Skip to content
Construction · Australia

Protect the project, not just the paperwork.

Large invoices and a web of subcontractors make payment-redirection fraud devastatingly effective against builders. Plain-English protection for your tender pricing, project data and the security requirements your insurer and head contractor now expect.

Dossier 04 / 10

Construction

Large invoices and a web of subcontractors make payment-redirection fraud devastatingly effective.

  • Privacy Act 1988
  • Contractual & insurance security requirements
  • Supply-chain due diligence
Named obligations

What the obligation actually requires of you.

  1. 01

    Privacy Act 1988

    Where the Privacy Act applies, tenders, subcontractor details and client information need reasonable protection; coverage depends on the entity and the information it holds.

  2. 02

    Contractual & insurance security requirements

    Head contracts and cyber-insurance policies increasingly name specific security controls as renewal or tender conditions — controls your business needs to prove, not just claim.

  3. 03

    Supply-chain due diligence

    A subcontractor's weak security can become your breach. Project-based businesses need to know who touches their data, and how well it is actually protected.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Commercial builder, QLD

A subcontractor invoice targeted for duplicate payment.

Illustrative scenario — In this example, Midway through a multi-million-dollar commercial fit-out, the project accounts team received an email — apparently from a long-standing subcontractor — requesting updated bank details ahead of a progress payment. The sender's domain was one character off the real one.

Example response — A suitable response is to pause the payment, verify supplier details through a known contact, review mailbox rules and limit supplier access to the project need.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, before we ever speak.

  • Payment and bank-detail changes verified by phone before funds move, every time
  • MFA enforced across project-management and accounting platforms
  • Subcontractor and supplier access reviewed and time-limited to the project duration
  • Tender and design documents access-controlled and watermarked
  • Cyber-insurance and head-contract security clauses mapped against your actual controls
  • Site and office devices covered by managed endpoint protection
  • An incident response plan naming a point of contact for principal contractors

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Get the Construction compliance checklist

A practical web checklist for your sector’s controls and obligations. No call. No obligation.

Before you call us

The questions this vertical always asks.

Find out exactly where your project data is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au