Many contractors are weighing a move from an on-premises accounting and job cost system to a cloud-hosted one. The promise is appealing: less server maintenance, easier remote access, and faster updates. But a migration moves risk around rather than removing it, and it changes who is responsible for what.
This guide gives owners, controllers, and IT leads a set of questions to answer before signing, so the move improves security rather than creating a blind spot.
Understand the Shared Responsibility
In a cloud model, the vendor secures the platform, data centers, and underlying infrastructure. You remain responsible for users, passwords, permissions, and how data is exported and shared. Most incidents involving cloud software trace back to the customer side: weak sign-in controls, excessive access, or compromised accounts.
Ask the vendor to explain in plain language what they handle and what you must handle.
Questions About the Vendor
Independent assurance
Ask whether the vendor can provide an independent security report, such as a SOC 2 report, and be ready to read the scope and exceptions, not just the cover page. Ask how often penetration testing is performed and how vulnerabilities are handled.
Data location and ownership
Where is your data stored, and who owns it? Confirm in the contract that you own your data and can retrieve it in a usable format.
Incident notification
How and how quickly will the vendor tell you about an incident affecting your data? Is it in the contract?
Subprocessors
Which other companies touch your data, such as hosting providers and support partners?
Questions About Access
- Does the platform support multi-factor authentication for all users, and can you require it?
- Does it integrate with single sign-on so you can control accounts centrally?
- Can you define roles with least privilege, for example separating who can create vendors from who can approve payments?
- Are there audit logs showing who changed what, and how long are they kept?
- Can you restrict access by location or device?
For accounting systems, segregation of duties is especially important. Fraud often involves one person who can both add a vendor and release payment.
Questions About Data Protection
- Is data encrypted in transit and at rest?
- What are the vendor's backup frequency and retention, and can you request a restore?
- What is the recovery time objective after a vendor outage?
- Can you perform your own periodic export as an independent copy?
Do not assume the vendor's backup replaces yours. Most agreements cover availability of the service, not recovery from your own mistakes or malicious activity inside your account.
Questions About Integrations
Accounting platforms often connect to project management, payroll, banking, and expense tools. Each connection is another path to your data.
- List every integration and who approved it.
- Review what permissions each integration holds.
- Use dedicated service accounts with limited access, not an executive's login.
- Remove integrations that are no longer used.
Planning the Migration
Clean before you move
Review user accounts, vendor records, and permissions before migrating. It is easier to remove stale accounts and duplicate vendors beforehand than to carry them into a new system.
Run in parallel carefully
During cutover, keep the old system read-only and secured, and set a date to retire it. Old systems that linger unpatched become a risk.
Train users
New platforms often introduce new sharing and export features. Teach staff what they may and may not do, especially regarding exporting payroll, bank, or customer data.
Costs and Exit
Ask what happens if you leave. How long will the vendor retain your data, how can you get it, and what does it cost? Exit terms are easy to ignore on the way in and painful on the way out.
Final Thoughts
Cloud accounting can be a good decision, particularly for companies without the staff to patch servers. The key is walking in with clear expectations about your own responsibilities. Ironfield Cyber helps contractors evaluate cloud platforms, configure access and logging, and plan migrations so security does not get left behind in the rush to go live.