
October 2026 | Contractor Cybersecurity Salt Lake City | Cybersecurity Awareness Month | Security Myths
October is Cybersecurity Awareness Month — a good time to take stock of what you actually know versus what you think you know about protecting your Salt Lake City construction company. In an industry where every day of downtime eats into a fixed-price contract, bad assumptions are expensive. And plenty of the cybersecurity advice floating around jobsite trailers and front offices has been repeated so long it sounds like fact, even when it's outdated or flat-out wrong.
When bad advice goes unchallenged, it creates blind spots. And blind spots are exactly what cybercriminals look for. Knowledge gaps and comfortable assumptions are what make contractors easy targets — not their trade, their project mix or their location.
The good news is that these gaps are simple to close once you know where they are. Here are six myths we hear from construction owners and office managers regularly, along with the truth behind each one.
Myth 1: "Hackers Don't Target Construction Companies"
This one gets people hurt. Construction is now one of the most targeted industries in the country for payment fraud, precisely because money moves constantly between general contractors, subcontractors and suppliers — often on tight deadlines, often by email. A criminal doesn't need to understand concrete schedules to slip a fake "updated banking details" message into a draw request cycle.
If your company has exposed accounts, an unlocked email inbox or vulnerable systems, bad actors will take advantage of them. Every contractor offers something valuable: project files, bid data, payment flows and trusted email relationships with every GC, sub and supplier you work with.
Fact: Hackers choose targets based on opportunity, not profile — and construction payment chains are full of opportunity.
Myth 2: "Our People Will Recognize a Phishing Email"
The days of obvious phishing emails full of typos are gone. Today's scams arrive as a polished invoice from a supplier you actually use, a change-order approval from a GC you're actually working with or a subcontractor asking to update remittance details mid-project. They look like Tuesday's inbox.
Thanks to AI, it's become nearly impossible to catch a scam from the text alone. Instead, your office and field teams need to judge sender behavior. Ask whether the supposed sender would:
- Make an unusual request
- Change payment or remittance instructions
- Request sensitive project files or payroll information
- Send a new or unusual login link for Procore, Sage or your bank
If anything seems off, pick up the phone and verify with a number you already have — not one in the email.
Fact: A convincing subcontractor invoice can still be a scam.
Myth 3: "MFA Fully Protects Our Accounts"
Multi-factor authentication (MFA) is important, but it's not invulnerable. Hackers use MFA fatigue to their advantage, counting on a busy project manager approving requests out of habit or annoyance. "Prompt bombing," for example, floods a phone with requests in hopes someone approves access just to make them stop — easy to imagine at 6 a.m. on the way to a jobsite.
MFA is a tool, not a shield. Attackers are finding ways around weaker authentication methods, which is why MFA on your email, Procore, Autodesk Construction Cloud and accounting logins needs support from the security controls around it.
Fact: MFA should be part of a broader cybersecurity strategy.
Myth 4: "Our Backups Have Us Covered"
Ask yourself: if ransomware locked up your Sage 300 CRE or Foundation accounting system tomorrow morning, could you actually restore it? How long before you could run payroll, submit a pay application or bill a completed phase? On a fixed-price job, every day of that answer is money out of your pocket.
A backup is great when you know it's going to work. An untested backup isn't something you can rely on during an incident — and "it's in the cloud" is not the same as a verified restore of your project files, estimates and job cost data.
Fact: Having backups is not the same as being able to recover.
Myth 5: "Cybersecurity Is Only IT's Job"
Whoever handles your IT does a lot to keep systems safe, but they can't control every click. Cybersecurity decisions happen everywhere in a construction business — the estimator opening bid attachments, the office manager processing invoices, the field superintendent approving something from a tablet in a truck. It takes only one bad click to open your systems to threats.
Security awareness training matters for your office and field teams alike. When everyone knows what to look for and when to ask for help, they become part of your defenses instead of the gap in them.
Fact: Training your office and field teams to make good decisions strengthens your security posture.
Myth 6: "We'd Know What to Do If Something Happens"
It's Thursday morning of payroll week. The office suddenly can't get into the accounting system, and nobody can open project files. Many contractors discover in that exact moment that nobody ever answered the basic questions:
- Should employees shut down their computers?
- Who calls IT — and who tells the field?
- How do you run payroll if the system is down?
- When does the insurance company get involved?
- Who communicates with GCs, subs and owners — and how?
Don't rely on memory in the moment. Have a documented incident response plan that covers both the office and active jobsites.
Fact: Your recovery plan shouldn't debut during payroll week.
Frequently Asked Questions
Do you offer IT support for construction companies and contractors in Salt Lake City?
Yes. Qual IT provides IT support for construction companies in Salt Lake City, including cybersecurity, email security and phishing protection, MFA implementation, backup and recovery for systems like Sage and Procore, jobsite connectivity support and incident response planning.
What is the biggest cybersecurity mistake construction companies make?
Assuming they're covered without verifying it. Untested backups of accounting and project data, unexamined assumptions about who would spot a fake invoice and security tools nobody monitors create a false sense of protection — which is often more dangerous than a known gap.
How do I know if my construction company's cybersecurity is actually working?
Through testing and review: verified restores of your accounting and project management systems, simulated phishing exercises for office and field staff, and a periodic assessment of your tools, policies and response plans by a qualified IT partner who understands construction IT services in Utah.
Cybersecurity Awareness Starts With the Facts
Cybersecurity Awareness Month is about making sure the assumptions guiding your decisions are correct. Myths are comfortable — they let you feel covered without digging deeper. But cybersecurity gaps rarely come from a missing product. They come from believing you've already got it handled when you don't.
We work with Salt Lake City construction companies to keep office and field systems running securely. If any of these myths sound familiar, it's time to take a closer look at where your company stands.
Schedule a free 10-minute discovery call with Qual IT and we'll help you separate what's protecting you from what's only giving you peace of mind. Book your discovery call here.

