Key Takeaways
- Shared tablets and old subcontractor logins are real exposure. One device used by three shifts, with a login that outlives the sub’s contract, is the kind of exposure most sites never lock down.
- A password manager and multi-factor authentication are the fastest fixes. They solve most shared-login risk without buying anything fancy.
- Job trailer Wi-Fi is often wide open. An unlocked network on a remote site is an easy door for anyone parked nearby.
- Online safety belongs in your daily routine, not a once-a-year training. One habit added to a toolbox talk goes further than a long slideshow nobody remembers.
Why Online Safety Is a Jobsite Problem
A construction site carries a layer of digital exposure that sits right next to the physical hazards, and it usually goes unwatched. Think about how one shared tablet moves through a normal day:
- The morning crew logs a pre-task plan on it.
- The afternoon crew grabs it for inspections.
- A sub picks it up to sign off on a permit.
Every one of those hands touches the same login, the same saved passwords, and the same open apps. Nobody logs out, and nobody knows who did what.
Subcontractors multiply that exposure. A big project might run a dozen of them, each with their own crew and their own logins into your systems, and some of those logins stay active long after the sub’s contract ends. That leaves open accounts nobody is watching, on systems that hold your compliance records and worker data.
Field crews get trained hard on the hazards of the job and how to control them: fall protection at height, confined-space entry, and hazardous-energy lockout. Digital risk almost never makes the list. Nobody sits a crew down and says, “Here’s how to spot a fake text from the super.” So the exposure sits there, and you own the fallout when something goes wrong.
The fixes below don’t need an IT degree. They’re the same safety basics that get overlooked on busy sites, just pointed at your screens instead of your scaffolds.
Online Safety Tips for Passwords and Multi-Factor Authentication
Start with passwords, because weak ones are still the easiest way in.
Problem: Nobody can remember twelve strong passwords for a shared site tablet, so they pick something short and reuse it everywhere.
Solution: A password manager. It stores long, unique passwords for every app and login, and the crew only has to remember one. Set it up once on the shared tablet and it fills in logins automatically.
Length matters more than complexity. The NIST digital identity guidelines recommend longer passphrases over short, complicated strings, so a long phrase you can remember beats a short jumble of symbols you can’t.
Then turn on multi-factor authentication, or MFA. That just means a second check after the password, usually a code sent to a phone or an app. Even if someone steals the password, they can’t get in without that second step. Turn it on first for the accounts that matter most: email, your safety app, and anything tied to payments or payroll. The CISA cybersecurity best practices call MFA one of the strongest single moves you can make.
Shared Tablets and Group Logins
Problem: One login shared across a whole crew. It feels efficient, but when everyone signs in as the same user, you can’t trace anything. If a permit gets signed off wrong, a form gets deleted, or someone clicks a bad link, you have no idea who did it.
Solution: Individual logins tied to each worker, even on a shared device. Most apps let each person sign in and out on the same tablet. It’s an extra step, but now every action has a name on it, so when something goes sideways you can find out what happened instead of guessing.
Online Safety Tips for Spotting Phishing Aimed at Construction Crews
Scammers who target construction know how contractors get paid, and they aim right at it.
The FBI’s Internet Crime Complaint Center tracks business email compromise, where a scammer poses as a trusted party to reroute payments. It’s consistently among the costliest scam types they report, and construction is a target because so much money moves between the general contractor and subs.
One common trick on site is a fake text or email that looks like it’s from the superintendent or safety manager: “Hey, quick, I need you to send me those inspection photos,” or “Log in here to approve this before end of day.” It comes when everyone’s busy, so people react fast and don’t check. That’s exactly what the scammer counts on.
Crews also get burned looking up safety answers. A worker who needs a quick answer on a chemical or a procedure might search a random site or click a link that got texted around, which is a phishing risk. A tool like Ask Mojo gives workers one trusted, bilingual place to ask questions straight from your uploaded documents, so they’re not hunting through random search results or texted links for an answer.
Invoice and Payment Scams
This is the one that hits contractors hardest, so it’s worth its own look.
Problem: An email that looks like it’s from a vendor or sub you already work with says their bank info changed and asks you to send the next payment to a new account. The logo looks right and the signature looks right, but the account is the scammer’s.
Solution: Never change payment details based on an email alone. Call the vendor at a number you already have on file, not the number in the email, and confirm the change by voice with a person you know. That one phone call stops most of these cold.
Secure Job Trailer Wi-Fi and Shared Devices
Your network often lives in a job trailer that anyone can drive up to, and your devices move around the site with the crews.
Problem: An open or shared trailer network, plus tablets left unlocked on the desk, gives anyone nearby an easy way in.
Solution: Separate your networks and lock your devices. Keep one guest network for visitors, subs, and general use, and one admin network for office and payment work, so a compromised guest device isn’t sitting next to your payroll. Set tablets to lock after a short idle time and ask crews to log out when they hand a device off, since a tablet left open in a trailer is the same as leaving it unlocked with the books on the desk.
Remote sites make the network trickier. If the only option is a public or open connection, don’t run sensitive work over it. Use a VPN, a virtual private network that scrambles your connection, or run a dedicated hotspot instead.
Protect Subcontractor and Worker Data
Every multi-sub project runs on paperwork: certs, insurance, training records, and compliance documents. The default way to move all that is email, and email is where it goes wrong.
Problem: When you pass sensitive compliance documents back and forth with a dozen subs, you lose track of where the files land. Copies sit in inboxes forever, old threads get forwarded, and that channel is exactly where invoice fraud and phishing sneak in.
Solution: Limit access so each sub only sees their own project data, and get compliance documents out of email threads and into one tracked place.
That’s the idea behind the Contractor Scorecard. Instead of emailing compliance and performance documents back and forth with every sub, it keeps that data in one tracked place, so you see who’s compliant without sensitive files bouncing around a dozen inboxes where they can get lost or spoofed.
Keep Devices and Safety Apps Updated
Outdated software is a plain, boring risk that causes real trouble. Old apps and operating systems have known holes, and scammers know exactly how to use them.
Problem: Nobody owns the updates on a shared site tablet, so they get skipped for months, and that unpatched app becomes an easy entry point sitting right there on the trailer desk.
Solution: Make updates a monthly routine. Pick one day, check every site device, and run the updates, then turn on automatic updates where the device allows it. Five minutes a month beats dealing with a breach later.
The CISA cybersecurity best practices point to regular updates as one of the simplest ways to close known security holes before anyone can use them.
Think Before You Post Jobsite Photos or Locations Online
Crews are proud of their work, and they should be. But a photo posted online can give away more than you meant.
Problem: Many phones tag photos with location data, called geotagging, without anyone noticing. A progress shot can broadcast the exact spot and timing of an active site, and the image itself can show site layouts, equipment staging, and schedules, telling a thief what’s there and when nobody’s around.
Solution: Set a short internal policy on what crews can and can’t post, and turn off location tagging on work photos. Keep it simple enough that people actually follow it.
Make Online Safety Part of Your Daily Safety Routine
A one-time cybersecurity training won’t stick, and you already know that from every other safety topic. What sticks is repetition, folded into the work you already do.
So don’t build a whole new program. Add one online-safety habit to your toolbox talks each month. One month it’s spotting a fake payment email. The next it’s logging out of the shared tablet. The month after, checking photos before posting. Small, steady, and tied to something crews already show up for. You could even turn this into a five-minute toolbox talk and knock out the first one this week.
The other piece is cutting down on scattered, unsecured file-sharing in the first place. The fewer sensitive files bouncing around random inboxes and searches, the less there is to protect.
For more field-tested safety guidance you can bring to the crew, check out the Safety Mojo blog.
Frequently Asked Questions
What are 5 internet safety tips?
Use a password manager for long, unique passwords. Turn on multi-factor authentication on your key accounts. Don’t click links in unexpected texts or emails. Keep your devices and apps updated. And verify any payment change by phone before you act on it.
What are 10 cyber safety rules?
Use strong unique passwords, turn on multi-factor authentication, give each worker their own login, log out of shared devices, keep software updated, separate guest and admin Wi-Fi, don’t click unverified links, confirm payment changes by phone, limit who can see sensitive data, and turn off location tags on work photos.
What are 5 ways to protect yourself online?
Use a password manager and turn on multi-factor authentication. Slow down before clicking any link or email that pushes you to act fast. Verify payment or bank-detail changes by phone, never by email alone. Keep your devices updated. And never share one login across a whole crew.
What are 5 facts about online safety?
Weak and reused passwords are still a top way in. Phishing scams target how contractors get paid, and the FBI’s Internet Crime Complaint Center reports business email compromise as one of the costliest scam types. Multi-factor authentication stops most stolen-password attacks. Old, unpatched apps are an easy entry point. And shared logins make it impossible to trace who did what.