Construction is the #2–3 most targeted sector globally for ransomware in 2024–2025. In Texas, that translates to a $80B+ annual industry running its payment workflows over email — draw requests, lien releases, subcontractor ACH changes — with minimal verification. The Akira ransomware group claimed Williams Brothers Construction in February 2026. A Texas GC lost $2.5M in a single BEC wire the same year, with only $776K recovered. FBI IC3 ranks construction in the top 3 for BEC and ransomware losses nationally.
Six Incidents Defining the Construction Threat Landscape
These are not hypothetical scenarios. They are documented incidents that hit GCs, government contractors, and construction-adjacent firms — some in Texas, all directly relevant to how Texas GCs operate.
The BEC Wire Fraud Kill Chain for Construction
Business Email Compromise draw fraud is the construction sector's most financially damaging threat — and the most preventable. The FBI IC3 documented $3B+ in BEC losses in 2025 alone. In construction specifically, the attack has a predictable pattern:
-
01
Reconnaissance: Attackers identify a GC working on a large project (public bid databases, county procurement records, SAM.gov). Payment schedules and billing contacts are often in public documents.
-
02
Email compromise or lookalike domain: The attacker either compromises a subcontractor's email (via phishing or credential stuffing) or registers a lookalike domain (e.g., "acme-construction-tx.com" vs "acmeconstruction-tx.com").
-
03
Bank change request: A routine-looking email requests a change of banking information for an upcoming draw, lien release, or progress payment. The timing coincides with a known payment milestone.
-
04
Wire processed without verification: The finance team, under schedule pressure, processes the payment change without calling the vendor on a known-good number. The window between wire initiation and detection is typically 2–4 hours.
-
05
Funds dispersed: The wire hits the fraudulent account, which is immediately swept to multiple accounts and international transfers. Recovery window: hours. After 24 hours, recovery rates drop below 30%.
Ransomware on Project File Servers: The 21-Day Shutdown
Ransomware targeting construction project file servers hits differently than generic corporate ransomware. The impact is not just data loss — it's job site paralysis. CAD files, BIM models, schedules, RFIs, submittals, and estimating databases are the operational heartbeat of an active project. When ransomware encrypts them, the consequences include:
-
⟶
Schedule disruption: Without current drawing packages and RFI logs, subcontractors cannot proceed — they're working blind. Material delivery windows, concrete pour schedules, and equipment rental commitments cascade.
-
⟶
Contract liability exposure: Most GC contracts include liquidated damages for schedule delays. A 21-day ransomware downtime on a $50M project with $10K/day LDs = $210K in contract penalties, separate from recovery costs.
-
⟶
Backup infrastructure is the first target: In 2024, 94% of ransomware attacks targeted backup infrastructure before encrypting production data. Standard network-attached backups are not safe. Offline, immutable backups are the only reliable recovery path.
-
⟶
Field laptops are the entry point: Ransomware enters through a compromised field laptop or project manager's device — then spreads laterally across a flat network to the project file server. Network segmentation stops the spread; EDR on field devices catches the initial compromise.
The Regulatory Stack: TDPSA, CMMC 2.0, and FAR 52.204-21
Texas construction GCs face a four-layer regulatory exposure. The overlapping obligations create both risk and competitive advantage — firms that get ahead of compliance have a demonstrable edge in federal and municipal procurement.
IRS WISP — A Requirement for GCs with Employee and Payroll Data
One frequently missed compliance requirement: the IRS Written Information Security Plan (WISP), mandated under the Safeguards Rule for any business that handles employee tax information. For GCs with W-2 employees and 1099 subcontractors, the WISP requirements include designated personnel, access controls, incident response procedures, and annual risk assessments. The IRS Publication 4557 provides the framework. This overlaps significantly with TDPSA's administrative safeguards requirement — a well-structured CoreRecon engagement covers both simultaneously.
30/60/90 Hardening Roadmap for Texas GCs
Days 1–30: Stop the Most Likely Losses
-
1
Enable MFA on all email and accounting software — Microsoft 365/Google Workspace, Sage/Viewpoint/QuickBooks, and any ERP. Before end of Month 1. This is the single highest-ROI security investment for a GC.
-
2
Implement callback verification SOP — any change of payment bank account triggers a direct phone call to the requestor on a known-good number before processing. Write it down. Sign it off. Train the finance team. This alone stops the $2.5M BEC scenario.
-
3
Deploy managed EDR on all endpoints — office computers, field laptops, project manager tablets. Prioritize finance team and PM computers first. A field laptop is often the first device compromised.
-
4
Verify backup integrity — confirm existing backups are running, test a restore, and move at least one backup copy offline/immutable. In 2024, 94% of ransomware attacks targeted backups first.
-
5
Write a one-page IR quick reference — legal counsel contact, IT provider, cyber insurance claim number, and FBI IC3 filing process (ic3.gov). Post it. Do not search for this during an active incident.
Days 31–60: Layered Defense
-
1
Segment project file servers from general corporate network. Ransomware spreading from IT to file servers was the mechanism in the Bouygues and most other construction incidents. VLAN architecture documented in a System Security Plan (SSP).
-
2
Harden email security — implement SPF, DKIM, DMARC with p=reject mode. Add BEC-specific email filtering tuned for construction payment workflow patterns. Lookalike domain detection.
-
3
Audit Procore/Autodesk ACC access controls — review user permissions, enforce MFA on platform accounts, implement conditional access tied to device compliance. A compromised Procore account gives attackers visibility into your entire payment schedule.
-
4
Begin subcontractor security survey — assess top 5 subs for basic controls (MFA, EDR). Establish minimum requirements for future subcontracts. DFARS flow-down means your CMMC exposure includes your sub tier.
Days 61–90: Compliance and Resilience
-
1
CMMC gap assessment — if you work on any DoD project in Texas, conduct a NIST SP 800-171 gap assessment and build your POA&M now. Phase 2 C3PAO assessments begin November 2026. Assessment wait times are already 6–12 months.
-
2
TDPSA data mapping — identify all personal data covered by TDPSA (employee records, subcontractor payroll, W-9s, client data). Document data flows and consumer rights fulfillment process.
-
3
Cyber insurance review — confirm your policy covers wire fraud/BEC AND ransomware, and that you can demonstrate the controls your insurer requires. 40%+ of claims were denied in 2024 due to missing MFA, EDR, or backup testing documentation.
The SDVOSB Advantage for Federal Construction GCs
Service-Disabled Veteran-Owned Small Business (SDVOSB) certification opens federal set-aside competition pathways at Fort Cavazos, JBSA, Lackland AFB, Fort Bliss, Corpus Christi NAS, and Red River Army Depot. For federal construction GCs in Texas, working with an SDVOSB cybersecurity partner who understands CMMC 2.0 creates two advantages: (1) it checks a federal procurement requirement box while securing your network, and (2) it gives you a cybersecurity partner who has been through the DoD compliance documentation process before and knows what C3PAO assessors actually look for in an evidence package.
CoreRecon is SDVOSB-certified, Texas-based, and the only MSSP in the state with published pricing and a documented 30-minute SLA for construction sector clients.
Get Your TX Construction Security Assessment
30-minute call with a construction security specialist. We review your BEC exposure, CMMC gap, project file server topology, and EDR coverage — at no cost. Written report delivered in 14 days.
Get Free Assessment →Or download the full TX Construction Threat Brief (PDF) with 32 verified sources.