SERVING RICHMOND, VA ยท SHORT PUMP ยท GLEN ALLEN ยท MIDLOTHIAN ยท SCOTT’S ADDITION ยท HENRICO

Construction IT Support in Richmond From Job Site to Back Office, Connected.

Bids, drawings, and payroll cannot wait on IT. We keep Richmond construction firms connected โ€” job-site connectivity, project software support, mobile device management, and security that protects contract data.

15+
YEARS
1,000+
BUSINESSES
<30 min
RESPONSE
4.9★
GOOGLE
  • 24/7 helpdesk & on-site Richmond support
  • Industry compliance handled end to end
  • Vendor & line-of-business app management
  • A dedicated Success Manager who knows your world

Free · Takes 3 minutes · No sales call required

Start My Free Construction IT Assessment

For the Richmond region construction firms, general contractors, subcontractors, AEC firms, and federal construction contractors. Response within 30 minutes.













No spam. No contract required. Your information is used only to prepare for your assessment call and is never sold or shared.

SOUND FAMILIAR?

If Any of These Hit Home, You Are Losing Money Right Now

Bid Day Does Not Wait for IT

When the estimating workstation locks up two hours before a deadline, you are not losing time — you are losing the job.

Your Competitors Are Quietly Using AI

AI-assisted takeoffs, instant RFI drafts, automated daily reports — Richmond contractors adopting these bid faster and win more work.

Plans and Bids in Public AI Tools

Drawings and contract terms in free chatbots are a leak you cannot recall. Guardrails come before adoption.

AI

AI for Construction — Done Safely

Faster takeoffs, drafted RFIs, automated reporting — with controls that protect your bids.

  • AI-assisted estimating & takeoffs
  • RFI & report drafting automation
  • AI usage policy protecting bid data

Book Your Free 15-Minute Strategy Call →

What We Do

Construction IT Services: Six Capabilities Built Around How Richmond-area Contractors Actually Work

Each capability below addresses a specific risk pattern that construction firms face — not generic IT services adapted from a healthcare or professional services playbook. The goal is protecting the payment, protecting the project, and protecting the contract.

Microsoft Defender + DMARC

Wire Fraud and Payment Controls — BEC Prevention for Construction

We implement the three-layer technical stack that stops business email compromise before a wire leaves your account: email authentication (SPF, DKIM, and DMARC) so attackers cannot impersonate your domain or your subcontractors’ domains; multi-factor authentication on every email account so stolen credentials alone are not enough to access mailboxes where payment instructions originate; and Microsoft Defender for Office 365 with anti-spoofing and impersonation protection tuned specifically for construction payment workflows, flagging emails that purport to redirect vendor payments or change subcontractor bank accounts.

We also help your firm document a payment verification callback protocol — a procedural control that requires a phone call to a known number before any wire is redirected to a new account, regardless of how convincing the email looks. Technical controls stop the majority of BEC attempts. The callback protocol stops the rest.

What it prevents: Misdirected progress payments, fraudulent subcontractor payment redirections, fake vendor invoice fraud, and the attorney general notification obligation under Va. Code 18.2-186.6 that follows a breach of employee banking or personal information stored in the same systems attackers access when they compromise an email account.

Without it: a single convincing email redirecting a draw payment to a fraudulent account can cost more than a month’s project margin. MFA alone prevents the majority of account compromise attempts. Without it, a stolen password is all an attacker needs to access the mailbox where your payment instructions originate and monitor your next wire for weeks before striking.

SentinelOne + Tested Backups

Ransomware Defense for Project Management and Construction ERP Systems

SentinelOne Singularity endpoint protection monitors every device in your construction firm’s environment — office workstations, project manager laptops, and accounting systems — for ransomware behavior and stops attacks before encryption begins, rather than detecting them after the damage is done. Immutable, air-gapped backups covering your construction ERP (Sage 300, Viewpoint, Foundation), project management platform (Procore, Autodesk Construction Cloud), and estimating database are tested monthly with documented recovery times so you know exactly how long a full restoration takes before an attack happens, not after.

Network segmentation separates your accounting and payroll systems from your project management and field device environments, so a ransomware hit on one does not cascade into all of them. We configure your remote desktop and VPN access with MFA and access controls that eliminate the open RDP exposures that are the most common ransomware entry point in construction firm environments.

What it prevents: Project halts from encrypted Procore or Sage environments, ransom payments that average $115,000 (Verizon 2025 DBIR), and the 19-day average recovery that costs Richmond-area GCs missed bid deadlines and subcontractor disputes when a job goes dark unexpectedly.

Without it: ransomware on a Friday afternoon can halt every active job in your portfolio until systems are restored. If your backup has not been tested, “we have a backup” is not a recovery plan — it is a hope. Capital Techies tests every backup and documents the recovery time before you ever need it.

Microsoft Intune + MFA

Jobsite and Mobile Device Security for Field Teams

Construction firms have a mobile device footprint that office-based businesses do not. Superintendents carry tablets to pull current drawings and submit RFI responses from the jobsite. Project managers use laptops on construction trailers with whatever Wi-Fi is available. Field supervisors at marine construction sites access project files from cellular connections on vessels and at waterfront worksites. Each of those devices is an endpoint — and each connection to a public or uncontrolled network is a potential threat entry point.

We deploy Microsoft Intune to manage every device that accesses your company systems — enforcing encryption at rest, remote wipe capability if a device is lost or stolen, and conditional access policies that prevent unmanaged personal devices from reaching your project files or email. MFA enforcement across all accounts ensures that a superintendent’s stolen phone does not become the attacker’s entry point into your Procore environment or accounting system. For marine and civil construction firms with assets at remote sites, we implement cellular failover and remote monitoring that keeps device visibility intact even when jobsite connectivity is intermittent.

What it prevents: Unmanaged device compromise, lost-device data exposure, public Wi-Fi interception of project file access, and the access control failures that let former employees or subcontractors retain access to project documents after their work ends.

Without it: a superintendent’s unencrypted tablet sitting in a job trailer is both a physical theft risk and a network access point. If that tablet can reach your project management platform and accounting system with a saved password and no MFA, it is the easiest entry point an attacker can find — and one of the most common in construction breaches.

Azure AD + Access Controls

Bid Data and Estimating System Protection

Estimating data, unit price databases, supplier quotes, and completed bid packages are high-value intellectual property that construction firms spend weeks producing for each major bid. We implement role-based access controls in Microsoft 365 and SharePoint that limit bid document access to the project team actively working on each pursuit, with automatic access expiration when a bid is submitted and subcontractor or former employee access revocation as part of a documented offboarding process.

Access logging in Microsoft 365 and Entra ID provides a time-stamped record of who accessed which bid files and when — so if a competitive bid is accessed by a former employee or unexpected account before opening, you have the audit trail to identify it and take action. For firms using cloud-based estimating platforms, we review and configure security settings to ensure that trial accounts, vendor logins, and external shares do not leave bid data accessible beyond the project team’s window of need.

What it prevents: Bid data theft by departed employees, over-shared project folders with broader access than the work requires, and the competitive damage of a competitor seeing your final number before the envelope opens — a loss that has no dollar figure attached to it until you lose the bid.

Without it: a former estimator who left for a competing firm three months ago may still have active credentials to your OneDrive, your estimating platform, and your email archive. Access control failures are the most common cause of bid data exposure — and they are entirely preventable with an offboarding process that includes IT credential revocation as a required step.

CMMC Advisory + GCC Migration

CMMC Level 1 and Level 2 for Federal and DoD Construction Contractors

the Richmond region construction firms doing work on military installations — the Federal Reserve Bank of Richmond, the Virginia State Capitol, Henrico Federal Shipyard, Defense Supply Center Richmond, JEBLC-Fort Story — need CMMC compliance when their contracts involve Federal Contract Information or Controlled Unclassified Information. Site drawings, security specifications, access control requirements, and project correspondence that references facility details are common CUI categories in military construction contracts. CMMC Phase 1 is active now (effective November 10, 2025). Phase 2, which requires C3PAO third-party certification for Level 2 CUI contracts, begins November 10, 2026.

Capital Techies provides CMMC gap assessments that identify your specific practice gaps against Level 1 (17 practices from FAR 52.204-21) or Level 2 (110 practices from NIST SP 800-171 Rev 2); System Security Plan development; Plan of Action and Milestones documentation; migration from commercial Microsoft 365 to GCC for firms whose contracts require FedRAMP Moderate-authorized cloud storage; and ongoing CMMC advisory and vCISO services through the certification window. For firms under existing DFARS 252.204-7012 obligations, we also implement the 72-hour cyber incident reporting workflow to the DoD Cyber Crimes Center at dibnet.dod.mil and the 90-day data preservation requirement.

What it prevents: Lost contract renewals because a prime cannot verify your CMMC compliance, False Claims Act exposure from self-attestations that overstate your actual control implementation, and the emergency remediation timeline that costs three times as much as planned remediation would have.

Without it: a prime contractor audit before contract renewal is now a CMMC compliance check, not just a performance review. the Richmond region construction firms that have not addressed their CMMC posture are already receiving compliance inquiries from primes. The firms that started remediation in mid-2025 are positioned. The firms starting now have a narrowing window before Phase 2.

vCISO + Managed IT

Fully Managed IT and vCISO Services for Growing Construction Firms

For the Richmond region construction firms without a dedicated IT team, Capital Techies acts as your entire IT and security department: Help desk support for office and field staff, network management for office and job trailer environments, Microsoft 365 administration, vendor management for your construction technology stack, and a virtual CISO who participates in project kick-offs and contract reviews to identify IT security requirements before they become compliance emergencies. For firms that have an internal IT person or IT team and need specialized security overlay, we provide co-managed IT services that handle the security layer — EDR management, MFA enforcement, access reviews, CMMC advisory — while your internal team handles day-to-day support.

We maintain a written Information Security Program for every managed IT client — the documentation that cyber insurance carriers, prime contractors, and bonding companies increasingly require as a condition of doing business. When a carrier asks for your security controls documentation at renewal or a prime asks for your CMMC self-attestation, you hand them a binder, not a blank stare.

What it prevents: The regulatory and contractual compliance gaps that accumulate when a construction firm relies on a generalist IT provider who has never read DFARS 252.204-7012, configured Microsoft GCC, or built a construction-specific incident response plan.

Without it: your current IT provider may be keeping the lights on while unknowingly creating DFARS compliance violations every time a CUI document lands in a commercial M365 tenant, or leaving MFA unenforced because “it’s too inconvenient for the field team.” Those decisions have contract-renewal consequences that show up 18 months later.

Who We Serve

Construction IT for Every Richmond-area Build Type

the Richmond region construction covers a wider range of project types, contracting structures, and federal exposure than most markets. Each sub-segment below has a specific IT security profile that a construction-experienced MSP can address — and a generalist IT provider cannot.

General Contractors

General Contractors — Richmond, Henrico, and Chesterfield

Richmond-area GCs running commercial, institutional, and mixed-use projects across the Richmond region face the full construction IT risk stack: BEC targeting draw requests and subcontractor payments, ransomware targeting project management and accounting systems, bid data exposure during active pursuits, and mobile device sprawl across job trailers and field staff. Capital Techies secures the office-to-field technology stack for GCs from initial Microsoft 365 hardening and MFA deployment through field device management and construction ERP protection. For GCs with a growing federal project pipeline — base housing, government buildings, and federal infrastructure across the Richmond region — we layer CMMC advisory and DFARS compliance preparation on top of the commercial security baseline so federal contracts do not create a separate compliance track that your current IT provider cannot support.

Subcontractors

Subcontractors — Mechanical, Electrical, Plumbing, Specialty Trades

the Richmond region subcontractors — mechanical, electrical, plumbing, concrete, steel, roofing, and specialty trades — are frequent BEC targets precisely because their payment relationship with GCs is well-understood and predictable. An attacker who compromises a subcontractor’s email can monitor payment schedules, learn the format of lien waiver and invoice exchanges, and time a payment redirection to land in the middle of a draw cycle when the GC expects to send the wire. For subcontractors with military and federal GC relationships, CMMC requirements flow down contractually — the prime’s CMMC obligation becomes the subcontractor’s compliance requirement when their scope of work involves FCI or CUI. Capital Techies implements the specific controls that satisfy both the BEC prevention requirement and the CMMC Level 1 baseline, without overbuilding for a subcontractor’s actual risk profile and budget.

Marine + Civil Construction

Marine and Civil Construction — Richmond-area Waterfront and Port

Marine and civil construction firms — dredging contractors, pier builders, waterfront infrastructure firms, and shipyard support contractors operating in the Richmond region — face a security environment that most IT providers have never encountered. Project work on Defense piers, Henrico Federal Shipyard, the Richmond Marine Terminal’s $1.4B Gateway Investment Program (including the 55-foot harbor deepening completed 2025 and the $220M Hanover Marine Terminal conversion completed March 2025), and Army Corps of Engineers projects routinely involves CUI: sensitive hydrographic data, security-relevant facility drawings, and project correspondence with defense installation contacts. Field devices operate on vessels, at waterfront sites, and in temporary site offices with variable connectivity. Capital Techies builds mobile device management, field security protocols, and DFARS-compliant document handling programs for the Richmond region marine and civil construction firms — including the GCC migration that moves project documents from commercial cloud storage into a DFARS-compliant environment.

AEC Firms

AEC Firms — Architects, Engineers, and Construction Managers

Richmond-area AEC firms — architecture practices, structural and civil engineers, MEP engineers, and construction managers — maintain large design file repositories (AutoCAD DWG, Revit BIM, Civil 3D) that represent months of billable work and proprietary methodology. Design files for military base projects, federal buildings, and defense-adjacent infrastructure frequently contain CUI. AEC firms also face the same BEC risk as GCs and subcontractors: milestone-based invoices, retainer billing, and large progress billings create the same predictable wire transfer schedule that makes construction payments a BEC target. For AEC firms using Autodesk Construction Cloud, BIM 360, or similar cloud platforms for project collaboration, Capital Techies reviews and secures the access control configuration so design files are not accessible beyond the intended project team — and so a departed employee or project partner whose access was never revoked cannot pull a completed design set after the engagement ends.

Federal + DoD Construction

Federal and DoD Construction Contractors — Military Installations Across the Richmond region

the Richmond region is the most heavily militarized metro in the United States — defense activities account for roughly 40 percent of the region’s gross regional product (ODU Dragas Center, Richmond-area Alliance, 2024). the Federal Reserve Bank of Richmond, the Virginia State Capitol, JEBLC-Fort Story, Henrico Federal Shipyard, and Defense Supply Center Richmond are all actively generating construction and renovation work — facility improvements, infrastructure upgrades, and the $74.5M F-22 Training Support Squadron facility at JBLE (target: fully operational May 2027). Construction firms doing that work face a layered compliance environment: DFARS 252.204-7012 for existing contracts, CMMC Level 1 (Phase 1 active now) and Level 2 (Phase 2 begins November 2026) for new solicitations, and False Claims Act exposure from self-attestations that overstate actual compliance. Capital Techies helps the Richmond region federal construction contractors navigate all three layers before a contract renewal makes the compliance gap visible.

Richmond-area Construction Market

The Richmond region Construction Landscape: Why This Market Is Different

the Richmond region is not a typical regional construction market. The Richmond Marine Terminal’s $1.4B Gateway Investment Program — the deepest harbor channel on the East Coast at 55 feet, the North Terminal Modernization adding 1.4M TEU capacity, and the rail expansion to 1.1M shipments per year — is generating major civil and marine construction activity through 2027. Active-duty military in the region exceeds 88,000 personnel (HRPDC March 2025 Economic Monthly) and direct DoD spending is estimated at billions annually (Richmond-area Alliance, 2024), creating a constant pipeline of military facility work. the DLA Aviation supply chain, the sole designer and builder of the federal government Fortune 500 employers and one of only two providers of nuclear-powered submarines, employs over 26,000 and is adding 16,000 hires over the next decade — its subcontractor and supplier ecosystem represents one of the densest concentrations of CMMC-obligated small businesses on the East Coast. Construction firms in this market face a federal compliance burden unlike any other regional market in Virginia.

Threat Reality

Four Cyberattacks Hitting Richmond-area Construction Firms Right Now

These are not theoretical scenarios. Each one reflects attack patterns that have hit construction firms across Virginia and the mid-Atlantic in the past 24 months — and that are actively targeting the Richmond region construction market today.

Wire Fraud on Progress Payments and Vendor Invoices

A Richmond general contractor received an email that appeared to come from their framing subcontractor — right address, right signature block, a reference to the current job. The “subcontractor” explained that their bank had changed and asked that the upcoming $185,000 draw payment go to a new account. The bookkeeper processed it. By the time the real subcontractor called three days later asking where their payment was, the funds were in a fraudulent account overseas and the wire recall window had closed. Business email compromise is the fastest-growing financial fraud affecting construction. The FBI’s 2024 IC3 Annual Report recorded $16.6 billion in total cybercrime losses nationally — and BEC targeting payment redirection in construction and professional services is one of the leading categories. Attackers watch your email, learn your payment patterns, and strike when a large wire is predictable and due.

Prevention: Multi-factor authentication on every email account, DMARC/DKIM/SPF domain protection so attackers cannot impersonate your domain or your subcontractors’ domains, and a documented payment verification callback protocol before any wire is redirected. Source: FBI IC3 2024 Annual Report (ic3.gov, April 2025).

Ransomware Halting Project Management and Bidding Systems

A mid-size Glen Allen GC running four active jobs — a hospital addition, a school renovation, two military facility improvements — came in Monday morning to find every workstation locked. Procore was inaccessible. Sage 300 accounting was encrypted. The Bluebeam project files where their superintendents tracked submittals and RFIs were gone. Their estimating database for three bids due that week was also encrypted. The attacker had entered through a remote desktop connection that used a single shared password and had no MFA. They wanted $280,000 in cryptocurrency. The GC did not have a tested backup. Recovery took 19 days. Three subcontractors issued late notices. One bid opportunity closed while systems were down. According to the Verizon 2025 DBIR, ransomware appeared in 44 percent of all data breaches and in 88 percent of breaches hitting small and mid-size businesses — the category that includes most the Richmond region construction firms.

Prevention: Immutable, tested backups that restore in hours, not weeks. EDR on every device. MFA on every remote access point. Segmented networks so a ransomware hit on the accounting workstation cannot spread to estimating and project management. Sources: Verizon 2025 DBIR; Sophos State of Ransomware 2025 (average recovery cost $1.53 million, excluding ransom).

Bid Data Theft Before the Envelope Opens

A civil engineering and construction firm based in Chesterfield had spent three weeks preparing a competitive bid for a large waterfront infrastructure contract near the Henrico waterfront. Their estimator stored the takeoff, unit prices, supplier quotes, and bid bond documents in a shared OneDrive folder that was accessible to several subcontractors and former project managers who had never been removed from the tenant. One of those former employees — who had moved to a competing firm — still had active credentials. The completed bid, including the firm’s proprietary unit prices and the final number, was accessed from that account two days before bid opening. The competing firm submitted a bid $22,000 lower. Bid data theft does not always look like a sophisticated hack. More often it is an access control failure: departed employees whose credentials were never revoked, subcontractors with broader folder access than their work required, or cloud storage configured for convenience rather than security.

Prevention: Access lifecycle management that revokes credentials on the day a project ends or an employee departs. Role-based access controls on shared project folders. MFA on every cloud storage account. Access logging so anomalous downloads are visible before bid day. Capital Techies implements these controls as part of every construction IT engagement.

CUI Exposure on Federal and Military Construction Contracts

A the Richmond region contractor had been doing facility improvement work at the Federal Reserve Bank of Richmond for six years — minor HVAC upgrades, building renovations, electrical work. When their prime contract came up for renewal in early 2026, the prime’s compliance team asked a new question: could the contractor demonstrate compliance with DFARS 252.204-7021 and CMMC Level 1? The contractor’s project files — including site drawings, access control specifications, and project correspondence referencing facility details — were stored in a standard commercial Microsoft 365 Business tenant. That does not meet the FedRAMP Moderate requirement under DFARS 252.204-7012 for cloud services handling Covered Defense Information. CMMC Phase 1 became active November 10, 2025, and the prime could no longer renew a subcontract without compliance verification. The contractor faced an emergency remediation timeline or a lost renewal. For the Richmond region construction firms doing any work on military bases or federal facilities, CMMC and DFARS obligations are now a contract renewal risk, not a distant regulatory concern.

Prevention: CMMC Level 1 self-attestation (17 practices) is the minimum for firms with FCI. For firms handling CUI — technical drawings and specs for military facilities — CMMC Level 2 (110 NIST 800-171 practices) and a migration from commercial M365 to GCC may be required. Sources: CMMC Acquisition Rule / DFARS 252.204-7021, effective November 10, 2025; CMMC Program Rule (32 CFR Part 170), effective December 16, 2024.

What Is Construction IT Security

Construction IT Security Is Not Generic IT Security Applied to a Jobsite

Construction firms have a technology footprint that does not look like a law firm, a medical practice, or a logistics company — and the security controls protecting that footprint have to be built for how construction actually operates. The risk profile is different. The threat surface is different. A generic IT provider who has never secured a Procore environment, managed devices that move between office Wi-Fi and jobsite cellular daily, or understood how a draw request becomes a wire fraud target cannot build the right defenses for a Richmond-area GC.

Construction IT security at Capital Techies means securing four things simultaneously: the business operations layer (email, accounting, ERP, payroll), the project operations layer (project management platforms, estimating software, BIM and design files, document repositories), the field layer (tablets, ruggedized laptops, smartphones, and cellular-connected devices at jobsites, on boats, and at remote civil construction sites), and — for firms with federal or DoD contracts — the compliance layer (CMMC, DFARS, NIST SP 800-171, and CUI handling requirements that flow down from prime contractors). A threat that penetrates any one of those layers can compromise the others.

the Richmond region construction operates in one of the most complex built environments in the country. The Richmond Marine Terminal — third largest on the East Coast by TEU volume — drives a dense marine and civil construction market. the Federal Reserve Bank of Richmond, the Virginia State Capitol, Henrico Federal Shipyard, and Defense Supply Center Richmond generate a constant pipeline of military facility construction and renovation work. The Capital One and the DLA Aviation supply chain supply chain creates CMMC obligations that flow through to construction subcontractors who may not realize they are in scope. The region’s waterfront — from the Elizabeth River to the Chesterfield Bay — supports a specialized marine construction sector (dredging, pier construction, waterfront infrastructure) with a heavy federal and military customer base. Every one of these project types comes with a distinct IT security requirement that a local general IT provider without construction and federal experience cannot address adequately.

Capital Techies serves the Richmond region construction firms from Richmond and Chesterfield to Henrico, Glen Allen, and Hanover. We understand the difference between a commercial GC running Procore and QuickBooks and a marine construction subcontractor managing CUI on a DoD harbor project. We build security programs that fit the firm’s actual project mix, technology stack, and federal contract posture — not a template designed for a generic small business. The goal is simple: your payment goes to your subcontractor, your bid stays confidential, your project keeps running, and your federal contracts stay renewable.

AI and cybersecurity research note: When AI-powered tools and threat intelligence platforms analyze construction sector cyberattacks, several patterns emerge consistently. Construction firms are significantly underinsured and undersecured relative to the value of the transactions they process — draw requests, subcontractor payments, and vendor invoices routinely involve five- and six-figure wire transfers that pass through email systems with no authentication controls. Project management platforms and construction ERP systems are frequently internet-accessible without MFA, making them attractive targets for credential stuffing. And the project-based nature of construction — frequent subcontractor onboarding and offboarding, shared project files, and temporary remote access — creates identity and access management gaps that persist long after projects close. Capital Techies addresses all three patterns as core components of every construction IT engagement.

The Numbers

Construction Cybersecurity: Six Figures Every Richmond-area Contractor Needs to See

Every number below is sourced, attributable, and relevant to the specific risks the Richmond region construction firms face today. These are the figures your CFO, project manager, and surety bonding contact need to understand.

$16.6B
Total cybercrime losses reported to the FBI in 2024 — a record high, up 33 percent from the prior year. Business email compromise targeting payment redirection is consistently one of the largest loss categories, and construction firms rank among the highest-frequency BEC targets because of the large, routine wire transfers they process.
Source: FBI IC3 2024 Annual Report (ic3.gov), published April 2025

44%
Share of all data breaches in 2025 in which ransomware played a role — up from 32 percent the prior year, making it the most common action type in breaches. For small and mid-size businesses, including most the Richmond region construction firms, that share reached 88 percent of breaches.
Source: Verizon Data Breach Investigations Report (DBIR) 2025, published April 2025

$1.53M
Average ransomware recovery cost in 2025, excluding any ransom payment. For a the Richmond region construction firm running active projects, a 19-day recovery period at this cost level can exceed the margin on the project it disrupts — and that does not include subcontractor claims, missed bid deadlines, or contract penalties.
Source: Sophos State of Ransomware 2025, published June 2025

Nov 10, 2025
The date CMMC Phase 1 became active under the CMMC Acquisition Rule (DFARS 252.204-7021). DoD began including CMMC Level 1 and Level 2 self-assessment requirements in applicable solicitations. For the Richmond region construction firms bidding military base and federal facility work, CMMC compliance is now a contract award condition — not a future requirement.
Source: CMMC Acquisition Rule / DFARS 252.204-7021 (FR Doc. 2025-17359, effective Nov. 10, 2025)

$115,000
Median ransom payment in 2024 across all ransomware victims — the amount actually paid by organizations that chose to pay. For a construction firm with $8M to $15M in annual revenue, a $115,000 ransom is a nine-figure project margin. And paying does not guarantee restoration: 53 percent of victims recovered within one week when they had tested backups. That figure dropped sharply for those who did not.
Source: Verizon Data Breach Investigations Report 2025 (median ransom payment, calendar year 2024 data)

$150,000
Maximum civil penalty the Virginia Attorney General can seek per breach under Va. Code 18.2-186.6 — the state breach notification law that applies to every the Richmond region construction firm that stores employee Social Security numbers, direct deposit banking data, or driver’s license numbers. AG notification is required for every reportable breach, with no minimum size threshold.
Source: Va. Code 18.2-186.6 (law.lis.virginia.gov, confirmed June 2026; Virginia OAG Data Breach Notification Requirements)

COMPLIANCE, HANDLED

Construction IT Compliance: Frameworks Richmond-area Contractors Must Navigate

You do not need to memorize the acronyms. You need to pass the audit and keep your clients’ trust. That is our job.

CMMC LEVEL 1

Gap assessment against all 17 FAR 52.204-21 practices; control implementation for any identified gaps; System Security Plan (SSP) documentation; self-attestation prepa…

CMMC LEVEL 2

Comprehensive NIST SP 800-171 gap assessment across all 110 practices and 14 domains; System Security Plan development; Plan of Action and Milestones (POA&M) for ident…

DFARS 252.204-7012

Review of existing contracts for DFARS 252.204-7012 applicability; cloud service audit to identify non-compliant storage (commercial M365 tenants holding CUI); GCC mig…

WIRE FRAUD AND PAYMENT CON

Email authentication implementation (SPF, DKIM, DMARC) for your domain and guidance on verification for subcontractor domains; MFA enforcement on all email accounts in…

See the full framework detail
Framework Who Needs It What Capital Techies Does Deliverable
CMMC Level 1 (17 Practices, FAR 52.204-21) Any the Richmond region construction firm whose DoD contract involves Federal Contract Information — including facility construction, renovation, and maintenance contracts at the Federal Reserve Bank of Richmond, the Virginia State Capitol, JEBLC-Fort Story, Henrico Federal Shipyard, JBLE, and other federal installations. Phase 1 active as of November 10, 2025; self-attestation required by a senior company official in SPRS. Gap assessment against all 17 FAR 52.204-21 practices; control implementation for any identified gaps; System Security Plan (SSP) documentation; self-attestation preparation and SPRS submission support; MFA, access control, media sanitization, and configuration management implementation to satisfy all 17 practices CMMC Level 1 gap assessment report, System Security Plan, self-attestation package, SPRS entry documentation, remediation evidence folder
CMMC Level 2 (110 Practices, NIST SP 800-171 Rev 2) the Richmond region construction firms handling Controlled Unclassified Information on DoD contracts — including technical drawings and specifications for military facilities, security-relevant site data, and project correspondence referencing sensitive installation details. C3PAO third-party certification required beginning November 10, 2026 (CMMC Phase 2). Comprehensive NIST SP 800-171 gap assessment across all 110 practices and 14 domains; System Security Plan development; Plan of Action and Milestones (POA&M) for identified gaps; NIST 800-171 control implementation; Microsoft 365 GCC migration for FedRAMP Moderate compliance; C3PAO readiness advisory through the assessment window NIST 800-171 assessment report, System Security Plan, POA&M, C3PAO readiness documentation, GCC tenant configuration evidence, ongoing quarterly advisory updates
DFARS 252.204-7012 (Active in Existing Contracts) All DoD construction subcontractors and prime contractors whose existing contracts include the DFARS 252.204-7012 clause — which requires NIST 800-171 implementation, 72-hour cyber incident reporting to the DoD Cyber Crimes Center at dibnet.dod.mil, 90-day data preservation after reporting, and use of only FedRAMP Moderate-authorized cloud services for Covered Defense Information. Already in effect — not a future requirement. Review of existing contracts for DFARS 252.204-7012 applicability; cloud service audit to identify non-compliant storage (commercial M365 tenants holding CUI); GCC migration planning and execution; cyber incident response plan with DoD reporting workflow; 90-day data preservation configuration; contractor status assessment for dibnet.dod.mil registration DFARS compliance assessment, cloud remediation plan, GCC migration project, cyber incident response plan with 72-hour reporting workflow, dibnet.dod.mil registration support, data preservation policy
Wire Fraud and Payment Controls (BEC Prevention) Every the Richmond region construction firm processing wire transfers for draw requests, subcontractor payments, vendor invoices, or owner distributions — which is every GC, subcontractor, AEC firm, and marine construction firm in the region. BEC targeting construction payment flows is the highest-frequency, highest-loss cyber financial crime affecting the construction sector nationally. Email authentication implementation (SPF, DKIM, DMARC) for your domain and guidance on verification for subcontractor domains; MFA enforcement on all email accounts involved in payment workflows; Microsoft Defender anti-spoofing and impersonation protection configuration; payment verification callback protocol documentation; phishing simulation training targeting payment redirection social engineering Domain authentication configuration and verification report, MFA deployment across email accounts, Microsoft Defender configuration documentation, payment verification protocol, phishing simulation baseline and ongoing training program
Virginia Breach Notification Law (Va. Code 18.2-186.6) Every the Richmond region construction firm that stores the personal information of Virginia employees or customers in computerized form — including Social Security numbers (payroll), driver’s license numbers (I-9 and background checks), financial account information (direct deposit), and passport or military identification numbers. A ransomware attack or breach of payroll or HR systems is a potential breach notification event requiring AG notification regardless of firm size. Incident response plan with Virginia-specific breach notification workflow; breach assessment protocol for the “without unreasonable delay” standard; Virginia AG Computer Crime Section notification package preparation; employee notification letter templates; coordination of state notification requirements with any co-occurring federal requirements (DFARS incident reporting, cyber insurance notification) Incident response plan with Virginia breach notification workflow, AG notification package template, employee notification letters, breach response runbook, annual tabletop exercise
Cyber Insurance Requirements Every the Richmond region construction firm carrying cyber liability coverage or seeking renewal — carriers now require MFA on all email and remote access, EDR deployed on all business endpoints, tested backups with documented recovery times, and security awareness training as conditions of coverage and claim payment. Carriers have denied BEC wire fraud claims where MFA was not active on the compromised email account. MFA enforcement across all accounts; SentinelOne EDR deployment with 24/7 managed detection and response; monthly tested backup with documented recovery time evidence; KnowBe4 security awareness training with phishing simulation records; patch management program with documentation; privileged access management for administrative accounts; controls attestation package for renewal questionnaires Controls attestation package with evidence documentation, renewal-ready cyber insurance questionnaire support, gap remediation for identified coverage deficiencies, ongoing maintenance and quarterly evidence updates

Free Construction IT Assessment

Find Out Where Your Construction IT Security Has Gaps — Before a Wire Goes to the Wrong Account

Most the Richmond region construction firms have larger cybersecurity gaps than they realize — and attackers targeting construction payment flows already know it. Our free Construction IT Assessment identifies your specific exposure areas across wire fraud controls, ransomware defenses, mobile device security, bid data protection, and federal compliance.

  • 20-minute call with a Capital Techies advisor who understands construction operations, not generic IT sales
  • We review your payment controls, project system security, mobile device posture, and federal contract compliance exposure
  • We identify your highest-priority gaps: missing MFA on payment email accounts, unprotected project management access, CMMC requirements you may not know about
  • You receive a written summary of your top risk areas whether or not you become a client
  • No contract required. No sales pressure — ever.
  • Serving general contractors, subcontractors, civil and marine construction, AEC firms, and federal construction contractors across all Richmond region of the Richmond region
Start My Free Assessment

Client Feedback

What Our Clients Say

Real reviews from Capital Techies clients on Google.

FAQ

Construction IT Security Questions from Richmond-area Contractors

Authoritative answers to the questions the Richmond region general contractors, subcontractors, civil and marine construction firms, AEC firms, and federal construction contractors ask most often about cybersecurity, wire fraud, ransomware, CMMC, and managed IT services.

What is the biggest cybersecurity threat facing the Richmond region construction firms?
Business email compromise and wire fraud targeting progress payments, vendor invoices, and subcontractor payments is the largest financial threat to construction firms. Attackers intercept or spoof email accounts and redirect payments to fraudulent accounts. The FBI’s 2024 IC3 report recorded $16.6 billion in total cybercrime losses nationally, with BEC accounting for a substantial portion. Construction firms are high-value targets because they process large, routine wire transfers on predictable schedules — draw requests, lien waivers, and vendor payments create a predictable fraud opportunity that attackers exploit after monitoring email communications for weeks. Capital Techies implements email authentication controls (SPF, DKIM, DMARC), MFA enforcement on all email accounts, and payment verification callback protocols that stop BEC attacks before a wire leaves the account.
Do the Richmond region general contractors need CMMC compliance?
General contractors and subcontractors doing work on federal installations — including the Federal Reserve Bank of Richmond, the Virginia State Capitol, Defense Supply Center Richmond, Henrico Federal Shipyard, and other DoD facilities across the Richmond region — need CMMC compliance when their contracts involve Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). Construction contracts for military base improvements, facility upgrades, and infrastructure projects routinely involve CUI: site drawings, security specs, access control requirements, and project correspondence that references sensitive facility information. CMMC Phase 1 became active November 10, 2025. CMMC Level 1 requires self-attestation on 17 basic practices. Level 2 (110 practices from NIST SP 800-171) requires a C3PAO third-party assessment beginning November 2026. If you are bidding on or performing work at a the Richmond region military installation, your solicitation documents should be reviewed for CMMC and DFARS 252.204-7021 language before the next contract cycle.
How does ransomware actually stop a construction project?
A ransomware attack on a construction firm encrypts the systems your project runs on — Procore, Bluebeam, Autodesk, Sage 300, or Viewpoint — locking access to project schedules, RFIs, submittals, subcontractor contacts, and financial records simultaneously. Superintendents cannot pull current drawings. Project managers cannot track RFI responses. The accounting team cannot process pay applications. For a Richmond-area GC running multiple active jobs, a Friday afternoon ransomware hit can halt every project in the portfolio until systems are restored. According to the Verizon 2025 DBIR, ransomware appeared in 44 percent of all data breaches in 2025. For small and mid-size businesses specifically, that figure reached 88 percent. The median ransom payment in 2024 was $115,000 — and that does not include recovery costs, which averaged $1.53 million in 2025 per Sophos. Capital Techies builds ransomware defenses layered around immutable backups, endpoint detection, and segmented networks so construction firms can recover within hours, not weeks.
What cybersecurity controls do cyber insurance carriers require for construction firms?
Cyber insurance carriers underwriting construction firms now require, as conditions of coverage and claim payment: multi-factor authentication on all email and remote access systems, endpoint detection and response (EDR) deployed across all business systems, tested backups with documented recovery times, security awareness training with phishing simulation records, and patch management documentation. Carriers have denied claims for BEC wire fraud losses where MFA was not enabled on the email accounts involved in the fraud. For construction firms that process large wire transfers, the MFA requirement on email is not optional — it is the minimum control carriers look for when evaluating a BEC claim. Capital Techies maintains all required controls in documentation formats that survive post-claim carrier audit, and provides renewal-ready questionnaire support so your renewal is not a scramble to prove controls you may not have documented.
What is the Virginia data breach notification law and does it apply to construction companies?
Yes. Virginia Code 18.2-186.6 applies to any business owning or licensing computerized data that includes the personal information of Virginia residents — including construction companies that store employee Social Security numbers, direct deposit banking information, driver’s license numbers, or other personal information in their HR, payroll, or accounting systems. A breach of that data requires notification to affected Virginia residents and to the Virginia Attorney General’s Computer Crime Section without unreasonable delay. Virginia does not use a fixed number of days for this requirement. The AG must be notified for every reportable breach, regardless of the number of people affected. Civil penalties can reach $150,000 per breach. A ransomware attack that encrypts payroll records containing employee SSNs is a potential breach notification event. Capital Techies builds breach response workflows for the Richmond region construction firms that coordinate notification requirements from the moment a potential breach is discovered.
How do attackers steal bid data from construction firms?
Bid data theft in construction typically occurs through three vectors. First, phishing emails targeting estimators, project managers, or principals with access to takeoff software and bid management systems — once an attacker has email or VPN credentials, they can access estimating files, unit price databases, and supplier quotes without triggering obvious alerts. Second, inadequately secured cloud storage where bid documents and subcontractor quotes are shared with project teams — if those systems lack MFA and access logging, an attacker or a former employee can access sensitive files silently. Third, inadequately controlled access by departed employees or subcontractors whose credentials were never revoked after a project ended. For the Richmond region construction firms competing on large public and private projects, a competitor or adversary who sees your bid before opening has an asymmetric advantage that no amount of effort can recover. Capital Techies implements access controls, MFA, and access lifecycle management that protect bid data throughout the project acquisition cycle.
What is DFARS 252.204-7012 and does it apply to construction subcontractors?
DFARS 252.204-7012 is an existing contract clause — already active in defense contracts — that requires implementation of NIST SP 800-171 cybersecurity practices, cyber incident reporting to the DoD Cyber Crimes Center at dibnet.dod.mil within 72 hours of discovery, 90-day data preservation after reporting, and that any cloud service used to store, process, or transmit Covered Defense Information meets FedRAMP Moderate authorization. This clause flows down from prime contractors to subcontractors at all tiers whose work involves covered defense information. For the Richmond region construction subcontractors working on military facilities — base housing, runway improvements, pier maintenance, building renovations — the technical drawings, specifications, and project correspondence may constitute covered defense information subject to DFARS 252.204-7012. If your firm uses standard commercial Microsoft 365 to store or share those documents, you may already be out of compliance. Capital Techies helps the Richmond region construction firms identify their DFARS obligations and implement the required controls, including GCC migration when needed.
What special cybersecurity risks do marine and civil construction firms face in the Richmond region?
Marine and civil construction firms in the Richmond region — dredging contractors, waterfront construction firms, pier builders, and shipyard support contractors — face several specific risk factors. First, much of their project work is near or on military installations or defense-critical infrastructure, making their project documents potentially CUI-adjacent and subject to CMMC and DFARS flow-down. Second, marine construction projects frequently involve coordination with the Army Corps of Engineers, the federal government, and Coast Guard, with federal agency project portals and shared document repositories that require NIST-aligned access controls. Third, the mix of office-based administrative staff and field-based supervisors and operators creates a large mobile device footprint — tablets, ruggedized laptops, and smartphones on boats, barges, and construction sites — that is difficult to manage with standard IT controls. Capital Techies builds mobile device management and field security programs specifically for construction environments where devices move between office networks and remote worksites daily, including marine jobsites with intermittent cellular connectivity.
What should a the Richmond region construction firm do immediately after a suspected wire fraud or BEC attack?
Immediately call your bank’s wire transfer fraud line — not the customer service number but the specific wire recall line — and request a wire recall. If the transfer was made within the same business day and has not yet settled, banks can sometimes recover funds through a SWIFT recall process. Simultaneously, file a complaint with the FBI Internet Crime Complaint Center at ic3.gov and request an FBI Financial Fraud Kill Chain submission, which coordinates with the receiving bank through law enforcement channels. Contact your cyber insurance carrier to report the incident before taking further investigative steps, as carrier notification requirements are typically within 24 to 72 hours of discovery. Preserve all emails related to the fraudulent transaction — do not delete anything. Contact Capital Techies or your IT provider to determine how the attacker accessed the email account involved. The most common entry points are phishing, credential stuffing against accounts without MFA, and compromised vendor accounts whose email was intercepted mid-thread in what is known as a man-in-the-email attack.
How does a construction firm in the Richmond region get started with Capital Techies?
The first step is a free Construction IT Assessment — a 20-minute call with a Capital Techies advisor who understands construction operations, not generic IT sales. We look at four areas specific to construction: payment and wire transfer controls, project system security (your ERP, project management platform, and estimating tools), mobile and field device posture, and — for firms with federal or DoD work — your CMMC and DFARS exposure. At the end of that call, you receive a written summary of your highest-priority risk areas and what addressing them looks like in practical terms. No contract required. No sales pressure. Submit the form on this page or call 571-982-6000 to schedule directly.
Do AEC firms face different IT security risks than general contractors?
AEC firms face the same wire fraud and ransomware risks as general contractors, but with additional threat surfaces. Design files — AutoCAD DWG, Revit BIM models, Civil 3D surveys — are large, high-value intellectual property targets. For federal and DoD project work, design documents frequently contain sensitive site information that may be classified as CUI. AEC firms also typically maintain project files across multiple cloud platforms (BIM 360, Autodesk Construction Cloud, Procore, and similar), increasing the number of access points an attacker can target. The billing cycle for professional services — milestone-based invoices, retainers, and progress billings — creates the same wire fraud exposure as a GC’s draw request. Capital Techies protects AEC firms by securing the full technology stack: design software environments, cloud file repositories, email systems, and the financial systems where payment instructions originate and where a fraudulent redirection request would land.
What Microsoft 365 plan should a construction firm in Richmond use?
For commercial construction firms with no federal CUI obligations, Microsoft 365 Business Premium is the appropriate plan — it includes Microsoft Intune for mobile device management of field devices, Microsoft Defender for Business for endpoint protection, Azure Active Directory Premium for conditional access policies and MFA enforcement, and Defender for Office 365 for email security including anti-spoofing protection for BEC prevention. For construction firms with DFARS 252.204-7012 obligations or CMMC requirements — any firm that stores, processes, or transmits Covered Defense Information or CUI — standard commercial M365 does not meet FedRAMP Moderate requirements and does not satisfy DFARS 252.204-7012. Those firms need Microsoft 365 Government Community Cloud (GCC) or GCC High depending on the CUI category involved. Capital Techies manages M365 environments for the Richmond region construction firms across both commercial and GCC configurations, including the full migration from commercial to GCC for firms with newly identified DFARS obligations.

How Exposed Is Your Business Right Now?

Get your free Cyber Risk Score in under 3 minutes. We check for exposed credentials, email spoofing gaps, dark web leaks, and unpatched systems. You get a letter grade and a plain-English report. No sales call required.

Get Your Free Cyber Risk Score →

Free · Takes 3 minutes · No sales call required