In a nutshell: Summer is peak season for ransomware. According to Semperis’ Ransomware Holiday Risk Report, up to 86% of organizations are attacked on a weekend or holiday—precisely when security staff levels drop by half. The good news: the attack surface doesn’t change in the summer. Endpoints that have been hardened in advance remain protected even without active monitoring. Here’s how to prepare your workstations and servers before the summer break.
Cyberattacks are not evenly distributed throughout the year: they tend to occur during periods when security teams are at their smallest, particularly during the summer and on holidays. It’s not that technical vulnerabilities increase in July and August—it’s that your ability to detect and respond plummets. For a CISO or CIO at an SMB or mid-sized company, the challenge is therefore not whether you’ll be targeted during the holidays, but how long a breach will go undetected. And that’s exactly where endpoint hardening makes all the difference.
Why Do Cyberattacks Increase During the Summer?
Attackers exploit a seasonal imbalance: the threat remains constant, but defenses weaken. Three factors converge during the summer months, creating a natural window of opportunity for cybercriminals.
Reduced security staffing levels. This is the key factor. According to Semperis’ 2025 Holiday Ransomware Risk Report (a survey conducted in ten countries, including France), 78% of organizations reduce their SOC staffing levels by 50% or more during holidays and weekends, and 6% do not maintain any monitoring at all during these periods. The reasons cited are related to staff: 62% want to preserve their teams’ work-life balance, 47% consider the company to be closed, and 29% simply believe they won’t be attacked.
A decline in vigilance. Vacations, temporary replacements, and remote work from vacation destinations: employees on the job often have less control over procedures and must handle more urgent matters with fewer resources. However, according to a figure from the World Economic Forum regularly cited by the DGSI, nearly 95% of data breaches involve human error. CEO fraud—a fake urgent wire transfer order sent while an executive is away—remains one of the most effective attacks of the summer for this reason.
A longer response time. Fewer analysts to triage alerts means a longer MTTD (Mean Time To Detect) and a longer lateral movement window for the attacker. An administrator account compromised on August 14 can remain active for several days before a human notices the anomaly—more than enough time to encrypt an entire network.
What do the statistics say about the seasonality of attacks?
The data points to a clear trend: the majority of the most serious attacks occur outside of business hours, during periods of low staffing levels. The figures below, drawn from industry-specific studies, provide objective evidence for a phenomenon that has long been treated as mere intuition.
- Up to 86% of victims were attacked on a weekend or a holiday. Semperis’ 2024 Ransomware Holiday Risk Report, which surveyed organizations in the United States, the United Kingdom, France, and Germany, put this figure at 86%. The 2025 edition, expanded to include ten countries, reports a rate of 52%—a different scope, but the same finding: the majority of attacks occur when people let their guard down.
- According to a study by the DFCG (National Association of Financial and Management Control Directors), 30% of French companies have observed an increase in cyberattacks during holidays and weekends.
- A 64% increase in reported attacks during the summer compared with the previous summer, according to data cited by the publisher Oodrive—a figure that illustrates the seasonal nature of the risk.
- According to Semperis, 9 out of 10 ransomware attacks compromise the identity system (Active Directory or Entra ID). This is a critical point: the directory is the key target that attackers seek to compromise in order to spread, and this is precisely what hardening workstations and servers is designed to protect.
The situation in France during the summer of 2026 confirms the tension. In the week of July 20–24 alone, CERT-FR reported the active exploitation of critical vulnerabilities in SonicWall SMA 1000 gateways (CVE-2026-15409 and CVE-2026-15410), an SQL injection vulnerability in WordPress, and published a series of advisories regarding privilege escalation in Linux kernels (Debian, Red Hat) and ESET products. That’s a lot of patches to apply… at a time when IT teams are stretched thin.
Does summer really create new faults?
No—and that is the strategic key to this article. The summer period does not create any new technical vulnerabilities: your attack surface on August 15 is exactly the same as it was on June 15. What changes is your ability to respond. A patch not applied in July remains an exploitable CVE for three more weeks; an unprioritized alert remains an unaddressed alert.
This distinction changes how we prepare. Strengthening detection for the summer requires mobilizing personnel—on-call shifts, rotations, a managed SOC—which is costly and difficult to sustain over two months. Conversely, reducing the attack surface in advance does not require any human presence during the holidays. A system with unnecessary services disabled, privileged accounts locked down, and a configuration that follows a CIS or ANSSI baseline simply does not offer the same opportunities to an attacker—regardless of whether someone is monitoring it or not.
This is the very principle of hardening: not relying solely on detection (which requires a response), but on structural prevention (which works on its own). The ANSSI-BP-028 guideline on system hardening and the CIS Benchmarks formalize hundreds of configuration parameters specifically for this purpose.
How Should You Prepare Your Endpoints Before the Summer Break?
Preparation takes place in three phases: before, during, and after the holidays. The bulk of the effort should be focused onthe “before” phase, when your teams are still available and any measures put in place will continue to provide protection without requiring further action.
Before the holidays:
- Apply any pending critical patches, prioritizing actively exploited vulnerabilities reported by CERT-FR. Don't put off applying a patch "until after the summer break."
- Harden the configuration of your workstations and servers according to a CIS or ANSSI baseline: disable unnecessary services and protocols, restrict local administrator privileges, disable Office macros, and implement a password policy.
- Protect the identity system: review privileged accounts, deactivate dormant accounts, and monitor Active Directory and Entra ID access.
- Check your backups: Perform a test restore and make sure you have an offline (immutable) copy that is out of reach of ransomware.
During the holidays:
- Maintain a standby team—even a small one—capable of initiating an isolation procedure.
- Enable alerts for high-signal events (creation of an admin account, login from abroad, mass encryption).
After the holidays:
- Resume the patch management cycle as soon as you return.
- Analyze the logs from that period to detect any unusual activity that may have gone unnoticed.
What the “pre-summer” phase has in common is that these are preventive measures which, once implemented, require no ongoing monitoring to remain effective. It’s the best return on effort for a worry-free summer.
FAQ — Summer Cyberattacks and Endpoint Hardening
Why do ransomware attacks strike mainly on weekends and holidays?
Because security staffing levels are reduced during these periods. According to Semperis, 78% of organizations cut their SOC staffing levels by half or more during holidays and weekends. Attackers exploit this extended response time to encrypt as many systems as possible before a human can react.
Are there really more cyberattacks in the summer?
Studies indicate that attacks are concentrated during periods of low staffing levels rather than representing an absolute increase in volume. In France, 30% of companies report seeing a surge during vacation periods (DFCG study), and some software vendors have recorded increases of up to 64% in attacks from one summer to the next.
Does hardening provide protection if no one is monitoring the system during the holidays?
Yes, that’s precisely the point. Unlike detection, which requires a human response, hardening structurally reduces the attack surface: a properly configured system remains secure whether or not someone is monitoring it. It’s the most appropriate measure during a period of reduced staffing.
What are the top priorities to take care of before leaving?
Apply pending critical patches, disable dormant accounts, restrict administrator privileges, harden the configuration according to a CIS/ANSSI baseline, and test an offline backup restore.
Are small and medium-sized businesses affected as much as large corporations?
Yes, and often even more so: they rarely have a 24/7 SOC, so their ability to respond drops to virtually zero during the summer. This is precisely the scenario in which proactively reducing the attack surface is most cost-effective.
Sources
- Semperis — 2025 Holiday Ransomware Risk Report
- Semperis — 2024 Ransomware Holiday Risk Report
- CERT-FR — Security Advisory
- CISA — Ransomware Awareness for Holidays and Weekends (AA21-243A)
- CIS Benchmarks
- ANSSI — Recommendations and Hardening Guides
Cyberlib automatically hardens your endpoints before summer—and keeps them compliant while you’re on vacation. Our agentless SaaS platform continuously applies and monitors more than 1,586 hardening settings (CIS baselines, ANSSI-BP-028) on your Windows, Linux, and macOS workstations and servers, without any human intervention. Request a demo so you can go on vacation with peace of mind.
