PS ProTech(305) 699-5652
← All posts

Architecture and engineering firms

Ransomware and the project deadline: what design firms should prepare

· PS ProTech · 2 min read

A design firm's value sits in its project files: years of drawings, models and specifications, most of them too large to recreate. Attackers know what those files are worth to you the week before a submission. That timing is the whole business model of ransomware.

Why design firms are exposed

Deadlines that can't move. A bid date or a planning submission gives an attacker leverage. The closer the deadline, the more a firm will consider paying.

Very large files. Models and drawing sets run to many gigabytes. Restoring them takes far longer than restoring documents, so even a firm with good backups can be down for days.

Specialist software on older systems. Design software is expensive to upgrade and sometimes tied to a particular version of an operating system. Workstations that can't be updated are the easiest way in, as we explain in why software updates matter.

A server at the center. Many firms still keep active projects on a server in the office because the files are too big for ordinary cloud storage. If that server is encrypted, everyone stops.

Many outside parties. Contractors, consultants and suppliers all exchange files and invoices with you by email. That makes impersonation easy, including fake invoices with changed bank details.

What to prepare

1. Decide how long you can be down. For most design firms the honest answer is "hours, during a deadline week." That number determines what you need. We explain how to work it out in backup versus business continuity.

2. Back up the project server so it can be run, not only restored. A business continuity device can start a copy of your server in minutes while the original is repaired. For large files, that's the difference between an afternoon and a week.

3. Protect every workstation with tools that recognize ransomware behavior. See antivirus is not enough.

4. Deal with the machines that can't be updated. Replace them, or separate them from the rest of the network so a problem there can't spread.

5. Confirm payment changes by phone. Any contractor or supplier asking to change bank details gets a call on a number you already hold. See the call-back rule.

6. Test the restore with a real project. Pick a large one and time how long it takes to get back. That's your real recovery time.

Think about the drawings themselves

Plans for buildings and infrastructure can show access routes, security systems and services. Some clients, particularly public bodies, treat them as sensitive and will ask how you protect them. A breach can be a contractual problem as well as an operational one.

When it happens anyway

Have a one-page plan with the numbers to call and the steps to take. We set one out in the first hour of a ransomware attack.

Our page for architecture and engineering firms covers the threats and the costs. To see how long your firm would be down, book a free IT and cybersecurity review.

See what it costs for your firm.

Build a plan in two minutes. No call required.