How to Secure Mobile Devices Used on Construction Jobsites
Construction companies should secure jobsite tablets, phones and laptops with a five-part framework: manage every device centrally, require strong account security, protect business data, control network access and create clear procedures for lost devices and departing employees.
For a construction company with 25–50 employees, the minimum security standard should include:
- Individual user accounts
- Multi-factor authentication
- Full-device encryption
- Endpoint detection and response
- Automatic security updates
- Mobile device management
- Remote lock and wipe capabilities
- Secure jobsite Wi-Fi
- Documented onboarding and offboarding
- Tested backup and incident response procedures
These controls protect access to Procore, Microsoft 365, Bluebeam, Sage, project drawings, contracts, payment information and customer communications. They also reduce the risk that a lost tablet, stolen laptop or compromised password will interrupt a project.
This guide explains how construction companies can protect mobile devices without making field technology difficult to use.
The Five-Part Jobsite Device Security Framework
- Inventory and centrally manage every device.
- Secure employee identities and application access.
- Protect data stored on devices and in the cloud.
- Secure office, remote and jobsite connections.
- Prepare for loss, theft, employee departure and cyber incidents.
The objective is not to eliminate mobile technology. Construction employees need fast access to drawings, photos, schedules, email and project applications. The objective is to provide that access through managed devices, verified identities and documented security controls.
For broader industry support, review 911 IT's construction IT services.
Why Jobsite Devices Create Unique Security Risks
Construction technology moves between offices, homes, vehicles, trailers and active jobsites. A project manager may use a laptop at the office, a tablet in the field and a phone while traveling between projects.
That creates several risks:
- Devices can be lost, stolen or physically damaged.
- Employees may connect through public or unsecured Wi-Fi.
- Personal and business information may exist on the same device.
- Shared devices can make individual activity difficult to trace.
- Field devices may miss security updates.
- Former employees may retain access after leaving.
- Saved passwords may expose cloud applications.
- Project files may be copied into unapproved applications.
- Temporary jobsites may use poorly secured networking equipment.
A device does not need to store every project document locally to create risk. An unlocked phone or compromised laptop may provide access to email, cloud storage, payment conversations and business applications.
Step 1: Inventory and Manage Every Device
A construction company cannot protect devices it does not know exist. Begin by creating an inventory of every company-owned laptop, tablet and smartphone.
What to Record in a Device Inventory
- Assigned employee
- Device type
- Manufacturer and model
- Serial number
- Operating system
- Purchase date
- Warranty expiration
- Encryption status
- Security software status
- Mobile management status
- Primary office or jobsite
- Replacement date
The inventory should be updated when a device is purchased, reassigned, repaired, lost, retired or returned by an employee.
Use Mobile Device Management
Mobile device management allows an IT administrator to apply consistent security settings to laptops, tablets and smartphones.
Depending on the device and management platform, the company may be able to:
- Require a passcode
- Enforce encryption
- Install approved applications
- Remove unauthorized applications
- Require current operating systems
- Configure email and Wi-Fi settings
- Separate business information from personal data
- Block devices that do not meet security standards
- Lock or erase a lost device
- Produce compliance reports
Microsoft Intune is one example of a platform used to manage devices and applications in a Microsoft 365 environment. The correct platform depends on the company's device mix, applications and security requirements.
Standardize Device Models
Supporting too many device types increases troubleshooting time and makes consistent security harder. A construction company should establish approved standards for:
- Office laptops
- Field laptops
- Tablets
- Smartphones
- Estimating and design workstations
Approved devices should meet minimum requirements for performance, encryption, operating system support and warranty coverage.
Replace Unsupported Devices
Devices should not remain in service after their operating systems stop receiving security updates. Older equipment may also be unable to run modern endpoint protection or construction applications reliably.
A hardware lifecycle plan should identify which devices will be replaced during the next 12–36 months so purchases can be budgeted rather than handled as emergencies.
Step 2: Secure Employee Accounts and Application Access
A secure device can still expose business information when the employee's account is compromised. Identity protection should be treated as seriously as device protection.
Require Individual Accounts
Every employee should have a unique account. Shared accounts make it difficult to determine who accessed, changed or downloaded information.
Individual accounts also make it easier to:
- Assign role-based permissions
- Review user activity
- Reset compromised credentials
- Remove access when an employee leaves
- Restrict users to assigned projects
Enable Multi-Factor Authentication
Multi-factor authentication requires users to provide a second form of verification in addition to a password. It should be enabled for Microsoft 365, remote access, administrative accounts and other critical cloud applications whenever supported.
Multi-factor authentication is especially important for:
- Procore
- Cloud storage
- Accounting systems
- Remote access tools
- Administrative portals
- Payroll and banking platforms
Whenever possible, use an authenticator application or hardware security key rather than relying only on text-message codes.
Use Role-Based Access
Employees should receive the minimum access required for their responsibilities.
For example:
- Superintendents receive access to assigned projects and field documentation.
- Project managers receive access to project financials and coordination tools.
- Estimators receive access to bidding and estimating resources.
- Accounting employees receive access to financial applications.
- Subcontractors receive limited, project-specific access.
- Temporary workers receive time-limited access.
Permissions should be reviewed when an employee changes roles, a project closes or a contractor's work ends.
Do Not Save Passwords in Unapproved Locations
Passwords should not be stored in spreadsheets, notebooks, text messages or browser profiles shared by several employees. Use an approved password manager with individual accounts, access controls and auditing.
Limit Administrator Rights
Most employees do not need administrator privileges on their laptops. Removing unnecessary local administrator access reduces the risk that unauthorized software or malicious code can change the device.
Administrative accounts should be separate from normal daily-use accounts and protected with stronger controls.
Step 3: Protect Business Data on Devices and in the Cloud
Construction companies should assume that a field device may eventually be lost, stolen or damaged. Security controls should prevent the device from becoming an easy path into company data.
Encrypt Laptops, Tablets and Phones
Encryption protects information stored on the device when it is powered off or locked. Without encryption, someone with physical access may be able to remove the storage drive or use recovery tools to access files.
Encryption should be enabled on:
- Windows laptops
- Mac computers
- Company-owned tablets
- Company-issued smartphones
- Portable storage devices when business use is approved
Encryption recovery keys should be stored securely in a centrally managed system rather than relying on the employee to remember or retain them.
Use Endpoint Detection and Response
Traditional antivirus looks primarily for known malicious files. Endpoint detection and response monitors device activity for suspicious behavior, such as credential theft, ransomware activity or unauthorized system changes.
A managed endpoint security service may provide:
- Continuous monitoring
- Suspicious behavior detection
- Automated isolation
- Threat investigation
- Central reporting
- Incident escalation
Learn more about device and account protection through 911 IT's cybersecurity services.
Install Security Updates Automatically
Laptops and mobile devices should receive operating system, browser and application updates through a centrally managed process.
Patch management should cover:
- Windows and macOS
- iOS and Android
- Web browsers
- PDF applications
- Microsoft 365 applications
- Remote access tools
- Construction applications when centrally supported
- Common third-party software
Critical updates should be deployed promptly, while routine updates should follow a tested maintenance schedule.
Control Local File Storage
Employees should know where project and business information belongs. Files should not be scattered across desktops, personal cloud accounts, removable drives and unapproved messaging applications.
A documented storage policy should define:
- Which information belongs in Procore
- Which files belong in SharePoint or Teams
- Which documents belong in OneDrive
- Which records belong in the accounting platform
- Whether local storage is permitted
- How information may be shared externally
- How completed project records are retained
Back Up Critical Cloud and Local Data
Cloud applications improve availability, but they do not eliminate every data-loss scenario. Accidental deletion, compromised accounts, ransomware, synchronization errors and retention limits may still affect business information.
Backup planning may need to cover:
- Microsoft 365 email
- SharePoint
- OneDrive
- Local file servers
- Accounting data
- Estimating files
- Project documents stored outside Procore
- Critical workstation data
Backups should be monitored and tested through actual restoration exercises. Review 911 IT's business continuity services for backup and disaster recovery options.
Step 4: Secure Jobsite, Office and Remote Connections
Field devices frequently connect through networks the construction company does not fully control. A secure device can still be exposed when it connects through a poorly configured jobsite network or public hotspot.
Use Business-Grade Jobsite Networking Equipment
Temporary jobsites should use managed firewalls, wireless access points and connectivity equipment appropriate for the number of employees and devices.
A business-grade jobsite network should support:
- Secure wireless encryption
- Separate employee and guest networks
- Content filtering
- Remote monitoring
- Centralized configuration
- Security updates
- Backup connectivity when required
Consumer-grade routers may not provide the visibility, network separation or support required for a busy project site.
Separate Different Types of Network Traffic
Employee devices, subcontractor devices, guests, cameras and connected equipment should not automatically share the same network.
Network separation reduces the chance that an unmanaged device can directly reach company resources.
Common network segments include:
- Company employees
- Guest and subcontractor access
- Security cameras
- Printers and connected equipment
- Administrative network management
Plan Connectivity Before Mobilization
Internet and wireless requirements should be evaluated before field personnel arrive.
The jobsite plan should answer:
- Which wired services are available?
- How long will installation take?
- Which cellular carriers have usable coverage?
- How many users and devices will connect?
- Will cameras or connected equipment use the network?
- Will subcontractors require guest access?
- What happens if the primary connection fails?
- Who will monitor and support the network?
Use Secure Remote Access
Procore and Microsoft 365 are cloud-based, but employees may still need secure access to private file servers, accounting systems or other internal applications.
Remote access should use:
- Multi-factor authentication
- Encrypted connections
- Approved company devices
- Restricted user permissions
- Logging and monitoring
- Automatic session timeouts
Legacy remote-access methods that expose internal systems directly to the internet should be replaced with modern, monitored solutions.
Avoid Untrusted Public Wi-Fi
Employees should avoid accessing sensitive systems through open public networks whenever possible. Safer alternatives include:
- Company-managed cellular hotspots
- Approved mobile tethering
- Secure jobsite Wi-Fi
- Encrypted remote-access tools
- Company-managed cellular routers
When travel requires public Wi-Fi, employees should use approved security controls and avoid conducting sensitive financial activity unless the connection is trusted.
Step 5: Prepare for Lost Devices, Employee Departures and Incidents
Security procedures should be written before an incident occurs. Employees should know exactly what to do when a device is lost, stolen, compromised or left behind at a project site.
Lost or Stolen Device Procedure
- Report the loss immediately to a supervisor and the IT provider.
- Identify the employee, device and last known location.
- Lock or erase the device remotely when appropriate.
- Revoke active cloud sessions.
- Reset exposed credentials.
- Review recent account activity.
- Confirm whether sensitive data was stored locally.
- Document the incident.
- Notify management, legal counsel or insurance contacts when required.
- Issue a secured replacement device.
Employees should not wait until the next business day to report a missing device. The faster the company acts, the more likely it is to contain the risk.
Compromised Account Procedure
When an employee enters credentials into a phishing page or notices suspicious activity, the IT team should:
- Reset the password.
- Revoke existing sessions.
- Review multi-factor authentication methods.
- Inspect mailbox forwarding and inbox rules.
- Review sign-in history.
- Check for unauthorized application access.
- Notify affected employees or business partners when necessary.
- Document the cause and corrective action.
Employee Offboarding Procedure
When an employee or subcontractor leaves, the construction company should disable access promptly.
The process should include:
- Disabling Microsoft 365 and application accounts
- Revoking cloud sessions
- Recovering company-owned devices
- Removing mobile access
- Transferring email and project files
- Reviewing forwarding rules
- Removing Procore permissions
- Recovering keys, badges and access tokens
- Preserving required business records
- Updating the device inventory
The offboarding date and time should be coordinated between management, human resources and IT.
Company-Owned Devices Versus Bring Your Own Device
| Category | Company-Owned Devices | Personal Devices |
|---|---|---|
| Security control | High | Limited unless enrolled |
| Application management | Centralized | May be restricted |
| Remote wipe | Can remove the full device | Should remove only business data |
| Employee privacy | Lower expectation of personal use | Requires clear separation |
| Support complexity | Lower with standardized models | Higher across many device types |
| Replacement process | Controlled by the company | Dependent on the employee |
Company-owned devices usually provide the strongest security and support consistency. A bring-your-own-device policy may be appropriate for limited use, but it should define minimum security requirements and which company applications may be accessed.
Minimum Requirements for Personal Devices
- A supported operating system
- A passcode or biometric lock
- Encryption
- Multi-factor authentication
- Approved mobile management
- Separation of business and personal information
- The ability to remove company data
- Immediate reporting of loss or theft
Employees should acknowledge the policy before accessing business information from a personal device.
How to Secure Procore Access on Mobile Devices
Procore access should follow the same identity and device security standards as other critical applications.
Procore Mobile Security Checklist
- Every user has an individual account.
- Multi-factor authentication is enabled when available.
- Permissions match the employee's role and assigned projects.
- Former users are removed promptly.
- Devices are encrypted and centrally managed.
- Operating systems and applications are current.
- Employees use approved networks and remote-access methods.
- Locally downloaded project information is protected.
- Subcontractor access is limited and reviewed.
- Account activity is investigated when suspicious behavior is reported.
For a broader discussion of the infrastructure surrounding Procore, review the company's construction technology requirements with an experienced construction IT provider.
How to Secure Microsoft 365 on Jobsite Devices
Microsoft 365 often provides email, Teams, SharePoint, OneDrive and identity services for construction companies. Because one Microsoft 365 account may provide access to several systems, strong account security is essential.
Microsoft 365 Security Priorities
- Require multi-factor authentication.
- Block outdated authentication methods.
- Review administrator roles.
- Apply sign-in and device-access policies.
- Protect email from phishing and impersonation.
- Monitor suspicious sign-ins.
- Review automatic forwarding rules.
- Manage devices through approved policies.
- Back up critical email and cloud data.
- Remove former employees promptly.
Conditional access policies can restrict sensitive applications based on the user, device, location or level of risk. These policies should be tested carefully to avoid interrupting legitimate field access.
How to Protect Devices From Phishing and Payment Fraud
A secure device cannot prevent every employee from responding to a convincing fraudulent message. Construction companies should combine technical protection with employee training and payment-verification procedures.
Common Warning Signs
- An urgent request to change banking information
- A message from an executive requesting unusual secrecy
- A login page reached through an unexpected email
- A vendor invoice with changed payment instructions
- A request to purchase gift cards
- A message sent from a slightly altered domain name
- An unexpected multi-factor authentication prompt
- A file-sharing invitation from an unfamiliar sender
Payment Verification Procedure
- Do not approve banking changes from email alone.
- Call a known contact using a previously verified number.
- Require a second employee to approve significant changes.
- Document the verification.
- Report suspicious messages to IT.
Employees who work from mobile devices should be particularly cautious because small screens can make altered email addresses and fraudulent links harder to recognize.
Security Requirements for Government Construction Work
Construction companies working on certain government or defense-related contracts may have additional security obligations involving CMMC, NIST or DFARS.
Depending on the contract and information handled, the company may need controls involving:
- Device inventory
- Multi-factor authentication
- Encryption
- Access control
- Security logging
- Incident reporting
- Media protection
- System documentation
- Employee training
- Risk assessments
Companies handling regulated information should not assume that standard mobile device settings are sufficient. Review 911 IT's CMMC compliance services for help evaluating contractual cybersecurity requirements.
Common Jobsite Device Security Mistakes
1. Sharing User Accounts
Shared credentials reduce accountability and make access difficult to remove when someone leaves.
2. Allowing Unmanaged Personal Devices
Personal devices may lack encryption, security updates and remote-removal capabilities.
3. Using Consumer-Grade Jobsite Wi-Fi
Home networking equipment may not provide adequate monitoring, segmentation or security.
4. Failing to Encrypt Devices
A strong password does not provide the same protection as full-device encryption.
5. Ignoring Mobile Application Updates
Outdated operating systems and applications may contain known security weaknesses.
6. Giving Every Employee Administrator Rights
Excessive permissions make unauthorized changes and malicious software more dangerous.
7. Waiting to Report a Lost Device
Delayed reporting gives unauthorized users more time to access accounts and information.
8. Saving Project Files in Personal Cloud Accounts
The company may lose control of access, retention and recovery.
9. Leaving Former Employee Accounts Active
Offboarding should occur at the employee's departure time, not days or weeks later.
10. Assuming Mobile Devices Are Too Small to Matter
A phone may provide access to email, authentication prompts, cloud storage, payment conversations and business applications.
Jobsite Device Security Checklist
Device Management
- Every device is recorded in an inventory.
- Company devices are centrally managed.
- Approved hardware standards are documented.
- Unsupported devices are replaced.
- Security status can be reviewed remotely.
Identity and Access
- Every employee has an individual account.
- Multi-factor authentication is enabled.
- Permissions are based on job responsibilities.
- Administrator rights are restricted.
- Former employee access is removed promptly.
Data Protection
- Devices are encrypted.
- Endpoint detection and response is active.
- Security updates are centrally managed.
- Approved file-storage locations are documented.
- Critical cloud and local data are backed up.
Connectivity
- Jobsite networks use business-grade equipment.
- Employee and guest networks are separated.
- Remote access requires multi-factor authentication.
- Public Wi-Fi use is restricted.
- Backup connectivity is planned where necessary.
Incident Readiness
- Employees know how to report lost devices.
- Devices can be locked or wiped remotely.
- Cloud sessions can be revoked quickly.
- Offboarding procedures are documented.
- Incident response roles are assigned.
A 30-Day Device Security Improvement Plan
Week 1: Inventory Devices and Accounts
- List company laptops, tablets and phones.
- Identify assigned employees.
- Document operating systems and warranty dates.
- List applications accessed from each device type.
- Identify shared and former employee accounts.
Week 2: Address Immediate Security Gaps
- Enable multi-factor authentication.
- Encrypt laptops and mobile devices.
- Remove unnecessary administrator rights.
- Disable unused accounts.
- Confirm endpoint protection is active.
Week 3: Improve Management and Connectivity
- Enroll devices in a management platform.
- Apply approved security policies.
- Review jobsite Wi-Fi configurations.
- Separate employee and guest traffic.
- Test remote lock and wipe capabilities.
Week 4: Document Procedures
- Create a lost-device procedure.
- Document employee onboarding and offboarding.
- Define approved applications and storage locations.
- Train employees on phishing and payment fraud.
- Schedule quarterly device and access reviews.
Questions to Ask an IT Provider About Mobile Device Security
- How will you inventory our laptops, tablets and phones?
- Which device management platform do you recommend?
- Can you manage company-owned and personal devices differently?
- How do you enforce encryption?
- Can you remotely lock or wipe a lost device?
- How do you protect Microsoft 365 and Procore accounts?
- Which endpoint security tools are included?
- How quickly are critical security updates deployed?
- Can you design and monitor jobsite networks?
- How do you separate employee and guest traffic?
- What happens when an employee reports a phishing attack?
- How do you handle employee onboarding and offboarding?
- Are mobile security services included in the monthly fee?
- Who monitors alerts outside normal business hours?
- Can you help with CMMC or other contractual requirements?
Frequently Asked Questions
What is the best way to secure construction tablets?
Use company-managed devices with encryption, strong passcodes, multi-factor authentication, endpoint security, automatic updates and remote lock or wipe capabilities.
Should construction employees use personal phones for work?
Personal phones may be used under a documented bring-your-own-device policy. The company should require minimum security standards and use application management to separate and remove business information.
Can a company remotely erase a lost tablet?
Yes, when the device is enrolled in an appropriate management platform and remains capable of connecting to the internet. The remote-wipe process should be configured and tested before a device is lost.
Does a password protect data on a stolen laptop?
A password provides some protection, but full-device encryption is also required. Encryption protects stored information when someone attempts to bypass the normal login process.
Should every jobsite have separate guest Wi-Fi?
Yes. Guest and subcontractor devices should generally be separated from company-managed devices, network equipment and internal resources.
Is public Wi-Fi safe for Procore and Microsoft 365?
Employees should use company-managed cellular connections or secure jobsite Wi-Fi whenever possible. When public Wi-Fi is unavoidable, use approved encrypted connections, multi-factor authentication and managed devices.
How quickly should a lost device be reported?
Immediately. Fast reporting allows IT to lock the device, revoke cloud sessions, reset credentials and investigate recent activity.
How often should mobile device access be reviewed?
Review access when employees change roles or leave, when projects end and during scheduled quarterly access reviews.
Do mobile devices need endpoint security?
Laptops require managed endpoint protection. Tablets and smartphones should use the security controls supported by their operating systems, including management policies, encryption, application controls and remote removal.
How much does managed IT security cost for a construction company?
A construction company with 25–50 employees may commonly budget approximately $100–$275 per user per month for managed IT services, depending on devices, jobsites, cybersecurity, backups and support scope.
Why Construction Companies Work With 911 IT
911 IT helps construction companies protect the laptops, tablets, phones, accounts and networks employees use in the office and across active jobsites.
Construction clients receive access to:
- Live 24/7 help desk support
- Remote and onsite assistance
- Mobile device management
- Endpoint security and monitoring
- Microsoft 365 administration
- Jobsite network planning
- Backup and business continuity services
- Employee onboarding and offboarding
- Cybersecurity planning
- A 100% satisfaction guarantee
“The remote service is great, so we don't have to worry about the security of our computers.”
Sam, Owner, Construction Industry
“They are always available and can take care of any need we have right away. I never panic anymore when something isn't working right. I just call anyone on the team, and they pleasantly take over.”
Rhonda, Office Administrator, Construction Industry
To evaluate your device inventory, Microsoft 365 security, field access and jobsite networks, schedule a discovery call. You can also contact 911 IT for additional information.
