ACHR News
search
Ask ACHR NEWS AI
cart
facebook twitter instagram linkedin youtube
  • Sign In
  • Subscribe
  • Sign Out
  • My Account
ACHR News
  • NEWS
    • Breaking News
    • New HVAC Products
    • Featured Products
    • Manufacturer Reports
    • HVAC Data
    • Legislation
    • ACHR NEWS Centennial
  • RESIDENTIAL
    • Air Conditioners
    • Furnaces
    • Residential Heat Pumps
    • Ductless
    • Residential IAQ
    • Testing, Monitoring, Tools
    • Components & Accessories
  • COMMERCIAL
    • Air Handlers
    • Rooftop Units
    • Chillers and Cooling Towers
    • Commercial Heat Pumps
    • Boilers and Hydronics
    • VRF/Ductless
    • Commercial IAQ
  • REFRIGERATION
    • Refrigerants
    • Refrigerant Regulations
    • Leak Management
  • CONTRACTOR PRO
    • Geothermal
    • Homeowner Study
    • VRF and VRV Ductless
    • Unitary Trends
  • EDUCATION
    • Training and Education
    • Business Management
    • Service and Maintenance
    • Continuing Education
    • Market Research >
      • HVAC Brand Awareness Report
      • VRV, VRF, VRVZ Report
      • Unitary Trends Report
      • Water Heat Professionals Report
    • Webinars
    • Sponsor Insights
    • eProducts Info
    • White Papers
  • EVENTS
    • HVAC Contractor Forum
    • Industry Events and Webinars
  • MEDIA
    • Videos
    • AHR Expo 2025 Videos
    • Podcasts >
      • ACHR News Podcast
      • HARDI Podcasts
      • AHR Expo Podcasts
      • ACCA Podcasts
    • Interactive Spotlights
    • Quizzes
    • eBooks
    • HVAC Talkback
  • HVAC GROUP
    • ACHR NEWS >
      • Current Issue
      • Digital Edition
      • Subscribe
    • Distribution Trends
    • SNIPS NEWS >
      • Join SNIPS NEWS
    • Engineered Systems News >
      • Join ES News
    • HVACR Directory
    • Contests
    • Newsletters
    • Contact
    • Advertise
    • My Account
HVAC Residential MarketHVAC Light Commercial Market

Practicing Good Cyber Hygiene

Small- and medium-sized HVAC firms often fall victim to ransomware attacks

By Joanna R. Turpin
HVAC Cyber Security - Practicing Good Cyber Hygiene - The ACHR News

TIME CONSUMING: If a recent backup is available, contractors can usually ignore the ransom demand and get to work restoring their data. However, this takes time and can also be expensive. PHOTO COURTESY OF DATA-BASICS

January 14, 2019

When it comes to cyber safety, contractors are more likely to be focused on keeping their customers’ data safe rather than their own. On the residential side, contractors are concerned about keeping IoT-enabled thermostats safe from hackers, and on the commercial side, they want to ensure that building automation systems are as impenetrable as possible.

Contractors are often less concerned about their own cyber safety because they may think that as a small- or medium-sized business, they are less prone to being hacked. But in the era of ransomware attacks, contractors need to be more vigilant than ever.

 

NEW THREATS

Most people have heard about the high-profile cyberattacks on large companies such as Target and Equifax that resulted in millions of customers’ financial records being stolen. The fallout from these data breaches was huge, with both companies facing a backlash from consumers that has hurt their reputations as well as their profitability.

HVAC and Cyber Security - Ransomware Attacks - The ACHR News

HOLD UP: Ransomware is a form of malicious software that blocks access to a computer system or network until the business owner pays a ransom, often in some type of cryptocurrency. PHOTO COURTESY OF DATA-BASICS

Small- to medium-sized businesses can also fall prey to cyberattacks, particularly ransomware, which can be destructive and costly to companies of all sizes. Ransomware is a form of malicious software that blocks access to a computer system or network until the business owner pays a ransom, often in some type of cryptocurrency like bitcoin. The amounts demanded are usually small — typically under $10,000 — because those perpetrating the attack know that many business owners would rather pay the fee than go through the inconvenience (and expense) of rebuilding their computer network.

Ransomware is highly profitable for criminals because they can target many small companies in a short period of time. That is why ransomware has emerged as one of the most serious online threats facing businesses, and the number of attacks has skyrocketed. In fact, a 2017 report from Osterman Research showed that more than one-third of small- or medium-sized businesses around the globe experienced a ransomware attack in the last year.

That is why it is imperative for contractors to take the necessary steps to protect themselves from this kind of attack.

 

PRACTICING PREVENTION

Ransomware can be delivered to a computer system in many different ways, but the most common entry point is from an employee opening an infected attachment, typically from a spoofed or phishing attack email, explained Derek Lauro, IT network/systems administrator, Data-Basics Inc.

Looking for quick answers on air conditioning, heating and refrigeration topics? Try Ask ACHR NEWS, our new smart AI search tool. Ask ACHR NEWS →

“Infected websites and pop-up ads can also lead to infection,” he said. “Weak passwords can also allow brute force attacks into a network, leaving a company open to unauthorized administrative control and software exploits. That is why contractors should review current password policies with staff members and enforce stricter rules where necessary.”

Typically, ransomware attacks appear to be trusted attachments or files, such as Excel or Word documents, PDF attachments, etc., according to Rachel Schmidt, director of marketing, Davisware Inc.

“The user is then tricked into opening or downloading the infected file or link,” she said. “Although distributed mainly through email, ransomware also propagates through compromised or malicious websites and pirated software.”

To prevent a ransomware attack, Schmidt recommends taking the following steps:

  • Ensure that all computers have updated antivirus/anti-ransomware software;
  • Ensure automatic weekly updates are enabled for antivirus/anti-ransomware software as well as for Windows.
  • Blacklist domains that are known to be malicious;
  • Provide ongoing employee training on best practices for identifying spoofs or suspicious emails;
  • Back up all company data regularly — daily, if possible;
  • Never save a backup to the same computer. Company data should be backed up to an external drive and then disconnected from the network;
  • Ensure all employees are using strong passwords that are more than eight characters in length, have at least one special character, and use upper- and lowercase letters. It should also be a password that is not used for any other account; and
  • If applicable, secure all remote desktop ports.

In addition to making sure the company is protected with server and client anti-ransomware software, contractors should also know that next-generation firewalls have become increasingly more capable, said Lauro.

“Much more advanced and reliable than the typical firewall that just blocks/opens ports, these new firewalls monitor the network for fishy application activity and are designed to stop anything in its tracks,” he said.

New software suites have also been developed that can bundle with typical anti-malware/user control and are seamless to the end user, according to Lauro. Adding a type of behavior scanner that is always monitoring the system for changes can also detect when ransomware has been installed and stop it almost instantly. But more importantly, he added that it is always a good idea to work with an outside IT company and/or IT staff to have a disaster recovery plan in place that can protect against and/or enable an expedited recovery from an attack.

 

REACTION

Contractors who become victims of a ransomware attack have two options: either pay the ransom or wipe their hardware clean and rebuild their computer network. Deciding whether or not to pay the ransom can be tricky, said Schmidt, and usually comes down to whether or not the contractor has recently backed up the company’s data.

“If you do not have a recent backup, can afford to just pay the ransom, and/or can’t afford to go without or lose your data, then you should consider paying it,” said Schmidt. “Remember that even if you pay it, there’s no guarantee that the attacker won’t still hold on to your data. If you have a backup to access, you can typically get back up and running within a couple of hours. In this instance, you would simply access your last backup and restore any data that was lost during the attack.”

“In our best-case scenarios, we have worked with clients who have lost no data due to a great disaster recovery plan, but keep in mind, even with a good plan and backups (and therefore no data loss), it still takes one to two days to get back to where they were before the ransomware attack.”
— Derek Lauro IT network/systems administrator Data-Basics Inc.

Lauro advises clients to only pay the ransom in a worst-case scenario; for example, if they can’t afford to lose their data, can’t withstand the downtime, or do not have any data backups.

“If you determine that paying the ransom is necessary, be cautious about providing sensitive information to the attackers,” he said. “Don’t give out credit card or bank routing numbers or personal information. There are more secure ways to send money, including cryptocurrency, prepaid cards, etc.”

If a recent backup is available, contractors can usually ignore the ransom demand and get to work restoring their data. However, this takes time and can also be expensive.

“In our best-case scenarios, we have worked with clients who have lost no data due to a great disaster recovery plan, but keep in mind, even with a good plan and backups (and therefore no data loss), it still takes one to two days to get back to where they were before the ransomware attack,” said Lauro. “It takes time to restore a server and data files, and downtime of your systems and IT consulting adds up quickly.”

If a contractor has no data backed up and no plans to pay the ransom, the road ahead may be more difficult. Lauro described how one of their contractor clients experienced a ransomware attack and had no data backups and no way to contact the criminals behind the attack.

“As their software providers, we were able to produce a database backup saved on our systems, so they were able to resume operations,” he said. “Unfortunately, their most recent data was not included, as the backup was from several years prior. While better than starting over, this client will never be able to recover the lost months or years of data and records.”

In addition to taking a financial toll on a company, a ransomware attack can also damage a contractor’s reputation — particularly if customer records were stolen. The good news is that in a typical ransomware event, that data is not stolen but rather encrypted with a unique algorithm, explained Lauro.

“It is usually done to incapacitate the company in the hopes that someone will pay up to get their business running again, not to steal data,” he said.

But if data is stolen, contractors must let their customers know, said Schmidt.

“Many do this via an announcement on social media and/or by emailing their saved contacts from their address book,” she said.

Of course, the best way to handle a ransomware attack is to prevent it in the first place. By regularly backing up data, training employees to strengthen passwords and delete suspicious emails, installing and regularly updating antivirus and anti-ransomware software, and creating a plan to prepare for an attack, contractors can keep their businesses and their reputations safe and secure.

Publication date: 1/14/2019

Want more HVAC industry news and information? Join The NEWS on Facebook, Twitter, and LinkedIn today!

KEYWORDS: cybersecurity Leadership and HVACR

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

 

Tn joanna 2017
Joanna Turpin is a Senior Editor at The ACHR NEWS. She can be contacted at 248-786-1707 or joannaturpin@achrnews.com. Joanna has been with BNP Media since 1991, first heading up the company’s technical book division before moving over to The ACHR NEWS, where she frequently writes about refrigerants and commercial refrigeration. She obtained her bachelor’s degree in English from the University of Washington and worked on her master’s degree in technical communication at Eastern Michigan University.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • HVAC-enrollment

    The Trades Are Back: HVACR Programs See Nearly 30% Enrollment Spike

    A new wave of future technicians is entering the pipeline.  
    Training and Education
    By: Matt Jachman
  • 2025 Top 40 Under 40

    2025 Top 40 Under 40 HVACR Professionals List

    The 11th annual Top 40 Under 40 list highlights those...
    HVAC Commercial Market
    By: Hannah Belloli-Oster
  • LG Ductless Mini-Split Systems

    The 9 Types of Heat Pumps

    As the U.S. moves toward electrification, heat pumps are...
    Air Source Heat Pumps
    By: Joanna R. Turpin
Subscription Center
  • Create an Account
  • Start a Subscription
  • Manage My Account
  • Sign Up for Newsletters
  • Visit Customer Service
  • Update Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to The News audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of The News or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Piggy Bank
    Sponsored byWatercress Financial

    Energy Prices, Inflation, and HVAC: What Today’s Homeowners Care About

  • Refrigerated Food
    Sponsored bySolstice Advanced Materials

    R-455A Refrigeration: A Cold Storage Solution for the Future

  • Airex Rooftop Units
    Sponsored byAirex Manufacturing Inc

    Consolidating Roof Penetrations: A Growing Trend in Multifamily HVAC Design

Popular Stories

Refrigerants-and-gauge.jpg

HVAC Industry Warns of Counterfeit Refrigerants Entering U.S. Supply Chain

U.S. Supreme Court building

95% Furnace Efficiency Rule to Get New Hearing

Midea-training.jpg

HVAC Workforce Crisis Expands Beyond Technicians to Instructor Shortages

Data_Center_facility.jpg

HVAC Manufacturers Respond to Growing Data Center Backlash

HVAC Minute retail refrigeration system

EPA Final Rule’s Impact on R-410A Deadlines

View The ACHR NEWS
Centennial Anniversary Timeline

The ACHR News Timeline Chart
Submit a Letter
Submit a letter to our editors.

Events

November 6, 2025

Next-Gen Data Center Cooling: HVAC Innovation and Real-World Solutions

On Demand As AI workloads and high-density computing push traditional cooling methods to their limits, the data center industry is accelerating the adoption of next-generation HVAC technologies.

June 23, 2026

HVAC Duct Sealing Mastics: Why Selection Matters

In this webinar we will detail what HVAC material buyers and technicians need to know when selecting duct mastics, including matching mastic to substrate, alternatives to liquid mastic, and where UL 181 Listings fit into real world installations.

View All Submit An Event

Poll

Summer Staff

Are you fully staffed for the summer season?
View Results Poll Archive

Products

BNI Mechanical/Electrical Square Foot Costbook, 2026 Edition

BNI Mechanical/Electrical Square Foot Costbook, 2026 Edition

See More Products
HVAC Duct Sealing Mastics: Why Selection Matters - Free Webinar - 6/23/2026

Related Articles

  • The commissioning of Fujitsu VRF systems at a residence in New Jersey.

    Five Good Reasons Why A Good Compressor Can Go Bad

    See More
  • HVAC Economic Outlook 2019 - MSCA - The ACHR News

    2019: A Good Year to Be a Better HVAC Contractor

    See More
  • Mixed refrigerants can be recovered and subsequently reclaimed. - The ACHR News

    It Is Never a Good Idea for HVACR Techs to Mix Refrigerants

    See More

Related Products

See More Products
  • The ACHR News - June 02, 2025

    ACHR NEWS June 2, 2025, Issue

See More Products

Related Directories

  • David Gooding Inc.

    DGI is a leading manufacturer's representative of plumbing, heating and showroom products headquartered in Brockton, MA with sales representation throughout NE, Upstate NY, NYC, LI and Mid-Atlantic states. We carry a wide variety of products, for residential and commercial applications, with knowledge to help you find what you're looking for.
×

Sign Up. Stay Informed.

The #1 trusted source for the HVACR industry since 1926

SUBSCRIBE
  • RESOURCES
    • Advertise
    • Contact Us
    • Advisory Board
    • Classifieds
    • Submit a Letter
    • Directories
    • Store
  • ACCOUNT CENTER
    • Create an Account
    • Start a Subscription
    • Manage My Account
    • Sign Up for Newsletters
    • Visit Customer Service
    • Update Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • Instagram
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing