Construction software has moved onto phones and tablets. Superintendents file daily logs from the field, inspectors complete checklists on a tablet, and crews capture photos and punch items on the spot. The convenience is real, and so is the exposure. A phone is easier to lose than a desktop, is often shared or personal, and may store project data offline.
This post covers the settings and habits that keep field apps useful without leaving project data unprotected.
What data lives on a phone
Understand what an app actually stores.
- Cached drawings, specifications, and documents downloaded for offline use
- Photos and videos taken in the app or saved to the camera roll
- Forms, daily logs, and inspection records
- Contact lists for project teams
- Saved login tokens that keep the user signed in
Some of that data is sensitive: contract details, owner information, and security-related drawings. A lost device could expose it if not protected.
Lock down the device first
App security depends on the device.
- Require a passcode or biometric lock with a short auto-lock time.
- Enable device encryption, which is on by default for most modern phones.
- Keep the operating system and apps updated.
- Turn on location and remote wipe features for lost device recovery.
- Avoid jailbroken or rooted devices.
If your company uses mobile device management, enforce these settings through policy rather than relying on users.
Review app permissions
Apps request access to the camera, photos, microphone, location, contacts, and files. Review each requested permission.
- Camera and photos are usually needed for field documentation
- Location may be useful for geotagging, but consider whether it is necessary
- Contacts access may not be required
- Allow notifications only if useful
Teach users to deny permissions that do not match the app's function.
Manage offline data
Offline access is a major benefit on sites with poor coverage, but it increases exposure.
- Download only the drawings and documents the user needs
- Remove offline files when a project ends
- Check whether the app encrypts offline data and whether it can be wiped remotely
- Be cautious with exporting files to other apps or personal cloud storage
Find out from your administrator or the vendor how to revoke offline access when someone leaves.
Handle photos carefully
Photos taken on a phone often end up in the personal camera roll and in personal cloud backups. That can place project images in an account the company does not control. Where possible, use in-app capture so photos go straight to the project, and train employees to avoid using personal messaging apps to share site photos.
Manage sign-in and sessions
- Require MFA at sign-in
- Use single sign-on where available
- Set session timeouts suitable for the risk
- Review active sessions or tokens when an employee leaves
- Never share logins among crew members using one device
Shared tablets need special care. Use individual profiles or sign-in per user, and sign out at the end of each shift.
Define a lost device process
Make the process clear and easy to follow.
- The employee reports the loss to IT or a supervisor immediately, with no blame.
- IT locates, locks, or wipes the device remotely.
- IT revokes the user's sessions and resets the password.
- IT reviews recent account activity for anything unusual.
- The project manager is told which projects the device could access.
- The incident is documented.
Speed matters. The sooner access is revoked, the less chance data is exposed.
Personal devices
If employees use personal phones, set expectations in a short written policy.
- Which apps and data are allowed
- Required device protections
- The right of the company to remove company data
- What happens when the employee leaves
App protection policies can separate work data from personal content without managing the whole phone.
Offboarding
When an employee or subcontractor leaves, remove them from every app, revoke offline access, and recover or wipe company devices. Do this on their last day, not weeks later.
A hypothetical example
Consider a hypothetical project engineer who loses a phone at a restaurant. If the phone has a passcode, encryption, and remote wipe, and the project platform allows token revocation, the company can neutralize the risk within minutes. Without those measures, the finder might gain access to drawings, contacts, and logged-in apps.
Where Ironfield Cyber helps
Ironfield Cyber helps contractors secure mobile devices and field apps, including device management, MFA, and practical policies for crews. If your team relies on phones and tablets for project work, we can review your setup and recommend steps that do not get in the way of the job.