Skip to content
Construction · Australia

Protect the project, not just the paperwork.

Large invoices and a web of subcontractors make payment-redirection fraud devastatingly effective against builders. Plain-English protection for your tender pricing, project data and the security requirements your insurer and head contractor now expect.

Dossier 04 / 10

Construction

Large invoices and a web of subcontractors make payment-redirection fraud devastatingly effective.

  • Privacy Act 1988
  • Contractual & insurance security requirements
  • Supply-chain due diligence
Named obligations

What the obligation actually requires of you.

  1. 01

    Privacy Act 1988

    Where the Privacy Act applies, tenders, subcontractor details and client information need reasonable protection; coverage depends on the entity and the information it holds.

  2. 02

    Contractual & insurance security requirements

    Head contracts and cyber-insurance policies increasingly name specific security controls as renewal or tender conditions — controls your business needs to prove, not just claim.

  3. 03

    Supply-chain due diligence

    A subcontractor's weak security can become your breach. Project-based businesses need to know who touches their data, and how well it is actually protected.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Commercial builder, QLD

A subcontractor invoice targeted for duplicate payment.

Illustrative scenario — In this example, Midway through a multi-million-dollar commercial fit-out, the project accounts team received an email — apparently from a long-standing subcontractor — requesting updated bank details ahead of a progress payment. The sender's domain was one character off the real one.

Example response — A suitable response is to pause the payment, verify supplier details through a known contact, review mailbox rules and limit supplier access to the project need.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, then see the priorities.

Review each practical control, assign an owner, and get an educational action list before you request a prepared follow-up.

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Construction Cybersecurity Checklist

0 / 7 reviewed0%

Payment and bank-detail changes verified by phone before funds move, every time

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Payment and bank-detail changes verified by phone before funds move, every time.

MFA enforced across project-management and accounting platforms

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: MFA enforced across project-management and accounting platforms.

Subcontractor and supplier access reviewed and time-limited to the project duration

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Subcontractor and supplier access reviewed and time-limited to the project duration.

Tender and design documents access-controlled and watermarked

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Tender and design documents access-controlled and watermarked.

Cyber-insurance and head-contract security clauses mapped against your actual controls

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Cyber-insurance and head-contract security clauses mapped against your actual controls.

Site and office devices covered by managed endpoint protection

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Site and office devices covered by managed endpoint protection.

An incident response plan naming a point of contact for principal contractors

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: An incident response plan naming a point of contact for principal contractors.

Complete each control to see your prioritised plan before submitting.

Request a prepared action plan

Share business details so GMAN IT can prepare a useful follow-up by email and with the team.

Optional business context

Your submitted details and checklist answers are shared with GMAN IT to prepare the plan and follow up. Read our Privacy Policy. If a delivery link is generated, it expires after 7 days.

Before you call us

The questions this vertical always asks.

Find out exactly where your project data is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au