A civil contractor opens a prequalification questionnaire for a state agency and finds a section headed information security. It asks whether multi-factor authentication is enforced, how often backups are tested, whether the business aligns to the Essential Eight, and what its data breach notification process is. The contractor builds roads. The questions look like they belong in a different industry.

They do not, and the reason is worth understanding properly, because once you see it the questions stop being arbitrary and the right answer becomes obvious. The client is not worried about your business being attacked. The client is worried about being attacked through you.

Why a civil contractor is being asked at all

Large organisations have spent years hardening their own systems. The remaining soft entry is the supply chain — hundreds of smaller businesses that hold their data, connect to their systems, receive their emails and get paid by them. A contractor is a credible route in.

Look at what a civil contractor actually holds for a single government job:

  • Design drawings and specifications, sometimes for assets the client would rather not have publicly mapped — water, power, rail, custodial or defence facilities.
  • Site security arrangements, access procedures, gate codes, key registers and induction records.
  • Client staff names, mobile numbers and email addresses, used daily.
  • Credentials for the client’s document management, portal or project system.
  • Commercial information — rates, tender pricing, contract values, claims positions.
  • Personal information about your own workers and about the client’s — licences, medicals, next of kin, bank details.

A contractor’s compromised mailbox gives an attacker legitimate-looking access to all of it, plus a trusted identity to send from. That is the risk being priced, and it explains why the questions are proportionate to the client’s exposure rather than to your revenue.

Where the questions come from

DriverWhat it produces in a tender
Government agency ICT and procurement policyGeneral information security questions in prequalification and in tender schedules, usually referencing national cyber security guidance
Critical infrastructure obligations on the clientWater, energy, transport, communications and some other asset owners carry statutory risk management obligations that extend to supply chain risk, which flows down as contractor requirements
Defence security requirementsThe most demanding tier — membership of the defence industry security program, personnel and facility requirements and specific ICT controls. Covered in our guide to defence infrastructure tenders
Privacy law and breach notificationQuestions about how personal information is handled and what happens if it is exposed
Tier 1 head contractor risk managementFlow-down clauses in subcontracts, sometimes with audit rights and minimum control requirements
Digital delivery requirementsWhere the project uses a common data environment or a model-based workflow, the security of the environment is part of the delivery method — see digital engineering and BIM in tenders
The client’s own incident historyAn organisation that has had a supply chain incident asks much harder questions afterwards. This is the most common reason the questions appear suddenly

What the questions actually ask

Despite the variety of drivers, the questions converge on a small set. Recognising them makes preparing an answer library straightforward — and this is exactly the kind of reusable content that belongs in the structure described in our guide to building a tender content library.

QuestionWhat they are really testing
Do you have an information security policy?Whether anyone has thought about it at all, and whether there is a document to point at
Is multi-factor authentication enforced?The single highest-value control. A no here is the most damaging answer in the section
How are backups performed and tested?Whether you could recover from ransomware without paying. Untested backups are the usual failure
How do you manage patching and supported software?Whether the business runs unsupported systems that cannot be secured
How is access granted and removed?Particularly whether departed staff and finished subcontractors lose access
Do you train staff on phishing and fraud?Whether people are treated as part of the control set
Do you have an incident response plan?Whether you would know what to do, and when the client would be told
Would you notify us of a breach, and how quickly?Frequently a contractual obligation with a short deadline attached
Do you align to a recognised framework?Usually the Essential Eight, sometimes an international standard
Do you hold cyber insurance?Increasingly a stated requirement rather than a question
How do you manage your own subcontractors’ access?Whether the flow-down continues past you

The Essential Eight, translated for a civil business

The Essential Eight is the Australian government’s baseline set of mitigation strategies, published by the national cyber security authority, with maturity levels describing how completely each is implemented. It is the framework Australian tenders reference most often, and it is worth knowing in plain terms.

StrategyWhat it means for a civil SMEDifficulty
Multi-factor authenticationA second factor beyond a password for email, remote access and any cloud system. The highest-value item on the list by a wide marginLow. Usually a configuration change on systems you already have
Regular backupsBackups of what matters, held where ransomware cannot reach them, and restored as a test rather than assumedLow to moderate. Testing is the part usually skipped
Patch applicationsKeeping browsers, document readers, email clients and business software currentLow if you use mainstream software with automatic updating
Patch operating systemsKeeping computers, servers and devices on supported, updated versionsLow to moderate. Old machines running unsupported systems are the usual blocker
Restrict administrative privilegesOrdinary users do not run as administrators; admin accounts are separate and limitedModerate. Often resisted internally, and worth doing anyway
Configure macro settingsBlocking macros in documents from the internet — the classic delivery route for malware in an emailed spreadsheetLow
User application hardeningTurning off risky browser and document features that are rarely usedModerate. Usually requires help
Application controlOnly approved software can executeHigh. Genuinely hard for a small business and rarely expected at entry level

Two things are worth knowing about how this is assessed in tenders. First, most civil tenders ask about alignment rather than certified maturity, so a truthful description of which strategies are implemented and a plan for the rest is an acceptable answer. Second, the first four items on that list are achievable by almost any business in a short period at modest cost, and they carry a disproportionate share of the protective value. A contractor who implements multi-factor authentication, tested backups and current software is in a materially better position than one who has written a policy about all eight.

Do you need ISO 27001?

The international standard for information security management systems is the information security equivalent of the quality, environmental and safety standards covered in our guide to the ISO prequalification trifecta — same structure, same audit model, same certification path.

For the overwhelming majority of civil contractors, the honest answer is no, not yet, and probably not for a long time. Certification is expensive, the scope is genuinely demanding, and civil tenders very rarely require it. The situations where it becomes worth considering are narrow: work involving sensitive government systems or data, sustained work in a sector where the client requires it, or a business whose own operations have become substantially data-based.

The middle path most contractors should take is to build the management system content — policy, asset register, access control, incident response, supplier management, review — without pursuing certification. It answers the tender questions, it is genuinely useful, and it leaves certification available later. If you already hold certified quality, environmental or safety systems, the document control, competency, internal audit and management review machinery is already there and can be extended rather than duplicated.

The higher tiers: defence and critical infrastructure

Two client types impose obligations well beyond the general questions, and both are worth recognising before you bid rather than after.

Defence. Work on defence estate and for defence prime contractors can require membership of the defence industry security program at a level matched to the work, covering governance, personnel security, physical security and information and cyber security. It takes time to obtain, it is a business-level commitment rather than a project one, and it cannot be arranged during a tender period. Our guide to defence infrastructure tenders for civil contractors covers the market and the entry requirements.

Critical infrastructure. Australian law imposes obligations on owners and operators of assets designated as critical infrastructure across sectors including water, energy, transport, communications and others, requiring them to identify and manage hazards — explicitly including supply chain hazards. The obligation sits on the asset owner, not on you, but the way an asset owner discharges it is by imposing requirements on contractors. In practice this is why a water corporation or a rail operator may ask harder questions than a council for structurally similar work, and it interacts with the network access arrangements described in our guides to water authority panels, rail civil works and utility and telecommunications civil works.

The practical implication of both is the same: treat the security requirement as a go/no-go input, not a compliance detail. If the tender requires a status you do not hold and cannot obtain in the tender period, that is a bid-defining fact, and it belongs in your go/no-go assessment.

The attack that actually happens: invoice fraud

Everything above is about answering the client’s question. This section is about the thing most likely to cost you money, and it deserves more attention than the tender questions do.

The dominant financial cyber crime affecting Australian businesses is payment redirection — commonly called business email compromise. The pattern is consistent and it is almost perfectly suited to construction:

  • An attacker gains access to a mailbox — yours, a subcontractor’s, a supplier’s or a client’s — usually through a password harvested by a convincing fake login page.
  • They read quietly, learning the projects, the names, the tone and the payment cycle. This can go on for weeks.
  • They send an email, from the genuine account or from a lookalike domain, advising new bank details. It refers to a real project, a real invoice and a real person, and it arrives when a payment is genuinely due.
  • The payment goes to the attacker. It is discovered when the real supplier follows up on a payment that never arrived, often weeks later.

Construction is a particularly good target because of the volume of invoices, the number of parties, the normality of bank detail changes when a supplier restructures, and progress claim amounts large enough to be worth the effort. And the loss lands in a commercial gap: you have paid the wrong party, but you still owe the right one.

The control is not technical and it costs nothing:

  • Never change bank details on the basis of an email. Any change is verified by telephone, on a number you already hold — not one from the email — with a person you know.
  • Make it a written rule with no exceptions, including for urgent requests and requests apparently from the owner. Urgency is part of the technique.
  • Verify new suppliers’ details at onboarding, by phone, and record who verified them.
  • Enforce multi-factor authentication on email. It is the control that prevents the mailbox access the whole attack depends on.
  • Watch for lookalike domains — a transposed letter, a different top-level domain, a hyphen added.
  • Tell your subcontractors and suppliers your rule, so a change request from you is treated the same way.

This also has a contractual dimension worth thinking through. Payment to the wrong account is generally not payment under the contract, which means the debt survives and the payment regime described in our guide to security of payment in Australia continues to run against you. Recovery from a bank after the funds have moved is difficult and time-sensitive — act within hours, not days.

Ransomware and what it does to a site

Ransomware encrypts your files and demands payment. For a civil contractor the operational consequences are more serious than the IT consequences, and they are worth thinking about concretely.

Without your systems you cannot access current drawings and revisions, issue or receive purchase orders, run payroll, produce a progress claim, retrieve inspection and test records, or evidence a delay claim. Work does not stop immediately, but it degrades within days, and the records you cannot produce are precisely the ones that matter in any subsequent dispute — the quality records described in our guide to quality management plans and ITPs, the contemporaneous records that support an extension of time claim, and the documentation that supports a payment claim.

Modern ransomware also copies data before encrypting it, and threatens publication. For a contractor that means client drawings, security arrangements, commercial rates and employee personal information potentially becoming public — which converts an IT incident into a client relationship problem, a privacy obligation and a reputational event at once.

The defences are the ordinary ones: multi-factor authentication, current software, restricted administrative privileges, and — decisively — backups held where the attacker cannot reach them and proven by an actual restore. An untested backup is a plan, not a control. Test it by restoring something real, and write down that you did.

The data you did not realise you held

A civil contractor holds a surprising amount of personal information: employee records, licences and tickets, medical and fitness-for-work information, emergency contacts, bank details, superannuation, induction records for every worker who has been on site, and sometimes drug and alcohol testing results.

Australian privacy law applies to entities meeting certain criteria, with an exemption based on annual turnover subject to exceptions — and that exemption has been under active review. Two practical points matter more than the threshold question:

  • Contracts routinely impose privacy obligations regardless of the statutory position. Government contracts commonly require the contractor to handle personal information as though the legislation applied, and to notify the client of any breach within a short period. That obligation is contractual, so the turnover threshold is irrelevant to it.
  • Health and biometric information carries higher sensitivity. Medicals, fitness-for-work assessments, injury records and any biometric site access system involve information treated as more sensitive than ordinary personal information.

The proportionate response is not a compliance program. It is knowing what personal information you hold and where, limiting who can access it, not keeping it longer than you need it, and having a plan for telling people if it is exposed.

Contract clauses to read before signing

ClauseWhat to check
Breach notificationThe deadline — often very short, sometimes measured in hours — and what triggers it. A requirement to notify a “suspected” breach is much broader than an actual one
Security requirementsWhether specific controls or a maturity level are mandated, and whether you actually meet them today
Audit rightsWhether the client may audit your systems, on what notice, and at whose cost
Data location and handlingRestrictions on storing data offshore. Relevant if you use cloud services, which is most contractors
Return and destructionObligations to return or destroy client data at the end, and to certify it. Consider how that interacts with the records you need to keep for your own protection
Subcontractor flow-downObligations to impose the same terms on your subcontractors — which means passing on requirements you must then verify
Liability and indemnityWhether cyber incidents are carved out of your liability cap or indemnity. This is where a modest project can carry a disproportionate exposure
InsuranceWhether cyber cover is required, at what limit, and whether your policy actually responds
Use of artificial intelligence toolsIncreasingly restricted or requiring disclosure — relevant to tender preparation as well as delivery, and covered in our guide to AI and human expertise in tender writing

The two worth escalating for advice are the notification deadline and the liability carve-out. A four-hour notification obligation is operationally difficult for a business with no after-hours IT function, and an uncapped cyber indemnity on a modest contract is a genuine balance sheet risk.

Cyber insurance

Cyber insurance is now commonly required in government and Tier 1 contracts, and it is not covered by the policies in our guide to insurance requirements in government civil tenders — public liability, works and professional indemnity policies generally exclude it.

What these policies typically respond to varies, and the questions worth asking your broker are specific rather than general: does it cover funds transferred as a result of fraud, and under what conditions; does it cover business interruption while systems are unavailable; does it fund the incident response — the specialists, the legal advice, the notification process — which is often the most valuable part; does it cover third party liability if client data is exposed; and what does it require of you as a condition of cover. That last one matters, because policies increasingly require controls such as multi-factor authentication, and a claim can be affected if they were not in place.

On funds transfer specifically, read the wording carefully. Cover for money lost to invoice fraud is frequently sub-limited, sometimes conditional on having followed a verification procedure, and sometimes excluded. The general points in our guide to making an insurance claim on a civil job apply here too: the exclusions matter more than the headline limit, and the time to read them is before the incident.

A proportionate control set

For a civil contractor with, say, twenty to a hundred people, this is a realistic and defensible set. It answers most tender questions and it addresses the risks that actually occur.

ControlEffortWhy
Multi-factor authentication on email, remote access and cloud systemsDaysPrevents the mailbox compromise that most attacks depend on
Backups isolated from the network, restored as a test at least annuallyDays, then ongoingThe difference between a bad week and an existential event
Supported, patched operating systems and applicationsOngoingRemoves the vulnerabilities used in mass attacks
Separate administrator accountsDaysLimits what a compromised account can do
Written payment verification procedure with phone callbackHoursThe single control that stops invoice fraud
Starter and leaver process for accounts and devicesHoursDeparted staff and finished subcontractors retaining access is a common and avoidable finding
Short information security policy and acceptable use rulesHoursThe document tenders ask for, and it makes expectations explicit
Incident response plan with named contactsHoursWho to call, who decides, who tells the client and by when
Staff awareness on phishing and payment fraud, repeatedOngoingPeople are the control that matters for the attacks that actually occur
Device management for laptops and phonesDaysSite devices are lost and stolen. Encryption and remote wipe matter
Cyber insurance appropriate to your contractsHoursIncreasingly a contract requirement, and it funds the response
An asset list of systems and data you holdHoursYou cannot protect or report on what you have not listed

How to answer the tender question well

The general principles for scored responses in our guide to addressing selection criteria apply here, with three specifics.

  • Be concrete and truthful. “We take cyber security seriously” scores nothing. “Multi-factor authentication is enforced on all email and cloud accounts; backups are held offline and a restore is tested annually, last tested in March” scores. Overstating is worse than understating, because these answers become contractual representations and are sometimes audited.
  • Answer at the scale of your business. Evaluators know they are reading a civil contractor, not a bank. A proportionate, specific answer from a contractor who has clearly thought about it reads better than a generic enterprise policy pasted in.
  • Where you do not meet something, say what you are doing about it. A dated implementation plan is a legitimate answer to most alignment questions. A blank is not, and a false yes is worse than both.

One further point specific to this subject: the answer should cover the site as well as the office. Devices in vehicles, shared site laptops, surveying and machine control equipment, site cameras and access systems, and the personal phones your supervisors use for project photographs and messages are all part of the picture, and mentioning them signals that you have thought about your actual operation rather than copied a template.

Checklist

  • Is multi-factor authentication enforced on email, remote access and cloud systems?
  • Are backups isolated from the network, and has a restore actually been tested and recorded?
  • Are all operating systems and applications supported and patched?
  • Do ordinary users run without administrative privileges?
  • Is there a written payment verification procedure requiring phone callback on any bank detail change?
  • Do your staff know the rule applies even when the request appears to come from the owner and is urgent?
  • Have you told your suppliers and subcontractors what your verification rule is?
  • Is there a starter and leaver process that removes access and recovers devices?
  • Do you have a short information security policy you could attach to a tender?
  • Is there an incident response plan naming who to call and who tells the client?
  • Do you know what personal information you hold, where it is, and who can access it?
  • Have you checked the breach notification deadline in your current contracts?
  • Have you checked whether cyber liability is carved out of your liability cap or indemnity?
  • Do you hold cyber insurance, and does it respond to funds transfer fraud?
  • Does your policy require controls you do not have in place?
  • Have you listed the systems and data you hold?
  • Does your answer library contain a truthful, current information security response?

The short version

  • You are asked because the client is managing supply chain risk. You hold their drawings, their site security arrangements, their people’s details and their credentials.
  • The questions converge on a small set. Build a truthful answer once and reuse it.
  • The Essential Eight is the framework Australian tenders reference. The first four items are cheap, fast and carry most of the protective value.
  • ISO 27001 is rarely required in civil tendering. Build the management system content without pursuing certification.
  • Defence and critical infrastructure clients impose requirements you cannot obtain during a tender period. Treat them as go/no-go inputs.
  • The attack that actually happens is invoice fraud. The control is a phone callback rule with no exceptions, and it costs nothing.
  • Paying the wrong account is generally not payment. You still owe the real supplier.
  • Ransomware’s real cost is operational — no drawings, no claims, no records, and the records you cannot produce are the ones disputes turn on.
  • Backups that have never been restored are not a control. Test one and write down that you did.
  • Read the breach notification deadline and the liability carve-out in your contracts, and check that your cyber policy responds to funds transfer fraud.
  • Answer concretely, at the scale of your business, and never overstate — these answers can be audited.

Sources and further reading

This guide is general information for Australian civil construction businesses and is not legal, information security, privacy or insurance advice. Cyber security frameworks, maturity models and government guidance are revised periodically. Privacy obligations, including whether they apply to a particular business and what a notifiable breach requires, depend on the entity, the information and the current legislation, which has been subject to reform. Critical infrastructure and defence industry security obligations apply to designated entities and activities and are outside the scope of any general description. Insurance policy coverage, sub-limits, conditions and exclusions differ between insurers and policies. Always work from the current published guidance, the actual contract terms, your policy wording, and current advice from a qualified information security specialist, lawyer and insurance broker.

  • Australian government cyber security guidance published by the national cyber security authority, including the baseline mitigation strategies commonly referred to as the Essential Eight and the associated maturity model, referenced throughout §04. The strategies, their maturity level definitions and the supporting guidance are updated periodically; the descriptions in §04 are plain-language summaries for a construction audience, not a substitute for the current published guidance.
  • Australian legislation imposing risk management obligations on responsible entities for assets designated as critical infrastructure, including obligations addressing supply chain hazards, referenced in §06 as the reason some asset owners impose materially stronger contractor requirements than others for structurally similar work. The obligation sits on the asset owner; the contractor requirement is how it is discharged.
  • The Australian defence industry security program referenced in §06, membership of which may be required at a level matched to the work for defence estate and defence prime contracting, covering governance, personnel, physical and information security. Sourced in full in our guide to defence infrastructure tenders for civil contractors.
  • Australian privacy legislation, the Australian Privacy Principles and the notifiable data breach scheme referenced in §09, including the small business exemption based on annual turnover and its exceptions. The exemption and the scheme have been subject to reform review; contractual privacy obligations in government contracts commonly apply regardless of the statutory position.
  • The international standard for information security management systems referenced in §05, which follows the same management system structure as the quality, environmental and safety standards sourced in full in our guide to the ISO prequalification trifecta.
  • Related TenderBuilt guides carrying the primary-source detail referenced above: insurance requirements in government civil tenders, making an insurance claim on a civil job, security of payment in Australia, addressing selection criteria, building a tender content library, digital engineering and BIM in tenders and AI and human expertise in tender writing.

Writing a tender? Let’s write it together.

HoursMon–Fri 7am–5pm AEST