Most architecture and engineering firm owners don’t want a technology conversation. They want to know whether anything is quietly going wrong.
This is a way to find out in about ten minutes, without needing a technical background.
Eight questions. Ask whoever manages your IT — an internal person, an outside provider, or the staff member who ended up handling it. For each one, there’s a clear answer that indicates things are in order, and a vague answer that indicates they probably aren’t.
Keep score as you go. There’s a way to read the result at the end.
Question 1: How fast does a large model open — and has anyone measured it?
Good answers sound like:
- A specific number, in seconds, measured recently
- “We track performance trends and here’s what they show over the last six months”
- “We tested it at 8am and at 11am and the difference was minimal”
Concerning answers sound like:
- “It’s about as fast as you’d expect”
- “Nobody’s complained recently”
- “That software is just slow”
Why it matters: Without measurement, nobody can say whether performance has degraded, by how much, or where the bottleneck actually sits. Firms routinely spend on new workstations when the constraint was storage — and see almost no improvement.
Question 2: When did we last restore from backup — what date?
Good answers sound like:
- A specific date within the last three months
- We test quarterly and here’s the report from the last one”
- We restored a full server, not just a file, and it took ninety minutes”
Concerning answers sound like:
- Backups run every night”
- The log shows they’re completing successfully”
- We restored a file for someone a while back”
Why it matters: A backup job reporting success confirms only that the job ran. Corrupted data backs up perfectly well. The gap between “backups run” and “recovery has been verified” is where firms lose weeks.
Question 3: Could ransomware on our network reach our backups?
Good answers sound like:
- No — copies are replicated off-site and aren’t reachable from the office network
- We keep multiple recovery points going back several weeks
Concerning answers sound like:
- The backup drive is in the server room”
- It’s on the network so it’s easy to access”
- I’d have to check”
Why it matters: Modern ransomware specifically hunts for connected backup storage, because attackers know a firm with working backups doesn’t pay. A backup reachable from an infected machine is a target, not a safety net.
Question 4: Is MFA enforced on every account, with no exceptions?
Good answers sound like:
- Yes — every account, including principals, on email and remote access”
- We can produce a report showing coverage”
Concerning answers sound like:
- It’s turned on for most people”
- The partners found it inconvenient so they’re exempt”
- It’s available if people want it”
Why it matters: Stolen credentials remain the most common way attackers get in, and MFA stops the large majority of those attempts. Exceptions are precisely what attackers look for — and exempted accounts usually have the broadest access.
Question 5: Who is watching our systems, and what happens when something looks wrong?
Good answers sound like:
- Everything is monitored continuously and alerts go to a team that acts on them”
- We caught a failing drive last month before anyone noticed”
Concerning answers sound like:
- “Staff let us know when something’s not working”
- “We check things periodically”
- “We’d find out pretty quickly”
Why it matters: Reactive support means every problem reaches your team before it reaches anyone technical. Monitoring is also the only thing that catches an intruder during the weeks they spend inside a network before triggering anything.
Question 6: If someone can’t work at 3pm on a deadline day, how fast do we get help?
Good answers sound like:
- Within minutes, and most issues are resolved remotely on the same call”
- “Here’s our average response time from last quarter”
Concerning answers sound like:
- “We leave a message and they usually get back to us”
- “Depends how busy they are”
- “Someone comes out, usually within a day or two”
Why it matters: The difference between a firm that loses twenty minutes and one that loses a day is response time. In a deadline-driven business, this is one of the highest-value differences available.
Question 7: How do consultants send and receive project files?
Good answers sound like:
- “Through a secure system we control, with a record of what was shared”
- Access is granted per project and removed when it ends”
Concerning answers sound like:
- “Whatever works — Dropbox, WeTransfer, sometimes a USB drive”
- “People use their personal accounts”
- “I’m not entirely sure”
Why it matters: Improvised file transfer moves project data outside any control the firm has, leaves no audit trail, and frequently means active access sitting in personal accounts long after a project closed.
Question 8: Could we complete a cyber insurance application honestly today?
Good answers sound like:
- Yes — MFA, monitoring, endpoint protection and tested backups are all documented”
- We reviewed the application against what we actually have”
Concerning answers sound like:
- “We’d tick the boxes and hope”
- “Someone filled that in last year, I’m not sure what they said”
Why it matters: The application is a legal document. Claims have been reduced or denied where a firm attested to controls it didn’t have. Increasingly, clients ask similar questions before engagement — and being unable to answer removes you from consideration entirely.

Reading your score
Count how many questions received a clear, specific answer.
Score — What it indicates
7–8 — Well managed. Worth confirming the evidence exists in writing, but the fundamentals are in place.
4–6 — Typical for a growing firm. Nothing alarming, but there are specific gaps worth closing deliberately rather than discovering later.
0–3 — The firm is running on assumptions. Not unusual, and not a reflection on anyone — but the exposure is real and worth addressing.
Most firms we assess land in the middle band. That’s the normal result of a practice growing faster than the infrastructure supporting it, which is what happens when things go well.
Which gaps to close first
If several answers were vague, these are worth addressing in this order:
1. MFA everywhere. Cheapest, fastest, and prevents the largest share of incidents.
2. Verified off-site backups. Determines what happens on your worst day.
3. Continuous monitoring. Turns invisible problems into early warnings.
4. Response time. Directly recovers billable hours.
5. Performance measurement. Prevents money being spent on the wrong constraint.
6. Secure file sharing. Closes an exposure most firms don’t know they have.
The first three address risk. The next two address cost. All five are usually less expensive than firms anticipate, particularly compared with what they’re already losing to the problems they’ve accepted.
A note on how firms end up here
None of this reflects poorly on the firms involved.
A&E practices in El Dorado Hills typically grew steadily and capably without building an IT function. Technology was handled by whoever was most comfortable with it, supplemented by a vendor called when something broke. That arrangement handles printers and password resets perfectly well.
What it doesn’t do is maintain a security posture, measure performance, or notice a problem developing quietly. Not because anyone failed — because it was never the arrangement’s job.
Four more questions — this time for a prospective IT provider
If the exercise above suggests you need different support, these are worth asking any provider you’re considering. The answers separate genuine managed services from break-fix work with a monthly invoice attached.
“What do you monitor, and what do you do when an alert fires?”
Look for specifics: which devices, which metrics, who receives the alert, and what action follows. Vague answers about “keeping an eye on things” usually mean nobody is watching outside business hours.
“How often do you test our backups, and what will you send me afterward?”
The correct answer includes a frequency and a deliverable. If testing produces nothing you can read, it either isn’t happening or isn’t being recorded — and for insurance and client questionnaires, an untested backup and an undocumented test are equally unhelpful.
“What’s included in the monthly cost, and what gets billed separately?”
Ask directly about after-hours work, onsite visits, project work, and onboarding new staff. The value of predictable pricing disappears if the predictable part covers only routine tickets.
“Who actually answers when we call at 3pm on a Thursday?”
Ask about response targets and whether they can produce last quarter’s actual figures. A provider measuring their own response times will have the number available. One that doesn’t measure will explain why measurement is difficult.
When to run this exercise again
Once is useful. Repeating it is what keeps the answers accurate, because environments drift.
Worth revisiting:
Annually, as a baseline habit
- After adding three or four staff, when the arrangements that fitted a smaller team start to strain
- Before a cyber insurance renewal, so the application reflects reality
- When a client sends a security questionnaire, which tends to expose gaps quickly
- After any staff departure involving the informal technology contact, which reveals how much was undocumented
- When a major project changes the shape of your file storage or consultant coordination
Each of these is a point where something that was true last year quietly stopped being true.
Where to go from here
If this exercise produced more uncertainty than answers, that’s useful information rather than bad news. Every gap identified above is closable, usually within weeks.
RJ PRO Tech Group provides managed IT, cybersecurity, and backup and disaster recovery for architecture and engineering firms across El Dorado County — with a Help Desk that answers in minutes rather than days.
Schedule a complimentary IT assessment for your El Dorado Hills firm