Cybersecurity for Architecture & Engineering Firms in Canada (2026)

Tags:

Download PDF (628 KB) PDF version, ready to print or share with your team.

Trusted byToronto law firmsHamilton manufacturersVancouver clinicsGTA accounting firmsOntario non-profitsBritish Columbia professional services

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

A 30-person engineering firm in the GTA called us three weeks before a major tender closed. A consultant’s invoice had been paid to a new bank account. The account was not the consultant’s. The email asking for the change came from an existing thread inside a mailbox the attacker already controlled.

The first thing I asked was who else could read that thread. Nobody knew. That 30-person firm did not think of itself as a target. It draws buildings. It also moves large payments and shares files with dozens of outside parties, on deadlines that push people to skip a verification step.

Fusion Computing secures architecture and engineering firms across Canada, so this guide is built from what we actually see. It covers the attacks that hit A&E firms, the CAD decisions that set your risk, the Canadian rules you answer to, plus a 90-day plan.

Key Takeaways

  • A&E firms are squarely in the target set. About 1 in 6 (16%) Canadian businesses were impacted by a cyber incident in 2023 (Statistics Canada).
  • The biggest cash loss is invoice and payment-change fraud, ahead of ransomware.
  • Most of the risk lives in how project files (CAD, Revit, BIM) are stored, synced, and shared. Antivirus is the smaller part.
  • Ontario’s Construction Act names an architect or engineer as a payment certifier and runs on 28-day, 14-day and 7-day clocks that an outage does not pause.
  • Cyber insurance and client security questionnaires now demand MFA, EDR, and tested backups before they pay out or let you bid.

Why would anyone target a firm that just does drawings?

According to Statistics Canada (2024), about 1 in 6 (16%) Canadian businesses were impacted by a cyber security incident in 2023, and national spending on recovery doubled to CA$1.2 billion. Large businesses were actually hit most often, at 30%. Smaller practices are targeted less often and absorb it far worse, because a 12-person studio has no second team to carry the deadline.

The money side is sharper than that rate suggests. The Canadian Centre for Cyber Security reports that, by one estimate, the average ransom paid in Canada in 2023 reached CA$1.130 million, up almost 150% in two years.

Attackers do not pre-screen revenue. They scan for exposed remote access, weak passwords, and leaked credentials. A 12-person studio looks the same as a 500-seat practice to an automated scanner. In our practice, the firms that get hit are rarely the ones that looked interesting.

Book a Consultation

CISSP-led, a Microsoft Solutions Partner, securing Canadian design and engineering practices since 2012.

Two things make A&E firms attractive once an attacker is in. Deadlines create pressure to pay and get back to work. Design files carry resale value, so they can be sold or held for extortion. Modern ransomware copies the data first, then encrypts it: 74% of Q2 2025 cases involved exfiltration.

Data exfiltration in ransomware cases.Donut chart showing 74 percent of ransomware cases in Q2 2025 involved data exfiltration, source Coveware by Veeam.Attackers copy the drawings before locking them.74%of ransomware cases involved data exfiltration (Q2 2025).Source: Coveware by Veeam, 2025 · fusioncomputing.ca
Source: Coveware by Veeam (2025).

The names in the news are not small either. Zaha Hadid Architects and CannonDesign have both disclosed serious attacks. The lesson holds at any size: a firm that moves money and ships valuable files is worth an attacker’s time.

Your real exposure is the project files, not just the laptops

According to IBM (2024), 40% of breaches involved data stored across multiple environments, including on-premise servers, private cloud, and public cloud. Those scattered breaches cost more than US$5 million and took 283 days to identify and contain. For an A&E firm, that scatter is your daily reality: drawings sit on a server, in OneDrive, in a client portal, then in email.

The honest question for most firms is where the big CAD and Revit files should live so they are both safe and fast. I get asked this in the first meeting more than anything else.

An on-premise file server performs well in the office and poorly for site staff unless you add the right access layer. OneDrive and SharePoint sync can corrupt a live Revit central model and quietly drop files. Running that software across a basic VPN tends to damage the model over time.

Speed, safety for active CAD work, then whether the tool counts as a true backup: three separate questions, and the 5 rows below keep them apart.

See where your firm’s CAD files, backups and project sharing are actually exposed with a free 30-minute review →

Where the files live Fast for remote and site staff? Safe for live Revit and CAD? Is it a backup?
On-premise file server Slow without added access. Yes, if maintained. No.
OneDrive or SharePoint sync Mixed. Risky for central models. No.
Autodesk Construction Cloud or BIM Collaborate Yes. Yes, built for it. No.
Hosted desktop in a Canadian data centre Yes. Yes. No.
Versioned off-site backup Not applicable. Not applicable. Yes.

Fusion Computing builds these layers together so the quick option and the safe option are the same option. That is the heart of good IT support for architecture and engineering firms.

What two attacks actually hit architecture and engineering firms?

According to the Verizon 2025 DBIR, ransomware appeared in 88% of breaches at small and medium businesses. That is the headline threat. The quieter and more expensive one for A&E firms is business email compromise: a faked invoice or a changed bank account on a progress payment, timed to land when nobody has a spare minute.

Invoice and payment-change fraud

This is where firms lose the most money. An attacker watches a real email thread, then asks to update payment details right when a draw or a consultant invoice is due. The request reads as routine, and Microsoft 365 delivers it because it comes from a real mailbox.

The control is simple and it works. Any change to a bank account gets a phone call back to a number you already had on file, plus a second person’s approval before payment. Our CISSP-led team sets this rule up with finance in the first week, before anything else.

Ransomware at deadline

Ransomware lands hardest when a submission is due. Project files lock. The team stalls while the clock keeps running, and double extortion adds a second threat to leak the stolen drawings. In Ontario that timing collides with the payment clocks below. Put a number on that lost time with our downtime cost calculator.

How do you secure CAD, Revit and BIM collaboration with consultants and clients?

According to ReliaQuest (2024), credential exposure accounted for 75% of digital-risk alerts in the construction sector over the year to September 2024, driven by heavy reliance on third parties and shared documents. A&E firms share project data with the same wide circle of consultants, contractors and clients, so every shared link is part of your attack surface.

Most firms still share drawings by emailing files or pasting a permanent link. Both are hard to take back, and a subcontractor who rolled off 18 months ago may still hold a working link to the current drawing set.

The fix is structured sharing: role-based access, links that expire, an audit log of who opened what, plus outside collaborators removed the day they roll off. Autodesk Construction Cloud, Newforma, Bluebeam, and Procore all support proper permissions when configured well. Construction firms face the same exposure, covered in our guide to cybersecurity for construction firms.

How to back up CAD and BIM files: the difference between sync and a real backup

According to Sophos (2024), criminals went after the victim’s backups in 94% of ransomware attacks. Of those attempts, 57% succeeded. When backups are hit, the median recovery cost runs eight times higher, US$3 million against US$375,000. Backups decide whether a bad week becomes a closed firm.

Median ransomware recovery cost by backup state.Bar chart comparing 375 thousand dollars recovery cost with intact backups to 3 million dollars when backups are compromised, source Sophos 2024.When backups are hit, recovery costs 8x more.US$375KUS$3MBackups intact.Backups compromised.Source: Sophos, 2024 · fusioncomputing.ca
Source: Sophos (2024).

Three rules, the backbone of the 3-2-1 method, separate a real backup from a false sense of safety. Keep versions, so you can roll back to last week. Keep one copy off-site and out of reach of the network. Test a restore on a schedule, because an untested backup is a guess.

Worried a faked invoice could slip through near a deadline? Have us set up payment-change verification this week →

Why Canadian firms bring this work to Fusion Computing.

CISSP-led, a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder, securing IT for Canadian SMBs across Toronto, Hamilton, and Metro Vancouver since 2012.

Backup approach Recovers a dead drive? Recovers from ransomware? Recovers last week’s file?
Folder sync to OneDrive Yes. No, encryption syncs. Sometimes.
One external hard drive Yes. No, often on the network. No.
Versioned cloud backup Yes. Yes, if tested. Yes.
Immutable plus offline copy Yes. Yes. Yes.

Fusion Computing pairs versioned, immutable backups with managed detection and response on the design workstations, so an attack is caught early and the recovery path is proven. I test restores on a schedule for exactly this reason.

Find out whether your backups would survive ransomware before you have to test them live →

SECURING CANADIAN FIRMS SINCE 2012.

CISSP-led  •  Microsoft Solutions Partner  •  CompTIA Managed Services Trustmark  •  50 Best Managed IT Companies (2024).

Why your professional seal is now a cyber asset

Under Ontario’s engineering regulation (O. Reg. 941, s.53), a practitioner must sign, date, and affix their seal to any engineering document whose content they prepared or take responsibility for, in paper or electronic form. Section 53(3)(b) permits an electronic image of that seal, and requires the image to carry the practitioner’s licence number.

That last requirement is the part firms miss. A seal image lifted from a PDF carries a real licence number, so a stolen seal is a working credential tied to a named practitioner on the Ontario register rather than a graphic. I have yet to meet a design firm that treats the seal file the way it treats a password.

Section 53(4) adds that the signature and date must be applied at the same time as the seal or immediately after. That is a workflow requirement, and workflows are what business email compromise attacks. An attacker inside a mailbox can swap a sealed PDF in transit, sending a different stamped drawing than the one your engineer signed.

Three steps close it. Keep the seal credential behind MFA and a hardware security key in Entra ID. Apply seals only from a hardened, monitored workstation. Confirm every transmittal through a channel the recipient can trust.

The Canadian rules and insurer requirements your firm needs to meet

Under PIPEDA (Justice Laws), section 10.1(1) requires you to report any breach creating a real risk of significant harm. Section 10.3(1) requires a record of every breach, and the Breach of Security Safeguards Regulations set that record at 24 months. Section 28 makes knowingly skipping either duty an offence carrying up to CA$100,000 on indictment.

Your professional obligations layer on top. Ontario’s engineering code requires practitioners to treat client information as confidential. The Ontario Association of Architects gives no single retention period; depending on the document, records may need to be kept seven years, fifteen years, or longer. Quebec firms also answer to Law 25, Alberta firms to PIPA.

The payment clock nobody counts as a security risk

Ontario’s Construction Act defines a “payment certifier” as an architect, engineer, or other person on whose certificate payments are made. That places your firm inside the prompt-payment chain, and the chain runs on fixed days that no outage pauses.

Section 6.4(1) gives an owner 28 days to pay a proper invoice, and section 6.4(2) gives that owner only 14 days to serve a notice of non-payment if it disputes one. Once your firm is paid, section 6.5(1) gives you seven days to pay your sub-consultants. The 2024 amendments came into force on January 1, 2026.

Seven days is shorter than most ransomware recoveries, and section 6.5(1) does not pause for one. A notice of non-payment is a dated document served in a prescribed form, and you cannot produce one from an encrypted network. That is the clock I point at when a design firm asks how long an outage it can actually survive.

Insurance has become the sharper forcing function. The City of Hamilton (Global News, 2025) had a cyber-insurance claim denied because multi-factor authentication was not fully implemented, leaving a CA$18.3 million bill. I have watched a renewal turn on that single control.

“According to the city’s insurance policy, no coverage was available for any losses where the absence of multi-factor authentication was the root cause.”

Global News, on the City of Hamilton cyberattack, 2025.

Client security questionnaires do the same on the sales side. Bids for government and large-enterprise work increasingly ask for ISO 27001 or NIST 800-171 controls. Meeting those Canadian IT compliance expectations is now part of winning the project.

What mistakes do we see in the field at architecture and engineering firms?

Across the architecture and engineering firms Fusion Computing manages, most of our clients arrive with two or three of these controls missing. Our engineers see the same short list from firm to firm, which is good news, because the fixes repeat too.

The first is a generic IT provider that does not understand Revit central files, xrefs, or data shortcuts, and breaks the model trying to help. The gap I see most often is offboarding that never happens. The third is shared logins, permanent share links, plus backups nobody has ever test-restored.

What does a 90-day hardening plan look like for an A&E firm?

A small firm does not need an enterprise stack. It needs a focused one, built in the right order. I run this 90-day plan with architecture and engineering clients, and it maps directly to what insurers and client questionnaires now ask for.

  • Days 1 to 30, the basics that stop most attacks: multi-factor sign-in everywhere, EDR on every design workstation, offboarding that cuts access on the last day.
  • Days 31 to 60, protect the work: tested versioned backups, a file architecture that is fast and safe for site staff, dual approval on every payment-detail change.
  • Days 61 to 90, qualify and recover: insurance and questionnaire readiness, protection for the seal and signing workflow, a short written incident-response plan.

Use a third-party rubric to check the result. The 13 CCCS Baseline Cyber Security Controls are the right yardstick for your own firm, scoped by control OC.1 to organizations under 499 employees. If you are still choosing who runs the plan, our buyer’s comparison of IT providers for A&E firms scores six provider types against the CCCS ITSM.50.030 due-diligence rubric.

Where should you start?

You do not have to do all of this at once. If I had to pick one control for a design firm to finish this week, I would take multi-factor sign-in on Microsoft 365 email. It shuts the door on the invoice fraud that costs the most.

Fusion Computing helps Canadian businesses across Toronto and the GTA, Hamilton, and Metro Vancouver with managed IT, cybersecurity, and Microsoft 365.

Frequently Asked Questions

Why would hackers target a small architecture or engineering firm?

Attackers scan for weak access and leaked passwords, so they reach a 12-person studio the same way they reach a large practice. A&E firms move large project payments and hold valuable design files, which makes them worth the effort once inside. About 1 in 6 (16%) Canadian businesses were impacted by a cyber incident in 2023 (Statistics Canada).

Is it safe to store Revit, AutoCAD and Civil 3D files in OneDrive or SharePoint?

Use them for documents, not live Revit or CAD central models, because their sync can corrupt a worksharing model and drop files. For active project work use a common data environment such as Autodesk Construction Cloud, or a hosted desktop in Canada. Cloud storage is not a backup, and 94% of ransomware attacks go after backups (Sophos, 2024).

How should an architecture or engineering firm back up CAD and BIM files?

Keep versions so you can roll back to last week. Keep one copy off-site and off the network, then test a restore on a schedule. Sync alone fails, because ransomware encrypts the synced copy too. When backups are compromised, the median recovery cost runs eight times higher, US$3 million against US$375,000 (Sophos, 2024).

How do we share large drawing sets with consultants and clients securely?

Share through a project platform with role-based access, expiring links, and an audit log, rather than emailing files or sending a permanent link. Remove outside collaborators the day they roll off. Credential exposure drove 75% of digital-risk alerts in construction, a sector that shares files the way design firms do (ReliaQuest, 2024).

How do we prevent fake-invoice and payment-change fraud?

Require a callback to a number you already had on file, plus a second approver, before any bank-account change is paid. Business email compromise is the costliest attack on A&E firms, because a payment-detail change reads as routine near a 28-day payment deadline. Two approvers and one phone call is the whole control.

Does Ontario’s Construction Act create a cyber risk for architects and engineers?

It creates a timing risk. The Act names an architect or engineer as a payment certifier, and its prompt-payment clocks run through an outage. An owner has 28 days to pay a proper invoice and 14 days to serve a notice of non-payment. A contractor has seven days to pay sub-consultants. The 2024 amendments took effect January 1, 2026.

If client data is breached, what are our reporting duties under PIPEDA?

Section 10.1(1) requires you to report any breach creating a real risk of significant harm and to notify affected people. Section 10.3(1) requires a record of every breach, kept 24 months. Knowingly skipping either duty is an offence carrying a fine up to CA$100,000 on indictment. You stay accountable even when the data sits with a cloud provider.

Does our firm need cyber insurance, and what controls do insurers require?

Most insurers now require multi-factor authentication, endpoint detection and response, and tested backups before they issue or renew a policy, and they deny claims when those controls are missing. The City of Hamilton lost a CA$18.3 million claim because MFA was not fully implemented (Global News, 2025). Put the controls in first.

Written by Mike Pearlstein, CISSP. Fusion Computing is a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder, securing Canadian design and engineering practices since 2012.

Ready to close these gaps before your next deadline? Talk to Fusion Computing →

Tell us your biggest headache across IT, security, or AI. We’ll let you know if we’re a fit.Get in Touch

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 10 to 150 employees across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611