IT for construction firms chasing enterprise project work
GC prequalification packets now include cybersecurity sections. What a 15-50 person contractor needs to pass upstream security review and win bigger work.
· Jake Schaaf, Founder of Atticus Rowan
The prequalification packet from the general contractor used to ask about bonding capacity, safety record and references. The current version has a new section, and it is not short: does your firm enforce multi-factor authentication, do you carry cyber insurance, do you run endpoint protection on field devices, when did you last test your backups, have you had a breach in the last 3 years.
For a 30-person specialty contractor, that section is where bigger work now gets won or lost before anyone reviews a bid number. GCs and owners are pushing security requirements down their subcontractor chains for the same reason manufacturers push them down supply chains: a subcontractor with access to project schedules, drawings, badging lists and payment flows is part of the project’s attack surface. When an owner’s security team reviews the project, every connected party gets reviewed with it.
This is a familiar pattern to us. The upstream pressure that hit manufacturing suppliers years ago, which we cover in our customer security questionnaire walkthrough, has arrived in commercial construction. The playbook for passing it translates well, but construction adds field conditions that office-centric security advice ignores. Here is what the requirements actually look like and how a 15-50 person firm gets ready.
Why construction firms are getting asked
Three forces converged:
- Payment fraud found the industry. Construction payment flows are large, milestone-based and coordinated over email among parties who have often never met in person. A fraudster who compromises or convincingly imitates a subcontractor’s email can redirect a progress payment with one message. That scam, business email compromise, is built for exactly this environment, and GCs have been burned enough to start asking about the controls that stop it.
- Project data went digital and shared. Drawings, schedules, RFIs and submittals now live in shared platforms. Every firm with a login is a possible entry point to every other firm on the project.
- Insurers and owners tightened together. Owners require GCs to carry cyber coverage, insurers price that coverage on downstream controls and the requirements roll downhill to every sub on the bid list.
The result: cybersecurity questions are becoming standard prequalification content alongside EMR ratings and OSHA logs.
What the packet actually asks
Across the prequalification and vendor-review forms circulating in commercial construction, the security section is consistent. Expect direct questions on:
- MFA on email and financial systems
- Endpoint protection (and increasingly EDR by name) on company computers, including field laptops
- Cyber insurance, with certificate and limits
- Backup, with words like “tested” and “offline or immutable”
- A named person responsible for security
- Employee security training
- Breach history and whether an incident response plan exists
Notice what is not on the list: nothing exotic. This is the same fundamentals-first checklist that a well-run 25-person office in any industry should have. The difference is that in construction, half of the endpoints live in trucks and trailers.
The field reality
Security advice written for offices breaks at the jobsite, and any provider serving contractors has to account for it:
- The jobsite trailer network is shared and temporary. Multiple subs on one hotspot or trailer Wi-Fi, stood up in a day, secured by whoever got there first. Company laptops on that network need to treat it as hostile: EDR running, disk encrypted, firewall on, VPN or cloud-app access with MFA. The same assume-hostile-network model that works for remote-first companies works on a jobsite, because a trailer is just a muddier coffee shop.
- Superintendents run the project from personal tablets and phones. Banning that fails. The workable answer is app protection policies that wall off company email and project apps from the rest of the device, with the ability to wipe company data when someone leaves, without touching family photos.
- Field turnover is constant and offboarding is weak. Crews change, project engineers rotate and shared logins to the project management platform outlive everyone who created them. Named accounts, MFA and same-day deactivation matter more in high-turnover environments, not less.
- SaaS sprawl is project-shaped. Procore-class project management, estimating tools, drone and photo documentation platforms, telematics, timekeeping. Each project adds logins and each login is an access point that someone needs to inventory and eventually shut off.
- Devices get stolen. Trucks get broken into and trailers get burglarized. Disk encryption plus cloud-synced files turn a stolen laptop from a data breach into a hardware receipt.
The 90-day path to an answerable packet
For a contractor staring at a prequalification security section, the honest sequence looks like this:
- Weeks 1-2: MFA everywhere. Email first, then the accounting system, then the project platforms. This single control answers the most questions per dollar of anything on the list.
- Weeks 2-4: EDR on every company computer, office and field. Not consumer antivirus. The distinction, and why underwriters and reviewers care, is covered in EDR vs antivirus.
- Weeks 3-6: fix the payment-change process. Written rule: any change to payment instructions, yours or a sub’s, gets verified by phone at a known number before money moves. Free, immediate and the control that most directly protects construction cash flow.
- Weeks 4-8: backup with proof. Automated backup of the file server or cloud tenant, with a restore actually tested and the test dated. “We think so” is a failing answer to “are backups tested.”
- Weeks 6-10: write the 1-page security summary. Who owns security, what controls run, insurance limits, training cadence. This becomes your standard packet insert and turns every future questionnaire from a scramble into an attachment.
- Weeks 8-12: baseline training. Short, recurring security awareness training with a construction flavor: payment fraud, text-message impersonation of PMs and executives, jobsite device habits.
A firm that completes this list can answer the current generation of GC and owner security sections truthfully and without hedging. In our experience with upstream reviews in other industries, truthful and specific beats polished and vague every time.
What this buys beyond the checkbox
The controls that pass prequalification are the same ones that keep a contractor solvent. The industry’s real, recurring loss event is not a headline breach. It is a progress payment wired to a fraudster’s account, and the controls above (MFA, verification callbacks, trained staff) are the specific defenses against it. Passing the packet and protecting the bank account are the same project.
Atticus Rowan brings a security-first managed IT model built on exactly these fundamentals: identity, endpoint, backup and the documentation that makes upstream reviewers comfortable. For a construction firm sizing up bigger commercial work, we can assess where you stand against the packets you are seeing and close the gaps in priority order. Start the conversation.
Related insights
More on Operations & OT →September 11, 2026
Choosing practice management software: the security questions that matter
The platform that will hold every client record deserves more scrutiny than the sales demo gave it. Here are the questions to ask before you sign.
September 9, 2026
Stop emailing client files: secure exchange for professional practices
Tax documents and case files still travel as email attachments. Here is how a 5 to 50 person practice standardizes one secure channel without losing clients along the way.
September 4, 2026
The Windows 7 box running your CNC: legacy systems on the plant floor
When the controller PC cannot be upgraded and cannot be replaced, you still have 4 real options. Here is how to rank them honestly.