Your Insurer Grades Your Cyber Controls. Who’s Grading Your Subs?

Every general contractor I talk to has filled out a cyber liability questionnaire. MFA on email? EDR on every machine? Backups ransomware can’t reach? A written incident response plan? Get those answers wrong and your premium goes up, your coverage shrinks, or your renewal gets declined.
Now ask yourself how many of your subs could answer the same questions. Most GCs don’t know, because they’ve never set subcontractor cybersecurity requirements at all. That matters, because your subs work inside your systems every day, and an attacker doesn’t care whose laptop they come in through. Below is the bar we recommend, how to roll it out, and a free prequal form and policy prompt to get you started.
Where the shared risk shows up
Construction runs on shared access and moving money, and that’s exactly what attackers look for. Your subs log into your project management platform. They send pay apps, lien waivers, change orders and invoices by email. They share drawings and bid docs through links nobody tracks. Some of them have credentials to your job site cameras or your plan room.
The most common problem isn’t ransomware. It’s a compromised mailbox somewhere in the chain. An attacker sits quietly in a partner’s email for weeks, learns your billing rhythm, then sends your AP team a perfectly timed note: “We’ve changed banks, please update our wire info before this draw.” It comes from a real address, references a real job, and matches a real invoice. Your team pays it, and the money’s gone.
Nobody did anything wrong in that scenario. Your sub is a victim too, and neither of you had a shared standard that would have caught it. Your insurer may not see it that way, and depending on your policy, social engineering losses like that can be sublimited or excluded entirely.
Use the bar your insurer already set
You don’t need to invent a security standard for your subs. Your cyber carrier already wrote one. The questionnaire you fill out at every renewal is the insurance industry’s distilled view of which controls actually stop losses, built from years of paid claims.
That makes it the right bar for three reasons. It’s practical, since these are controls a 10-person company can actually put in place. It’s fair, because when a sub has questions you’re not asking for anything beyond what your own insurer asks of you. And it’s already familiar, since plenty of your subs carry their own cyber policy and have seen the same questions.
If you bid federal work, you’re already headed here. CMMC requirements flow down from prime contracts to the subs who handle controlled information, so you’ll have to start asking these questions anyway. Better to build the habit across your whole sub base now than scramble on a single job later.
The subcontractor cybersecurity requirements to set
These are the controls that show up on nearly every leading cyber liability application. Ask your subs to attest to each one in your prequal, the same way they attest to insurance and safety. They’re also aligned with CIS Controls v8 Implementation Group 1, the recognized baseline for small businesses, so you’re asking for a named standard, not something you made up.
| Control | What it means for a sub | Why it matters to you |
|---|---|---|
| MFA on email and remote access | A second factor on every mailbox, VPN and cloud app | Stops the stolen password that leads to wire fraud |
| MFA on shared platforms | Their logins to your PM platform, plan room and portals use MFA | Your project data is only as safe as their weakest login |
| Managed detection and response | EDR on every laptop and desktop, watched 24/7 by a security team that can isolate a threat | Catches an attacker before they pivot to you |
| Email security | Advanced scanning of inbound and internal mail for phishing, impersonation and malicious links, plus SPF, DKIM and DMARC | Makes their domain harder to spoof against your AP team |
| Identity threat monitoring | 24/7 watch on their email and Microsoft 365 accounts for suspicious sign-ins, forwarding rules and account takeover | Catches the quiet mailbox compromise behind most wire fraud before the fake invoice reaches you |
| Encrypted, immutable backups | Multiple encrypted, immutable copies of email and files, at least one outside the primary platform, with restores tested at least yearly | Ransomware can’t alter or delete them, so a sub who gets hit can still deliver your job |
| Patching | Operating systems and key apps updated on a set schedule | Closes the holes attackers scan for first |
| Security awareness training | Annual training plus phishing simulations | Their people are your people’s first line too |
| Payment verification | Bank changes confirmed by phone to a known number | Kills the most common construction scam outright |
| Incident response plan | A written plan, including when they’ll notify you | You hear about a breach in hours, not months |
| Cyber liability coverage | Their own policy, including coverage for social engineering and funds transfer fraud | Their loss doesn’t become your claim |
Notice what’s not on this list: brand names. You’re requiring outcomes, not vendors. Any sub can meet these with whatever tools they choose, as long as they can prove it.
Download the subcontractor prequal form. It’s a two-page attestation covering all eleven controls, ready to drop into your prequal package, plus a starter AI prompt that drafts a written security policy built around your company, your projects and your subs. It works for any vendor that touches your systems, data or payments, not just subs. It’ll get you close, but every draft needs a human review before you put it to work.
How to roll it out
- Get your own house in order first. You can’t require what you don’t meet, and your subs will ask. Run your own answers against the questionnaire honestly and close the gaps before you send anything out.
- Add it to prequal. Put the controls into your subcontractor prequalification form as a short attestation. Start with new subs and renewals rather than your whole list at once. Our free subcontractor prequal form is ready to drop in as is.
- Set a grace period. Give existing subs six to twelve months to comply. Make MFA and payment verification day-one requirements, since they’re cheap and stop the most damage.
- Give subs a path. Point them to a provider who can assess them and get them compliant quickly at a predictable cost. A requirement with no path just shrinks your bid list.
- Write it into the subcontract. Once the program is running, add the controls and a breach notification clause to your standard subcontract language, the same way insurance requirements live there today. The policy prompt in our download drafts a written policy and starter clause language with your AI of choice, ready for your attorney to review.
- Verify, lightly. You don’t need to audit every sub. Spot-check a few each year, and ask for evidence from anyone handling sensitive data or touching your payment process.
The pushback you’ll hear
“I’ll lose good subs” is the first thing every GC says, and it’s the same thing they said about safety programs and certificates of insurance. The good subs adapted, and the market got better for it. Lead with the cheap, high-impact controls, give people time, and almost nobody walks away.
Cost is the next objection, and it’s smaller than most subs expect. MFA is usually included in the email platform they already pay for. Payment verification is a phone call. The bigger items, managed EDR and real backups, typically run less per month than a single change order dispute costs in lost time.
The last one is enforcement, and the honest answer is you won’t police every sub perfectly. You don’t have to. Asking the question in prequal shifts the conversation, documents that you did your diligence, and gets most subs moving. That alone puts you ahead of nearly every GC you bid against.
Where we come in
Open Tier Systems has supported construction firms across the Philadelphia suburbs since 2006, and this is exactly the work we’re built for. We start with the GC. A free discovery call tells us where you stand and what you’re up against. From there, our Cybersecurity Risk Assessment measures you against a leading insurer’s questionnaire and lays out exactly what it takes to close the gaps.
Once your house is in order, we help you build the sub requirement into prequal, and we support your subs directly so they’ve got a clear, affordable path to comply instead of a reason to walk. Many of the subs working Philadelphia-area jobs are already Open Tier Systems clients, so for a good part of your bid list the path is already in place. You set the standard. We help everyone meet it.
Not ready for a call yet? Grab the free prequal form and policy prompt and start with your own house.
Brian McCarthy, President, Open Tier Systems