, and intervenes just before a large interim payment with new account details. By the time the real subcontractor chases the money, it has moved. No encryption, no ransom note, and often no insurance recovery.
European incidents show what this looks like at scale. Bouygues Construction was hit by Maze ransomware in January 2020, with over 200 gigabytes of data exfiltrated including employee personal and banking records; the company shut down its international network to stop propagation, refused a reported ransom demand of ≈€9.2 million ($10 million) and spent weeks restoring systems manually. In the Netherlands, builder Nijhuis Bouw lost five consecutive days of operations across active sites to a targeted ransomware attack in 2023.
Converted from USD at ≈€0.92 per US dollar (August 2026).
What makes this estate different
| Structural reality | Security consequence |
|---|---|
| Sites exist for 3 to 24 months, connected over 4G/5G, temporary broadband or shared Wi-Fi | No static addressing, edge equipment rarely patched, site-to-site tunnels that break constantly |
| Dozens of subcontractors need project data for a defined phase | Account sprawl, shared logins across crews, credentials that outlive the contract |
| BIM models, tender calculations and unit pricing in a common data environment | Exfiltration provides extortion leverage and destroys competitive position in live tenders |
| Cameras, access gates, crane telemetry and plant systems on the site network | Default credentials and unpatched firmware become a pivot into corporate systems |
| Field crews working from phones and tablets on whatever connection exists | Corporate data on unmanaged devices without posture checks or enforced MFA |
| Large staged payments with frequently changing supplier details | High susceptibility to invoice fraud, with losses that are rarely recoverable |
Six failure modes follow from that structure, and every one of them is a direct consequence of applying a head-office model to a moving estate.
Tunnels that will not stay up. Site-to-site IPsec assumes stable latency and consistent addressing. Cellular connections re-address behind carrier NAT and drop packets, so tunnels re-key constantly, file syncs fail, and the site office learns to work around IT rather than through it.
The site trailer becomes part of your corporate LAN. A traditional site-to-site tunnel makes the temporary network a flat extension of head office. One compromised laptop or camera in that trailer has an unobstructed path to your ERP and finance systems.
Shared credentials. Provisioning proper accounts for temporary field staff is administratively heavy, so a site manager shares one login across the crew. Accountability disappears and so does any usable audit trail.
Subcontractor accounts that never end. Access is granted at the start of a phase by someone on site; nobody tells central IT when that phase finishes. The account stays live indefinitely.
Project data on personal phones. Site photos and drawings end up in personal cloud backups because that is the path of least resistance on a device the company does not manage.
Site systems installed and forgotten. Cameras and gates are commissioned quickly by an electrical contractor, often with factory default credentials and no patching plan, sometimes reachable from the internet. Attackers scan cellular address ranges for exactly this. The same problem we described for IP cameras and building management systems under NIS2 and for devices you cannot patch.
Where you actually stand under NIS2
This deserves precision, because there is a lot of confident nonsense in circulation.
General building construction is not a listed sector. Residential, commercial and civil engineering work under NACE code F does not appear in Annex I or Annex II of NIS2, and the Belgian law of 26 April 2024 follows that scope. If you build offices and apartments, you are almost certainly not directly designated as an essential or important entity.
Technical installation firms may well be. If your activity is the installation, cabling or technical maintenance of infrastructure inside a listed sector — energy networks, drinking water, digital infrastructure and data centres, healthcare facilities — you can be captured directly on the basis of that activity, regardless of what your NACE code says on paper. Check this properly rather than assuming; the classification follows what you do.
And everyone gets pulled in sideways. Article 21(2)(d) obliges in-scope entities to manage supply chain risk, which they discharge by imposing security requirements on contractors. When a utility, port authority, hospital or municipality hires you, their compliance obligation becomes your contractual one. That is the mechanism reaching most construction firms today, and we set out how it flows in NIS2 supply chain security obligations.
The commercial edge of this is already visible in Belgian tendering. Public buyers and large private clients increasingly include cybersecurity questionnaires in pre-qualification, typically asking for demonstrable alignment with the CCB’s CyberFundamentals framework — commonly the Basic level, 34 controls covering the majority of commodity attacks — or ISO 27001, along with evidence that subcontractor access is identity-gated and multi-factor authenticated, and that you assess your own suppliers. Failing those questions means administrative disqualification. Cybersecurity has become a pre-qualification criterion rather than an overhead, which is a very different conversation to have with a managing director. Our guide to the CyFun label covers what the levels involve and what they cost.
One more instrument worth knowing: the Cyber Resilience Act brings security requirements for products with digital elements sold in the EU. Installation firms that specify, configure and hand over connected building systems will increasingly be asked what happens when those products need patching, five years after handover.
The architecture that fits a moving estate
Connectivity that survives cellular. Replace static site-to-site tunnels with lightweight outbound connectors on the site gateway. The connector dials out to a cloud control plane, so no static public address and no inbound port are required; when the cellular connection re-addresses, the session re-establishes without the user noticing. This is the single change that removes the most day-to-day friction.
Per-project access instead of network membership. Site staff and workstations authenticate against your identity provider with multi-factor authentication and reach only the applications their project role requires. The rest of the corporate network is not merely blocked but invisible, so a compromised device in a trailer cannot enumerate what it cannot see.
Subcontractor access with an expiry date attached. Grant access agentlessly through the browser, tied to their own identity and scoped to a specific project folder in the common data environment — with an expiry timestamp set from the contract end date at the moment of onboarding. That converts account cleanup from a task someone must remember into a property of the account itself.
Site systems in their own zone. Cameras, gates, crane telemetry and building controllers belong on segmented zones with no route to corporate systems and no direct internet egress. Vendor maintenance access happens through identity-gated, logged sessions rather than a permanent hole. The same zone-and-conduit logic as industrial OT security.
Design and tender data protected at the access layer. Least-privilege permissions on the common data environment, controls on mass download, and tighter restrictions during tender submission windows, when the value of a leak is at its peak.
Central policy, no site visits. A lean IT team pushes policy and revokes access across every site from one console. Sending someone to a trailer two hours away to change a firewall rule is not a security model, and the same distributed-management problem we described for local government services applies here with mud on it.
The objections you will hear on site
“We’re a builder. Nobody wants our data.” They want three things: your ability to keep working, your bid calculations, and your payment flows. The encryption rate above 70% and the 21-day average standstill say attackers have worked out that a firm facing liquidated damages is a motivated payer, and the invoice fraud pattern shows they are equally happy to take the money directly without encrypting anything at all.
“Site offices are temporary and running on 4G — securing them properly is too complex.” True of the old model, and it is why the old model fails here. Static tunnels need static addressing and site-level configuration; an outbound connector needs neither and takes minutes rather than a site visit. The cost comparison is not security spend against zero, it is security spend against an unmonitored trailer with a route into your finance systems.
“Subcontractors will never accept extra steps.” They will not install a VPN client, correctly. That is exactly why identity-gated browser access exists: they sign in with their own credentials and MFA on the device they already carry, reach only the project folder they need, and lose access automatically when the phase ends. It is less friction than the account request they currently email to your site manager.
“The budget goes into machinery and project delivery.” It does, and cybersecurity now competes for it on commercial rather than technical grounds: public and large private clients are asking for framework alignment at pre-qualification, and failing that question removes you from the bid list. Under the Belgian NIS2 law, directors of in-scope entities also carry personal accountability for oversight, which changes who in the business needs to care.
Start with the sites you already have
Two questions worth answering this month. Which subcontractor accounts from projects that finished last year are still active? And if someone plugged into the switch in your busiest site trailer, what could they reach? Most construction IT teams already suspect the answers, and both are fixable without touching a single project deadline.
Jimber was built for exactly this shape of estate: ZTNA network isolation that gives per-project, identity-gated access with automatic expiry, SD-WAN and outbound connectors that hold up over 4G and 5G, firewall-as-a-service and secure web gateway for sites with no rack and no local IT — all from one EU-sovereign platform managed centrally, at a flat rate rather than a per-site appliance bill. Book a demo and we will map it against your current project sites, or read more about securing multiple locations. Building the risk documentation a client questionnaire will ask for? Start with our NIS2 risk assessment method.
Frequently asked questions
Why are construction companies targeted by ransomware?
Because operational downtime is contractually expensive. Projects carry liquidated damages for delay, so a firm whose scheduling and design systems are encrypted has strong pressure to restore quickly. Construction also shows the highest data encryption rate of any commercial sector at over 70%, with an average standstill of 21 days.
Does NIS2 apply to construction companies in Belgium?
General building construction is not listed as an essential or important sector under the Belgian NIS2 law. However, technical installation firms working within listed sectors such as energy, water or digital infrastructure can fall directly in scope, and all contractors face indirect obligations when in-scope clients pass down supply chain requirements under article 21(2)(d).
How does invoice fraud work in construction?
An attacker compromises a mailbox and monitors billing correspondence, learning the payment schedule and the parties involved. Shortly before a large staged payment, they submit revised bank details that look routine in a sector where such changes are common. The payment is made to the attacker and rarely recovered.
Why do VPN tunnels keep dropping on site offices?
Site-to-site IPsec expects stable latency and consistent addressing. Cellular connections re-address behind carrier-grade NAT and experience jitter and packet loss, forcing tunnels to re-key repeatedly. Outbound-only connectors avoid this by maintaining the session at the application layer regardless of the underlying address changing.
How do we give subcontractors access without domain accounts?
Use identity-gated access through the browser rather than network membership. Subcontractors authenticate with their own identity and multi-factor authentication, reach only the specific project folder or application they need, and have an expiry date set at onboarding that matches their contract end so access lapses automatically.
What cybersecurity evidence do Belgian public tenders ask for?
Increasingly, demonstrable alignment with the CCB’s CyberFundamentals framework — often the Basic level — or ISO 27001, together with documented proof that subcontractor access is identity-gated and multi-factor authenticated, and evidence that you assess your own suppliers’ security. Failing these questions can mean administrative disqualification from the tender.
How should job-site cameras and access gates be connected?
On a segmented zone of their own, with no route to corporate systems and no direct internet access. Change factory default credentials before deployment, and route any remote viewing or vendor maintenance through an identity-authenticated, logged gateway rather than exposing the devices to the internet.
How do we stop project photos ending up in personal cloud accounts?
Provide a sanctioned route that is easier than the workaround: a managed field application for capturing photos and progress logs, combined with policy controls that keep project data inside corporate storage. Blocking personal cloud sync without offering a working alternative tends to move the behaviour rather than stop it.