RepOne Consulting
CPM Scheduling | Construction Expert

non-disclosure-agreement

Non-Disclosure-Agreement (NDAs): How Secure Are Our Backbone Infrastructures?

When it comes to a non-Disclosure-Agreement, Cyber-security policy in the Construction Industry Is High-Risk for Backbone Infrastructures

I recently was issued an RFP from a government agency that included a non-disclosure-agreement (NDA), as well as a confidentiality agreement, for a public transportation project. Upon further inspection, the guidelines included strict protocols for document storage, sharing, reproduction, archiving, and destruction. Frankly, I was impressed.

I was impressed because I know that although these non-disclosure-agreement guidelines exist at most public agencies, I have never actually signed one, and this was the first time I can remember. Things have become more slack, Lax attitudes toward confidentiality and cyber-security mean that the agreements are poorly disclosed, implemented, and enforced. That is a cause for concern of who’s calling the shots.

Agency RFP design documentation is open-source to any Bozo with access.

Every day, RFPs with detailed drawings of public projects and their backbone infrastructures are more or less freely distributed to any contractor who purchase them. Even to a lay person, the implications of this must be staggering. Once drawings leave the agency, they are at risk of being used as guides for sabotage and terrorism.

The letting of a large transit project may publicly circulate hundreds of copies of drawings and specifications on the street. Only a handful of these will use the drawings if they are not contracted. What then? The drawings lay around the office for the taking, or perhaps in a dumpster somewhere – also open source.

A full set of drawings would show information that is easily interpreted. For example, the following inclusions of backbone systems:

  • Life safety system networks
  • Communication & Emergency Networks
  • Command Centers
  • Valve boxes
  • Security camera locations
  • Fibre optic splice boxes
  • Fire Alarm Systems
  • Project Logic Controllers (PLCs)
  • Switch locations
  • Access doors and hatches
  • Safety disconnect locations
  • Building Management Systems (BMS)
  • Ventilation controls
  • Structural specifications and details
  • Interior layouts and room designations

-you get the idea: it’s pretty much everything. The natural question to ask is: “how then do we maintain secure bidding environments without creating these risks?”

There is no simple answer, however, we can mitigate our risk in the following ways:

  • Mandate high level NDA and confidentiality agreements at all public agencies, and create a watchdog agency to enforce it
  • Require certifiable archiving of bid documents by contractors
  • Discontinue the process of providing high level system network diagrams in bid packages
  • Incorporate security points or sensors at any and all system critical entry points: virtual and actual
  • Discontinue the process of providing point to point (PTP) network wiring diagrams
  • Limit network drawing distribution to a short-list of security cleared suppliers and especially, systems integrators.
  • Publish a number of ‘decoy’ documents into circulation, so to at least create some confusion
  • Revamp security protocols at the public agencies to be compliant with present security operations, and monitor them with independent oversight

There’s only so much we can do to stop saboteurs, terrorists, nut-jobs, but that doesn’t mean we should make it so easy for them. Cavalier attitudes and a lack of accountability are impediments to developing more robust measures of project deployment. So will be implementation of new protocols: nothing moves slower than change at the executive level – a circumstance very few of us can do anything about, save for increasing awareness, and demanding change.

Archives: 2014 - 2024

Generating Effective Construction Schedule Oversight Reports

Construction Schedule Oversight Success is Predicated on Having the Right Skill Sets There are both art and science at play in the business of preparing effective and productive CPM construction...

Delay and Disruption Cases: a Tale of Two Claims

I recently had the pleasure of serving as an expert on two concurrent delay and disruption cases that proved to provide some interesting insights into the nuances of delay and disruptions experienced...

Construction Schedule Acceleration: Optimizing for Success

Schedule Acceleration: The Big Squeeze Construction schedule acceleration is a strategy designed and intended to either mitigate and stanch off float erosion (delay,) or to recover lost time –...

Successful Shop Drawing and Submittal Strategies

There has always been a lot of confusion about what constitutes a ‘shop drawing,’ submittal,  and finally – coordination drawings. In order to optimize project management outcomes, it is...

Mastering Retrofit Construction Layout: Optimizing Axes Lines and Benchmarks

Retrofit construction layout is distinct from new construction in that new elements are dictated by existing program to remain or ‘ETR’ – such as structure supporting walls, floors, and...

Punch List Techniques and Strategies for General Contractors 

Confusion and lack of consensus over what a construction project punch list or punch-out list is and what it isn’t, contribute mightily to project conflict in the close out stage of most any...

Managing Construction Contract Extension of Time Claims

Very few construction projects seem to progress without at least one general disruption or delay time impact that affects schedule milestones, and requires trades to accelerate in order to keep to...

Architectural Alignments in Construction

In most interior fit-out, builders only need to align major or basic elements – like walls, floors, and ceilings. As the sophistication of their commissions ratchet up, these architectural...

Resource Loaded CPM Scheduling Strategies

Resource loaded CPM scheduling pertains to developing schedules based on activity durations predicated on production rates and constraints of available personnel or resources. Many project...