Field staff increasingly run the job from a phone or rugged tablet: viewing drawings, approving change orders, snapping progress photos, checking email, and logging time. Those devices are easy to lose, easy to drop in a ditch, and often share a case with personal apps and photos. That makes mobile device security an everyday issue rather than a niche one.
This post offers practical rules that fit field work without turning every superintendent into a security administrator.
Decide who owns what
First, pick a model.
- Company-owned devices give the most control. You can require settings, install protection, and wipe the device if it disappears.
- Personal devices used for work (BYOD) are common and cost-effective, but need clear boundaries between personal and company data.
Many contractors use a mix. Whichever you choose, write the rules down and have staff acknowledge them.
The essential settings
Regardless of ownership, any device that touches company email or project data should meet a minimum standard.
- Screen lock with a passcode or biometric. Short timeouts, no trivial codes.
- Device encryption. Modern phones and tablets encrypt by default when a passcode is set, but confirm.
- Current operating system and apps. Enable automatic updates and retire devices that no longer receive them.
- Multi-factor authentication on email and cloud apps.
- Remote lock and wipe capability. A lost device with project data should be disabled quickly.
- App installation controls. Install apps from official stores only.
Use mobile device management
Mobile device management, or MDM, lets IT enforce those settings, push approved apps, and remotely wipe lost devices. For personal devices, many MDM tools can create a separate work container so only company data is wiped. A modest MDM setup solves most of the problems described here without heavy daily effort.
Handle loss and theft quickly
Field devices will be lost. The question is how fast you find out and respond. Build a simple rule: report a lost or stolen device immediately, any hour, to a specific phone number or contact. IT then locks or wipes it, resets the user's passwords, and revokes sessions. Make it clear that reporting quickly is never punished.
Be careful with Wi-Fi and charging
Phones connect to every network around them. Teach staff to prefer cellular or the company jobsite network over public Wi-Fi, avoid unknown open networks, and avoid plugging into unfamiliar public charging ports and shared USB devices. Carry personal charging cables and adapters.
Protect photos and documents
Jobsite photos often include sensitive details: site layouts, security systems, or equipment locations. Store them in the company's approved application rather than in a personal photo library or messaging app. Turn off automatic backups to personal cloud accounts for company photos where possible.
Messaging and file sharing
Text messages and personal chat apps are convenient and uncontrolled. Set a norm: project decisions and files go through approved project or messaging platforms, not personal accounts. This protects both security and the project record.
Guard against mobile phishing
Phishing works on phones too, and small screens hide details. Links in text messages, fake delivery notices, and messages that appear to come from a boss are common patterns. Teach staff to avoid tapping links in unexpected texts and to verify requests for money or credentials by phone.
Shared and kiosk devices
Shared tablets for time entry or safety checklists are tempting, but shared logins weaken accountability. Where sharing is unavoidable, use app-level individual sign-in, automatic logout, and a dedicated account with limited access instead of a full user profile.
Retire devices properly
When a device is replaced or an employee leaves, remove company data and accounts, perform a factory reset for company-owned equipment, and record the disposition in your inventory.
A one-page policy outline
- Who may use mobile devices for company work.
- Minimum security settings.
- Approved apps and storage locations.
- What to do if a device is lost or stolen.
- What the company may do remotely, such as lock or wipe.
- Consequences and support contacts.
Working with Ironfield Cyber
Ironfield Cyber sets up mobile device management, MFA, and practical mobile policies for contractors and energy services firms. If your field devices are managed by habit instead of by design, we can help you standardize.