The drawing is the asset. So is the payment run.
Project data, supplier payments and site connectivity are the three things that go wrong on a construction or engineering project, and they go wrong in that order. LANTEK covers all three from one accountable team.
What does an attacker actually want from an engineering or construction business?
The payment run, in most cases. Construction moves large sums between a long list of suppliers and subcontractors on predictable dates, which is exactly the pattern business email compromise is built for. A changed set of banking details on a real invoice from a real supplier is far more common than an attack on the drawings themselves.
The second target is project data. Drawings, models, tender documents and site records represent months of billable work, and on a project with a deadline the value of getting them back quickly is obvious to the person asking for a ransom.
Why is a construction project harder to protect than an office?
Because the perimeter moves. A project runs from a head office, a site office, a laptop in a bakkie and a phone on a scaffold, often over a connection nobody controls, and it involves people from several companies who are not on your systems. Every one of those is a legitimate way in.
The answer is not to lock the site down until nobody can work. It is to make identity the control point rather than the network, so that access follows the person and can be withdrawn the day they leave the project.
What happens if the project server goes down mid-programme?
Without a tested recovery plan, a project loses the current model, the revision history and the correspondence trail at the same time. On a contract with delay damages that is not an IT problem, it is a commercial one, and the question that follows is always whether the backup was ever restored from rather than whether it ran.
Does POPIA apply to a construction business?
Yes. POPIA applies to any South African business that holds personal information about identifiable people, which on a project means employee records, subcontractor details, site access registers and health and safety files. Section 19 requires appropriate technical and organisational measures to secure it, and the maximum administrative fine is R10 million.
What that looks like in practice is set out on the Compliant by Design page.
Has LANTEK worked on projects like this?
Yes. LANTEK delivered the infrastructure design, project management and implementation for the Cato Ridge and Scottburgh facilities of Hibiscus Hospitals, which is multi-site build work with the same constraints: a live programme, a fixed handover date and systems that have to be running on the day the doors open.
More of the track record is on the clients page.
Before you call
Can you get connectivity and systems onto a new site?
How do you handle subcontractors who need access to our files?
We use specialist design software. Will you support it?
Somebody changed a supplier's banking details by email. What now?
A free dark web scan
and thirty minutes.
We scan for your company email addresses, passwords and customer data in the places stolen and leaked data gets traded, then spend thirty minutes walking you through what came back and what it actually means. No pressure, no jargon, no obligation. You keep the report either way.
Worried about what it takes to move?
Changing IT provider is the single biggest reason businesses stay somewhere they have outgrown. We plan the move around your working week, and we help carry the cost of getting across. Ask us how that works when we speak.