Skip to main content
Home

Protect your business from cyber threats during the summer period

Protect your business from cyber threats during the summer period

Protect your business from cyber threats during the summer period

Summer is a time when many businesses operate at a reduced pace. Staff are on annual leave, temporary cover takes over duties, and much of the day-to-day work is handled by fewer people than usual. For this very reason, summer is also a period when cybercriminals intensify their attacks. They know that routines are not as robust, that fewer people are reviewing emails and invoices, and that it is easier to get something through when the pace is lower. To reduce the risk of being affected, it is important to prepare well in advance of the holiday period.

Establish robust procedures and prepare the organisation

A first step is to review and strengthen the company’s procedures. When key personnel are absent, it becomes even more important that processes for invoice handling, payment approvals and the management of unexpected emails are clearly documented. Simple instructions and short checklists make a significant difference for both regular staff and temporary workers, reducing the risk of incorrect payments or suspicious requests going unnoticed.

At the same time, technological developments have made it increasingly difficult to detect fraud. Using so-called deepfakes—manipulated audio or video—cybercriminals can imitate, for example, an owner, CEO or finance manager. This can be used to pressure individuals into making rapid payments, disclosing passwords or granting access to internal systems. This type of attack is becoming more common and places higher demands on both procedures and awareness.

Strengthen security with improved access management

A key measure is to ensure that multi-factor authentication is used across all critical systems. This is one of the most effective ways to prevent unauthorised access, as it can stop attackers even if they manage to obtain a password. This is particularly important for email, cloud services and business systems, where a compromised account can have serious consequences.

Email remains the most common entry point for cyber criminals, and during the summer the volume of phishing emails and fraudulent payment requests increases significantly. It is therefore important to review the company’s email security and ensure that filters and warning functions are operating as intended. Tailored protection can stop many attacks before they reach the user.

Training and awareness are your strongest defence

It is equally important that staff know how to recognise suspicious emails and how to report them. Training is one of the most effective defensive measures, as many attacks target users directly. A short briefing before the summer period can go a long way in raising awareness. Focus on what fraudulent invoices and fake supplier emails typically look like, how to verify payment requests, and why links in unexpected emails or text messages should never be clicked. Temporary staff often require additional support, as they may lack the same context as permanent employees.

Effective incident management when something goes wrong

If an incident occurs, everyone must know what to do, who to contact and how to act to limit the damage. A strong incident response plan should describe how to isolate a suspected device, stop an incorrect payment and document the incident. It is also important that the plan is known across the organisation and ideally tested before the summer. A swift and structured response can be crucial in minimising the impact.

Additional risk areas to pay attention to

During the summer, there are also some recurring risks to be especially mindful of:

  • Changes to payment details
    A common type of fraud involves a “supplier” (cybercriminal) notifying the company of a new bank account number. Changes to payment details should always be verified via a known contact number- never using the contact details provided in the email - and should ideally be approved by two individuals.
  • Out-of-office messages
    Automatic replies that reveal who is away and who is covering can easily be exploited by cyber criminals. Keep out-of-office messages brief and avoid stating who is responsible for approving payments during the leave period.
  • On-call contact and responsibilities
    It is not sufficient to name a contact person, as that individual may also be unavailable. Appoint a clearly defined on-call contact and an escalation chain that applies throughout the summer period.

Do not forget backup and recovery

It is also essential to have up-to-date and tested backups that are separated from the regular IT environment. In the event of a ransomware attack, a functioning backup can be critical for restoring operations quickly.

Do you need advise about preparing your company for cyber attacks?

Contact us

Jenny Thörn
Jenny Thörn

Jenny works as an auditor and advisor at Azets.

Subscribe to our newsletter here

About Azets

Find your local office

Join our team