A Backup and Recovery Guide for Engineering Firms
An engineering firm should back up active AutoCAD, Civil 3D, Revit, and project data at least every 15 to 60 minutes, depending on how much work the firm can afford to recreate. Critical servers and cloud systems should also have daily protected backups, multiple recovery points, and at least one isolated or immutable copy that ransomware cannot easily alter or delete.
Backup frequency should not be chosen only by storage cost or convenience. It should be based on two business requirements:
- Recovery point objective: How much recent engineering work can the firm afford to lose?
- Recovery time objective: How quickly must employees regain access to the files and systems?
For a 25-50 employee engineering firm, losing four hours of design work across 15 engineers could mean 60 hours of rework. At a fully burdened labor cost of $75 per hour, that represents approximately $4,500 in direct labor before accounting for project delays, overtime, missed deadlines, and client communication.
This guide provides a seven-layer backup framework for protecting engineering project files, Microsoft 365 data, servers, cloud platforms, templates, and business systems.
The Seven-Layer Engineering Backup Framework
- Define acceptable data loss and downtime.
- Identify every system containing critical information.
- Set backup frequency by workload.
- Maintain local, offsite, and isolated recovery copies.
- Protect Microsoft 365 and cloud data.
- Test file, project, and complete-system recovery.
- Document responsibilities and recovery priorities.
A reliable backup program needs all seven layers. Frequent backups are not enough when no one has tested a restore. Offsite storage is not enough when attackers can delete it using compromised administrator credentials. Cloud storage is not enough when retention periods, permissions, and recovery procedures are unclear.
911 IT provides business continuity and disaster recovery services for engineering firms that need protected backups, tested recovery procedures, and reduced downtime.
1. Define How Much Engineering Work the Firm Can Lose
The first step is determining the recovery point objective, commonly abbreviated as RPO. The RPO represents the maximum amount of recent work the firm is prepared to recreate after a disruption.
Example Recovery Point Objectives
| Workload | Illustrative RPO | Potential Data Loss |
|---|---|---|
| Active CAD and BIM projects | 15-60 minutes | Up to one hour of recent changes |
| Project administration documents | 1-4 hours | Part of a working day |
| Microsoft 365 email and collaboration | 4-24 hours | Depends on system criticality and backup design |
| Accounting and business systems | 1-24 hours | Depends on transaction volume |
| Archived projects | 24 hours or longer | Limited recent activity |
These are planning ranges rather than universal rules. A firm working on fast-moving infrastructure projects may need recovery points every 15 minutes. A firm using mostly archived reference data may accept a longer interval.
Calculate the Cost of Recreating Work
Use this formula:
Number of affected employees × hours of lost work × fully burdened hourly cost
For example, assume 12 employees lose three hours of work at an average fully burdened rate of $80 per hour:
12 × 3 × $80 = $2,880 in direct rework cost.
This calculation does not include:
- Project-manager time
- Overtime
- Missed submittals
- Consultant coordination
- Client dissatisfaction
- Contractual consequences
- Employee frustration
When the cost of rework is high, more frequent recovery points may be easier to justify.
2. Define How Quickly Systems Must Be Restored
The recovery time objective, commonly abbreviated as RTO, defines how long the firm can operate without a system before the disruption becomes unacceptable.
Example Recovery Time Objectives
| System | Illustrative RTO | Business Impact |
|---|---|---|
| Active project-file storage | 1-4 hours | Multiple engineers may be unable to work |
| Internet and network access | 1-4 hours | Cloud services, remote work, and communication may stop |
| Microsoft 365 | 4-8 hours | Email, Teams, and document collaboration may be disrupted |
| Accounting or ERP platform | 4-24 hours | Billing, payroll, and project administration may be delayed |
| Archived project storage | 24-72 hours | Historic files may be temporarily unavailable |
A backup system designed only to preserve files may not meet a four-hour recovery target. Restoring several terabytes of project data across the internet could take much longer unless local recovery, virtualization, or cloud failover options are available.
Recovery Priorities Must Be Documented
Leadership should identify the correct restoration order. A typical sequence might be:
- Identity, authentication, and network security
- Internet and remote access
- Active project-file systems
- Critical CAD, BIM, and business applications
- Microsoft 365 and collaboration services
- Accounting and administrative systems
- Archived data
The order should reflect how the firm actually operates. Restoring email first may provide limited value when every engineer is waiting for the project server.
3. Identify Everything That Needs to Be Backed Up
Engineering firms frequently protect the main file server while overlooking cloud systems, workstation-based project files, application configurations, or specialized engineering libraries.
Project Data
- AutoCAD drawings
- Civil 3D projects
- Revit models
- External references
- Data shortcuts
- Survey databases
- Point clouds
- Imagery
- Sheet sets
- Specifications and reports
- Project correspondence
- PDF markups
Shared Engineering Resources
- CAD templates
- Revit families
- Plot styles
- Custom scripts
- Design libraries
- Standard details
- Automation tools
- Application configurations
- License-server settings
Business Systems
- Accounting
- Payroll
- Project management
- Customer relationship management
- Time tracking
- Human resources
- Document management
- Phone-system configurations
Cloud Data
- Microsoft 365 email
- SharePoint
- OneDrive
- Teams
- Cloud CAD and BIM platforms
- Cloud file-storage systems
- Hosted project-management tools
- Cloud-based accounting platforms
Infrastructure Configurations
- Firewalls
- Network switches
- Wireless systems
- Servers
- Virtual machines
- Identity systems
- Backup systems
- Security platforms
The backup inventory should identify where each system is hosted, who owns it, how often it changes, how it is protected, and how it will be restored.
4. Set Backup Frequency by Engineering Workload
Not every system needs the same schedule. Backup frequency should reflect the amount of new data created and the business cost of losing it.
Active AutoCAD and Civil 3D Projects
Active projects may require recovery points every 15 to 60 minutes. The schedule should account for:
- Number of active users
- Frequency of file changes
- Project deadlines
- File size
- Reference relationships
- Storage-platform capabilities
- Impact of backup activity on performance
Continuous or snapshot-based protection may provide more useful recovery points than one nightly backup.
Revit Models
Revit backup planning should consider:
- Central and local models
- Cloud collaboration
- Linked models
- Families and templates
- Worksharing history
- Version retention
- External consultants
Application-level version history is valuable, but the firm should also understand how to recover the larger project environment after deletion, corruption, account compromise, or platform failure.
Project Documents
Specifications, contracts, reports, spreadsheets, and correspondence may be protected through hourly snapshots, version history, and daily backups.
Server and System Images
Critical servers may require backups several times per day or more frequently. System-image backups can help restore operating systems, applications, configurations, and data together.
Archives
Completed project archives may change infrequently, but they still require:
- Multiple copies
- Integrity checks
- Retention policies
- Controlled access
- Periodic recovery testing
An archive that has not changed recently can still be damaged by ransomware, storage failure, accidental deletion, or silent corruption.
5. Use the 3-2-1-1-0 Backup Strategy
A practical engineering backup plan can follow the 3-2-1-1-0 framework:
- 3: Maintain at least three copies of important data.
- 2: Store the copies on at least two different systems or media types.
- 1: Keep at least one copy offsite.
- 1: Keep at least one copy offline, immutable, or logically isolated.
- 0: Aim for zero unresolved errors after backup verification and testing.
Copy 1: Production Data
This is the working copy employees use every day, such as a file server, network-attached storage system, cloud project platform, or local project repository.
Copy 2: Fast Local Recovery
A local backup appliance or protected storage system can enable faster recovery after accidental deletion, server failure, or file corruption.
The local backup should not use the same unrestricted credentials as the production environment. Otherwise, ransomware or a compromised administrator may be able to damage both copies.
Copy 3: Offsite Recovery
Offsite copies protect against:
- Fire
- Flooding
- Theft
- Building access problems
- Power events
- Local hardware failure
- Widespread ransomware
Immutable or Isolated Recovery Copy
An immutable backup cannot be changed or deleted during a defined retention period. An isolated copy may be offline, disconnected, or protected by separate access controls.
This layer is essential because modern ransomware operators may search for and delete backups before encrypting production systems.
6. Do Microsoft 365 and Cloud Systems Need Separate Backups?
Yes. Cloud platforms may provide redundancy, version history, recycle bins, and retention features, but those capabilities are not always equivalent to an independent backup.
Microsoft 365 data can be affected by:
- Accidental deletion
- Malicious deletion
- Compromised administrators
- Retention-policy changes
- Ransomware synchronization
- Departing employees
- Application errors
- Short recovery windows
Microsoft 365 Data to Protect
- Exchange Online mailboxes
- OneDrive files
- SharePoint sites
- Teams files and related content
- Shared mailboxes
- Calendars and contacts
Questions to Ask About Cloud Backup
- How frequently is cloud data protected?
- How long are recovery points retained?
- Can individual messages and files be restored?
- Can entire mailboxes, sites, or user accounts be restored?
- Who can delete backup data?
- Is backup access protected by multi-factor authentication?
- Are backup administrators separate from normal cloud administrators?
- How long would a large restoration take?
- Has the restoration process been tested?
911 IT's cloud services help firms manage Microsoft 365, cloud identity, collaboration, data protection, and secure access.
7. Protect Backups from Ransomware
Backups should be designed under the assumption that an attacker may obtain employee or administrator credentials.
Separate Backup Credentials
Backup systems should use dedicated administrative accounts rather than the same credentials used to manage everyday servers and workstations.
Require Multi-Factor Authentication
Backup portals, cloud consoles, and administrative access should require multi-factor authentication whenever available.
Restrict Administrative Access
Only authorized personnel should be able to change retention, delete recovery points, disable backup jobs, or modify storage destinations.
Monitor for Backup Tampering
Alert on:
- Disabled backup jobs
- Unexpected retention changes
- Failed jobs
- Deleted recovery points
- Unusual administrator logins
- Changes to backup destinations
- Loss of connection to protected systems
Use Network Segmentation
Backup appliances and management systems should not be exposed broadly to every workstation. Firewall rules and access controls should restrict communication to required systems and administrators.
Preserve Clean Recovery Points
A ransomware infection may remain undetected for days or weeks. Retention should provide enough historic recovery points to restore data from before the compromise.
Learn more about cybersecurity services from 911 IT for protecting engineering identities, endpoints, cloud accounts, networks, and recovery systems.
Backup Is Not the Same as Disaster Recovery
A backup creates a recoverable copy of data. Disaster recovery defines how the firm will restore complete operations.
A disaster recovery plan should address:
- Who declares a disaster
- Who coordinates technical recovery
- Which systems are restored first
- Where restored systems will run
- How employees will connect
- How clean credentials will be established
- How cyber incidents will be investigated
- How clients and employees will be updated
- How the restored environment will be validated
File Recovery
Used when one or more drawings, models, folders, or messages are deleted or corrupted.
Server Recovery
Used when a server fails and its operating system, applications, configurations, and data must be restored.
Site Recovery
Used when the office cannot operate because of fire, power failure, flooding, building access, equipment theft, or widespread infrastructure failure.
Cyber Recovery
Used when ransomware, account compromise, or another attack requires systems to be isolated, investigated, rebuilt, and restored from known-clean recovery points.
Each recovery type requires different tools, documentation, and testing.
How Often Should Backups Be Tested?
Engineering firms should test different forms of recovery on a documented schedule.
| Test | Suggested Frequency |
|---|---|
| Individual file restore | Monthly |
| Complete project-folder restore | Quarterly |
| Microsoft 365 item restore | Quarterly |
| Server or virtual-machine recovery | Quarterly or semiannually |
| Disaster-recovery exercise | At least annually |
| Ransomware tabletop exercise | At least annually |
The correct frequency depends on risk, contract requirements, business criticality, and the rate of change.
What a Restore Test Should Record
- Date and time
- System or data tested
- Recovery point selected
- Person performing the test
- Time required
- Whether the restored data opened correctly
- Whether all dependencies were present
- Problems discovered
- Corrective actions
A successful backup notification is not a substitute for a restore test.
How to Test a Complete Engineering Project
Restoring one DWG or RVT file may not prove that the project is usable. Engineering projects often contain references and supporting information spread across several folders and systems.
Step 1: Select a Representative Project
Choose a project containing typical dependencies such as:
- External references
- Data shortcuts
- Linked models
- Survey data
- Point clouds
- Images
- Templates
- PDFs and specifications
Step 2: Restore to an Isolated Test Location
Do not overwrite production data during testing. Restore the project into a controlled test environment.
Step 3: Open the Project with the Correct Applications
Verify that:
- Drawings open
- References load
- Models synchronize
- Fonts and plot styles are available
- Permissions work correctly
- Users can save changes
- Required plug-ins function
Step 4: Measure Recovery Time
Compare the result with the firm's RTO. A technically successful restoration that takes two days may not satisfy a four-hour business requirement.
Step 5: Document and Correct Gaps
Update the backup scope, recovery documentation, storage design, or application procedures based on the test.
How Long Should Engineering Backups Be Retained?
Retention should reflect project requirements, legal obligations, contracts, ransomware risk, and the cost of storage.
A Practical Retention Framework
| Recovery Type | Illustrative Retention |
|---|---|
| Frequent recovery points | 24-72 hours |
| Daily backups | 30-90 days |
| Monthly backups | 12 months |
| Annual or project archives | Based on contract and legal requirements |
These ranges are examples. Legal counsel, insurance advisors, contract owners, and records-management requirements should help determine the final policy.
Why Longer Retention Can Matter
Some problems are not discovered immediately. A file may be corrupted, altered, or deleted weeks before an employee notices. Longer retention provides more opportunities to recover a clean version.
Why Unlimited Retention Is Not Always Appropriate
Keeping every backup forever can increase cost, legal exposure, and management complexity. The firm should apply a documented retention schedule and legal-hold process.
Should Engineering Firms Back Up Individual Workstations?
Ideally, critical project information should be stored in approved, centrally protected systems rather than only on employee workstations. However, workstation backup may still be needed when:
- Applications store important local databases
- Employees maintain approved local working files
- Large point clouds or caches are difficult to recreate
- Special configurations require significant setup time
- Field employees work offline
- Legacy software stores data locally
Local workstation backup should not encourage employees to keep the only copy of a project on a laptop or desktop. The firm should define which data is permitted locally and how it is synchronized or protected.
Common Backup Mistakes Engineering Firms Make
Backing Up Only Once Per Night
A nightly backup can result in nearly a full working day of lost changes. Active engineering projects may require more frequent snapshots or backups.
Treating File Synchronization as Backup
Synchronization can copy accidental deletion, corruption, or ransomware encryption to connected systems. Versioning may help, but an independent protected backup is still important.
Keeping Every Backup Online with the Same Credentials
If one compromised account can delete production data and every backup, the environment has no meaningful isolation.
Protecting the Server but Not Microsoft 365
Email, SharePoint, OneDrive, and Teams may contain important project and business information that is not included in the server backup.
Ignoring CAD and BIM Dependencies
Restoring the main drawing without its references, templates, survey data, families, linked models, or supporting files may leave the project unusable.
Never Testing a Complete Restore
A successful backup job does not prove that systems can be restored within the required timeframe.
Failing to Monitor Backup Jobs
Backup failures can remain unnoticed for weeks when alerts are not reviewed and escalated.
Using One Retention Period for Everything
Active projects, cloud email, accounting systems, archives, and server images have different recovery and retention requirements.
Not Updating the Backup Scope
New cloud services, project platforms, servers, offices, and applications may remain unprotected if the backup inventory is not reviewed regularly.
Engineering Backup Readiness Checklist
- Recovery point objectives are documented for critical systems.
- Recovery time objectives are documented for critical systems.
- Active CAD and BIM projects have frequent recovery points.
- Project dependencies and supporting files are included.
- Microsoft 365 email, OneDrive, SharePoint, and Teams are protected.
- Cloud engineering platforms have documented recovery procedures.
- Critical workstation-based data is protected or moved to managed storage.
- At least three copies of important data exist.
- At least one copy is offsite.
- At least one copy is immutable, offline, or isolated.
- Backup administration uses separate credentials.
- Multi-factor authentication protects backup systems.
- Backup failures and changes generate alerts.
- Retention periods reflect project and contractual needs.
- Individual file restores are tested regularly.
- Complete engineering projects are restored and validated.
- Servers or virtual machines are tested for recovery.
- The firm conducts an annual disaster-recovery exercise.
- The recovery plan identifies roles, contacts, and restoration order.
- Backup scope is reviewed whenever systems or applications change.
Every "no" or "not sure" answer represents a potential source of unrecoverable data or excessive downtime.
A 90-Day Backup Improvement Plan
Days 1-30: Assess
- Inventory project, cloud, server, and business data.
- Document existing backup jobs and retention.
- Identify systems with no backup.
- Define RPO and RTO targets.
- Review backup security and administrative access.
- Calculate the cost of downtime and rework.
Days 31-60: Improve
- Add missing systems to the backup scope.
- Increase recovery frequency for active projects.
- Implement Microsoft 365 backup where required.
- Create an isolated or immutable recovery copy.
- Separate backup credentials.
- Configure monitoring and alert escalation.
Days 61-90: Test
- Restore individual CAD and BIM files.
- Restore a complete representative project.
- Test Microsoft 365 recovery.
- Recover a server or virtual machine.
- Run a tabletop disaster scenario.
- Document results and assign corrective actions.
What Engineering Clients Say About 911 IT
"911 IT's services allow us to focus on our core business by effectively and safely managing security for our cloud-based services, such as Microsoft Office 365, Atlassian, GitLab, NextCloud, and more. They thoroughly research options before responding and work with us to implement the right solutions."
— Scott, Engineering
Reliable backup and recovery require more than installing software. The provider must understand where engineering data is stored, how project dependencies work, how quickly employees need access, and how to restore systems securely after a failure or cyber incident.
Additional customer experiences are available on the 911 IT client testimonials page.
Frequently Asked Questions
How often should AutoCAD files be backed up?
Active AutoCAD projects may require recovery points every 15 to 60 minutes, depending on the number of users, rate of change, project deadlines, and acceptable rework. Nightly backup alone may expose the firm to nearly a full day of lost changes.
How often should Civil 3D projects be backed up?
Active Civil 3D projects should generally have frequent recovery points that protect drawings, data shortcuts, survey databases, references, surfaces, and supporting files. The complete project should also be restored during periodic testing.
How should Revit models be backed up?
Revit protection should include central or cloud models, linked models, families, templates, and related project content. Built-in version history should be evaluated alongside independent backup and complete-project recovery procedures.
Is OneDrive or SharePoint a backup?
OneDrive and SharePoint provide useful versioning, recycle-bin, retention, and collaboration features. They may not replace an independent backup with separate administration, longer retention, and documented restoration procedures.
Does Microsoft back up Microsoft 365?
Microsoft provides platform resiliency and recovery features, but the customer remains responsible for retention settings, permissions, accidental deletion, compromised accounts, and business-specific recovery. Many firms use an additional Microsoft 365 backup service.
What is an immutable backup?
An immutable backup cannot be modified or deleted during a defined retention period. It helps protect recovery data from ransomware, malicious administrators, and accidental deletion.
How many backup copies should an engineering firm have?
A practical target is at least three copies of critical data, stored across at least two systems or media types, with one copy offsite and one copy isolated, offline, or immutable.
How long should project backups be kept?
Retention depends on contracts, legal obligations, project lifecycle, insurance requirements, and business needs. Many firms keep frequent short-term recovery points, daily backups for 30-90 days, monthly copies for a year, and project archives according to a formal records policy.
How often should backup restores be tested?
Individual files can be tested monthly, complete project folders quarterly, servers quarterly or semiannually, and full disaster recovery at least annually. Higher-risk environments may require more frequent testing.
What is the difference between RPO and RTO?
RPO defines how much recent data the firm can afford to lose. RTO defines how quickly a system must be restored. Both should be determined by leadership and used to design the backup system.
Can backups stop ransomware?
Backups do not prevent ransomware, but protected and tested copies can reduce downtime and data loss. At least one recovery copy should be isolated or immutable so attackers cannot easily delete it.
Should every engineering workstation be backed up?
Critical business data should preferably reside in centrally managed storage. Workstations may still need backup when they contain approved local project data, specialized databases, field information, or configurations that would be difficult to recreate.
Protect Your Engineering Projects from Data Loss
The correct backup frequency is determined by how much work the firm can afford to recreate and how quickly employees must resume production. For active engineering projects, that often means recovery points every 15 to 60 minutes, daily protected backups, offsite storage, an immutable copy, and regular restoration testing.
911 IT has served businesses in the Salt Lake City area since 2004 and provides engineering firms with managed IT support, cloud services, cybersecurity, protected backups, disaster recovery, and strategic technology planning.
To evaluate your current backup coverage, recovery times, ransomware protection, and testing process, explore 911 IT's business continuity services or schedule a discovery call with 911 IT.
