Magnifying glass with black handle on a blue textured background focusing light reflection.

Who Still Has Access? 5 Cybersecurity Risks AEC Firms Should Check

Architecture, engineering, and construction firms rely on Microsoft 365, cloud applications, project files, remote access, and outside vendors every day. That makes access management one of the simplest places for cybersecurity gaps to develop.

For AEC firms in Greater Boston and across the South Shore, a good place to start is asking a straightforward question:

Who can access your systems today, and do they still need that access?

Here are five areas worth checking.

1. Are former employee accounts still active?

When an employee leaves, access should be removed from more than just their email.

That can include:

  • Microsoft 365
  • VPN access
  • shared project folders
  • cloud applications
  • accounting systems
  • file-sharing platforms
  • remote access tools

Old accounts are easy to forget, especially when several people or vendors are involved in onboarding and offboarding.

What to ask your IT provider:
Can you show us that former employee accounts have been disabled across our major systems?

2. Is MFA required everywhere important?

Multifactor authentication adds another layer of protection when a password is stolen.

But having MFA on most accounts isn't the same as having it everywhere it matters.

Pay particular attention to:

  • administrator accounts
  • Microsoft 365
  • remote access
  • financial systems
  • cloud applications containing project or client information

What to ask:
Which accounts can still sign in without MFA?

3. Who has administrator rights?

Administrator access allows users to make significant changes to systems.

That access should be limited to people who genuinely need it. If an administrator account is compromised, the potential damage can be much greater than with a standard user account.

What to ask:
Who currently has administrator rights, and why?

4. Are shared accounts still being used?

Shared logins may seem convenient on a project site or shared workstation, but they create security and accountability problems.

If several people use the same account, it can become difficult to determine:

  • who accessed information
  • who made a change
  • whose access needs to be removed

Whenever possible, employees should use individual accounts.

5. Do vendors still have access?

AEC firms regularly work with consultants, subcontractors, software vendors, and outside service providers.

The problem is that access granted for one project can remain long after the work ends.

What to ask:
When was third-party and vendor access last reviewed?

A simple cybersecurity check for AEC firms

Cybersecurity doesn't always fail because a company has no protection. Sometimes one forgotten account or overlooked permission creates the opening.

Systems Support works with businesses throughout Greater Boston and Southeastern Massachusetts to help make these questions easier to answer.

Take the 2-Minute Sitting Duck Assessment:
www.systemsupport.com/campaign/duck

Frequently Asked Questions

How often should employee access be reviewed?
Access should be reviewed regularly and whenever employees, vendors, or job responsibilities change.

Should every Microsoft 365 account have MFA?
Businesses should generally require MFA for accounts that access company systems, with particular attention to administrator and remote-access accounts.

Why are old vendor accounts a security risk?
Unused accounts can remain an unnecessary path into company systems if they are forgotten or compromised.