Chapter 4Handbook

The minimum we hold you to

The 10-point standard, and how to score yourself

You cannot pour a slab without an inspection. You cannot wire a shed without a licence. You cannot step on site without a white card.

But you can run a 50-person construction company on IT that would fail any inspection ever written, and nobody stops you.

Construction already believes in minimums

No industry understands minimum standards better than this one. Licensed trades. SWMS before high-risk work. Scaffold tagged and inspected. Test and tag on every lead on site. None of it is optional, and nobody calls it best practice. It is code.

Now walk from the site shed to the server cupboard. Where is the tag? Who inspected the backups? Who is licensed to hold the admin password?

Nobody. IT is the only business-critical system in a construction company with no inspector, no ticket and no code.

Nobody chooses to run below code. They drift there

No one decided the estimator who left in 2023 should still have a working login. It just never got switched off.

No one decided the backups should be untested. The green tick appears every night and nobody has ever restored a file from them.

No one decided the admin password should live in passwords.xlsx. It was easier that day.

Each decision was reasonable on its own. Stack five years of them and you get the drift standard: the standard your business drifted into instead of the one you chose. It is always lower than you think, because "nothing has gone wrong yet" feels exactly like "we are fine".

There is a name for that feeling. She'll be right. On site it is the most dangerous phrase there is, the mindset that skips the brace, the test tag, the harness. You would never accept it from a worker. It is running most server cupboards in the country.

Site inspections exist to catch drift before it becomes an incident. IT never got its inspector, so you need to be your own.

The minimum is being written anyway, without you

Three groups are already defining a minimum IT standard for your business, and none of them asked you.

Government. Businesses turning over $3M or more that pay a ransomware demand must report it within 72 hours. That is law, enforced since January 2026, with penalties.

Insurers. Cyber insurance questionnaires are audits in disguise. No MFA, no tested backups, no policy, expect a loading, an exclusion or a knock-back. And after a claim, the insurer will check whether what you declared was true.

Clients. Head contractors, government projects and corporate clients are pushing security questionnaires down the supply chain. Standards like SMB1001, built for businesses under 200 staff, are appearing in tenders, with tiers a director signs off on personally.

You will meet a minimum standard either way. The only choice is whether you do it calmly and cheaply on your own schedule, or under pressure during a claim, an audit, or a tender you wanted.

The ASD logs a cybercrime report every six minutes. The average self-reported cost per incident is $56,600 for a small business and $97,200 for a medium one. Those figures are from the ASD Annual Cyber Threat Report 2024-25.

This is a floor, not a ceiling

None of what follows is gold-plating and none of it needs an enterprise budget. It is the baseline for running a reliable business in 2026, the IT equivalent of a tidy site with certified scaffold.

You do not get a trophy for meeting code. You get to keep operating.

The 10-point minimum

Score one point per item. Be honest, drift loves a generous marker.

  1. MFA everywhere. Email, remote access, and anything with admin rights.
  2. Restore-tested backups. Offsite, and actually restored from, recently. A backup you have never restored is a guess.
  3. Patching within 30 days. Automatic wherever possible.
  4. Supported hardware and software only. End-of-life gear is not a computer anymore, it is a liability with a power cord.
  5. EDR on every device. Modern endpoint protection on every laptop and server, site laptops included.
  6. Unique logins and same-day offboarding. Admin rights restricted. When someone leaves, access dies that day.
  7. Email authentication. SPF, DKIM and DMARC configured properly. This is what stops criminals sending "your" invoices to your clients.
  8. A password manager. Passwords in a spreadsheet is an automatic fail.
  9. Annual staff security training. Most breaches walk in through an inbox, not a firewall. Payment redirection scams love construction.
  10. A one-page incident response plan. Who to call, in what order, and who reports what. Written on a boring Tuesday, not during the fire.

8 or better: at or near the minimum. Maintain it.

Under 8: below code, and worth fixing before someone else makes you.

Do not try to fix all ten at once. MFA, backups and offboarding close the biggest holes fastest, and none of the three needs new hardware. Then work down the list.

Notice what is not on the list. Nothing exotic, nothing enterprise-priced. Most of it is configuration, habits and process, which is exactly why there is no excuse.

Want a second pair of eyes on the score? Contact us.