Engineering Inc - July/August 2019 - 25

THE IMPORTANCE OF STAFF TRAINING

Because hackers rely so heavily on phishing and spear phishing to
steal credentials and penetrate networks, it is essential that staffers
be trained to distinguish legitimate emails from fraudulent ones-a
skill that has grown more difficult as hackers have become more
sophisticated. Whereas phishing emails were once littered with
spelling errors and grammatical mistakes, they now sometimes
contain official corporate logos and utilize detailed knowledge of
organizational charts.
Effective training sessions will also cover other, often overlooked,
aspects of cybersecurity. For example, hackers will sometimes set
up unsecured Wi-Fi connections in public spaces like airports, and
then use those connections to steal credentials and data from unsuspecting employees. Without cybersecurity training, some staffers
may not know that such an attack is possible.
"It all starts with education," Nelson says. "That is one of the
things we have really beefed up as an organization. We have cybersecurity as a module in our onboarding for our new employees,
and we conduct training on an ongoing basis throughout the year.
Everybody is exposed to all the tricks of the trade and the things
they might be asked to do. It has proven to be one of the most effective tools we could put in place."
Nelson's firm conducts its own training sessions, but he notes that
smaller firms can bring in outside consultants to educate staffers.
Herlihy says his company works with a consultant to put employees through cybersecurity training. The consultant even sends out
(harmless) phishing emails to staffers to see whether they click
on bogus links. "We were taught to hover over the sender's email
address to see whether there might be
something slightly different from the
real email address," Herlihy says. "That
training is critical."
Buchheit says there is one central
message to the anti-phishing training
that staffers at his firm receive. "Whatever you do, do not click on the attachment," he says. "Instead, we tell people
to forward the message to IT. They
have the ability to figure out where it
originated. They can extract metadata,
"Nearly all
then use that information to inform
businesses
our filters and block future attempts."

are at least
asking to get
quotes for
cybersecurity
insurance."

MIKE HERLIHY
EXECUTIVE VICE
PRESIDENT AND
PARTNER
AMES & GOUGH
MEMBER, ACEC
RISK MANAGEMENT
COMMITTEE

COVERING
AGAINST LOSSES

Only a few years ago, cybersecurity
insurance policies were nearly unheard
of. Some liability policies covered
firms if they accidentally shared
infected files with their clients, but
stand-alone cybersecurity policies that
cover a firm's own losses are relatively
new.
Still, Herlihy estimates that 60 to
70 percent of his clients are opting
for cybersecurity coverage. "Nearly
all businesses are at least asking to get

A 13-POINT RISK
MANAGEMENT CHECKLIST
When firms attempt to obtain cybersecurity insurance,
they will likely be asked if they have put the following
precautions in place:
1.

Up-to-date, active firewall technology

2.

Patch management

3.

Multifactor login for privileged access

4.

Remote access limited to VPN

5.

Incident response plan

6.

Media and website content controls

7.

Require service providers to demonstrate adequate
network security

8.

Updated anti-virus software active on all computers
and networks

9.

Intrusion detection software

10. Data backup procedures
11. Procedure to test or audit network security controls
12. Disaster recovery plan or business continuity plan
13. A person or department responsible for
information security

quotes for cybersecurity insurance," he says. "Certainly, when a
company is up for renewal, we are advising them that they should
be carrying it. Another factor driving the decision for engineering
firms to purchase cybersecurity insurance is that some clients
are insisting in their contracts that firms have standalone cyber
insurance policies."
Nelson says his firm began carrying cybersecurity insurance
three to four years ago. He recommends that firms not only buy
coverage but also carefully evaluate different providers and their
ability to help a company respond to a cyberattack.
"If you just buy a cyber policy, you can report back to your
board that you have it, but there is a lot of due diligence you need
to do to make sure the policy is meaningful," he says. "You are
hiring a partner-more so than almost any other insurance-by
way of someone who has a dedicated team that can respond to
an event immediately, help you sort out how it happened, and
remedy your system to get you back up and operating."
According to Herlihy, that type of partnership can help firms
not only to respond to attacks but also to prevent them.
"Even if you do not have a claim for a loss, there is a lot of
useful information [during the approval process] that helps people
figure out how to design a program to protect themselves," he
says. "You are getting a lot of upfront help, in hopes that you
never have a claim. It is definitely money well spent." n
Calvin Hennick is a business, technology and travel writer based in
Milton, Massachusetts.

JULY / AUGUST 2019

ENGINEERING INC.

25



Engineering Inc - July/August 2019

Table of Contents for the Digital Edition of Engineering Inc - July/August 2019

Engineering Inc. - July/August 2019
Contents
From Acec to You
Market Watch
Legislative Action
The Private Side
From A Global Perspective
Navigating A New Future
Protecting Your Firm Against Cyberattacks
Pli Market Remains Steady
A Half-Century Of Caring
2019 Acec Member Survey
Risk Management
In The News
Mergers And Acquisitions
Members In The News
Business Insights
Engineering Inc - July/August 2019 - Intro
Engineering Inc - July/August 2019 - Engineering Inc. - July/August 2019
Engineering Inc - July/August 2019 - Cover2
Engineering Inc - July/August 2019 - T1
Engineering Inc - July/August 2019 - T2
Engineering Inc - July/August 2019 - T3
Engineering Inc - July/August 2019 - T4
Engineering Inc - July/August 2019 - T5
Engineering Inc - July/August 2019 - T6
Engineering Inc - July/August 2019 - T7
Engineering Inc - July/August 2019 - T8
Engineering Inc - July/August 2019 - Contents
Engineering Inc - July/August 2019 - 2
Engineering Inc - July/August 2019 - 3
Engineering Inc - July/August 2019 - From Acec to You
Engineering Inc - July/August 2019 - 5
Engineering Inc - July/August 2019 - Market Watch
Engineering Inc - July/August 2019 - 7
Engineering Inc - July/August 2019 - Legislative Action
Engineering Inc - July/August 2019 - 9
Engineering Inc - July/August 2019 - The Private Side
Engineering Inc - July/August 2019 - 11
Engineering Inc - July/August 2019 - From A Global Perspective
Engineering Inc - July/August 2019 - 13
Engineering Inc - July/August 2019 - 14
Engineering Inc - July/August 2019 - 15
Engineering Inc - July/August 2019 - 16
Engineering Inc - July/August 2019 - 17
Engineering Inc - July/August 2019 - Navigating A New Future
Engineering Inc - July/August 2019 - 19
Engineering Inc - July/August 2019 - 20
Engineering Inc - July/August 2019 - 21
Engineering Inc - July/August 2019 - Protecting Your Firm Against Cyberattacks
Engineering Inc - July/August 2019 - 23
Engineering Inc - July/August 2019 - 24
Engineering Inc - July/August 2019 - 25
Engineering Inc - July/August 2019 - 26
Engineering Inc - July/August 2019 - Pli Market Remains Steady
Engineering Inc - July/August 2019 - 28
Engineering Inc - July/August 2019 - 29
Engineering Inc - July/August 2019 - 30
Engineering Inc - July/August 2019 - 31
Engineering Inc - July/August 2019 - 32
Engineering Inc - July/August 2019 - 33
Engineering Inc - July/August 2019 - 34
Engineering Inc - July/August 2019 - 35
Engineering Inc - July/August 2019 - A Half-Century Of Caring
Engineering Inc - July/August 2019 - 37
Engineering Inc - July/August 2019 - 38
Engineering Inc - July/August 2019 - 39
Engineering Inc - July/August 2019 - 2019 Acec Member Survey
Engineering Inc - July/August 2019 - 41
Engineering Inc - July/August 2019 - Risk Management
Engineering Inc - July/August 2019 - 43
Engineering Inc - July/August 2019 - In The News
Engineering Inc - July/August 2019 - 45
Engineering Inc - July/August 2019 - Mergers And Acquisitions
Engineering Inc - July/August 2019 - 47
Engineering Inc - July/August 2019 - 48
Engineering Inc - July/August 2019 - Members In The News
Engineering Inc - July/August 2019 - 50
Engineering Inc - July/August 2019 - 51
Engineering Inc - July/August 2019 - Business Insights
Engineering Inc - July/August 2019 - Cover3
Engineering Inc - July/August 2019 - Cover4
https://www.nxtbook.com/nxtbooks/acec/engineeringinc_spring2020
https://www.nxtbook.com/nxtbooks/acec/engineeringinc_winter2020
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1119
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0919
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0719
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0519
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0319
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0119
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1118
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0918
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0718
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0518
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0318
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0118
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1117
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0917
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0717
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0517
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0317
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0117
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1116
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0916
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0716
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0516
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0316
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0116
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1115
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0915
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0715
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0515
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0315
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0115
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1114
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0914
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0714
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0514
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0314
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0114
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1113
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0913
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0713
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0513
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0313
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0113
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1112
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0912
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0712
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0512
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0312
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0112
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1111
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0911
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0711
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0511
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0311
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0111
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1110
https://www.nxtbook.com/nxtbooks/acec/engineeringincSeptOct
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0910
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0710
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0510
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0310
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0110
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1109
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0909
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0709
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0309
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0109_v2
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0109
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1108
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0908
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0708
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0508
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0308
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0108
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1107
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0907
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0707
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0507
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0307
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0107
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0505
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0305
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1105
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0306
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0105
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1103
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0906
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0903
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0703
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0106
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0506
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0503
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0303
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0904
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1104
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0704
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0504
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0304
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0905
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0705
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0104
https://www.nxtbook.com/nxtbooks/acec/engineeringinc1106
https://www.nxtbook.com/nxtbooks/acec/engineeringinc0706
https://www.nxtbookmedia.com