
Knowledge base
August 12, 2026
Cybercriminals don’t take vacations. Your company does.
Every summer, half of the Netherlands shuts down at once. Auto-replies are turned on, laptops are turned off, and caravans are hooked up. Offices are running at half capacity, temporary staff are only partially familiar with the procedures, and messages pile up in inboxes that no one checks for weeks on end.
Attackers know that, too. Not because they’re any smarter than usual, but because the defense is slower. A suspicious payment request is less likely to raise suspicion if the CEO is truly unreachable, and an alert that no one reads isn’t an alert.
In this blog, you’ll learn about five real-life situations where things go wrong during the holiday season, and how to set up your organization so that everyone can take time off without leaving the door wide open.
Why Summer Is the Striker’s Season
The mechanism is simple: fewer people in the office, replacements who aren’t familiar with the procedures, and a response time that stretches from minutes to days. Attackers count on that slow response, and in the summer, they get it. The five situations below are all real-life examples, anonymized, and each could have had a different outcome with a different setup.
The auto-reply that gave too much away
“I will be away through August 3. For invoices, please contact Sandra in the accounting department. For urgent matters, please call our director on his cell phone.” We came across this auto-reply from a newly registered customer. Well-intentioned, but a gift to an attacker: who’s away and until when, who handles payments, the director’s name, and his direct number. Everything needed for targeted invoice fraud, all in a single automated email sent to every unknown sender.
The safe option is free: send a neutral message to external recipients, using only a general email address as a placeholder. Names, dates, and phone numbers should only appear in the internal auto-reply.
The other half of this risk lies within your domain itself: could an attacker send an email that appears to come from your company? Our free Security Check at check.alta-ict.nl assesses this, using SPF, DKIM, and DMARC, among other methods. Let’s be clear from the start: the check assesses the external aspects of your domain and doesn’t resolve any issues on its own. You’ll see the results of the assessment along with an explanation, and it’s up to you to decide what to do with that information.
The payment request from the airport
“I’m at the airport and can’t make a call right now. Can you urgently transfer 14,900 euros to this supplier?” The text message came from an unknown number, but it included the CEO’s name and profile picture. And it was true: the CEO really was at Schiphol that morning. The entire company could have read about it on LinkedIn the Friday before.
The office manager hesitated, called the director’s familiar number, and got him on the line—at the gate. No text message sent, no payment made. That’s how it’s supposed to work, but it’s far from always the case. That’s why we establish the same rule with every client: always verify payments above a certain threshold through a second, known channel. Even when the director is on vacation. Especially then.
The login that doesn’t work
One Tuesday afternoon in the summer: a notification that someone had logged into a customer account from Marbella. It turned out the employee was simply on vacation there, just checking email from the hotel’s network. Fine. Half an hour later, a second notification: same account, logged in from another country, thousands of kilometers away. No one travels that fast.
Conditional Access detected the implausible travel behavior, blocked the session, and forced a password reset—all without anyone having to intervene. That’s the difference between allowing vacation time and allowing abuse: an environment that recognizes travel patterns lets the employee in Marbella work as usual and keeps the attacker out.
All the management know-how in one person’s head—and that person is at a campground
A company with dozens of employees and a single system administrator. He was highly skilled—everything depended on him. He left for three weeks in France, camping in an area with no cell service. In week two, the CRM system crashed. No one had the admin passwords, no one knew which vendor to call, the contract was in his name, and the documentation was all in his head. Four days of downtime—not due to an attack, but because one person was on vacation, as he perfectly well deserved to be.
This is called a single point of failure, and we see it more often in small and medium-sized businesses than we do ransomware. The solution isn’t to hire a second administrator, but to set up the right systems: a password vault with emergency access, a “break-glass” procedure, documentation stored in an easily accessible location, and a third party that can take over if necessary.
The alert that nobody read for eleven days
At a company that later became a client, the security system triggered an alert in late July: a suspicious login, followed by a forwarding rule to an external address. The system did its job and sent a notification as expected—to the IT manager’s email inbox, who was sailing on a boat at the time. The notification was read eleven days later. Eleven days during which every email from the accounting department was forwarded to an external address.
Here’s the truth about security software: detection without follow-up is like a smoke detector in an empty house. It beeps perfectly, but no one comes. That’s why our Premium and Platinum workstations include a SOC that responds 24/7: no alert in an empty inbox, but an analyst who terminates the session and removes the rule—even in the middle of the night, even during the construction industry’s summer break.
Before You Leave: The Quick Checklist
Five things to take care of before packing up the car, in order of increasing difficulty: set the external auto-reply to a neutral tone; establish the verification policy for payments and inform your substitutes; check whether foreign logins are being screened for implausible travel patterns; centralize administrative access using a secure vault and an emergency procedure; and designate who will read and follow up on notifications during the vacation weeks. Only that last question sometimes has no internal answer, and in that case, that’s the honest answer.
If you are subject to the Cybersecurity Act or supply organizations that are subject to it, the holiday season is also a bad time to leave your doors open for a second reason: the questionnaires from the supply chain ask specifically about the points mentioned above.
How ALTA-ICT Handles This Itself
We are an MSP ourselves facing the same summer challenge, and we set up our own environment just as we do for our clients: neutral auto-replies, verification via a second channel, conditional access based on travel patterns, administrative access distributed among multiple users, and monitoring that doesn’t depend on who happens to be in the office. This is documented and verifiable, in accordance with our certifications for ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024.
Frequently Asked Questions
Is my business really a target during the summer, even though we’re a small company?
Yes, that’s exactly when. Attackers aren’t looking for big names, but for slow responses—and they find them during the holiday season at companies of all sizes.
What is the biggest risk of a detailed auto-reply?
He provides an attacker with a step-by-step guide to invoice fraud: who is absent, who pays, and in whose name the email should be sent. Keep the external notification neutral.
How can I prevent CEO fraud if the CEO is truly unreachable?
A fixed rule that does not depend on availability: always verify payments above a certain threshold amount through a second, known channel. The rule provides protection precisely because it applies even if the request appears to come from the director himself.
Should I block foreign logins while I’m on vacation?
No, that makes it impossible to work while on vacation. If you let your environment determine the difference between normal travel behavior and impossible travel behavior, then the employee can work in Spain and the attacker won’t be able to get in.
What if no one internally can follow up on the reports during the vacation weeks?
Well, that’s the honest answer, and it’s exactly the gap that an external SOC fills: an organization that reviews reports and takes immediate action, regardless of vacation schedules.
Conclusion
None of the five situations above required more technology; they required a system that doesn’t depend on who happens to be there. A neutral auto-reply, a verification rule, travel behavior monitoring, administrative access managed by more than one person, and follow-up on reports: together, these make the difference between a business that’s closed and one that’s open.
Would you like to know where your organization stands before the next vacation period? Schedule a short session with ALTA-ICT, and we’ll go over the five points together.
Want to know more?

Related
blogs
Tech Updates: Microsoft 365, Azure, Cybersecurity & AI – Wekelijks in je Mailbox.



