Autodesk and BIM Collaboration: Protecting Models and Drawings

BIM models and shared drawings can reveal sensitive facility details. Learn how to control access, sharing and retention across Autodesk and similar platforms.

3 min readBy Ironfield Cyber Team

Building information models and shared drawing sets hold a great deal of detail: structural layouts, utility routes, security system placement, and the internal structure of facilities. When that information is shared among architects, engineers, contractors, and owners through cloud collaboration platforms, the question of who can see and download it becomes a security question as well as a project management one.

This article offers general guidance for companies using Autodesk's collaboration tools or comparable platforms. Features and menus differ by product and license, so confirm details with your administrator or vendor.

Why model and drawing security matters

For many projects, drawings are routine. For others, such as power infrastructure, water systems, data centers, government facilities, or defense-related work, they can be sensitive. Detailed information about a facility's layout can help someone plan physical or cyber attacks. Some contracts may also require specific handling of design documents, and a lost or leaked set can create contractual trouble.

Beyond security, models represent significant intellectual property and a company's competitive value.

Start with the project

Classify the information

At project kickoff, determine whether any information carries handling requirements. Ask the owner whether drawings are marked or designated as sensitive. If the work involves Controlled Unclassified Information for a federal customer, additional requirements may apply and should be handled by a defined, controlled environment.

Define roles and permissions

Most platforms allow permissions by folder, role, or project. Give people access only to the folders and models they need. Subcontractors working on a single scope generally do not need to see everything.

Control access

  • Named accounts only. Avoid shared logins, which make it impossible to know who accessed what.
  • MFA. Require it for all users, including external collaborators on sensitive projects.
  • Single sign-on where available, so access follows your company directory.
  • Regular access reviews. Remove people when they roll off the project or leave the company.
  • Limited administrators. Keep the number of project administrators small.

Control sharing and downloads

External sharing

Review how links and invitations work. Prefer invitations to named people over open links. Where the platform allows, set expirations and restrict download or print rights for sensitive content.

Local copies

Once a file is downloaded, you lose control of it. Decide what staff may store on laptops and phones. For sensitive projects, consider requiring viewing in the platform instead of local downloads, and make sure devices are encrypted and managed.

Email attachments

Avoid sending models and sensitive drawings as email attachments. They end up in mailboxes, on phones, and in forwarded threads. Share links from the controlled platform instead.

Integrations and add-ons

Plug-ins and connected apps may request broad access to your project data. Review them before approving, limit who can install them, and remove ones that are no longer used.

Retention and closeout

Archiving

When a project finishes, decide what must be retained and for how long, and archive it in a controlled location. Leaving old projects open to dozens of former collaborators is a common and avoidable exposure.

Removing access

At closeout, remove outside collaborators and review who still has access. Document the final state.

Disposal

When retention periods end, delete data properly, including copies on devices and in backups where policy allows.

Watch for scams

Fraudulent invitations that copy the look of a collaboration platform are an effective way to steal credentials. Train staff to access the platform from a bookmark and to be suspicious of unexpected invitations, especially from unknown parties. Be alert to messages that claim a change in project payment instructions through the platform.

Protect the workstations

BIM work uses powerful workstations that hold large local caches. Keep them patched and encrypted, restrict administrator rights, and make sure they are backed up. Back up local project files that are not synced elsewhere.

A simple checklist per project

  1. Identify sensitivity and any contract requirements.
  2. Define roles and folder permissions.
  3. Require MFA and named accounts.
  4. Review sharing settings.
  5. Review access monthly during the project.
  6. Close out and archive properly.

Support from Ironfield Cyber

Ironfield Cyber supports contractors and energy companies using Autodesk, Procore, and Microsoft 365, including access design, device management, and secure sharing. If you have a sensitive project starting, we can help you set the controls up before the first file is shared.