
July 2026 | Engineering Company IT Services Utah | Midyear Security & Systems Review for Engineering Firms
Your Salt Lake City engineering firm hasn't stood still since January — and your IT systems haven't either.
You've added project engineers to the team, onboarded new subconsultants to Procore or Newforma, adopted engineering platforms to handle growing project workloads, and made fast decisions to keep deliverables on schedule. Civil and structural engineering practices in particular have expanded their use of cloud-based document control and collaboration tools this year. What's hard to track is the trail those decisions leave behind: who still has access to project files in Newforma they no longer need, where engineering documents and calculations ended up, and who's actually responsible for what.
By July, most engineering firms are running on assumptions about how their systems work. Here are four things every Salt Lake City engineering firm principal should examine before those assumptions become expensive — or before a DOT project audit asks for answers you don't have documented.
1. Access to Project Files Was Expanded. Was It Ever Revisited?
New project engineers needed to get onto Newforma, Procore, and SharePoint quickly. Other staff moved into new roles and picked up permissions along the way. Temporary access was granted to subconsultants to keep a project moving or cover for someone on field assignment.
But access to project files almost never gets revisited after it's no longer needed. Inside most engineering firms, the picture looks like this:
- Project engineers have more access to sensitive engineering documents and calculations than their current assignment requires
- Former employees or subconsultants who completed their work may still carry active permissions to project repositories in Newforma or SharePoint
- There's no clean view of who can actually reach which project files, structural models, or proprietary specifications
Do the right people have the correct access today? If that answer takes longer than a few seconds, it's worth a closer look. Reviewing user access to project data is one of the most impactful — and most overlooked — steps in IT security for Salt Lake City engineering firms. It's also a documented control that CMMC and DOT auditors will ask about.
2. Your Engineering Software Stack Solved Problems While Creating New Ones
Your structural team needed better collaboration on RISA models, so a shared server environment was added. The civil group brought on an additional Esri ArcGIS license to handle a DOT project. Project managers adopted Deltek Vantagepoint to track resource allocation more precisely. The mechanical team signed up for a SolidWorks PDM deployment that seemed straightforward at the time.
Every one of those was a reasonable decision. Collectively, they created something messier: engineering documents and calculations now live in more places across AutoCAD Civil 3D, Newforma, SharePoint, and local workstations. Integrations between platforms were set up quickly and may not be working as intended. Visibility across the full project data environment has fragmented.
When engineering platforms coexist without anyone owning the full picture, risk doesn't announce itself. It shows up later in slower project delivery, inconsistent document control, and data gaps that belong to nobody. Proactive IT services for Salt Lake City engineering firms can audit this before it becomes a problem — and before a subconsultant data breach travels into your project file environment.
3. Your Backup and Recovery of Engineering Data Is Probably Assumed, Not Verified
Most Salt Lake Valley engineering firms have backups in place and operate under a false sense of security. Recovery of CAD project files, ANSYS simulation datasets, and HPC outputs is rarely tested. The realistic timeline to restore a full project environment after a ransomware attack is unclear. And ownership of the recovery process — who declares an emergency, who leads restoration, who communicates with the client — often isn't formally defined.
When something goes wrong — ransomware locking a project file in AutoCAD Civil 3D the week before a DOT submittal, a server failure taking down ETABS models mid-analysis, or an accidental deletion of a structural calculation set — the conversation too often starts with: 'Wait, who handles this?'
Having backups of project files is not the same as being able to recover them on a timeline that protects billable work and client commitments. The difference between them only becomes clear at the worst possible time. A midyear IT review is the right moment for your Salt Lake City engineering firm to test that process — before you need it on a live project.
4. Responsibility Has Blurred as Your Project Portfolio Has Grown
Early on, who owned what was clear. Your internal team handled workstations and the local server, vendors handled specific platforms, and responsibilities were roughly defined — even if nobody had formally documented the escalation path for a Newforma outage during a deadline week.
Then your engineering project portfolio expanded, new subconsultants came in with their own platform requirements, internal roles shifted, and somewhere in the middle of that growth, IT ownership got blurry. Now when something breaks across systems or providers — a Procore integration fails, a Deltek Vantagepoint license server goes offline, a drawing in AutoCAD Civil 3D won't sync — the question of who takes the lead gets answered in real time. Issues bounce between project PMs and IT contacts, small problems sit unresolved longer than they should, and nobody's sure whose job it is.
Outsourced IT support for Salt Lake City engineering firms can solve this by establishing clear ownership and documented escalation paths — so when something goes wrong during a critical project phase, your engineering team knows exactly what to do and who to call.
Most Risk Comes From What's Changed, Not What's Broken
The vulnerabilities that hurt engineering firms most aren't usually dramatic system failures. They're the slow drift — access to project files that was never revoked, engineering platforms that were never integrated properly into the document control environment, backups of simulation results that were never actually tested, and responsibilities that were never formally handed off as the firm grew.
A midyear IT review with your Salt Lake City engineering IT services team is the right time to close those gaps before Q3 opens new ones — and before a DOT project audit or CMMC assessment surfaces them under pressure.
Frequently Asked Questions
Why should Salt Lake City engineering firms do a midyear IT review?
By July, most engineering firms have made enough changes — new project engineers, new software platforms, new subconsultant relationships — that their IT environment looks significantly different than it did in January. A midyear review helps confirm that access to project files, backups of engineering documents and calculations, and security controls still match how the firm actually operates today.
What does a midyear IT security review typically cover for an engineering firm?
A thorough review for engineering firms covers user access to project repositories in Newforma, Procore, and SharePoint; backup and recovery testing of CAD project files and simulation datasets; engineering software integrations and license management; subconsultant access and vendor permissions; CMMC and DOT compliance alignment; and any new risks introduced by business or project changes in the first half of the year.
How long does a midyear IT assessment take for a small engineering firm?
For most small and mid-sized engineering firms in the Salt Lake Valley, a focused IT review can be completed within a few hours. Qual IT offers a free 10-minute discovery call to help engineering firm principals identify where to start and what to prioritize.
Do you offer IT support for engineering firms and technical consultancies in Salt Lake City?
Yes. Qual IT works with civil, structural, mechanical, and specialty engineering firms across Salt Lake City and Utah. We understand engineering-specific workflows, document control systems like Newforma, and the compliance requirements that come with DOT and government contracts.
Ready to Clear the Assumptions Before They Cost Your Engineering Firm?
We work with Salt Lake City engineering firms to protect project data and support technical workflows — so your engineering team can focus on delivering accurate, on-schedule project documents without IT uncertainty underneath them.
Qual IT helps Salt Lake City engineering firms identify where their systems have drifted, where project file risk has accumulated, and what needs attention before it becomes urgent during a critical project phase. Schedule your free discovery call today.

