A 90-Day Cybersecurity Starter Plan for Small Contractors

Most small contractors do not need a big security program. They need a sequenced 90-day plan that closes the gaps attackers actually use first.

3 min readBy Ironfield Cyber Team

Most small and mid-sized contractors do not have a cybersecurity problem that requires a six-figure program. They have a handful of predictable gaps: shared passwords, email accounts without multi-factor authentication, laptops nobody patches, and backups nobody has tested. Attackers go after those gaps first because they work.

This plan assumes a contractor with roughly 20 to 150 employees, a mix of office and field staff, and no full-time security person. It is sequenced so each month builds on the last, and every step can be explained to a superintendent or an owner without jargon.

Days 1-30: Stop the easy attacks

The first month is about the accounts and inboxes where most contractor incidents begin.

Turn on multi-factor authentication everywhere that matters

Start with Microsoft 365 or Google Workspace email, then your accounting and ERP platform, your project management tools, your banking portals, and any remote access. Use an authenticator app or hardware key rather than text messages where you can. Prioritize owners, executives, accounting staff, and anyone who can approve payments.

Fix the shared-login habit

Shared logins for the office printer or the estimating software are common. Each one is a door with no record of who opened it. Replace them with named accounts, and store any remaining shared credentials in a business password manager.

Inventory what you actually have

Make a simple list of every computer, phone, tablet, jobsite router, and cloud service the company pays for. You cannot protect a laptop in a truck you forgot you own. Note who uses each item and where it lives.

Days 31-60: Reduce the damage an attacker can do

Patch and encrypt

Turn on automatic operating system updates for all laptops and desktops, and replace anything that can no longer receive security updates. Turn on disk encryption for every laptop. A stolen laptop from a truck is a routine event in this industry, and encryption turns it from a data breach into a hardware loss.

Separate admin power from daily work

Nobody should check email and browse the web while logged in as an administrator. Give staff standard accounts and keep admin credentials for the people and moments that need them.

Back up with ransomware in mind

A backup that sits on the same network as your servers can be encrypted along with them. Keep at least one copy that is offline or immutable, and include the systems people forget: the accounting database, project document stores, and cloud data that is not automatically protected just because it lives in the cloud.

Then do the step most companies skip: restore something. Pick a folder and a server and prove you can get them back, and write down how long it took.

Days 61-90: Build habits and a plan

Train for the scams you will actually see

Generic awareness videos have limited value. Focus on the patterns that cost contractors money: fake invoices from a subcontractor or supplier, requests to change banking details, shared-document links that ask for a Microsoft login, and urgent texts from someone claiming to be the owner. Short, frequent sessions with real examples work better than one annual lecture.

Set a payment verification rule

Any change to vendor or subcontractor banking instructions gets confirmed by calling a known phone number, not one in the email asking for the change. Make it policy and apply it to everyone, including the owner.

Write a one-page incident plan

List who to call first, who has authority to disconnect systems, where the backups are, who your insurance carrier and legal contact are, and how the team will communicate if email is down. Keep a printed copy, because the digital one may be unreachable when you need it.

What to skip for now

Do not buy a stack of tools before the basics are in place. Advanced monitoring is valuable, but it works best on top of MFA, patching, and tested backups. Also resist the urge to treat this as a one-time project. Put a 30-minute review on the calendar every quarter to check who has access, which devices are new, and whether any of the steps above have slipped.

Where to get help

If you want an outside set of eyes, Ironfield Cyber can walk through these steps with you and tell you plainly which ones your company has already covered and which ones need attention first. A short security review is a reasonable place to start, and you can take the findings and do the work with your own team if you prefer.