Skip to content
// Industries

Regulated, deadline-bound, and allergic to downtime.

The site never stops. The paperwork is on a clock.

Every other sector we work with keeps its systems and its work in the same building. Construction does not. The job happens where the network does not reach, and what it produces — the invoice, the change order, the photo of the thing that was buried — has a statutory deadline attached to it.

Construction IT is not a downtime problem. It is a transit problem.

Documents have to move between two places that share nothing: a site with no permanent infrastructure, and an office where the software that records the money sits on a server the crew never visits. Almost every failure we see in this sector shows up at one end or the other — a drawing that was a week old, an invoice that missed a deadline, or a payment instruction that turned out to belong to somebody else.

01 · What actually breaks

Five failures that cost a draw.

Ordered by what they cost, which in construction is usually measured in delayed payment rather than lost hours.

Construction IT failures, their cause, and the fix
Failure Why it happens here What we do about it
01A payment goes to the wrong account Why it happens hereMany parties, large sums and routine banking changes — the Canadian Anti-Fraud Centre names construction and contracting as common targets What we do about itEmail authentication, a written out-of-band verification rule for banking changes, and warning banners on outside mail
02The crew builds to an old revision Why it happens hereDrawings reach site by whatever worked that morning — email, a text, a memory stick — and no one version is authoritative What we do about itOne place documents live, reachable from a phone, with the current revision obvious and older ones still retrievable
03The office server is the whole company Why it happens hereJob costing and accounting run on-premises because the software requires it, and nobody has tested what happens if that box dies What we do about itMonitored, patched, and a restore that has actually been rehearsed rather than assumed
04Site connectivity arrives after the crew does Why it happens hereA new site often has no civic address to provision a line against, and a wired install runs weeks behind mobilisation What we do about itCoverage checked before mobilisation, cellular sized for where the trailer actually sits, and apps set up to tolerate a bad signal
05Last season’s crew still has access Why it happens hereHeadcount changes twice a year and nobody owns the list. Statistics Canada found only 36.9% of small construction firms had identity and access management in 2023 What we do about itDated accounts for seasonal staff, and an offboarding list that includes the systems other companies invited you into

The pattern is that none of these announce themselves. A shop knows instantly when the till is down. A contractor finds out at month end.

02 · The money

Somebody else’s invoice.

The Canadian Anti-Fraud Centre says plainly that “businesses in the construction and contracting industry, and real estate sector are common targets” of payment redirection fraud, and that these schemes predominantly affect small and mid-sized businesses. Reported spear phishing losses in Canada exceeded $68 million in 2025.

The security stack
01

Verify banking changes out of band

A request to change payment details is confirmed by phoning a number you already had — never one printed in the email. This single habit stops most of it, and it costs nothing.

02

Know the CAFC’s warning signs

Requests to update banking details. Pressure to move quickly or skip a step. An address that closely resembles a real one. Unexpected wire instructions. A new account. A past-due notice for something already paid.

03

Make outside mail look like outside mail

A banner on external email is unglamorous and it works, because the fraud depends on a message appearing to come from inside the project team.

04

Report it the same day

In April 2026 the CAFC helped recover roughly $3.5 million linked to a payment redirection fraud against a Quebec business. Recovery depends on speed, and on the receiving bank being told before the money moves on.

03 · A job

Where IT has to be present.

Ontario’s Construction Act sets the rhythm: an owner has 28 days to pay a proper invoice and 14 to dispute it, and a contractor 7 days to pay its subcontractors once paid. The paperwork has to keep up.

Mobilise

Trailer goes in

Connectivity, a printer nobody planned for, and access for a crew that starts Monday.

On site

Drawings and photos

The current revision has to be the one in someone’s hand, and today’s photos have to survive the phone they were taken on.

Change

Instruction to record

A verbal instruction that never reaches the file becomes an argument at close-out.

Invoice

The clock starts

A proper invoice starts a statutory countdown. Systems being down does not pause it.

Close-out

Everything, findable

Holdback, deficiencies and warranty all depend on records still being retrievable years later.

// What the agreement must say

Coverage that includes early starts, and a provider who understands that a site with no wired line is the normal case rather than an exception to apologise for. If a quote assumes every user sits at a desk on your network, it was not written for a builder.

04 · What we recommend

For a contractor, in this order.

First The payment path. Email authentication, external-sender banners and a written rule for banking changes. Cheapest and highest-return thing on this list, given who the CAFC says is being targeted.
Second Backup for the office server. Job costing and accounting usually still run on-premises. A rehearsed restore, not an assumed one.
Third Documents in one place. Reachable from a phone on a bad signal, with the current revision unambiguous.
Ongoing Managed IT. One owner for the office, the sites and the accounts that come and go with the season.

Worth knowing where the risk actually sits: Statistics Canada found Canadian construction firms were impacted by cyber incidents less often than the private-sector average in 2023 (12.6% against 16.1%), but more often by incidents intended to steal money or demand a ransom (6.9% against 5.9%). The exposure is financial rather than general. Further reading: how business email compromise actually arrives, and ransomware and Canadian business. The layers behind this list are the email gateway, managed firewall and EDR.

05 · Questions

The ones builders actually ask.

If yours isn’t here, ask it directly — you’ll get an answer from an engineer, not a form letter.

It is normal. Statistics Canada found that in 2021 only 1.7% of small Canadian construction firms employed an ICT specialist, and that in 2023 43.5% had nobody whose regular duties included cyber security. The problem is rarely competence. It is that the arrangement is undocumented — nobody has written down which systems exist, which are backed up, or who still has a login.

Sometimes, and it depends more on the site than on us. A new site often has no civic address a carrier can provision against, and where a wired line is possible it is usually weeks out while you need connectivity on day one. In practice the answer is normally cellular. We cannot fix coverage that is not there, but we can check it before you mobilise rather than after.

Often you cannot, and be wary of anyone who says otherwise without first asking what you run. Several packages this industry depends on are on-premises client/server software with specific server and network requirements. The realistic goal is usually not eliminating the server but making it survivable — monitored, patched, and restorable to a known point.

Take them away, and know which ones exist so that you can. Statistics Canada found that in 2023 only 36.9% of small construction firms had identity and access management in place, and only 12.7% had hardware and asset management. Part of it is not yours to control either — if a general contractor invited your people into their project software, that account is theirs to remove, so it belongs on your offboarding list as a phone call.

Yes, and it is more rigid than most people expect. Where a contract involves handling protected federal information electronically, Public Services and Procurement Canada’s Contract Security Program requires written approval before that information is accessed electronically, and getting there involves an IT security inspection and a data flow diagram showing where information is accessed, stored, processed and backed up. Start it before you bid, not after you win.

The invoice goes out on time.

Twenty minutes. Tell us how many active sites you run and what happens today when someone on site needs a drawing — that answer usually decides the whole plan.