Download PDF (813 KB)
PDF version, ready to print or share with your team.

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. I have helped Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton and Metro Vancouver.
Yes, construction is now one of the most attacked sectors in Canada, because milestone billing moves large sums on email approvals and site deadlines punish downtime. Fusion Computing secures Canadian construction and trades firms with CISSP-led controls, starting with multi-factor authentication, banking-change callbacks and managed endpoint detection.
On intake I almost always find a fake payment-change email already sitting in an accounts-payable inbox within the first 30 days. The firms that never lose money are the ones where somebody picks up the phone and verifies the banking change before a release goes out.
A mid-size builder moves more money in one milestone billing than most retailers see in a quarter. Attackers worked that out years ago. What changed after 2024 is the cost of losing access, now averaging 24 days of downtime per incident.
Fusion Computing has secured Canadian construction and trades firms since 2012. In our practice the intake pattern is consistent, and it is always the same three things: strong operations, thin defences and an approval workflow built on trust. This guide covers what is hitting the sector in Canada and the controls that stop it.
Short answer: Cybersecurity for construction firms in Canada comes down to defending 3 things: the milestone approval chain, the shared project environment that subcontractors log into, and the ability to recover from ransomware without paying.
In practice that means MFA on every Microsoft 365 account, callback verification on banking changes, least-privilege project shares, tested backups, managed endpoint detection and staff trained on construction-specific lures.
KEY TAKEAWAYS
- Construction sits in the top 3 attacked sectors. Rapid7 ranked it there for 2025, with Canada placed second by country after the United States.
- Downtime is the real bill. Insurer QBE measures 24 days of average downtime per construction ransomware incident, in a sector where 77% of firms tolerate no more than 5 days without project documentation.
- Being small is not protection. Verizon found ransomware present in 88% of breaches at small and medium businesses, against 39% at large organizations.
- Your subcontractors are now the entry point. Breaches involving a third party doubled in a year, from 15% to 30%.
Why are construction firms now a top cyber target in Canada?
According to Rapid7 (2025), the construction industry ranked among the top 3 most attacked sectors in 2025, and Canada sits second by country behind the United States for construction ransomware victims. Attackers like the mix of large recurring billings, hard deadlines, a deep subcontractor ecosystem and budgets that lag the money moving through the firm.
The sharper number is downtime. Canadian Underwriter (2026) records that insurer QBE measures 24 days of downtime for the average construction ransomware incident. A 2023 resilience survey it cites found 77% of construction respondents tolerate no more than 5 days without access to project documentation.
Kyle Gray, cyber underwriting team lead at QBE Canada, put it plainly in that report: when access to drawings is lost, costs escalate and subcontractors feel it immediately. The 2025 CIRA Cybersecurity Survey (2025) found 74% of Canadian ransomware victims paid.
Why the schedule makes builders pay.
The Progress-Draw Fraud Kill-Chain: how construction firms actually get robbed.
The Progress-Draw Fraud Kill-Chain is the 5-step pattern that produces most construction payment fraud, built from anonymized client data across Fusion Computing engagements since 2012. Public recon on project awards, a phished mailbox inside the approval chain, weeks of silent observation, a banking-detail swap timed to a milestone release, then a transfer that clears before month-end reconciliation.
Where each step breaks.
- Recon. You cannot stop this. Project awards and tender results are public by design.
- The phish. Email filtering plus MFA. A stolen password sitting behind MFA is a dead end most of the time.
- Observation. Microsoft 365 audit alerting on new mailbox forwarding rules.
- The swap. A callback to a known number plus dual approval in finance.
- The transfer. Daily bank reconciliation instead of monthly, so the window closes in hours.
Step 3 is where logging earns its keep. A mailbox rule that quietly forwards anything containing the word invoice to an outside address is the classic tell. Our engineers find it during Microsoft 365 reviews more often than any other artifact I look for.
Step 4 is beaten by a process control rather than a product, and it costs nothing to run. The Competition Bureau of Canada (2026) reported that the Canadian Anti-Fraud Centre logged over CA$704 million in fraud losses in 2025, with only 5% to 10% of frauds reported at all.
Want to know whether your approval process would survive a spoofed banking change? Talk to us →
What 7 controls stop the attacks construction firms actually face?
According to Verizon (2025), the human element featured in roughly 60% of breaches, and credential abuse stayed the most common initial access vector at 22%. Seven controls cover the construction threat model because they map to how breaches actually start rather than to a product catalogue.
The 7 controls, mapped to construction workflows.
| Control | Construction workflow it protects | Minimum standard |
|---|---|---|
| 1. Multi-factor authentication | Email, PM platform, bank portal, estimating server | MFA on every account; legacy sign-in blocked |
| 2. Email and phishing defence | Draw notices, tender documents, CRA and WSIB lures | Advanced filtering, external-sender banners, link scanning |
| 3. Payment-change verification | Progress draws, holdback releases, sub payments | Callback to a known number + dual approval on any banking change |
| 4. Least-privilege project shares | Drawings, contracts, joint-venture folders | Per-project access that expires at substantial completion |
| 5. Tested, immutable backups | Estimating data, project records, accounting | Immutable copies with a restore tested at least quarterly |
| 6. Managed endpoint detection | Office workstations, site laptops, trailer machines | Managed detection with 24/7 response, not just antivirus |
| 7. Awareness training | PMs, site supers, accounting clerks | Quarterly phishing simulations using construction lures |
None of the 7 needs an enterprise budget. They need a right-sized stack for a 25 to 200 person firm and one accountable owner, which is the role our managed IT services team plays for builders. Order matters here, and I sequence it the same way every time. Identity and email come first, because that is where the money leaves.
What the CCCS baseline controls checklist requires of a firm under 499 employees.
According to the Canadian Centre for Cyber Security (2020), the Baseline Cyber Security Controls for Small and Medium Organizations set out 13 controls, and control OC.1 scopes them to organizations with less than 499 employees. That covers almost every general contractor and trade in Canada, which makes it a scorecard nobody can accuse of being vendor-shaped.
I reach for this list precisely because it is not ours. When I walk a construction client through a gap review, using a federal baseline removes the argument about whether we are selling something. Four of the 13 do the heavy lifting on the construction files I review.
| CCCS baseline control | What it means on a job site |
|---|---|
| 3.1 Develop an Incident Response Plan | Who phones the owner, the surety and the insurer when the estimating server locks. |
| 3.5 Use Strong User Authentication | MFA on the mailbox that approves releases, and on the bank portal behind it. |
| 3.7 Backup and Encrypt Data | A restore you have actually run, not a backup job reporting green. |
| 3.10 Secure Cloud and Outsourced IT Services | The project platform, and every subcontractor account still logging into it. |
The Cyber Centre (2026) also warns that smaller organizations often integrate parts of their supply chains with multiple other entities, which increases the threat surface when a third party is compromised. That sentence describes a construction project almost exactly.
Where do project platforms, drawings, and site IoT fit in?
According to QBE and Zscaler (2026), IoT malware activity aimed at the construction sector rose 410% year over year. The shared project environment is the structural weakness, because one Canadian project links the general contractor, its subcontractors, consultants and the owner through the same platforms and file links.
Verizon also found that breaches involving a third party doubled in a year, from 15% to 30%. On a construction file that statistic has a name and a face. It is the subcontractor whose mailbox was compromised in March and who is still submitting payment applications in July.
Project management platforms hold your drawings, RFIs and contracts, and they are only as strong as the weakest login with access. Single sign-on through Microsoft 365 with MFA, plus per-project access revoked at substantial completion, closes most of that exposure.
Site technology and the office network.
Site technology is the newer problem. Telematics on heavy equipment and trailer routers ship with default passwords and rarely get patched. Segment them onto their own network, never bridged to the office network. Our zero-trust guide for Canadian SMBs covers the access model.
Construction versus professional services: the same attack, a different payment chain.
Business email compromise looks identical in every vertical until you follow the money. In our practice the wealth-management version targets a client transfer instruction, while the construction version targets a milestone release or a 10% holdback. Same phish, same mailbox rules, another signature on the outbound transfer and another person entirely who can stop it.
That difference decides who gets trained first. At a wealth firm the last line of defence is an advisor who knows the client’s voice. If you also run a finance-side entity, read the sibling guide on wire fraud and business email compromise at Canadian wealth firms, where the callback protocol is built around CIRO-regulated client instructions.
- Wealth firm. The fraudulent instruction moves client money out of a managed account, and the advisor is the human check.
- Construction firm. The fraudulent instruction diverts a milestone release or holdback, and the coordinator reconciling the payment application is the human check.
On a construction file the last line is a project coordinator reconciling a payment application against a schedule of values, usually against a deadline. That is why I train the coordinator and the accounts-payable clerk before I train the executive, because 9 times out of 10 the executive is not the person clicking approve. Architecture and engineering practices sit between the two, which our guide to cybersecurity for architecture and engineering firms covers.
What do Canadian rules and cyber insurance expect from a contractor?
According to the National Cyber Threat Assessment 2025-2026 (2024), ransomware is the top cybercrime threat facing Canada’s critical infrastructure, the category that includes the supply chains construction anchors. PIPEDA applies to the personal information a builder holds, which means employee records, client contacts and payroll data.
Why Canadian builders bring this work to Fusion Computing
CISSP-led, a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder, securing IT for Canadian SMBs across Toronto, Hamilton and Metro Vancouver since 2012.
What your insurer checks before it pays.
The sharper enforcement mechanism is your insurer. Every application I have completed alongside a client now asks for MFA, endpoint detection, tested backups and written payment-verification procedures by name, and a wrong answer either voids coverage or prices it brutally. Our guide to cyber insurance requirements for Canadian businesses maps the control list insurers check.
IBM and the Ponemon Institute (2026) put the global average cost of a data breach at USD 4.99 million, a 12% rise and a record high. For a builder the bigger number is usually the schedule, because liquidated damages do not pause while somebody rebuilds a server.
The Construction Act clock keeps running while your systems are down.
According to Ontario’s Construction Act, R.S.O. 1990, c. C.30 (2026), section 6.4(1) requires an owner to pay a proper invoice no later than 28 days after receiving it. Section 6.5(1) then requires a contractor to pay each subcontractor no later than seven days after receiving that payment. Neither clock pauses for a cyber incident.
- 14 days to dispute, section 6.4(2). An owner refusing payment must give a notice of non-payment in the prescribed form within that window.
- 28 days to pay, section 6.4(1). The amount stays payable whether or not your accounting system is readable.
- Seven days to pay down the chain, section 6.5(1). Subcontractors get paid from records you may not currently be able to open.
Set those against the 24 days of average ransomware downtime earlier in this guide. An outage of that length runs past the 14-day notice window and lands on the 28-day deadline, and under section 6.9 interest starts accruing automatically on anything unpaid when it was due.
Disputes then go to interim adjudication under Part II.1, administered by an Authorized Nominating Authority under section 13.2. I raise this in every construction gap review because it reframes the backup conversation. A tested restore is how an Ontario builder keeps a statutory deadline.
Architecture and engineering firms invoice under the same Part I.1 clock. Our comparison of IT providers for architecture and engineering firms maps those deadlines onto the provider-selection questions.
Three mistakes I find on almost every construction intake.
Across our 41 Canadian SMB client engagements the same 3 gaps open almost every construction file. Shared logins to the project platform and the estimating tools. The approver’s mailbox running without MFA. A backup that has never once been test-restored. None of the 3 is a software problem and all 3 are fixable inside a month.
Spend order beats spend size.
The spending instinct is usually backwards. Firms ask for a firewall upgrade when the exposure is a clerk who can change banking details from an unprotected mailbox. Spend on identity and email first. The 2025 CIRA survey found 43% of Canadian organizations were targeted inside 12 months, and what landed came through people.
The “we are too small” objection does not survive the national numbers either. Statistics Canada (2024) reported that scams and fraud were the most common method behind cyber incidents at Canadian businesses in 2023, hitting 50% of impacted firms, and that recovery spending doubled to CA$1.2 billion.
A 30-person trades company with healthy receivables is exactly the right size to pay a 6-figure ransom. Attackers scan for unpatched systems and leaked credentials without pre-screening revenue. Right-sized security for that firm is its own stack rather than a shrunken enterprise one.
What does a 90-day hardening plan look like for a contractor?
Ninety days is enough to close the doors that matter, based on the rollout Fusion Computing runs for Canadian builders. Days 1 to 30 cover MFA everywhere, legacy sign-in blocked and a payment-change callback rule signed by finance. Days 31 to 60 cover endpoint detection, rebuilt project shares and segmented site technology. Days 61 to 90 cover a tested restore and the first phishing simulation.
The 90-day sequence.
| Phase | What gets done |
|---|---|
| Days 1-30 | MFA everywhere, legacy sign-in blocked, payment-change callback rule signed by finance. |
| Days 31-60 | Managed endpoint detection deployed, project-share permissions rebuilt, site IoT segmented. |
| Days 61-90 | Backup restore tested, incident plan written, first phishing simulation sent. |
I front-load the payment-fraud defences because that is where builders lose money first. Ransomware resilience lands second and the training cycle makes both stick. FC internal benchmark from Q2 2026: the first 30 days runs 20 to 40 IT-hours at a 50-seat firm. A free cybersecurity assessment shows which of the 7 controls you already hold.
If you would rather see the operational context first, our IT services for construction firms page covers the full stack from estimating servers to site connectivity. The ransomware recovery playbook walks the first 72 hours of the bad week when preparation was skipped.
Fusion Computing helps Canadian businesses across Toronto and the GTA, Hamilton and Metro Vancouver with managed IT, cybersecurity and Microsoft 365.
Free download
Network Security Checklist for Canadian Contractors
The 7 controls and the 90-day sequence above, written out as a checklist your team can work through office by office and trailer by trailer. It covers the payment-change callback rule, per-project share expiry and the segmentation checks that keep telematics off your accounting network.
Written and reviewed by Mike Pearlstein, CISSP, and mapped to the CCCS baseline controls.
No sales call required. Want the 7 controls scored against your own approval process instead? Book a consultation.
How to choose your first two controls.
My advice is to choose the 2 that stop real losses. Put MFA on every account in the approval chain, then write a callback rule for any banking-detail change and have finance sign it. Test a restore before somebody else tests it for you. Fusion Computing runs that rollout for Canadian builders in 90 days, and I would rather walk your process than sell you a product. Start here.
Frequently Asked Questions
Why are construction companies targeted by cyber attacks?
Construction firms move large recurring payments through progress draws, run on hard deadlines and connect dozens of subcontractors through shared platforms. Rapid7 ranked the sector among the top 3 most attacked industries in 2025, with Canada second by country behind the United States. Attackers know a builder facing liquidated damages will pay faster than almost any other victim.
What is progress-draw fraud?
Progress-draw fraud is business email compromise aimed at construction payments. An attacker phishes a mailbox in the approval chain, watches the billing cadence for 4 to 6 weeks, then submits altered banking details timed to a draw or holdback release. The transfer clears before month-end reconciliation. A callback to a known phone number plus dual approval on any banking change defeats it.
Get the 7 controls mapped against your current setup by a CISSP-led team before tender season →
How much should a construction company spend on cybersecurity?
For a 25 to 200 person Canadian contractor, right-sized managed security runs CA$180 to CA$250+ per user per month all-in, far below the cost of one diverted payment. Spend order matters more than spend size. Identity and MFA first, email defence second, payment verification third, because that chain is where construction firms actually lose money.
Is a small contractor really at risk?
Yes. Verizon found ransomware present in 88% of breaches at small and medium businesses, against 39% at large organizations, and the 2025 CIRA survey found 43% of Canadian organizations were targeted inside 12 months. A 30-person trades company with healthy receivables is the right size to pay a 6-figure ransom, which is exactly how attackers price it.
Are project management platforms like Procore secure?
The platforms themselves are generally well built. The exposure is access: shared logins, no MFA, and subcontractor accounts that never get revoked after substantial completion. Connect the platform to your Microsoft 365 identity with single sign-on and MFA, and rebuild per-project permissions so access expires when the project closes.
What should we do about subcontractor cyber risk?
Treat subs like the connected parties they are. Limit each sub to its own project folders, require MFA on accounts you issue and verify any payment-detail change by phone regardless of who appears to ask. Verizon found breaches involving a third party doubled from 15% to 30% in a year, and one compromised sub mailbox is the most common way draw fraud enters a general contractor.
Does site equipment and IoT really need security?
It does now. Zscaler measured a 410% year-over-year rise in IoT malware aimed at construction, and telematics units, connected cameras and trailer routers ship with default passwords. The fix is segmentation: site devices live on their own network, never bridged to the office network that holds estimating and accounting systems.
What do cyber insurers require from construction companies?
Applications now ask by name for MFA on email and remote access, endpoint detection and response, tested backups and written payment-verification procedures. A wrong answer can void coverage after a claim. Treat the application as a control checklist, because every question maps to one of the 7 baseline controls in this guide.
How fast can a construction firm reduce its cyber risk?
Materially within 30 days. MFA everywhere, legacy sign-in blocked and a written callback rule for banking changes close the draw-fraud path almost immediately. Endpoint detection and rebuilt project-share permissions land by day 60, and a tested backup restore plus an incident plan complete the 90-day baseline Fusion Computing runs for contractors.
Does PIPEDA apply to construction companies?
Yes, for the personal information a contractor holds: employee records, client contacts and payroll data. The Office of the Privacy Commissioner requires you to report breaches posing a real risk of significant harm, notify affected individuals as soon as feasible and keep records of every breach for two years. Most contractors clear that bar through the same 7 controls their insurer expects.
Contractors adding AI to the same environment should sequence governance first. Our guide to AI for Canadian field services sets out the 90-day order we run for trades and mechanical firms.
Reviewed by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited, August 2026.

