A contractor's payroll and HR files are some of the most sensitive records in the company. They contain Social Security numbers, bank account details, addresses, identity documents and often information about dependents. Construction's reliance on seasonal and subcontract labor means a lot of people pass through, and a lot of copies get made.
Protecting this data is both a security task and a legal and trust obligation. A breach affects employees personally, and it can bring notification duties under state law, which your attorney can explain.
Know where the data lives
Start by mapping it. In many contractors it sits in more places than anyone intended.
- Payroll and HR systems
- Accounting and job cost software
- Certified payroll and prevailing wage reports
- Email attachments with onboarding forms
- Scanned I-9 documents and copies of identity documents
- Shared drives and desktop folders
- Phones and tablets used to photograph documents
- Paper files in a field office or trailer
Every copy is something to protect or eliminate.
Collect less and keep less
The simplest way to reduce risk is to hold less data. Collect only what the law and your processes require. Keep it only as long as required, and dispose of it on schedule. Ask your attorney or accountant about retention periods for payroll records and I-9 forms, since requirements vary and some documents have specific retention rules.
Do not accept sensitive documents by text message or personal email. Provide a secure method, such as a protected upload portal or in-person collection.
Restrict access
Access should follow job duties.
- Limit payroll and HR data to the small number of people who need it.
- Separate duties so the person who changes bank details is not the only one who approves them.
- Use named accounts, never shared logins.
- Require multi-factor authentication on payroll, HR, email and file storage.
- Review access quarterly and remove it for people who change roles or leave.
Field supervisors who submit time do not need access to Social Security numbers. Check what your system exposes to them.
Protect the files themselves
- Store sensitive files in a restricted location, not on desktops or general project folders.
- Encrypt laptops and external drives that may contain them.
- Disable unmanaged personal devices from syncing HR data.
- Use secure sharing, with expiration, when sending files to an outside accountant or benefits provider.
- Keep paper records in a locked cabinet, and shred what you no longer need.
Guard against payroll fraud
Criminals target payroll in two common ways.
Direct deposit change scams
An attacker impersonates an employee, by email or by a compromised account, and asks payroll to change direct deposit details. The fix is the same as for vendor bank changes: verify through a known channel, such as a phone call or in-person confirmation, before making any change, and send a confirmation to the employee's existing contact information.
Credential theft
Stolen credentials let attackers log in to payroll portals and redirect pay. Multi-factor authentication and alerts on bank detail changes reduce this risk.
Handle vendors carefully
Payroll providers, benefits administrators, outside accountants and staffing agencies hold your employees' data. Ask them about their security practices, including access controls, encryption and incident notification. Put expectations in the contract and confirm who to call if something happens. Remove access for former contacts.
Handle onboarding and offboarding
Onboarding is when sensitive documents flow. Make a standard process: a designated person collects documents, records them in the proper system and removes stray copies from email and phones. At offboarding, disable system access promptly, recover devices and make sure no one retains copies.
Prepare for the worst
Know in advance what you would do if payroll data were exposed.
- Who leads the response?
- Which attorney do you call about notification obligations?
- How would you contact affected employees, including seasonal workers who may have moved on?
- What services would you offer, such as credit monitoring, if appropriate?
- Which insurer should be notified?
Writing this down before an incident saves precious days.
A short action list
- Map where payroll and HR data is stored.
- Delete or consolidate stray copies.
- Turn on MFA for payroll, HR and email.
- Restrict access by role.
- Add verification for direct deposit changes.
- Review vendor security and contracts.
Next steps
Ironfield Cyber helps contractors lock down sensitive employee data without making payroll harder to run. If you would like to know where your payroll and HR files actually live, we can map them with you and recommend practical fixes.