
Ask most architects whether their firm would interest an attacker and the answer is usually no. We don’t handle money, the reasoning goes. We’re not a bank or a hospital. We draw buildings.
It’s an understandable assumption, and it’s the reason design firms are more exposed than they realize. What a Sacramento architecture practice actually holds — often without thinking of it as data at all — is a detailed record of how buildings are constructed, secured, and accessed, alongside the financial and personal information of every client who has ever engaged the firm.
That combination is genuinely valuable, and the people who look for such things are aware of it even when the firms holding it are not.
What a design firm actually holds
Consider what sits on a typical practice’s server on an ordinary Tuesday.
There are the models and drawing sets, representing years of accumulated work and the firm’s competitive position. There are the specifications and details that describe how a building is put together. On projects involving schools, healthcare facilities, government buildings, or commercial properties, there are frequently drawings showing security systems, server room locations, access control, and structural vulnerabilities — information that has obvious value to someone planning to target that building rather than the firm.
Alongside all of that sits the ordinary business material: client contact details, contracts, fee proposals, financial arrangements, and correspondence covering matters clients would prefer stayed private.
None of this is stored with the assumption that it might be stolen. It’s stored so people can work.
The attacks that actually reach design firms
The popular image of a hacker breaking through defenses bears very little resemblance to how firms are actually compromised. The reality is more ordinary, which is also what makes it preventable.
Nearly everything begins with email. Someone receives a message that looks entirely reasonable — a consultant sharing a model, a client sending a revised programme, a supplier with an invoice. The link goes to a page that replicates a Microsoft 365 login perfectly, and someone enters their password without a second thought. Nothing visible happens afterward, which is precisely the point.
What follows is patient. The attacker reads the mailbox, learns how the firm communicates, identifies which projects involve significant payments, and works out who authorizes what. Some set up quiet mail rules so their activity remains hidden from the account’s actual owner. Weeks later, at a well-chosen moment, they send a message from that legitimate address requesting a change to payment details, or attach something to a conversation that is already underway and therefore trusted.
Ransomware often arrives through the same door. Once inside, an attacker maps the network, locates the model storage and the backup system, and triggers encryption over a weekend when nobody is watching. For an architecture firm this is particularly damaging, because every active project stops simultaneously. The deadline for one project might be flexible. All of them at once is not.
There is also a quieter category worth mentioning. Consultant and client relationships mean project files move constantly between organizations, and a compromise at any one of them produces messages that genuinely originate from a real person the firm knows and trusts. Nothing about such a message looks wrong, because in every technical sense it isn’t.
Why Sacramento firms warrant particular attention
The regional context matters here more than it might elsewhere.
Sacramento practices work regularly with state agencies, public institutions, healthcare organizations, and educational facilities. Public sector work brings requirements that private commercial work often doesn’t, and clients in these categories increasingly ask their design consultants how project information is protected — sometimes as part of the procurement process rather than as an afterthought.
That shift is worth noticing, because it changes the nature of the investment. Security stops being purely defensive and becomes something a firm may need to demonstrate in order to win work. A practice that can answer clearly is in a different position from one that has never considered the question.
The controls that prevent most of this
The reassuring part of all this is that the overwhelming majority of successful attacks exploit a small number of gaps, and closing them is neither exotic nor especially expensive.
Multi-Factor Authentication matters more than anything else on the list. Because stolen credentials remain the most common entry point, requiring a second factor stops the large majority of attempts before they begin. It needs to apply to every account without exception — principals included, since those accounts hold the broadest access and their messages carry the most authority.
Email threat filtering removes a substantial proportion of malicious messages before anyone has to exercise judgment about them at five o’clock on a Friday. It won’t catch everything, particularly a message written specifically for your firm, but it dramatically reduces how often anyone’s judgment is tested.
Endpoint detection and response addresses what traditional antivirus cannot. Antivirus recognizes threats it already knows about. EDR watches for suspicious behavior, which is how ransomware gets caught during the mapping phase — after an attacker is inside but before encryption begins. That window is the best opportunity to stop an attack, and it’s invisible to a firm without monitoring.
Controlled file transfer solves a problem most practices don’t recognize as one. Large models don’t fit in email, so people improvise with personal Dropbox accounts, free transfer services, and USB drives handed over at site meetings. Each of these moves project data outside any control the firm has, leaves no record of what was shared with whom, and frequently means access sitting in someone’s personal account long after a project closed. A proper solution is also faster than the improvisation it replaces, which is usually what persuades people to adopt it.
Verified backups determine what happens on the worst day. A backup that has never been restored is an assumption rather than protection, and ransomware specifically hunts for connected backup storage because attackers know a firm with working backups doesn’t pay. Copies need to live somewhere an attacker on your network cannot reach, with enough recovery points to go back past the date an infection began. Our backup and disaster recovery service is built around exactly that principle.
Finally, and least technically, a verification habit around payments prevents most financial losses. Any change to banking or payment instructions confirmed by phone, using a number already on file rather than one supplied in the email requesting the change. This costs nothing and stops the attack that takes the most money from firms of this size.
Our cybersecurity services implement these as a single coordinated layer rather than a collection of separate products, and our managed IT services keep them monitored and current — which matters, because a control nobody is watching drifts out of effectiveness within months.

What we typically find
Assessments across architecture practices tend to surface the same handful of things. MFA is usually enabled for some people rather than enforced for everyone, and frequently not on the accounts with the broadest access. Backups have been running successfully for years without anyone attempting a restore. Patch compliance sits somewhere between 55% and 70%, with third-party applications lagging furthest behind. Consultant file transfer happens through personal accounts nobody has visibility into. And there is generally no written plan for what happens if something goes wrong, meaning the first decisions get made under pressure.
None of this reflects poorly on the firms involved. It reflects a practice that grew while nobody’s job description included security, which is the normal situation for a business that has been busy doing good work.
The insurance conversation has changed
Something worth knowing before your next renewal comes around.
Cyber insurance used to be relatively simple to obtain. An application, a signature, a premium. That is no longer the case, and the shift has been rapid enough that many firms haven’t encountered it yet.
Insurers now require evidence of specific controls before issuing or renewing coverage. Multi-Factor Authentication appears on virtually every application. So do questions about backup testing, endpoint protection, and whether systems are monitored. The questions are specific because insurers have learned which controls actually correlate with claims.
The part that catches firms out is that the application is a legal document. Claims have been reduced or denied where a business attested to controls it didn’t actually have in place — sometimes because whoever completed the form ticked a box based on a reasonable assumption nobody had verified. A principal signing that application is making a statement on behalf of the firm, and it’s worth being confident the statement is accurate.
The practical implication is straightforward enough. Reviewing the application against what your firm genuinely has, before signing it, is an hour well spent. If the review reveals gaps, closing them is almost always cheaper than the coverage problem they would otherwise create.
Smaller practices aren’t exempt
There’s a persistent belief that attackers focus on larger organizations, and it’s worth addressing directly because it leads firms to postpone decisions they’d otherwise make.
Most attacks aren’t chosen. They’re automated. Attackers scan broadly for exposed systems and send phishing in enormous volume, then direct attention wherever something responds. Being a six-person studio doesn’t make you invisible to that process — it frequently makes you an easier result, because defenses tend to be lighter and there is rarely anyone watching.
The advantage a smaller practice has is that most of what matters can be implemented quickly. Enforcing MFA across eight accounts is an afternoon’s work. Establishing a payment verification habit across a small team is a single conversation that everyone actually remembers. Getting backups tested and replicated off-site is a straightforward project.
What smaller firms lack isn’t budget so much as someone whose job includes thinking about any of this. That’s the real gap, and it’s the one worth closing.
Where to start
If this has raised more uncertainty than it resolved, that’s useful rather than alarming. The gaps described here are closable, generally within weeks, and usually less expensive than firms anticipate.
The sensible order is straightforward. Enforce MFA everywhere first, because it prevents the largest share of incidents for the least cost. Then confirm that backups can actually be restored and that they sit somewhere ransomware cannot reach. Then put monitoring in place, so problems become early warnings rather than discoveries. Everything else follows more easily once those three are settled.
RJ PRO Tech Group works with Sacramento architecture firms to protect the work that represents years of effort — with a Help Desk that answers in minutes when something needs attention.
Schedule a complimentary IT assessment for your Sacramento architecture firm