Choosing Construction ERP: Security Questions to Ask Every Vendor

Picking accounting and project software is a long commitment. These security questions help contractors compare vendors before signing a multi-year deal.

3 min readBy Ironfield Cyber Team

A construction accounting or ERP system holds payroll, job cost, vendor banking details and contract values. Once you migrate years of data into it, switching is painful, so the decision tends to last a decade. Yet vendor evaluations often focus on features and price, with security reduced to a single checkbox.

This guide gives owners, CFOs and controllers a practical list of questions to ask during selection. You do not need to be technical to ask them, and a vendor's willingness to answer plainly tells you a lot.

Hosting and Architecture

Where does the system run?

Options include vendor-hosted cloud, a hosting provider running software on your behalf, or software you run on your own servers. Each shifts responsibility. In your own environment, you patch, back up and protect it. In the cloud, the vendor handles much of that, but you still control users, permissions and integrations.

Ask:

  • Who is responsible for patching, backups and monitoring?
  • Where is data stored, and in what regions?
  • What happens to availability during maintenance?

Identity and Access

How do users sign in?

  • Is multi-factor authentication supported, and can you require it for all users?
  • Does the product support single sign-on with your identity provider?
  • Can you define roles with segregation of duties, for example one person cannot both create a vendor and approve its payment?
  • Can you restrict access by job, cost code or business unit?
  • Is there an audit trail of logins and changes?

For payment-related functions, ask specifically about approval workflows and controls on changes to vendor bank details. Those are the points fraudsters aim for.

Data Protection

  • Is data encrypted in transit and at rest?
  • How are backups handled, how often, and how long are they retained?
  • Can you export your data in a usable format at any time, and what does it cost?
  • What is the process for restoring data if you make a mistake?

Vendor Security Practices

Ask what independent assurance the vendor can show. Many software providers undergo third-party audits and can share summary reports under a confidentiality agreement. Ask what the report covers, which systems are in scope and whether there were exceptions. Do not accept a logo on a web page as evidence.

Also ask:

  1. How does the vendor test its software for vulnerabilities?
  2. How quickly are security fixes released, and how are customers notified?
  3. How are the vendor's employees screened and how is their access to customer data controlled?
  4. Does the vendor use subcontractors who touch your data?

Incident Handling

  • How will you be notified of a security incident affecting your data, and within what timeframe?
  • What does the contract say about liability and cooperation?
  • Does the vendor have an incident response plan and conduct exercises?

Read this section of the contract carefully. Vague language about notification is a warning sign.

Integrations

Modern construction software connects to project management, payroll, banking and estimating tools.

  • How do integrations authenticate, and can you control which are allowed?
  • Is there an app marketplace, and how are third-party apps vetted?
  • Can you see and revoke connected apps?
  • Are API keys managed and rotated?

Compliance Considerations

If you handle controlled unclassified information for defense customers, or serve regulated energy clients, ask whether the vendor can support your obligations. Cloud services that store regulated data may need to meet specific requirements, and the vendor should be able to explain how.

Exit and Continuity

People rarely ask about leaving until they want to.

  • What are the data return terms if you terminate?
  • How long will the vendor retain your data after cancellation, and how is it deleted?
  • What is the vendor's financial stability and what happens to your data if it is acquired?

Running the Evaluation

  1. Send the vendor a short written questionnaire based on these topics.
  2. Ask your IT or security partner to review the answers.
  3. Request a demo that includes security administration, not just reports.
  4. Check references from similar contractors, and ask them about support and incidents.
  5. Negotiate contract terms around notification, data return and uptime.

Scoring What You Hear

You are looking for specific answers rather than marketing language. "Yes, multi-factor authentication is required for all users and enforced at the platform level" is useful. "We take security very seriously" is not.

Support for Your Decision

Ironfield Cyber can help contractors and energy companies review software vendors, draft security questions and assess the answers before a purchase. A few hours of review before signing can prevent years of regret.