How to Secure Procore, Microsoft 365 & Field Devices from Cyberattacks
A Practical Cybersecurity Guide for Construction Companies
Construction companies have become prime targets for cybercriminals. Why? Because they manage valuable project data, financial information, contracts, blueprints, payroll records, and communications across multiple offices and jobsites.
Today’s construction firms rely on cloud applications like Procore and Microsoft 365, along with laptops, tablets, and smartphones used in the field. If any of these systems are compromised, projects can stall, sensitive data can be exposed, and the financial consequences can be significant.
For construction companies with 50–150 employees, cybersecurity isn’t about buying another software product—it’s about building multiple layers of protection that work together.
This guide explains how to secure your construction technology environment, reduce cyber risk, and keep your teams productive.
Why Construction Companies Are Being Targeted
Cybercriminals know construction companies often have:
- Large payment transactions
- Valuable intellectual property
- Tight project deadlines
- Multiple subcontractors
- Distributed workforces
- Temporary jobsites
- Mobile devices
- Cloud collaboration tools
Attackers don’t need to compromise your entire network.
They only need one employee to click one phishing email.
Once inside, they often attempt to:
- Steal Microsoft 365 credentials
- Access Procore projects
- Encrypt file servers
- Redirect vendor payments
- Compromise executive email accounts
- Demand ransomware payments
The good news is that most successful attacks exploit common weaknesses that can be addressed through planning and proactive management.
The Construction Cybersecurity Framework
Think of cybersecurity like building a commercial structure.
You wouldn’t rely on a single wall to protect the building.
You’d use multiple layers:
- Foundation
- Steel framework
- Exterior walls
- Doors
- Locks
- Alarm systems
- Cameras
Cybersecurity works the same way.
Below is the six-layer framework we recommend.
Layer 1: Secure User Identities
Everything starts with identity.
If attackers gain access to an employee’s Microsoft 365 account, they may never need to “hack” your network.
Every construction company should implement:
✔ Multi-Factor Authentication (MFA)
✔ Strong password policies
✔ Password manager
✔ Conditional Access policies
✔ Role-based permissions
✔ Separate administrator accounts
✔ Quarterly user reviews
✔ Immediate account removal for terminated employees
Common Mistake
One Microsoft 365 Global Administrator account shared by multiple people.
Every administrator should have their own account with only the permissions required for their role.
Layer 2: Secure Microsoft 365
Microsoft invests heavily in security, but many of its advanced protections must be configured correctly.
Simply purchasing Microsoft 365 licenses does not automatically secure your environment.
Protect:
- Exchange Online
- Teams
- SharePoint
- OneDrive
- Microsoft Entra ID
Recommended Security Controls
✔ Multi-Factor Authentication
✔ Safe Links
✔ Safe Attachments
✔ Anti-phishing policies
✔ Conditional Access
✔ Block legacy authentication
✔ External sharing controls
✔ Mailbox auditing
✔ Security alerts
✔ Microsoft Secure Score monitoring
Pro Tip
Review your Microsoft Secure Score at least monthly and work toward improving it over time. Even small configuration changes can significantly strengthen your security posture.
Layer 3: Secure Procore & Construction Applications
Construction software contains some of your company’s most valuable information.
Including:
- Contracts
- RFIs
- Drawings
- Submittals
- Financial records
- Project schedules
- Change orders
Best Practices
✔ Require MFA for every Procore user
✔ Remove inactive subcontractor accounts
✔ Review permissions quarterly
✔ Limit administrator accounts
✔ Monitor third-party integrations
✔ Log administrative activity
✔ Protect exported reports
✔ Document ownership of projects
Don’t Forget Other Applications
Your cybersecurity strategy should also include:
- Autodesk Construction Cloud
- Bluebeam Revu
- Sage 300 CRE
- Viewpoint Vista
- Foundation Software
- CMiC
These systems often integrate with Microsoft 365 and should be reviewed as part of your overall security program.
Layer 4: Protect Field Devices
Construction companies have one challenge many industries don’t:
Technology leaves the office every day.
Project managers and superintendents carry company data on laptops, tablets, and smartphones to active jobsites.
Every device should be treated as a potential entry point into your network.
Protect Every Device
✔ Full disk encryption
✔ Endpoint Detection & Response (EDR)
✔ Automatic updates
✔ Remote monitoring
✔ Mobile Device Management (MDM)
✔ Remote wipe capability
✔ Strong screen lock policies
✔ Asset inventory
Device Standards
Establish standard configurations for:
- Office laptops
- Rugged field laptops
- Tablets
- Smartphones
- Mobile hotspots
Standardization simplifies support, improves security, and speeds recovery when devices are lost or replaced.
Layer 5: Protect Your Data
No cybersecurity strategy is complete without a reliable backup and recovery plan.
Construction companies should follow the 3-2-1 backup rule:
- 3 copies of important data
- 2 different storage types
- 1 off-site or immutable copy
Protect
- Microsoft 365
- File servers
- Project documentation
- Accounting systems
- ERP databases
- Shared drives
Test Your Backups
Backups should be tested regularly.
A backup that cannot be restored is not a backup—it’s a false sense of security.
Conduct recovery testing at least quarterly and document recovery time objectives (RTO) and recovery point objectives (RPO).
Layer 6: Train Your Employees
Technology alone cannot stop every attack.
Employees remain the first line of defense.
Every construction company should provide regular training on:
- Phishing emails
- Business email compromise
- Password security
- Safe file sharing
- Mobile device security
- Reporting suspicious activity
Quarterly phishing simulations can help reinforce good habits and identify areas where additional education is needed.
What to Do If You Suspect a Cyberattack
The first few minutes after discovering suspicious activity are critical.
Step 1: Disconnect the affected device
Remove it from the network to help prevent the attack from spreading.
Step 2: Contact your IT provider immediately
Avoid trying to “fix” the problem without guidance, as this can destroy valuable forensic evidence.
Step 3: Preserve evidence
Do not delete emails, logs, or files that may help determine how the incident occurred.
Step 4: Assess the impact
Identify:
- Which systems are affected
- Whether data was accessed
- Whether backups are intact
- Whether operations are disrupted
Step 5: Recover and strengthen
After restoring operations:
- Reset passwords
- Patch vulnerabilities
- Review security policies
- Conduct additional employee training
- Update your incident response plan
Every incident should lead to improvements that reduce the likelihood of future attacks.
Common Cybersecurity Mistakes We See in Construction Companies
Even well-run organizations often have avoidable security gaps.
Common examples include:
- Multi-Factor Authentication not enabled for all users
- Shared administrator accounts
- Outdated firewalls
- Unsupported Windows devices
- No Mobile Device Management
- Weak password policies
- Inactive Procore accounts left enabled
- Microsoft 365 not backed up
- Employees using personal devices without security controls
- No documented incident response plan
Addressing these issues proactively is typically much less expensive than responding to a security breach.
Cybersecurity Is a Business Strategy
Strong cybersecurity protects more than computers.
It protects:
- Project schedules
- Client relationships
- Financial information
- Company reputation
- Employee productivity
- Future growth
Construction companies that invest in cybersecurity are better positioned to meet client expectations, satisfy cyber insurance requirements, and operate with confidence in an increasingly connected industry.
Schedule a Construction Cybersecurity Assessment
If you’re unsure whether your current security controls are sufficient, a cybersecurity assessment provides a practical starting point.
At Impress Computers, we help construction companies:
- Evaluate Microsoft 365 security
- Review Procore access and permissions
- Assess field device security
- Identify compliance gaps
- Test backup and disaster recovery readiness
- Build a prioritized cybersecurity roadmap
Our goal isn’t just to identify risks—it’s to help you implement practical solutions that reduce downtime, protect your business, and support long-term growth.
