General contractors share a lot with subcontractors: drawings, specifications, schedules, pricing, access to project platforms and sometimes owner information that carries confidentiality duties. A subcontractor with weak security can expose all of it, and the owner will usually look to the general contractor first. At the same time, most subcontractors are small businesses with limited IT resources, and a heavy questionnaire will not be answered honestly or at all.
A short, proportionate vetting process protects you without crushing the people you depend on.
Decide what you are sharing
Risk depends on what a subcontractor will hold. Sort them into tiers.
- Low: limited project information, no sensitive documents, no system access. A landscaping or hauling contractor may fall here.
- Medium: full drawing sets, schedules and access to a project platform. Most trades fit here.
- High: sensitive or restricted information, such as security system layouts, critical infrastructure details, controlled unclassified information or owner data covered by confidentiality or regulatory duties. Also any sub with connectivity to your network or systems.
Scale the questions to the tier, and ask less of the low tier.
A short questionnaire for most subcontractors
Keep it to a dozen questions or fewer, in plain English.
- Do all employees with email use multi-factor authentication?
- Do you use company-managed email accounts rather than personal ones?
- Are laptops and phones that hold project data protected with a passcode and encryption?
- Who handles IT for you, and how quickly can they respond to a problem?
- Do you back up your business data, and have you tested a restore?
- Do you have a process to confirm bank detail changes by phone?
- Do you remove access when employees leave?
- Has your company experienced a security incident in the past few years, and how was it handled?
- Will you notify us promptly if you suspect project information has been exposed?
- Will you limit sharing of project documents to those who need them?
For the high tier, add questions about written security policies, incident response plans, and relevant compliance, such as NIST SP 800-171 for defense-related work.
Treat answers as conversation starters. Unclear or hesitant answers tell you where to focus.
Put expectations in the contract
Include a short security clause in subcontract agreements.
- Protect project information and use it only for the project.
- Use MFA and reasonable safeguards on systems that hold it.
- Restrict sharing to people who need it.
- Notify the general contractor promptly of suspected incidents affecting project data.
- Return or securely delete project information at the end of the project, subject to retention needs.
- Flow down additional requirements where your prime contract demands them.
Ask your attorney to draft or review the language, particularly for regulated or government work.
Control the access you grant
The most practical control is limiting what you give.
- Invite subcontractors to your project platform with the minimum role they need.
- Restrict folders so each trade sees only relevant documents.
- Use expiring links rather than permanent ones for large files.
- Disable downloads for particularly sensitive documents where the platform allows.
- Review the external user list at least quarterly and at project closeout.
- Never allow shared logins for a subcontractor's whole crew.
Watch for warning signs
- Project documents arriving from personal email accounts.
- Requests to send payment to a new or personal account.
- Subs who cannot say who manages their IT.
- Frequent password reset requests or lost devices.
- Unexpected emails that appear to come from a subcontractor's account with links or attachments.
A compromised subcontractor mailbox is a common launching point for fraud against everyone in the project chain. If something looks wrong, verify by phone and notify the sub so they can investigate.
Help them where you can
Where practical, offer small subs resources: a one-page security checklist, a short training session or a recommendation of low-cost protections, such as MFA and password managers. A stronger supply chain reduces your own risk, and many subs will appreciate the help.
Keep a record
Maintain a simple register of subcontractors, their tier, the date of vetting, any follow-up items and contract terms. Review the register at the start of each project and update it when relationships change.
Do not forget your own house
Subcontractors will also assess you. Be ready to answer the same questions, and be sure your own controls, such as MFA and access reviews, would hold up.
How we can help
Ironfield Cyber helps general contractors design vendor and subcontractor vetting that is practical for the trades. If you want a template questionnaire and contract language to take to your attorney, we can help you build one.