It’s easy to assume that cyber threats are someone else’s problem — big companies, banks, government departments. The reality for tradespeople and construction firms in the UK is considerably less comfortable. Criminals target small trades businesses specifically because the cybersecurity is often minimal, the staff count is low enough that everyone knows each other (which makes impersonation easier), and the invoices are large enough to make the effort worthwhile.
A sole trader electrician or a ten-person builder sending invoices for tens of thousands of pounds is an attractive target. Here’s what the threats actually look like and what you can do about them without spending a fortune or hiring an IT person.
Invoice Fraud: The Biggest Risk for Trades
By far the most common and damaging attack on trades businesses is invoice fraud, also called mandate fraud or bank detail change fraud. The way it works: a criminal either hacks into one side of an ongoing business relationship, monitors the email thread, and then intercepts at the right moment to swap bank details — or simply impersonates one party convincingly enough to get the other side to change their payment records.
For a joiner or plumber working on large contracts, a single compromised invoice can mean thousands of pounds lost, often with limited recourse. Banks do recover some of these funds if reported quickly through Action Fraud (actionfraud.police.uk), but recovery is far from guaranteed.
The protection is straightforward but requires discipline: always verify any change of bank details by calling a known number, not the one in the email. Use a phone number you already have saved, not one provided in the same email that’s asking you to update payment details. This single habit catches the vast majority of bank detail change fraud attempts.
Your own invoices are also at risk. If your email is compromised, someone could intercept your invoices to clients and alter the bank details before they arrive. Setting up email monitoring (most business email providers have this) and using a consistent format that clients are trained to recognise helps, but the most important thing is using a business email address on a paid domain — not a Gmail or Hotmail — and keeping that account secured with two-factor authentication.
Phishing That Actually Targets Trades
Phishing emails aimed at construction and trades businesses often spoof real companies in the industry: tool suppliers, scaffolding hire firms, HSE and HMRC correspondence, Local Authority communications about planning permissions. They know the context because they’ve done basic research on your business from Companies House and your website.
Common scenarios: a fake HSE safety alert requiring you to download an attachment, a fake invoice from a tool supplier with slightly wrong bank details, a fake HMRC communication about an outstanding payment, a fake “overdue invoice” from a name that sounds like a real supplier you use.
The tell is usually the sender’s email address. If HSE is emailing you, it’ll be from an @hse.gov.uk address. HMRC emails come from @hmrc.gov.uk. A supplier email that uses a free email provider or has odd domain variations (like “hse-alerts.co.uk”) should be treated as suspicious regardless of how official the content looks.
If you receive an unexpected email asking for action — clicking a link, paying money, downloading a file, updating credentials — pause before doing it. Call the organisation on a number you find independently, not one in the email.
Protecting Your Business Email
For a trades business, the email account is often the most valuable digital asset you have. It holds client contact histories, quotes, contracts, and is usually the recovery method for every other account you have. If it’s compromised, everything else becomes vulnerable.
The minimum protections:
Use a business email on your own domain, not a free service. Gmail for Business (Google Workspace) or Microsoft 365 are both reasonable options and cost around £5-10 per user per month. This gives you two-factor authentication, better spam filtering, and doesn’t look dodgy to clients.
Enable two-factor authentication on your email account. This means that even if someone gets your password, they can’t log in without also having access to your phone. It’s the single most effective security control available to a small business.
Use a unique, strong password for your email that you don’t use anywhere else. A password manager like Bitwarden (free) or 1Password handles this for you so you don’t have to remember dozens of different passwords.
Your Website and Online Presence
If your business has a website that processes any payments or stores customer data, it needs SSL (the padlock in the browser bar). This is standard on most modern hosting platforms. If yours doesn’t have it, contact your web host or get a new one.
If you use a booking or quoting tool on your website, check that it’s maintained and updated. Outdated WordPress plugins are a consistent route into small business websites. If you’re not sure whether your site is up to date, a web developer can check for around £50-100 and fix any obvious problems.
For social media business accounts (Facebook, Instagram, Google Business Profile), use unique passwords and two-factor authentication. Account takeovers on these platforms are used for advertising fraud and reputation damage, and recovery can be slow.
NCSC’s Cyber Aware Scheme and Cyber Essentials
The NCSC (National Cyber Security Centre, part of GCHQ) offers free guidance specifically for small businesses through their Cyber Aware programme at cyberaware.gov.uk. It covers the six key controls that protect against the vast majority of attacks: strong passwords, multi-factor authentication, software updates, backing up data, protecting devices, and reporting incidents.
Cyber Essentials is a government-backed certification scheme that demonstrates you have the basic protections in place. For trades businesses working on government or local authority contracts, Cyber Essentials is sometimes required. Even if it’s not required for your work, the certification process (which costs from around £300 for self-assessment) walks you through fixing the gaps. The NCSC has subsidised access for small businesses.
What to Do If Something Goes Wrong
If you think you’ve been scammed or your accounts have been compromised, act quickly. Report to Action Fraud at actionfraud.police.uk or by calling 0300 123 2040. Contact your bank immediately if any money has moved or is at risk. Change passwords on any accounts that might be affected, starting with email. If you think your email has been accessed, check sent items and forwarding rules — criminals often set up forwarding rules to monitor your email after a breach.
You’re not alone in this. The NCSC’s 24/7 cyber incident helpline (03000 200 973) is available if you’ve suffered a serious incident and aren’t sure what to do. It’s free and intended for exactly this situation.