Construction Cyber Attacks Cost Firms Nearly 28 Days of Lost Work Every Year

Person in a gray hoodie typing on a laptop showing lines of code on the screen, seated at a white desk.

New research has revealed that cyber attacks are causing major disruption across the construction industry, with firms losing an average of 24 working days per year due to ransomware incidents and system downtime. The findings highlight growing concerns around digital security as the sector becomes increasingly reliant on connected technologies and cloud-based systems.

These delays are costly to all stakeholders, including contractors, landlords, tenants, finance providers and also those involved with rent collection

Construction projects face delays for several reasons including weather-related, expected issues, illness, lack of materials – but cyber attacks is not one usually on the list, until recently. 

According to the latest industry analysis from QBE, the rise of Building Information Modelling (BIM), connected operational systems and remote collaboration tools is creating new opportunities for cyber criminals to target construction businesses. Every new digital connection within a contractor or supplier network can potentially become an entry point for attackers.

The report found that inadequate separation between IT and operational technology systems contributed to 81% of operational technology incidents recorded in 2025. At the same time, state-aligned cyber attacks against UK infrastructure and supply chains continue to rise, increasing pressure on firms to improve cyber resilience.

Neil Fleming, construction portfolio manager at QBE UK, warned that a single ransomware incident now has the power to derail entire projects. He explained that when firms lose access to drawings, project files or digital platforms, project costs can escalate rapidly while completion deadlines are put at risk.

The construction sector has undergone rapid digital transformation in recent years. Industry data shows a 43% increase in the use of digital construction processes compared with previous years, driven by technologies such as BIM, cloud collaboration platforms, drones and IoT-connected equipment.

While these technologies improve efficiency and communication, cybersecurity experts say they also expand the industry’s attack surface. Remote working, shared supplier networks and unsecured smart devices have all contributed to increased vulnerability across the sector.

Research cited by industry specialists shows that architecture, engineering and construction firms are now more than twice as likely to experience ransomware attacks compared with many other sectors. One report found that 44% of UK construction companies had suffered a ransomware attack within a two-year period, with many firms hit multiple times.

The financial impact can be severe. Beyond ransom demands, firms face project delays, operational shutdowns, reputational damage and lost productivity. Previous research found that the average ransomware disruption can last between 15 and 23 days globally, with some firms taking more than a week simply to restore operations.

Cybersecurity experts are now calling on construction businesses to treat cyber resilience as a core project risk rather than purely an IT issue. Recommended measures include stronger governance, improved supply chain visibility, regular software patching, employee training and tested incident response plans.

David Warr, cyber portfolio manager at QBE International Markets, said the line between cyber risk and operational risk has now “effectively disappeared”, particularly as more operational technology becomes internet-connected.

With digital adoption accelerating across the construction sector, industry leaders warn that firms failing to strengthen cybersecurity measures could face increasing operational and financial disruption in the years ahead.