Skip to main content
Cybersecurity

Construction & Engineering Ransomware Response: What to Do First

  • Ransomware
  • Akira
  • Construction Cybersecurity
  • Incident Response
Crossguard Cyber
Spencer Heath
August 5, 20267 min read
Share

Key Takeaways

  • CISA and the FBI's updated Akira ransomware advisory, released November 13, 2025, names construction and engineering among the strain's top three targeted sectors, alongside manufacturing and legal and professional services.
  • Real 2026 Akira attacks have already hit firms this size, including IH Engineers in June and Kruse Construction and Pioneer Construction in July.
  • CISA's guidance calls for isolating affected systems first, activating incident response contacts second, and only then investigating, doing these out of order can let an attack spread further.
  • A ransomware incident that exposes client, subcontractor, or payment data is very likely a reportable breach under Virginia or North Carolina law.
  • Firms with tested backups, deployed EDR, and a written incident response plan recover fastest, and those same controls are now the baseline cyber insurers require for renewal.

If ransomware has locked up your project files, or you're trying to get ahead of it before it happens, here's the plan. Akira, the ransomware strain the FBI and CISA now name as a top threat to construction and engineering firms, doesn't care whether you're a five-person engineering shop or a general contractor running six job sites at once. A ransomware response for a construction or engineering firm comes down to the same three phases every time: contain the damage in the first hours, meet your legal notification obligations in the days after, and recover in a way that actually closes the hole the attackers used to get in.

What is a ransomware response for a construction or engineering firm, exactly?

A ransomware response for a construction or engineering firm is the sequence of steps a business takes after an attack: isolating infected systems, activating IT and legal support, determining what project, financial, or client data was accessed, meeting any state notification requirements, and restoring operations from clean, verified backups. Handled well, it turns a serious incident into a costly but manageable event. Handled poorly, or not planned at all, a single infected workstation can turn into weeks of delayed submittals, stalled payment approvals, and a client or general contractor relationship that never fully recovers.

Are construction and engineering firms actually being targeted by ransomware?

Yes, and the government's own threat advisory says so directly. In November 2025, CISA and the FBI updated their joint #StopRansomware advisory on Akira ransomware, naming construction and engineering among Akira's top three targeted sectors, alongside manufacturing and legal and professional services.

The advisory isn't describing a hypothetical. In June 2026, the group claimed a cyberattack on IH Engineers, a U.S. consulting firm, threatening to release 65GB of corporate data. The following month, Akira claimed attacks on Kruse Construction, a mechanical contractor, and Pioneer Construction, a general contractor, each with tens to hundreds of gigabytes of data at stake. None of these are massive national firms. They're the same size and shape as most construction and engineering businesses in Hampton Roads and Northern North Carolina: valuable project and financial data, thinner security budgets than an enterprise target, and often no dedicated IT security staff at all.

How does Akira actually get in?

Entry pointWhy it worksWhat stops it
VPN or remote access without MFASingle-factor remote credentials are Akira's most common way inMulti-factor authentication on every remote access point
Exposed remote desktop (RDP)Akira scans for open RDP ports and brute-forces weak credentialsDisable public RDP, or require MFA and a VPN in front of it
Unpatched, internet-facing softwareKnown vulnerabilities give attackers a foothold without stealing a single credentialA documented patch schedule for anything internet-facing
Backup systems left onlineAkira increasingly targets backup infrastructure first, specifically to block recoveryOffline or immutable backup copies the ransomware can't reach

What should you do in the first 24 hours after a ransomware attack?

Isolate first, notify second, investigate third, in that order. CISA's ransomware response guidance is built around this exact sequence, and skipping ahead to investigation before containment is one of the most common mistakes that lets an attack spread from one workstation to an entire network.

  1. Isolate affected systems immediately. Disconnect infected machines from the network instead of powering them off, since a live but isolated machine preserves more evidence than one that's been shut down. If several systems appear affected, take the whole subnet offline at the switch level rather than isolating machine by machine.
  2. Activate your incident response contacts. That means your managed IT or security provider, your cyber insurance carrier (most policies require notification within a set window to preserve coverage), and, for a serious incident, your local FBI field office or the FBI's Internet Crime Complaint Center (IC3).
  3. Don't pay the ransom before consulting your incident response partner and, in most cases, legal counsel. Payment doesn't guarantee data recovery or that stolen bid documents and client data won't still be leaked, and it can carry its own legal exposure depending on who the attacker turns out to be.
  4. Preserve logs and evidence from your antivirus, EDR, or firewall systems before anything gets overwritten during recovery. This is what your incident response partner uses to determine how the attacker got in and what they touched.
  5. Keep a written timeline as you go, noting what was discovered, when, by whom, and what action was taken. You'll need this for your insurance claim, for any breach notification filing, and for your own after-action review.

Do you have to notify clients or partners after a ransomware attack?

In most cases, yes, if project, client, or payment data was exposed. Virginia and North Carolina both have breach notification statutes that apply to any business holding personal information, construction and engineering firms included, using a "without unreasonable delay" standard rather than a fixed number of days. We've broken down Virginia and North Carolina's data breach notification law in detail elsewhere.

If the ransomware incident exposed employee records, client contact information, subcontractor payment details, or banking information tied to a wire transfer, and for most project management and accounting systems that's exactly the data at risk, it's very likely a reportable breach under state law. Confirming this with legal counsel early, rather than during a fire drill, is one of the most overlooked steps in a firm's response.

How do you choose the right incident response partner?

Not every managed IT provider does forensic incident response, and finding that out mid-attack costs you time you don't have. Before you need one, confirm your provider, or a partner they work with, can do the following:

  • Determine the initial point of entry and whether the attacker still has access
  • Assess what data, if any, was exfiltrated versus simply encrypted in place, including bid documents, drawings, and subcontractor or client financial information
  • Rebuild affected systems from clean, verified backups rather than the infected image
  • Coordinate with your cyber insurance carrier's required vendor list, since some policies mandate using a pre-approved forensics firm

The project management platform you run matters here too. Who can actually see your bid documents, subcontractor data, and payment information varies by system, as we've compared for Procore and Buildertrend, and that access map is exactly what an incident response partner needs on day one, not something to figure out mid-attack.

A firm's day-to-day IT support and its incident response capability aren't automatically the same thing. If you don't already know which one you have, that's worth confirming now, not during the next attack.

How can you prevent the next ransomware attack?

Recovery closes the immediate crisis. Prevention is what keeps the next one from happening. ACEC's cybersecurity guidance for AEC firms points to the same handful of controls that show up in nearly every real-world incident review, and they line up closely with what CISA recommends across every sector:

  • Multi-factor authentication on email, your project management platform, and any remote access tools. Compromised credentials remain the single most common way attackers get into a network in the first place.
  • Offsite, tested backups, not just backups that run on schedule, but backups your team has actually confirmed can be restored. An untested backup is a hope, not a plan.
  • Managed endpoint detection and response (EDR) across every workstation and server, with alerts actually monitored around the clock instead of installed and forgotten.
  • A written incident response plan, reviewed at least annually, so the first 24 hours described above happen by procedure instead of improvisation.
  • Staff training on recognizing phishing attempts, since a single clicked link is still how most ransomware incidents start.

None of these controls are exotic or enterprise-only. They're also close to the exact baseline that cyber insurance carriers now require for renewal, which means the same investment that keeps Akira out of your network is also what keeps your policy from getting re-priced or denied.

A ransomware attack on a construction or engineering firm is a bad day no matter how prepared you are. Whether it turns into a bad week, or a bad year, depends almost entirely on what was already in place before it happened. If you're not sure where your firm actually stands on backups, MFA, or a written response plan, Crossguard Cyber's free assessment walks through your current setup and shows you the real gaps, before Akira or the next group finds them for you.

Ready to put this into practice?

Get a free IT risk assessment and see exactly where your business stands today.