Servers go dark. CAD models become inaccessible. Or a cloud folder shows unexpected external downloads. The question is not whether the incident is technical. It is whether you are dealing with active encryption that has locked project files, or an unencrypted leak that has already moved data outside the firm.
The first fork: ransomware lock or unauthorized leak?
Every project data incident in an AEC firm splits into two very different situations. Either this is ransomware that has encrypted BIM servers, or it is an unauthorized data leak or unencrypted exfiltration.
That distinction changes almost everything downstream: how aggressively you isolate systems, who you notify first, whether law enforcement and cyber insurance clocks start, and what you tell clients and staff while the investigation is still open.
A ransomware lock means you are managing an active containment and recovery operation. An unauthorized leak means you are managing access revocation, audit trails, and potential statutory notice obligations. Treating the two the same is how firms either under-isolate a spreading threat or over-communicate a contained access issue.
If BIM servers are encrypted: isolate, disconnect, and give one clear instruction
Once ransomware is confirmed, the first moves are technical and procedural. Disconnect affected BIM file servers. Disable remote VPN access. Isolate cloud storage sync. Disconnect off-site physical backup drives so malware cannot propagate further. Export access logs, firewall histories, and admin audit trails to secure external media. Pause every scheduled promotional post, digital ad, and newsletter so nothing tone-deaf goes out while systems are down. Notify firm leadership, the cyber insurance broker, and legal counsel.
Only after isolation is underway does internal messaging begin. Here is the actual staff SMS from the playbook, sent the moment an active server lock is confirmed:
CYBER ALERT: An active server security incident has locked internal BIM networks at [Firm Name]. Disconnect all workstations from network cables immediately. Media or client queries to communications at [Phone/Email].
It does not describe the malware. It does not speculate about recovery time. It gives every recipient two instructions: disconnect immediately and route all outside questions to one place. That is deliberate. In the first hour the riskiest action is a well-meaning employee reconnecting a workstation or improvising answers to a client call. The SMS is built to prevent that.
Next comes the holding statement prepared for clients, press, or public posting. From the playbook:
We are aware of a cybersecurity incident affecting internal servers at [Firm Name] and have engaged IT security specialists to investigate. We will share updates on [channel] as more information becomes available. Media inquiries: [spokesperson].
This statement is held for Managing Partner approval and used only when needed. It acknowledges the incident, confirms specialist engagement, and creates a single contact path. It does not confirm data exposure, promise a specific recovery date, or discuss ransom demands.
From there the playbook branches on the sensitivity of the compromised files. If proprietary CAD drawings are involved and law enforcement plus insurer notice are required, the response expands to forensic investigators, formal cybercrime reports, and a client advisory. Here is the client email template from that branch:
Dear Valued Partner,
We are writing to inform you of a cybersecurity incident that temporarily impacted internal file servers at [Firm Name].
What is confirmed is that our IT team isolated affected servers and engaged independent forensic specialists; what is currently underway is a security sweep to verify file integrity and restore CAD models safely.
Firm Actions:
- External cybersecurity experts are conducting network remediation and system hardening.
- Active project design work continues via secure, isolated cloud backup repositories.
- Direct any data privacy or technical questions to our response desk at [Phone/Email].
We take data protection seriously and will share additional verified updates. Contact [Phone/Email] with questions.
Sincerely,
[Executive Leadership Team]
Notice what this message does and does not do. It states confirmed actions only. It reassures that project work continues through isolated backups. It routes every question to one desk. It does not admit specific data loss, discuss the ransomware note, or invent a full-restoration timeline that does not yet exist.
If the lock is isolated and clean backups allow an internal restore, the messaging stays tighter: password resets, firewall updates, and short internal notices that networks are cleared for use.
If the issue is an unauthorized data leak: revoke access, audit, and match notice to the data involved
An unencrypted leak or unauthorized download is a different kind of risk. The first steps are still containment: revoke external sharing permissions on cloud drawing repositories, reset compromised credentials, pause promotional campaigns that feature project designs, and notify leadership, insurance, and counsel. Export access logs and isolate the specific project folders and drawing numbers that were exposed.
The next branch depends on what left the firm. If confidential client bidding documents are involved, formal statutory notices and potential credit monitoring may be required, but only after legal counsel approves the language and timing. If the leak is limited to internal project files, the response tightens folder permissions, runs a cloud security audit, and issues an internal studio notice that reinforces approved sharing channels.
In both leak branches the failure mode is the same: sending formal client notices before counsel has cleared them, or discussing unconfirmed details while the audit is still open.
The pattern across all four branches
Whether the incident is ransomware encryption or an unauthorized leak, whether proprietary CAD is compromised or the exposure is internal, the same structure repeats:
- Isolate systems and pause marketing first. Every branch begins with technical containment and an immediate hold on promotional content.
- Preserve logs and evidence before anyone speaks. Access records, firewall histories, and backup status are secured so the team works from one set of facts.
- Silence untrained voices. Staff receive short, restrictive instructions to disconnect, stop external file sharing, and route every client or media question to one authorized contact.
- Match the message to the audience and the confirmed facts. Internal alerts stay directive. Clients and partners, when notice is required, receive verified actions and a single response desk. Holding statements acknowledge the incident without confirming unproven exposure.
- Monitor, log, and debrief. News, trade media, and threat channels are watched for 24 to 48 hours. Decisions and messages are logged. A post-incident debrief is scheduled within 72 hours so the playbook itself can be improved.
That structure, more than any single paragraph of template language, is what protects an AEC firm when project data or BIM servers are compromised.
A project data breach or ransomware lock does not leave you time to draft a plan from scratch
The templates above come directly from CrisisComms.io’s Project Data Breach or BIM/File Server Ransomware playbook, a decision-tree template that takes a communications and IT team from “we do not yet know the full scope” to “here is exactly what to send, to whom, right now.”
A server lock or file leak rarely arrives with clean notice. You can still decide, ahead of time, exactly what your team does in the first hour after one is detected.