Cybersecurity|7. October 2026|

Five ways to strengthen cybersecurity across your project

By: Gina Ross Eriksen

Construction projects involve large volumes of sensitive information shared across different stakeholders and systems. This makes them attractive targets for cybercriminals – but targeted attacks are only part of the picture. Human error and lapses in judgement can have serious consequences, and technology can only take us so far. Here are five practical steps you can take to actively strengthen security and protect project data.

2FA/MFA på tvers av flere enheter

In today’s construction and infrastructure projects, we all have an important role to play in how large volumes of data are handled and shared – from personal data, contracts and financial information to BIM models and technical drawings, to name just a few. And a technical drawing is not “just a drawing”: It can reveal how a building is designed and secured, where critical functions are located and how they can be accessed.

At the same time, more and more project work is becoming digital. While you should be able to expect today’s solutions to have robust security mechanisms in place, there is one important thing to remember: Security is not created by technology alone. How we use it matters just as much.

Cybersecurity Month 2026: Sikkerhet på arbeidsplassen

Every October, we celebrate the European Cybersecurity Month (ECSM), ENISA’s annual awareness campaign in collaboration with the European Commission. The aim is to raise awareness among people and organisations alike, and this year, cybersecurity in the workplace is on the agenda – as well as how we recognise and manage digital threats in our day-to-day work.

ENISA also tracks emerging trends within Europe’s digital threat landscape in its annual ENISA Threat Landscape report. This year’s report analyses more than 8,000 recorded incidents from the previous year, highlighting several trends relevant to the construction industry:

  • Public administration is the most targeted sector: Public administration accounted for 31.8% of all recorded incidents in 2025. Local authorities, including municipalities, represented a significant proportion of these.

  • Manufacturing is the fourth most targeted sector: The manufacturing sector accounted for 6.9% of recorded incidents. Within the sector ENISA classifies as manufacturing, construction accounted for 21.8% of these incidents.

  • Ransomware remains the biggest threat: Alongside the public sector and local authorities, ENISA highlights construction as one of the subsectors where ransomware is particularly prevalent.

  • The supply chain is an increasingly important attack vector: By targeting third-party suppliers, cybercriminals can compromise multiple organisations at once. This makes construction and infrastructure projects particularly exposed, with numerous stakeholders collaborating at once.

These figures don’t place construction and infrastructure among the hardest-hit sectors overall. They do, however, reveal a threat landscape that is important to understand and be aware of – particularly in projects where stakeholders from both the public and private sectors are working together.

“Digital security is essential for every organisation, but this is an important reminder for municipalities and other public-sector clients in particular: When projects involve critical infrastructure, public services or buildings with specific security requirements, the consequences of a security breach can extend far beyond the project organisation. In the worst case, they can affect an entire community.”
– Geir Johnson, CIO at Tribia

Digital sikkerhet på hjemmekontoret

Exploiting trust: Cyberattacks don’t always start with technical vulnerabilities

Among the incidents where ENISA was able to identify attackers’ entrance points to closed systems, software vulnerabilities accounted for around 60% of all cases. Misconfigured system set-ups and careless access sharing accounted for an additional 20.7%.
At the same time, cybercriminals are increasingly exploiting human trust to gain access to sensitive data. Phishing accounted for nearly 78% of all reported incidents involving social engineering in 2025. But what exactly is social engineering?

Social engineering is an attack technique in which fraudsters exploit human psychology such as trust, fear or curiosity. The aim is typically to gain access to confidential information and potentially use it for financial extortion. A common example is when attackers pose as a person or service you trust, while also pressuring you to act quickly. This can trick users into sharing login credentials or approving fraudulent authentication requests under pressure.

And that is precisely why our collective understanding and awareness of security is so important. Secure technology is essential – but so is our ability to recognise and mitigate risk.

Five ways to take charge of project security

We all play an important role in keeping project data secure. Combined with robust digital tools, the choices we make every day make a real difference. Here are five practical steps you can take to proactively strengthen cybersecurity at work:

1. Stop and think before clicking – even when the sender seems familiar

Scamming doesn’t just happen by email. Scammers target people through fraudulent phone calls, QR codes, authentication requests, text messages and other messaging platforms such as Teams or Slack. And it’s not just the content of a message that can be deceptive – phone numbers, email addresses, links and attachments can all be spoofed. What these attempts often have in common is a sense of urgency designed to make you act quickly.

Be particularly cautious when asked to log in or download something via a link, share information or make a payment. Verify requests directly with at least one other responsible role, and only use contact details you already know to be correct and up to date. An email address or phone number provided in the message itself may be fraudulent.

2. Protect your login information

Enable multi-factor authentication (MFA) wherever it is available. MFA adds an extra layer of security by requiring you to verify your identity using two or more independent factors before logging in.

While preventing most password-based identity attacks, authentication by text message or app can still be bypassed – which is why MFA shouldn’t be your only line of defence. We recommend using a password manager and enabling passkeys on all your devices. And most importantly: don’t ever share your passwords or one-time codes with anyone else!

3. Only grant access when it is in fact needed

Follow the principle of least privilege: project members should only have access to the information they need to do their job. Review access permissions on a regular basis – particularly whenever someone joins or leaves the project, and if roles change.

4. Keep project information contained within approved systems

Project data should only be stored, handled and shared within the project’s approved solutions and any integrated systems – and should never be uploaded to open AI tools. That does not mean AI is off the table, however.

With Interaxo as your CDE, you can access Interaxo Intelligence; the platform’s built-in AI assistant. Developed specifically for construction and infrastructure projects, the assistant strictly operates within the system’s closed data environment. You can rest assured that project information won’t be used to train public AI models – allowing you to work more efficiently without compromising security.

5. If something seems off, speak up immediately – even when in doubt

Did you click on something you shouldn’t have? Or share information incorrectly? Or notice something suspicious? Don’t hold off on reporting it or try to resolve it yourself – notify your IT department or security team immediately. Remember, it’s always better to report something once too often rather than once too little.

Seemingly small mistakes can have serious consequences, and the sooner an incident is reported, the greater your chances are of limiting potential damage. If you are unsure how an incident should be handled, don’t hesitate to ask for guidance. Cybersecurity isn’t just about the systems we use – it’s about staying alert, asking questions and speaking up when something seems suspicious. When everyone is taking an active role, we’re able to build more resilient projects and organisations in today’s digital threat landscape.

Sikkerhet på byggeplassen

Technology that keeps up with your project’s cybersecurity

Interaxo is built on multiple layers of security:

Some projects have particularly stringent requirements for how data is stored and handled – particularly those involving military defence, national resilience or critical infrastructure. For high-security projects like these, Interaxo can be hosted on your own infrastructure – whether on local servers, in a private cloud or on a closed network.

Related news

Nothing Found

Book a demo

Implement Interaxo and get the power to execute

Curious about how you can improve project delivery with Interaxo? We’d be happy to show you how the platform streamlines collaboration, keeps project data secure and accessible, and frees up more time to focus on real value creation.

Fill in the form or give us a call on +47 22 50 45 50, and we’ll set up a non-binding product demo to walk you through Interaxo, explore all features, and answer any questions you may have.