Cyber Liability sounds like a tech-company coverage, but construction has become one of the more frequently targeted industries for a specific kind of attack: wire fraud. Large payments, multiple parties on a project, and email-based communication make contractors an attractive target.
The Risk That Actually Hits Contractors Most
Social engineering fraud — an attacker impersonating a vendor, GC, or client by email and redirecting a legitimate payment to a fraudulent account — is one of the most common cyber losses in construction specifically, not just a generic data-breach scenario. A single successful redirect can be a six-figure loss with no clean way to recover the funds.
What a Policy Typically Covers
First-party costs: breach response, forensic investigation, data recovery, and notification costs if client or employee data is exposed.
Third-party costs: liability if a client’s data was compromised through your systems.
Social engineering/fraud coverage, if specifically added — this is often a separate endorsement, not automatically included, and worth confirming explicitly rather than assuming.
Low-Cost Prevention Worth Doing Regardless of Coverage
Verify any changed payment instructions by phone, using a known number — never one provided in the same email requesting the change.
Use two-factor authentication on email and financial accounts.
Train office staff specifically on this scam pattern, since it targets people, not just systems.
Handling client payments or data digitally? Request a Quote and we’ll make sure fraud coverage isn’t just assumed.