Page 26 - CITS Theft Guide
P. 26
CITS Guide for Theft Prevention
- 26 -
8. Cyber Defence and Information Security
As construction sites become more connected — through BIM, telematics, smart building systems, and
IoT-enabled plant — cyber security has become an integral part of site security rather than a separate
discipline. Current industry reporting confirms that insurers and clients now expect contractors to
demonstrate a documented, multi-layered approach to protecting site data, not just physical assets.
8.1. Good Cyber Hygiene on Site
Good cyber hygiene includes strong, unique credentials and multi-factor authentication for site systems;
prompt patching of network-connected devices, including CCTV, access control, and building management
systems; segregation of site IT from corporate and BIM cloud networks where practical; and a documented
incident response plan for a cyber event, exercised in the same way as a physical security incident (see
Section 10).
8.2. Control of BIM and Sensitive Data
Building Information Modelling (BIM) software and the models it holds are a valuable target, since a full
BIM model can reveal a building's structural weak points, security system layout, and asset locations.
Access to BIM and other sensitive project data should follow a need-to-know principle: role-based
permissions, logged access, and the removal of access promptly when a role or contract ends. The diagram
below sets out this approach at a high level, aligned to ISO/IEC 27001 and ISO/IEC 27002 and to NCSC and
CIOB guidance on cyber security for construction businesses (see Annex B).
Figure 5: A need-to-know approach to BIM and sensitive site data.
8.3. Smart Buildings and IoT Vulnerabilities
Smart buildings — those with networked building management, access control, and environmental
systems — are vulnerable to cyber-attack in ways a conventional building is not; a compromised building
management system can, in principle, be used to disable alarms, unlock doors, or disrupt environmental
controls. Security requirements for these systems should be specified and tested before handover, not
left until the building is operational, and CITS recommends reference to NPSA's Cyber Assurance of
Physical Security Systems (CAPPSS) guidance.

