A recent ASCE feature on infrastructure cybersecurity included a line from Arizona State’s Mikhail Chester that should be hanging on the wall of every engineering firm principal in the country: “Civil engineering firms shouldn’t try to be Microsoft in terms of fighting cyberattacks. They should be able to do what they can in-house and be able to protect their systems.”
That sentence is doing a lot of work. It rejects two equally bad responses to the cybersecurity problem that have become common in the AEC industry. The first is the firm that decides cybersecurity is “an IT thing” and outsources the entire problem to a managed services provider, then quietly loses visibility into its own risk posture. The second is the firm that overcorrects, hires a security director, buys a stack of tools it does not have the staff to operate, and ends up worse off than if it had done nothing.
The right answer is in the middle. And getting there requires actually deciding, function by function, what your firm should own, what you should co-manage with partners, and what you should hand off entirely.
Why Engineering Firms Get This Wrong
Most civil engineering firms make cybersecurity decisions reactively. A phishing attempt slips through, so someone buys an email security tool. A client asks about your security posture during procurement, so you scramble to put together a one-page response. A peer firm gets hit with ransomware, so leadership greenlights a budget request that should have been approved two years ago.
That pattern produces a cybersecurity stack that looks like a junk drawer. Overlapping tools, no clear owner for any of them, no documented decisions about why this vendor was chosen over that one. And critically, no shared understanding inside the firm of what you are actually trying to defend.
The fix is not more tools. It is a clearer division of responsibilities, with deliberate choices about which capabilities live with your people, which live with partners, and which live with specialists you simply pay to handle.
A Three-Tier Framework

A useful way to organize the conversation is to sort cybersecurity capabilities into three tiers based on how close they sit to your firm’s core operations.
- Tier 1: Own. Functions where outsourcing creates more risk than it removes. They require institutional knowledge about your projects, your clients, and your people. You cannot hand them off without losing the visibility you need to make good decisions.
- Tier 2: Co-Manage. Functions where you need a partner who brings specialized expertise, but you still need to retain enough involvement to direct the work and make judgment calls. The partner builds and operates; you set policy and review.
- Tier 3: Outsource. Functions that are largely commodity. The specialist firms doing this work do it better and cheaper than you ever could, and there is little value in keeping it in-house. Pay them. Move on.
Once a function is sorted into a tier, the questions you ask about it change. Tier 1 questions are about policy and discipline. Tier 2 questions are about partnership terms and shared responsibility. Tier 3 questions are mostly about price and reliability.
Tier 1: What Your Firm Must Own
Access controls and identity management
Who at your firm has access to what data is a question only your firm can answer well. Project teams change, subconsultants come and go, employees leave. Maintaining the discipline of removing access promptly, granting least-privilege access by default, and reviewing access on a regular cadence is a function that lives and dies with your operations team.
This does not mean you cannot use software to enforce these policies. You absolutely should. It means the policies themselves, and the discipline of applying them, have to be owned internally.
Project data classification
Some of your project data is publicly available. Some is sensitive but not catastrophic if exposed. Some, like fee proposals, internal cost data, pursuit intelligence, and certain client communications, would do real competitive damage if it leaked. Knowing the difference is your job, not a vendor’s. So is enforcing the rules about where each category is stored, who can access it, and how it gets shared externally.
Vendor and software vetting
Every SaaS tool your firm adopts is a new piece of attack surface. The decision about whether a given vendor has acceptable security practices, where their data lives, what their incident history looks like, and what their contract terms say about your data is a decision your firm needs to make with full information. A managed services provider can advise. They cannot decide for you.
Incident response leadership
When something goes wrong, decisions need to be made fast and they need to be made by people who understand the firm. Who do we call? What do we tell the client? Do we pay the ransom? When do we go to law enforcement? When do we disclose to insurers? These are leadership decisions, not vendor decisions. You can and should have a partner on speed dial who handles the technical forensics. But the strategic calls stay with you.
Tier 2: What You Should Co-Manage With Partners
Custom internal applications
This is where most engineering firms either underinvest or get it badly wrong. The applications that handle your fee proposals, your project data, your competitive intelligence, your operational workflows are too important to leave to off-the-shelf tools that were built for someone else’s business, and too specialized to build entirely in-house.
The right model is co-managed. A software partner who understands your domain builds and maintains the tools, integrates them into your security architecture, and works with you to define what data goes where. You set the requirements, the access policies, and the data handling rules. They translate those into working software that holds up under audit.
Cloud infrastructure
You are almost certainly on AWS, Azure, or Google Cloud, whether you realize it or not. Your file sharing, your email, your CAD collaboration tools all live there. The hyperscalers handle the bottom of the stack better than anyone. But the configuration of your tenant, the identity policies, the network architecture, the logging and monitoring posture, all of that requires active management. A partner who specializes in cloud security for AEC firms is invaluable, and so is your involvement in setting the policies they enforce.
Client and project system integrations
When you connect to a client’s BIM environment, a permitting portal, or a state DOT data exchange, you are extending your attack surface into systems you do not control. The technical work of building those integrations securely is partner work. The decisions about which integrations are worth the risk, and which client requirements you are willing to accept, are yours.
Tier 3: What to Fully Outsource
Endpoint protection
The market for endpoint detection and response tools is mature, the products are good, and there is no value in your firm trying to operate this in-house. Pick a reputable vendor, deploy it everywhere, and move on.
Email security
Same logic. Email is the most common attack vector in the industry. The vendors who specialize in this do it well. Pay them.
24/7 monitoring and SOC services
Unless your firm is large enough to staff a security operations center around the clock, and almost no engineering firm is, this is a clear outsource. The managed detection and response market has matured significantly in the last several years. You can get round-the-clock monitoring of your environment for a price that is far below what hiring in-house would cost.
Penetration testing and security audits
You need independent eyes on your security posture at least annually. By definition, those eyes cannot belong to your own staff. Engage a reputable testing firm. Take their findings seriously. Repeat.

The Question That Matters Most: Vendor Selection
When Chester says firms should “do what they can in-house and protect their systems,” he is implicitly raising the question of how firms choose the partners who handle everything else. This is where most engineering firms have the least process and the most exposure.
A few questions worth asking any software or security vendor before signing:

- Where does our data live, and under what jurisdiction?
- Who at your company has access to our data?
- What is your incident notification timeline, and is it in our contract?
- What happens to our data when our contract ends?
- Have you been independently audited? Can we see the report?
- Who owns the code or configurations you build for us?
That last question matters more than firms tend to realize. If a vendor builds a custom workflow for your firm and you do not own the source code or the configurations, you are locked in. If the vendor gets acquired, raises prices, or goes out of business, you start from zero. The right software partner is comfortable with you owning what they build.
Where InfraTech Fits
InfraTech Strategy Group exists in Tier 2. We partner with civil engineering firms to build the custom software that sits between the commodity tools you outsource and the policies you have to own. Our work is shaped by the same constraint Chester pointed at: firms should not try to be Microsoft, but they cannot afford to be passive consumers of generic software either.
Practically, that means we design tools that respect the data classification rules your firm sets, integrate with the identity systems your firm controls, and produce code and configurations your firm owns outright. We are happy to sit at the table with your MSP, your insurance carrier, and your in-house IT lead. The work is better when everyone understands their lane.
Where to Start
If your firm has not had a deliberate conversation about which cybersecurity functions live where, the cheapest place to start is on a whiteboard. List every cybersecurity-adjacent function your firm performs or pays for. For each one, decide whether it is Tier 1, 2, or 3. Identify the gaps. Identify the overlaps.
The exercise usually surfaces two or three findings that pay for themselves immediately. A tool you are paying for that no one is operating. A function you are doing in-house that you should have outsourced years ago. A partner relationship that needs to be restructured because the lines have blurred.
Cybersecurity is becoming part of what it means to deliver civil engineering work responsibly. The firms that figure out their stack early will spend the next decade compounding the advantage. The ones that wait will spend it cleaning up after incidents that were entirely preventable.
InfraTech Strategy Group partners with civil engineering firms to build custom software that fits the way your firm actually works. If you are thinking through your cybersecurity stack and want a second set of eyes on the Tier 2 layer, get in touch.