{"id":8480,"date":"2022-03-02T15:02:00","date_gmt":"2022-03-02T23:02:00","guid":{"rendered":"https:\/\/essential.construction\/news\/?p=8480"},"modified":"2022-03-02T15:02:00","modified_gmt":"2022-03-02T23:02:00","slug":"ukraine-invasion-heightens-contractors-risk-of-cyberattack","status":"publish","type":"post","link":"https:\/\/essential.construction\/news\/ukraine-invasion-heightens-contractors-risk-of-cyberattack\/","title":{"rendered":"Ukraine invasion heightens contractors&#8217; risk of cyberattack"},"content":{"rendered":"<p>Cybersecurity experts around the world are sounding the alarm about a potential increase in <a href=\"https:\/\/www.theguardian.com\/world\/2022\/feb\/24\/russia-unleashed-data-wiper-virus-on-ukraine-say-cyber-experts\" rel=\"nofollow noopener\" target=\"_blank\">Russia-led cyberattacks<\/a> following the country&#8217;s Feb. 24 invasion of Ukraine, and some say the construction industry could be a target. <\/p>\n<p><a href=\"https:\/\/www.cnn.com\/2022\/02\/24\/tech\/russia-ukraine-us-sanctions-cyberattacks\/index.html\" rel=\"nofollow noopener\" target=\"_blank\">According to CNN<\/a>, U.S. officials are concerned that the incursion could spill over into cyberspace, and warned businesses, banks and local governments about being vigilant against threats.\u00a0Construction companies should be on high alert as well, according to Raymond Monteith, senior vice president with HUB International Limited\u2019s risk services division.<\/p>\n<p>&#8220;Small- and medium-sized enterprises, which contractors often fall into that realm, are among the most targeted organizations, and often that is because they&#8217;re especially vulnerable to cybersecurity attacks,&#8221;\u00a0he said.\u00a0&#8220;Largely because of a lack of resources, they often don&#8217;t have dedicated IT individuals, they don&#8217;t have the internal resources that can be focused on building and maintaining and monitoring robust cybersecurity and defensive systems, so they are frequently targets and do have some significant vulnerabilities.&#8221;<\/p>\n<div class=\"figure_content\">\n<div><\/div>\n<\/div>\n<p>Raymond Monteith<br \/>\nCourtesy of HUB International Limited<\/p>\n<p>Construction has been documented as particularly vulnerable to cyberattacks such as ransomware, a type of program that can steal or encrypt sensitive files and information and demand compensation for their return or safety. Construction was the top industry hit by ransomware attacks in 2021, according to a <a href=\"https:\/\/nordlocker.com\/recent-ransomware-attacks\/\" rel=\"nofollow noopener\" target=\"_blank\">December report<\/a> from encryption software firm NordLocker, which analyzed 1,200 companies across 35 industries.<\/p>\n<p>Ransomware attacks can target firms of any size, from family-owned contractors to global giants. The proliferation of new technologies in the industry also means <a href=\"https:\/\/www.constructiondive.com\/news\/construction-suffered-most-ransomware-attacks-of-any-industry-report\/610792\/\" rel=\"nofollow noopener\" target=\"_blank\">more potential vulnerabilities<\/a>.<\/p>\n<p>These kinds of attacks don&#8217;t start out, however, with criminals in masks hiding behind monitors filled with lines of code actively &#8220;hacking the mainframe,&#8221;\u00a0but rather from ordinary people clicking a bad link or exposing their information, he said.<\/p>\n<p>&#8220;Generally speaking, ransomware and business email compromise are what we would term &#8216;public enemies No. 1 and 2&#8217;\u00a0these days,&#8221;\u00a0Monteith said.<\/p>\n<p>Countries are responding to the possibility of increased cyber threats from Russia. In the U.K., <a href=\"https:\/\/www.ncsc.gov.uk\/news\/groundbreaking-cyber-advice-will-help-construction-firms-build-strong-foundations-against-online-threats\" rel=\"nofollow noopener\" target=\"_blank\">new cybersecurity guidance for contractors<\/a>, launched by Britain&#8217;s National Cyber Security Centre along with the Chartered Institute of Building, aims to help small- and medium-sized contractors use new technologies safely.<\/p>\n<p>&#8220;By following the recommended steps, businesses can significantly reduce their chances of falling victim to a cyberattack and build strong foundations for their overall resilience,&#8221; said Sarah Lyons, NCSC Deputy Director for Economy and Society Engagement, in the press release.<\/p>\n<p>Some of <a href=\"https:\/\/www.ncsc.gov.uk\/files\/Construction_Guidance_English_Web_Version.pdf\" rel=\"nofollow noopener\" target=\"_blank\">the NCSC&#8217;s cybersecurity guidance<\/a> for contractors includes avoiding common passwords or using a default password and being careful about what information is posted on social media. The group also recommends that construction firms enable two-factor authentication, where a separate channel, such as an email or a phone number, is used to verify new logins or other security issues on company accounts.<\/p>\n<p>&#8220;Due to online threats facing the sector, the NCSC advises firms that cyber security measures are as vital as wearing a hard hat on site,&#8221; the NCSC said in the release.<\/p>\n<p>Stateside,\u00a0New York Gov. Kathy Hochul and New York City Mayor Eric Adams, along with the mayors of other large cities in New York State,\u00a0<a href=\"https:\/\/www1.nyc.gov\/office-of-the-mayor\/news\/088-22\/mayor-adams-governor-hochul-joint-security-operations-center-combat-cybersecurity#\/0\" rel=\"nofollow noopener\" target=\"_blank\">unveiled the creation of a Joint Security Operations Center (JSOC)<\/a>\u00a0last week. Hochul said last week at a press conference that the state&#8217;s institutions, governments and critical infrastructure, which includes water, transportation and power sources, were all vulnerable to attacks, <a href=\"https:\/\/www.cybersecuritydive.com\/news\/new-york-cyber-command-center\/619456\/\" rel=\"nofollow noopener\" target=\"_blank\">Smart Cities Dive reported<\/a>.<\/p>\n<p>Phil Casto, senior vice president for risk services at HUB international, <a href=\"https:\/\/www.constructiondive.com\/news\/6-steps-to-protect-your-data-and-improve-cybersecurity\/598737\/\" rel=\"nofollow noopener\" target=\"_blank\">wrote last year<\/a>\u00a0about some other steps contractors can take:<\/p>\n<p>Train employees.<br \/>\nKeep software up to date.<br \/>\nDispose of technological assets properly.<br \/>\nGive your company an annual cybersecurity checkup.<br \/>\nPurchase a cyber insurance policy.<\/p>\n<p>&#8220;Cybersecurity is never a one-and-done event. It is a continual process,&#8221;\u00a0Monteith said.<\/p>\n<p class=\"itemsource\">This item was originally posted here: <a href=\"https:\/\/www.constructiondive.com\/news\/russian-invasion-ukraine-construction-cyberattack-threats\/619631\/\" target=\"_blank\" class=\"feedzy-rss-link-icon\" rel=\"noopener nofollow\">Read More<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Cybersecurity experts around the world are sounding the alarm about a potential increase in Russia-led cyberattacks following the country&#8217;s Feb. &#8230; <a title=\"Ukraine invasion heightens contractors&#8217; risk of cyberattack\" class=\"read-more\" href=\"https:\/\/essential.construction\/news\/ukraine-invasion-heightens-contractors-risk-of-cyberattack\/\" aria-label=\"Read more about Ukraine invasion heightens contractors&#8217; risk of cyberattack\">Read more<\/a><\/p>\n","protected":false},"author":0,"featured_media":8481,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1066,457],"tags":[],"class_list":["post-8480","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-all-posts","category-construction-dive","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-33"],"_links":{"self":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/8480","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/comments?post=8480"}],"version-history":[{"count":0,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/posts\/8480\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/media\/8481"}],"wp:attachment":[{"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/media?parent=8480"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/categories?post=8480"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/essential.construction\/news\/wp-json\/wp\/v2\/tags?post=8480"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}