IT and cybersecurity for Architecture & Engineering
You are held to NIST 800-171 / CMMC (federal subset only) – and, like most firms your size, you are expected to meet it without anyone in-house whose job it is to own it. We run the IT and the security program so the obligation is actually covered, not just acknowledged.
Where we usually start: 2× ransomware + IP/downtime.
If this sounds familiar
“If we get hit with ransomware and can’t open our Revit models, every project stops at once.”
The firm’s entire output lives in BIM/CAD files; lose access for even a few days and deadlines slip across every active project simultaneously, with client trust and penalty clauses on the line.
“Our drawings and models are the whole firm – losing them or having them leak would be devastating.”
Design IP is the crown jewel and the competitive advantage; a loss or breach is both an operational and a reputational catastrophe.
“Half the team is remote or on a job site, and getting them fast, secure access to huge model files is a daily fight.”
Distributed work has outrun the firm’s access and remote-connectivity setup, creating both a productivity drag and a security exposure on shared drives.
Who this is for
Typical size: 20–200 employees (sweet spot 30–120), revenue $5M–$80M. If that is roughly you, the rest of this page will land.
What working with us looks like
A named team that knows your stack, monitoring and patching that happens whether or not anyone chases it, and a written security program kept current – with the evidence to back it up when a client, an auditor or an insurer asks. We report to the Principal + Ops/BIM lead, not to a ticket queue.
Talk to us
Call 206-850-1496 or email mhasse@itwerx.net and we will set up a short call – no audit, no pitch deck, just a conversation about what you have and what is worrying you.

