DOI: 10.1680/jcien.26.00101 ISSN: 1751-7672

Briefing: Cybersecurity in engineering and the built environment

Paul Heigham

Cybersecurity has become a core professional concern for civil engineers as digital tools, connected assets and data-driven delivery reshape the built environment. Engineering organisations now depend on cloud platforms, mobile devices and supply chain collaboration to design, construct and manage assets, while regulators and clients expect demonstrable control of information throughout an asset’s lifecycle. The UK Building Safety Act has sharpened this focus through the requirement for a secure and accurate ‘golden thread’ of information, placing new demands on information technology (IT) infrastructure, governance and professional practice. At the same time, cyber threats affecting the sector are increasing in frequency and sophistication, with ransomware, business email compromise and data leakage presenting material risks to safety, reputation and commercial viability. This briefing examines the cybersecurity implications for engineering organisations worldwide, with particular attention to zero-trust design, multi-factor authentication, secure collaboration across locations and devices, and the role of staff awareness. Drawing on practical experience from Bellingham IT, a Yorkshire-based IT company supporting the construction sector, the article explores how Microsoft 365, structured policies and continuous education can support compliance, resilience and professional responsibility in an increasingly hostile digital landscape.

More from our Archive