Cyber Security in the Frame & Truss Industry: What Members Need to Watch For
26th March 2026
By Guilherme Zanella
Data is often described as the “new oil” and in today’s digital environment, cybersecurity has become a critical issue for businesses of all sizes, including those in the frame and truss industry. Cybercrime is reported every six minutes in Australia. The Australian Cyber Security Centre (ACSC) received over 87,400 cybercrime reports in Fiscal Year 2023–24, with the average self-reported cost reaching $49,600 per incident for small businesses and $62,800 for medium businesses.
In addition, Microsoft’s 2024 research found that 31% of small and medium-sized businesses (SMBs) with 25 to 299 employees have experienced ransomware, phishing, or data breaches. Despite this, many organisations still believe they are “too small to be targeted.”
The good news is that you don’t need to be a cybersecurity expert to significantly reduce your risk. By understanding the most common attack methods and applying practical measures, you can better protect your business and your operations.
Email Scams & Social Engineering
Phishing and Business Email Compromise (BEC) are among the most common and effective attack methods used against businesses today. These attacks rely on social engineering, where cybercriminals manipulate people into taking actions such as clicking malicious links, downloading attachments or transferring money. Emails may appear legitimate often impersonating suppliers, clients or internal staff and can include fake invoices or urgent payment requests.
Invoice fraud alone costs Australian businesses millions each year. In Fiscal Year 2023–24, reported BEC losses totalled nearly $84 million, with the average incident exceeding $55,000.
Industry relevance:
For frame and truss businesses, this often appears as:
• Fake supplier invoice changes
• Requests to update bank details
• Urgent payment requests from “management”
Passwords, Logins & Access Control
Weak or reused passwords remain one of the most exploited entry points for cybercriminals. Using the same password across multiple systems significantly increases cybersecurity risks. If one system is compromised, attackers can access others using the same credentials.
To reduce this risk:
• Use strong, unique passwords for every system
• Change passwords regularly
• Implement multi-factor authentication (MFA).
Tools such as Google Authenticator or Microsoft Entra ID add an extra layer of security by requiring a second verification step typically through a mobile device. Research from ReliaQuest shows that credential-related incidents account for 75% of digital risk alerts, an 83% increase year-on-year. Stolen credentials are often sold on the dark web and used to access business systems without detection.
Ransomware & Business Disruption
Ransomware is one of the most damaging cyber threats facing businesses today. In a ransomware attack, cybercriminals gain access to your systems and encrypt your data, demanding payment (a ransom) to restore access. These attacks can halt operations entirely impacting production, administration and project delivery.
For frame and truss businesses, this could mean:
• Loss of design files or CAD data
• Disruption to manufacturing schedules
• Inability to process orders or invoices.
Ransomware accounted for 11% of all cyber incidents in Australia, with the ACSC responding to 121 incidents in Fiscal Year 2023–24. These attacks continue to pose significant operational and reputational risks.
Remote Access
The increasing use of cloud-based systems and remote work has expanded the number of potential entry points for cyberattacks. Staff accessing systems from home, job sites or public spaces can unintentionally expose business data, especially when using unsecured networks.
Public Wi-Fi networks are particularly risky. Attackers can intercept data by positioning themselves between the user and the connection point (a “man-in-the-middle” attack), allowing them to capture sensitive information.
To reduce these risks:
• Avoid using public Wi-Fi where possible
• Use a Virtual Private Network (VPN) when remote access is required
• Disable file sharing on public networks
• Ensure devices are secure and up to date.
Practical Do’s and Don’ts for IT Security

Cybersecurity is no longer just an IT issue, it is a business risk that can directly impact your company. The majority of cyberattacks are not highly sophisticated, they rely on simple tactics such as deceptive emails, weak passwords, and unsecured access points. This means by following safety practices when using internet can significantly reduce cybersecurity risks.
By building awareness across your team, implementing basic protections such as multi-factor authentication and secure backups, and maintaining a cautious approach to emails and online activity, your business can significantly strengthen its resilience. Small and practical actions taken today can prevent major disruptions tomorrow.
Sources
• Australian Cyber Security Centre (ACSC). Annual Cyber Threat Report 2023–2024. Australian Signals Directorate, November 2024.
https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2023-2024
• Woodgate, S. (Microsoft Security). 7 Cybersecurity Trends and Tips for Small and Medium Businesses to Stay Protected. October 2024.
https://www.microsoft.com/en-us/security/blog/2024/10/31/7-cybersecurity-trends-and-tips-for-small-and-medium-businesses-to-stay-protected/
• Dilgen, J. (ReliaQuest). Report Shows Ransomware Has Grown 41% for Construction Industry. November 2024.
https://reliaquest.com/blog/report-shows-ransomware-has-grown-41-for-construction-industry/
• Cybersecurity and Infrastructure Security Agency (CISA). Secure Your Business and Critical Manufacturing Sector Landscape. 2024.
https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business

