The Summer Security Paradox: Why Fewer Attacks Still Increase Your Vulnerability
The Summer Security Paradox: Why Fewer Attacks Still Means More Vulnerability @channel As I was drafting this article, I found something I didn’t expect - ransomware attacks decline by 18% during summer ! Now although that may sound like great news, it comes with some significant caveats. 🏖️ Summer's Hidden Attack Vectors While ransomware declines, travel-related phishing can spike. Kaspersky blocked 26% more phishing attempts in 2024, noting a surge in summer, targeting travellers with holiday themed phishing scams – e.g. last-minute holiday bargains; fake airline/hotel updates; travel insurance alerts. Then there's your out-of-office auto-reply. It’s a low-risk way for attackers to assess your organisation - they can scope out an understanding of who’s away, for how long and who covers their work. This information can map out decision-making chains and enable more competent & informed social engineering. ⤵️ The Resilience Collapse Of key concern is that summer staffing levels can break controls. One individual covering multiple roles means segregation of duty fails; the office ‘expert’ may be absent so escalations are avoided; or the sheer volume of work means tasks are put to one side, or corners are cut to hit deadlines. This may mean that your understaffed SOC doesn’t detect the attack; a junior Finance clerk pays that urgent high value invoice; or your internet facing systems don’t get the latest patch – either way, you’ll be increasing your vulnerability exactly when attackers know you’ll be running depleted teams. 👍 Addressing The Risk Although it seems that the attackers may take a summer vacation too, it’s not a time to become complacent 🍹. The controls you’ve created across the rest of the year are stretched thin, & defences are less effective, so when an attack does happen you are less able to detect and respond. Consider these pre-holiday steps:
Travel related phishing - Run a pre-holiday phishing simulation that is holiday themed, supported by a communication plan to remind people about contextually-correct lure emails!
Out-of-office auto-reply - Educate staff on information leakage and the importance of external out-of-office responses that don't broadcast key information.
Summer staffing - Ask line managers to remind their staff about the need to adhere to process regardless of the summer break, even if that impacts deadlines. Ensure playbooks (who's on-call, decision thresholds, out-of-band communication for critical incidents) are up to date before people leave, and specifically call out which systems can have updates deferred.
Talking Points 1. What risks do you see over summer? Untrained contract staff filling roles, skill depletion etc? 2. How do you educate people on summer risks without triggering them?
