Contractors are practical people. They build things that work, and they tend to be skeptical of anything that sounds like hype. That skepticism is healthy, but it can also leave a few persistent myths about cybersecurity unchallenged. Here are seven we hear regularly, and what is actually true.
Myth 1: "We are too small to be a target"
Reality: Attackers use automation. They scan for exposed systems, send phishing to thousands of addresses, and take whatever works. Size matters less than weak points: an open remote access service, a reused password, or an email account without multi-factor authentication. Small and midsize companies may also be seen as easier prey, because they have fewer defenses and less time to respond.
Myth 2: "We have nothing worth stealing"
Reality: Consider what you hold: payroll data and Social Security numbers, bank account information, bid and pricing data, project drawings, customer contracts, and the ability to send convincing email to your vendors and clients. Even if no data is stolen, locking your systems has value, because a contractor with idle crews and missed deadlines will feel pressure to restore operations quickly.
Myth 3: "Our antivirus protects us"
Reality: Basic antivirus catches known malicious files. Many attacks use stolen credentials, legitimate tools, or social engineering that never trips a traditional scanner. Modern protection combines endpoint detection and response with monitoring, plus email filtering, multi-factor authentication, and patching. Software with no one watching its alerts is a weaker defense than it seems.
Myth 4: "Our data is in the cloud, so the provider handles security"
Reality: Cloud providers secure their infrastructure. You remain responsible for your accounts, passwords, access settings, and data. Most cloud incidents trace back to stolen credentials or misconfigured permissions on the customer side. Cloud data also needs a backup plan that does not depend on the same login that an attacker may have stolen.
Myth 5: "Our employees would never fall for a scam"
Reality: Skilled and careful people fall for well-made phishing, especially when it arrives during a busy day and refers to a real project. Training helps, but the real answer is layered protection: MFA so a stolen password is not enough, email filtering, verification procedures for payments, and a culture in which people report mistakes quickly rather than hiding them.
Myth 6: "A strong password is enough"
Reality: Even strong passwords get stolen through phishing, data breaches at other sites, and malware. Multi-factor authentication adds a second barrier. Unique passwords stored in a password manager prevent one breach from unlocking many accounts. Passwords are still important, but they are no longer sufficient alone.
Myth 7: "Cybersecurity is an IT problem"
Reality: Security decisions affect operations, finance, safety, and contracts. Who can approve a wire? How are jobsite devices handled? What happens if the accounting system is down for a week? Those are business questions, and owners and managers must answer them. IT can implement controls, but leadership sets priorities and enforces habits.
What this means in practice
If the myths are false, what does a sensible baseline look like?
- Multi-factor authentication on email, remote access, and key applications.
- Monitored endpoint protection on every computer and server.
- Email security that filters threats and flags impersonation.
- Backups with at least one offline or immutable copy, tested regularly.
- Patching on a schedule, with attention to internet-facing systems.
- Payment verification procedures that do not depend on email alone.
- Training that is short, frequent, and specific to construction work.
- An incident response plan that you have actually discussed.
Where to start
Owners often ask where to begin. Start with the controls that stop the most common attacks: MFA, email protection, backups, and payment verification. Then address monitoring, patching, and training. Write a short plan, set owners and dates, and review quarterly.
A myth worth retiring about cost
Another common belief is that doing security properly is prohibitively expensive. Many of the highest-value steps, such as turning on MFA and tightening payment procedures, are inexpensive. The expensive part is usually the cleanup after an incident.
Talking with Ironfield Cyber
Ironfield Cyber is a managed IT and cybersecurity provider for contractors and energy companies. If you would like a candid assessment of where your company stands against these basics, we offer security reviews that end with a short, prioritized list of fixes.