Construction Cybersecurity in Houston: Why General Contractors Are Losing Bids

Houston general contractors can lose bids over cybersecurity when an owner asks for security proof, a cyber insurance certificate, or access controls the firm can’t produce, and the firm gets screened out before anyone compares price. Nobody calls to explain. The invitations just stop coming.

That’s the quiet way a Houston bid gets lost now, and it’s why construction cybersecurity in Houston has become a prequalification question. Part of my job as Uprite’s Lead vCIO is reading owner requirements before our construction clients sign them, alongside the construction IT services in Houston we run for general contractors and specialty trades. Over the past 2 years those requirements have grown a security section. Sometimes it’s a questionnaire. Sometimes it’s a clause about incident notice. Sometimes it’s a rating the owner can see and you can’t.

The GC with the sharpest number and a clean safety record can still get scored out. Nobody says your email security cost you the job. So I went looking for what Houston owners publish, what the prequalification platforms check, and what the public breach record says about Texas contractors. Where I cite a document, it’s linked.

Houston owners can check contractor security in 3 places, which are the prequalification platform, the contract, and the day your crew touches their systems. Chevron runs cyber diligence on suppliers before contracting. Port Houston’s purchase terms let it terminate, with no cure period, a vendor that mishandles its confidential data. ISN lets owners see a daily security rating for each contractor. And half of construction respondents in Travelers’ 2024 survey had no cyber insurance. Build the evidence before bid season.

What does it mean to lose a bid over cybersecurity?

Losing a bid over cybersecurity means an owner screens a contractor out, scores it down, or declines to award work because the contractor can’t show basic security controls, the right insurance, or safe access to the owner’s systems. It usually happens during prequalification or contract review, before anyone compares bid prices.

I’ll be straight about the evidence. No owner, platform, or survey publishes how many contractors lose work this way. Owners don’t announce it. Scores rarely come with comments. What owners do publish is the checklist. And the checklists changed.

The pressure comes from above you, not from the side. Autodesk’s TradeTapp, the tool a lot of GCs use to vet subs, gives 3 preset reasons for denying a subcontractor, which are safety, insurance, and other, according to Autodesk’s TradeTapp help guide. Cyber isn’t on the list. Procore’s standard prequalification form starts with 4 preset sections, which are General Information, Safety, Insurance and Bonding, and Financials, according to Procore’s own setup guide. None is a security section. A GC can add its own questions, though.

So the software GCs use on their subs doesn’t screen for cyber out of the box. Owners are screening GCs. Almost every guide I read skips that, because they’re written for a subcontractor answering a GC’s custom questionnaire, not for a prime facing a refinery, a hospital system, or a port.

The screening shows up at 3 points in the life of a job.

  • Before you bid, inside the owner’s prequalification platform, where a cyber module can be switched on and a security rating sits next to your safety record.
  • At award. Contract clauses, insurance certificates, and flow-down terms.
  • At mobilization, the first time someone on your crew needs an account on the owner’s network, a badge system, or a building controls interface, and a training rule or notice clock kicks in.
Contractor safety manager and owner representative reviewing a contractor cybersecurity prequalification on a tablet in a jobsite trailer beside a Gulf Coast petrochemical plant

Which Houston owners check a contractor’s security, and what do they ask for?

The big ones put it in writing. You just have to read past the safety manual to find it.

Chevron, now headquartered in Houston, published its supplier cybersecurity expectations in January 2025. The document lists 11 of them, and a few land hard on a general contractor. Suppliers are expected to align with a named framework such as ISO/IEC 27001, the NIST Cybersecurity Framework, IEC 62443, or NIST 800-53 and 800-82. Incidents go to Chevron immediately. Staff training has to cover business email compromise. And suppliers are expected to manage the cyber risk of their own suppliers, which for a GC means your subs. The last paragraph matters most. Chevron says it performs cyber-related diligence on its suppliers before contracting and during the relationship.

Before contracting. So, while you’re still bidding.

Port Houston is narrower. Its purchase order terms, revised August 19, 2025, govern any purchase that doesn’t have a separate signed agreement, and they only reach for security when a vendor touches port systems or data. A large construction contract will carry its own terms. Read those too. Anyone who gets an account on a Port Houston computer system, subcontractors included, has to complete a cybersecurity training program the port selects, and the vendor has to verify completion. A vendor handling Confidential Data has to safeguard it to commercially reasonable standards, with NIST and the Center for Internet Security named as examples, and give written notice within 5 business days of discovering an impermissible disclosure. If the port decides those duties were breached, it can terminate immediately, without notice or a chance to cure. An ordinary default under the same terms gets 10 calendar days’ notice to cure. A data security breach gets none.

Owners don’t always put cyber on the certificate, either. Port Houston’s default insurance list, the one that applies when a solicitation doesn’t name coverage, has no cyber line at all. Its cyber duties sit in the security clauses instead. Scope decides it.

Hospitals work differently. Memorial Hermann’s construction and facility services page says it requires HIPAA training for all employees and vendors, regardless of access levels. Every vendor, not just IT. Its security best practices govern the installation of all security hardware, devices, and technology across the system. If your low-voltage or electrical sub is pulling cable for cameras and card readers in a Memorial Hermann building, those standards are part of the job.

Houston owner or platformWhat its published document asks of contractorsWhat you’d need to hand over
Chevron (supplier expectations, January 2025)Alignment with ISO/IEC 27001, NIST CSF, IEC 62443, or NIST 800-53 and 800-82, immediate incident reporting, BEC training, and supply chain risk management, with diligence before contractingYour framework mapping, an incident response plan with Chevron’s notice path in it, training records, and your subs’ answers
Port Houston (PO terms, rev. August 19, 2025)Port-selected cyber training for anyone with a port system account, subs included, plus evidence of controls when handling port data and written notice within 5 business days of a disclosureCompletion records by name and a written summary of your safeguards on request
Memorial Hermann (construction and facility services)HIPAA training for all vendors regardless of access, plus system standards for security hardware and devicesHIPAA training records for everyone the hospital treats as a vendor, and install documentation that matches its standard
ISNetworld hiring clientsA cyber questionnaire, cyber-focused written programs, verified cyber liability insurance, and worker awareness training, at the owner’s optionWritten policies, a current certificate, and training completions uploaded before the owner’s review

Who uses ISNetworld around here? Filter ISN’s hiring client directory to Texas and you’ll find BP, Chevron, ExxonMobil, Phillips 66, Motiva, Valero, TotalEnergies, Lyondell Chemical, INEOS, Enterprise Products, Kinder Morgan, and Freeport LNG. ISN doesn’t disclose which of them switch on the cyber tools. I won’t pretend otherwise. But every one of those names can do it without calling you first.

What does an owner see before you answer a single question?

More than most contractors assume. ISN’s cybersecurity page says hiring clients can see SecurityScorecard ratings of their contractors inside ISNetworld, built from 10 categories of risk that include patching cadence and network and application security. The ratings refresh daily. They’re built from what’s visible from the outside, which means an owner’s risk team can form an opinion of your firm before you’ve filled in a single field.

Owners pay nothing extra. In September 2025, ISN expanded its Cyber Secure tools, added breach scanning, and said the package is available to hiring clients at no additional fee. Avetta, another prequalification platform owners use, launched a cyber score in 2023 that gives every supplier an A to F grade, and its launch release says clients can use it to inform sourcing decisions. Sourcing decisions. That’s the bid list.

The causes are rarely exotic. Public-footprint findings tend to be leftovers, like a VPN portal on a firewall nobody’s patched since the last big job, a webmail login page for a project that closed, a domain with no email authentication records, or an office router with its management page open to the internet. A rating service finds all of it with a scanner. So can anyone else.

Then comes the deeper review. When an owner wants more than a desktop review, ISN offers Cyber 360, which combines document submission, an employee survey, and an interview with the contractor’s IT or management team. If your IT is one person who left in March, that interview is going to be short.

Why doesn’t an insurance certificate settle the cyber question?

Because a certificate says a policy exists. It doesn’t say what the policy covers, or whether you’d get paid.

Start with the base rate. In the Travelers 2024 Risk Index, 50% of construction respondents said they lacked cyber insurance, the highest share of the 8 industries Travelers broke out. On the same panel, 45% didn’t use multifactor authentication for remote access, 70% didn’t use endpoint detection and response tools, and 56% had no incident response plan, even though 80% said proper controls were critical. Travelers’ 2025 construction panel shows some progress, with 36% still skipping MFA for remote access and 65% without endpoint detection, but it didn’t report the insurance number, so 2024 is still the latest read on coverage.

The MFA, endpoint detection, and incident response gaps are exactly what a cyber insurance application asks about. An owner questionnaire asks the same things. Make sure the answers match. An owner’s risk team that sees MFA claimed on the questionnaire and a carrier that later finds MFA only on the firewall will both have questions. In 2022 one carrier went to federal court to void a policy over exactly that kind of gap, a case we covered in our cybersecurity checklist for Houston small businesses.

An owner who’s been burned has reason to stop trusting the certificate. Texas law backs that up. Under Insurance Code Section 1811.051, a certificate can’t alter the policy it describes and can’t give the holder a contractual right, and the Texas Department of Insurance tells certificate holders they can request a copy of the policy. A careful owner will. When that request comes, 3 things get read first.

  • Whether social engineering and funds transfer fraud are covered at all, and at what sublimit. That’s the pay application scenario below.
  • The limit, against the contract.
  • Endorsements. Insurers do write construction-specific ones, and a January 2025 IRMI article on construction cyber risk lists coverage for missed bids among them, which pays bid preparation costs when a breach stops you from submitting. Somebody built a product for losing a bid to a breach. That tells you it happens.

Sureties are watching too. I’d still rank them behind owners. Liberty Mutual Surety, in guidance updated in 2024, says skilled underwriters will also ask about cybersecurity, and ties strong internal controls to whether a contractor takes on larger projects. Bonding still turns mostly on capital, capacity, and character. Cyber is one of the controls in the file.

Standard forms stay quiet. The AIA A101-2017 insurance exhibit lists cyber security insurance as an optional owner coverage and gives the contractor side only an other insurance fill-in. So when an owner on an AIA contract wants contractor cyber coverage, someone typed it in.

Who pays when a pay application gets redirected?

In Texas, whoever the factfinder decides was most at fault. Which is why owners have started caring about your email.

You’ve seen this one. Someone gets into a mailbox, or spoofs one, waits for a pay application, and sends new banking instructions from what looks like the GC’s controller. The money moves. Business email compromise cost victims about $3.05 billion in 2025, according to the FBI’s 2025 Internet Crime Report.

Houston has its own case law on who eats it. In Prosper Florida, Inc. v. Spicy World of USA, Inc., decided by Houston’s First Court of Appeals on April 28, 2022, a Houston buyer wired $16,950 for 6,000 pounds of black pepper to an account that turned out to belong to a fraudster. The seller sued for the price anyway. It lost. The trial court found the buyer’s manager had called the seller’s manager to verify the wiring instructions before sending the money, and the appeals court affirmed the take-nothing judgment, holding that the loss from a misdirected payment belongs on whichever party the factfinder finds most at fault for the misdirection.

Now flip chairs. If a payment to a GC gets redirected because the GC’s mailbox was compromised, the owner’s lawyer is going to argue the GC enabled the fraud. The owner who’d rather not have that argument at all screens for it up front. That’s likely part of why Chevron’s list asks for BEC training specifically. It’s also why a November 2025 article by construction lawyers at Peckar and Abramson on ConsensusDocs, which found courts split 3 ways on these losses, tells parties to agree by contract how payment changes get verified, including a call to a live person before any wire goes out.

A callback needs no software. It’s also what won that Houston case. We walk through the jobsite side of this risk, including how the fake banking change usually arrives, in the IT risks that stop Texas construction projects.

Construction company controller calling to verify a payment change while holding a pay document, with a steel yard outside the window

How exposed are Texas construction companies right now?

More than the industry’s size would suggest, at least in Houston.

We pulled the Texas attorney general’s data breach report list on September 28, 2026. It held 640 notices, covering roughly the prior 12 months, from organizations reporting breaches that affected Texans, with filing required once 250 or more are affected. The AG’s form has no construction category, so we read all 640 names by hand and checked every plausible construction firm against its own business line. General contractors, heavy civil firms, homebuilders, specialty trades, and construction materials suppliers made the cut. Design-only engineering firms, construction software, and equipment dealers didn’t.

We counted 23 construction filings. Here’s how they compare with everyone else on the list.

MeasureConstruction filingsAll 640 filings
Notices that exposed Social Security numbers23 of 23 (100%)530 (82.8%)
Notices that exposed financial account information16 of 23 (69.6%)296 (46.3%)
Notices that exposed driver’s license numbers15 of 23 (65.2%)331 (51.7%)
Median days from breach start to discovery69 (17 filings with a start date)72 (535 filings)

All 23 exposed Social Security numbers. Payroll records, onboarding packets, and certified payroll files all carry them. Financial account data showed up in 7 of every 10 construction notices against fewer than half of everyone else’s, which fits a business that stores direct deposit details for its crews and banking details for its subs, although the AG’s form doesn’t say whose records they were, so I won’t claim more than the pattern.

Detection speed is no different. A median of 69 days from the start of a breach to discovery, against 72 for the whole list. Two months before anyone notices is normal, apparently. It shouldn’t be.

The Houston number surprised me. Construction made up 10.5% of Greater Houston’s 76 notices, against 3.6% of the full list and 7.4% of the metro’s business locations in Census data. Greater Houston also filed 8 of the 15 construction notices from Texas-based organizations, while the metro filed only 29% of all Texas-based notices. Half of those 8 came from industrial specialty contractors along the Ship Channel, the kind of firms that live inside refinery and chemical plant prequalification systems. Take them out and Houston has 4. The sample is small. I’d still watch it.

Two limits apply. Filing is only required once a breach reaches 250 Texans, so it’s a floor, and every date on it is self-reported. It also doesn’t record cause, so none of these can be pinned on ransomware or email fraud from the list alone. What the list does do is put company names on a public page for about a year. Anyone can search it. Owners’ risk teams included.

Which Houston contractors feel this first?

The ones whose customers answer to someone else.

Size matters less than your customer list, but size sets what Texas law will reward. Census County Business Patterns for 2023 counts 7,718 construction establishments in Harris County employing 166,110 people. We sorted them into the size tiers Senate Bill 2610 uses for its safe harbor. Of those, 82.9% have fewer than 20 employees. Another 1,005 locations sit in the 20 to 99 tier, where the safe harbor’s named standard is CIS Controls Implementation Group 1, which overlaps much of an owner questionnaire, including MFA, anti-malware, backups, and basic incident reporting roles. A full incident response process and restore testing sit a tier up, in IG2. Another 200 sit at 100 to 249. And 112 locations have 250 or more employees, which puts them outside the safe harbor entirely.

Commercial GCs skew toward the middle. Among Harris County’s 649 commercial and institutional building establishments, 16.8% fall in that 20 to 99 tier, compared with 13.0% for construction overall. Those are the firms that bid schools, hospitals, and office towers. Census counts locations, not companies, so a multi-yard contractor shows up more than once, but the shape holds. Our guide to the IT compliance rules each Texas contract brings covers what SB 2610 actually offers and what federal work adds.

If most of your work isExpect to be asked forFix this first
Refinery, chemical plant, or midstream work on the Ship ChannelA platform cyber module, written programs, a security rating, and rules for remote access into plant systemsNamed accounts and MFA on every remote access path, plus a written program mapped to the owner’s framework
Hospital projects, Memorial Hermann for oneHIPAA training for anyone the hospital treats as a vendor, plus device standards for security hardwareTraining records by name and install documentation for every camera, reader, and controller
Port Houston, Texas state agencies, and other public owners with similar termsOwner-selected training for anyone with a system account and short breach notice windowsAn incident response plan that names each owner’s notice clock
Federal work at a base, NASA site, or VA facilityContract safeguarding clauses that flow down to any sub that handles federal contract informationAn honest self-assessment you’d sign, before the solicitation arrives
Private work for developersNothing yet, until your insurer or surety asksMFA on email and a payment callback rule, then revisit when your owner list changes

If you only build private work for developers who’ve never sent a questionnaire, you probably don’t need a compliance program. You need MFA, a callback rule, and working backups. We’d rather tell you that than sell you a tier you won’t use.

What should a GC have ready before the next prequalification packet?

Evidence with dates on it. Intentions don’t score.

Build this folder.

  • A report showing MFA enforced on every account, superintendents, estimators, and the shared project mailbox included.
  • Endpoint detection coverage. A count, not a claim, of every laptop and tablet that opens company email.
  • Proof of a restore test, with a date. Which file, from what date, and how long it took to come back.
  • An incident response plan that names the clocks you’ve signed, including Chevron’s immediate notice, Port Houston’s 5 business days, and the Texas attorney general’s 30 days once 250 Texans are affected.
  • Your payment change rule, written down. Callback to a number already on file, 2 people to release a wire.
  • Written security policies an owner’s platform can actually read.
  • Training completions by name, subs too if they’ll touch owner systems.
  • The cyber policy and its endorsements, not just the certificate.
  • Subcontractor answers, collected early.
  • Your own outside view. Look at your public footprint the way a rating service does, and clean it up first.
Superintendent on a concrete deck checking a sign-in request on his phone beside a tower crane with Houston office towers behind him

A compliance and regulatory assessment ties each item to the owner clause that asks for it.

Timing trips people up. Owners ask at predictable moments, such as the platform review, the prequalification packet, the pre-award questionnaire, the certificate before mobilization, and the flow-down clause in your subcontracts. The worst time to build this pack is the 2 weeks before a bid is due, which is precisely when the request usually shows up.

My advice is to build at least a full quarter of dated records before you need them. A single restore test dated last Tuesday tells the reviewer you started when they asked.

What does closing the gaps cost a Houston GC?

Less than a lost bid, usually. A 30-seat GC with its own IT person would start at $1,200 a month for the security layer.

If you already have an IT person or provider, a monitored security layer on top, which covers SOC monitoring, vulnerability scanning, and quarterly security reviews, starts at $40 per user per month. Co-managed IT, where we work alongside your internal person, starts at $100. Fully managed IT starts at $138 per user per month and carries the whole stack. When an owner’s requirements outgrow the office, Uprite BUILD Secure℠, part of our managed IT services for construction, adds the compliance and vCISO layer. Our breakdown of construction IT pricing in Texas shows what each band covers per seat, our cybersecurity services in Houston page covers the security side on its own, and cybersecurity cost in Houston breaks down what that layer runs by industry rulebook.

Still comparing providers? Our list of the best IT providers for construction in Houston is a reasonable place to start, and we’re on it, so read it with that in mind.

The pack above is the same whether we build it or someone else does. Just don’t let the first owner who asks be the one who finds the gaps.

What Houston Contractors Ask About Security and Bids

Why would a GC with the lowest price still lose on security?

Because price usually isn’t compared until a contractor has cleared the owner’s screen. A prequalification score, a missing insurance line, or an unanswered questionnaire can drop a firm from the short list, and owners rarely say that’s what happened.

Is cyber liability insurance mandatory for Texas contractors?

No Texas statute requires a contractor to carry cyber insurance. Texas does require reasonable procedures to protect sensitive personal information under Business and Commerce Code 521.052, and owners can write a cyber policy into any contract they like. Some Houston owners handle it through security clauses instead. Port Houston’s default purchase order insurance list has no cyber line, while its security terms still apply to anyone with an account on port systems.

What does ISNetworld’s cybersecurity review actually ask for?

ISN lets a hiring client require 4 things, which are a cybersecurity questionnaire, cyber-focused written programs, verified cyber liability insurance, and awareness training for individual workers. Owners can also see a SecurityScorecard rating that refreshes daily, and owners that want more than a desktop review can send contractors through Cyber 360, which adds document review, an employee survey, and an interview with your IT or management team.

Does a certificate of insurance prove we have cyber coverage?

Not really. It shows a policy exists, and under Texas law a certificate can’t change that policy or give the holder any contractual right. Careful owners ask for the policy, then check the limit, whether social engineering and funds transfer fraud are covered, and which endorsements you carry.

If an owner wires our pay application to a scammer, who eats the loss?

Under Texas case law, whichever party the court finds most at fault for the misdirection. Houston’s First Court of Appeals applied that rule in Prosper Florida v. Spicy World in 2022, and the buyer won after the trial court credited its manager’s call to verify the wiring instructions. If your mailbox was the one compromised, expect the owner to argue you enabled it. A written callback rule on both sides is the cheapest protection there is.

Do our subs need CMMC certification right now?

Only on defense work that carries the clause, and even then mostly at the self-assessment level. DoD suspended CMMC Phase 2 on July 13, 2026, but self-assessments and the underlying NIST controls still apply wherever a solicitation includes them, and they flow down to subs.

We just failed an owner’s security review. Now what?

Ask which items scored you down, in writing, before you fix anything. Guessing wastes time. Close the cheap ones first, such as MFA, a payment callback rule, and a dated restore test. Then send dated evidence back with a short plan for the rest.

Have an owner questionnaire on your desk, or expect one this bid season? Get an assessment before you answer it. We’ll work through the questionnaire with you, write down the controls you already have, and put dates on the ones you don’t.

Get an Assessment

About Author

Learn More