The security program that only works when everyone is at their desk
Every August, without exception, someone’s SOC dashboard turns red at 3 a.m. while the two people who actually know how to respond are on a beach or a ferry, phone on airplane mode, out of office autoreply cheerfully promising a response “as soon as possible.” Attackers know this. They have known it for years, and they plan around it with the same discipline that legitimate businesses apply to their own seasonal calendars. Summer itself is not the danger. What it does, with brutal clarity, is reveal whether an organization’s cybersecurity program was ever built to survive contact with reality or whether it was built to survive an audit.

In brief
- Summer attack spikes are not a mystery: reduced staffing, key-person dependency, and slower detection times create a predictable window that ransomware crews exploit every year.
- The 2026 Sophos Active Adversary Report found that 88% of ransomware payloads are deployed outside business hours, exactly when monitoring coverage is thinnest.
- NIS2 and DORA don’t mention August, but both demand continuous, demonstrable operational resilience, which summer coverage gaps directly contradict.
- Documentary compliance (policies, PDFs, signed procedures) is not the same as operational compliance, a distinction ENISA’s own Handbook for Cyber Stress Tests was written specifically to close.
- Italy’s ACN calendar makes autumn 2026 a hard deadline: baseline security measures under Determinazione 379907/2025 must be operational and evidenced within 18 months of first application.
The predictable arithmetic of August risk
There is nothing subtle about why attackers like summer. The 2026 Sophos Active Adversary Report, based on 661 incident response and MDR cases across 70 countries, found that 67% of intrusions traced back to identity-related weaknesses, that multi-factor authentication was missing where it mattered in 59% of cases, and that ransomware remains a firmly off-hours activity, with 88% of payloads deployed at night or on weekends and 79% of data exfiltration happening in the same low-visibility windows. None of this requires a zero-day. It requires an organization that quietly downgrades its own defenses for six to eight weeks a year, running with fewer eyes on the SIEM and slower escalation paths, and hopes nobody notices.
The mistake is treating this as a seasonal anomaly to patch over with a memo about “vigilance during the summer period.” The problem is structural, not seasonal. If a security program only works when every key person is at their desk, on their normal shift, reachable within minutes, then it was never a resilient program, merely a set of individual habits dressed up as a process, and habits go on holiday along with the humans who hold them. Attackers have been exploiting this rhythm for years, and by now it barely qualifies as a tactic; it is closer to a seasonal business model.
Why documentation was never the point
I’ve written before about how security awareness training optimizes for completion certificates rather than behavior change, and the same critique applies to how many organizations approach NIS2 and DORA more broadly: policies get signed, boxes get ticked, and the actual behavior of the system under stress remains untested. Summer is where that gap stops being theoretical and starts being expensive. A binder full of incident response procedures means nothing if the on-call rotation collapses the moment two people book the same two weeks off. A risk register reviewed quarterly by the board means nothing if nobody actually rehearsed what happens when the primary incident commander is unreachable and the backup was never properly briefed.
Regulators have started saying this explicitly rather than leaving it implicit in the text. ENISA’s Handbook for Cyber Stress Tests, published to support supervisory authorities under NIS2, defines a cyber stress test as an assessment of an organization’s ability to “withstand and recover from significant cybersecurity incidents… in different risk scenarios,” and lays out a five-step methodology that goes well beyond checking whether a document exists. As I discussed when looking at what operational resilience under DORA actually demands, the regulation’s testing pillar requires scenario-based exercises that prove recovery workflows function under realistic pressure, not idealized ones. A tabletop exercise conducted in March with a full team present tells you very little about what happens in July with 40% of that team unreachable. If your test scenario has never included “half the response team is on leave and the other half just landed from a different time zone,” you haven’t tested resilience, you’ve tested a best-case simulation with the difficulty slider turned down.
NIS2 pushes in the same direction from the other end. Directive (EU) 2022/2555 frames risk management as a continuous obligation on governing bodies, not an annual snapshot, and the periodic review requirements I covered when discussing how to make NIS2 reviews work in real life exist precisely to stop organizations from treating compliance as something verified once a year under ideal conditions. Reality changes every June whether the compliance calendar likes it or not.
Key-person dependency is a design flaw
There is a particular kind of organizational denial that shows up every summer: the quiet acknowledgment that “if Marco is out, we’re basically blind,” followed by absolutely no structural change to fix it. I’ve argued elsewhere that tabletop exercises work best when they are treated as rehearsal rather than punishment, and the same logic applies here: the point of running a summer-specific scenario is discovery, not punishment: in a low-stakes setting, you learn exactly where your process depends on a single irreplaceable human. If that discovery only happens during an actual incident in August, you’ve paid for the lesson in the worst possible currency.
Key-person dependency should be understood as a design flaw in how the security function was built, not a staffing shortage, and it tends to correlate closely with the structural gaps I described when writing about why Italian cybersecurity is structurally behind: compliance calendars and portal registrations accumulate, while the underlying capability to actually run detection and response with a reduced team never gets tested. Fixing it isn’t glamorous. Given that Sophos found MFA absent in 59% of incidents it investigated, enforcing phishing-resistant multi-factor authentication across the board is a reasonable starting point, alongside runbooks detailed enough that a competent but unfamiliar analyst can follow them without a phone call, on-call authority distributed across more than two people, and 24/7 monitoring coverage (via outsourced MDR or a virtual CISO arrangement if internal capacity runs thin) treated as a non-negotiable baseline control rather than a nice-to-have reserved for budget-rich years.
What autumn deadlines actually demand
The timing this year makes the summer stress test unusually consequential. Under ACN Determinazione 379907/2025, applicable since 15 January 2026, entities already on the NIS list have 18 months to adopt the baseline security measures set out in Annexes 1 and 2, which means the deadline for many organizations lands squarely in autumn 2026, with documentary evidence expected: system logs, audit reports, training records, the whole apparatus that proves controls were not just adopted but actually integrated into daily operations. Miss that bar and the exposure goes beyond reputational embarrassment: the Italian NIS decree implementing Directive (EU) 2022/2555 provides for administrative sanctions that can reach 10 million euros or 2% of global annual turnover, whichever number makes the CFO more uncomfortable.
DORA’s incident reporting clock is even less forgiving of a slow August response. Under Regulation (EU) 2022/2554, Article 19, financial entities must submit an initial notification within four hours of classifying an incident as major, an intermediate report within 72 hours, and a final report within a month once the root cause analysis is complete. Those timers do not pause because the compliance officer is on a train to the Dolomites. An organization that spent summer running with a skeleton crew and no tested fallback process will discover, in October, that its evidence trail has gaps exactly where the auditors look first. The organizations that treat summer as a genuine stress test, running realistic scenarios now, distributing key-person knowledge now, and fixing the coverage gaps now, will walk into the autumn deadline with real evidence instead of a scramble to backfill documentation after the fact. Everyone else will find out the hard way that a directive doesn’t care whether your incident commander was reachable. It only cares whether the incident was handled.
FAQ
Why do cyberattacks increase during the summer? Reduced IT staffing, delayed patching, more remote work over unsecured networks, and slower incident detection all converge in summer, giving attackers a wider window between compromise and response.
Does NIS2 or DORA specifically require summer coverage plans? Neither directive names August explicitly, but both require continuous risk management, tested incident response, and demonstrable operational resilience, obligations that do not pause for staff holidays.
What happens if an organization fails to demonstrate operational resilience by the NIS2 deadline? For entities already on the NIS list since 2025, the ACN deadline requires baseline security measures to be fully operational with documentary evidence within 18 months, and non-compliance exposes organizations to administrative sanctions up to 10 million euros or 2% of global annual turnover.