Skip to content

IT and cybersecurity that moves with the job.

Site offices appear and disappear. Subbies need the project files and nothing else. Every estimating and project platform wants its own logins. And head contractors now push security clauses into every subcontract. It's a lot. It's also the kind of problem we like.

What's actually different

Construction IT is logistics, not product selection.

You're probably not short on technology. What you're short on is someone who sequences it against the way the work actually runs. A site stands up, runs for six months, comes down. A subbie joins for two weeks. A design partner needs the shared building model and nothing else. A laptop gets stolen off the back of a ute. None of it is exotic. All of it needs a pattern you set once and reuse.

Then there is the security questionnaire that lands in your procurement inbox a week before tender close. The questions repeat from contractor to contractor, so a prepared firm answers in a morning. Unprepared, you spend a fortnight finding the gaps, then either lose the tender or tick "yes" on something that surfaces after an incident. We get your answers written and evidenced before the questionnaire arrives.

Site offices don't need heroic infrastructure. They need a managed router, a sensible primary link with failover, and someone watching whether it stays up. Boring. Which is the point.

Live right now

The 2026 pressure points we're actively working on with clients.

The specific asks, deadlines and enforcement actions shaping 2026 conversations in your sector.

Head-contractor security clauses are now standard

Lendlease, Multiplex, CPB, John Holland and the rest now ask subcontractors to show their security before onboarding. The usual list: multi-factor authentication (MFA), endpoint detection and response (EDR), how quickly you patch, staff training and an Essential Eight self-attestation. All of that before you get onto Procore, Aconex or Autodesk Construction Cloud. This isn't regulation, it's tender eligibility. Answer it accurately, because the contract auditors do check and an over-answered questionnaire surfaces after an incident.

Modern Slavery Act reporting is reaching subcontractors

The federal government responded to the Modern Slavery Act review in December 2024. It agreed in principle to civil penalties for reporting entities that don't comply. The $100M turnover threshold stays, but the businesses that do report are pushing supplier attestations further down the chain. Subcontract to one and you can expect an attestation form in the procurement pack.

Ransomware payments must be reported inside 72 hours

Turn over more than $3M and you have to report a ransomware payment to the Australian Signals Directorate within 72 hours. The Cyber Security Act commenced that on 30 May 2025. Most mid-size builders and engineering firms sit above the threshold, so you need an incident response plan with the reporting clock built into it.

Frameworks and regulators

Industry frameworks, regulations and audit standards for construction & engineering in Australia.

WHS record retention
Privacy Act 1988
Head-contractor security clauses
ACSC Essential Eight
Project and estimating platforms

Common questions

The things construction & engineering clients ask us first.

Our site offices have rough internet. Are we stuck?
Subbies need access to our project files but they shouldn't see the whole business. How?
Our estimating laptops are out of warranty and slow. Is that a security issue?
A head contractor sent us a security questionnaire as a condition of the tender. Can you help?

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit