Texas Construction  •  BEC Protection • CMMC 2.0 • TDPSA • SDVOSB

Texas Builds on
BEC Wire Fraud.
Attackers Know It.

Draw requests, lien releases, and subcontractor payments move millions weekly — over email. Akira ransomware locked Williams Brothers Construction's files in February 2026. A Texas GC lost $2.5M in a single BEC wire with only $776K recovered. CoreRecon protects the firms building Texas.

Get your free security assessment → Download the TX Construction Threat Brief →
🎖️ SDVOSB-certified 🛡️ 24/7 TX SOC ⏱️ 30-Min Response SLA 📍 Texas-Based Team
Threat Reality — Named Construction Incidents

Six incidents that prove
construction is a target.

Ransomware groups have catalogued construction as a high-value sector. BEC wire fraud specifically targets draw requests. These six incidents — including two from 2026 — document the exact attack patterns hitting GCs and their subs right now.

Feb 2026 — US GC — Akira
Williams Brothers Construction
Akira ransomware group listed Williams Brothers Construction as a victim in February 2026 — alleging theft of employee files, financial records, and project data. Double-extortion: data theft + encryption threat. Akira specifically targets mid-market construction firms using credential-based intrusion.
Source: ransomware.live, integratecyber.com (Feb 2026)
2024 — Texas GC — BEC Wire Fraud
Texas GC — $2.5M BEC Loss
A BEC syndicate impersonated a contractor and requested a change of payment bank account for a draw request. $2.5M wired, only $776K recovered — $1.7M unrecovered, dispersed through multiple accounts. Part of a national campaign targeting government–contractor payment relationships. The county processed payment without callback verification.
Source: Eftsure US, FBI IC3 complaint data (2024)
Jan 2020 — Global Top-10 GC — Maze
Bouygues Construction
Maze ransomware encrypted ~237 computers and potentially exfiltrated ~1,000 TB of data. Global IT network shut down worldwide. €10M ransom demand. Bouygues was one of the world's top-10 GCs — TX GCs face the same threat with thinner defenses.
Source: Multiple cybersecurity outlets (Jan 2020)
Early 2020 — Hospital Construction — Ransomware
BAM Construct UK
Network intrusion took BAM's website and internal systems offline to neutralize an attack. NHS hospital construction projects in Yorkshire and Humber disrupted. TX GCs working on VA/DoD/healthcare facilities face the same supply-chain exposure.
Source: UK construction press, parent company disclosures
Sep 2022 — Government Project — AlphV/BlackCat
Suffolk County, NY — $25M Recovery Cost
AlphV/BlackCat stole ~4 TB of data. County services disrupted for months. Total recovery cost exceeded $25M through 2023–2024. Government-contractor payment relationships — identical to TX municipal construction billing — were the primary target.
Source: Suffolk County disclosures, Newsday (Sep 2022)
2024 — TX Energy/Construction — Ransomware
Halliburton TX Operations
Ransomware disrupted Halliburton's TX information systems, causing multi-million dollar response and recovery costs. TX construction GCs working on petrochemical, refinery, and energy projects are in the same supply chain and face the same ransomware exposure.
Source: Recorded Future News, regulatory filings (2024)
Download the TX Construction Threat Brief 2026 →
Regulatory Stack — Texas Construction

Four overlapping obligations.
One SOC covers them all.

Texas GCs face TDPSA from the state, CMMC 2.0 for federal work, FAR 52.204-21 for any federal contract, and NIST SP 800-171 for CUI handling. Phase 2 enforcement begins November 2026 — C3PAO wait times are already 6–12 months.

State Law — Active
⚖️
TDPSA — Texas Data Privacy and Security Act
Eff. July 2024. Employee PII (SSNs, I-9s, direct deposit, health plan data), subcontractor payroll, W-9 data, and client records are all in scope. Civil penalties $7,500/violation. TX AG enforcement posture: already settled $1.4B with Meta (biometric) and $3.5M with Marriott.

CoreRecon maps: access controls, breach notification, data inventory, subcontractor due diligence.
Federal — Phase 2 Nov 2026
🏛️
CMMC 2.0 — Cybersecurity Maturity Model Certification
32 CFR Part 170 + 48 CFR Part 204. Phase 2 enforcement begins November 2026 — mandatory C3PAO assessments for Level 2. GCs working on Fort Cavazos, JBSA, Lackland, Fort Bliss, Corpus Christi NAS, or Red River Army Depot must have CMMC certification in SPRS to bid. C3PAO wait times: 6–12 months nationally.

CoreRecon maps: 110 NIST SP 800-171 Rev 2 controls, POA&M tracking, C3PAO readiness evidence package.
Federal — Active
📋
FAR 52.204-21 — Federal Contract Basic Safeguarding
Applies to any contractor with a federal contract involving Federal Contract Information (FCI). Requires 15 basic safeguarding requirements — essentially CMMC Level 1. Every federal construction contract has this requirement active now. Non-compliance risks contract suspension and debarment.

CoreRecon maps: access control, media protection, configuration management, and all 15 FAR 52.204-21 controls.
Federal — NIST Framework
🔒
NIST SP 800-171 Rev 2 — Protecting CUI
110 controls across 14 families for GCs handling Controlled Unclassified Information on DoD projects. Contractors must maintain and submit a self-assessment score to SPRS (Supplier Performance Risk System) — and defend that score during a C3PAO assessment. No valid score = no DoD contract eligibility.

CoreRecon maps: all 14 NIST 800-171 control families, SPRS score documentation, POA&M gap management.
Security Controls — Texas Construction

8 controls built for
how construction actually works.

Standard IT security frameworks weren't built for BEC draw fraud, Procore credential theft, or field laptops at distributed job sites. CoreRecon's construction controls are built around the actual attack surface of GC operations.

01
MFA on All Financial Systems and Email
Multi-factor authentication on Microsoft 365/Google Workspace email, accounting software (Sage, Viewpoint, QuickBooks), ERP systems, and all remote access (VPN/RDP). BEC and ransomware both start with credential compromise. MFA blocks the most common initial access vector. Nearly all cyber insurers now require MFA as a baseline.
02
Callback Verification for Wire/ACH Changes
Before any change of bank account instruction for a draw request, lien release, or subcontractor payment — call the requestor on a known-good number, not the number in the email. The $2.5M TX BEC loss occurred without callback verification. This SOP would have stopped it cold.
03
Managed EDR on All Endpoints Including Field Laptops
Endpoint Detection & Response (EDR) with behavioral analysis on every device — office computers, project manager laptops, field tablets, mobile devices running Procore/Autodesk ACC. Field laptops rarely get the same security attention as office systems. Construction-specific EDR with 24/7 SOC response dramatically reduces the 21-day average ransomware downtime.
04
Network Segmentation of Project File Servers
Isolating project file servers (CAD, BIM, schedules, RFIs) from general corporate network and internet-facing systems. A flat network lets ransomware spread from one compromised field laptop to every project file on the server. Segmentation limits the blast radius — one project instead of the whole firm.
05
Procore/Autodesk ACC Access Controls
Audit access controls on project management platforms; enforce MFA + conditional access policies tied to device compliance. Compromised Procore credentials give attackers direct visibility into your payment workflow and project schedules — enabling highly targeted BEC fraud. Platform security plus endpoint security is the complete picture.
06
Subcontractor Cybersecurity Requirements
Assess subcontractors' cybersecurity posture before awarding work; require cybersecurity minimums in subcontract agreements; monitor compliance throughout the project lifecycle. DFARS requires primes to ensure subs meet cybersecurity requirements. Supply chain is the #1 attack vector for breaching larger organizations via smaller vendors.
07
CMMC Gap Assessment and POA&M Management
For GCs working on Fort Cavazos, JBSA, Lackland, Fort Bliss, Corpus Christi NAS, or Red River Army Depot: NIST SP 800-171 gap assessment and POA&M build. Phase 2 C3PAO assessments begin November 2026 — with 6–12 month assessment wait times, the prep window is now. CoreRecon builds the operational evidence C3PAO assessors look for.
08
Immutable Backup for Project File Servers
Offline, immutable backups of CAD/BIM files, schedules, RFIs, submittals, and estimating databases. In 2024, 94% of ransomware attacks targeted backup infrastructure first. Ransomware groups encrypt your backups before your production data — immutable backups are the only reliable recovery path.
Sector Coverage — Texas Construction

Every construction sector
has a different threat profile.

Municipal GCs face Texas PIA exposure. Federal GCs face CMMC. Oil & gas GCs inherit TSA directives. Commercial GCs face BEC at closing. CoreRecon maps the right controls to the right threat for each segment.

🏛️
Municipal & State GCs
City, county, and state agency construction work. Texas Public Information Act (Texas Gov't Code Ch. 552) creates document security obligations — contractor employee records and subcontractor lists held by government bodies may be subject to public disclosure. BEC draw fraud is the primary financial threat in government–contractor payment flows.
🎖️
Federal & DoD GCs
Fort Cavazos, JBSA, Lackland AFB, Fort Bliss, Corpus Christi NAS, Red River Army Depot. Every federal construction project has CMMC 2.0 and FAR 52.204-21 requirements flowing to every sub tier. SDVOSB positioning + CMMC Level 2 certification creates competitive advantage in federal set-aside competitions.
Oil & Gas GCs
Petrochemical, refinery, and energy construction GCs in the Permian Basin, Eagle Ford, and Houston Ship Channel. TSA Pipeline Directive security requirements flow to major contractors. Ransomware groups targeting TX energy sector are hitting adjacent construction and supply chain firms. Halliburton's 2024 breach is the reference incident.
🏢
Commercial & Semiconductor GCs
Commercial office, retail, industrial, and semiconductor fab construction GCs on the Tesla Gigafactory expansion, Samsung Austin, Texas Instruments fab projects, and DFW semiconductor corridor. NDA and supply-chain cybersecurity flow-down requirements. BIM model and process data for semiconductor fabs are a different class of breach — competitive intelligence theft at scale.
Transparent Pricing — Construction Edition

SOC coverage from the first
field laptop to the Command tier.

Sentinel covers BEC protection basics — MFA, callback SOP, EDR, and awareness training. Fortress adds CMMC gap support, project file server segmentation, and vendor risk management. Command adds full SOC coverage, C3PAO readiness, and a ransomware recovery retainer.

Sentinel
$89 / endpoint / month
10-endpoint minimum • Month-to-month
  • MFA deployment on email, accounting software, and VPN
  • Managed EDR on all endpoints including field laptops
  • Phishing simulation with construction-specific templates (BEC draw fraud, vendor impersonation)
  • SIEM log collection — 90-day retention
  • TDPSA data inventory and vendor due diligence templates
  • 24/7 SOC alert triage
  • Monthly security posture report
FAQ — TX Construction Security

Five questions GCs actually ask.

No. Cyber insurance is a backstop, not a prevention program. In 2024, 40%+ of cyber insurance claims were denied or reduced because policyholders couldn't demonstrate required controls — MFA, EDR, documented backup procedures, written IR plan. Insurers ask for evidence before paying. The average TX construction firm breach costs $4.2M; recovery costs often run 3× the ransom demand. Insurance covers the check; CoreRecon prevents the incident.
That's exactly why attackers target small GCs. You have the same valuable data — project files, payment records, employee PII, subcontractor information — as a national GC, but significantly thinner defenses. Criminal groups run automated campaigns scanning for exposed RDP, unpatched VPNs, and weak email security across thousands of TX firms simultaneously. A 12-person GC in Austin has the same attack surface as a top-100 firm, but without the security team. 70% of data breaches hit small businesses. "Too small" is the most dangerous assumption in the sector.
CMMC and TDPSA requirements flow down to every subcontract tier. If you're a subcontractor on a Fort Cavazos housing project or a San Antonio JBSA facility upgrade, you inherit the same CUI data handling obligations as the prime — and the same regulatory exposure. A breach at the sub level exposes the prime's project data. Primes are increasingly requiring subcontractors to demonstrate security controls as a prequalification requirement. "My GC handles it" is not a compliance defense.
Procore and Autodesk implement enterprise-grade security on their platforms. That's not the problem. The risk is: (1) compromised credentials for Procore accounts give attackers direct visibility into your payment workflow and project schedules — enabling highly targeted BEC fraud; (2) your own network connecting to those platforms (field laptops, office computers) is where ransomware enters; (3) construction-specific attack chains use Procore credential theft as a step in the attack, not the endpoint. Platform security + endpoint security + MFA on those platforms is the complete picture.
CoreRecon is not a CMMC gap-assessment consultancy. We run managed cybersecurity operations — EDR, email security, MFA enforcement, backup monitoring, incident response — that produce the evidence C3PAO assessors actually look for (controlled account access, media protection, system integrity monitoring, incident response plan execution). A CMMC consultant tells you what controls you need; CoreRecon runs the controls. The POA&M that gets you to CMMC Level 2 compliance is built on an operational security program, not a spreadsheet.
Free Security Assessment — TX Construction

Get a security assessment built for your jobs.

We assess your BEC exposure, project file server topology, CMMC gap (if applicable), TDPSA data footprint, and EDR coverage — and deliver a prioritized remediation plan. No credit card. No commitment. Delivered in 14 days.

SDVOSB-certified team. Texas-based. Construction-sector specialists.

Get your free security assessment →

Delivered within 14 days  •  No credit card  •  SDVOSB-certified  •  TX-based

Texas builds on $80B/year in construction activity. Make sure yours isn't the next ransom headline. Download the TX Construction Threat Brief →

Free Tool · Texas-Calibrated IBM CODB 2025
What Does a Breach Actually Cost a Texas GC?
Plug in endpoint count, revenue band, and project data sensitivity. Get a Texas-calibrated IBM CODB 2025 breach cost estimate, TDPSA notification costs, and CoreRecon ROI — in 30 seconds.
Calculate My Breach Cost →