A Year-End Access and Backup Review for Your Construction Software

Use December to review who can access Procore, Sage, and Viewpoint, confirm backups restore, and close the year with cleaner permissions and fewer risks.

3 min readBy Ironfield Cyber Team

The end of the year is a natural time for housekeeping. Projects close, staff change, budgets reset, and the accounting department is already doing its annual reviews. It is also a good moment to give your construction software a security checkup. A few hours spent now can remove accounts you no longer need, verify that your backups work, and make the next year start cleaner.

This checklist covers the major platforms contractors depend on: project management such as Procore, accounting and job cost such as Sage or Viewpoint, and the Microsoft 365 environment that surrounds them.

Part one: users and access

Reconcile users with the payroll roster

For each platform, export the user list and compare it with your current employees and approved external partners. Flag:

  • Former employees and completed contractors.
  • Subcontractor staff whose projects are closed.
  • Generic or shared accounts.
  • Users who have not signed in for months.

Deactivate what you cannot justify.

Review roles and permissions

  • Confirm that administrators are few and named.
  • Check that finance data is visible only to roles that need it.
  • Make sure the person who edits vendor banking details cannot also release payments.
  • Look for people who changed jobs this year and still carry their old permissions.

Check sign-in protection

Confirm that multi-factor authentication is required, either on the platform or through your identity provider, for all internal users and, where possible, for external users.

Part two: integrations and connections

List what is connected to each platform, including accounting links, payroll feeds, estimating tools, and third-party apps. For each one, confirm an owner, a purpose, and the narrowest permissions it needs. Remove any that nobody can explain, and rotate credentials for those that remain, especially if the person who set them up has left.

Part three: backup and recovery

Confirm what is backed up

For each system, answer:

  1. Is it backed up, how often, and where do the copies live?
  2. Is at least one copy offline or immutable, beyond reach of stolen administrator credentials?
  3. Who watches for failures?
  4. Do cloud systems, including Microsoft 365, have a separate backup?

Test a restore

This is the most valuable item on the list. Choose one system, such as the accounting database or a project folder, and restore it to an alternate location. Time it, note problems, and document the steps. If you restore only one thing this year, make it your accounting data.

Preserve year-end data

Before year-end close, confirm that a verified backup exists of the accounting data as of the close date. Ask your controller and accountant what records they need to retain and for how long.

Part four: patching and versions

  • Confirm that servers and databases supporting the software are on supported versions of their operating systems.
  • Apply pending security updates, scheduled around payroll and close activities.
  • Check with the software vendor about upcoming end-of-support dates for your version, and add any upgrade to next year's budget.

Part five: remote access

Make sure remote access to accounting and file servers goes through a protected method with MFA. Verify that no remote desktop service is directly exposed to the internet. Remove vendor access that is no longer needed.

Part six: policies and records

  • Update the access request and termination procedures if you found gaps.
  • Document who owns each system, who administers it, and who the vendor contacts are.
  • Record the date and results of this review.
  • Keep screenshots and logs as evidence for auditors, sureties, lenders, and insurance renewals.

A simple timeline

  • Week one: Export user lists and reconcile them.
  • Week two: Fix roles, disable stale accounts, review integrations.
  • Week three: Run a restore test and verify backups.
  • Week four: Patch, document, and set a calendar reminder for the next quarterly review.

What good looks like

At the end, you should be able to say who has access to what, how that access is protected, how data would be restored if something failed, and when each of these was last checked. If you can say that, you are ahead of many companies.

Working with Ironfield Cyber

Ironfield Cyber supports Procore, Sage, Viewpoint, Autodesk, and Microsoft 365 for contractors and energy companies, including year-end reviews. If you would like help running this checklist, we can work alongside your accounting and operations teams.