Of all the systems in a construction company, the accounting platform is the one that attackers and fraudsters value most. It holds employee Social Security numbers, bank details, vendor payment records, job cost data and the authority to issue payments. Whether you run Sage, Viewpoint or another construction-oriented ERP, a few core security practices apply.
This post focuses on process and access. Specific menus and settings differ by product and version, so confirm details with your vendor or administrator.
Why this system deserves special attention
A compromise or misuse of the accounting system can lead to payroll diversion, fraudulent vendor payments, exposed employee data and manipulated job costs. Some of the worst events are not outside hackers at all. They are an employee with too much access and no oversight.
Step 1: Understand how the system is hosted
Know where your accounting data lives. Is it on a server in your office, hosted by a provider, or delivered as software as a service? Each model changes who is responsible for patching, backups, network protection and sign-in security. Ask your vendor for a written description of the division of responsibility.
Step 2: Review user access
Export the list of users and their roles. Check:
- Is every account tied to a current employee?
- Does each person have only the permissions the job requires?
- Are there shared or generic accounts?
- Who has administrator rights, and is the number as small as possible?
- Are there accounts for former vendors or consultants?
Repeat this review at least every quarter.
Step 3: Segregate duties
Segregation of duties means no single person can complete a risky transaction from start to finish. Look at the following combinations and separate them:
- Creating a vendor and approving a payment to that vendor
- Changing vendor bank details and releasing payments
- Setting up an employee and processing payroll
- Entering invoices and reconciling bank accounts
- Approving change orders and paying the resulting invoices
Small companies cannot always separate every function. When you cannot, add compensating controls such as owner review of exception reports.
Step 4: Lock down vendor and payroll changes
Changes to bank accounts, addresses and pay rates are high-risk. Require documentation, a callback verification for vendor banking and a second approver. Generate a monthly report of all changes to vendor and employee master data and have someone independent review it.
Step 5: Strengthen sign-in
Enable multifactor authentication where the product or hosting environment supports it, and always for remote access. If your system sits behind a remote desktop or VPN, protect that entry point with multifactor authentication. Avoid exposing accounting servers directly to the internet.
Step 6: Keep software current
Apply vendor patches and updates on a schedule, and test them first where the system is heavily customized. Unsupported versions may no longer receive security fixes, so include end-of-support dates in your planning.
Step 7: Back up and test recovery
Accounting data should be backed up frequently, with at least one copy that cannot be altered or deleted by a compromised account. Test a restore, and have the controller confirm that the restored data is complete.
Step 8: Control integrations and exports
Accounting systems often connect to project management platforms, payroll services, banks and reporting tools. Document each connection, who set it up, what credentials it uses and what data it moves. Remove integrations you no longer use. Be cautious with spreadsheets that export sensitive data and then travel by email.
Step 9: Enable audit trails and review them
Turn on logging of key events: logins, permission changes, master file edits and payment approvals. Logging is only valuable if someone looks. Assign a person and a schedule.
A short monthly routine
- Review new and changed vendors
- Review changes to bank details and payroll
- Check for inactive users and terminated employees
- Confirm backups succeeded
- Review failed login reports
Involve the right people
Security for the accounting system is shared between finance, HR and IT. The controller or CFO should own the business rules, while IT or your managed provider maintains the technical protections.
How Ironfield Cyber helps
Ironfield Cyber supports contractors running Sage, Viewpoint and similar platforms with access reviews, secure remote access, backup design and fraud-resistant payment workflows. If you want a review of your accounting environment, we can work alongside your controller to complete it.