Bid season compresses a lot of risk into a few weeks. Estimators handle large files, exchange quotes with dozens of subcontractors and suppliers, work late, and send final numbers minutes before a deadline. That pace makes mistakes more likely, and the information involved, including unit costs, margins, and strategy, is highly valuable.
Protecting it does not require slowing the team down. It requires a few well-chosen habits and settings.
What attackers want from preconstruction
Different parties want different things.
- Criminals may look for payment details, contract terms, and ways to impersonate a bidder or subcontractor.
- Competitors or opportunists may want pricing, quotes, or strategy.
- Fraudsters may pose as plan rooms, owners, or suppliers to harvest credentials or redirect communication.
Estimating mailboxes and shared folders are an attractive target because they hold a concentrated set of sensitive documents.
Protect the accounts first
Most breaches begin with a stolen login.
- Require MFA on email, the estimating platform, plan room accounts, and file storage.
- Use unique passwords stored in a password manager.
- Avoid shared accounts for plan rooms, and use named logins where the platform allows.
- Review who has access to the estimating system and remove people who have moved roles.
- Turn off automatic forwarding of estimating mailboxes to outside addresses.
Be careful with invitations and links
Phishing during bid season often imitates what estimators expect to see: invitations to bid, plan room notices, addenda alerts, and shared file links. Teach the team to:
- Navigate to a plan room or portal directly instead of clicking through an unexpected email
- Check the sender's real address, not just the display name
- Be suspicious of requests to sign in again to view a document
- Confirm unusual invitations with the general contractor or owner by phone
- Report suspicious messages to IT before clicking
Control how files are shared
Estimates travel in many formats. Set clear rules.
- Share files through approved tools with sign-in required rather than open links
- Set expiration dates on shared links
- Avoid emailing complete estimates to personal addresses
- Use read-only or watermarked formats for documents shared externally
- Limit who can see markup, margin, and contingency details
Treat subcontractor quotes as sensitive
Quotes from subs and suppliers are confidential business information. Store them in a controlled project folder, restrict access to the estimating team, and avoid forwarding them casually. At the same time, treat any change in a sub's payment details, or a quote that arrives from an unfamiliar address, with caution.
Watch the deadline rush
The last hour before bid submission is when errors happen. Sensible safeguards include:
- A defined submission process with one person responsible for final transmission
- A checklist that confirms the correct file, recipient, and version
- Verification that the submission portal or address is the official one in the bid documents
- A second person confirming the transmission
These steps reduce misdirected bids as well as fraud.
Protect the laptops
Estimators often work from laptops at home or on the road. Confirm each laptop has disk encryption, current updates, security software, and a screen lock. Use secure remote access rather than saving working copies on personal devices.
Keep historical data tidy
Old bids and cost data are valuable too. Archive completed bids to controlled storage, restrict access, and delete working copies on personal drives. Include estimating systems in your backup plan and test restores before the busy season, not during it.
A hypothetical example
Consider a hypothetical estimator who receives what looks like an addendum notice from a general contractor she bids with often. The link leads to a convincing sign-in page. With MFA in place, a stolen password alone would not open her mailbox. With a habit of checking addenda directly in the portal, she may not click at all. Layered habits work better than relying on any single one.
Do a pre-season check
Before the busy period, spend an hour on a short review.
- Confirm MFA is on for all estimating accounts
- Review the user list on the estimating platform
- Check backups and run a test restore
- Remind staff of phishing examples
- Confirm who to call with a security concern after hours
Where Ironfield Cyber helps
Ironfield Cyber helps contractors protect preconstruction teams without slowing them, with email security, MFA, secure file sharing, and training tailored to estimators. If bid season is approaching, we can run a short review of your estimating environment and give you a practical list of fixes.