Skip to content
Coverwright
For contractors and trades businesses

The fraud that actually costs contractors money isn’t ransomware

Business email compromise — a fake payment-detail change, sent with urgency — is documented across the industry as the costliest, fastest-growing way construction and trades businesses actually lose money to a cyberattack. What your documents already say to stop it.

Usually one of two moments: a bookkeeper nearly wires a subcontractor payment to a “new” account before someone double-checks and catches it, or a general contractor, lender, or bigger client now asks for a written security policy before you can bid on a larger job.

5
documents
79
clauses
7
gaps flagged

What the engine actually produced for one real business of this kind — including the gaps, which it states with a remediation clause rather than leaving out.

What tends to be true of firms like yours.

This is the fraud that actually happens, not the one that makes headlines

Ransomware gets the coverage; business email compromise is what independent industry reporting consistently names as the costliest and fastest-growing financial crime hitting construction and trades firms specifically — a fake request to change payment or bank details, timed to look urgent and routine. It works because it doesn’t need to break into anything; it only needs one person to move money before they check.

The pattern fits how this industry actually pays people

A contractor managing a few active jobs is routinely sending payments to subcontractors and suppliers — sized in the tens of thousands, on a schedule the job dictates rather than a monthly cycle. That volume and time pressure is exactly the cover a fraudulent “updated bank details” email needs, and it is normal enough on a busy week that it doesn’t stand out.

Your documents already carry the specific control that stops it

Any change to payment or bank details is verified by a phone call to a number already on file — never a number in the request itself — before money moves, with a second person’s approval above a set threshold. If a fraudulent payment does go out, the plan’s first instruction is to call the bank immediately, before anything else, because banks can sometimes recall a payment within hours. On the Complete set, the acceptable use policy carries the same rule to every employee in plain terms: urgency is the tell, and nobody will be annoyed at you for making the call.

A bigger client may start asking you to prove it

General contractors and larger developers are increasingly pushing security and insurance requirements down to the subcontractors bidding on their jobs, the same way any larger customer pushes a vendor review down its supply chain. A written policy that names who’s responsible and how payments are verified is what that ask is actually looking for.

Where this stops

Coverwright’s documents state the payment-verification practice; they don’t call your bank, don’t monitor your accounts, and don’t guarantee a fraudulent payment is recoverable — that depends on your bank and how quickly it’s caught. Producing these documents doesn’t guarantee insurance acceptance or claim outcomes either; whether a specific insurer’s or lender’s requirement is satisfied is a question for your broker or counsel.

Worth reading first

Before you decide anything.

See your own set before you pay.

Answer 21 plain-English questions — about ten minutes — and read the first section of your real generated program before deciding. From $199, one time, renewed for $99 a year.

No account needed to see your documents · no sales call, ever