

Secure Digital Collaboration in the Construction Industry
0.0 Colophon
This publication is issued by ConTech Lab - part of Molio, in connection with the analysis project Secure Digital Collaboration in the Construction Industry (August 2025 to January 2026).
The project, which maps the construction industry’s digital vulnerabilities and solutions that strengthen security in digital collaboration, has been carried out in collaboration between DI Construction, Implement Consulting Group, COWI, Molt Wengel, Molio, buildingSMART Denmark and ConTech Lab.
Graphic design and layout by Chris Adam for Crash Creative.
ConTech Lab is the construction industry’s shared development platform, where companies collaborate to develop and experiment with new ways of using data, digitalisation and technology to create the construction of the future, a more sustainable and productive industry.
ConTech Lab shares all knowledge and learning for the benefit of the entire industry.
3.0
3.1
3.5
4.0
1.0 Reading Guide
The publication brings together knowledge and insights from dialogue with experts, workshops with companies in the construction industry, interviews, surveys, and desk research.
The publication is divided into two parts:
Part 1: The Digital Threat in the Construction Industry
Part 1 describes the threat landscape and the construction sector’s specific risk conditions, including the industry’s digital setup, IT culture, complex value chain, and the phase transitions of construction projects. The purpose is to provide a common language and an overview of risks that companies can use as inspiration for their own risk assessments.
Part 2: Solution Catalogue
Part 2 presents relevant requirements as well as recommended actions and tools to strengthen secure digital collaboration in the construction industry. The focus is on risk assessment, requirements in procurement and contracts, shared project practices including ICT, concrete technical and organisational measures, as well as examples of relevant tools and solutions.
At the end of the publication, a glossary with explanations and definitions is provided.
Who can use this publication and how?
The publication can be used by all stakeholders in the construction and civil engineering industry, but for different purposes:
• Clients and investors can use the publication to define clear, risk-based requirements for digital security in procurement, contracts, and governance.
• Consultants can use it to integrate risk assessment and information security into design, modelling, and collaboration processes.
• Contractors can use it to establish secure collaboration platforms, access management, network practices on site, and shared procedures with project partners.
• Subcontractors and suppliers can use it to understand expectations and minimum requirements, as well as document their own maturity and compliance.
How to turn the publication into action
As a reader, you can use the publication in three ways:
• As inspiration for mapping your own risk landscape (organisation, supply chain, or a specific construction project).
• As a checklist at project start-up, fx when defining requirements in procurement, selecting platforms, managing access, and agreeing on responsibilities
• As a reference for shared practices in ongoing construction projects, where security should be continuously monitored and documented.
Scope and Focus
This publication focuses on secure digital collaboration in construction and civil engineering projects. The focus is on digital workflows, systems, and data exchanges that arise when multiple companies collaborate across the construction value chain.
The publication specifically addresses:
• Collaboration across clients, consultants, contractors, subcontractors, and suppliers.
• Shared data environments and project platforms (CDE, project web, cloud solutions).
• Access and permission management in projects with many stakeholders and project phases.
• Networks and digital infrastructure on construction sites.
• Operational technology (OT), such as machinery, cranes, and sensors.
• Governance, roles, responsibilities, culture, and behaviour in digital collaboration.
The focus is therefore not only on technical IT security, but on the interaction between technology, people, and processes in cross-organisational collaboration. Primary emphasis is placed on the early and execution phases of construction projects, where the framework for digital collaboration is established and where the most significant practical vulnerabilities arise. Operations and maintenance are included to the extent that decisions made during the project phase affect information security and robustness later in the building’s lifecycle.
What is not covered by this publication?
To ensure a clear focus, the publication does not cover:
• Detailed technical configurations or product recommendations.
• Specific descriptions of vulnerabilities at individual construction sites or in named projects.
• In-depth treatment of cybersecurity in the operational phase of buildings (facility management, smart buildings, etc.), unless it is directly relevant to the digital collaboration within the construction project itself.
• Legal advice in a strict sense (the publication outlines frameworks and key considerations but does not replace specific legal or technical advice).



2.0 Introduction
Digital collaboration has become a prerequisite for efficient construction, but it has also made the industry more vulnerable. Construction and civil engineering projects involve many stakeholders, changing phases, and extensive data sharing across companies and platforms. This means that a vulnerability in one part of the value chain can have consequences elsewhere. Cybersecurity in construction therefore requires not only a focus on individual companies, but also shared methods, clear requirements, and practices that work in everyday operations on site.
This publication has been developed as part of the analysis project Secure Digital Collaboration in the Construction Industry (August 2025 to January 2026). It outlines the construction industry’s specific risk landscape and highlights solutions that can strengthen security and robustness in digital collaboration without hindering progress and productivity.
The five key takeaways are:
• The value chain is the attack surface. Cyberattacks often exploit the weakest link. Security must therefore be addressed across companies, suppliers, and collaboration platforms in construction projects.
• Project platforms and access management are among the most significant practical risk areas. Unclear roles, overly broad access rights, and lack of proper access termination create unnecessary risk, especially when projects move between phases and participants.
• Construction site networks and OT represent a growing vulnerability. A single shared network, lack of segmentation, and unpatched equipment create entry points that can, in the worst case, lead to security, financial, and operational consequences.
• Culture and behaviour are often the decisive factors. Awareness, training, and shared practices are among the most cost-effective measures and are essential to ensure compliance in practice.
• Security must be embedded from the outset and followed up continuously. Risk assessments, clear requirements in procurement and contracts, ICT agreements, and ongoing follow-up make security manageable and documentable throughout the entire project lifecycle.
The project Secure Digital Collaboration in the Construction Industry is led by DI Construction, Implement Consulting Group, COWI, Molt Wengel, Molio, buildingSMART Denmark , and ConTech Lab.
Part 1
The Digital Threat in the Construction Industry
Construction companies, like all other Danish businesses, operate under constant risk pressure. The Danish Centre for Cyber Security’s “Threat Assessment of the Cyber Threat against Denmark 2025” states that cyber threats have become a basic condition. Authorities, companies, and citizens are exposed daily to attacks from both state and non-state actors¹.
Phishing remains the most widespread type of attack². These attacks are often not targeted at a single company but are carried out broadly using large volumes of email addresses that are traded illegally.
At the same time, “social engineering” is gaining ground as a method. Here, attackers manipulate individuals into revealing sensitive information or performing actions that compromise security, often by impersonating a trusted sender and using imitation, pressure, or persuasion³.
1 samsik.dk/publikationer/cybertruslen/
2 PWC’s Cybercrime Survey 2025
For the construction and civil engineering industry, attacks can also occur on and through operational technology (OT), such as machinery, cranes, ventilation systems, and sensors. When OT is connected to networks, new attack surfaces emerge. In the worst case, equipment may be affected or destroyed, or safety systems may be compromised.
According to PwC’s Cybercrime Survey 2025⁴, 32% of companies report having experienced a security incident. Among affected companies, phishing is the most common incident (62%). In addition, DoS attacks (28%), supplier failures (25%), and accidental sharing of sensitive information (23%) are reported as frequent incidents.
3 Cybersikkerhed: social engineering - Consilium
4 PWC’s Cybercrime Survey 2025
What types of security incidents are we dealing with?
Accidental sharing of personal data or other sensitive information
Unauthorised access to or use of information, systems, or networks
Financial fraud targeting your organisation
Social engineering
Malware (viruses, worms, or other code)

Has your organisation experienced a security incident within the past 12 months?
Example: Bouygues, France
Bouygues, a major French construction company, was hit by a ransomware attack in 2020 that began with phishing emails. With a “flat network”, where systems were closely connected without segmentation, attackers were able to move quickly and freely once they had gained access.
The result was the shutdown of numerous construction sites for three weeks and an estimated financial loss of DKK 7.5 billion.
The example illustrates how a single click on a malicious link can have disproportionate consequences for many stakeholders across a construction project’s value chain.
The Construction Industry’s Digital Setup
A significant part of the construction industry’s risk landscape is related to its long value chain: A company can be affected because an attacker finds a weak link at a partner or supplier.
“ The construction industry is characterised by many stakeholders, with companies entering into numerous partnerships and collaborating across the value chain – especially digitally. Cybersecurity in construction must therefore be considered far more broadly than just a company’s own IT systems.
Malene
Stidsen
Programme Manager for Cybersecurity, Industriens Fond
This makes it essential to consider value chain security:
• Who has access to data?
• Who can influence systems?
• Which platforms connect the collaboration?
Construction and civil engineering projects often span several years and go through multiple phases, where both governance and project management can change in nature. This means that IT governance and security procedures can become unclear or inconsistent.
Idé Finansiering Projektering Planlægning
Bygherrer Projektudviklere og Investorer
Nedrivere Arkitekter
Driftsherrer
BYGGERIETS
VÆRDIKÆDE
Materialeleverandører
Rådgivende ingeniører
Entreprenører
Renovering og transformation Drift
Udførelse
Phase transitions, such as moving from planning to execution, can make it difficult to maintain responsibility for, among other things, platforms, access control, data sharing, and preparedness. Project practices may at times conflict with the companies’ own policies regarding, for example, role allocation and security.

The Risk Landscape
In the National Risk Assessment 20255, the Danish Agency for Civil Protection encourages companies to develop their own risk assessments. To support the construction industry, the project partners behind the project ‘Secure Digital Collaboration’, together with input from the industry, have developed a consolidated risk overview for construction. This can be used as inspiration for companies’ own risk evaluations, as well as for assessing risks in supply chains and collaborations.”
The construction industry’s risk landscape highlights the following key issues:
5 Nationalt Risikobillede 2025 – Danmarks væsentligste risici og trusler

IT culture and security practices
Many companies lack clear IT security policies, and employees are not trained in the secure use of systems.
Interconnected systems
Many systems, platforms, and processes are interdependent within a construction project. A disruption in one place can create a domino effect, including in payments and deliveries, if a central actor or supplier is affected.

Inadequate user and access management
Access is often granted broadly to ensure progress. This can mean that contractors and others gain access to sensitive information they do not need, and that access rights are not removed when they are no longer relevant.
Many partners and phase transitions
Construction projects involve many different and changing stakeholders (contractors, subcontractors, material suppliers, etc.), who often have varying levels of cybersecurity maturity. This increases the risk of weak links and unclear allocation of responsibilities.
Lack of updates and legacy systems
Outdated systems without updates pose a particular risk, especially if they are connected to modern platforms.
Simple digital networks on construction sites
Many construction sites have simple or flat networks where segmentation and layered protection are lacking. When “everything is connected,” an attacker can move freely between systems and data after gaining initial access.
OT – operational technology
Machines, cranes, ventilation systems, and sensors are connected to networks, and software updates are not performed automatically. Digitalisation of OT creates new opportunities but also new vulnerabilities. In the worst case, someone could remotely control a crane or tamper with safety systems.
Physical access to the construction site
Construction sites have many visitors and temporary workers. This makes it difficult to maintain a full overview of who has access to what, both physically and digitally.
3.3 Vulnerabilities in the Office, on Site, and in the Cloud
Digitalisation has blurred the boundary between office and construction site. The technology connects everything, and therefore cybersecurity in the two environments is closely linked.
In the office, many solutions are cloud-based. Vulnerabilities can therefore be hidden, for example when data is transferred between regions, or when network and security configurations are not maintained systematically.
The contractor’s digital landscape
A particularly critical vulnerability is project platforms for document, information, and data sharing. These platforms are often financed by the client but administered by consultants or contractors.
In practice, access management is not always consistent: participants may gain access to more than necessary, and access rights are not always revoked when they are no longer needed.
Inappropriate use of digital tools also increases risk. Excel, for example, is widely used to manage critical functions such as budgets, schedules, contracts, and resources, where more secure systems should be used instead. Old spreadsheets are shared, version control is limited, and security is often insufficient. This can create both security risks and errors in critical decision-making.
On construction sites, vulnerabilities particularly arise from the use of a single shared Wi-Fi network for drones, tablets, cameras, sensors, and private devices. At the same time, many individuals with varying levels of connection to the site are present, from permanent business partners who are part of the construction project to material suppliers who may only visit the site once or twice. This increases the risk of unauthorized access and non-compliance with procedures.
Finally, the use of private devices (BYOD) for work tasks creates additional entry points that the company does not fully control within its IT infrastructure. If an employee’s device is hacked in a private context, an attacker may gain access to the company’s software, and vice versa.
3.4 IT Culture in the Construction Industry
The construction industry’s efforts in IT security are generally assessed as insufficient compared to other sectors.
Statistics Denmark’s survey from spring 20246 on IT usage in small businesses shows that small companies within construction typically focus most on software updates (79%), backup to alternative locations (76%), and network access control (59%). In 13 out of 15 measures, the industry ranks below other sectors (industry, trade/transport, information/communication, and business services).
Skills development is a particular weakness. Only 24% of companies in the construction industry offer voluntary training/education, and only 16% have mandatory training. 26% include information on IT security in written contracts, and 22% have conducted a risk analysis.
The Danish Industry Foundation’s Cyber Barometer 20247 also shows that while most sectors have increased the number of cybersecurity measures over time, this is less evident in construction.
The sector has both the fewest measures and the smallest increase.
The firgure shows the development in the average number of cyber security measures across industires from 2022 to 2024 8
Secure digital collaboration in construction: Survey
In the project, a survey has been conducted among companies in the construction industry on how they work with secure digital collaboration.
The results show that only about a quarter of the companies have a jointly agreed minimum level of cybersecurity on a project or construction site, and only just under half use secure encrypted systems to share data.
Among the most frequently mentioned vulnerabilities are the sharing of Excel sheets and links to project folders.
How is project data shared between partners?
Without special security measures
Through secure, encrypted channels or approved systems Typically via regular email or file sharing with some guidelines
IT security measures in small businesses distributed across industries in 2024
The figure shows the results from Statistics Denmark’s survey
Percentage of all small businesses

3.5 Vulnerabilities in the Construction Industry
As described, the specific conditions in the construction industry, IT culture, and limited security efforts create a number of recurring vulnerabilities. The list below is not exhaustive, but highlights the most central vulnerabilities identified in the project:
• Widespread use of simple passwords and reuse across projects and portals, often without a password manager or multi-factor authentication.
• Sharing of links to project folders where access is not restricted on a “need-to-know” basis, and where access often persists longer than necessary (lack of access control and deprovisioning).
• Physical placement of servers and insufficient protection may constitute a vulnerability.
• Vehicle data can provide access to mobility infrastructure via cars located at construction sites.
• USB drives are used to share data and documents and can transfer malware without being detected.
• Public tenders with complete project descriptions can provide unwanted insight into critical conditions if materials are freely available on municipal websites.
• Lack of IT security training increases the risk of phishing and social engineering.
• Temporary workers and visitors on construction sites often do not know security procedures.
• Shared Wi-Fi for “everything” without segmentation, and in some cases without sufficient access control.
• Sharing of documents via insecure platforms, email, or open cloud links (e.g., Dropbox/ WeTransfer).
• Backups are not always automated, and restore processes are not systematically tested, which worsens the impact of ransomware.
• Tablets and smartphones are used for critical tasks without MDM (Mobile Device Management).
• Older systems run without updates and constitute known vulnerabilities.
Part 2
Catalogue of Solutions
Digital collaboration makes construction projects more efficient, but it also means that project stakeholders must work more systematically with digital security. A leak of construction drawings, schedules, or operational data can have consequences for people, business, and reputation. Therefore, information security should be seen as an integrated part of professional project management.
Secure digital collaboration is about supporting cooperation, reducing errors, and creating confidence for all parties involved in a construction project. Good IT governance and data quality reduce risk, promote progress, and make it easier to document compliance with requirements.
Cyber security is therefore no longer an isolated IT matter, but a competitive parameter and a prerequisite for robustness in the construction of the future. It requires companies not only to manage their own security, but also security in the supply chain and in collaborative relationships. The industry needs a cultural shift where digital security becomes a natural part of tendering, collaboration, and project management—supported by shared methods and tools.
“ Digitalization makes the construction industry more efficient, but also more vulnerable.
When construction sites are as digital as they are physical, cybersecurity becomes an operational issue that must be addressed on par with occupational health and safety and quality assurance. Fundamental strengths in productivity, trust, and robustness in our projects are strengthened when we, together with the industry, take responsibility for security in our digital collaboration
Søren Cajus Head of Construction and Technology, DI Construction
The purpose of the solution catalogue is to describe common requirements, methods, and digital solutions that the industry can use as a starting point to increase security while also supporting efficient project execution.

4.1 Risk Assessment as a First Step
A fundamental prerequisite for better digital security in construction projects is systematic risk mapping or analysis. Today, only about one in five projects and construction sites consistently carry out such mapping9.
Has a cybersecurity risk assessment been carried out in projects and on construction sites?
After the risk assessment, initiatives for risk treatment are formulated.
These may include:
• Governance (roles, responsibilities, processes)
• Technical controls (access control, encryption, backup)
• Organizational measures (awareness, training, quality assurance)
Risk mapping should be carried out early in the construction process, already before the design phase, and continuously reassessed, including when the construction site is established and active. The mapping should describe which data and information assets are involved, how critical they are, and whether the project as a whole may be subject to regulatory requirements.
Risk mapping focuses on threats, vulnerabilities, consequences, and likelihood. Based on this mapping, a risk assessment can be carried out based on likelihood × consequence, making it possible to prioritize efforts so they match the level of risk.
“ Future construction projects, especially those involving critical infrastructure, require a risk-based approach to digital security. It is about understanding where the project’s real vulnerabilities lie and building governance, processes, and collaboration models around them. Only then can we create true resilience.
Emil Sahin Associate Technical Director i COWI
9 ConTech Lab Cyber Survey 2026
Idé Finansiering Projektering
Bygherrer Projektudviklere og Investorer
Nedrivere Arkitekter
BYGGERIETS VÆRDIKÆDE
Driftsherrer
Materialeleverandører
Entreprenører
Rådgivende ingeniører
4.2 Governance and Allocation of Responsibilities
Clarity of responsibility is a prerequisite for secure digital collaboration
A large part of the construction industry’s digital collaboration today takes place in cloud-based solutions and shared project platforms. Here, a fundamental misunderstanding often arises: that security “belongs to the provider.”
In practice, responsibility for enforcing the various cybersecurity-related tasks is shared, and if this is not clearly agreed upon, gaps in security arise.
In construction projects where platforms are often paid for by the client, administered by consultants or contractors, and used by many parties, the risk of unclear responsibility is particularly high.
Lack of clarification can lead to overly broad access, failure to deactivate users, unclear incident response procedures, and ultimately an increased risk of data breaches.
Is it clear who is responsible for data security in the different phases of your projects? (e.g., design, tendering, execution)
Is it clear who is responsible for data security in the different areas of your projects? (an area could, for example, be IoT)
Responsibility for shared tasks means that security is distributed across multiple parties, and that each party is responsible for different parts of the overall security.
A
simplified model for shared responsibilities in construction projects can be described as follows:
Platform and cloud provider:
• Operation and technical stability of the platform
• Basic technical security (e.g., data centers, network, physical security)
• Built-in platform security (e.g., encryption, backup capabilities, logging)
Client (Project owner):
• Overall requirements for information security in the project
• Definition of risk level and data classification
• Requirements for the use of platforms in tenders and contracts based on NIS2, CER, and ISO 19650 (see sections 4.7 and 4.8 for more information on requirements and standards)
Typical pitfalls in construction projects:
Experience from the project points to a number of recurring challenges:
• No one has clear responsibility for closing access at phase transitions or at project completion.
• The platform’s security features (e.g., logging, MFA, permission groups) are not activated.
• Users share links or export data outside secure platforms.
• Incident response for security events is unclear: who does what—and when?
These pitfalls are rarely due to lack of willingness, but rather a lack of shared clarification.
Consultant / Contractor:
• Integrating risk assessments into design and modeling processes
• Daily administration of the project platform
• Creating, modifying, and deactivating users and access rights
• Ensuring the correct use of the platform throughout the project phases
Individual project participant:
• Proper use of systems and platforms
• Protection of own login credentials
• Compliance with agreed procedures for data sharing and storage
• Document their own security maturity in relation to requirements from main contractors
If any of these roles are not clearly defined, a security “gap” will arise.
How to clarify responsibilities in practice:
To translate responsibility for shared tasks into practice, the division of responsibilities should:
• Be explicitly described in IT agreements, contracts, or project governance documents.
• Be tied to specific roles (not just organizations).
• Be followed up at project start and continuously, especially during phase transitions.
It is recommended that each project appoint a clearly responsible person for platform administration and digital security—for example, an IT coordinator or digital project manager with the mandate to enforce shared practices.
4.3 Technical Controls
Technical controls that support secure digital collaboration include:
• Software optimization
Software should be maintained securely and restricted or isolated as much as possible. The process of security optimization of existing software is called “hardening” and involves removing unnecessary functions, closing vulnerabilities, and enabling relevant security settings that often exist in systems but are not always utilized.
• Network access control
Another way to strengthen digital security is to provide different levels of access for different project partners depending on their affiliation— for example, as seen in hospitals and schools: a guest network, an administrative network, and a technical/OT network.
It is also crucial to strengthen user and permission management, especially on project platforms where sensitive information is shared.
• Scanning tools
Vulnerability scanning can provide a quick overview of exposed systems and companies’ digital touchpoints with the internet. Online services such as Shodan and Censys continuously map visible systems. This means that if a company has open ports or exposed systems, they are already registered. This information can easily be found by both researchers, competitors, criminals, and state actors. Scanningsværktøjer10
4.4 Organisational Measures
It is important to build a security culture that can function across the value chain, project phases, and disciplines
Awareness and shared habits are often the most cost-effective way to reduce cyber risk while also strengthening trust and collaboration.
Ongoing follow-up and documentation of efforts help maintain an appropriate level of security and create learning that can improve practices in future phases and projects.
Effective awareness training
The biggest challenge in working with cybersecurity is often behavior and creating understanding, motivation, and accountability among everyone working on the project or construction site.
It involves both common sense and basic security habits (e.g., not sharing sensitive drawings via email) as well as reducing human error in a fast-paced environment with many stakeholders.
Today, nearly half of construction companies do not conduct cybersecurity training11
No, we do not conduct any training Yes, employees are continuously tested and trained in cybersecurity
Yes, we do it in connection with new hires
Training works best when it is short, relevant, and frequent
Long annual sessions have limited effect. An effective approach can be microtraining in modules of 90–120 seconds, where users are trained continuously and linked to concrete, relatable risks (e.g., phishing, sharing links, handling sensitive information).
A key element is measurement and documentation. With the right systems, it is possible to track who has completed training, where the risks lie, and
Maximize the outcome of the training

which departments need targeted efforts. In this way, cybersecurity becomes both measurable and manageable.
There are also solutions where employees must pass short tests to gain access to systems or workplaces, and these solutions can also be used in construction projects.


“ We need to engage people where the risk is and integrate requirements for awareness training into tender and collaboration processes, so that all parties work from the same baseline and documentation.
Anders Balslev Partner hos Implement Consulting Group
However, attention must be paid to requirements regarding transparency and equal treatment, particularly in public procurement processes.
Follow-up and documentation
Ongoing follow-up is important to ensure that requirements and practices are adhered to. This can be done by revisiting the risk assessment, where new vulnerabilities or initiatives may become relevant.
General Reporting


Dashboards allows easy visibility and actions to ensure overview and outlines the progress an organization reaches. All results can be extracted via PDF, open API, integrations and CSV. files to support data workflows for optimal output. Certificate for employees are issued upon completion.
Documentation can be embedded in agreements (e.g., IT agreements) and in digital systems that record training and activities.
As part of collaboration, parties can set requirements for controls, documentation reviews, and spot checks. Documentation can also be supported by external schemes such as supplier declarations, the CE marking, or similar (see section 4.9 for further information).



Interactive and real-life situations based on a No blame –No shame methodology

4.5 Organisational Maturity Level
It is beneficial to understand your own maturity level in order to prioritize the next steps. For construction projects, inspiration can be drawn from Molt Wengel and buildingSMART Denmark’s maturity model (5 levels).
High risk
Low risk
1 Unorganized and vulnerable
No formal procedures. Unstructured data management. No access control.
2 Ad hoc solutions
Simple access control and loose IT policies. No anchoring in processes.
3
Structured openBIM support
IT policies also cover data and information in construction and infrastructure. Controlled access and data exchange.
4
Proactive and integrated security
Security integrated into contracts, CDE, and compliance processes. ISO 19650-5 is implemented.
5 Automated and resilient
IT security is strategic. AI and automation protect data and information.
4.6 Data Classification in Construction Projects
Not all data is equally critical – and therefore should not be treated the same
In construction and civil engineering projects, large amounts of data are shared across companies, systems, and phases.
A common data classification makes it possible to prioritize security where the consequences of a breach are greatest, and to create a shared understanding of access and sharing.
How the classification is used in practice:
• Included in risk assessments and ICT agreements
• Governs access and permissions on project platforms
• Supports requirements in tenders and contracts
• Clarifies why some data requires higher security than others
Example of a practical classification level for construction projects:
Critical data
Examples
Access information, OT/IoT data, security and contingency plans
Examples Contracts, financial data, personal data, detailed schedules
Requirements
Very restricted access, multifactor authentication, and special security measures
Examples Working documents, meeting minutes, non-critical drawings
Requirements
Restricted access (needto-know), clear permission management
Examples
General project descriptions, non-sensitive tender material
Requirements
Controlled access via a shared platform
How the classification is used in practice:
• Included in risk assessments and ICT agreements
• Governs access and permissions on project platforms
• Supports requirements in tenders and contracts
Requirements
Can be shared broadly via approved channels
• Clarifies why some data requires higher security than others
4.7 Requirements for Digital Security
Companies must be aware of both legal requirements and obligations, and clients/developers can advantageously set these early in the process, for example in tender materials and contracts.
Below are the most central legal requirements and regulations that companies in the construction industry need to understand and navigate.
Legal requirements for security (NIS2)
The NIS2 Directive sets requirements for companies regarding risk management, contingency planning, documentation, training, and reporting of cyber incidents within critical areas.
The legal responsibility lies with the owner of the construction project, which is often the client. However, the NIS2 legislation has derived consequences throughout the entire value chain. Larger companies must ensure that their partners comply with relevant requirements. This means that
consultants and contractors are also expected to meet the requirements. The requirements will also be reflected in client organizations, for example subcontractors, suppliers, and ultimately also smaller craft businesses.
NIS2 is risk-based: critical suppliers are subject to stricter requirements, while non-critical suppliers will typically face fewer requirements. Therefore, the applicable requirements will vary across projects and supplier roles.
The AB system
Companies must also be aware of their responsibilities within the AB system, which includes standard terms for construction contracts. If a cyber incident, for example, leads to delays, additional costs, or operational disruption, rules on time extensions, delay liability, defects, limitations of liability, etc., may become relevant.

Requirements in tenders
Cybersecurity is increasingly becoming part of tenders, where clients can set requirements for specific digital platforms, forms of collaboration, and documentation of security. This affects not only main contractors, but also subcontractors and suppliers, and makes cybersecurity a competitive parameter.
“ In larger projects we bid on, we increasingly see requirements regarding which digital platforms must be used for collaboration, and that our employees have the right training. That makes good sense, because ultimately it is about ensuring that we collaborate in a way based on sound judgment.
Kenneth Højbjerg Digital Lead at AFRY, and participant in the project’s workshops
Cybersecurity in contracts
Cybersecurity should be considered in contracts from the outset through risk assessments, clear requirements, and balanced sanctions. The contract should support collaboration and responsibility—not merely serve as a conflict tool.
“ Cybersecurity is not only a technical issue, but also a contractual and business matter. Many current agreements do not regulate cybersecurity, which can create problems if a cyberattack leads to delays, data manipulation, or operational disruption. In such cases, consultants, contractors, and suppliers may become financially liable, even if they are not directly covered by NIS2.
Nicolaus Falk-Scheibel Ph.D & lawyer at Molt Wengel
Almindelige betingelser

4.8 Standards Relevant to Digital Collaboration
• ISO 27001: Framework for managing information security
• ISO 19650: Information security in interdisciplinary project collaboration, tailored to the construction industry
• Risk analysis and Business Impact Assessment (BIA) as methods for prioritizing security in projects

“ The logic of the standard can be used as a governance tool throughout the entire project lifecycle—from planning to operations. ISO 19650-5 should not be seen as a technical document, but as a shared method for working in a risk-based and holistic way with information security.
Peter Bo Olsen Standardization specialist, BuildingSMART Danmark
Governance tool with ISO 19650 ISO 19650 focuses on collaboration across organizations and makes it possible to establish shared processes that can be reused and elevate the industry. The standard specifies which processes should be carried out, in what sequence, and for what purpose, and can therefore function as a practical governance tool in project work.
Information and Communication Technology (ICT) ICT covers technologies that enable construction project participants to access, edit, transfer, and store information.
ICT regulations set requirements for, among other things, ICT coordination, digital communication, project web platforms, and digital deliverables at handover. The client must ensure coordination of ICT usage among all parties throughout the construction project.
ICT agreements can be expanded with cybersecurity requirements, responsibilities/roles, procedures, governance, risk assessments, and ongoing follow-up.
Since ICT coordination involves a significant level of responsibility, it is a good idea to assign the task to a specific person—such as an ICT coordinator or an ICT manager.
“ The purpose of the ICT regulations is to ensure a harmonized and value-creating use of ICT in construction, renovation, operations, and maintenance activities in the public sector. Productivity in these areas can be significantly increased through expanded use of ICT. It is also an obvious tool for establishing concrete agreements and shared processes for secure digital collaboration.
Allan Schiøtz Head of Product for ICT at Molio
4.9 Available Tools
There are a number of tools that companies in the construction industry can benefit from when implementing measures to increase digital security in their business and their digital collaboration. Here is a selection of the tools.
Industry Foundation’s Cyber Barometer 13
Self-assessment and benchmarking with the industry provide recommendations for improvements within cybersecurity.
The recommendations are developed based on general knowledge, expert contributions, and case interviews, among others.
self-evaluation 14

An overview of important focus areas for IT security and responsible data use.
The process is designed for efficient documentation and success criteria for supervision processes, so that the business can document compliance with requirements in the self-evaluation and achieve a more robust and responsible approach on the other side.

D-mærket’s
Sikkerdigital.dk
Contains awareness materials and guides from the Danish Agency for Social Security, including a flyer with 7 tips on IT security, a flyer with 3 tips on securing IoT devices (smart products), as well as the Board’s guide and checklist for digital responsibility.

Guidelines on cybersecurity
A number of guidelines have been published for companies regarding their cybersecurity, including by the Danish Agency for Social Security, the Council for Digital Security, the Confederation of Danish Industry, the Agency for Digital Government, the Danish Road Directorate, and ISO.
Managing Security Incidents and Preparedness in Construction Projects:
What do we do if things go wrong?
In construction and civil engineering projects, timelines are tight, dependencies are many, and collaboration is often temporary.
When a digital security incident occurs, the consequences can quickly spread across companies and stop work on the construction site. Nevertheless, preparedness is often unclear:
1. Who takes the lead?
2. Who contacts the platform provider?
3. Should the work be stopped – and how does the project continue temporarily?
Is there a shared procedure for handling cyber incidents or data breaches in projects or on the construction site?
No, there is no common plan Yes, with clear roles and communication channels Partly, but only internally within our own company


Without common agreements, projects risk losing both time, data, and trust.
Data from the ConTech Labs Cyber Survey 2026 shows that there is rarely a shared procedure for handling cyber incidents or data breaches in projects or on construction sites.
A simple and shared preparedness approach makes it possible to respond quickly, limit damage, and resume collaboration in a controlled manner.





What is a security incident in construction?
In construction projects, security incidents can include:
• Compromise of user accounts (phishing, stolen login credentials)
• Unauthorized access to project platforms or folders
• Disclosure or leakage of drawings, models, or contract data
• Ransomware or disruption of central systems
• Incidents related to OT or the construction site’s network
Not all incidents are equally serious, but all should be handled systematically.


A “light” preparedness plan for construction projects
The preparedness plan should be simple enough to work in practice and shared by all project participants. A basic plan can consist of several different elements, and the following are examples for inspiration:
1 2 3 4
Clear roles and points of contact
• One person responsible for digital security in the project (e.g., IT coordinator).
• Contact information for platform provider and possibly IT operations.
• Clear decision-making authority in case of incidents.
Shared response principles in case of suspected incident
• Stop further spread (close accounts, change access codes).
• Inform relevant parties quickly and in a coordinated manner.
Temporary continuation of work
• Agreement on how critical information can be accessed temporarily.
• Consideration of offline access or alternative solutions.
• Prioritization of which functions are most critical for progress.
Documentation and learning
• Brief recording of the incident, course of events, and consequences.
• Assessment of the need to adjust procedures, access, or training.
Which solutions are missing in the construction industry?
There are not yet established common methods for secure digital collaboration when many companies work together on the same project. This makes it particularly difficult for smaller companies to navigate requirements and expectations, and may mean that they face different requirements from different clients.
“ A small company may end up having to comply with many different requirements depending on who they collaborate with. In the project, it has been pointed out several times that there is a need to develop common methods and tools that can help the industry operationalize security in practice.
Christina Juell-Sundbye Project Manager, ConTech Lab




Shared baseline for cybersecurity
A shared baseline – a minimum level of security –will make collaboration on construction projects easier and more consistent.
The solution could resemble occupational health and safety requirements in the industry. They are standardized and make it easy to know what applies. Cybersecurity should be approached in the same way—not as something “extra,” but as an integrated part of quality and operations. If the industry can agree on a level, it will be a major advantage for the construction sector’s digital collaboration.
A “lightweight” version can cover less critical construction projects. This model could, for example, include measures such as multi-factor authentication, access management, system updates, and backup of critical data, while more critical construction projects (e.g., infrastructure) require stricter requirements.
Shared competencies for the industry
A shared training program with basic modules for all project participants, combined with project- or company-specific modules, can create a common starting point.
Many contractors and consultants already use similar systems for occupational health and safety on construction sites, and cybersecurity can be incorporated in the same way.

Checklists
What can an individual company do?
• Conduct a maturity assessment.
• Establish awareness training and campaigns.
• Implement multi-factor authentication across all relevant systems.
• Strengthen access control across networks and systems.
• Ensure continuous updating of software and devices.
What can the construction project do?
The most tangible solutions include:
• Multi-factor authentication.
• Access control.
• Secure networks and segmentation.
• IoT/OT security.
At the same time, shared frameworks are crucial:
Security must be embedded in the project’s culture, structure, and collaboration model. The project can set documentation requirements regarding maturity and security measures.
Key measures in the construction project:
• Risk assessment for the project and construction site, continuously updated and clearly prioritized.
• ICT agreements that define responsibilities, roles, and governance.
• Ongoing follow-up and training, including procedures and preparedness that can be documented and updated.
Digital solutions you should keep an eye on
The digital security landscape is constantly evolving, and it can be beneficial to keep an eye on digital solutions and companies that are continuously entering the market.
A selection of solutions addressing different needs is presented here. These are examples of available solutions and should therefore not be interpreted as specific recommendations.


SagaLabs

SagaLabs is a rapidly growing startup that offers realistic cybersecurity training under the mantra “Train as you fight.” In their self-developed training platform, they train everything from companies to public authorities in realistic, scenario-based attacks such as ransomware, insider leaks, and phishing.
The training is instructor-led by professionals from the cyber front line, ensuring strong handson learning, with exercises that are realistic and up to date.
SagaLabs originates from experienced professionals from the Danish Defence, with roots in cybersecurity and software development. They combine technical insight with pedagogical strength and help organizations and authorities build strong and practically grounded cyber resilience.

Skjoldet

SKJOLDET is a proactive line of defense that warns against fraud through a simple visual “shield” before you are deceived.
Skjoldet uses proactive artificial intelligence and algorithm-based detection that protects and warns in real time against phishing, fake competitors, fake webshops, and other scams directly on the site you are visiting, even if the threat was not previously known.
SKJOLDET can be used on the go, as it is a browser extension for all devices and browsers. For private users, it is completely anonymous, and for organizations, it also enables visibility into whether employees are being exposed to fraud.
Criminals are constantly improving, but with SKJOLDET, users can see within seconds whether a site is fake.
What makes SKJOLDET unique is how proactively it protects users by delivering real-time alerts directly on the webpage before any information is entered.
made
Privacy & AI Compliance made easy!
the automated way of managing ndors, scaling your privacy efforts lding trust. Loved by customers for
to use.
Openli is the automated way of managing your vendors, scaling your privacy efforts and building trust. Loved by customers for being easy to use.


Openli


Openli helps screen vendors and digitally manage a company’s privacy settings.
The company also focuses on the ROPA, which stands for “record of processing activities,” a GDPR requirement consisting of a documented list of the company’s data processing activities.


Cyber Security Tool
Copenhagen Business Hub (Erhvervshus Hovedstaden, EHHS) offers small and mediumsized enterprises in the construction industry a “Cyber Check.” Through a series of initial questions, the company’s risk profile is identified in relation to its value chain.
The purpose is to provide a clear picture of where the company stands and which areas require attention. In addition, EHHS offers one-on-one consultations, where companies receive concrete guidance on how to best protect themselves against cyberattacks.


9.0 Conclusion
Digitalization of the construction industry is an important tool for strengthening the sector in a more efficient and sustainable direction. It therefore remains a prerequisite in this analysis that efforts related to digitalization must be made more secure, not reduced.
This publication has described the specific challenges of the construction industry and pointed to concrete actions that can support secure digital collaboration in practice. It is not about making everything equally secure, but about working risk based and proportionally, focusing on what is most critical for the project’s progress, safety, and trust.
Secure digital collaboration should be seen in the same way as occupational health and safety, as an integrated part of the professional and project related work. By integrating security early, clarity is created regarding responsibilities, roles, and collaboration across actors, which helps reduce risk and at the same time strengthens productivity and cooperation.
The project “Secure digital collaboration in construction” has shown that there is a need for shared methods and tools in the industry. The next step is for these initiatives to be anchored among key stakeholders and implemented more broadly. When digital security becomes a natural part of everyday practice, both trust, robustness, and quality in future construction projects are strengthened.



Ordliste
BYOD
Bring Your Own Device
CDE
Common Data Environment (fælles datamiljø)
CER
Critical Entities Resilience: An EU regulation that sets requirements for robustness and resilience among companies and organizations that deliver or support critical societal functions.
Cyber sercurity
In this publication, cybersecurity refers to IT security for network-connected IT systems, as defined by the Danish Agency for Social Security (SAMSIK)15. Cyber security is part of the broader concept of information security.
DoS
Denial of Service: An attack in which a system or digital service is overloaded, making it unavailable to legitimate users.
Hardening
Security optimization of software
Information security
Information security is a broad term for the set of measures implemented to protect information in terms of confidentiality, integrity (changes to data), and availability. The work includes, among other things, organizing security efforts, influencing behavior, processes for handling data, supplier management, and technical security measures.
IoT
Internet of Things
IT security
IT security concerns protecting information processed in IT systems (hardware and software) against unauthorized access, use, or modification16
Legacy-systemer Outdated systems
MDM
Mobile Device Management: An IT solution used to manage and secure smartphones, tablets, and laptops used for work.
MFA
Multi-Factor Authentication: This means verifying your identity in more than one way when logging in.
OT
Operational Technology, such as cranes
Ransomware
A type of cyberattack where data or systems are locked or encrypted, and a ransom is demanded to restore access.

ConTech Lab is the construction industry’s shared development platform, where companies in the sector can collaborate to develop and experiment with new ways of using data, digitalization, and technology to create the construction of the future, a more sustainable and productive industry.
ConTech Lab shares knowledge and learning, so the entire industry can benefit.
ConTechLab.dk
