Cyber Risk Report

Foundations under fire. What construction firms look like from the outside.

An anonymised cross-organisation intelligence report on external attack surface exposure, supply chain risk, and the critical findings that construction companies share — whether they know it or not.

9,238
Internet-facing assets discovered
Across 5 construction organisations
829
Supplier connection vectors
Script · cert · ASN · DNS · header
54
Fix Now findings identified
Requiring immediate remediation
5/5
Organisations graded C overall
100% share the same resilience grade

What construction firms share — beyond concrete and steel

This report draws on agentless external scanning of five construction and engineering organisations across Europe and the UK. No agents installed, no credentials shared, no questionnaires completed — every finding was discovered from public data alone, the same view an attacker has before they move.

The results are striking not because any individual finding is unique, but because the same patterns repeat across every organisation in the sector. Construction firms face a common set of digital risks that are structurally linked to how the industry operates: project-based delivery, multi-party subcontractor networks, legacy web infrastructure, and a supply chain that has grown beyond what any vendor register captures.

Supplier and technology data is factual, drawn from live scans. This is what your sector looks like from the outside.

Sector benchmark

Five construction organisations — one shared risk profile

Every organisation in this benchmark was scanned independently, from public data only, using the same agentless methodology. The convergence on a C resilience grade — across firms of wildly different sizes, geographies, and technical maturity — is not coincidence. It reflects the structural security debt of an industry that has digitalised rapidly without investing proportionally in the discipline to manage what it has built.

Organisation
Assets
Suppliers
Fix Now
Fix Soon
Grade
Top Risk
Company AContractor · UK
3,173
105
15
23
C
Headers D · Software C
Company BSpecialist constructor · BE
58
7
2
0
C
Software F · DNS D
Company CEngineering consultancy · NL
3,834
94
31
24
C
Headers D · Software D · 3 AI findings
Company DArchitecture & engineering · BE
89
12
2
2
C
Headers F · DNS F · Apps D
Company EContractor · UK
2,084
43
4
5
C
Headers D · Software C
100% of organisations in this benchmark scored C — independently

No two organisations share a domain, a network, or a technology team. Yet every one of them received the same overall cyber resilience grade. A sector signal. The C grade reflects a consistent pattern: well-configured core infrastructure coexisting with critical gaps in header security, software currency, and supply chain visibility — the exact areas where construction firms invest least.

Sector-wide risk patterns

What every construction firm in this benchmark has in common

When five independent organisations show the same risk categories, you stop asking "is this firm exposed?" and start asking "why is the sector exposed?" The following patterns appeared across every organisation benchmarked.

HTTP security headers
5 / 5
Every organisation carries a D or F grade for HTTP security header implementation. Missing Referrer-Policy, X-Frame-Options, CSP, and HSTS headers are endemic — exposing project portals and client-facing applications to clickjacking, cross-site leakage, and session theft with no active vulnerability required.
Outdated software components
4 / 5
End-of-life and unpatched software libraries — including jQuery versions with known CVEs — were detected on production web assets across four organisations. In one case, a JavaScript library with publicly documented exploit code was flagged as Fix Now. Project websites and portals are built and often forgotten, accumulating software debt that never gets patched.
SSL / TLS configuration
3 / 5
Three organisations carry C or D grades for SSL/TLS configuration. Legacy cipher suites, weak certificate chains, and absent HSTS on public-facing subdomains are common — a compliance exposure as much as a technical risk where tender portals handle sensitive project data.
DNS security gaps
3 / 5
DNSSEC is absent from most domains. Two organisations carry a D or F DNS risk grade, driven by misconfigured SPF/DMARC records and missing DNSSEC — leaving them vulnerable to domain spoofing, a realistic and costly threat for firms handling high-value tender communications.
Application-layer exposures
3 / 5
Three organisations carry C or D application risk grades. Undocumented admin paths, exposed CMS dashboards, and login portals without brute-force protection were recurring findings — project portals are often built under deadline pressure, where security is rarely a delivery criterion.
Undeclared supplier connections
5 / 5
Every organisation in the benchmark carries supplier connections discovered via technical vectors that did not originate from a vendor register or questionnaire. Shared JavaScript libraries, sub-processors for analytics and marketing, and legacy infrastructure providers are embedded in every estate — unknown to the security function and unmonitored by any current TPRM programme.
Sector verdict: The construction sector is not uniquely insecure compared to other industries — but it is systematically under-maintained. The assets are there. The infrastructure is real. The suppliers are connected. What is missing is the continuous visibility to know what exists, the prioritisation to act on what matters, and the supply chain intelligence to see what no questionnaire will ever surface.
The three pillars

Why discovery, prioritisation, and monitoring are non-negotiable in construction

The construction sector combines two properties that make it uniquely exposed: a large, constantly changing digital footprint — driven by project lifecycles, joint ventures, and acquisitions — and a culture of operational urgency that has historically deprioritised security hygiene.

01

Discovery

Construction firms operate multiple project websites, tendering portals, BIM collaboration platforms, and subcontractor-facing systems — many spun up quickly and never formally decommissioned. ThingsRecon discovered an average of 1,848 internet-facing assets per organisation — far in excess of what any CMDB typically captures.

02

Prioritisation

With 622 total findings across five organisations and 54 requiring immediate action, the challenge is knowing which represent a live risk versus a theoretical one. ThingsRecon's Fix Now / Fix Soon / Monitor / Track framework cuts through the noise so stretched teams act on what matters today.

03

Monitoring

Construction's project-based operating model means the digital surface changes constantly — new joint ventures, abandoned portals, subcontractor collaboration environments that become permanent connections. Continuous monitoring ensures your risk picture expands with the surface, not months later.

Supply Chain Intelligence

Why construction has a supply chain problem that TPRM cannot solve

Construction is one of the most supply-chain-intensive industries on earth. A single major project involves dozens of specialist subcontractors, design consultancies, equipment suppliers, and platform vendors — each of whom gains some level of digital access to the prime contractor's systems. TPRM programmes ask vendors to fill in questionnaires. ThingsRecon discovers them from the outside — whether they're on a vendor list or not.

Sector Supply Chain Intelligence — Key Numbers

829 supplier connection vectors. Discovered without asking a single question.

Across the five organisations benchmarked, ThingsRecon identified 829 active technical connection vectors linking their attack surfaces to third-party suppliers — via script chains, certificate sharing, DNS delegation, header signatures, and ASN proximity, not a vendor register. The average TPRM programme covers fewer than 50 vendors; the external surface connects to ten times that number.

261
Suppliers detected across sector
5
Suppliers appear in 3+ organisations
41%
Max digital proximity recorded
3
AI Smart Findings detected

The sector's risk is compounded by three factors: subcontractors are digitally immature — smaller firms sharing credentials and repositories with prime contractors; shared platforms proliferate across competing organisations; and project relationships are informal, rarely offboarded, leaving connection vectors active long after the project closes.

What digital proximity means for construction

Proximity is not the supplier's security score — it is how short the path is from a compromised supplier to your sensitive data. A supplier rated B for cyber hygiene can still sit at 41% proximity to your crown-jewel systems if it serves JavaScript onto your most-visited project portal. In construction, the crown jewels are BIM models, site survey data, tendering intelligence, and subcontractor personal data.

The top 5 suppliers found across the construction sector — none of them construction-specific. That is the point: the sector's shared digital risk is largely invisible to the sector itself, embedded in generic technology infrastructure connecting firms to the same handful of third parties.

Supplier
Max proximity
Vector
Found in
Key sector risk signal
Cloudflare, Inc.cloudflare.com · USA
41%
cert · ASN · DNS
3/5
CDN and DNS provider for project portals — compromise would expose traffic routing and certificate management across multiple estates simultaneously
GitHub Inc.github.com · USA
32%
script · header
3/5
Source code repositories and CI/CD pipelines detected on external surfaces — misconfigurations in public repos can expose deployment secrets and project credentials
OpenJS Foundationopenjsf.org · jQuery · USA
30%
script · URL
3/5
End-of-life jQuery versions (incl. 3.5.1) detected on production assets — flagged Fix Now in one organisation; known XSS and prototype pollution CVEs apply
F5 Networks, Inc.f5.com · USA
26%
cert · ASN · header
3/5
Legacy load-balancing infrastructure detected across three estates — F5 BIG-IP carries a history of critical KEV-listed CVEs including unauthenticated RCE (CVE-2022-1388)
Let's Encryptletsencrypt.org · USA · ISRG
28%
cert chain
3/5
Free certificate authority widely adopted for project microsites — its presence indicates domains often provisioned without formal IT oversight or lifecycle management
Why sector-level supplier mapping matters

When the same supplier appears in multiple competing organisations in the same sector, the risk is no longer confined to one organisation's attack surface. A targeted compromise of a shared supplier — a JavaScript library, a certificate authority, a CDN node — can simultaneously affect multiple construction firms. Nation-state actors and sophisticated ransomware groups understand this. Sector-level supply chain intelligence is the only lens that makes this visible.

Critical supplier — found across 3 of 5 construction organisations
F5 Networks, Inc.
Network & Application Delivery Infrastructure | Seattle, USA | Discovered via certificate chain & ASN proximity
Business profile
F5, Inc. — public company (NASDAQ: FFIV), ~$2.8B revenue, ~6,000 employees
Public (NASDAQ)Known breach historySOC 2 certified
Cyber posture
Carries a documented history of critical severity CVEs on its BIG-IP product line
CVE-2022-1388 (KEV listed)CVSS 9.8 — unauth. RCEActive exploitation confirmed
Connection to sector estates
Detected via certificate chain and ASN proximity in 3 of 5 scanned organisations
Proximity up to 26%Undeclared in TPRM registers
Why it matters for construction
BIG-IP is often deployed as legacy on-prem load balancer feeding project portals and client-facing applications — frequently inherited through acquisitions or subcontractor integrations
Rarely in vendor registers

Why this supplier: F5 BIG-IP appliances are legacy infrastructure — deployed years ago, maintained by network teams, invisible to the TPRM programme. CVE-2022-1388 allows unauthenticated RCE on the management interface, was added to CISA's KEV catalogue, and was actively weaponised within days.

Attack vector chain: BIG-IP management interface → exposed on external IP (undocumented in CMDB) → unauthenticated RCE via CVE-2022-1388 → project portal back-end → BIM model storage, tendering data, subcontractor PII
How the pieces connect

One attack path — built from sector findings

Individual findings are just a list. The value is understanding the connection between them — the route an attacker takes from entry point to sensitive data. Below is a representative attack path assembled from findings observed across this benchmark; every node is grounded in a real pattern.

1
Entry point
Outdated jQuery (v3.5.1) served on project collaboration portal — known XSS vulnerability, loaded from third-party CDN
Supplier / OSS
exploited via →
2
Pivot · no CSP header present
Project management portal — missing Content-Security-Policy and X-Frame-Options headers, session cookies accessible via injected script
Asset — Fix Now
session hijack →
3
Pivot · legacy infrastructure
F5 BIG-IP load balancer — undocumented, running vulnerable firmware (CVE-2022-1388), management interface reachable externally
Asset — Fix Now
lateral movement →
4
Impact
BIM model repository, tendering documentation, subcontractor PII, project financial data — ransomware deployment or data exfiltration
Crown jewel
Three suppliers. Three configuration gaps. One path to your most sensitive project data. Every node was discovered from public data — no credentials, no access, no insider knowledge. The same view is available to any threat actor targeting this sector.
AI Smart Finding — what rule-based scanners miss

Exposures that legacy tools cannot see

source-map-scanner

Unminified source maps with embedded internal path references and dependency tree data detected in publicly accessible JavaScript build artefacts. The maps revealed server directory structures, CI/CD naming conventions, and the full npm dependency list — a detailed map of the application's internal architecture without any codebase access. Severity: high. Confidence: 94%.

bundle-exposure-scanner

API endpoint paths and parameter names embedded in production JavaScript bundles — including undocumented internal API routes used by the project management portal — discoverable by any attacker who reads the public-facing bundle. These routes, combined with weak authentication headers identified by the classic scan, create an enumeration-to-exploitation path a conventional rule-based scanner would not connect. Severity: high. Confidence: 91%.

Why Smart Findings matter: Rule-based scanners look for known signatures; AI agents read content and structure like a skilled penetration tester. Construction apps are often built under deadline pressure and rarely pen-tested post-launch, so the gap between rule engines and real attackers is substantial. Eight AI agents run per scan; three fired here.
Sector findings — aggregated across 5 organisations

The full picture: 622 findings, 54 requiring immediate action

The numbers below represent the aggregated finding landscape across all five organisations. The Fix Now count (54) represents findings where a live, exploitable exposure exists today — not a theoretical risk, but a current, verifiable gap that an attacker could use this week.

54
Fix Now
54
Fix Soon
66
Monitor
136
Track
  • Fix Now
    5/5 orgsMissing HTTP security headers on external web assets. Referrer-Policy, Content-Security-Policy, X-Frame-Options, and HSTS absent across all five organisations' project portals and marketing sites. These headers prevent cross-site leakage, clickjacking, and session theft at zero remediation cost.
  • Fix Now
    4/5 orgsEnd-of-life and unpatched JavaScript libraries serving production web assets, including jQuery versions with documented CVEs. In one organisation, jQuery 3.5.1 was flagged as Fix Now. Exploit code for these versions is publicly available and automated in common attack toolkits.
  • Fix Now
    3/5 orgsWeak or misconfigured SSL/TLS services on externally reachable endpoints — legacy cipher suites, missing HSTS, and expired or near-expiry certificate chains on project subdomains. Tender portals and client login systems are the most commonly affected assets.
  • Fix Soon
    3/5 orgsCookie security misconfigurations on project portal and CMS sessions — session cookies without the Secure, HttpOnly, or SameSite flags, served over HTTPS-capable but improperly configured endpoints. Cross-site scripting and session hijacking are the direct consequence.
  • Fix Soon
    2/5 orgsDNS security gaps — absent or misconfigured DMARC, SPF and DNSSEC — leaving two organisations' primary domains vulnerable to spoofing. Where payment diversion and BEC fraud via spoofed tender communications cause millions in losses annually, DMARC enforcement is a first-line defence, not an optional hygiene item.
  • Monitor
    5/5 orgsUndeclared supplier connections detected via technical vectors — not questionnaires. Analytics providers, marketing automation platforms, CDN nodes, and JavaScript framework publishers are embedded in every estate without appearing on any formal vendor register.
Go deeper — your organisation, your data

Everything above was found without internal access. Imagine what a full scan reveals.

This report is based on limited-scope agentless scanning — a surface-level read of public data. A full ThingsRecon engagement maps every internet-facing asset, profiles every supplier across 77 BI + 63 cyber-hygiene attributes, models every attack path, and provides a prioritised remediation programme. No agents. No questionnaires. No internal access. We start from a domain name.

✦ Full external asset inventory ✦ Supplier & proximity graph ✦ 77 BI + 63 Cyber attributes ✦ AI Smart Findings — 8 agents ✦ OSINT & dark-web signals ✦ NIS2 / DORA mapping
Request a full scan for your organisation