UK construction cyber and compliance weekly · Edition 01

Week commencing
3 August 2026

Coverage27 July – 2 August 2026
AudienceIT and security leadership · compliance and risk leads · programme directors
HandlingPublished by ClearPath Partnership
If you just remember one thing from this briefing…
One hardcoded GitHub credential reportedly gave attackers seven months inside Arup's project data, including HS2 design files.

FulcrumSec's claimed breach of Arup Group traces to a personal access token left in a JavaScript file on a forgotten subdomain — a housekeeping failure, not a sophisticated exploit. The group says it reached over 10,000 repositories, including Oasys and ArupCompute source code and HS2 tunnelling and station design data. Arup has issued no public statement. Ask your design teams this week: where do our access tokens live, and who last audited our public-facing source control.

This week

Incidents and sector activity

Priority27–29 Jul

Three edge and remote-access products added to the exploited-vulnerability catalogue

CISA added Fortinet FortiOS (CVE-2025-68686), Arista VeloCloud Orchestrator (CVE-2026-16812) and Cisco Secure FMC (CVE-2026-20316, hardcoded credentials, remediate by 1 Aug). All three sit in front of the VPN, SD-WAN and firewall estate connecting site cabins, subcontractors and design offices.

So what: treat KEV listing as the minimum patch queue for internet-facing assets, regardless of internal CVSS scoring. Confirm exposure today.

PrioritySince 14 Jul, ongoing

SonicWall SMA1000 zero-days chained by INC ransomware

Two vulnerabilities in the SMA1000 Work Place interface (CVE-2026-15409, CVE-2026-15410), exploited since at least June, let an unauthenticated attacker tunnel into internal services and, when chained, execute code as root. SMA1000 is a common choice for contractor and site remote access.

So what: confirm the vendor patch is applied, not scheduled. INC has already used this pair operationally.

PriorityStanding risk

Invoice fraud remains construction's costliest cyber-enabled loss

NCA data show £3.9m lost to invoice fraud in September 2025 alone across 83 cases, with construction and manufacturing together a quarter of reported losses. Attackers compromise a supplier's email thread, then redirect a genuine payment to an account they control.

So what: make a callback to a known, previously verified number mandatory for any bank detail change on a live project — no exceptions.

WatchOngoing

Ransomware groups continue naming UK construction and engineering firms

NCC Group's Q2 data puts construction and engineering among the most-targeted capital-goods sub-sectors, Qilin the most active group globally. William Davis Homes (Qilin, 27 May) and, within this coverage window, digital services provider Caspian One (Deadlock, 26 Jul) were both named.

So what: check both against your supplier and integrator register, including fourth parties reached through subcontractors.

ClearPath Partnership · UK construction cyber weekly · Edition 011 of 2
UK construction cyber weekly · Edition 01Actions, regulatory watch and outlook
Action queue

Changes and vulnerabilities to act on this week

Change or vulnerabilityWhat it applies toWhy it matters on a projectAct by
CVE-2025-68686 / -16812FortiOS & Arista VeloCloudSite-to-site and subcontractor remote access. Confirmed exploited.Immediate
CVE-2026-20316Cisco Secure FMCHardcoded credential, confirmed exploited. CISA deadline 1 Aug.Immediate
CVE-2026-15409 / -15410SonicWall SMA1000Chained SSRF and RCE, used by INC ransomware.Immediate
Cyber Essentials v3.3CE / CE+ holdersMFA and a 14-day patch SLA are automatic-fail controls.Existing accounts by ~27 Oct

Identifiers are as published in the CISA KEV catalogue. Confirm applicability against your own asset inventory — this list is a prompt, not a substitute for it.

Regulatory and sector watch

What changed, and what is coming

In force now

  • Procurement Act 2023 debarment regime, live since Feb 2025. Investigations into seven Grenfell-linked firms remain paused at the request of the CPS and Met Police.
  • Cyber Essentials v3.3 applies to accounts opened since 27 April 2026 — mandatory MFA, 14-day critical-patch SLA.
  • CDM 2015 unchanged — HSE's five-year review confirms it remains fit for purpose.

Approaching

  • Cyber Security and Resilience Bill — Lords Committee 1 September 2026, Royal Assent expected late 2026. Widens NIS-adjacent duties to more supply-chain firms.
  • Existing Cyber Essentials accounts have until roughly 27 October 2026 to move to v3.3.
  • Gateway 3 evidence packs must be audit-ready before occupation; BSR guidance stays thin.

Standing watch — golden thread evidence gaps. Fragmented metadata and weak document control in CDE platforms continue to force manual evidence-pack rework ahead of Gateway 2 and 3 submissions. Budget review time before you submit.

Recommended

Three things to do before next Monday

Outlook — next seven days

We assess it is likely that a further remote-access or identity product is added to the exploited-vulnerability catalogue this week, and a realistic possibility that another UK construction or engineering firm is named on a ransomware leak site, given Qilin's and Deadlock's current focus. Both test whether your patch and credential hygiene move faster than the attackers.

Next edition

Monday 10 August 2026. Send additions, corrections or sector intelligence to your ClearPath engagement lead.

ClearPath Partnership
ClearPath Partnership · clearpathpartnership.com · Judgements are analytical assessments, not statements of fact.2 of 2
← All briefings Download PDF