Construction has not historically been a primary target for attackers, who have traditionally favored finance, healthcare, and the legal sector. However, we are recently witnessing a paradigm shift. Today, a company's sector, size, or field no longer matters. Cybersecurity concerns everyone. Construction firms, the real estate industry in general, architecture, and engineering are not immune to the threat. As in other sectors, the trend is toward accelerated digitalization and evolving work methods (remote work, cloud computing, etc.) within the real estate industry. The sector has become aware of the risk and is strengthening its security posture. Is this enough today? What are the characteristics of this rapidly changing sector?

Table of Contents
Current Situation
What do we mean by the real estate sector?
The real estate sector is divided into 3 main business areas:
- Production and Development
- Transaction Services
- Property Management
This includes real estate agencies, property developers, real estate agents, property administrators, property management firms, and rental and co-ownership managers. It also encompasses architects, construction companies, and all activities related to civil engineering, engineering, etc. The list of stakeholders is long. In France, this represents 213,534 companies. In Spain, the economy is primarily made up of micro-enterprises, with the highest percentage belonging to the service sector.
Cyber Assessment
Why is the construction industry, and the real estate sector more broadly, an easy target for cyberattackers?
- Investments by construction companies in this area lag behind other sectors. This lack of cyber maturity can be explained by theabsence of regulations, as well as a lack of preparation. 74% of companies in the real estate sector are not prepared for cyberattacks.
- Another important point: the lack of awareness among employees also creates vulnerability, paving the way for cyber attackers. The sector hires many contractors and temporary workers who are not always familiar with cyber risks.
- The industry also has a cash flow that is very significant. It is expected to reach $15 billion by 2030, with the global industry projected to grow by 42%. This might lead one to believe that companies would be more likely to pay in the event of a ransom demand...
- Another significant factor is that the sector holds valuable resources that catch the eye of attackers: strategic data. This is the case, for example, during the construction of nuclear or hydroelectric power plants. These projects are highly strategic for a state or a competitor.
- Finally, the real estate sector holds a substantial amount of personal data, the oil of the 21st century. Confidential or financial information, as well as employee or client data, are all attractive targets for hackers.
- Lastly, the sector is undergoing a major technological shift (virtual reality, robotics, machine learning). This transformation is both a strength and a weakness—a weakness because the entire infrastructure is not always adequately secured. This shift increases the digital footprint and, with it, the attack surface for construction companies.
In practical terms
Key figures:
In two years, the number of cyberattacks against real estate players in the United States has increased tenfold, resulting in total losses of $56 million.Capital - Real estate, the new preferred target for hackers-2018
These statistics are confirmed by another survey; the 2021 KPMG real estate industry report revealed that "30% of organizations had experienced a cybersecurity event in the last two years, and only 50% of organizations stated they were sufficiently prepared to prevent or mitigate a cyberattack."
Nature of attacks
The attackers' primary motivation remains financial gain. "71% of all cyberattacks are financially motivated," but sabotage, to eliminate or weaken the competition, and espionage follow. Overall, the construction sector faces the same threats as other sectors, namely:
Ransomware
Cybercriminals could take control of computer networks and hold them for ransom or obtain information that could be used to commit fraud and other crimes. Real estate is targeted for financial reasons, and attackers do not hesitate to practice double or even triple extortion.Here are a few examples:
- Bird Construction, a Canadian company, suffered a ransomware attack orchestrated by the Maze group in December 2019. The ransom demand was $9,000,000.
- In January 2020, the company Bouygues Construction was the victim of a ransomware attack. 237 workstations were encrypted.
- Bam Construct was the victim of a cyberattack following a vulnerability discovered on the company's website in May 2020.
- The company Ronmor Holdings, a real estate developer, was hit by ransomware at the end of September 2021. Behind the attack was REvil. 755 GB of data was stolen.
Phishing
Phishing attacks are commonplace, with the goal of collecting personal information. The most frequent attacks are business email compromise attacks. BEC or whaling and spear-phishing.Here are a few examples:
- Solid Bridge Construction, an American company, fell victim to this. The cost of the operation was $210,312.00.
- In December 2021, a French real estate developer (Sefri-Cime) lost 35 million euros when an attacker impersonated the company's CEO to demand wire transfers.
Data theft
Construction companies hold highly sensitive information that can be of interest to both competitors and foreign states. Intellectual property, patents, and company expertise are a gold mine for attackers. Tender data can provide a competitive advantage. All of this data will catch the eye of a cybercriminal.Here is an example:
- In 2019, First American suffered a data breach that exposed 885 million customer records.
Attack vectors
- The insider threat is common in this industry. The case of an employee leaking data is unfortunately frequent and cannot be explained solely by greed. Often, the motivation lies elsewhere; it may stem from a lack of recognition, ambition, or pride, leading the individual to steal company information to succeed elsewhere. Revenge is another possible explanation.
- Other threats come directly from states when it comes to highly strategic real estate projects. This is the case for the construction of nuclear power plants or hydroelectric dams, for example.
- The supply chain: Construction projects often involve multiple entities such as suppliers, subcontractors, and partners, which weakens the security chain. If these entities are compromised, the entire chain potentially becomes vulnerable.
- Criminals also target cloud providers to access data. It is important to understand the risks associated with storing sensitive data without appropriate security precautions.
- IoT : Smart buildings are made up of complex, interconnected systems with vulnerabilities that serve as entry points for cybercriminals. Currently, there are more than 12 billion connected objects worldwide.
Consequences
Legal implications
Every company must ensure the protection and confidentiality of customer data and secure online purchases and banking information for clients, suppliers, and more. In Europe, failure to comply with the GDPR can lead to legal and financial penalties. In France, there is now a label called R2S for "ready2services." The Smart Building Alliance and Certivéa established this label for commercial buildings. It aims to assess the quality of IT services provided by a site and their interoperability through four levels of certification. https://r2s.certivea.fr/
Financial impact
The slightest system malfunction can lead to serious financial consequences.
- A data security breach can have a major impact on operations. If a machine stops working or an IT system becomes inoperable, the entire project falls behind schedule, resulting in daily financial penalties. The construction industry relies heavily on the ability to deliver projects on time.
- This can also lead to an inability to respond to a call for tenders, resulting in the loss of massive contracts.
- An attack damages the trust established between a company and its clients and can tarnish its image and online reputation.
- To this, we must add indirect costs, including data recovery, personnel and equipment expenses, and expert fees.
In terms of security
A security incident can lead to chaos. Protecting critical infrastructure must remain a priority. Imagine a connected crane losing control. We can expect—and are already seeing—increasingly sophisticated threats, particularly with the advent of AI, machine learning, and quantum computing, which will require significant adaptation and highly specialized skills.
Understanding the risk
Not all construction companies face the same level of risk. It depends on:
- The type of company
- The jurisdiction
- The quantity and nature of the personal information held
- How well an organization is prepared to manage a security incident
It is therefore essential for these organizations to conduct a clear strategic risk assessment. Everyone plays a role in this process. Risks must be quantified, qualified, and reported in simple terms to management, who will then allocate budgets and initiate a genuine protection strategy by implementing the most appropriate technology. In this regard, the priority is to detect and neutralize incoming attacks before they harm the company, which is the daily value proposition of TEHTRIS.
TEHTRIS solutions
TEHTRIS works with companies in the real estate sector to strengthen their security posture and protect them from cybercriminals. Real estate companies need to protect their entire information system, deploy their chosen solution quickly and easily, and find a solution compatible with all operating systems in their fleet. In this context, TEHTRIS recommends, as a priority, the deployment of EDR for workstation protection and MTD, for protecting phones and tablets. Thanks to automated remediation, IT and production tools remain unaffected. Your IT infrastructure is protected 360° against the most advanced threats, powered by hyper-automation, TEHTRIS's CYBERIA artificial intelligence, and TEHTRIS CTI Cyber Threat intelligence. Deployment is fast, and TEHTRIS provides ongoing support for your cybersecurity roadmap. TEHTRIS EDR and TEHTRIS MTD are two modules of the TEHTRIS XDR Platform. This modular, customizable, and trusted platform is the augmented detection and response solution designed for lightning-fast cyber threats. The TEHTRIS XDR Platform monitors, analyzes, detects, and neutralizes threats worldwide for major players in real estate, industry, transport, engineering, services, and government. Awarded the Cybersecurity Made in Europe label, TEHTRIS is also the only European Union vendor recognized by Gartner® as a representative XDR provider in the 2021 Market Guide for eXtended Detection and Response. TEHTRIS is also a representative vendor in the 2021 Market Guide for Mobile Threat Detection. By staying at the forefront of cybercrime trends and listening to our clients, our goal is to minimize risk and prepare for the unpredictable.SOURCES:KPMG. Securing real estate assets in a digital world.2018https://www.hka.com/cyberattacks/https://www.natlawreview.com/article/real-estate-industry-target-cyberattackshttps://minfosec.com/cybersecurity-for-real-estate-agencies/https://krebsonsecurity.com/2019/05/first-american-financial-corp-leaked-hundreds-of-millions-of-title-insurance-records/


