Assessment of the cybersecurity vulnerability of construction networks

Mantha, B R K and García de Soto, B (2021) Assessment of the cybersecurity vulnerability of construction networks. Engineering, Construction and Architectural Management, 28(10), pp. 3078-3105. ISSN 0969-9988

Abstract

Purpose: The aim of this study is o examine the advantages and disadvantages of different existing scoring systems in the cybersecurity domain and their applicability to the AEC industry and to systematically apply a scoring system to determine scores for some of the most significant construction participants. Design/methodology/approach: This study proposes a methodology that uses the Common Vulnerability Scoring System (CVSS) to calculate scores and the likelihood of occurrence based on communication frequencies to ultimately determine risk categories for different paths in a construction network. As a proof of concept, the proposed methodology is implemented in a construction network from a real project found in the literature. Findings: Results show that the proposed methodology could provide valuable information to assist project participants to assess the overall cybersecurity vulnerability of construction and assist during the vulnerability-management processes. For example, a project owner can use this information to get a better understanding of what to do to limit its vulnerability, which will lead to the overall improvement of the security of the construction network. Research limitations/implications: It has to be noted that the scoring systems, the scores and categories adopted in the study need not necessarily be an exact representation of all the construction participants or networks. Therefore, caution should be exercised to avoid generalizing the results of this study. Practical implications: The proposed methodology can provide valuable information and assist project participants to assess the overall cyber-vulnerability of construction projects and support the vulnerability-management processes. For example, a project owner can use this approach to get a better understanding of what to do to limit its cyber-vulnerability exposure, which will ultimately lead to the overall improvement of the construction network's security. This study will also help raise more awareness about the cybersecurity implications of the digitalization and automation of the AEC industry among practitioners and construction researchers. Social implications: Given the amount of digitized services and tools used in the AEC industry, cybersecurity is increasingly becoming critical for society in general. In some cases, (e.g. critical infrastructure) incidents could have significant economic and societal or public safety implications. Therefore, proper consideration and action from the AEC research community and industry are needed. Originality/value: To the authors' knowledge, this is the first attempt to measure and assess the cybersecurity of individual participants and the construction network as a whole by using the Common Vulnerability Scoring System.

Item Type: Article
Uncontrolled Keywords: construction network; cvss; cybersecurity; risk management; security score; vulnerability assessment; vulnerability metrics
Index terms: critical infrastructure, automation, risk management, owner, becoming, exposure, methodology, construction project, practitioner, vulnerability, public safety, society, digitalization
Subjects: public and environmental health, research methods, production management, automation and robotics, sociology, emergency and crisis management, environmental hazards, philosophical process, communities and social development, infrastructure and transport systems, risk assessment, practitioner, digital technology
Topics: Digital Applications, Risk Management, Roles and Professions, Stakeholder Management, Sustainability, Health and Safety, Engineering Principles, Research Practice, Project Management
Descriptive scope: 3 PCT

N.B. Descriptive scope is a count of how many of the five facets of empirical research are indicated by the words used in title, abstract and keywords. It is not intended as a judgement on the research; merely a count of the kind of word we would expect to indicate Phenomenon, Concepts, Theoretical framing, Empirical techniques, Analytical techniques. If all five are present, then a code of “5 PCTEA” will indicate this. If you feel the coding for this record is questionable, we welcome discussion around the terms we matched or the way we categorized them. The facet you would expect may not be coded, or a facet may be coded inappropriately. This can also bear on a larger question, of which facets should be treated as defining in construction management research. Please get in touch, and we will look at it. More details here