The Job Site Device Your IT Has Never Touched Is Your Biggest Security Gap

The project superintendent is standing on a Billings job site at 7:45am reviewing a submittal that just came through. He opens the attachment on his personal iPhone, responds with an approval, and forwards a copy to the GC’s project manager. The whole exchange takes three minutes. The phone is connected to the cell network because the site’s temporary Wi-Fi was flaky this week. The iPhone has never been enrolled in any company security system, has no management profile installed, and is running three other project management apps alongside the one the company officially uses. Nobody at the firm has ever looked at it.
That phone now holds approved submittals, subcontractor contact lists, project schedule documents, and the email thread where the GC and the owner’s rep discussed a budget revision two weeks ago. If it is lost on the job site, there is no way to remotely wipe it. If the email app is compromised through a phishing attachment that arrived disguised as an RFI, nobody at the company will know. If the superintendent leaves the firm, the project data on that phone leaves with him, and there is no policy that requires him to return it.
This is not an edge case at a Billings construction firm. It is the default operating condition at most of them. The research firm RSM put the operational picture plainly in their 2025 cybersecurity analysis of the real estate and construction sector: workers in the field regularly connect to open networks to access and share company and client data, and most are unaware they are putting sensitive information at risk. The question for every Billings contractor managing a field workforce is not whether this is happening at your firm. It is how many devices are involved and what your exposure actually looks like when one of them becomes an incident.
Every Billings Job Site Now Runs on Devices Nobody Manages
Construction operations have become device-dependent faster than most firms have built the policies and infrastructure to manage that dependency. A commercial project running in Billings in 2026 typically has a project manager pulling files from a cloud-based project management platform on a laptop, a superintendent reviewing drawings on a tablet, foremen checking daily logs on smartphones, and subcontractors using their own devices to receive and respond to field communications, all within the same project environment.
Each of those devices is a potential access point to the same project data, financial records, and communication threads. The project management platforms used on modern job sites, Procore, PlanGrid, Buildertrend, and similar tools, are designed for field accessibility. They work on any device with a login. That accessibility is operationally essential and structurally problematic, because it means that access to project data is only as secure as the weakest device that has ever logged into the platform.
For a Billings GC managing multiple simultaneous projects, the total number of devices that have touched the company’s project management environment at any given time can reach into the dozens. Some belong to the firm. Most belong to field personnel who use them for personal purposes alongside professional ones. An unknown subset belong to subcontractors who were granted temporary platform access for a specific project and whose credentials were never revoked when the work wrapped up.
None of these devices are enrolled in a management system. None are running a company-controlled security profile. None can be remotely wiped if lost or stolen. And none of them show up on any inventory that a Billings IT provider could audit, because the firm has never formally mapped what devices have access to what systems.
For context on how this operational device exposure connects to the broader financial fraud risk that Billings construction firms face through their email environments, the BEC fraud article for Billings contractors covers the payment redirection threat that runs directly through the same devices and email accounts.
What Happens When One of Those Devices Is the Entry Point
Rapid7’s 2025 threat landscape analysis of the building and construction sector identified the attack methods most specifically tailored to how construction teams communicate. The patterns are worth understanding plainly, because they are designed around exactly the field device behaviors described above.
Phishing attachments disguised as construction documents are the primary delivery mechanism. An email arrives appearing to be a submittal, an RFI response, or a change order from a familiar sender. The attachment is opened on a phone while the recipient is standing on a job site, moving between tasks, and less likely to scrutinize the sender address or notice that something about the formatting is slightly off. The attachment installs credential-harvesting software. Within hours, the attacker has the login credentials for the project management platform, the company email account, and potentially the banking portal if the same password was reused.
The Verizon 2025 Mobile Security Index documented how significantly this threat has grown: 85 percent of organizations reported that mobile device attacks were increasing, and the percentage experiencing significant downtime from a mobile-related security incident jumped from 47 percent to 63 percent in a single year. Construction was specifically identified as one of the sectors where field device exposure was most operationally significant.
Once credentials from a field device are compromised, the attacker’s options expand considerably. They can monitor project communications to identify payment timing and banking details for a payment redirection attempt. They can access architectural drawings or project specifications that have competitive or strategic value. They can use the legitimate account to send convincing internal messages that establish false urgency around financial decisions. The initial compromise of a single field device is not the end of the incident. It is the beginning of a reconnaissance phase that can last weeks before anything financially damaging occurs.
The network security page covers how network-level monitoring can detect the kind of anomalous behavior that follows a credential compromise, often before the attacker acts on the access they have obtained.
The Four Device Categories Construction Firms Never Formally Secure
Field device exposure in construction concentrates in four categories. Each one carries a distinct risk profile, and each one is routinely left outside the scope of whatever IT management a Billings construction firm has in place.
Personal smartphones used for company communications. Most field personnel use their personal phones for work-related email, text, and project platform access because it is operationally convenient and nobody has given them a company device or a policy that says otherwise. These phones are never enrolled in a company mobile device management system, run whatever apps the owner has installed, and connect to whatever networks are available. When the employee leaves the firm, the data on that phone is gone with them and there is no mechanism to recover it.
Personal or shared tablets used for drawing review and submittals. Tablets issued to a job site frequently become shared devices that multiple field personnel access interchangeably. A tablet that multiple people use and that connects to the company’s project management platform is an access point with no individual accountability attached to it. There is no way to determine who accessed which documents on which dates, and when the project closes, the tablet often sits in a storage room rather than being formally wiped and reissued.
Subcontractor devices with active platform credentials. When a subcontractor is granted access to a project management platform, that access persists until someone explicitly revokes it. Most Billings GCs do not have a formal subcontractor offboarding process that includes credential revocation when a subcontractor’s scope is complete or a project closes. The result is an accumulating inventory of active credentials belonging to companies and individuals who no longer have a current business reason to access the platform.
Laptops used by project managers and estimators in the field. Project managers working from trucks, trailers, and job site offices are using laptops to access the company’s most sensitive operational data: bid documents, contract terms, subcontractor pricing, client communication, and financial records. These laptops are frequently not enrolled in any centralized management system, not monitored for security configuration, and not subject to any patch management process. When one is lost or stolen on a job site, the data on it is not recoverable and cannot be remotely wiped.
Addressing each of these categories requires the same underlying capability: a device management framework that enrolls devices, enforces security baselines, and maintains the visibility the firm needs to respond when a device is lost, compromised, or needs to be decommissioned. The complete IT management relationship is how that capability gets built and maintained without adding internal overhead.
Why Job Site Connectivity Makes the Problem Worse
The connectivity environment on a construction job site is structurally different from an office environment, and those differences compound the device security problem in ways that most IT conversations about construction firms never fully address.
Job sites run on whatever connectivity is available. Temporary cellular hotspots, public Wi-Fi at the nearest coffee shop, the owner’s site trailer network that was set up by whoever was on-site that week, and the field crew’s personal mobile data plans are all used interchangeably depending on what works at a given moment. None of these networks are controlled by the GC, none are monitored, and none provide any security inspection of the traffic moving through them.
Connecting to an unmonitored public or temporary network with a device that holds project management credentials and financial communications is a meaningful exposure event. Network interception on open Wi-Fi, while more technically involved than phishing, remains a viable attack method when the target is high-value project data or financial credentials. A superintendent who uses the coffee shop Wi-Fi near the job site to review a change order is making a decision that feels entirely routine and carries security implications that nobody briefed him on.
Site trailers and temporary offices add a physical security dimension. Shared workstations in site trailers are frequently used by multiple people with the same login, are left unlocked and unattended during shift changes, and are connected to whatever temporary network infrastructure was installed at the beginning of the project. These devices are almost never enrolled in the company’s IT management system, never patched on any regular schedule, and never formally wiped at project close.
The combination of unmanaged devices, unmonitored networks, and shared physical access points creates an exposure profile that is specific to construction and that standard IT advice, written for office-based businesses, consistently misses. Addressing it requires an IT partner who understands the field operating environment, not just the back office.
For related context on how connectivity and network architecture affect security posture across a construction firm’s full footprint, the network design services page covers the infrastructure decisions that establish the foundation for secure field and office connectivity.
The hidden IT costs for small businesses guide is also useful here. The cost of a field device incident rarely appears as a single line item. It shows up as project delays, staff time spent on incident response, subcontractor communication disruptions, and the overhead of managing a breach investigation during an active build, all distributed across the project budget in ways that make the real cost hard to see until the project is done.
What an IT Partner Does That a Policy Memo Cannot
Sending a field crew an email about device security is not a security program. It is documentation that the firm acknowledged the problem existed. The gap between a memo and a managed security posture is the difference between describing a risk and actually reducing it.
A managed IT partner that understands construction operations builds the infrastructure that makes field device security operational rather than aspirational. Mobile device management enrollment is configured and deployed to firm-issued devices. MFA is activated across every platform account. Access logs are reviewed for anomalous behavior on a schedule, not after a complaint. Subcontractor offboarding checklists include platform credential revocation as a required step. And when a field device is reported lost or stolen on a job site, remote wipe happens within the hour, not after a help desk ticket sits in a queue for three days.
The on-site dimension matters for construction specifically. The on-site IT support services that are part of a full managed services relationship mean that when a site trailer workstation needs a security configuration, a field tablet needs to be enrolled, or a network issue at a job site needs physical troubleshooting, the response is not a remote session with a technician in another state. It is someone who can be on the site.
Cybersecurity services for construction firms also need to account for the backup and recovery dimension of field device incidents. If a ransomware event spreads from a compromised field device to the office network, the question that determines whether the firm survives the incident intact is whether the backup environment was isolated from the path the ransomware traveled. For a Billings contractor with active projects and committed delivery schedules, recovery from a ransomware event without a tested, isolated backup is not a technology problem. It is an existential business problem. The backup and recovery services page covers how that protection is built.
For firms that have grown their field operations faster than their IT infrastructure has kept up, the business continuity planning guide for 2026 is a useful companion read. What happens to active projects when systems go down is a question every Billings contractor should have a written answer to before an incident makes it urgent.
The Devices Are Already Out There
The field devices touching your project data are not a future risk to manage. They are already out there, on job sites and in trucks and on kitchen tables, connected to your project management platforms, your email, and your financial systems through credentials that most Billings construction firms have never formally audited or managed.
The firms that address this problem do not wait for a lost phone to trigger the conversation. They build the enrollment, monitoring, and offboarding infrastructure before an incident creates the urgency. The decision to manage field devices is not a technology decision. It is an operational decision about whether the project data, client relationships, and financial records the firm depends on are going to be protected by something more durable than trust and good intentions.
Entre works with construction firms across Billings and throughout the region to build the IT and security infrastructure that field operations actually require. The construction services page covers the full scope of what Entre provides for contractors and project-based businesses, from field device management to email security and network monitoring.
The IT and cybersecurity readiness quiz is a five-minute starting point that gives you a structured picture of where your firm’s current gaps are concentrated. Or reach out to Entre directly to have a direct conversation about your firm’s field technology environment and what securing it actually involves.


















