Legal & Compliance

Contractor Cybersecurity: Protect Your Business From Ransomware

Moil Team · 7 min read · Published 2025-12-18 · Last updated 2026-08-26

Contractor cybersecurity in four steps: MFA, a password manager, off-site backups and trained staff. What to do first and what it costs.

Contractor Cybersecurity: Protect Your Business From Ransomware

Do Hackers Really Target Small Plumbing and HVAC Companies?

Yes — because most attacks are automated, and automation does not care how big you are. A contractor's cybersecurity comes down to four controls: multi-factor authentication on email and banking, a password manager, an off-site backup you have tested, and a crew that knows what a fake invoice looks like. Set those up and you are harder to rob than almost every competitor in your trade.

The attackers scanning for weak logins are not choosing between you and a Fortune 500 company. They run software that tries stolen passwords against thousands of email accounts at once and follows up wherever one works. A two-van plumbing shop holds exactly what that software is looking for: customer addresses, saved card details, payroll information, and an owner with no IT department. You are not too small to be a target. You are the target profile.

What Are the Real Threats to a Trades Business?

Three attack types account for most of the damage done to small service businesses, and none of them requires a sophisticated hacker.

Notice what these have in common: none of them attacks your technology. They attack your habits. Verizon's annual Data Breach Investigations Report has found year after year that the large majority of breaches involve a human element — a reused password, a hurried click, an unverified payment change. That is bad news for anyone hoping to buy their way out of the problem with one gadget, and good news for anyone willing to change four habits.

What Is the Fastest Way to Protect My Business Today?

Turn on multi-factor authentication for your email and your bank. This is the single highest-value ten minutes in small business security: even when an attacker has your password, they cannot get in without the code on your phone. Use an authenticator app such as Google Authenticator or Authy rather than text messages where the service allows it — SMS codes can be intercepted, app codes generally cannot.

Second: stop reusing passwords. When one site you signed up for years ago gets breached, that email-and-password pair gets tried everywhere else — which is how a forgotten forum account becomes a drained bank account. A password manager such as Bitwarden (free for individuals) or 1Password (a few dollars a month) generates a unique password for every account and remembers them all. You memorize one master password and nothing else.

Third: never take card numbers by text or email. An unencrypted text sits on two phones forever and travels through systems you do not control. Send a secure payment link from Square, Stripe or whatever invoicing tool you use instead. If a customer starts typing digits, the professional reply is one sentence: "For your security, I'll send you a secure payment link." If invoicing is still a pile of paper in the passenger seat, fixing that has security benefits on top of the cash-flow ones — getting paid faster with invoice automation walks through the options.

What Is the 3-2-1 Backup Rule?

Keep three copies of your data, on two different types of storage, with one copy off-site. In practice for a small shop: the working files on your computer, a copy on an external drive in the office, and a cloud backup service such as Backblaze (under $10 a month per computer) running automatically in the background.

Backups are what turn ransomware from a business-ending event into a bad afternoon. If you can wipe the infected machine and restore yesterday's copy, there is nothing to negotiate over. Two warnings, though. A backup drive that stays plugged into the computer gets encrypted right along with everything else — the off-site copy is the one that saves you. And a backup you have never tried to restore is a hope, not a plan. Once a quarter, pick a file and actually restore it.

How Do I Train My Crew Without Becoming an IT Department?

Your team is your firewall, and training them takes minutes a month, not a course. Fold one security topic into your existing crew meetings: how to spot a phishing email (urgency, odd sender addresses, unexpected attachments) one month; why every payment-detail change gets verified by phone the next; what stays out of van paperwork the month after. The single rule that prevents the most expensive losses is worth repeating until it is reflexive: any email that changes where money goes gets confirmed by a phone call to a number you already had.

If your crew works in Spanish, train in Spanish. A warning that half the team only partly understood is a warning that does not work, and bilingual shops are routinely left translating safety-critical rules at the tailgate. The same applies to every written policy in the business — the essential Spanish documents for a bilingual shop covers which ones matter and why both versions need to say the same thing.

Is Cyber Insurance Worth It for a Small Contractor?

Usually yes — but read the application before you count on the payout. Small business cyber policies typically cover data recovery, legal costs, customer notification and sometimes ransom payments, for premiums that commonly run a few hundred to a couple of thousand dollars a year depending on revenue and coverage. The catch is that insurers now expect the basics — MFA, backups, some evidence of staff training — to actually be in place, and a claim can be denied if you attested to controls you never turned on. Treat the policy as a backstop for the fundamentals, not a substitute for them.

While you are at it, know your legal obligations. Most US states have breach notification laws requiring you to tell customers when their personal information is exposed, and states with consumer privacy statutes add rights around data deletion. The rules vary by state and change often, so the durable habit is simpler than the statutes: collect only the customer data you need, protect it with the controls above, and if a breach happens, notify affected customers promptly rather than hoping it stays quiet.

Where Does Security Fit in the Business Plan?

Security is an operating cost like insurance and fuel, and it belongs in the plan next to them: a password manager, a backup service and a cyber policy together typically cost less per month than one tank of diesel. If your business plan does not have an operations section where costs like these live, that is a bigger gap than the security itself — how to write a business plan for a small business shows what belongs in each section. Moil Professional at $25/month will write that plan with you — research, the full business plan, coaching and documents, in English and Spanish — so policies like "how we take payments" and "who can access the bank account" are written down once instead of living in the owner's head.

The Bottom Line

You cannot make a business unhackable, and you do not need to. You need to be harder to rob than the next contractor in the search results, and the controls that get you there are cheap and finite: MFA everywhere money or email lives, a password manager, a tested off-site backup, secure payment links, and a crew that verifies before it clicks. Do one this week. In a month you will have done them all.

Frequently asked questions

Why would hackers target a small plumbing or HVAC company?
Because you are easier and you still pay. Attacks are automated and indiscriminate — they scan for weak credentials, not for famous names. A contractor holds customer addresses, card details and payroll data, and usually has no IT staff, which is precisely the combination attackers look for.
What is the fastest thing I can do to protect my business today?
Turn on multi-factor authentication for email and banking, and stop reusing passwords. Those two changes block the overwhelming majority of real-world attacks and take about ten minutes. Everything else is worth doing, but nothing else has that ratio of effort to protection.
What is the 3-2-1 backup rule?
Three copies of your data, on two different types of storage, with one copy kept off-site. It is the reason ransomware becomes an inconvenience instead of a business-ending event: if you can restore from a clean copy, there is nothing to negotiate over.
Is cyber insurance worth it for a small contractor?
Usually yes, but read what it requires. Most policies now expect basic controls — MFA, backups, staff training — to be in place, and a claim can be denied if they are not. Treat the policy as a backstop for the basics, not a substitute for them.

Put Security in Writing

Moil Professional at $25/month includes research, the business plan, coaching and documents in English and Spanish — so payment policies, access rules and customer-data practices are written down where your whole crew can read them.

Start Professional at $25/month
Share this guideWhatsAppLinkedInXFacebookRedditEmail