TL;DR:
- Summer is high season for fraud and cyberattacks on small businesses — reduced staff means slower detection and response
- The most dangerous gap: who’s actually monitoring your email and systems when your usual people are away
- Three things to do before anyone goes on leave: document who’s covering what, review who has admin access, and make sure your backup and recovery contact list is current
July and August are busy for one type of person in particular: cybercriminals. While your team is out of the office or operating with reduced capacity, attackers are aware that incident response slows down, phishing emails get less scrutiny, and the person who would normally spot something unusual is on a beach somewhere.
This isn’t paranoia — it’s a documented pattern. The NCSC has noted that holiday periods see elevated fraud and social engineering attempts targeting organisations where key decision-makers are away. The good news: a few hours of preparation before the summer rush significantly reduces the risk.
The Biggest Risk: Coverage Gaps
The most dangerous cybersecurity vulnerability during summer isn’t technical. It’s human. Someone sends a phishing email on a Tuesday in July. Normally three people would see it, and one would recognise it and raise the alarm. This week, one person is on holiday, one is working reduced hours, and the third is covering two other people’s jobs. The email sits in an inbox until Friday.
That gap — between something happening and someone noticing — is what attackers exploit. In ransomware incidents, the time between initial access and encryption is often measured in days. A system that would normally catch something in hours might take a week during skeleton-staff periods.
The fix isn’t complex monitoring technology. It’s a simple coverage plan: who is watching what, and who do they call if something looks wrong.
Before holidays start, document:
- Who is the first contact if something goes wrong with IT or systems
- Who is the backup if that person is unavailable
- Where to find incident contact numbers (your IT support company, your ISP, your bank’s fraud team)
- What constitutes “something going wrong” — be specific enough that staff covering unfamiliar roles know when to escalate
Print this out or put it somewhere everyone can find without needing to log in to anything.
Review Who Has Admin Access
Summer is a good time to look at who currently has administrator privileges on your systems. Admin access — the ability to create accounts, change settings, and bypass normal restrictions — is exactly what attackers target once they get a foothold.
Common issues to look for:
Former employees or contractors still having access. People leave companies all year round. If you haven’t audited who has accounts on your key systems recently, summer is a practical time to do it. Check your Microsoft 365 admin panel, any cloud services you use, and your accounting software. Disable accounts for anyone who no longer works with you.
Temporary workers or seasonal staff with more access than they need. If you’ve brought in summer staff to cover, make sure they have access to what they need for their job — not admin rights or access to systems they don’t use.
Shared passwords. If multiple people share a single login to a service (a common workaround that is genuinely a security risk), summer is when it bites hardest. If the person who knows the shared password is on holiday, either nothing works or people start trying to reset it in ways that create new risks.
Set Up Out-of-Office Responses Carefully
Out-of-office messages are useful but they broadcast information to anyone who sends you an email — including attackers probing your business for targets.
Avoid including in auto-replies:
- The name of the person covering you (this tells attackers who to impersonate or target)
- The full date range you’re away (gives them a window to exploit)
- Details about a major project or deal that might be referenced in a follow-up attack
A safe format: “I’m out of the office until [date] with limited access to email. For urgent matters, please contact [business email/phone], or I’ll respond when I return.”
Brief Whoever Is Covering on the Common Scams
The most effective social engineering attacks exploit context. An email that arrives the day after the owner goes on holiday saying “Hi, I’m covering for [name] and need you to urgently transfer £3,000 to this new supplier account” is a classic executive impersonation fraud — and it works because the recipient is expecting the owner to be unavailable and for unusual requests to come from unexpected sources.
Before anyone senior goes away, brief the person covering on:
- Any payments they might legitimately be asked to approve, and the correct process to verify them
- The fact that requests to change bank account details should always be verified by phone to a number you find independently, never the number in the email
- That it’s always acceptable to delay or question a request that feels unusual, even if it appears to come from a senior person
This two-minute conversation genuinely prevents the most common summer fraud.
Make Sure Backups Are Actually Working
A ransomware attack that happens while half your staff are away is harder to recover from quickly — which means you’ll be relying on your backups more heavily than usual. This is the time to check they’re actually working, not just running.
A working backup means you can restore from it. Test it:
- Restore one file from your most recent backup and verify it opens correctly
- Check the backup log shows recent successful runs (not just “job scheduled”)
- Confirm the backup destination (cloud or external drive) is actually accessible and has current data
If you’re using Windows File History, check it in Control Panel. If you’re using a cloud backup service (Backblaze, Carbonite, Veeam), log into the portal and verify recent backup runs. If you’re not sure how to do this, your IT support company should be able to check it in under 30 minutes.
A 20-Minute Pre-Holiday Checklist
Run through this before the main holiday exodus:
- Written coverage plan: who responds to what, with phone numbers
- Admin access review: disable accounts for anyone no longer with the business
- Out-of-office messages: reviewed for information that shouldn’t be shared publicly
- Staff briefing: covering staff know the common fraud patterns
- Backup check: recent backup confirmed, restoration tested
- Patch check: any outstanding critical updates applied before staff leave
- Physical: office locked, server/networking equipment secured, CCTV working if applicable
None of these individually takes long. Done together, they close the most common gaps that attackers exploit during summer. The goal isn’t perfect security — it’s making your business a harder target than it was in June.