AccuSights
PartnersBlogAbout
Book my 30-minute demo

Architecture, Engineering & Construction · Cybersecurity, compliance and GRC, in plain English

Protect your designs, bids and payments. Win the federal work.

Principals run on trust with owners, contractors and subs, and every one of those relationships moves money by email. We stop payment diversion, protect project IP, keep you eligible for DoD projects under CMMC, and answer the owner’s security questionnaire before it costs you the bid.

Wire-fraud controls firstCMMC-ready for federal projectsPublic pricing

The test is scored against CIS Controls v8.1 IG1 and the CIS Community Defense Model. You see your score immediately, then we talk if you want to.

A story we hear too often

The morning thirty years of drawings became a ransom note

the principal of a 22-person architecture studio

Sam Reyes founded the studio in 1994 in a loft on Hubbard Street. Twenty-two people now, a hospital wing under construction, two schools in design, and a project server that holds every drawing the firm has ever issued. Thursday is the draw request for the hospital: $1.4 million to the contractor.

At 7:20 on a Thursday the office manager cannot open the project server. Every folder has a new file in it, and the file is a letter. It explains that thirty years of drawings are encrypted, that copies have been taken, and that the price goes up on Monday. The Revit models for the hospital wing are in there. So are the schools.

In the version that closes a studio, the backups were on the same server, the contractor’s draw request that morning carried new bank details from a compromised sub, and the firm learns in the same week that its drawings are for sale and its money is gone.

In Sam’s version, the offline backup from Wednesday night is intact, the engineer on watch had isolated the server at 4:12 a.m. when the encryption began, and the draw request goes out at noon after a phone call confirms the contractor’s bank has not changed. The hospital does not know. The studio loses a morning, not thirty years.

It explains that thirty years of drawings are encrypted, that copies have been taken, and that the price goes up on Monday.

What changes the ending

  1. Offline, tested backups of the project server, the models and the drawing archive (CIS Control 11, Data Recovery)
  2. A call-back rule on every draw, pay application and bank change, with project mailboxes under MFA (CIS Controls 5, 9 and 14)
  3. Endpoint protection and a watched network that isolates a server at 4 a.m., not at 7:20 (CIS Controls 10 and 13)
Show me this running for my business

The questions owners are afraid to ask

Ask them anyway. Here are the answers.

If someone encrypts thirty years of our drawings, what do we actually do on day one?

Isolate, then restore from the backup the attacker could not reach, then decide what to tell the owners whose projects are in the archive. If the backup is offline and was tested last month, day one is a long day; if it sat on the project server, day one is a negotiation, which is why the assessment tests the restore first.

A sub emailed new bank details the week the draw is due. How do we know it is real?

You do not know from the email; you know from a phone call to the sub on the number in the contract, made before any change is entered. That rule, written into the pay-application procedure, is the control that stopped the loss in every version of this story that ended well.

An owner’s security questionnaire asks about our BIM environment and our federal work. Where do we start?

With an inventory of where models and drawings live, who can reach them and how they are backed up, then the controls the questionnaire names: MFA, endpoint detection, encryption and a response plan. If the project is federal, the same inventory becomes the CUI scoping for the CMMC self-assessment.

What you hold, and why someone wants it

Your data protection needs, by the data.

Drawings, models and the project archive

Thirty years of the firm’s work, the owners’ facilities and, on federal projects, CUI. Offline backups, access limits and data classification protect them.

Draws, pay applications and bank details

Progress payments moving by email on a known schedule, the exact path a diverted payment takes. A call-back rule and mailbox MFA protect them.

Project mailboxes and the file-sharing platform

Where the spoofed sub, the fake owner and the ransomware attachment arrive. MFA, forwarding-rule alerts and monitoring protect them.

Bid packages and fee proposals

What a competitor would pay to see the week before a shortlist. Access scoping and monitoring protect them.

Consultant and sub connections

Structural, MEP and civil consultants inside your project folders, and you inside theirs. Vendor review and shared-folder controls protect both.

$3.05B
lost to business email compromise in 2025 across 24,768 complaints, 86% moved by wire or ACH, the exact path a diverted progress payment takes
Source: FBI IC3 2025 Internet Crime Report
31%
of breaches start with an exploited vulnerability; project servers and remote-access tools are the usual door
Source: Verizon 2026 Data Breach Investigations Report
48%
of breaches involve a third party. Your subs, consultants and file-sharing platforms are inside your perimeter
Source: Verizon 2026 Data Breach Investigations Report

What applies to you

The rules, in one page, with the dates that matter.

CMMC 2.0 and DFARS 7012 on DoD projects
US Department of War (DoD)
Facility drawings and specifications are often CUI; Phase 1 self-assessment and SPRS posting apply now despite the Phase 2 pause.
State privacy and breach laws
State attorneys general
Twenty comprehensive privacy laws in 2026 plus universal breach notification; employee and B2B exemptions vary by state.
Owner, GC and insurer requirements
Your clients and carriers
Security questionnaires, cyber-insurance conditions (MFA, EDR, backups) and data clauses in AIA and ConsensusDocs agreements.
ISO 19650 information security expectations
ISO
Information-security practices on BIM-managed projects, increasingly written into large owner contracts.

Verified September 2026 from the regulators' own publications. We map all of it to one control set so evidence is produced once.

A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.

The threat picture

What actually goes wrong, and what we do about it.

  • A spoofed sub or GC email changes banking details the week a draw is due.
  • Drawings and bid packages walking out through a compromised file share or personal cloud.
  • A federal project that requires CMMC Phase 1 attestation the firm has never done.

It happened to businesses like yours

ENGlobal, a US engineering and automation contractor, disclosed that a November 2024 ransomware attack limited access to its business applications for about six weeks and that sensitive personal data was taken.

November 2024 to January 2025 · Infosecurity Magazine

Smiths Group, a UK engineering firm, took systems offline and activated business-continuity plans after a January 2025 cyberattack; rival IMI disclosed its own attack a week later.

January 2025 · SecurityWeek

Public incidents, listed to show the pattern, never to shame a victim.

Protect, for a aec business

We protect your people, every device, the servers and the website. Day and night.

  • We protect every principal, project manager and accounting inbox, where the spoofed sub and the fake pay application arrive.
  • Every workstation and laptop, including the Revit seats and the field tablets.
  • The project server and the file share holding thirty years of drawings and models.
  • The website and the client and consultant portals, including file-sharing links.
  • The cloud apps: BIM collaboration, project management, accounting, email and e-signature.
  • Day and night, with an AI agent that contains a threat in seconds and a named human engineer watching.

Think of it as a per-employee service, like payroll. Except that this is the one corner that, if you cut it, can empty the account and take the business with it. We have your back.

How Protect works →

Where we start

Cybersecurity and Data Protection Assessment for Architecture, Engineering and Construction

Built on the CIS Controls v8.1 IG1 and scoped from what a studio or a contractor stands to lose: the archive, the draw and the federal project. The output is a tested restore, a pay-application rule that holds and, where the work is federal, the CUI scoping that feeds the CMMC self-assessment.

  • Inventory of every workstation, project server, cloud platform and consultant connection, including field devices (CIS Controls 1, 2 and 15)
  • Backup and restore test for the project server, models and the drawing archive (CIS Control 11)
  • Pay-application and bank-change workflow test with the call-back rule written in (CIS Controls 14 and 17)
  • Mailbox security review for principals, project managers and accounting: MFA, forwarding rules, sign-in logs (CIS Controls 5, 6 and 9)
  • Shared-folder and file-sharing review: who outside the firm can reach which project, and for how long (CIS Control 3)
  • Owner questionnaire answers, and CUI scoping for federal projects that feeds the CMMC self-assessment, with a ranked remediation plan
Start with the 3-minute test

Packages

Built for aec businesses, with the price on the page.

Cyber and Data Protection Assessment

A complete read on your exposure: every endpoint, server, cloud account and identity inventoried, controls tested against CIS and NIST CSF 2.0, threats mapped to your industry, and a plan ranked by what would actually hurt.

Fixed feescoped in 30 minutes
1 to 3 weeks
Details →

CMMC Self-Assessment and SPRS Score Calculation

The simplest step a defense supplier can take this quarter: a guided self-assessment against all 110 controls, the DoD scoring methodology applied correctly (1, 3 and 5-point weights, from -203 to 110), the quick wins that move the score most, and a number you can post in SPRS and defend to a prime..

Fixed feescoped in 30 minutes
1 to 2 weeks
Details →

CMMC Level 2 Gap Readiness Package

A fixed-scope package for defense suppliers who need a defensible SPRS score, an SSP a C3PAO will accept and a remediation path that fits a small company.

From $6,000published price
3 to 5 weeks to the delivered gap assessment, SSP and POA&M
Details →

Governance, Risk and Compliance (GRC), simplified

The discipline the largest institutions run, sized for a business that cannot hire a department for it.

Governance, Risk and Compliance is how a bank or a hospital system decides what to protect, proves it is protected, and shows a regulator the evidence. We ran it for those institutions. We now run it for the 30-person supplier, the medical practice and the defense subcontractor, because that is where the supply chain is thinnest and where a breach does the most damage, sometimes to more than one company.

Governance

Who owns security, which policies are real, and what the owner signs. One page, not a binder.

Risk

What could stop the business, ranked by likelihood and cost, refreshed as the threats change, not once a year.

Compliance

The evidence a regulator, a prime contractor or a customer asks for, produced once and kept current every day.

A defense contractor with 40 people is a link in a national supply chain. A breach there is not a small-business story; it is a national-security one. The same is true, at a smaller scale, for the accounting firm that holds 900 client returns and the clinic that holds 12,000 patient records.

Questions owners ask

Straight answers.

We are a 40-person architecture firm. Do we really need this?
A single diverted payment or a lost federal bid costs more than a year of protection. The free check takes five minutes and tells you where you stand; most firms find two or three gaps they can close in a week.
Do CMMC requirements apply to design firms?
When you work on DoD projects and handle CUI such as facility drawings, yes. Phase 1 self-assessment and SPRS scoring apply today. The self-assessment package gets you a defensible score without a consulting army.

People also search: cybersecurity for architecture firms near me · AEC cybersecurity in Chicago · for a 22-person architecture studio · for a structural engineering firm with two offices · construction payment fraud protection · CMMC help for an engineering firm on federal projects · for a general contractor in the suburbs · architecture firm IT security in the Midwest

Never too big or too small

Let's talk about your cyber anxieties. Thirty minutes with an engineer.

3-min test