Engineering Inc - July/August 2019 - 24

Cyberattacks can be especially devastating for small and midsized businesses, which may lack the resources to bounce back after
a large financial or data loss. "Most engineering firms are small or
midmarket firms," Nelson says. "So that really hits home." 
One of the most pressing cyber dangers facing engineering firms
is ransomware-malicious software that locks down access to
corporate data until a company pays a "ransom" to the hackers.
"We work on extremely large proposals, and their cost of preparation can be in the hundreds of thousands of dollars. A ransomware
attack that locked down the proposal documents immediately
before submission would present a significant risk," says John Buchheit, senior vice president and corporate risk officer
at Gannett Fleming, and chair of ACEC's Risk
Management Committee. "If we had a proposal
due today at 4 p.m., and hackers locked down the
proposal with ransomware, there would be more at
stake in not meeting that deadline than in paying
the ransom."
According to Buchheit, Gannett Fleming has
experienced one minor ransomware incident that
seized control of a single workstation, but files were
restored from a backup server.
Social engineering attacks such as phishing or
spear phishing are also prevalent-and potentially
costly. "Phishing" occurs when an attacker attempts
to trick targets into entering credentials such as
usernames and passwords via a phony link; "spear
phishing" attacks are similar but use personalization-such as the spoofing of a boss's or colleague's
email address-to fool victims.
Nelson says that an employee at his firm was nearly tricked
by an email that appeared to be from a manager, instructing the
employee to purchase gift cards for a fundraiser and then share the
codes on the cards. The scam was only caught because the company requires multiple people to sign off on such expenditures.
"We have even had attempts where attackers have
mimicked the writing style of our CEO," Nelson says.
"The level of sophistication of the phishing attacks is really
mind-blowing."

Engineering firms must put in place
cybersecurity tools such as firewalls,
endpoint security solutions, and identity
and access management tools. But processes are also important. For instance,
a policy requiring callback verification
for any changes to payment information
can prevent firms from disbursing funds
to fraudsters. And a policy requiring
employees to change their passwords
"We look at
at set intervals can limit the amount
of time that hackers the data from
are able to leverage
the attempts
stolen credentials.
"Cybersecurity
on our servers,
plans need to be
and there are
quite comprehensive," says Andrew
an awful lot of
Mendelson, chief
attempts on
risk management
officer of the proa daily basis.
fessional liability
I believe it is
insurance company
Berkley Design
happening to
Professional, and
everybody in
an ACEC Risk
Management
the industry."
Committee memTERRY C. NELSON
ber. "The goal is to
VICE
PRESIDENT OF
protect the confidentiality, integrity
RISK MANAGEMENT
and availability of data and informaFOTH
tion. In order to do that, you have to
VICE CHAIR, ACEC
address the people, policies, proceRISK MANAGEMENT
COMMITTEE
dures and technology."
Mendelson calls password
hygiene the "low-hanging fruit"
of cybersecurity and says that firms should not only require
employees to regularly change their passwords but should also
implement stringent requirements for password complexity.
For example, firms should require a certain number and mix
of letters, numbers and symbols. According to Mendelson,
firms should also regularly (not less than daily) back up their
data to limit the potential damage of a ransomware attack or
other cyberattack.

According to
the National
Cybersecurity
Alliance,
60 percent
of small and midsized companies
will go out of
business within
six months of a
successful hack

PUTTING SECURITY MEASURES IN PLACE

The phishing attacks that swindled Herlihy's clients out of
thousands of dollars could have been prevented through
technologies and procedures designed to boost cybersecurity.

CYBERSECURITY: BY THE NUMBERS
1.95 billion
The total number of records
containing
personal and
other sensitive
data that were
compromised
between
Jan. 1, 2017,
and March 20,
2018.

191
The average
number of
days it takes
for organizations to
identify a data
breach.

77 percent
The portion
of IT professionals who
say their
organizations
lack a formal
cybersecurity incident
response plan.

76 percent
The portion
of organizations that say
they would
likely increase
cybersecurity
spending
following a
breach that
causes significant damage.
SOURCE: TECHBEACON

24

ENGINEERING INC.

JULY / AUGUST 2019

64 percent
The portion of
organizations
who say they
would not
increase their
cybersecurity
budgets after
an attack that
does not cause
harm.

75 percent
The portion of
data breaches
caused by
external
attackers.

25 percent
The portion
of breaches
caused by
careless, negligent or malicious insiders
with legitimate
access to systems and data.

71 percent
The portion
of U.S. enterprises that
report suffering at least
one data
breach over
the past few
years.

56 percent
The portion
of IT decisionmakers who
identify phishing attacks
as their biggest current
cybersecurity
threat.



Engineering Inc - July/August 2019

Table of Contents for the Digital Edition of Engineering Inc - July/August 2019

Engineering Inc. - July/August 2019
Contents
From Acec to You
Market Watch
Legislative Action
The Private Side
From A Global Perspective
Navigating A New Future
Protecting Your Firm Against Cyberattacks
Pli Market Remains Steady
A Half-Century Of Caring
2019 Acec Member Survey
Risk Management
In The News
Mergers And Acquisitions
Members In The News
Business Insights
Engineering Inc - July/August 2019 - Intro
Engineering Inc - July/August 2019 - Engineering Inc. - July/August 2019
Engineering Inc - July/August 2019 - Cover2
Engineering Inc - July/August 2019 - T1
Engineering Inc - July/August 2019 - T2
Engineering Inc - July/August 2019 - T3
Engineering Inc - July/August 2019 - T4
Engineering Inc - July/August 2019 - T5
Engineering Inc - July/August 2019 - T6
Engineering Inc - July/August 2019 - T7
Engineering Inc - July/August 2019 - T8
Engineering Inc - July/August 2019 - Contents
Engineering Inc - July/August 2019 - 2
Engineering Inc - July/August 2019 - 3
Engineering Inc - July/August 2019 - From Acec to You
Engineering Inc - July/August 2019 - 5
Engineering Inc - July/August 2019 - Market Watch
Engineering Inc - July/August 2019 - 7
Engineering Inc - July/August 2019 - Legislative Action
Engineering Inc - July/August 2019 - 9
Engineering Inc - July/August 2019 - The Private Side
Engineering Inc - July/August 2019 - 11
Engineering Inc - July/August 2019 - From A Global Perspective
Engineering Inc - July/August 2019 - 13
Engineering Inc - July/August 2019 - 14
Engineering Inc - July/August 2019 - 15
Engineering Inc - July/August 2019 - 16
Engineering Inc - July/August 2019 - 17
Engineering Inc - July/August 2019 - Navigating A New Future
Engineering Inc - July/August 2019 - 19
Engineering Inc - July/August 2019 - 20
Engineering Inc - July/August 2019 - 21
Engineering Inc - July/August 2019 - Protecting Your Firm Against Cyberattacks
Engineering Inc - July/August 2019 - 23
Engineering Inc - July/August 2019 - 24
Engineering Inc - July/August 2019 - 25
Engineering Inc - July/August 2019 - 26
Engineering Inc - July/August 2019 - Pli Market Remains Steady
Engineering Inc - July/August 2019 - 28
Engineering Inc - July/August 2019 - 29
Engineering Inc - July/August 2019 - 30
Engineering Inc - July/August 2019 - 31
Engineering Inc - July/August 2019 - 32
Engineering Inc - July/August 2019 - 33
Engineering Inc - July/August 2019 - 34
Engineering Inc - July/August 2019 - 35
Engineering Inc - July/August 2019 - A Half-Century Of Caring
Engineering Inc - July/August 2019 - 37
Engineering Inc - July/August 2019 - 38
Engineering Inc - July/August 2019 - 39
Engineering Inc - July/August 2019 - 2019 Acec Member Survey
Engineering Inc - July/August 2019 - 41
Engineering Inc - July/August 2019 - Risk Management
Engineering Inc - July/August 2019 - 43
Engineering Inc - July/August 2019 - In The News
Engineering Inc - July/August 2019 - 45
Engineering Inc - July/August 2019 - Mergers And Acquisitions
Engineering Inc - July/August 2019 - 47
Engineering Inc - July/August 2019 - 48
Engineering Inc - July/August 2019 - Members In The News
Engineering Inc - July/August 2019 - 50
Engineering Inc - July/August 2019 - 51
Engineering Inc - July/August 2019 - Business Insights
Engineering Inc - July/August 2019 - Cover3
Engineering Inc - July/August 2019 - Cover4
https://www.nxtbook.com/nxtbooks/acec/engineeringinc_spring2020
https://www.nxtbook.com/nxtbooks/acec/engineeringinc_winter2020
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1119
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0919
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0719
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0519
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0319
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0119
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1118
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0918
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0718
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0518
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0318
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0118
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1117
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0917
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0717
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0517
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0317
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0117
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1116
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0916
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0716
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0516
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0316
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0116
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1115
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0915
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0715
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0515
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0315
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0115
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1114
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0914
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0714
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0514
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0314
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0114
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1113
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0913
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0713
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0513
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0313
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0113
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1112
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0912
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0712
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0512
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0312
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0112
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1111
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0911
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0711
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0511
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0311
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0111
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1110
https://www.nxtbook.com/nxtbooks/acec/engineeringincSeptOct
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0910
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0710
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0510
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0310
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0110
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1109
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0909
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0709
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0309
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0109_v2
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0109
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1108
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0908
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0708
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0508
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0308
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0108
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1107
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0907
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0707
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0507
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0307
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0107
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0505
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0305
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1105
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0306
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0105
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1103
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0906
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0903
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0703
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0106
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0506
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0503
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0303
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0904
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1104
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0704
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0504
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0304
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0905
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0705
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0104
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1106
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0706
https://www.nxtbookmedia.com