For most contractors, the accounting and job cost system is the most sensitive application they own. It holds payroll, vendor bank details, bonding information, job costs, and margin data that competitors would love to see. Whether you run Sage, Viewpoint, or a similar ERP, the principles for protecting it are the same.
Many of the incidents that reach finance teams begin elsewhere, with a stolen email password or a phishing message, and then use the accounting system's access or processes as a lever. Tightening how people sign in and what they can do closes many of those paths.
Know who has access and why
Start with a list of every user account in the system, who it belongs to, and what role it has. Compare it to your current employee roster. Look for:
- Former employees whose accounts are still active.
- Generic or shared logins such as "accounting" or "admin2."
- Consultants or implementation partners with leftover access.
- Users with rights far beyond their current duties.
Remove or disable anything you cannot justify. Most systems let you deactivate rather than delete so that the audit history remains intact.
Apply least privilege to roles
Each role should have the minimum access needed. In a typical contractor, that means:
- Project managers see their own jobs' costs and commitments, not the whole company's payroll.
- Payroll staff see payroll, but cannot change vendor banking details.
- Accounts payable can enter invoices, but cannot release payments they entered.
- Only a small number of named people hold system administrator rights.
Segregation of duties
The classic fraud controls still apply. The person who adds or changes a vendor should not be the person who approves payment to that vendor. If your team is small, compensate with a second reviewer who looks at a weekly change report, even if it takes ten minutes.
Vendor and payment changes deserve special handling
Sage and Viewpoint record bank account details for vendors, and payment diversion scams target exactly that data. Add controls:
- Require a callback to a known phone number before any banking change.
- Generate a report of vendor bank changes each week and have someone outside AP review it.
- Alert the controller when a vendor record is edited and a payment follows within days.
Secure how people reach the system
Remote access
If staff reach the system through remote desktop, a VPN, or a web portal, make sure it requires multi-factor authentication. Exposed remote desktop services are a long-standing entry point for ransomware, so they should never be open to the internet without strong protection.
Single sign-on and MFA
Where your version supports it, connect sign-in to your main identity provider, such as Microsoft 365, so that you can enforce MFA and remove access in one place when someone leaves.
Device standards
Limit access to company-managed devices where possible. A personal laptop with no protection is a poor place to open payroll records.
Protect the data behind the application
- Make sure database and server backups run on schedule, and keep a copy that cannot be changed or deleted from the production network.
- Test a restore at least once a year, and time it. Know how long a recovery would take.
- Keep the server and database patched, within the vendor's supported versions.
- Encrypt laptops, and encrypt exports and reports sent by email.
Watch the integrations and exports
Integrations with Procore, payroll providers, banks, and reporting tools use credentials of their own. List them, review who set them up, and rotate credentials when staff change. Be cautious with spreadsheets of exported data. They often contain more than anyone realizes and spread through email and personal drives.
Review on a schedule
Set a calendar reminder every quarter to review user lists, roles, administrators, and integration accounts. Document what you changed. This also helps when auditors, sureties, lenders, or insurers ask about your controls.
A short checklist
- User list reconciled with HR.
- Shared accounts replaced with named accounts.
- Admin rights limited to named individuals.
- Vendor bank changes reviewed independently.
- MFA on all remote access.
- Backups tested, with an offline or immutable copy.
Getting help
Ironfield Cyber supports contractors and energy companies running Sage, Viewpoint, and related tools, with a focus on access, backup, and fraud controls. If you would like us to review your accounting system's user roles and remote access setup, we can do it alongside your finance team in a single working session.