Don’t let your cyber defences take a holiday
12th August 2026
Summer is peak season for cyber attacks because hackers know that people get thinner on the ground, but there are some surprisingly easy methods that can be deployed to reduce the risk of holiday season disasters.
The timing is no accident. In one survey of organisations across the UK, US, France and Germany, 86 per cent of those hit by ransomware said the attack landed on a weekend or public holiday.
Some of the largest ransomware incidents of recent years were deliberately launched over holiday weekends – a pattern stark enough to have prompted formal warnings from the FBI and America’s cyber security agency. Attackers know exactly when the A-team is away.
Connectus Business Solutions CEO Roy Shelton says many organisations are facing the same set of pressures: annual leave and temporary cover, tasks delegated to people who would not normally handle them, staff working from gardens and hotels, and decision-makers who are difficult to reach when an urgent issue arises.
“Cyber criminals plan around the calendar just like the rest of us. The difference is that August is their busy season,” says Mr Shelton.
“An out-of-office reply tells an attacker exactly who is away and until when and the colleague you’d normally sanity-check something with is on a beach. None of your technology has changed, but your safety net has.”
The main risks are laptops on public Wi-Fi that can be intercepted or spoofed. Devices left unlocked, unencrypted or unpatched because the update prompt was dismissed at the departure gate.
Phishing and payment fraud can be timed for when the person being impersonated cannot be reached to confirm, and there are monitoring gaps: incidents that go unnoticed for longer than they should because coverage is more sporadic.
“Most summer incidents don’t start with anything sophisticated,” says Mr Shelton. “They start with a laptop on hotel Wi-Fi, an update postponed until after the flight, or an urgent payment approved from a sun lounger because the boss couldn’t be reached.”
Mr Shelton offers five tips for working way from home safely this summer:
Treat public Wi-Fi as public. That café, hotel or airport network is also open to anyone else using it. Where possible, use a mobile hotspot or a company VPN so traffic is encrypted end to end, rather than connecting straight to whatever network is available.
Keep devices locked down, physically and digitally. A laptop left on a table or a phone unlocked on a sun lounger is a real risk, not just a hypothetical one. Make sure every device has a strong PIN, password or biometric lock enabled, full-disk encryption switched on, and auto-lock set to a short timeout.
Be extra alert to phishing. Attackers know summer means more people checking email quickly on a phone. Slow down before clicking a link, especially if the request feels rushed or slightly out of character, and verify unusual requests through a second channel, like a phone call, before acting.
Don’t let updates slide. It’s easy to dismiss a software update prompt when you’re trying to finish up before a flight. Set devices to update automatically wherever possible, and make sure this is checked before, not during, time away.
Plan for reduced cover, not just reduced staff. The businesses that come through summer unscathed tend to be the ones who treated these basics as routine rather than optional. That’s really the same principle behind Connectus’ approach to managed IT and cyber security year-round: proactive monitoring, secure connectivity, and a UK-based team who are watching the network even when your own team is out of office.