Focus this month | Cybersecurity: What Happens when your IT Team are on Holiday?
Staying secure while your team is on annual leave
July is when most offices start to empty out. Desks sit unused for a week or two at a time, out of office replies go up, and the usual rhythm of who's around and who isn't gets a lot less predictable. For cyber criminals, that's exactly the kind of gap they're looking for.
It's easy to think of summer as a quieter time for the business, but from a security point of view, it can actually be one of the riskier periods of the year. Here's what's worth thinking about before your team heads off.
Out of office replies give away more than you'd think
Most people don't think twice about their out of office message, but it can be a genuinely useful tool for an attacker. Naming a specific colleague to contact instead, mentioning job titles, or listing direct phone numbers all hands over information that can be used to impersonate someone or target a follow up scam.
Keep it simple. A return date and a general contact address is normally all that's needed.
Unfamiliar networks mean unfamiliar risks
Holidays often mean laptops and phones connecting to hotel WiFi, airport networks, or a café hotspot somewhere abroad. These networks aren't secured in the way an office network is, which makes it far easier for someone to intercept data or access a device that isn't properly protected.
If staff are working while away, clear guidance should be delivered on what's safe to access on public WiFi and what should wait until they're back on a trusted connection.
Fewer people around means slower detection
A big part of catching a cyber incident early comes down to people. Someone notices an odd email, a colleague flags a strange login, IT spots something during a routine check. When half the team is away, that natural safety net gets thinner.
This is worth factoring into any incident response plan. Who's covering while others are away, and do they know what to do if something looks wrong?
Phishing attempts often increase over summer
Attackers know exactly when businesses are running with reduced staff, and they time their efforts accordingly. A convincing email asking for an urgent payment or password reset is far more likely to succeed when the usual checks and balances aren't fully in place.
A quick reminder to staff before they go on leave, and to anyone covering while they're away, can make a real difference here.
A few practical steps before your team goes on leave
Review out of office messages for anything that gives away too much detail
Make sure multi-factor authentication is switched on across all accounts
Check that devices are up to date before they leave the building
Agree who's responsible for spotting and escalating issues while colleagues are away
If you'd like a proper review of how prepared your business is heading into the summer, get in touch with the team and we'll help you close any gaps before they become a problem.
