Out-of-office cyberthreat
Your business may be taking a break. Cybercriminals are not.
Every summer, security teams watch a familiar pattern unfold. As out-of-office replies increase, so do reports of cyber incidents. The connection is not accidental. Holiday periods alter the way organisations work, and attackers understand those changes well.
Summer does not slow criminal activity, it only opens up the conditions that might invite it.
With staff travelling overseas and teams working around annual leave, responsibilities move between colleagues and decisions are often made by people who would not usually make them.
Processes still need to continue, of course, but the usual checks can become harder to maintain when the person who normally provides them is sitting on a beach several time zones away.
Out-of-office replies are a useful place to start. A message that gives exact dates, and names the colleague providing cover, may look like an ordinary courtesy. But to someone preparing a convincing impersonation e-mail, it confirms who is away, who has stepped in and how long the arrangement will last.
That detail gives an attacker a believable reason for approaching the person providing cover. An urgent e-mail that appears to come from the absent colleague, asking them to act quickly or depart from the usual process, fits the circumstances the business has already disclosed.
A shorter reply can offer the same courtesy without revealing quite so much. Confirming that someone is away and will respond on their return is often enough. Where an alternative contact is needed, a shared inbox or general team address can keep work moving without explaining the internal handover.
It is also worth agreeing beforehand how an unusual request will be checked, rather than leaving the person providing cover to improvise when one arrives. A call to a known number, or confirmation from someone outside the original e-mail exchange, introduces a pause. Often, that is enough to show that a request does not stand up to closer scrutiny.
The quality of fraudulent e-mails has improved in tandem. AI tools are getting better and better at drafting a convincing message. They can imitate someone’s writing style or create a professional-looking invoice within seconds. Reminding people to look out for poor spelling and awkward phrasing were never dependable signs of fraud, but they offer even less reassurance now.
Remote working brings its own considerations. Sending a work e-mail from a hotel or airport is neither unusual nor necessarily careless; it is simply part of the way many people now work. The surroundings, however, are different. The network has not been chosen by the business, the device may sit outside its IT controls and the person using it may have several other things competing for their attention.
A company-managed device, multi-factor authentication and a secure connection reduce much of that exposure. There is also a sensible distinction between work that can be done while away and work that should wait. Reading a routine e-mail is one thing; approving an important change or accessing sensitive information over public wi-fi is another.
The same applies to messages people expect while travelling. Hotel confirmations, itinerary changes and delivery notifications — they can all look entirely ordinary if the recipient is genuinely waiting for one. A short reminder to check the sender, avoid unexpected links and open bookings through the original website or app is more useful than a general instruction to “be vigilant”.
The summer reshuffle happens elsewhere, too. Suppliers, service providers and outsourced IT teams are likely covering holidays, passing work between colleagues and waiting longer for decisions. Against that background, an unfamiliar name or unexpected change can look like nothing more than part of the handover.
Agreeing beforehand who can authorise a change, and how it will be confirmed, removes much of the guesswork. Where outsourced IT is involved, businesses should also know who installs updates, who confirms that the work has been completed and who takes responsibility while the usual contact is away.
Otherwise, if everyone assumes somebody else has picked up responsibility, work might be unfinished, leaving you open to attacks.
For businesses unsure whether they have covered the essentials, the Cyber Essentials framework offers one useful checklist, including access controls, multi-factor authentication, secure configuration and software updates. Certification is not the point here so much as using an established standard to identify anything that could be overlooked before staff begin to leave.
A brief review before annual leave begins gives businesses the chance to deal with those details while the right people are still available. It also means that staff providing cover know where their authority begins and ends, rather than having to work it out when an urgent request arrives.
With a little forethought, businesses can keep the same checks in place through the summer, even when teams are smaller and familiar routines have shifted.
A short review before the out-of-office replies go on can help ensure that, when the organisation returns to full capacity in September, it does so from the same secure position in which it entered the summer.
• Louise Ralston is chief operating officer of Cyber Tec Security, a cybersecurity specialist business providing cyber certification-led resilience and adherence to regulatory compliance
