CertIQ
Cyber risk for construction businesses

Progress claims are large, scheduled, and easy to redirect.

Construction runs on big predictable payments between parties who mostly deal by email. That is close to ideal conditions for payment redirection fraud — and with subcontractors, suppliers and principals all in the chain, there are many places for an attacker to sit.

Takes 45 seconds · No sales call · Australian businesses

What actually goes wrong

Three ways construction businesses get hit.

01
Progress payment redirection
A single altered bank detail on a progress claim moves six figures. The fraud is usually discovered weeks later when the real subcontractor chases payment.
02
Long, loose supply chains
Dozens of subcontractors and suppliers exchanging documents by email, with no shared standard for verifying a change of bank details.
03
Site and mobile exposure
Site offices, cameras and project management tools connected quickly and rarely reviewed once the job moves on.
What we check first

The three that matter most for construction businesses.

Your score covers all six checks. These are the ones that most often explain a low score in your industry.

Email spoofing
Whether someone can send email that looks like you.
Exposed services
Open ports and remote access visible from the internet.
Forgotten systems
Subdomains and old hosts still attached to your domain.
Where you stand

The obligations that apply to you.

Security of Payment legislation governs the claims process but offers no protection against a redirected payment — recovery is a civil matter against a party that has already gone.

General information only, not legal advice. CertIQ scores your operational posture — it does not assess your compliance.

Weeks
Typical gap before a redirected progress payment is noticed

See where you actually stand.

Enter your website and CertIQ scores your cyber health out of 100 in about 45 seconds. Free, no account needed.