UK construction cyber briefing · Edition 02

Week commencing
17 August 2026

Coverage3 – 16 August 2026
AudienceIT and security leadership · compliance and risk leads · programme directors
HandlingPublished by ClearPath Partnership
If you just remember one thing from this briefing…
A load balancer and a firewall VPN both joined the federal exploited-vulnerability list this fortnight — both sit at the edge of a typical site estate.

CISA added Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) on 7 August and Cisco Secure ASA/FTD's SSL VPN service (CVE-2026-20349) on 11 August. Both federal deadlines have passed. Ask your infrastructure team this week: which internet-facing appliances are still unpatched against either, and who owns the answer.

This fortnight

Incidents and sector activity

Priority7–11 Aug

Two more edge products added to the exploited-vulnerability catalogue

CISA added Progress Kemp LoadMaster's command injection flaw (CVE-2026-8037), exploited within days of a public proof of concept, then Cisco ASA/FTD's remote-access SSL VPN flaw (CVE-2026-20349), which crashes the appliance on an unauthenticated request. Both commonly sit in front of contractor remote access.

So what: treat KEV listing as the minimum patch queue regardless of internal CVSS scoring. Confirm both are patched — the 10 and 14 August federal deadlines have passed.

Priority13 Aug

UK contractor Pacific Construction named on the INC Ransom leak site

INC Ransom listed pacific-construction.com on 13 August, claiming exfiltration of project, client and contract data. Neither the company nor a parent group has issued a public statement; the claim is unverified beyond the leak-site posting.

So what: check the name against your subcontractor register. Confirm your incident response plan covers a leak-site naming, not only encryption.

WatchOngoing, H1 2026

Qilin remains the most active ransomware group worldwide, construction a frequent target

Cyble recorded Qilin as the most active group globally in H1 2026, with 158 attacks across Europe and the UK. It named TIS in April and William Davis Homes in May; INC Ransom's Pacific Construction claim this fortnight extends the same pattern to a second active group.

So what: leak-site naming is now routine for UK construction. Verify fourth-party exposure through every subcontractor and consultant, not only direct suppliers.

WatchStanding risk

Invoice fraud campaign continues; construction remains disproportionately hit

The NCA and National Federation of Builders' invoice fraud campaign runs through the fortnight, built on figures showing construction and manufacturing together took a quarter of the £3.9m lost to invoice fraud in September 2025 alone — the most recent published NCA data.

So what: make a callback to a previously verified number mandatory for any bank-detail change on a live project, whoever is asking.

ClearPath Partnership · UK construction cyber briefing · Edition 021 of 2
UK construction cyber briefing · Edition 02Actions, regulatory watch and outlook
Action queue

Changes and vulnerabilities to act on this fortnight

Change or vulnerabilityWhat it applies toWhy it matters on a projectAct by
CVE-2026-8037Progress Kemp LoadMasterCommand injection, CVSS 9.6, exploited at the network edge.Overdue
CVE-2026-20349Cisco Secure ASA / FTDUnauthenticated crash of the remote-access SSL VPN service.Overdue
Cyber Essentials v3.3Accounts opened before 27 Apr 2026MFA and 12-character passwords become automatic-fail controls.~26 Oct 2026
Gateway 2/3 evidence packsHigher-risk building projectsGolden thread data must be audit-ready before submission.Before submission
NCA/NFB invoice fraud guidanceFinance and accounts payable teamsCallback verification stops the sector's costliest cyber loss.This week

Identifiers as published in the CISA KEV catalogue. Confirm against your own asset inventory.

Regulatory and sector watch

What changed, and what is coming

In force now

  • Cyber Essentials v3.3 applies to accounts opened since 27 April 2026 — mandatory MFA and a 12-character minimum password.
  • BSR Gateway 2 approvals reached 82% nationally (85% remediation, 92% London) to 1 August; median approval time nearly halved to 22 weeks.
  • Procurement Act 2023 debarment list remains empty since the regime went live in February 2025.

Approaching

  • Cyber Security and Resilience Bill — Lords Committee Stage 1 September 2026. Widens NIS-adjacent duties to supply-chain firms.
  • Pre-27 April 2026 Cyber Essentials accounts have until roughly 26 October 2026 to move to v3.3.
  • Future Homes Standard confirmed in force from 24 March 2027 (non-higher-risk); plan procurement now.

Standing watch — golden thread evidence gaps. Fragmented metadata and weak document control in CDE platforms still force manual evidence-pack rework ahead of Gateway 2 and 3 submissions. Budget review time before you submit.

Recommended

Three things to do before the next edition

Outlook — next fortnight

We assess it is likely a further edge or remote-access product is added to the exploited-vulnerability catalogue before the next edition, and a realistic possibility another UK construction or engineering firm is named on a leak site, given Qilin's and INC Ransom's current pace.

Next edition

Monday 31 August 2026. Send additions, corrections or sector intelligence to your ClearPath engagement lead.

ClearPath Partnership
ClearPath Partnership · clearpathpartnership.com · Judgements are analytical assessments, not statements of fact.2 of 2
← All briefings Download PDF