The tender pack lands, and somewhere behind the insurances, the safety management plan and the referee projects is a security schedule asking what maturity level your business has reached against the Essential Eight. It is not a mistake and it is not going away, but it is also not the most useful question a builder should be asking about cyber risk.
The more useful question is what happens when a progress claim gets diverted. That is the loss most construction businesses will actually meet, it is large, and the controls that prevent it are the same ones the tender schedule is asking about. This article connects the two. If you want the framework explained on its own terms first, start with our guide to what the Essential Eight is.
Why builders get asked twice
A builder sits in the middle of a supply chain, which means the security question arrives from both directions.
From above: the principal — a department, a council, a developer, a head contractor — has its own obligations. The Essential Eight is mandatory for Australian non-corporate Commonwealth entities under the Protective Security Policy Framework, and state and territory agencies operate their own policies that lean on the same framework. Those obligations do not stop at the agency boundary. ASD’s guidance on managing cyber supply chains makes the point plainly: an organisation transfers any cyber supply chain risk it holds to its customers. So the principal asks the head contractor, and the head contractor asks you.
From below: once you sign a head contract with a security schedule in it, you are the one who has to flow those requirements down to subcontractors and consultants, and satisfy yourself that they mean something. You go from being the party answering the questionnaire to being the party issuing it, usually in the same week. None of this makes the Essential Eight law for a private construction business; it makes it contractual, which we cover in is the Essential Eight mandatory?.
The loss a builder actually recognises: the diverted progress claim
Somebody gets into an email account — yours, your contract administrator’s, or a subcontractor’s. They do not do anything for a fortnight. They read. They learn the claim cycle, the format, the names, the tone, the approximate amounts.
Then, at the right point in the month, one of two things happens. Either a claim you have submitted is followed by a polite note advising that your banking has changed, and the principal pays a different account. Or a subcontractor’s claim arrives with amended bank details, and you pay it. Either way the money is gone before anyone notices, and the argument about who wears the loss is expensive on its own.
Construction is attractive for this because the cycle is predictable, the amounts are large, the number of parties is high, almost all of it runs on email, and security of payment legislation in each state and territory sets strict timeframes for payment claims and payment schedules. That last point is the one attackers exploit hardest: statutory deadlines create pressure to process a claim quickly, and pressure is what stops people checking.
Three Essential Eight strategies bear directly on this. Multi-factor authentication is the one that stops the mailbox being opened in the first place, and it applies to your own email and to the cloud services holding your project and financial data. Restricting administrative privileges governs who can change a payee bank account in your accounting or project management system, and who can add a user. Patching applications keeps the software that handles all of it — email clients, PDF software, browsers — current.
There is also one control that is not in the framework and belongs in your process anyway: any change to bank details, from anybody, is verified by phoning a number already on file — never a number contained in the request — and approved by a second person, with who requested, who verified and who approved recorded against the payment. It costs nothing and it is the single most effective thing in this article.
What “your IT” actually covers on a construction business
ASD states the Essential Eight was designed to protect internet-connected information technology networks, and that while its principles may be applied to enterprise mobility and operational technology networks, it was not designed for those purposes. For a building firm, that draws the boundary usefully.
In scope: head office machines and the accounting, estimating and payroll systems on them; email; your project management platform; the drawing and document repository, whether that is your own or a common data environment you are a participant in; site tablets, phones and the site office laptop; and any staff device carrying work email.
Generally out of scope: plant telematics, crane and lift controllers, site security cameras, building management systems in a handed-over building. Those carry real risk and deserve attention, but they are not what the Essential Eight was built for, and scoping them in will bog down an assessment that should take an afternoon.
The eight strategies on a construction business
| Strategy | What it means for a builder |
|---|---|
| Multi-factor authentication | A second factor on email first — email is where progress-claim fraud lives — then the project management platform, the drawing repository, accounting and estimating. It applies to third-party services too, which covers the platforms you subscribe to and, where they hold sensitive information, the ones your clients log into. |
| Restrict administrative privileges | Who can change a bank account on a supplier or subcontractor record, add a user to the project platform, or grant access to the drawing repository. The account a contract administrator uses for email all day should not be the account that can do any of those things. |
| Patch applications | PDF software matters more here than in almost any other industry — a construction business lives in PDFs, and ASD names PDF software specifically among the categories to be patched within two weeks of release, or 48 hours where the vendor rates the flaw critical. The same applies to browsers and their extensions, email clients, office software and security products, plus anything of yours reachable from the internet. |
| Patch operating systems | Site tablets and phones count, not just the office. Workstation operating systems are patched within one month; anything internet-facing on a tighter clock. Operating systems the vendor no longer supports are replaced — which usually catches the site office laptop that has been on the same build since the last project. |
| Regular backups | Project records, correspondence, RFIs, marked-up drawings, defect photos and as-builts. ASD requires backups to be retained in line with business criticality and business continuity requirements — and a builder’s criticality horizon runs through the defects liability period and any dispute after it, which can be years. Restoration must be tested, and everyday accounts must not be able to modify or delete backups. |
| Application control | Only approved software runs on the machines your people use, including the site tablets. At Maturity Level 1 this covers the folders where downloads and email attachments land — which on a construction business is a constant stream of drawings, schedules and claims from parties you do not control. |
| Restrict Microsoft Office macros | Estimating and cost-planning workbooks are the most macro-heavy documents in the industry. At Maturity Level 1, macros are disabled for anyone without a demonstrated business requirement, macros in files that arrived from the internet are blocked, macro antivirus scanning is on, and staff cannot change the setting. Note the direction of travel: a macro-enabled workbook emailed in by a subcontractor is exactly the delivery route the control exists to close. |
| User application hardening | Internet Explorer 11 disabled or removed, browsers not processing Java or web advertisements from the internet, and browser security settings staff cannot change. Straightforward on current machines; the settings-locking part is where a fleet of site devices needs some form of management capability. |
Site-based and mobile working
This is where construction diverges most from an office business, and where self-assessments quietly overstate.
- Shared site logins. A single account on the site tablet that everyone uses defeats administrative privilege separation and destroys the audit trail. If something goes wrong, “the site tablet did it” is all you will ever know. Individual accounts are the answer, and the objection is always convenience.
- Personal phones carrying work email. If a phone can open the project mailbox, it is in scope: it needs operating system updates within the required timeframe and it needs the second factor. Businesses routinely assess themselves as compliant while half the workforce reads project email on unmanaged handsets.
- Lost and stolen devices. Sites lose things. The relevant capability is being able to revoke access and wipe a device remotely, which in practice means device management, the same capability that lets you lock browser and macro settings.
- Drawings on personal devices. Photographing a drawing to send to a subbie is normal and understandable, and it moves commercial-in-confidence information onto a device you do not control. Worth a written position, particularly on government work where the drawings may be sensitive in their own right.
Plans, drawings and project records
The drawing and document repository is the asset most builders underweight. It holds commercial-in-confidence design information, sometimes for buildings where the layout itself is sensitive, and it is typically shared with dozens of external parties across the life of a project.
Two practical failures recur. Access is granted freely at the start of a project and never removed — consultants, subcontractors and staff who left eighteen months ago still hold a login. And the repository is treated as the backup, when it is a live working system: a deletion or an encryption propagates through it exactly like a legitimate change.
Set a review point at each project milestone where you check who still has access and remove those who should not. It takes twenty minutes and it is the closest thing to a free control in this article after multi-factor authentication.
When the security schedule arrives with the tender
- Read what is actually being asked, then answer it honestly, including partially. The schedule usually names a maturity level and usually asks for a self-assessment rather than a certification. Attach evidence rather than assertions, and date what you send, because maturity is a point-in-time position rather than a certificate. The full treatment, including what an evaluator means by evidence and how to write a partial answer that reads as competent, is in our guide to answering Essential Eight questions in government tenders.
- Work out your flow-down before you sign. If the head contract requires you to impose equivalent obligations on subcontractors, decide what that means in practice. Requiring a three-person subcontractor to demonstrate Maturity Level 1 will not work and both of you know it. Requiring specific controls — multi-factor authentication on email, and verification of any bank-detail change by phone to a number on file — is enforceable, checkable and addresses the actual risk you carry.
- Keep the completed schedule. The next tender asks most of the same questions, and the second response takes a fraction of the time.
Where CyberSmart360 fits
The reason these schedules are painful is not that the controls are hard. It is that they are written in language built for corporate IT, and translating them into your business is the whole job.
CyberSmart360 holds 186 controls across the Essential Eight and the ACSC Security Principles, with every control rewritten for 44 industries — 8,184 published translations. Working through the construction set, you are asked about your project management platform, your drawing repository and the tablets your site team uses, not about executables, software libraries and control panel applets.
The output is a compliance score, a gap report ranked by priority, evidence tracking and a costed 12-month remediation plan, in a dated PDF report. That is the artefact that goes into a tender response or across to a principal contractor when they ask. If you want the underlying requirements in full first, our Maturity Level 1 guide sets out everything the assessment is measuring against.
Frequently asked questions
Is the Essential Eight mandatory for construction companies?
No. It is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. For a private construction business it arrives through contracts, tender schedules, insurance renewals and head contract flow-down obligations. That is commercial rather than legal, but no less binding once you sign.
What maturity level will a tender usually ask for?
Read the schedule; it normally states one. Maturity Level 1 across all eight strategies is the realistic target for most small and mid-size builders. ASD advises achieving the same level across all eight before moving up, and its assessment guidance says you should not be assessed against Level 2 until Level 1 has been demonstrated.
Do our subcontractors have to comply as well?
That depends entirely on your head contract. Where flow-down is required, be realistic about what a small subcontractor can demonstrate. Requiring named controls — multi-factor authentication on email, and verified bank-detail changes — is more enforceable and more useful than requiring a maturity level nobody will assess.
Does our project management platform make us compliant?
No. The vendor patches their own platform, which removes part of the patching burden. Multi-factor authentication, who holds administrative access, patching your own devices, controlling what runs on site tablets, browser and macro settings, and backups of everything the vendor does not hold all remain yours.
What is the single most valuable thing to do first?
Enforce multi-factor authentication on email, then write down and circulate the bank-detail verification rule. Between them they address the loss most likely to actually happen to a construction business, and neither costs anything beyond an hour and a conversation.
Assess before the next tender, not during it
Security schedules do not arrive with generous timeframes, and the worst version of this work is doing it in the fortnight before a submission closes. A dated assessment sitting on file, refreshed annually, turns a scramble into a copy-and-paste. The free 7-day trial at cybersmart360.com needs no credit card and covers one user and one assessment. Detail is on the plans and pricing page.
This article is general information about a security framework and the obligations that commonly sit around it. It is not legal, tax or professional advice, and it does not replace advice specific to your business or practice.