Here’s a statistic from our recent webinar that may come as a surprise: roughly 90% of security failures happen on the phone.
Not through exotic zero-day exploits or nation-state hacking tools. Through a phone call, a text, or a convincing email that asks someone to do something they shouldn’t.
Social engineering, the process of tricking people into granting access or sharing credentials, is the main entry point for attacks on firms of all sizes. In the AEC industry, where staff are trained to be responsive, collaborative, and client-focused, the cultural instinct to be helpful is exactly what attackers exploit.
When an attacker calls posing as IT support, a vendor, or a client with an urgent request, they create urgency. They know how to exploit trust. Then, a busy project manager or administrative staff member, juggling deadlines, thinks they’re doing a helpful thing by clicking the link, sharing the code, and approving access.
While you may think your most important security control is a firewall, it’s actually a workforce that knows how to recognize and refuse social engineering attempts. That requires:
Security spending often gets framed as a cost center. Money spent against a risk that might never materialize. But you invest in insurance because if something did happen and you didn’t have insurance to cover it, the costs would be astronomical.
The average cost of recovering from a ransomware incident is $1.53 million, and if you add ransom in, you can add an additional $1 million to that number.
Now, compare that to the cost of a meaningful security program that includes training, monitoring, backups, incident response planning, and managed detection and response. Even a robust program is a fraction of the recovery cost of a single serious incident.
This is the calculation AEC leaders should be making. It’s not “how much does security cost?” It’s “how much does not having it cost, and can the firm absorb that number?”
For many firms, the honest answer is no. A single serious incident can wipe out a year of profitability and put years of client relationships at risk. Prevention isn’t an expense. It’s insurance against a near-certain event.
If your firm has been putting off cybersecurity, here is where you can start:
These seven steps won’t make your firm invulnerable. But they move you from findable and exploitable to hardened and prepared, and that difference is what determines whether an incident is a crisis or a manageable event.
Cybersecurity in AEC is no longer optional, and it’s no longer just IT’s job. Firms need to treat it as a core business discipline alongside project quality, financial management, and client service. The question is no longer whether your firm will face an attack. It’s whether you’ll be ready.
If you’re looking for an honest assessment, NetCov is trusted by 100’s of AEC firms. Contact us to schedule your assessment today.