Incident Response Planning for Alberta Architecture and Construction Firms
It is 7:40 on a Tuesday morning. Tender closes at 2:00. Someone opens the Revit central model and gets an error. The project architect tries a different workstation and gets the same error. Nobody knows whether the file is corrupted, whether the server is the problem, or whether last night’s backup is any good.
The next forty minutes decide how the day goes. Not the technology. The forty minutes.
Firms that have thought about this in advance spend those minutes executing. Firms that have not spend them arguing about who should call whom, whether to tell the client, and whether it is worth trying to rebuild the model from someone’s local file. By the time they have decided, it is 8:30 and the submission is at risk.
An incident response plan is what removes those forty minutes. It is not a technical document and it is not long. It is a short set of decisions made when nobody is panicking.
Why this matters more than the general statistics suggest
Statistics Canada’s most recent Canadian Survey of Cyber Security and Cybercrime found that 16 percent of Canadian businesses were impacted by a cyber security incident in 2023, continuing a slow decline from 21 percent in 2019. That headline number is easy to misread as good news.
The cost trend went the other way. Total business spending on recovery from cyber incidents doubled between 2021 and 2023, from roughly $600 million to $1.2 billion nationally. Fewer incidents, more expensive ones.
The same survey found that only 26 percent of Canadian businesses had a written cyber security policy, unchanged from 2021, and 22 percent carried cyber risk insurance.
For an AEC firm, cyber incidents are only part of the picture anyway. A failed server, a corrupted central model, a departed employee who owned the folder structure, or a fibre cut on the block will all stop billable work just as effectively as ransomware, and they happen more often.
Sources: Statistics Canada, “Impact of cybercrime on Canadian businesses, 2023,” The Daily, October 2024. CIRA 2025 Cybersecurity Survey, which separately found that 43 percent of surveyed Canadian organizations were targeted by an attempted or successful cyber attack in the previous 12 months and 24 percent were hit by ransomware.
What belongs in the plan
Six components. Each one is followed by the way firms usually get it wrong, because the mistakes are more instructive than the checklist.
1. Who decides, and who speaks
When the central model will not open, three questions need an owner before anyone touches a keyboard:
- Who decides whether to stop work on the project or keep going in a degraded state?
- Who calls the client, and how long do we work the problem before we make that call?
- Who talks to the general contractor, the sub consultants and the trades who are waiting on the drawings?
That last one is specific to how AEC firms work and it gets missed constantly. Your problem is rarely contained inside your office. If you are the prime consultant, a half day outage propagates to every sub consultant coordinating against your model. If you are a sub, the prime needs to know before their coordination meeting, not after.
Where firms get this wrong: the principal assumes they will make every call, then turns out to be on a site visit in Nisku with one bar of signal. Name a deputy for every role. Write down at what point the deputy takes over, in minutes.
2. A contact list that is actually complete
In the middle of an incident, hunting for a phone number burns the time you do not have. Your list needs, at minimum:
- Your IT provider, with the after hours path, not just the ticket portal
- Your Autodesk reseller or software partner, for licensing and file recovery escalation
- Your internet provider, with the account number, because they will ask
- Your cyber insurance broker and the policy number
- Your legal counsel
- The Office of the Information and Privacy Commissioner of Alberta, if personal information may be involved
- Key clients, the prime consultant on active projects, and the general contractors on projects in construction
That Alberta privacy point is worth reading twice. Under Alberta’s Personal Information Protection Act, organizations are required to notify the Commissioner of a breach involving personal information where there is a real risk of significant harm to an individual. Client contact details, employee records and homeowner information on residential projects all count as personal information. This is a legal obligation with a clock on it, not a courtesy, and finding out about it during an incident is the wrong time.
Where firms get this wrong: the list lives in a shared folder on the server that just went down. Keep a printed copy and a copy on someone’s phone. A one page PDF taped inside a cabinet door has saved more firms than any software.
3. A communication plan that survives losing your usual tools
Teams and email are usually the first casualties. If your firm runs on Microsoft 365 and the incident is an account compromise, the first thing that happens is that you lose access to the tools you would normally use to coordinate the response.
Decide in advance:
- What the fallback channel is. A group text thread and a phone tree are unglamorous and they work.
- What field staff do. Site crews often have a phone and no laptop. They need a way to receive a stop or proceed instruction that does not depend on your office network.
- What you tell clients, in what timeframe, and who signs off on the wording.
The external communication piece matters more in this industry than most. A client who hears from you at 9:00 with “we have a systems issue, here is our plan, we will update you at noon” is dealing with a vendor managing a problem. The same client who hears nothing until 3:00 is dealing with a vendor who missed a deadline.
Where firms get this wrong: they plan internal communication carefully and forget that a schedule slip on your end may trigger obligations under your client agreement or your prime consultant agreement. Read those clauses before you need them.
4. A ranked list of what gets restored first
Not everything comes back at once, and treating every system as equally urgent means everything takes longer.
For most AEC firms the honest ranking is:
- Project file storage and access, including the server, SharePoint site or Autodesk cloud environment where live models and drawing sets live
- Identity and email, because everything else depends on being able to log in
- Whatever your active deadline depends on this week, which may be plotting and printing if a hard copy submission is due
- Time tracking and project accounting
- Everything else
Write down the acceptable downtime for each tier. Not the downtime you would like. The downtime you can survive without a contractual or reputational cost. That number is what your backup and recovery design should be built around, and if your current setup cannot meet it, you have learned something useful on a calm day rather than a bad one.
Where firms get this wrong: they assume backups are the plan. Backups are one input to the plan. A backup tells you the data can come back. It does not tell you in what order, by whom, or how long it takes. A firm with excellent backups and no restore sequence still loses the morning.
5. Response steps written for the person who will actually follow them
The steps do not need to be technical. They need to be followable by whoever is in the office at 7:40 on a Tuesday.
Cover:
- What to do first, including what not to do. “Do not keep opening the file to see if it works this time” is a legitimate instruction, because repeated open attempts on a damaged workshared model can make recovery harder.
- Whether to disconnect a machine from the network, and who has authority to make that call
- When to escalate, expressed as a time limit rather than a judgment call. “If it is not resolved by 8:15, call the client.”
- Who documents what happened, as it happens
Where firms get this wrong: the plan is written by someone technical, in technical language, for an audience that includes a two week old co op student and an office manager who is covering reception. Have someone outside IT read it. If they cannot follow it, rewrite it.
6. A review and test schedule
A plan that has never been tested is a hypothesis.
Test the restore, not the backup. Confirming that a backup job completed is not the same as confirming that a 4 GB Revit central model comes back intact and openable. Those are different claims and only one of them matters.
Review the plan whenever any of the following changes, which in a growing firm is a few times a year:
- Someone with a named role in the plan leaves or changes jobs
- You add or change a major system, including moving project files to the cloud
- You take on a client or a public sector contract with its own data handling requirements
- You change insurers or brokers
Where firms get this wrong: they treat this as an annual task and then skip the year they are busiest, which is the year the plan is most likely to be needed. Attach the review to something that already happens on a schedule, such as your insurance renewal or your fiscal year end.
A ten minute version you can do this week
If a full plan is more than you have appetite for right now, do this instead. It is genuinely better than nothing.
On one page, write down:
- The three systems that stop billable work if they go down
- Who makes the stop or proceed call, and their backup
- Five phone numbers: IT, internet provider, insurance broker, Autodesk reseller, legal
- The last date anyone successfully restored a project file from backup and confirmed it opened
- What you tell a client in the first hour
If you cannot fill in number four, that is the first thing to fix.
Where MatrixCore fits
We work with architecture, engineering, construction and design firms across Edmonton, Leduc, Beaumont, Nisku and Devon. That focus matters here, because the recovery priorities of an AEC firm are not the recovery priorities of an accounting office. Large project files, workshared models, sub consultant coordination and immovable submission dates change what “recovered” actually means.
We help firms build the plan, test the restores, and confirm that the backup and recovery design matches the downtime the business can actually absorb.
If you are not sure whether your firm could answer those five questions this morning, book a 15 minute discovery call. No pitch. We will walk through where the gaps are and what is worth fixing first.
Related reading: Data Backup and Disaster Recovery Services | Cybersecurity Services | IT Services for Architectural Studios | IT Services for Construction Firms
This article is general information, not legal advice. Confirm your obligations under Alberta’s Personal Information Protection Act and under your own client and professional agreements with qualified counsel.