Digitalisation in construction improves collaboration and asset management, but it also introduces new cybersecurity and resilience risks. Tools such as BIM, common data environments (CDEs), mobile apps, and remote access increase the number of systems and connections.
This creates more entry points than paper-based workflows. If credentials are weak, access rights are misconfigured, or application programming interfaces (APIs) are unsecured, attackers may gain unauthorised access to sensitive information such as layouts, schedules, costs and asset data.
Data centralisation creates a different risk. When BIM models, financial records and schedules are stored on a single shared platform and accessed by many parties, the platform becomes a high-value target. A single compromise can affect a large volume of information and may enable data theft.
The large number of users, contractor accounts, and devices also makes identity and access management more difficult, so strong access control, multi-factor authentication, secure configuration, logging and backups are essential.
Major construction software vendors such as Autodesk, Trimble, Nemetschek and Bentley Systems provide cloud platforms used across large numbers of projects and organisations. This concentration can create systemic third-party risk, as a vulnerability or breach affecting a widely used platform could affect multiple customers.
These vendors often use cloud-based tools such as Autodesk Construction Cloud or Trimble Connect, so they should apply robust security controls and independent assurance, including standards such as ISO 27001, to protect data. For example, in early 2025, Trimble’s Cityworks software was found to have a high-severity vulnerability that could allow an authenticated attacker to execute remote code on Microsoft IIS servers.
Attackers exploited this flaw, with indicators of compromise including malicious tooling associated with Cobalt Strike, potentially enabling data theft or broader system compromise. In response, Trimble released security patches and strongly urged all users to update immediately.
AI, OT and connected infrastructure
AI is increasingly used in construction to improve project planning, analyse BIM models, monitor site progress, predict maintenance needs and enhance safety. These systems rely on large volumes of critical and sensitive data, such as client financials, architectural designs, infrastructure blueprints, equipment performance logs and personal information, which are stored on cloud-based platforms and shared among multiple stakeholders, including contractors, subcontractors, clients and regulators.
While this improves efficiency and reduces downtime, it also creates cybersecurity risks. If attackers gain access to the system or manipulate sensor data, the AI may produce inaccurate predictions, potentially contributing to serious maintenance failures.
Merging IT with OT raises further concerns. Construction sites use OT systems, sensors, access controls, machinery and building management systems that may have weaker security controls than conventional IT systems. This unique blend of databases that store sensitive project data, OT systems that control physical operations, and building management systems that regulate on-site environments creates a much broader attack surface.
A breach in any one area can cascade, causing financial loss, reputational damage, or major operational disruptions.
In one case study, CyberProof worked with a global real estate and construction group to develop a security operations centre spanning IT, OT and IoT environments. The project addressed risks around building management systems, high-voltage power infrastructure and limited visibility across interconnected IT and OT environments. CyberProof deployed security monitoring, intrusion detection and orchestration capabilities designed to improve threat detection and enable rapid isolation of systems when a compromise was suspected.
As construction adopts BIM, CDEs, cloud platforms, AI and connected OT systems, the attack surface grows, and critical data becomes more concentrated. To realise the benefits safely, firms and their supply chains must treat cybersecurity as a core project risk by strengthening identity and access management, securing configurations and APIs, maintaining logging and backups, and holding vendors to clear security standards to prevent a single weakness from becoming a major breach.
