91视频

How to strengthen defenses against mounting cyber risks | Opinion

By: Paul Quandt//December 20, 2024//

How to strengthen defenses against mounting cyber risks | Opinion

Paul Quandt//December 20, 2024//

Listen to this article
Paul Quandt

By 2026, new rules will require some 316,000 organizations involved in critical infrastructure聽to report cyber breaches almost immediately (within 24 hours to 72 hours, depending on the type of intrusion) to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

This includes many of Oregon鈥檚 construction firms that have been among the beneficiaries of the 2021 Infrastructure Investment and Jobs Act,聽which for projects improving airports, ports and waterways, roads and bridges and more.

聽on reporting and on what a 鈥渃overed cyber incident鈥 consists of are complex and detailed, understandably, given these assets鈥 role in a smoothly functioning society. But they also raise an issue of broader concern to an industry that is fast expanding its tech investment: How prepared are construction firms for the exposures created by their increasingly digitized environment?

Most aren鈥檛. In fact, three-fourths of construction firms聽. That鈥檚 a real failure when聽the sector most breached聽in 2023 by bad actors, at 1.5 billion records, was construction/real estate.

For all the transformative power of construction technology 鈥 from improved productivity and safety to more cost-effective and sustainable building practices 鈥 the industry needs to do a better job of understanding the scope of risks produced by its increasing reliance on tech solutions. Even more important is to highly prioritize education, planning and prevention.

Here鈥檚 how construction firms can strengthen their defenses against the intensifying risk of cybercrime.

Understand types of cyber intrusions

Cybercriminals are resourceful at finding openings in an organization鈥檚 defenses. Three of the most common types of cyberattacks against construction firms include:

  • Ransomware attacks.聽These start with phishing, in which fake emails and messages trick employees into downloading malicious software that, once in the system, encrypts files. They are then held until payment is made to release them. But costs aren鈥檛 only financial because the disruption can delay work and cause cost overruns and quality problems. Further, when business information is at risk of exposure, vendors and clients are also jeopardized. Financial penalties and lawsuits also may result due to missed deadlines.
  • Data theft.聽Whether through ransomware or social engineering schemes, this is a significant issue for contractors. Not only confidential intellectual property like design documents, patents and bid strategies are targeted. Also at risk is Social Security and credit card information, along with personal information of employees, vendors and customers.
  • Fraudulent funds transfer.聽Substantial funds are transferred via online banking between construction firms and business, customer and vendor accounts. Cybercriminals target them, using phishing emails or phone calls to trick victims into responding. People need to become aware and trained to avoid becoming victims of these scams.

Add protections against cyber crime

It takes a comprehensive strategy built around the three pillars of education, planning and prevention to ensure a construction firm鈥檚 protections will minimize cyber risks while also establishing a culture of digital security. The most important components include:

  • A comprehensive cyber risk assessment.聽This identifies vulnerable assets 鈥 from systems to customer data to intellectual property 鈥 along with threats, whether from bad actors or failures due to natural disasters. Risks should be evaluated and prioritized, controls selected to manage them, and the environment monitored for changes.
  • Train employees in cyber safety; refresh often.聽Employees who are unaware typically open the door to cyber intrusions. In addition to providing guidelines on safely handling confidential information, training should identify common risks and new ones as they emerge. It鈥檚 also critical to institute and train people in processes for confirming changes to vendor and/or client bank routing and reporting questionable cyber activity.
  • Good聽hygiene improves cyber health.聽Good practices include multifactor authentication 鈥 an extra security layer for accessing sensitive information like bank accounts, invoices and legal documents. This is essential for email and across the corporate network. Strong passwords, regular software updates (including antivirus programs) and properly configured firewalls are also important.
  • Guard against external exposures.聽Many cyber breaches derive from lax practices of outside partners 鈥 software services, subcontractors or vendors and suppliers. These risks should be evaluated and contractual relationships reviewed to ensure their cybersecurity practices are up to snuff.
  • Ready a response plan.聽It鈥檚 critical to be able to mobilize fast if a cyberattack occurs. Have experts lined up and ready to help 鈥 IT, incident response teams, insurance brokers and breach response counsel. Knowing what聽not聽to do will also help mitigate the damage.
  • The right insurance (and broker partner) matters.聽Cyber insurance has never been more important. What鈥檚 key, though, is to use the services of insurance professionals who specialize in the construction industry and understand the cyber coverage particulars that apply to it. The right partner will be an invaluable resource for firms looking to strengthen their cyber defenses.

Paul Quandt is a senior commercial lines insurance executive for global insurance brokerage HUB International. He serves the Oregon region. Contact him at 971-224-1914 or [email protected].

The opinions, beliefs and viewpoints expressed in the preceding commentary are those of the author and do not necessarily reflect the opinions, beliefs and viewpoints of the Daily Journal of Commerce or its editors. Neither the author nor the 91视频 guarantees the accuracy or completeness of any information published herein.



News

See All News

Commentary

See All Commentary

COMMUNITY CALENDAR