Your Insurer Grades Your Cyber Controls. Who’s Grading Your Subs?

Construction team collaborating on a project with laptops and tablets

Every general contractor I talk to has filled out a cyber liability questionnaire. MFA on email? EDR on every machine? Backups ransomware can’t reach? A written incident response plan? Get those answers wrong and your premium goes up, your coverage shrinks, or your renewal gets declined.

Now ask yourself how many of your subs could answer the same questions. Most GCs don’t know, because they’ve never set subcontractor cybersecurity requirements at all. That matters, because your subs work inside your systems every day, and an attacker doesn’t care whose laptop they come in through. Below is the bar we recommend, how to roll it out, and a free prequal form and policy prompt to get you started.

Where the shared risk shows up

Construction runs on shared access and moving money, and that’s exactly what attackers look for. Your subs log into your project management platform. They send pay apps, lien waivers, change orders and invoices by email. They share drawings and bid docs through links nobody tracks. Some of them have credentials to your job site cameras or your plan room.

The most common problem isn’t ransomware. It’s a compromised mailbox somewhere in the chain. An attacker sits quietly in a partner’s email for weeks, learns your billing rhythm, then sends your AP team a perfectly timed note: “We’ve changed banks, please update our wire info before this draw.” It comes from a real address, references a real job, and matches a real invoice. Your team pays it, and the money’s gone.

Nobody did anything wrong in that scenario. Your sub is a victim too, and neither of you had a shared standard that would have caught it. Your insurer may not see it that way, and depending on your policy, social engineering losses like that can be sublimited or excluded entirely.

Use the bar your insurer already set

You don’t need to invent a security standard for your subs. Your cyber carrier already wrote one. The questionnaire you fill out at every renewal is the insurance industry’s distilled view of which controls actually stop losses, built from years of paid claims.

That makes it the right bar for three reasons. It’s practical, since these are controls a 10-person company can actually put in place. It’s fair, because when a sub has questions you’re not asking for anything beyond what your own insurer asks of you. And it’s already familiar, since plenty of your subs carry their own cyber policy and have seen the same questions.

If you bid federal work, you’re already headed here. CMMC requirements flow down from prime contracts to the subs who handle controlled information, so you’ll have to start asking these questions anyway. Better to build the habit across your whole sub base now than scramble on a single job later.

The subcontractor cybersecurity requirements to set

These are the controls that show up on nearly every leading cyber liability application. Ask your subs to attest to each one in your prequal, the same way they attest to insurance and safety. They’re also aligned with CIS Controls v8 Implementation Group 1, the recognized baseline for small businesses, so you’re asking for a named standard, not something you made up.

ControlWhat it means for a subWhy it matters to you
MFA on email and remote accessA second factor on every mailbox, VPN and cloud appStops the stolen password that leads to wire fraud
MFA on shared platformsTheir logins to your PM platform, plan room and portals use MFAYour project data is only as safe as their weakest login
Managed detection and responseEDR on every laptop and desktop, watched 24/7 by a security team that can isolate a threatCatches an attacker before they pivot to you
Email securityAdvanced scanning of inbound and internal mail for phishing, impersonation and malicious links, plus SPF, DKIM and DMARCMakes their domain harder to spoof against your AP team
Identity threat monitoring24/7 watch on their email and Microsoft 365 accounts for suspicious sign-ins, forwarding rules and account takeoverCatches the quiet mailbox compromise behind most wire fraud before the fake invoice reaches you
Encrypted, immutable backupsMultiple encrypted, immutable copies of email and files, at least one outside the primary platform, with restores tested at least yearlyRansomware can’t alter or delete them, so a sub who gets hit can still deliver your job
PatchingOperating systems and key apps updated on a set scheduleCloses the holes attackers scan for first
Security awareness trainingAnnual training plus phishing simulationsTheir people are your people’s first line too
Payment verificationBank changes confirmed by phone to a known numberKills the most common construction scam outright
Incident response planA written plan, including when they’ll notify youYou hear about a breach in hours, not months
Cyber liability coverageTheir own policy, including coverage for social engineering and funds transfer fraudTheir loss doesn’t become your claim

Notice what’s not on this list: brand names. You’re requiring outcomes, not vendors. Any sub can meet these with whatever tools they choose, as long as they can prove it.

Download the subcontractor prequal form. It’s a two-page attestation covering all eleven controls, ready to drop into your prequal package, plus a starter AI prompt that drafts a written security policy built around your company, your projects and your subs. It works for any vendor that touches your systems, data or payments, not just subs. It’ll get you close, but every draft needs a human review before you put it to work.

How to roll it out

  1. Get your own house in order first. You can’t require what you don’t meet, and your subs will ask. Run your own answers against the questionnaire honestly and close the gaps before you send anything out.
  2. Add it to prequal. Put the controls into your subcontractor prequalification form as a short attestation. Start with new subs and renewals rather than your whole list at once. Our free subcontractor prequal form is ready to drop in as is.
  3. Set a grace period. Give existing subs six to twelve months to comply. Make MFA and payment verification day-one requirements, since they’re cheap and stop the most damage.
  4. Give subs a path. Point them to a provider who can assess them and get them compliant quickly at a predictable cost. A requirement with no path just shrinks your bid list.
  5. Write it into the subcontract. Once the program is running, add the controls and a breach notification clause to your standard subcontract language, the same way insurance requirements live there today. The policy prompt in our download drafts a written policy and starter clause language with your AI of choice, ready for your attorney to review.
  6. Verify, lightly. You don’t need to audit every sub. Spot-check a few each year, and ask for evidence from anyone handling sensitive data or touching your payment process.

The pushback you’ll hear

“I’ll lose good subs” is the first thing every GC says, and it’s the same thing they said about safety programs and certificates of insurance. The good subs adapted, and the market got better for it. Lead with the cheap, high-impact controls, give people time, and almost nobody walks away.

Cost is the next objection, and it’s smaller than most subs expect. MFA is usually included in the email platform they already pay for. Payment verification is a phone call. The bigger items, managed EDR and real backups, typically run less per month than a single change order dispute costs in lost time.

The last one is enforcement, and the honest answer is you won’t police every sub perfectly. You don’t have to. Asking the question in prequal shifts the conversation, documents that you did your diligence, and gets most subs moving. That alone puts you ahead of nearly every GC you bid against.

Where we come in

Open Tier Systems has supported construction firms across the Philadelphia suburbs since 2006, and this is exactly the work we’re built for. We start with the GC. A free discovery call tells us where you stand and what you’re up against. From there, our Cybersecurity Risk Assessment measures you against a leading insurer’s questionnaire and lays out exactly what it takes to close the gaps.

Once your house is in order, we help you build the sub requirement into prequal, and we support your subs directly so they’ve got a clear, affordable path to comply instead of a reason to walk. Many of the subs working Philadelphia-area jobs are already Open Tier Systems clients, so for a good part of your bid list the path is already in place. You set the standard. We help everyone meet it.

Book a free discovery call

Not ready for a call yet? Grab the free prequal form and policy prompt and start with your own house.

Brian McCarthy, President, Open Tier Systems

About The Author

Brian McCarthy

Share This Post

Post Meta

Table Of Contents

Recent Posts

Featured Review

testimonial

Tortoise and Hare has been a key partner in our MSP's growth. Over the year's we've worked together they've helped our MSP dramatically increase our website traffic, and build a steady stream of leads sourced from our website and advertising efforts. Over that time, we've been able to raise our base customer size, build economies of scale to more efficiently service customers, and expand into new markets.

R.D.
President Regional MSP

Open Tier Systems

We Get IT Done
IT For Eastern Pennsylvania Businesses
Home » Field Notes » Your Insurer Grades Your Cyber Controls. Who’s Grading Your Subs?

Visit Us On Social Media

More About Our Open Tier Systems

Managed IT, Voice, AI and Compliance

Locations We Serve

Policies and Terms

Proudly Serving The State Of Pennsylvania

© 2018-2026 Open Tier Systems. All Rights Reserved.
This site content may not be copied, reproduced, or redistributed without the prior written permission of Open Tier Systems or its affiliates.

Get the prequal form and policy prompt

A two-page form covering the eleven controls your cyber insurer cares about, plus a starter AI prompt that drafts a written security policy for your subs, or any vendor that touches your systems, data or payments. It gets you close; you review and finish it. Fill this out and the download starts right away.