Your office laptops sit behind a locked door. Your field laptops ride on dashboards, sit in trailers, and get left in trucks overnight. Phones and tablets get dropped in mud, lent to a coworker, and lost at a gas station. Yet those same devices hold project plans, email, contacts, and logins to systems that matter.
Securing field devices is less about expensive tools and more about a handful of consistent settings and habits. This is a practical guide for owners and operations managers.
The realistic risks
- Theft from vehicles and trailers. Equipment thefts are a known problem in construction, and a stolen laptop is also a data breach if it is not protected.
- Loss and damage. Devices are lost more often than stolen.
- Shared use. A tablet in a trailer may be used by several people on a project.
- Unsecured connections. Public Wi-Fi at the diner, or a wide-open trailer network.
- Delayed updates. Devices that rarely visit the office rarely get patched.
Baseline controls for every device
1. Full-disk encryption
If a laptop is stolen and its drive is encrypted, the thieves get hardware, not your data. Turn on BitLocker on Windows or FileVault on Mac, and store recovery keys in your management system, not on a sticky note. Phones and tablets are typically encrypted by default when a passcode is set, so make sure passcodes are enforced.
2. Strong lock screens
Require a PIN or password, with a short automatic lock timeout. Biometrics are fine as a convenience as long as a strong fallback exists. Avoid "1234" and similar.
3. Central device management
Enroll devices in a management platform. It lets IT enforce settings, push updates, install approved apps, and, importantly, remotely lock or wipe a device when it goes missing.
4. Automatic updates
Configure updates to install without relying on the user to remember. For devices that rarely connect to a corporate network, cloud-based management works well.
5. Endpoint protection
Install endpoint security that is monitored. A laptop that touches the internet from jobsites needs it.
6. Multi-factor authentication
Make MFA mandatory for email and business apps, so a stolen password or phone does not unlock your systems.
Habits for crews
- Do not leave laptops in vehicles overnight. If unavoidable, hide them and lock them out of sight, with the understanding that this reduces rather than removes the risk.
- Report a lost or stolen device immediately, within the hour. A written, no-blame rule encourages fast reporting.
- Do not share logins. Use individual accounts, even on shared tablets.
- Avoid public Wi-Fi for sensitive work, or use a trusted connection such as a company router or hotspot.
- Keep personal use separate, and do not let family members use work devices.
Shared tablets in trailers
A trailer tablet that displays drawings and takes inspections may be used by many. Options:
- Use a kiosk or limited account that only opens approved apps.
- Require individual sign-ins to the apps themselves, so actions are traceable.
- Limit the data stored on the device, preferring cloud access.
- Keep a short check-out log for tablets that circulate.
Bring your own device
Many crews use personal phones. If you allow it, do so with guardrails: require a passcode, use app-level protection that separates company data from personal data, and be able to remove company data without wiping personal photos. Put these expectations in a short written policy.
Asset tracking
Keep a list of every device, its serial number, who has it, and where it is. Tracking features can help locate a device, but they work only when it is online and enabled. For higher-value equipment, consider physical locks and tracking tags, understanding their limits.
When a device is lost
- The employee reports it right away.
- IT locks the device remotely and attempts location.
- If it cannot be recovered quickly, IT wipes it and revokes the user's sessions.
- Passwords for accounts used on the device are reset.
- A police report is filed for theft, which also supports insurance.
- The incident is reviewed to determine what data was exposed, and whether any notification obligations apply.
Plan for the whole life cycle
Provision devices consistently, retrieve them at offboarding, and wipe them before they are reissued or retired. Old laptops in a closet are a quiet risk.
Support from Ironfield Cyber
Ironfield Cyber manages laptops, tablets, and phones for contractors and energy companies, including encryption, update policies, and remote wipe, and ships ready-to-use devices to jobsites. If your field devices are not centrally managed today, that is the place to start.