General contractors work with a constantly rotating cast of subcontractors, designers, inspectors, and consultants. Every one of them eventually asks for access to something: a project management platform, a shared drive, a document control system, or sometimes the network itself. Granting access is necessary, but how it is done decides whether it stays a convenience or turns into a security problem.
Here are the mistakes we see most often, along with practical fixes.
Mistake 1: Sharing one login with a whole company
It is tempting to create a single account for a subcontractor and let their team share it. The problem is that you lose any ability to know who did what, and when one person leaves, the password remains known to them.
Fix: Create named accounts for each individual who needs access. If a license cost is an issue, limit the number of people rather than sharing.
Mistake 2: Granting broad access by default
Project platforms often include folders for bids, financials, contracts, and personnel. A subcontractor who needs drawings should not see cost data.
Fix: Use role-based permissions. Define standard roles, such as subcontractor field staff, subcontractor project manager, and design consultant, and assign each the minimum folders required.
Mistake 3: Letting access outlive the job
Access given for a project often remains years after the work ends. Former subs, former consultants, and former employees of those subs may still log in.
Fix: Attach an end date to every external account where the platform supports it. At project closeout, remove or disable external users as a standard checklist item. Run a quarterly report of external users and ask each project manager to confirm who is still needed.
Mistake 4: Skipping multifactor authentication for outsiders
Companies often require MFA for staff but not for guests, because enforcing it on someone else's employees feels awkward. Yet a stolen password from an outside party can expose your data just as easily.
Fix: Turn on MFA for all users of project platforms, including external ones, where possible. Make it a contract requirement for access.
Mistake 5: Giving network access when application access would do
Occasionally a vendor asks to connect a laptop to your office or jobsite network. That puts an unmanaged device on the same network as your files and systems.
Fix: Offer a separate guest network for outside parties, isolated from your business systems. Provide application access through the web rather than network access.
Mistake 6: Forgetting about shared files outside the platform
Teams often share files through personal email, public links, or consumer file-sharing sites because it is faster. Those links can be forwarded and may never expire.
Fix: Set a clear policy that project files are shared through approved tools. Where links are used, set expiration dates and require sign-in rather than allowing anyone with the link to open the file.
Mistake 7: No record of who has access
If someone asks which outside companies can see a project folder, can you answer quickly? Many cannot.
Fix: Keep a simple access register for each project listing company, individuals, role, approval, and end date. Review it at project milestones.
Mistake 8: Ignoring the vendor's own security
An outside company with weak security can become the path into yours. A subcontractor's compromised email account might send you convincing messages with attachments or links.
Fix: Include basic security expectations in your subcontract, such as MFA on accounts with access to your data, prompt reporting of suspected incidents, and removal of project data when the work ends.
A short onboarding routine for outside parties
- A project manager requests access in writing, naming the person and role.
- IT or the project administrator creates a named account with the minimum permissions.
- The user enables MFA before first use.
- An end date is entered.
- Access is added to the project register.
Consider a hypothetical mid-size contractor with twelve active projects and about two hundred outside users. Without a routine, a few dozen accounts could be stale at any moment. A quarterly review of five minutes per project manager could remove most of them.
Where Ironfield Cyber helps
Ironfield Cyber helps contractors build access processes that field teams will actually follow. We can review your project platforms and guest accounts, set up role templates, and give you a repeatable checklist for onboarding and closeout.