Cybersecurity threats continue to evolve, and organizations of all sizes—including architectural practices—remain attractive targets for cybercriminals. Phishing emails, fraudulent text messages, malicious links, and business email compromise scams are increasingly sophisticated and often appear to come from trusted sources such as clients, consultants, vendors, financial institutions, or colleagues.
A successful phishing attack can result in unauthorized access to business systems, financial loss, data breaches, project delays, and reputational damage. While technology plays an important role in cybersecurity, awareness and good business practices remain the first line of defense.
Ten Best Practices for Protecting Your Practice
The OAA’s Practice Hotline continues to receive inquiries from members concerned about suspicious communications, attempted fraud, and potential breaches affecting their professional operations.
Although the specific circumstances vary, these inquiries highlight the importance of maintaining strong administrative and cybersecurity safeguards within architectural practices. The following best practices outline general measures that can help support a more secure and resilient practice environment:
- Be cautious of unsolicited emails, text messages, or phone calls requesting sensitive information, passwords, payments, or urgent action.
- Verify requests involving financial transactions, banking changes, wire transfers, or confidential information through a separate communication channel.
- Avoid clicking links or opening attachments unless you are confident of their legitimacy.
- Use strong, unique passwords and enable multi-factor authentication (MFA) wherever possible.
- Regularly update operating systems, applications, network equipment, and security software with the latest security patches.
- Maintain appropriate security controls for your organization's size and risk profile, including firewalls, endpoint protection, secure backups, and access controls.
- Regularly review user accounts and permissions to ensure employees have only the access required to perform their duties.
- Back up critical business data and periodically test restoration procedures to confirm backups are functioning as expected.
- Conduct periodic security assessments or audits to identify vulnerabilities and areas for improvement.
- Provide ongoing cybersecurity awareness training to staff, as human error remains one of the most common causes of security incidents.
When in Doubt, Seek Expertise in the IT/Cybersecurity Field
Technology and cybersecurity requirements can be complex, and no architectural practice is expected to navigate them alone. If you are uncertain about the legitimacy of a communication, the security of your systems, or the adequacy of your cybersecurity controls, consult a qualified technical advisor or cybersecurity professional. As part of this process, your practice should also consult with appropriate insurance professionals to understand, evaluate, and maintain cyber insurance coverage aligning with your business needs and risk profile.
A proactive approach to cybersecurity can significantly reduce risk and help protect your practice, your clients, and the sensitive information entrusted to your organization. Investing time in prevention today can help avoid costly incidents tomorrow.
This article originally appeared in an edition of Practice Advisory—a newsletter developed by the OAA’s Practice Advisory Services team, which offers numerous resources for both members and the public.
The OAA does not provide legal, insurance, or accounting advice. Readers are advised to consult their own legal, accounting, or insurance representatives to obtain suitable professional advice in those regards.