NetCov Resources

How to Defend Your AEC Firm Before the Next Attack

Written by Jen Anthony | Aug 5, 2026, 2:27:55 PM

Your Staff Is Your Biggest Risk and Your Best Defense

Here’s a statistic from our recent webinar that may come as a surprise: roughly 90% of security failures happen on the phone.

Not through exotic zero-day exploits or nation-state hacking tools. Through a phone call, a text, or a convincing email that asks someone to do something they shouldn’t.

Social engineering, the process of tricking people into granting access or sharing credentials, is the main entry point for attacks on firms of all sizes. In the AEC industry, where staff are trained to be responsive, collaborative, and client-focused, the cultural instinct to be helpful is exactly what attackers exploit.

When an attacker calls posing as IT support, a vendor, or a client with an urgent request, they create urgency. They know how to exploit trust. Then, a busy project manager or administrative staff member, juggling deadlines, thinks they’re doing a helpful thing by clicking the link, sharing the code, and approving access.

While you may think your most important security control is a firewall, it’s actually a workforce that knows how to recognize and refuse social engineering attempts. That requires:

  • Regular, realistic training: Not annual click-through compliance modules, but practice with actual phishing and vishing scenarios
  • A no-blame culture: If someone suspects they made a mistake, they need to feel safe reporting it immediately, not hiding it
  • Clear verification procedures: Staff should know exactly how to confirm any request for access, credentials, or payment changes
  • Leadership modeling: When partners and principals take training seriously, the rest of the firm follows
  • Your people are the front line: Invest in training and a no-blame reporting culture. This is your highest-leverage security spend.
  • Do the math: Prevention is a fraction of the cost of recovery. Frame security as risk management, not overhead.
  • Start with 90 days: The seven-step plan above is achievable for any firm willing to commit a quarter to it.

Why Prevention Pays

Security spending often gets framed as a cost center. Money spent against a risk that might never materialize. But you invest in insurance because if something did happen and you didn’t have insurance to cover it, the costs would be astronomical.

The average cost of recovering from a ransomware incident is $1.53 million, and if you add ransom in, you can add an additional $1 million to that number.

Now, compare that to the cost of a meaningful security program that includes training, monitoring, backups, incident response planning, and managed detection and response. Even a robust program is a fraction of the recovery cost of a single serious incident.

This is the calculation AEC leaders should be making. It’s not “how much does security cost?” It’s “how much does not having it cost, and can the firm absorb that number?”

For many firms, the honest answer is no. A single serious incident can wipe out a year of profitability and put years of client relationships at risk. Prevention isn’t an expense. It’s insurance against a near-certain event.

A 90-Day Action Plan for AEC Firms

If your firm has been putting off cybersecurity, here is where you can start:

Days 1–30: Understand and Assess

  • Get an honest risk assessment. Identify your most valuable assets, your biggest vulnerabilities, and your current exposure. This is the baseline.
  • Inventory your access points. Remote access, vendor connections, cloud services, and collaboration tools. You need to know every door into your firm.
  • Locate and test your backups. A backup you’ve never restored from is a hope, not a plan. Test recovery before you need it.

Days 31–60: Train and Protect

  • Launch realistic security awareness training. Focus on social engineering — phishing, vishing, and the phone-based attacks that cause 90% of failures. Make it ongoing, not annual.
  • Implement multi-factor authentication everywhere. Especially on email, remote access, and any system holding client or project data. This single step blocks a large share of attacks.
  • Establish a clear verification procedure. Every request for payment changes, credentials, or access must follow a defined confirmation process that includes no exceptions or urgency overrides.

Days 61–90: Plan and Partner

  • Build an incident response plan. Define roles, decision authority, communication protocols, and a contact list for legal, insurance, and forensic support. Then tabletop it. Run a simulated scenario with your leadership team so the plan is tested before it’s real.

These seven steps won’t make your firm invulnerable. But they move you from findable and exploitable to hardened and prepared, and that difference is what determines whether an incident is a crisis or a manageable event.

The Important Takeaways

Cybersecurity in AEC is no longer optional, and it’s no longer just IT’s job. Firms need to treat it as a core business discipline alongside project quality, financial management, and client service. The question is no longer whether your firm will face an attack. It’s whether you’ll be ready.

If you’re looking for an honest assessment, NetCov is trusted by 100’s of AEC firms. Contact us to schedule your assessment today.