ISO 19650 and Penetration Testing: The Honest Picture for Construction Firms

ISO 19650 and Penetration Testing: The Honest Picture for Construction Firms

By EJN Labs · 29 Jul 2026 · 8 min read

ISO 19650 does not mandate iso 19650 penetration testing anywhere in its clauses. It is a voluntary information management standard for BIM, and its security part expects a risk-managed approach to protecting project information. In practice, that means testing your common data environment where risk justifies it. A typical UK CDE test runs 4 to 6 days, around £4,800 to £8,400.

What ISO 19650 penetration testing actually means for a construction firm

ISO 19650 penetration testing means less than vendors imply, because the standard does not force any construction firm to buy a test. ISO 19650 is the voluntary international standard for managing information across the life cycle of a built asset using building information modelling (BIM).

It is published by ISO and adopted in the UK through BSI. Search for the phrase and you will still find vendors implying a mandatory purchase, which is not what the standard says.

What makes it feel mandatory is procurement. UK public sector frameworks and a growing share of private clients specify ISO 19650 compliance in tenders. If you bid on BIM-mandated projects, you will be asked how you protect project information. That is where security evidence, including penetration testing of the systems holding that information, enters the conversation.

Why information security matters on BIM projects

Information security matters on BIM projects because a federated BIM model is never just drawings. Your common data environment (CDE) can hold structural calculations, access control and CCTV positions, plant room locations, commercial pricing and the personal data of site operatives.

For sensitive assets such as data centres, utilities or transport hubs, that information is genuinely valuable to hostile actors, not just competitors.

Construction also has a structural weakness: joint ventures and long supply chains mean dozens of organisations share the same CDE for years, with staff churn at every tier. An attacker rarely needs to break the platform itself. They need one credential from one subcontractor that nobody revoked.

What ISO 19650 actually says about security testing

Here is the honest picture. The core parts of ISO 19650 cover concepts, delivery and operation of information management. Security sits in ISO 19650-5, which sets out a security-minded approach: assess the sensitivity of your project information, then apply proportionate controls to people, processes and technology.

Nowhere does the standard name penetration testing as a required control, and we will not invent a clause number that says otherwise. What it does require is a risk-based judgement about how well the systems holding sensitive project information are protected. If your assessment concludes the CDE holds sensitive asset information, it is hard to argue you have applied proportionate technical controls without ever having them independently tested. Testing is not mandated, but it is the most credible evidence that your controls work.

In tenders, this shows up concretely. Employers increasingly ask bidders for security questionnaire responses, Cyber Essentials Plus certification, and evidence of recent independent testing of the environments that will hold project data. A clean report from a CREST-accredited firm answers that in one attachment.

What to test: the CDE and everything around it

When we scope this kind of engagement, we start from where the project information actually lives and who can reach it. A typical construction estate breaks down like this:

  • The common data environment itself. For a SaaS CDE, the test focuses on your tenant configuration: user roles, folder permissions, sharing links, MFA enforcement and integrations. If you self-host, the application and its infrastructure are in scope too.
  • Identity and access. Microsoft 365, single sign-on, and the joiners-movers-leavers process across your staff and supply chain accounts. This is where most real-world CDE compromises begin.
  • External infrastructure. VPN endpoints, remote desktop gateways and file transfer services exposed to the internet from head office or site offices. Our external infrastructure penetration testing covers this layer.
  • Cloud estate. Many firms sync models into their own Azure or AWS storage. Misconfigured storage is a classic leak path, and our cloud penetration testing addresses it directly.
  • APIs and integrations. CDEs connect to design tools, cost platforms and field apps through APIs, and each integration token is a credential worth stealing.

One first-hand detail from testing these estates: the most common finding is not a software vulnerability. It is live CDE accounts belonging to subcontractors whose involvement ended months earlier, still holding download rights to the full federated model. No exploit needed, just a password nobody rotated. That only surfaces when someone independent enumerates who can access what.

How an engagement runs

A typical engagement runs in five stages: scoping, legal authorisation, testing, reporting, then a free retest of critical and high findings. Testing usually takes one to two weeks, is run by UK-based testers, and is planned to keep disruption to live projects minimal.

Scoping is a short call to map your CDE, identity platform, external footprint and any employer security requirements from live tenders. Authorisation includes consent from the CDE vendor where their terms require it. Every finding is rated by real-world risk, with plain-English remediation steps your IT team or MSP can act on, and the retest means your final report shows issues closed, which is the version you attach to tenders.

Our penetration testing checklist walks through what to have ready before a test starts.

What it costs and how scope drives the price

Penetration testing in the UK is priced on tester days. Typical day rates run from £1,200 to £1,400, and days are driven by scope: how many external hosts, how large the cloud estate, how complex the CDE permission model. Typical ranges for construction and property firms:

ScopeTypical effortTypical cost
External infrastructure (head office and site connectivity)2 to 3 days£2,400 to £4,200
Cloud configuration review (Azure or AWS storage and identity)3 to 5 days£3,600 to £7,000
CDE tenant and web application testing4 to 6 days£4,800 to £8,400
Combined CDE, cloud and external estate6 to 9 days£7,200 to £12,600

These are typical UK ranges, not a quote. A firm with one SaaS CDE sits at the lower end; a contractor with joint ventures, self-hosted systems and a large cloud estate sits higher. For a fuller breakdown, see our guide to penetration testing cost in the UK. For an exact price, use the quote form.

How EJN Labs approaches ISO 19650 environments

EJN Labs is a CREST-accredited UK penetration testing firm, certified to ISO 27001 and Cyber Essentials Plus, with all testing delivered by UK-based testers. The employer’s information manager gets a report from an accredited firm they can accept without argument, and we hold ourselves to the same information security standard we are assessing in your environment.

We scope from your risk assessment, not from a product sheet. If your ISO 19650-5 sensitivity assessment says the information is low sensitivity, we will say a lighter external test is proportionate rather than sell you the full stack. If you are delivering a sensitive asset, we test the CDE, identity layer and cloud estate as one connected attack surface, because that is how an attacker sees it. The report serves two audiences: technical detail for your IT team, and a summary your bid team can hand to an employer as evidence of a security-minded approach. Our CREST penetration testing page explains the methodology, and our guide to choosing the best UK penetration testing provider covers what to check before you appoint anyone, including us.

Frequently Asked Questions

Does ISO 19650 require penetration testing?

No. ISO 19650 is a voluntary information management standard and none of its parts mandate penetration testing. ISO 19650-5 requires a security-minded, risk-based approach to protecting project information, which is where testing enters the picture for firms holding sensitive project data.

Where your risk assessment identifies sensitive information in your common data environment, independent testing is the strongest evidence that your technical controls actually work, and employers increasingly ask for it in tenders.

What does penetration testing cost for a construction firm?

Budget £2,400 to £12,600 at UK day rates of £1,200 to £1,400. An external infrastructure test is usually 2 to 3 days, £2,400 to £4,200, while a combined CDE, cloud and external engagement runs 6 to 9 days, £7,200 to £12,600. Scope drives the price.

A CDE tenant and web application test sits between those, typically 4 to 6 days, £4,800 to £8,400. An exact figure comes from a short scoping call.

Can we test a SaaS common data environment we do not own?

Yes, usually, within boundaries. You cannot authorise testing of the vendor’s underlying platform, but your tenant is yours, so user accounts, roles, folder permissions, sharing links, MFA enforcement and API integrations can all be assessed. Most major CDE vendors publish rules for customer security testing.

We handle that vendor authorisation as part of scoping, so nothing in the engagement breaches the vendor’s terms.

Will testing disrupt live construction projects?

It should not. Testing is scheduled around project deadlines and model submission dates agreed at scoping, and anything with the potential to affect availability is flagged before it runs. Most of the work is reading configuration, enumerating access and testing controlled exploit paths rather than anything destructive. Site operations and design teams normally notice nothing at all during the engagement.

How often should we repeat the test?

Repeat the test annually as a baseline, which is what most employers expect when asking for recent evidence in a tender, and retest sooner after major changes: a new CDE platform, a large joint venture mobilisation, a migration to new cloud storage, or a security incident.

Between full tests, quarterly reviews of supply chain account access close the gap where most real risk accumulates.

Get evidence an employer will accept

If ISO 19650 requirements are appearing in your tenders, the fastest route to credible security evidence is a scoped test of your CDE and the systems around it. Get a CREST pentesting quote and we will respond with a fixed scope and price within one working day.

Leave a Reply

Your email address will not be published. Required fields are marked *