The company goes on holiday, cybercriminals do not: how Cybersecurity risks change

July 27, 2026

When the holiday period begins, many things change within a company: activity decreases, teams are reorganised, processes are modified and remote working increases. None of these changes represents a risk in itself, but they do alter the conditions in which the company prevents, detects and responds to a Cybersecurity incident.

______

Cybercriminals do not adapt their activity to the business calendar. Phishing, ransomware, credential theft and attacks targeting suppliers continue to occur during holiday periods. However, companies do temporarily change the way they operate.

Reduced staffing levels due to holidays, cover arrangements between teams, the accumulation of tasks before the holiday closure, automatic out-of-office messages and access to corporate resources from different locations mean that some processes operate differently for a few weeks. It is not so much that the threats change, but rather that a different operational context emerges, which can make it more difficult to prevent, detect or respond to an incident.

For this reason, preparing the company for this scenario involves more than reviewing technical controls before closing for the holidays. It also means ensuring that the capabilities required to prevent, detect, respond to and recover from an incident remain operational throughout the holiday period.

When the company changes, the risk changes

These changes are part of the normal activity of any company, but they alter the context in which Cybersecurity measures are applied. A process that operates normally during the rest of the year may work differently when the usual people responsible are unavailable, approval workflows change or oversight capacity is reduced.

The technology infrastructure changes very little; what changes temporarily is how people and processes interact with it. This combination can create situations that cybercriminals attempt to exploit, particularly through social engineering campaigns targeting employees who take on new responsibilities, suppliers or staff managing specific tasks during that period.

Cybersecurity also depends on how the company operates.

For this reason, preparing for the holidays is not simply a matter of reviewing systems or applying updates. It also involves understanding how organisational changes affect the company’s operations and ensuring that these processes remain secure throughout the holiday period.

Business continuity is prepared before the holidays

Ensuring business continuity is not only about reacting to an incident. It involves anticipating the scenarios that could affect the company’s operations and ensuring that critical processes can be maintained or restored within acceptable timeframes.

The holiday period introduces a number of variables that should be taken into account in this planning. If these scenarios have not been anticipated, the reduced availability of certain roles, temporary changes in responsibilities or the need to manage incidents with smaller teams can affect the ability to respond to a cyber incident.

For this reason, it is advisable to review which processes are essential to the company’s operations, which people are involved in them and how their continuity would be maintained if an incident affected systems, communications or access to information.

Business continuity begins before the incident.

Advance planning helps to reduce the impact of a disruption, regardless of its cause. Whether it is a cyberattack, a technical failure or any other event affecting operations, having defined processes and clear responsibilities enables a faster, more coordinated recovery.

Technical controls remain the same, but become even more important

Once critical processes have been identified and business continuity has been planned, the next step is to verify that technical controls remain ready to protect the company throughout this period. The aim is therefore not to introduce new Cybersecurity measures, but to ensure that those already in place remain effective despite changes in operating conditions.

When day-to-day oversight decreases, prevention and early detection become more important. An unpatched vulnerability, a backup that is not running correctly or an alert that goes unnoticed can have a greater impact if the company’s ability to respond is lower than during the rest of the year.

For this reason, before the holiday period it is advisable to check that essential controls continue to operate correctly. Keeping systems and applications up to date, applying the principle of least privilege, strengthening authentication through MFA (multi-factor authentication) and verifying that backups are working correctly are measures that help reduce the attack surface and minimise the impact of a potential incident.

A control is only effective if it continues to work when needed.

Monitoring and automation also play a fundamental role during these weeks. Having properly configured alerts and checking that staff are responsible for reviewing them makes it possible to detect anomalous behaviour even when normal activity decreases. Similarly, it is advisable to confirm that protection solutions, such as EDR systems, antivirus software and firewalls, have up-to-date policies and continue to operate normally before the holiday closure.

In companies where part of the workforce continues to work remotely or from locations other than the office, it is essential to ensure that corporate resources are accessed through secure connections, managed devices and appropriate authentication mechanisms. Endpoint protection remains one of the main factors in reducing the risk of unauthorised access.

Incident response cannot take a break

Even when a company has appropriate preventive measures in place, no company can completely eliminate the risk of experiencing a Cybersecurity incident. For this reason, in addition to protecting and monitoring systems, it is essential to ensure that response capabilities remain operational throughout the holiday period.

The availability of the people responsible forms part of that capability, so it is advisable to review who will manage an incident if the usual people responsible are unavailable, how escalation procedures will be activated and which communication channels will be used to coordinate the response. Clear planning prevents delays and reduces uncertainty when every minute counts.

Coordination with suppliers, managed security services and specialist teams should also form part of this preparation. Confirming that contact details are up to date, notification procedures remain valid and support agreements cover the holiday period helps speed up the management of any incident.

Preparation determines the ability to respond.

Responding to an incident does not simply mean containing the attack. It also involves keeping the relevant teams informed, restoring affected services, minimising the impact on operations and learning lessons that can strengthen the company’s security posture. When these procedures have been defined in advance, the response is faster, better coordinated and more effective.

Cybersecurity is also part of business continuity

Throughout this article, we have seen that the holiday period changes the way a company operates. This is precisely why Cybersecurity has become an inseparable part of business continuity.

A ransomware attack, compromised credentials, the unavailability of a critical service or an incident affecting a supplier can have operational consequences similar to those of any other business disruption. For this reason, Cybersecurity can no longer be understood solely as a discipline for protecting systems and data, but as an essential component of ensuring business continuity.

A company’s resilience is also built through Cybersecurity.

This relationship becomes particularly apparent during holiday periods. When companies operate with smaller teams, temporary changes to processes or reduced oversight capacity, maintaining business continuity depends as much on planning as it does on the ability to prevent, detect, respond to and recover from a cyber incident.

Conclusion

Threats do not change during the holiday period. The company does. And this is precisely why Cybersecurity and business continuity must be ready to continue functioning when activity changes. Phishing, ransomware, credential theft and attacks targeting suppliers remain part of today’s Cybersecurity landscape. What changes is the context in which the company operates and, with it, the way those risks must be managed.

Planning becomes even more important because of the temporary reduction in activity, staff absences, the reorganisation of responsibilities and working from different locations. Preparing business continuity, reviewing technical controls and ensuring response capabilities help the company approach this period better prepared and reduce the impact of a potential incident.

Therefore, preparing a company for the holidays involves more than activating an out-of-office message or closing the office for a few weeks. It means ensuring that the capabilities required to protect operations remain available when they are needed.

The company may temporarily reduce its activity, but not its ability to protect the business.

Digital nomads and Cyber Security, remote and protected