Construction accounting systems hold the information criminals want most: payroll and tax data, vendor banking details, job cost, and the ability to initiate payments. Whether your company runs Sage 300 CRE, Viewpoint Vista, or a similar platform, the system is usually the financial core of the business, yet it often sits on older infrastructure that receives less security attention than email.
This checklist covers the practical steps that apply whether the system is hosted in your office, in a data center, or in the cloud. Specific menus and features vary by version, so confirm the details with your software vendor or reseller.
Know where the system lives
Start by documenting the basics. Is the application and database on a server in your office, in a hosted environment, or a vendor cloud? Who administers the server? Who administers the application? Where do backups go? Responsibilities often blur between the company, the reseller, and the IT provider, and the gap between them is where problems hide.
Control user access
Apply least privilege
Review each user's roles and confirm they match the job. An accounts payable clerk generally should not be able to create vendors and approve payments. A project manager rarely needs payroll data. Many firms discover that roles were copied from a previous employee years ago and never trimmed.
Separate vendor changes from payments
The ability to edit vendor banking details and the ability to release payments should sit with different people. This single separation is among the strongest defenses against payment diversion fraud.
Remove departed users promptly
Disable accounts as part of the offboarding checklist, and review the active user list at least quarterly. Pay attention to generic and shared accounts, which cannot be tied to a person.
Use strong sign-in
Where the application integrates with your identity provider, use it so multi-factor authentication and offboarding apply consistently. For remote access to the system, require MFA at the point of entry.
Protect the server and database
- Keep the operating system and database software supported and patched. Older versions that no longer receive security updates need a replacement plan.
- Limit who can log into the server itself, and avoid using administrator accounts for daily work.
- Restrict network access so the database is reachable only by the application and authorized staff.
- Disable remote desktop access directly exposed to the internet. Exposed remote access is a common ransomware entry point.
Backups that can survive an attack
Accounting data is among the first things attackers try to encrypt. Back up the database and application files frequently, keep at least one copy offline or immutable, and test restores. Confirm you can recover to a clean system and that the accounting vendor's licensing allows it. Know how long a restore takes, because payroll deadlines do not move when systems are down.
Secure integrations and exports
Accounting data flows to banks, payroll providers, project management tools, and spreadsheets. Review each integration and its credentials. Be careful with exported reports containing Social Security numbers or banking details, and avoid sending them by regular email. Use secure sharing and delete copies you no longer need.
Monitor and review
Turn on audit logging where available, and review changes to vendors, banking details, and user permissions on a schedule. Unusual after-hours activity, a sudden series of vendor edits, or a new user with broad rights deserves an immediate question.
Plan for upgrades
Aging versions of any ERP product become harder to secure. When you plan upgrades or migrations, include security in the project from the start: how access will be managed, how data will be moved, and how the old system will be retired and wiped.
A simple quarterly routine
- Review all user accounts and roles.
- Review changes to vendor banking details.
- Confirm backups completed and run one restore test.
- Check that server and database patches are current.
- Review third-party integrations and credentials.
Working with Ironfield Cyber
Ironfield Cyber supports contractors and energy companies running Sage, Viewpoint, and related platforms, working alongside your software reseller on the infrastructure and security side. If you would like a review of your accounting environment, we can start with access, backups, and remote connectivity.