New England Construction

Dedicated to the people who make our built environment better and safer. We tell your stories and celebrate your successes.

Register with us and receive industry news and content only available to subscribers.

Subscribe
Contacts

Indianapolis, IN, USA (HQ)

903 E. Ohio St., Indianapolis, IN 46202

Call: (317) 423-2325

info@acppubs.com
August 2026

Cyber Insurance Blind Spots

by: Kirk Chamberlain, Mark Wooditch, and Michael Snelling, HUB International
Kirk Chamberlain, Executive Vice President, HUB International
Kirk Chamberlain, Executive Vice President, HUB International
Mark Wooditch, Los Angeles Orange County Construction Practice Leader, HUB
Mark Wooditch, Los Angeles Orange County Construction Practice Leader, HUB
Michael R. Snelling, Vice President of Commercial Lines, HUB
Michael R. Snelling, Vice President of Commercial Lines, HUB

Construction firms have become prime targets for cybercriminals in recent years, driven by the industry's combination of high-value projects, tight timelines, complex subcontractor networks, and increased adoption of digital tools.

Nationally, cybercrime losses reached nearly $20.9 billion in 2025, a 26 percent increase from the prior year, according to the FBI’s latest Internet Crime Report.

In this environment, cyber insurance has become foundational to a strong cyber resilience strategy. But too many firms secure coverage without fully understanding what their policy does — and doesn't — cover. Coverage gaps are common, and in construction, they tend to surface in precisely the areas where the financial and operational stakes are highest.

On the bright side, the cyber insurance market has softened over the past two years, with carriers offering more competitive terms to well-prepared buyers. For construction firms, this creates a meaningful window to revisit existing programs, close gaps, and build stronger protection before market conditions shift again.

What Cyber Policies Should Cover

A comprehensive cyber policy typically covers two broad categories: first-party coverage (which protects the insured organization from the direct costs of an incident) and third-party coverage (which addresses liability to others).

For construction firms, the most critical first-party coverages include:

  • Ransomware and cyber extortion
  • Business interruption
  • Data recovery
  • Social engineering (when criminals manipulate employees into taking actions that result in financial loss, such as tricking someone into wiring money to a fraudulent account) and funds transfer fraud protection

On the third-party side, a well-structured program should include:

  • Network security and privacy liability coverage (which addresses claims from parties whose data was compromised)
  • Regulatory defense coverage for legal costs and fines that can follow a breach
  • Where Coverage Blind Spots Emerge

    Understanding the conditions, sublimits, and exclusions each coverage carries is where many firms fall short. For construction firms, the gaps tend to emerge in a few predictable areas:

    Third-Party Vendor Incidents
    Many cyber policies restrict dependent business interruption coverage to information technology (IT) vendors with shared computer systems, rather than extending to all supply chain partners.

    This gap can hit construction firms especially hard given their dependence on subcontractors, vendors, and cloud-based platforms. If a cloud-based payroll provider is taken offline by a ransom attack, for example, a firm may absorb the full loss if that vendor falls outside the policy’s definition of a covered IT service provider. Reviewing vendor contracts alongside policy language before an incident occurs is the only reliable way to know where that exposure actually sits.

    Funds Transfer Fraud Sublimits
    Most cyber policies include social engineering and funds transfer fraud coverage, but the sublimits attached to that coverage are typically capped around $250,000 and may not reflect the scale of transactions construction firms routinely handle.

    For a contractor regularly moving six-figure sums for project costs and vendor payments, that gap can leave significant exposure unaddressed. Wire fraud schemes targeting construction firms have grown more sophisticated, with attackers intercepting email threads and impersonating project owners or subcontractors to redirect payments.

    Business Interruption Exclusions
    Cyber business interruption policies typically require a network breach or unauthorized access to activate coverage. However, exclusions commonly apply to infrastructure-related outages such as a power disruption or internet failure.

    Consider a contractor who lost power and internet connectivity due to a malicious cyber incident during a critical project deadline. Unable to access project management systems or process payments, the firm incurs costly delays and potential penalties. Despite having cyber insurance, the policy explicitly excluded infrastructure-related outages.

    5 Steps to Close Gaps

    The following best practices offer firms a practical starting point for strengthening a cyber insurance program.

    1. Audit Third-Party Coverage
    Determine whether dependent business interruption coverage extends to all critical vendors or is limited to IT providers with shared computer systems. Map out the subcontractors, cloud platforms, and service providers that operations depend on, and confirm whether a disruption to any of those parties would trigger coverage. Pay particular attention to software-as-a-service platforms used for project management, estimating, or document control, as these are often overlooked but deeply embedded in daily operations.

    2. Review Social Engineering Limits
    Compare existing funds transfer fraud sublimits against realistic loss scenarios. If the gap is significant, work with a broker to negotiate higher sublimits, explore supplemental coverage, and enhance internal payment controls to reduce exposure.

    3. Examine Trigger Language
    Review the business interruption insuring agreement carefully to understand what events activate coverage and what is excluded. When gaps exist, captive structures or parametric products can be structured to respond to losses that fall outside traditional coverage triggers.

    4. Understand Notification Requirements
    Cyber policies typically require notification within 60 to 90 days of a circumstance that may lead to a claim. Missing that window can result in a coverage denial. Documenting notification requirements and building them into incident response protocols is essential. It is worth assigning a specific individual, not just a department, to own that responsibility so nothing falls through the cracks during a high-pressure incident.

    5. Build and Test an Incident Response Plan
    A comprehensive incident response plan improves a firm's ability to respond effectively when an attack occurs and directly affects insurance outcomes. Carriers increasingly factor preparedness into underwriting decisions, so firms that demonstrate a current, tested plan with clear protocols for notifying their broker, carrier, and pre-approved vendors are better positioned to secure favorable terms.

    From Coverage to Resilience

    Treating cyber insurance as a strategic risk management tool is critical for construction firms navigating an increasingly complex threat environment.

    Esco Corporation
    Your local Esco Corporation dealer
    Genalco
    Genalco
    Genalco
    Genalco
    Genalco

    The current soft market is an opportune time to revisit coverage, address gaps, and negotiate more favorable terms. Working with a broker who understands construction-specific exposures can help firms move beyond checkbox coverage and build genuine cyber resilience.

    Kirk Chamberlain is an Executive Vice President, leading global insurance brokerage HUB International’s construction practice. Mark Wooditch is the Los Angeles Orange County Construction Practice Leader for HUB. Michael R. Snelling is Vice President of Commercial Lines at HUB.