How Frequently Construction Companies Should Assess Cybersecurity
A construction company with 25–50 employees should complete a formal cybersecurity assessment at least once every 12 months. It should also perform targeted reviews after major technology changes, mergers, new government contracts, security incidents, office moves or the launch of new jobsites.
Annual reviews are the minimum. Higher-risk contractors may need quarterly vulnerability reviews, monthly security reporting and continuous monitoring of devices, networks and cloud accounts.
A practical assessment schedule includes:
- Continuous monitoring of devices and cloud accounts
- Monthly review of alerts, patching and backup status
- Quarterly access, vulnerability and risk reviews
- Annual comprehensive cybersecurity assessment
- Immediate reassessment after significant business or technology changes
The purpose is not simply to produce a report. A useful assessment identifies real risks, assigns priorities, estimates costs and creates a documented remediation plan.
The Five-Part Construction Cybersecurity Assessment Framework
- Inventory systems, users and sensitive information.
- Evaluate identity, device, network and cloud security.
- Review backup, recovery and incident response readiness.
- Measure risks against business and compliance requirements.
- Create a prioritized remediation roadmap.
Construction companies should repeat this process regularly because employees, jobsites, applications and cyber risks change throughout the year.
For industry-specific support, review 911 IT's construction IT services.
Why Construction Companies Need Regular Cybersecurity Assessments
Construction companies combine financial systems, project applications, cloud collaboration, mobile devices, subcontractor access and temporary jobsite networks. That creates a broad and changing technology environment.
A company may hold or access:
- Banking and payment instructions
- Employee and payroll records
- Customer information
- Contracts and change orders
- Bids and estimates
- Project plans and drawings
- Insurance documents
- Subcontractor information
- Government contract data
- Microsoft 365 email and files
Attackers may use phishing, stolen passwords, fraudulent payment requests, ransomware and compromised vendor accounts to reach this information.
A cybersecurity assessment helps leadership answer five important questions:
- Which systems and information are most important?
- Where are the greatest security gaps?
- How likely is each risk to interrupt operations or create financial loss?
- Which improvements should be completed first?
- What should the company budget during the next 12–36 months?
How Often Should Each Security Activity Occur?
| Security Activity | Recommended Frequency |
|---|---|
| Endpoint and cloud security monitoring | Continuous |
| Critical alert review | Immediate |
| Patch and device compliance review | Monthly |
| Backup status review | Daily or automated with alerting |
| Sample backup restoration | Quarterly |
| User access review | Quarterly and after role changes |
| Vulnerability review | Quarterly |
| Phishing simulation or awareness activity | Quarterly |
| Incident response exercise | At least annually |
| Comprehensive cybersecurity assessment | Annually |
| Policy review | Annually or after major changes |
| Compliance gap assessment | Annually and before relevant contract deadlines |
These are general planning ranges. Companies with regulated information, repeated incidents or high-value contracts may require more frequent testing.
Step 1: Inventory Users, Devices, Applications and Data
Every security assessment should begin with an accurate inventory. A company cannot properly evaluate risks involving systems it does not know exist.
User Inventory
Document:
- Employees
- Temporary workers
- Subcontractor accounts
- Shared mailboxes
- Administrative accounts
- Former employee accounts
- External vendor access
- Service and integration accounts
Device Inventory
Include:
- Desktop computers
- Laptops
- Tablets
- Smartphones
- Servers
- Firewalls
- Network switches
- Wireless access points
- Printers and scanners
- Jobsite routers
- Security cameras and connected equipment
Application Inventory
Construction environments may include:
- Microsoft 365
- Procore
- Bluebeam
- Autodesk Construction Cloud
- AutoCAD
- Sage
- QuickBooks
- Buildertrend
- On-Screen Takeoff
- Payroll and banking systems
- Cloud storage platforms
- Remote access tools
Data Inventory
Identify where sensitive information is stored and who can access it.
Examples include:
- Financial records
- Employee information
- Customer records
- Project documentation
- Government-controlled information
- Contracts
- Bids and estimates
- Payment instructions
- Insurance records
Identify Unmanaged Technology
The assessment should look for technology that was added outside the formal IT process, including:
- Personal cloud storage
- Unapproved mobile applications
- Shared passwords
- Consumer file-sharing tools
- Personal email accounts
- Unmanaged jobsite devices
- Temporary routers and hotspots
- Old applications still accessible from the internet
Unmanaged technology often creates some of the largest security gaps because it may not be patched, monitored or included in backup plans.
Step 2: Evaluate Identity and Access Security
Many cyber incidents begin with a compromised user account rather than a direct attack on a server or firewall. Identity security should be one of the highest priorities in every assessment.
Identity Controls to Review
- Multi-factor authentication
- Password policies
- Administrative accounts
- Shared accounts
- Former employee access
- Application permissions
- Remote access
- Cloud sign-in monitoring
- Mailbox forwarding rules
- Third-party application access
Multi-Factor Authentication
Multi-factor authentication should be required for:
- Microsoft 365
- Remote access
- Administrative portals
- Accounting systems
- Payroll platforms
- Cloud storage
- Project management applications when supported
The assessment should verify that the control is active for every required user rather than relying on a policy statement.
Administrative Access
Review who has administrator privileges and whether those privileges are necessary.
Recommended controls include:
- Separate administrator and daily-use accounts
- Multi-factor authentication
- Restricted local administrator access
- Logging of privileged activity
- Regular access reviews
- Immediate removal of unused accounts
Former Employees and Contractors
The assessment should compare current employee records with active accounts across Microsoft 365, Procore, accounting systems and other applications.
Any unneeded account should be disabled or removed promptly.
Role-Based Access
Employees should have access only to the information required for their jobs.
Examples include:
- Field employees access assigned projects.
- Estimators access bidding resources.
- Accounting staff access financial systems.
- Subcontractors receive limited project access.
- Temporary users receive time-limited permissions.
Step 3: Assess Device and Endpoint Security
Construction devices move between offices, vehicles, homes and active jobsites. The assessment should verify that each device meets a consistent security standard.
Endpoint Controls to Review
- Operating system support
- Security patch status
- Full-device encryption
- Endpoint detection and response
- Automatic screen locking
- Local administrator rights
- Approved application policies
- Remote management
- Mobile device management
- Lost-device procedures
Unsupported Devices
Computers and mobile devices should not remain in use after they stop receiving security updates. The assessment should identify:
- Unsupported operating systems
- Expired hardware warranties
- Devices unable to run current security tools
- Equipment with recurring reliability problems
- Devices missing from central management
Encryption Verification
Do not assume devices are encrypted because the operating system supports encryption. The assessment should confirm that encryption is enabled and recovery keys are stored securely.
Endpoint Monitoring
Endpoint detection and response should provide central visibility into suspicious activity.
The assessment should determine:
- Which devices are monitored
- Who receives alerts
- Whether alerts are reviewed 24/7
- How compromised devices are isolated
- How incidents are documented
911 IT's cybersecurity services help protect devices, cloud accounts, email and company information.
Step 4: Review Email and Microsoft 365 Security
Email is a common path for phishing, account theft, malware and payment fraud. Microsoft 365 security should receive a dedicated review.
Microsoft 365 Controls to Evaluate
- Multi-factor authentication
- Administrator roles
- Legacy authentication
- Suspicious sign-in monitoring
- Email filtering
- Impersonation protection
- External forwarding
- Mailbox rules
- Third-party application permissions
- Mobile device access
- Data retention
- Backup protection
Executive and Vendor Impersonation
Construction companies regularly exchange invoices, change orders and payment instructions. Attackers may impersonate:
- Owners
- Executives
- Project managers
- Vendors
- Subcontractors
- Accounting employees
The assessment should determine whether email security tools can detect suspicious sender names, look-alike domains and unusual payment-related messages.
Payment Change Verification
The company should have a written procedure requiring independent verification of banking changes.
A secure process includes:
- Do not approve the change through email alone.
- Call a known contact using a previously verified number.
- Require approval from a second employee.
- Document the verification.
- Report suspicious requests to IT.
Cloud Application Permissions
Third-party applications may have permission to access email, files or user profiles. The assessment should identify unnecessary or high-risk integrations and remove those that are no longer required.
Step 5: Evaluate Office and Jobsite Network Security
Construction companies may maintain one main office, several temporary jobsites and remote employees. Each connection point should be reviewed.
Office Network Controls
- Business-grade firewall
- Supported firewall software
- Managed switches
- Managed wireless access points
- Separate guest network
- Secure remote administration
- Content and threat filtering
- Configuration backups
- Monitoring and alerting
Jobsite Network Controls
- Business-grade router or cellular gateway
- Secure wireless encryption
- Separate employee and guest access
- Remote monitoring
- Updated firmware
- Restricted administrative access
- Backup connectivity where required
- Network separation for cameras and connected equipment
Public and Remote Access
The assessment should identify how employees connect while traveling or working from home.
Secure remote access should include:
- Multi-factor authentication
- Encrypted connections
- Approved devices
- Restricted permissions
- Session timeouts
- Logging and monitoring
Network Documentation
Every office and major jobsite should have current documentation showing:
- Internet provider
- Firewall and router details
- Wireless configuration
- Administrative ownership
- Connected equipment
- Vendor contacts
- Support responsibilities
Step 6: Review Backup and Recovery Readiness
A cybersecurity assessment is incomplete without reviewing whether the company can recover from ransomware, accidental deletion, hardware failure or cloud account compromise.
Systems That May Need Backup Protection
- Microsoft 365 email
- SharePoint
- OneDrive
- Accounting data
- Estimating files
- Local servers
- Critical workstations
- Project information stored outside the primary construction platform
- Network and firewall configurations
Backup Questions to Answer
- What information is backed up?
- How frequently does backup occur?
- How long are copies retained?
- Where are backup copies stored?
- Who receives failure alerts?
- Can attackers modify or delete the backups?
- When was the last successful restoration test?
- How quickly can critical systems be restored?
Recovery Point and Recovery Time Objectives
For each critical system, define:
- Recovery Point Objective: The acceptable amount of recent data loss.
- Recovery Time Objective: The acceptable length of downtime.
Payroll, accounting and active project files may require faster recovery than archived records.
Test Real Restorations
A backup report showing “successful” does not prove that the company can restore usable information.
The assessment should include sample recovery of:
- An email message
- A cloud file
- An accounting file
- A server folder
- A critical device or system when appropriate
911 IT's business continuity services include backup, disaster recovery planning and recovery testing.
Step 7: Evaluate Incident Response Readiness
A construction company should assume that an employee may eventually click a malicious link, lose a device or experience a compromised account. The important question is whether the company can respond quickly and consistently.
Incident Response Roles
The plan should identify who will:
- Receive the initial report
- Isolate affected devices
- Reset accounts
- Review logs
- Contact the cyber insurance carrier
- Coordinate with legal counsel
- Communicate with employees
- Notify customers or vendors when required
- Restore systems
- Document lessons learned
Common Incident Scenarios
The assessment should test readiness for:
- Phishing and stolen credentials
- Fraudulent payment instructions
- Ransomware
- Lost or stolen devices
- Unauthorized cloud access
- Compromised vendor accounts
- Jobsite network outages
- Accidental data deletion
Run a Tabletop Exercise
At least once per year, leadership, accounting, operations and IT should walk through a realistic incident scenario.
For example:
An accounting employee receives an urgent email that appears to come from a known subcontractor. The message requests a banking change for a pending payment. After the payment is sent, the real subcontractor reports that it never requested the change.
The exercise should identify:
- Who discovers the incident
- Who is contacted first
- How payment recovery is attempted
- How email accounts are investigated
- Whether insurance or law enforcement is contacted
- How future requests will be verified
Step 8: Review Security Awareness and Employee Procedures
Technology controls reduce risk, but employees still make decisions about messages, passwords, files and payments.
Training Topics
- Phishing recognition
- Payment fraud
- Password security
- Multi-factor authentication prompts
- Lost-device reporting
- Approved file storage
- Public Wi-Fi use
- Secure handling of customer and employee information
- How to report suspicious activity
Training Frequency
Employees should receive training:
- During onboarding
- At least annually
- Through recurring short reminders
- After significant policy changes
- After incidents or phishing test failures
Quarterly awareness activities are often more effective than one long annual presentation.
Measure the Results
The assessment may review:
- Training completion rates
- Phishing simulation results
- Employee reporting rates
- Repeated risky behavior
- Time required to report suspicious messages
Step 9: Determine Compliance and Contract Requirements
Construction companies working with government agencies, defense contractors or regulated customers may have additional requirements.
Depending on the information and contract, requirements may involve:
- CMMC
- NIST security controls
- DFARS clauses
- Cyber insurance requirements
- Customer security questionnaires
- Contractual incident reporting
- Data location and retention requirements
Compliance Assessment Questions
- Which contracts include cybersecurity requirements?
- What types of information does the company receive?
- Where is that information stored?
- Which users and systems can access it?
- Which security controls are already implemented?
- Which policies and evidence are required?
- Who owns the compliance process?
- What deadlines apply?
A standard IT assessment may not be sufficient for a formal compliance program. Companies should confirm whether the assessment must follow a specific framework or documentation standard.
911 IT provides CMMC compliance services for organizations preparing for government cybersecurity requirements.
What Should a Cybersecurity Assessment Deliver?
A useful assessment should produce more than a technical list of problems.
Executive Summary
Leadership should receive a clear overview of:
- The most important risks
- Potential business impact
- Immediate priorities
- Estimated budget ranges
- Recommended timelines
Technical Findings
Each finding should include:
- The affected system or process
- The observed condition
- The potential risk
- The recommended improvement
- The person or provider responsible
- The target completion date
Prioritized Remediation Plan
Use a three-tier framework:
- Critical: Immediate risks that could lead to account compromise, data loss, operational disruption or compliance failure.
- Important: Gaps that should be addressed during the next 30–90 days.
- Strategic: Longer-term improvements that strengthen resilience and efficiency.
Technology Roadmap
The assessment should feed into a 12–36 month roadmap covering:
- Device replacements
- Microsoft 365 security
- Network improvements
- Backup and recovery
- Employee training
- Compliance projects
- Security monitoring
- Policy development
How Much Does a Cybersecurity Assessment Cost?
The cost depends on company size, number of locations, number of cloud applications, depth of testing and compliance requirements.
Pricing may be structured as:
- A fixed project fee
- A per-user or per-device fee
- An hourly consulting engagement
- A service included with managed IT
- A separate compliance assessment
A basic review may focus on users, devices, Microsoft 365, backups and policies. A more advanced assessment may include vulnerability scanning, penetration testing, compliance mapping and formal evidence collection.
Before approving an assessment, ask:
- Which systems are included?
- Is vulnerability scanning included?
- Will cloud services be reviewed?
- Will the provider examine policies and procedures?
- Does the engagement include remediation planning?
- Will findings be presented to leadership?
- Is follow-up validation included?
- Which items will cost extra?
Cybersecurity Assessment Versus Vulnerability Scan
| Category | Cybersecurity Assessment | Vulnerability Scan |
|---|---|---|
| Scope | People, processes, technology and risk | Technical weaknesses in selected systems |
| Identity review | Usually included | Limited |
| Policy review | Usually included | Not included |
| Backup review | Usually included | Not included |
| Employee training | May be evaluated | Not included |
| Technical scanning | May be included | Primary focus |
| Business impact analysis | Included in a mature assessment | Usually limited |
| Remediation roadmap | Expected | Often limited to technical findings |
A vulnerability scan can be useful, but it should not be mistaken for a complete assessment.
Cybersecurity Assessment Versus Penetration Test
| Category | Cybersecurity Assessment | Penetration Test |
|---|---|---|
| Primary purpose | Identify and prioritize overall risk | Test whether selected weaknesses can be exploited |
| Business processes | Reviewed | Usually limited |
| Policies and procedures | Reviewed | Usually not the main focus |
| Technical depth | Broad | Deep within the agreed scope |
| Best use | Annual risk planning | Validation of specific technical defenses |
A penetration test may be appropriate when required by a customer, contract, insurance carrier or compliance program. It should be carefully scoped and performed by qualified professionals.
Common Cybersecurity Assessment Mistakes
1. Treating the Assessment as a One-Time Project
Security conditions change as employees, devices, applications and jobsites change.
2. Reviewing Only Office Computers
Tablets, smartphones, cloud accounts, remote users and jobsite networks must also be included.
3. Focusing Only on Antivirus
Identity security, email protection, backups, access control and employee procedures are equally important.
4. Ignoring Microsoft 365
Email and cloud accounts are major targets and should receive a detailed review.
5. Producing Findings Without Priorities
Leadership needs to know which risks should be fixed first and why.
6. Failing to Assign Ownership
Every remediation item should have a responsible person and target date.
7. Not Retesting Improvements
After a control is implemented, the company should confirm that it works as intended.
8. Ignoring Business Impact
A technical weakness should be evaluated based on its potential effect on projects, payments, employees and customers.
9. Skipping Backup Restoration Tests
Backup success messages do not prove recoverability.
10. Assuming Compliance Equals Security
Compliance can provide a useful framework, but checking boxes does not eliminate every practical risk.
Construction Cybersecurity Assessment Checklist
Users and Access
- Every user has an individual account.
- Multi-factor authentication is enabled.
- Former employee accounts are disabled.
- Administrative access is restricted.
- Permissions are reviewed quarterly.
Devices
- All devices are inventoried.
- Operating systems are supported.
- Encryption is enabled.
- Endpoint security is active.
- Devices are centrally managed.
Email and Cloud
- Email filtering is configured.
- Impersonation protection is enabled.
- Suspicious sign-ins are monitored.
- External forwarding is controlled.
- Third-party application access is reviewed.
Networks
- Firewalls are supported and monitored.
- Guest networks are separated.
- Jobsite equipment is business-grade.
- Remote access requires multi-factor authentication.
- Network configurations are documented.
Backup and Recovery
- Critical systems are backed up.
- Backup failures generate alerts.
- Recovery objectives are documented.
- Restorations are tested quarterly.
- Incident response roles are assigned.
Policies and Training
- Employees receive recurring security training.
- Payment changes require independent verification.
- Lost devices are reported immediately.
- Onboarding and offboarding procedures are documented.
- Policies are reviewed annually.
A 30-Day Cybersecurity Assessment Action Plan
Week 1: Build the Inventory
- List users, devices and applications.
- Identify sensitive information.
- Document offices and jobsites.
- List administrators and external vendors.
- Identify unsupported or unmanaged systems.
Week 2: Review High-Risk Controls
- Verify multi-factor authentication.
- Review administrator accounts.
- Disable former employee access.
- Confirm endpoint protection.
- Review email and payment fraud controls.
Week 3: Test Recovery and Response
- Review backup status.
- Perform sample restorations.
- Review the lost-device process.
- Conduct a short incident response exercise.
- Confirm cyber insurance contacts and requirements.
Week 4: Build the Roadmap
- Rank findings as critical, important or strategic.
- Assign responsibility.
- Estimate costs.
- Set completion dates.
- Schedule quarterly progress reviews.
Questions to Ask a Cybersecurity Assessment Provider
- Do you have experience with construction companies?
- Will you review office and jobsite technology?
- Are Microsoft 365 and cloud applications included?
- Will you assess laptops, tablets and smartphones?
- Is vulnerability scanning included?
- Will you review backup and disaster recovery?
- Will you evaluate phishing and payment fraud controls?
- Can you assess CMMC, NIST or DFARS requirements?
- Will findings be prioritized by business risk?
- Will you provide estimated remediation costs?
- Will leadership receive an executive presentation?
- Is follow-up validation included?
- Can you help implement the recommendations?
- How will sensitive assessment information be protected?
- What is excluded from the engagement?
Frequently Asked Questions
How often should a construction company complete a cybersecurity assessment?
At least once every 12 months, with additional reviews after major changes, security incidents, mergers, office moves, new jobsites or new compliance obligations.
Is an annual cybersecurity assessment enough?
An annual assessment should be supported by continuous monitoring, monthly security reporting, quarterly access reviews, recurring training and regular backup testing.
What should a cybersecurity assessment include?
It should include users, devices, Microsoft 365, email, networks, jobsite connectivity, cloud applications, backups, incident response, employee training and relevant compliance requirements.
How long does a cybersecurity assessment take?
The timeline depends on company size, number of locations, technical complexity and assessment depth. A basic assessment may take several days, while a more detailed compliance or penetration-testing engagement may take longer.
Does a cybersecurity assessment disrupt employees?
Most review activities should cause little disruption. Interviews, device checks, testing and remediation projects should be scheduled to reduce impact on operations.
Is a vulnerability scan the same as a cybersecurity assessment?
No. A vulnerability scan identifies selected technical weaknesses. A complete assessment also reviews identity, policies, backups, employee procedures, business impact and remediation priorities.
Do construction companies need penetration testing?
Not every company needs it annually. It may be appropriate when required by a customer, insurer, government contract, compliance program or specific risk profile.
Should Microsoft 365 be included?
Yes. Microsoft 365 often contains email, files, identities and administrative access, making it one of the most important systems to assess.
What happens after the assessment?
The company should receive a prioritized remediation plan, assign owners and deadlines, budget for improvements and review progress at least quarterly.
How much does managed cybersecurity cost?
A construction company with 25–50 employees may commonly budget approximately $100–$275 per user per month for managed IT services, depending on cybersecurity, backup, device and support requirements. A formal assessment or compliance project may be priced separately.
Why Construction Companies Work With 911 IT
911 IT helps construction companies identify cybersecurity risks across office systems, jobsites, cloud accounts, mobile devices and industry applications.
Construction clients receive access to:
- Cybersecurity assessments
- Microsoft 365 security reviews
- Endpoint monitoring and protection
- Email security
- Mobile device management
- Office and jobsite network reviews
- Backup and recovery planning
- Employee security training
- CMMC and compliance guidance
- 24/7 support and monitoring
“The remote service is great, so we don't have to worry about the security of our computers.”
Sam, Owner, Construction Industry
“They are experienced and they take time to know our setup. This allows them to resolve our issues fast.”
Clay, Owner, Construction
To identify security gaps, prioritize risks and build a practical remediation roadmap, schedule a discovery call. You can also contact 911 IT for additional information.
