
July 2026 | Engineering Firm Cybersecurity Utah | Summer Threat Awareness | Business Email Compromise & Subconsultant Risk
On the surface, the water looks calm. That's what makes Shark Week fascinating every year — the danger is never visible on the surface. It's already moving underneath.
Cybercriminals targeting Salt Lake City engineering firms operate the same way. The threats that civil, structural, and mechanical engineering practices face right now are designed to blend in with normal project operations — until the moment something breaks, money moves, or project files get locked by ransomware hours before a DOT submittal deadline.
During the summer months, when project teams are in the field, schedules shift to accommodate construction season, and office oversight gets thinner, cybercriminals know engineering firms are often paying less attention to what's happening in their systems. Here are three ways they're circling Salt Lake City engineering firms right now.
1. Fake Subconsultant Invoices and Vendor Impersonation
Attackers don't always need to hack your AutoCAD Civil 3D environment or breach your Newforma document control system. In many cases, they just need to send one believable email.
This is called business email compromise (BEC), and it works by impersonating a subconsultant, materials vendor, or firm principal your engineering team already trusts. The email arrives looking completely normal — it references a real project, uses the subconsultant's name, and includes a plausible invoice amount. Someone on your team processes the payment — and by the time anyone realizes the request wasn't legitimate, the engineering firm's money is gone.
These attacks spike during summer for a predictable reason: when the project engineer or principal who normally approves subconsultant invoices is out on field work or at a DOT project site, payment requests get rerouted to people who don't always know what normal looks like for that relationship. Temporary stand-ins are less likely to question urgency — and cybercriminals who have researched your firm's active projects and subconsultant relationships know exactly how to exploit that gap.
The fix is straightforward to implement: build a verification process for any financial request received via email. A quick confirmation call to the subconsultant's known office number — not the number listed in the suspicious email — is enough to stop most of these before they go anywhere. This is a foundational element of cybersecurity for Salt Lake City engineering firms that work with multiple subconsultants across active project portfolios.
2. Phishing Disguised as DOT or Client Project Communications
Phishing works because it's engineered around how project engineers and principals actually behave when they're managing multiple active deadlines.
For engineering firms, summer field season creates a predictable vulnerability: project engineers are splitting attention between field coordination and office deliverables, DOT submittal deadlines are compressing timelines, and communication volume across Procore, email, and Newforma is elevated. Cybercriminals design phishing campaigns specifically for this environment. A fake DOT project portal notification lands in an engineer's inbox. A spoofed client email requests urgent approval on a revised scope document with an embedded link. A text message that looks like it came from the firm's IT team asks for credentials to access a project file in SharePoint.
Nobody stops to verify because stopping feels like losing time on a billable project. A distracted project engineer sees what looks like a routine DOT communication and clicks the link. By the time the credential theft or malware installation is discovered, the damage to engineering documents and calculations — and to the firm's ability to deliver on active contracts — is already done.
The most effective protection isn't a software solution alone — it's culture and process. Your engineering team needs to feel empowered to slow down when something seems off, even during a busy project phase:
- An unexpected password reset for a project file in Newforma or SharePoint
- A payment or scope approval instruction that arrived via email without prior project discussion
- A link in an email claiming to be from a DOT project portal or government client they weren't expecting
Speed is a weapon attackers use against engineering firms during summer field season. Slowing down — and having a clear process for flagging suspicious project communications — is how your engineering team takes that weapon away from them. Security awareness training tailored to engineering workflows is one of the most cost-effective cybersecurity investments a Salt Lake City engineering firm can make.
3. Subconsultant Portal Supply Chain Risk
When a subconsultant with access to your Procore project environment, Newforma document control system, or shared project file server is compromised, the threat doesn't stay contained to them. It travels directly into your engineering firm's environment through whatever connection they have to your project data.
This is supply chain exposure, and most engineering firms have significantly more of it than they realize: subconsultants with active Procore logins who completed their scope months ago, software vendors with remote access credentials to workstations running AutoCAD Civil 3D or RISA, and contractors whose Newforma permissions were never revoked after a project closed — all of these create pathways into your engineering documents and calculations that most principals have never formally mapped.
Outsourcing survey work, geotech analysis, or specialty engineering to subconsultants doesn't outsource accountability for the security of your project data. DOT and government clients increasingly hold prime engineering firms responsible for the security posture of their entire project team. To understand your subconsultant supply chain exposure, you need to be able to answer three questions:
- Which subconsultants and vendors can currently access your project files, engineering documents, or internal systems?
- What exactly are they connecting to — Newforma, Procore, SharePoint, or your local project file server?
- Who inside your firm is responsible for managing and revoking that access when a subconsultant's scope is complete?
If those answers aren't documented and current, your engineering firm's IT security posture has gaps that CMMC assessors and DOT auditors will find — and that cybercriminals may find first.
By the Time You See It, It's Already Moving
Sharks don't announce themselves — and neither do the cybercriminals targeting Salt Lake City engineering firms right now.
The engineering practices that get hit aren't always the ones that ignore obvious warning signs. They're the ones who assume everything is fine because nothing looks wrong on the surface. Summer is when project schedules get compressed, field teams are stretched thin, attention drifts from the office environment, and the water looks the calmest. It's also when attackers targeting engineering IP — structural calculations, civil design files, proprietary specifications — are most active.
Proactive cybersecurity for Salt Lake City engineering firms means building the defenses before the threat arrives — not scrambling to recover project files and notify DOT clients after a breach has already occurred.
Frequently Asked Questions
What is business email compromise and how do Salt Lake City engineering firms protect against it?
Business email compromise (BEC) is a cyberattack where criminals impersonate a trusted contact — often a subconsultant, vendor, or firm principal — to trick project staff into wiring money or sharing credentials. For engineering firms, these attacks frequently reference real project names and subconsultant relationships to appear legitimate. Protection starts with verification: any financial request or access change received via email should be confirmed by phone using a known contact number before action is taken.
Why do cyberattacks targeting engineering firms increase during summer months?
Attackers look for moments when oversight is thinner. During summer field season, project engineers are split between field coordination and office deliverables, approval processes get rerouted to stand-ins, and security awareness tends to dip under deadline pressure. Cybercriminals who research engineering firms' active project portfolios and subconsultant relationships know exactly how to exploit these gaps.
How do I know if my Salt Lake City engineering firm has subconsultant supply chain risk?
If any subconsultant, vendor, or software tool has active access to your project files in Newforma, Procore, or SharePoint — and you don't have a current, documented record of what they can access and who manages that relationship — you have supply chain risk. A managed cybersecurity review can map your full subconsultant exposure and flag any access that should be revoked.
Do you offer IT support for engineering firms and technical consultancies in Salt Lake City?
Yes. Qual IT works with civil, structural, mechanical, and specialty engineering firms across Salt Lake City and Utah. We help engineering firms protect project data, manage subconsultant access, meet CMMC and DOT security requirements, and build the kind of security culture that keeps project operations running through summer field season and beyond.
Don't Wait Until You See the Fin
We work with Salt Lake City engineering firms to protect project data and support technical workflows — including subconsultant access management, phishing defense, and CMMC compliance controls.
Qual IT helps Salt Lake City engineering firms identify cybersecurity vulnerabilities, close subconsultant supply chain exposure, and build the processes that stop attacks before they halt billable project work. Schedule your free discovery call today.

