A competitive bid is a few days of concentrated work and a lot of confidential information: material pricing, labor assumptions, subcontractor quotes, margin and strategy. If a competitor sees it, or if someone alters it before submission, the damage is immediate. Cybersecurity for estimating is less about exotic attacks and more about controlling who can see and change a handful of files and emails.
What is at stake
Think through what an attacker or insider could do with access to your estimating environment.
- Read your numbers. Pricing and margins shared with a competitor undermine your bid.
- Change a number. A small alteration to a subcontractor quote or a total can cost you the job or leave you with a loss.
- Impersonate you to a subcontractor. Fake emails can pull quotes or redirect communications.
- Disrupt bid day. A locked system or a lost laptop hours before a deadline can mean a missed submission.
Lock down where estimates live
Use one controlled location
Keep estimating files in a defined, access-controlled folder or application rather than scattered across email attachments, desktops and USB drives. Set permissions so only the estimating team and necessary leadership can open active bids. Remove access when people leave the team or the company.
Separate active and archived bids
Active bids deserve tighter controls. When a bid is awarded or lost, move the file to an archive with limited access. Old bids contain pricing history that remains valuable to competitors.
Turn on versioning and logging
Make sure your file platform keeps version history and records who changed what. If a number changes unexpectedly, you want to see when and by whom. This also protects honest estimators from blame.
Control the quotes that come in
Subcontractor and supplier quotes often arrive by email on bid day, which makes them a prime target.
- Use a consistent intake address or portal so quotes land in one place.
- Verify unusual changes by phone, using a number you already have. A last-minute revised quote that arrives from a slightly different email address deserves a call.
- Be careful with links to "view the quote" that ask you to sign in. Fake sign-in pages are a common way to steal email credentials.
- Save received quotes in the bid folder so the record is complete.
Protect the people doing the work
Estimators are visible. Their names appear on bid lists, plan rooms and project directories, so they get targeted by phishing disguised as plan room invitations or addenda notices.
- Require multi-factor authentication on email, file storage and any estimating or plan platform.
- Train the team to recognize fake addenda, invitations and shared-file requests, and to confirm unfamiliar ones through the known platform rather than the link.
- Limit local administrator rights on estimating machines so malicious downloads have less power.
Be ready for bid day trouble
A short contingency plan beats panic.
- Know where the latest copy of every active bid lives and who can access it.
- Keep a spare laptop or approved alternative that can open the estimating software and files.
- Confirm that licenses for estimating tools can be moved or reactivated quickly.
- Decide in advance who has authority to request an extension if systems fail.
- Make sure backups of active bids are frequent and that someone has tested a restore.
Handle leaving employees carefully
Estimators know pricing, vendors and methods, and they sometimes leave for competitors. Use a clear offboarding process that removes access the same day, recovers company devices and reviews recent downloads or forwards from their accounts. Consider confidentiality agreements with your attorney's guidance. Technical controls cannot replace clear expectations.
Watch for mailbox rules and forwarding
A frequent sign of compromise is an unexpected inbox rule that forwards or hides messages. Review forwarding and rule settings on estimator mailboxes periodically, and alert on new external forwarding.
Where to start this week
- List every location where active bid files exist.
- Consolidate them and fix permissions.
- Turn on MFA for everyone on the estimating team.
- Review mailbox forwarding rules.
- Run a ten-minute drill: if the lead estimator's laptop died now, how fast could the bid continue?
How we help
Ironfield Cyber helps contractors protect estimating workflows without slowing the team down on deadline days. If you want a focused review of how bid files and quotes move through your company, we can do that in a short engagement and give you a prioritized list of fixes.