www.insurancebusinessmag.com Ransomware Threats Disrupt UK Construction Sector Operations
Article Content
- •Ransomware attacks in the UK construction sector average 24 days of downtime per incident.
- •The construction industry has become the most frequently attacked sector, surpassing financial services.
- •Regulatory pressures are increasing with the EU's NIS2 directive and UK's Cyber Security and Resilience Bill.
The UK construction industry is facing a surge in ransomware attacks, causing an average of 24 days of operational downtime per incident. In 2025, the sector saw a 410% increase in Internet of Things (IoT) malware activity. The National Cyber Security Centre reported 204 major cyberattacks in the year leading to September 2025, with construction becoming the most frequently attacked industry. Cyber incidents threaten to derail entire construction projects, especially as firms adopt digital tools like Building Information Modelling (BIM). Insurers like QBE emphasize the need for construction firms to integrate cyber resilience into project planning. The European Union's NIS2 directive and the UK's proposed Cyber Security and Resilience Bill are increasing regulatory pressures on the sector. Despite these threats, many firms still treat cyber resilience as an IT issue rather than a project risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Bam in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…