Ask an architect whether their firm would interest a cybercriminal and the answer is usually a puzzled no. We don’t handle money. We’re not a bank. We draw buildings.
That assumption is exactly why design firms are more exposed than they think. What sits on a Placerville architecture practice’s server — often not thought of as “data” at all — is a detailed record of how buildings are constructed, secured, and accessed, alongside the financial and personal information of every client the firm has ever had.
That’s genuinely valuable, and the people who look for such things know it even when the firms holding it don’t.
What’s actually on your server
Consider an ordinary Tuesday’s worth of files.
Years of drawings and detail libraries — the accumulated work that lets a small firm compete, existing in exactly one place. Active project files, where losing access stops not one project but all of them at once. Client contracts, fee arrangements, and correspondence covering matters people would prefer stayed private.
And on projects involving schools, healthcare, government, or commercial buildings: security system layouts, access control details, server room locations, and structural information. That has obvious value to someone whose interest is the building rather than your firm — a category of exposure most practices have never considered.
How firms actually get hit
Not the dramatic technical breach of the popular imagination. Something more ordinary.
It starts with an email that looks reasonable — a consultant sharing a model, a client sending revisions, a supplier with an invoice. The link leads to a convincing replica of a Microsoft 365 login, and someone signs in during a busy afternoon. Nothing visible happens.
Then the attacker reads, quietly, for weeks — learning how the practice communicates, which projects involve payments, who approves what. Eventually either a fraudulent payment request arrives from a genuine address, or, having located the file storage and backups, they trigger ransomware over a weekend.
The consultant angle makes this harder to spot. Firms exchange files constantly with structural engineers, MEP consultants, and surveyors, and a compromise at any one of them produces messages that genuinely come from someone you work with, in a thread already running. Nothing about them looks wrong, because technically nothing is.
The controls that stop most of it
The reassuring part: the overwhelming majority of successful attacks exploit a small number of gaps, and closing them isn’t exotic or expensive.
- Multi-factor authentication on every account, principals included — it stops the large majority of break-ins, and the exemptions firms grant for convenience are exactly what attackers hunt for.
- Email threat filtering, removing most malicious messages before anyone has to judge them at five on a Friday.
- Endpoint detection and response, watching for suspicious behaviour rather than known threats — how ransomware gets caught during the weeks before it triggers.
- Verified, off-network backups, because ransomware hunts connected backup storage and a firm that can restore doesn’t pay.
- Controlled consultant file transfer, replacing the personal Dropbox and USB improvisation that moves project data outside any control you have.
- A payment verification rule — free, and it stops the attack most likely to take real money.
Our cybersecurity services run these as one coordinated layer, and managed IT keeps them maintained, because coverage drifts as tools and staff change.
On being a small foothill practice
A six- or eight-person firm in Placerville is not too small to be attacked. Most attacks are automated — scanning broadly, following whatever responds — and lighter defences make a small practice a more useful result, not an ignored one.
The advantage is that fixing this is fast. Enforcing MFA across eight accounts is an afternoon. A payment rule is one conversation. There’s no committee, no approval cycle. The obstacle was never budget — it’s that nobody’s job included thinking about it, and specialist support has historically been thin in the foothills. Both are solvable.
Where to start
Two questions this week. Ask for a report showing MFA coverage across every account and system — a report, not a reassurance, with attention to anything adopted recently. And ask for the date of the last actual restore test, plus whether ransomware on your network could reach the backup.
Those answers locate most of your exposure. If both are reassuring, you’re ahead of most practices. If either hesitates, you’ve found the highest-value fix — and it’s cheaper than you expect.
Send us a message describing your setup and we’ll tell you straight what’s likely missing and what closing it involves. We’ll also tell you if you’re in good shape. Call 209-920-4077 or write to us here.