Cyber Insurance for Construction in Switzerland
Construction businesses increasingly use Building Information Modelling (BIM), cloud-based project management, connected machinery and digital tendering platforms. These tools improve coordination but also add accounts, interfaces and supplier dependencies that need to be secured.
Why Construction Is Particularly Exposed
Construction businesses rely on interconnected project teams, suppliers and digital tools. This creates several structural cyber risks:
Complex supply chains. A typical construction project involves dozens of subcontractors, architects, engineers, quantity surveyors and suppliers. Each partner represents a potential point of entry for attackers. Project data is frequently exchanged via unsecured channels such as email attachments or shared cloud folders with weak access controls.
Invoice fraud (BEC). Large invoice amounts, numerous subcontractors and time-critical payments increase the risk of manipulated payment instructions.
BIM data sensitivity. 3D building models contain far more than architectural details. They include information about security systems, access controls, cable routing, structural vulnerabilities and technical infrastructure — highly sensitive data, especially for government buildings, data centres and critical infrastructure.
Mobile workforce. Construction workers, site managers and project leaders operate from multiple locations with mobile devices, often connecting to unsecured networks on construction sites.
Hypothetical Loss Scenarios
The following examples are hypothetical scenarios, not documented claims. Actual impact depends on the systems, data, contractual duties and incident response capability involved.
- Invoice Fraud via Business Email Compromise
- Ransomware Disrupting Project Operations
- BIM Data Theft and Espionage
Coverage Components to Review
Available cover depends on the insurer, policy wording, exclusions, sub-limits and agreed security requirements. Only the specific quote and policy wording are binding.
- Cyber fraud / BEC — coverage for losses from manipulated invoices and fraudulent payment instructions
- Business interruption — revenue loss during outages of project management, ERP and scheduling systems
- Project data recovery — costs for restoring lost plans, calculations, BIM models and documentation
- Third-party liability — claims from project owners for data loss, delays or security compromises
- IT forensics — investigation of network intrusions, email compromises and data exfiltration
- Contractual penalties — coverage for late-delivery penalties caused by cyber incidents
- Subcontractor/supply chain risk — protection against attacks that enter via partner organisations
- Crisis communication — informing project owners, partners and, where necessary, authorities
Compare Quotes and Policy Terms
A suitable solution depends on the organisation’s actual risk profile. BTAG can obtain current quotes and explain differences in cover, exclusions, deductibles and security requirements.
Compare quotes against your actual risks and the binding policy wording.