Free Resource · guide

What Cybersecurity Controls Does a Construction Company Need for Cyber Insurance?

Most carriers now treat five controls as non-negotiable before they will quote or renew: multi-factor authentication on email, remote access, and admin accounts; endpoint detection and response on every machine; backups that are offline or immutable and tested; email filtering with security awareness training; and a written incident response plan. Everything else on the application affects your premium. Those five affect whether you get a policy at all.

Cyber insurance for construction companies stopped being a checkbox purchase several years ago. Carriers took heavy ransomware losses, tightened underwriting, and now send a supplemental application that reads like a security audit. Answer it wrong and you either get declined, get quoted with a ransomware sublimit that guts the coverage, or, worst case, get a policy that a carrier can later void because an answer was inaccurate.

Here is what those applications actually ask for, why construction companies specifically get tripped up, and what it takes to answer honestly.

The five controls that decide whether you get a policy

These are the questions where a “no” usually ends the conversation, regardless of your revenue, claims history, or broker relationship.

1. Multi-factor authentication on email, remote access, and administrative accounts. All three, not just email. Business email compromise is the most common claim carriers see, and unprotected VPN or remote desktop access is the most common ransomware entry point. Underwriters ask about each separately because companies frequently have MFA on Microsoft 365 and nothing on the VPN into the office server.

2. Endpoint detection and response on every endpoint. Servers, office workstations, laptops, and the machines in the jobsite trailer. Applications now distinguish EDR from antivirus, and many ask whether it is monitored around the clock. A tool nobody watches at 2am on a Saturday is not the answer they’re looking for.

3. Backups that are offline or immutable, segregated from the network, and tested. The test part matters. Several applications ask when you last performed a full restore test, not whether backups are running. If your last verified restore is “we’ve never actually tried”, that is the honest answer and it is a problem worth fixing before you submit. Our backup and disaster recovery service exists largely because untested backups fail at exactly the wrong moment.

4. Email filtering plus security awareness training with phishing simulation. Carriers want a technical control and a human one. Training with no simulated phishing tests is generally treated as weaker than training with them, because simulations produce a measurable click rate the underwriter can look at.

5. A written, tested incident response plan. Written means a document that names who calls the carrier, who calls the attorney, who isolates systems, and who talks to the owner and the GC. Tested means you have walked through it at least once. This one is free to fix and is disproportionately common as a “no”.

Where construction companies specifically get caught

The supplemental application is industry-agnostic, but construction environments create predictable failure points.

Jobsite trailers. A trailer with a consumer router, one shared Wi-Fi password used by everyone including subs and inspectors, and a port forwarded so the superintendent can reach a PC from home will fail the remote access questions outright. The fix is business-grade equipment with the trailer network segmented from guest access, and remote access that runs through an MFA-protected connection instead of an open port. Setting jobsite connectivity up properly is a one-time project, not an ongoing cost.

On-premise construction software servers. Jonas, Sage 300 CRE, Viewpoint, and similar systems often run on a server nobody wants to touch during an active project. Underwriters ask how quickly critical patches get applied, typically expecting 30 days or better for critical severity. “We patch during the winter slowdown” is not a passing answer. See our notes on supporting Jonas and other construction platforms for how this gets handled without project downtime.

Shared logins on field devices. Tablets and trailer PCs used by whoever is on shift, logged into a single generic account, break the privileged access and accountability questions. They also make an incident nearly impossible to investigate, which is what the carrier’s forensics firm will need to do.

Funds transfer controls. This is the one construction companies underestimate. Applications ask whether you verify banking detail changes by callback to a known phone number before sending payment. With subcontractor payments, progress billing, and lien waivers moving by email constantly, construction is a prime target for payment diversion fraud, and the funds transfer fraud coverage in your policy usually depends on having attested to a verification procedure.

The controls that shape your premium

Past the five gating items, applications commonly ask about privileged access management and separate admin accounts, network segmentation, encryption on laptops, centralized logging with a stated retention period, vulnerability scanning, end-of-life systems still in production, and whether you have removed local administrator rights from standard users. None of these individually will sink an application, but a cluster of “no” answers moves you into a worse pricing tier or a lower ransomware sublimit.

If you want a framework to work against rather than chasing one carrier’s form, CIS Controls Implementation Group 1 covers nearly everything the standard supplemental application asks about, in a defined order.

Answer the application accurately, every time

The application is a warranty, not a wish list. Attesting to a control you do not have gives the carrier grounds to deny a claim or rescind the policy after the fact, which is a materially worse outcome than being declined up front. If a question is a “no”, answer “no”, then decide whether to fix it before binding or accept the pricing.

The practical sequence is: get the supplemental application from your broker, go through it honestly with whoever runs your IT, list the “no” answers, and fix the five gating controls first. Most construction companies in the Houston and Dallas-Fort Worth area can close those five gaps in a matter of weeks, not quarters, because the environments are small enough to move quickly.

If you want an outside read on where you stand before submitting, a cyber security risk assessment maps your current state against the same controls underwriters ask about, and our cybersecurity services cover the ongoing pieces, EDR monitoring, patching, training, and testing, that a carrier will re-verify at every renewal.

Working through a cyber insurance application?

Send us the supplemental application your carrier or broker gave you. We'll go through it question by question, tell you which answers are currently "no", and give you a straight estimate of what it takes to turn them into "yes".

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

Can we just answer yes on the application and sort the controls out later?

No, and this is the most expensive mistake a construction company can make here. The application is a warranty. If you attest to MFA on email and a claim investigation shows it wasn't enabled, the carrier can deny the claim or rescind the policy entirely. You'd be paying premiums for coverage that evaporates exactly when you need it.

Does antivirus count as endpoint detection and response?

Not to an underwriter. Traditional antivirus matches known signatures. EDR watches behavior, catches things it has never seen before, and lets someone isolate a compromised machine remotely. Applications increasingly ask specifically whether EDR is monitored 24/7, which means a security operations center, not just software running unattended.

What does "immutable backup" actually mean on the application?

A backup copy that cannot be altered or deleted for a set retention period, even by an administrator account. Ransomware crews look for backups first and encrypt or wipe them before triggering the payload. Carriers ask about immutability because a backup sitting on the same domain with admin credentials that can delete it is not really a backup, it is a second target.

Our jobsite trailers use consumer routers. Does that hurt us?

It can. Applications ask whether remote access is protected by MFA and whether RDP is exposed to the internet. A trailer with an off-the-shelf router, shared Wi-Fi password, and a port forwarded so the PM can get in from home is exactly the exposure those questions target. Business-grade equipment with segmented guest and trailer networks fixes the answer.

Will having these controls actually lower our premium?

Sometimes, though the bigger effect is availability. In a hard market, missing controls mean no quote at all, or a quote with a sublimit on ransomware that makes the policy nearly pointless. Controls first get you an offer; after that they influence pricing and how much of the ransomware and funds-transfer exposure the carrier is willing to cover.

Do we need all of this if we're a 25-person construction company?

Yes, because underwriters do not scale the required controls down by headcount. A 25-person general contractor and a 400-person one see largely the same supplemental application. The good news is the smaller environment is faster and cheaper to bring into compliance, often in weeks rather than quarters.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.