
Digital collaboration has become foundational to modern design-build delivery. Platforms like Autodesk Forma (ACC), BIM 360 and other connected project environments allow Owners, designers and builders to coordinate in real time, accelerating decision making and improving schedule alignment across increasingly complex projects.
For design-build teams pursuing federal and defense work, this digital transformation makes it more important to keep project data secure, recoverable and compliant with evolving cybersecurity requirements.
Cloud-based collaboration has made cyber resiliency part of project delivery for agencies and contractors rather than simply an IT issue.
Why Cyber Resiliency Matters to Design-Build Teams
Design-build’s integrated structure depends on uninterrupted access to shared project data. Models, drawings, RFIs, schedules, specifications and field documentation are continuously exchanged between teams and stakeholders. A disruption to that information flow can impact coordination, schedule certainty and Owner confidence.
The risk environment is also intensifying.
According to the FBI’s Internet Crime Report, ransomware complaints in the United States increased 18% in 2023, with critical infrastructure sectors among the most heavily targeted industries.
Meanwhile, the U.S. Department of Defense continues implementing the Cybersecurity Maturity Model Certification (CMMC) framework to strengthen protection of Controlled Unclassified Information (CUI) across the defense industrial base.
The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the Department of Defense’s framework for verifying that contractors in the Defense Industrial Base actually implement required cybersecurity controls, rather than simply self-attesting to them. It replaced the original five-tier 2020 model with three streamlined levels tied to established federal standards: Level 1 (Foundational) covers 17 basic safeguarding practices from FAR 52.204-21 for protecting Federal Contract Information, verified through annual self-assessment; Level 2 (Advanced) aligns with the 110 requirements in NIST SP 800-171 for protecting Controlled Unclassified Information, verified through self-assessment or third-party assessment depending on the contract; and Level 3 (Expert) applies to a small group of high-priority programs, adding enhanced NIST SP 800-172 requirements and government-led assessments to guard against advanced persistent threats. Once a required level appears in a solicitation, achieving it becomes a condition of contract award, making non-compliant contractors ineligible to bid.
For design-build firms working on federal infrastructure, military facilities or defense-related programs, compliance with standards such as NIST SP 800-171 is increasingly becoming a contractual requirement rather than a future consideration.
NIST SP 800-171 is a set of security guidelines published by the National Institute of Standards and Technology that spells out how companies should protect sensitive government information — known as Controlled Unclassified Information or CUI — when it lives on their own computer systems rather than the government’s. In plain terms, it’s the rulebook the Department of Defense uses to decide whether a contractor is handling sensitive data responsibly, and it forms the technical foundation of CMMC Level 2, the certification tier most defense contractors will need. The current version in active use, Revision 2, lists 110 specific safeguards contractors must have in place, covering things like controlling who can access sensitive systems, training employees on security practices and responding to potential breaches. A newer version, Revision 3, was finalized in 2024 and adds further requirements around supply chain security and incident response, but the Department of Defense has not yet required contractors to switch to it. So for now, compliance still centers on the Revision 2 standard.
The “Shared Responsibility” Gap in Cloud Collaboration

One of the most common misconceptions in cloud adoption is assuming a software platform alone fully protects project data.
Most cloud environments operate under a “shared responsibility model.” While software providers secure the underlying platform infrastructure, contractors and project teams remain responsible for managing, protecting, retaining and recovering their own project data.
In design-build, this responsibility becomes critical because multiple organizations work from the same information and rely on it to make decisions throughout the project.
If a ransomware attack, accidental deletion or synchronization failure impacts project files, the consequences can extend well beyond a single discipline. Delays in restoring models or documentation can disrupt coordination meetings, procurement sequencing, field operations and Owner reporting requirements.
For teams handling CUI or other sensitive project information, resiliency increasingly depends on maintaining independent recovery capabilities and clearly defined security boundaries.
Resiliency Is Becoming a Project Delivery Requirement
Federal cybersecurity guidance has moved beyond perimeter security to focus more on recoverability and continuity.
NIST SP 800-171 includes requirements related to backup and recovery, audit logging, media protection, configuration management and incident response.
NIST SP 800-171 in the Design-Build Environment
In a design-build environment, where architects, engineers and construction contractors routinely share drawings, specifications and technical data, these controls have direct operational implications:
- Access Control – Restricting project files, drawings and specifications to only the team members who need them, especially across multiple subcontractors and design partners
- Media Protection – Safeguarding physical and digital plans, blueprints and backups, whether stored on-site, in the cloud or transferred between firms
- System and Communications Protection – Encrypting sensitive design data and specifications when shared electronically between architects, engineers, contractors and the government
- Configuration Management – Controlling how project management and design software (CAD, BIM platforms, etc.) is set up and updated to prevent security gaps
- Incident Response – Having a plan to quickly detect and report any exposure of sensitive facility designs or infrastructure details
- Personnel Security – Managing access as team members rotate on and off a project, particularly with subcontractors and temporary staff
For design-build firms, the core challenge is that sensitive information like building layouts, security system designs or infrastructure plans often flows through many hands across multiple organizations before a project is complete. These requirements are meant to ensure that data stays protected at every handoff, not just within the prime contractor’s own systems.
Implications of Non-Compliance
Failing to meet these requirements carries real consequences:
- Loss of contract eligibility – Since these requirements underpin CMMC Level 2 certification, non-compliant firms can be disqualified from bidding on new DoD contracts or lose the ability to renew existing ones, including option years.
- Legal and financial exposure – Firms that misrepresent their compliance status (even unintentionally) can face liability under the False Claims Act, which allows the government to pursue penalties for false certifications, separate from any contract termination.
- Contract termination or clawbacks – A significant security gap discovered mid-contract can lead to termination for default, repayment demands or exclusion from future work with that agency.
- Cascading impact on subcontractors and partners – In a design-build structure, a security failure by one subcontractor or design partner can jeopardize the compliance status and contract eligibility of the entire project team, not just the party responsible.
- National security and safety risk – Beyond the business consequences, exposed building plans, security system designs or infrastructure details can create real vulnerabilities for military facilities, critical infrastructure or other sensitive sites that adversaries could exploit.
- Reputational damage – A publicized breach or compliance failure can make it harder to win future government or even private-sector work, particularly for firms that market themselves as trusted partners on sensitive projects.
In short, non-compliance isn’t just a paperwork problem. It can end a firm’s ability to compete for defense work altogether, expose it to legal risk and, in the worst cases, compromise the physical security of the facilities it was hired to build.
Granular Recovery Reduces Project Disruption
Large design-build programs generate massive volumes of continuously changing project data, including drawings, models, schedules, submittals and coordination records. When that information is lost, corrupted or compromised, the impact can extend quickly across the delivery team.
Native cloud recovery tools may not always support rapid restoration at the file, folder or model-version level. More granular restoration capabilities can help teams recover from accidental deletions, restore specific model versions, minimize coordination downtime and reduce broader schedule impacts. In integrated project environments, faster recovery helps preserve momentum across the entire delivery team.
Audit Readiness Supports Owner Confidence
Cybersecurity compliance is increasingly tied to documentation and traceability. Design-build teams pursuing federal work may need to demonstrate who accessed project information, how data was protected, whether backups were verified and how incidents would be managed.
Maintaining audit-ready records can support CMMC assessments, insurance requirements, Owner reporting obligations and long-term asset handover expectations. Just as important, it can help build Owner confidence by showing that the team has a clear, documented approach to protecting project information and maintaining continuity.
The Growing Risk Surface of Connected Construction

The rise of digital twins, connected jobsite technologies and cloud-based collaboration continues to expand the construction industry’s cyber risk surface. IBM’s 2026 Cost of a Data Breach Report found that the global average cost of a data breach reached a record $4.99 million, up 12% from the previous year.
Construction firms are becoming more attractive cyber targets because project delivery often depends on distributed teams, third-party data sharing, mobile field access and complex supply chain relationships. For design-build organizations, resiliency planning increasingly needs to extend beyond traditional IT considerations and into operational continuity planning.
That means evaluating independent backup strategies, recovery time objectives, malware protection, access controls and long-term data retention policies as part of a broader project delivery risk strategy.
Building Resiliency Into Integrated Delivery
Design-build is fundamentally built on collaboration, integration and shared accountability. As project delivery becomes more digitally connected, those same principles increasingly apply to cybersecurity and data governance.
Organizations are beginning to treat cyber resiliency as part of maintaining reliable project delivery performance, not merely as a standalone compliance exercise.
For some firms, that may involve strengthening synchronization and recovery layers between cloud collaboration tools and independently controlled storage environments. Others are focusing on audit visibility, retention management or incident recovery planning as part of broader risk management strategies.
Technology providers like SIINC are part of a growing ecosystem supporting these resiliency efforts across cloud-based construction environments, particularly for firms operating in regulated sectors.
Looking Ahead
Cloud collaboration platforms have transformed how design-build teams coordinate projects, improve visibility and accelerate delivery. But as digital integration increases, so does the importance of ensuring project information remains resilient, recoverable and compliant.
For firms pursuing federal and defense work, cybersecurity readiness is rapidly becoming intertwined with project readiness. The organizations that proactively strengthen their data resiliency strategies today may be better positioned to maintain continuity, protect Owner trust and compete for tomorrow’s most security-sensitive projects.

Ross Semplice, Head of Sales and Global Channels at SIINC is a senior strategist and U.S. Army Veteran with over 25 years of experience specializing in cybersecurity, data sovereignty and digital transformation within the AEC and manufacturing sectors. He applies disciplined risk management and technical expertise to help organizations safeguard digital assets and ensure operational continuity across major industry platforms.
