Protect the project, not just the paperwork.
Large invoices and a web of subcontractors make payment-redirection fraud devastatingly effective against builders. Plain-English protection for your tender pricing, project data and the security requirements your insurer and head contractor now expect.
Dossier 04 / 10
Construction
Large invoices and a web of subcontractors make payment-redirection fraud devastatingly effective.
- Privacy Act 1988
- Contractual & insurance security requirements
- Supply-chain due diligence
What the obligation actually requires of you.
- 01
Privacy Act 1988
Where the Privacy Act applies, tenders, subcontractor details and client information need reasonable protection; coverage depends on the entity and the information it holds.
- 02
Contractual & insurance security requirements
Head contracts and cyber-insurance policies increasingly name specific security controls as renewal or tender conditions — controls your business needs to prove, not just claim.
- 03
Supply-chain due diligence
A subcontractor's weak security can become your breach. Project-based businesses need to know who touches their data, and how well it is actually protected.
controls to review
Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.
A subcontractor invoice targeted for duplicate payment.
Illustrative scenario — In this example, Midway through a multi-million-dollar commercial fit-out, the project accounts team received an email — apparently from a long-standing subcontractor — requesting updated bank details ahead of a progress payment. The sender's domain was one character off the real one.
Example response — A suitable response is to pause the payment, verify supplier details through a known contact, review mailbox rules and limit supplier access to the project need.
What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.
Control evidence to collect
Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.
Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.
Run it yourself, before we ever speak.
- Payment and bank-detail changes verified by phone before funds move, every time
- MFA enforced across project-management and accounting platforms
- Subcontractor and supplier access reviewed and time-limited to the project duration
- Tender and design documents access-controlled and watermarked
- Cyber-insurance and head-contract security clauses mapped against your actual controls
- Site and office devices covered by managed endpoint protection
- An incident response plan naming a point of contact for principal contractors
These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.
The questions this vertical always asks.
You hold tender pricing, project IP, subcontractor bank details and payment authority — exactly what invoice-fraud and supply-chain attacks target, whether or not it counts as personal data.
Insurers are beginning to write security controls into renewal terms. Meeting them now, on your terms, is easier than meeting them under pressure at renewal.
Yes. We assess where your exposure actually sits — often a subcontractor's compromised email — and harden your side of that relationship: verification steps, access limits and monitoring.
Find out exactly where your project data is exposed.
The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.
Melbourne VIC · Australia · gmanit.com.au