The security program that only works when everyone is at their desk | Andrea Fortuna
Every August, without exception, someone’s SOC dashboard turns red at 3 a.m. while the two people who actually know how to respond are on a beach or a ferry, phone on airplane mode, out of office autoreply cheerfully promising a response “as soon as possible.” Attackers know this. They have known it for years, and they plan around it with the same discipline that legitimate businesses apply to their own seasonal calendars. Summer itself is not the danger. What it does, with brutal clarity, is reveal whether an organization’s cybersecurity program was ever built to survive contact with reality or whether it was built to survive an audit.
In brief
Summer attack spikes are not a mystery: reduced staffing, key-person dependency, and slower detection times create a predictable window that ransomware crews exploit every year.
The 2026 Sophos Active Adversary Report found that 88% of ransomware payloads are deployed outside business hours, exactly when monitoring coverage is thinnest.
NIS2 and DORA don’t mention August, but both demand continuous, demonstrable operational resilience, which summer coverage gaps directly contradict.
Documentary compliance (policies, PDFs, signed procedures) is not the same as operational compliance, a distinction ENISA’s own Handbook for Cyber Stress Tests was written specifically to close.
Italy’s ACN calendar makes autumn 2026 a hard deadline: baseline security measures under Determinazione 379907/2025 must be operational and evidenced within 18 months of first application.
The predictable arithmetic of August risk
There is nothing subtle about why attackers like summer. The 2026 Sophos Active Adversary Report, based on 661 incident response and MDR cases across 70 countries, found that 67% of intrusions traced back to identity-related weaknesses, that multi-factor authentication was missing where it mattered in 59% of cases, and that ransomware remains a firmly off-hours activity, with 88% of payloads deployed at night or on weekends and 79% of data exfiltration happening in the same low-visibility windows. None of this requires a zero-day. It requires an organization that quietly downgrades its own defenses for six to eight weeks a year, running with fewer eyes on the SIEM and slower escalation paths, and hopes nobody notices.
The mistake is treating this as a seasonal anomaly to patch over with a memo about “vigilance during the summer period.” The problem is structural, not seasonal. If a security program only works when every key person is at their desk, on their normal shift, reachable within minutes, then it was never a resilient program, merely a set of individual habits dressed up as a process, and habits go on holiday along with the humans who hold them. Attackers have been exploiting this rhythm for years, and by now it barely qualifies as a tactic; it is closer to a seasonal business model.
Why documentation was never the point
I’ve written before about how security awareness training optimizes for completion certificates rather than behavior change, and the same critique applies to how many organizations approach NIS2 and DORA more broadly: policies get signed, boxes get ticked, and the actual behavior of the system under stress remains untested. Summer is where that gap stops being theoretical and starts being expensive. A binder full of incident response procedures means nothing if the on-call rotation collapses the moment two people book the same two weeks off. A risk register reviewed quarterly by the board means nothing if nobody actually rehearsed what happens when the primary incident commander is unreachable and the backup was never properly briefed.
Regulators have started saying this explicitly rather than leaving it implicit in the text. ENISA’s Handbook for Cyber Stress Tests, published to support supervisory authorities under NIS2, defines a cyber stress test as an assessment of an organization’s ability to “withstand and recover from significant cybersecurity incidents… in different risk scenarios,” and lays out a five-step methodology that goes well beyond checking whether a document exists. As I discussed when looking at what operational resilience under DORA actually demands, the regulation’s testing pillar requires scenario-based exercises that prove recovery workflows function under realistic pressure, not idealized ones. A tabletop exercise conducted in March with a full team present tells you very little about what happens in July with 40% of that team unreachable. If your test scenario has never included “half the response team is on leave and the other half just landed from a different time zone,” you haven’t tested resilience, you’ve tested a best-case simulation with the difficulty slider turned down.
NIS2 pushes in the same direction from the other end. Directive (EU) 2022/2555 frames risk management as a continuous obligation on governing...