Every construction accounting system eventually gets exported to Excel. Project managers want custom views, owners want cost reports and bankers want schedules of values. The exports are useful, and they are also copies of sensitive data that live outside your controlled systems: in email attachments, on desktops and in personal cloud accounts.
You cannot, and should not, ban spreadsheets. You can reduce the risk by deciding which data needs protecting, limiting who can export it and managing where the files go.
What Is Sensitive in Job Cost Data
- Labor rates, payroll details and employee information.
- Markup, overhead and margin information.
- Vendor and subcontractor pricing and banking details.
- Contract values, change orders and claims positions.
- Bonding and financial statements.
A leak of any of these can hurt negotiations, expose employees or provide fuel for fraud.
Why Exports Escape
- Easy access. Standard reports offer an export button, and no one controls who uses it.
- Email. Files are attached and forwarded, including to personal addresses or outside parties.
- Local copies. Downloads folders accumulate old exports on laptops that may be lost.
- Personal accounts and USB drives. Convenience beats policy.
- Stale data. Old spreadsheets are used as if current, leading to mistakes.
- Departing employees. They may take files with them, intentionally or not.
Step 1: Control Export Permissions
Review who in your accounting and project systems can export which reports. Many platforms let you restrict export capabilities by role. Align them with job duties. A superintendent may need a labor report for one project but not company-wide payroll.
Step 2: Provide Better Alternatives
People export because built-in views do not answer their questions. Reduce the need by:
- Building dashboards and saved reports that show what managers need, within the system.
- Using connected reporting tools with access controls, where your platform supports them.
- Providing templates that pull live data instead of static copies.
If the system gives people what they need, they export less.
Step 3: Define Where Files May Live
Set a clear rule: sensitive exports are stored in a designated company location, such as a restricted SharePoint library, and nowhere else. Make it easy by creating folders with the right permissions in advance, organized by project or function.
Configure that location with:
- Access limited to the people who need it.
- Multi-factor authentication.
- Version history and retention rules.
- Sharing restrictions that prevent anonymous links.
Step 4: Protect Files in Transit and at Rest
- Enable encryption on laptops and phones.
- Use secure sharing links with expiration and named recipients instead of email attachments for sensitive spreadsheets.
- Consider sensitivity labels or rights management in Microsoft 365 for the most sensitive files, which can restrict forwarding and copying.
- Block auto-forwarding of email to external addresses.
Step 5: Add Data Loss Prevention Where It Fits
Microsoft 365 and other platforms offer tools that detect when files containing sensitive patterns, such as tax identification or bank account numbers, are shared externally. Start in monitoring mode to see what happens, then tune and enforce. Do not turn on aggressive blocking without testing, or you will interrupt legitimate work.
Step 6: Clean Up Old Files
Periodically review shared drives and laptops for old exports. Set retention rules so that temporary files are deleted automatically after a defined period, and encourage people to use the system of record for current numbers.
Step 7: Handle Departures
When someone leaves, review recent file downloads and transfers, disable access promptly and ensure the company retains the files they created. Include this in your offboarding checklist.
Step 8: Train and Explain
Tell staff why. A short explanation helps: spreadsheets with pricing and payroll are exactly what fraudsters and competitors want. Give practical rules:
- Use the company library, not personal email or storage.
- Share links, not attachments.
- Delete local copies when you are done.
- Ask before sending anything with banking or payroll details outside the company.
Be Realistic
You will not eliminate exports, and trying to will frustrate people. The goal is to reduce the number of uncontrolled copies and to know where the important ones live. Ironfield Cyber can help review export permissions in your construction software, set up secure document libraries and tune data protection tools so they protect without getting in the way.