Southwest Networks - Managed IT Services & Cybersecurity
Free Guide for Construction Owners

The Construction Owner’s I.T. Survival Guide

How Inland Empire Contractors Stay Qualified for Jobs, Keep Crews Productive, and Make Sure IT Never Costs Them a Contract

“Here’s the uncomfortable truth most brokers won’t say out loud: your GL policy almost certainly doesn’t cover a cyber event — and the GCs, agencies, and bonding companies you work with are starting to require coverage you may not have.” — Matt Disher, CISSP, HCISPP · President, Southwest Networks

CISSP Certified Employee-Owned Riverside · San Bernardino 30 Years Local

Get Your Free Copy

Instant download — no obligation.

We respect your privacy. Your information is never sold or shared. Unsubscribe at any time.

California Doesn’t Require Cyber Insurance. The Market Does.

There is no California statute mandating cyber liability coverage for construction firms. That distinction is becoming irrelevant, because three separate groups are now requiring it anyway.

General Contractors

On the Qualification Form

GCs are adding cyber insurance requirements to subcontractor qualification forms alongside general liability, workers’ comp, and professional liability. If you can’t produce proof of coverage, you don’t get added to the project.

Public Agencies

Written Into Bid Documents

Cities, counties, and school districts are beginning to specify cyber coverage in bid documents — particularly on projects involving building automation, infrastructure, or sensitive data.

Bonding & Lending

Asked During Underwriting

Bonding companies and construction lenders are starting to ask about cyber coverage during underwriting. No coverage can mean higher premiums — or a denied bond.

The Coverage Gap Most Owners Don’t Know About

Many construction owners assume their general liability policy covers cyber events. It usually doesn’t — or covers them so narrowly that a ransomware attack or data breach would leave them largely unprotected. Standard GL policies were written before cyber threats existed in their current form. If you haven’t specifically verified your cyber coverage with your broker, there’s a good chance you have a gap.

A Target of Choice, Not Coincidence

Ransomware attacks on construction firms have spiked sharply in recent years, and the reason is structural. Attackers know construction firms often run lean on IT, that a firm’s data is valuable, that downtime is costly, and that many owners will pay to get back up and running quickly.

A modern construction firm is a rich target:

  • Subcontractor and vendor banking information stored in accounting systems
  • Employee payroll data, W-2s, and personally identifiable information
  • Project financials, contracts, and proprietary bid data
  • Connected systems — BIM platforms, IoT sensors, Procore, Buildertrend
  • Cloud-based collaboration across distributed job sites

Every Workaround Has a Cost

Even setting aside cyber threats, the day-to-day technology problems cost you money every week. Project managers who can’t pull up current plans from a job site. Estimators who can’t reach files from the road. Field crews who resort to text messages and personal email to share documents because the official system is too slow or too difficult.

Every idle crew member is money out the door. And every version of a drawing shared via text message is a liability waiting to happen.

“A project manager’s laptop crashes. Three months of job files — subcontractor communications, change orders, daily logs, photos — may or may not have been backed up. Nobody knows for sure.”

What Changes When IT Is Actually Handled

With a Qualified IT Team & Cyber Policy

  • Always qualified. No scrambling when a GC asks for proof of coverage.

  • Crew connected from the field. Plans, reports, and communications work wherever the job is.

  • Files protected and recoverable. A crashed drive means a same-day restore, not a crisis.

  • Owner focused on the business. Technology is invisible, as it should be.

  • Audit-ready for cyber insurance. Your broker can bind coverage. You stay qualified.

Without One

  • ×

    Losing bids over an insurance checkbox while a qualified competitor gets the contract.

  • ×

    Field crews texting photos and emailing documents from personal accounts.

  • ×

    One hard drive failure away from losing months of project records.

  • ×

    Friday afternoons spent on IT problems instead of the next job.

  • ×

    Unknown gaps in the GL policy. Potentially uninsurable or facing high premiums.

What Cyber Underwriters Ask

Five Questions Most Contractors Can’t Answer Confidently

EDR on All Devices

Endpoint detection and response, not basic antivirus

MFA on Email & Remote Access

The control underwriters ask about first

Tested Offsite Backups

Regularly verified, stored offsite or in the cloud

Documented Incident Response

A written process, in place before an event

Offboarding & Access Revocation

How access ends when someone leaves the crew

Score Yourself in 5 Minutes

Free 15-point self-assessment — “Is Your IT Costing You Jobs?”

Matt Disher, President of Southwest Networks — CISSP and HCISPP certified

Matt Disher — CISSP & HCISPP

Matt Disher is the president of Southwest Networks, a Palm Desert–headquartered managed IT provider that has protected Southern California businesses since 1996. He holds two of the most rigorous credentials in cybersecurity: the CISSP (Certified Information Systems Security Professional) and the HCISPP, distinctions achieved by only a few thousand IT professionals worldwide.

Matt is the author of Keys To The Castle, a guide for small business owners navigating the world of hiring IT consultants. He has been cited as a cybersecurity expert by KESQ, and hosts the monthly Cappuccino Chats series on practical technology decisions for small businesses.

CISSP HCISPP CRN MSP 500 Featured on KESQ News

FAQ

Who is this guide for?

Owners and operations leads of construction firms in the Inland Empire — Riverside County, San Bernardino County, and the Coachella Valley. It is written for the person who signs the subcontractor qualification forms, carries the insurance renewals, and gets the call when a project manager’s laptop dies with three months of job files on it. You do not need an IT background to read it. If a GC has ever asked you for proof of cyber liability coverage, or you are not certain whether your current policy would cover a ransomware event, this guide was written for you.

Does California require construction firms to carry cyber liability insurance?

No. There is no California statute requiring cyber liability coverage for construction firms. But that distinction is becoming irrelevant, because the market is requiring it anyway. General contractors are adding cyber insurance to subcontractor qualification forms alongside general liability and workers’ comp. Government and public agency bid documents — cities, counties, school districts — are beginning to specify it, particularly on projects involving building automation or sensitive data. Bonding companies and construction lenders are starting to ask about it during underwriting, where no coverage can mean higher premiums or a denied bond. Contracts that had no cyber requirement two years ago have one today, and the trend is accelerating.

Doesn’t my general liability policy already cover a cyber event?

Usually not, and this is the single most common misconception we encounter. General liability policies were written to cover bodily injury and property damage, and most were drafted before cyber threats existed in their current form. Most GL policies do not cover data breaches, ransomware attacks, or network outages — and the ones that touch cyber at all typically do so narrowly enough that a real incident would leave you largely unprotected. If you have not specifically verified your cyber coverage with your broker, there is a good chance you have a gap. The guide covers exactly what to ask before your next contract qualification.

Why are attackers targeting construction firms specifically?

Because the data is valuable, the downtime is expensive, and the IT is usually thin. A modern construction firm stores subcontractor and vendor banking information in its accounting system, employee payroll data and W-2s, and project financials, contracts, and proprietary bid data. It runs connected systems — BIM platforms, IoT sensors, and project management tools like Procore and Buildertrend — and increasingly collaborates through the cloud across distributed job sites. Attackers know construction firms often run lean on IT, that downtime during a project phase costs real money, and that many owners will pay to get running again quickly. That combination is what makes construction a target of choice.

What do cyber underwriters actually ask before they issue a policy?

Five questions come up again and again: Do you have endpoint detection and response (EDR) on all devices? Do you use multi-factor authentication on email and remote access? Are your backups tested regularly and stored offsite or in the cloud? Do you have a documented incident response process? How do you handle employee offboarding and access revocation? Many construction firms cannot answer these confidently — and getting a policy is only part of the problem. Staying insurable at reasonable rates means maintaining the underlying IT hygiene: working backups, endpoint protection, access controls, and documented security practices.

What does the guide cover besides insurance?

The field-to-office gap, which costs money every week whether or not you ever have a cyber incident. Project managers who cannot pull up current plans from a job site. Estimators who cannot reach files from the road. Field crews who fall back on text messages and personal email to share documents because the official system is too slow. Every workaround has a cost, every idle crew member is money out the door, and every drawing shared by text is a liability waiting to happen. The guide also includes a side-by-side look at what a week runs like with a qualified IT partner versus without one.

How much does the guide cost?

Nothing. It is a free PDF — fill out the short form and it is emailed to you immediately, and also available on the confirmation page. You can unsubscribe in one click, anytime. We publish it free because most contractors we meet find out about the cyber insurance requirement the same way: a qualification package lands on the desk with a deadline attached, and there is no time left to get a policy quoted and bound. The contract goes to a competitor who was already covered. If this guide keeps one Inland Empire contractor out of that position, it has done its job.

What if I want to talk it through after reading it?

Call 760-770-5200 or visit /discoverycall/ and reference the guide to book a free 15-minute conversation. We ask a few targeted questions about your current setup, your biggest pain point, and whether cyber insurance is already showing up in your contracts. If there is a fit, we talk about next steps. If there is not, we will tell you that too. The IT and cyber insurance readiness audit that follows is a real assessment, not a sales pitch — you get a written gap report with real findings whether or not you decide to work with us.

Don’t Lose the Next Contract to an Insurance Checkbox.

Download the free guide and find out exactly where your firm stands — before a GC’s qualification package arrives with a deadline attached.

Reference this guide when you call to schedule a free 15-minute discovery call.