The summer holidays are approaching, and while many employees pack their bags and log off, this is exactly the period threat actors exploit. Reduced staffing and less monitoring make many organizations more vulnerable during the summer weeks. Attackers know that alerts go unnoticed for longer, and that the person who usually makes the decisions may be at the cabin.
In recent years, attacks have also become easier to launch and harder to detect. AI-generated phishing messages are nearly flawless, and attacks against identities and logins remain the most common way in. The most important measures remain simple, and there is still time to put them in place.
Here is Sicra's checklist of 10 effective measures you can complete before the holidays.
Multi-factor authentication (MFA) is still the most effective protection against account takeovers. Make sure it is enabled for all users, especially for email, cloud services and administrative accounts.
You should know that MFA is enabled. In practice, individual accounts often fall outside the policy, and guest users in particular lack MFA without anyone noticing. Sicra offers a system that reads your Entra ID directly and shows who lacks MFA, including guest users, so you can close the gaps before the holidays instead of discovering them afterwards. More on this under point 5.
Tip: Test MFA on both mobile and web before you log off for the summer. Also consider phishing-resistant MFA (such as passkeys or FIDO2 keys) for your most critical accounts, since traditional one-time codes can be intercepted in increasingly sophisticated phishing attacks.
Most serious attacks start with an email. What if you could reduce the number of attacks that reach the inbox at all? Sicra can remove phishing and spoofing messages before they reach your employees, in just 15 minutes.
Try our email protection free this summer and experience how we can protect your business effectively and immediately.
Install the necessary security patches on servers, systems and machines before the holidays. This applies in particular to:
Prioritize known vulnerabilities that are already being actively exploited, these are the ones attackers look for first.
If you have a SOC service, such as Arctic Wolf MDR, make sure the contact information is up to date and that someone is responsible for following up on alerts throughout the holidays. If not, consider temporary monitoring during the summer weeks. An alert left unhandled for three weeks is, in practice, no monitoring at all.
The summer is a good opportunity to clean up who actually has access to what. Many organizations have poorer control here than they think. Do a quick access review and ask the questions:
Are there users who have left but still have active accounts and access?
Have temps and summer staff been given more access than they need?
Are there accounts without MFA, or admin rights no one has an overview of anymore?
Are there old guest and supplier accounts that should have been deactivated?
The challenge is that this overview is often spread across several systems, and assembling it manually takes time few have right before the holidays. That is why Sicra offers a system that reads your Entra ID and gathers everything in a real-time dashboard: who has and lacks MFA, who has which access, and who has actually left but is still listed. Setup takes around an hour, and we then go through the results together with you.
The dashboard provides a strong security overview and shows what you can save on unused Microsoft licenses and other licenses you pay for without using. You can try it free for a week to see how good your control actually is before you log off for the summer. Get in touch if you would like this overview in place.
Who takes the first call if something happens? Make a simple plan that describes:
Who is available and when
Which suppliers can be contacted
How a security incident should be handled
Make sure the plan is stored in a place that is easily accessible to multiple people, so it can be found again even when key personnel are on holiday.
Limit the attack surface by disabling external access and test environments that are not needed during the summer weeks. Many attacks happen via open ports, forgotten services or temporary setups that were never cleaned up.
Send out a short summer reminder:
Be extra careful with emails, links and unexpected payment requests
Do not use open networks for work purposes
Be aware that fraud attempts can now look very convincing, even in flawless language
Report unusual activity, it is better to say something once too often
Do you have a backup? Good. Have you tested that it can actually be restored? Do it now. A backup you have never tried to recover data from is an assumption and involves a certain level of uncertainty. Also make sure at least one copy is protected against being changed or deleted, so it holds up against ransomware.
Whether you need a CISO-for-hire, help with security strategy, a technical review or support before or after the holidays, Sicra is ready to assist. We offer rapid security assessments, advice and practical help to get the most important measures in place.
Holiday time brings increased risk. With a few simple measures, you can set the stage for a safe and relaxing summer, both for your employees and for your IT systems.
.png?width=292&height=365&name=90dd117b-87c6-4f54-9a74-516e4beddade%20(1).png)


