Ho ho ho, hack hack hack: why Semperis is warning IT leaders about holiday attacks

Everyone deserves a break, especially cybersecurity workers after an exhausting year of countless attacks. But there’s a problem here: ransomware gangs never take a break and see the festive holiday period as the perfect time to attack. To find out how big this problem is, Semperis has published its Ransomware Holiday Risk Report. Here we interview Dan Lattimer, Area VP at Semperis, to dig into the findings.

Let’s start with two key numbers from the report. 86% of participants who experienced a ransomware attack were targeted on a weekend or holiday, when staffing is most likely to be reduced.

Despite this, 85% reduced staffing in their Security Operations Centre by up to half on holidays and weekends.

“Fewer eyes on the network traffic and less attention to suspicious activity mean that hackers can slip in unnoticed โ€“ leaving organisations wide open to cyberattacks,” Dan told us. “Attackers obviously expect this behaviour and use it to their advantage, carrying out ransomware attacks during times when employee distraction is high.”

The report highlights other worrying trends too, and Dan goes into more depth about these below. Issues such as over-confidence in your company’s ability to withstand attacks and the growing sophistication of attackers: they know when you’re at your weakest, and that includes the crucial period when companies are going through M&A proceedings.

The big question is what you can do to protect yourself, and fortunately Dan provides practical advice to help you do exactly that. And there’s no time to wait, as some steps need to be taken before we all go off on our well-earned breaks.

What motivated Semperis to commission this report? Did you instinctively know its findings? 

Weโ€™ve seen time and again how cyber attackers strike on holidays and weekends. The most recent example of this was the attack on Blue Yonder that affected retailers and supermarkets in the US and the UK ahead of Thanksgiving, leaving shelves bare. The hugely damaging Transport for London hack started on a Sunday and the 2023 attack on payroll provider Zellis also unfolded over a weekend, affecting tens of thousands of British Airways, Boots and BBC staff.

While we already knew that ransomware groups prefer to attack organisations outside business hours and during material events, when defences areย weakestย and security staffing is reduced, the aim of the Semperis Ransomware Holiday Risk Report was to determine the size of the problem. This is why we surveyed 900 IT and security leaders globally about the ransomware attack patterns they had experienced, and to find out how they defend their organisation against identity-based attacks.

Did anything surprise you in terms of the report’s findings? Or did one company’s story stand out?

The report did uncover striking gaps in ransomware defences related to reduced security staffing out-of-hours. As many as 86% of surveyed organisations that were attacked were targeted on a holiday or weekend. Yet, 85% said they reduce security staffing by up to 50% during those periods, with some not staffing their Security Operations Centre at all.

Fewer eyes on the network traffic and less attention to suspicious activity mean that hackers can slip in unnoticed โ€“ leaving organisations wide open to cyberattacks. Attackers obviously expect this behaviour and use it to their advantage, carrying out ransomware attacks during times when employee distraction is high.

In addition, the report also found that 63% of attacked respondents were targeted during a major corporate event such as a merger, acquisition, or IPO. In finance, that number even jumped to 76%, which is alarming, given the presence of stricter security mechanisms such as Sarbanes-Oxley and Graham-Bliley.

Adding to these issues is the fact that many organisations overestimate their identity defences. We know that in nine out of ten ransomware attacks, hackers compromise their victimโ€™s identity system, usually Microsoft Active Directory (AD) or Entra ID. Yet the Semperis study results show that 35% of organisations donโ€™t budget for the defence of those critical systems, and 61% donโ€™t have dedicated AD or Entra ID backup strategies in place.

Clearly, this is not good enough: 81% of respondents believe they have the necessary expertise to protect against identity-related attacks, yet 83%ย suffered a successful ransomware attack within the past 12 months.

If there was one piece of advice you would give businesses in terms of cyber security during holidays, what would it be? 

Threat actors are calculated and persistent in their attack methods. As the threat to business, critical infrastructure and consumers is constant, security awareness and functionality must not wax and wane. If anything, organisations should increase their security persistence on holidays and weekends, knowing that threat actors are not taking time off and may target precisely these times.

Ideally, someone should be on call at all times. To ensure adequate staffing levels, security teams could rotate responsibilities with some employees taking weekdays off. In addition, businesses must have solid emergency procedures in place, with a tried and tested incident response plan that allows them to contain threats and restore operations quickly should an attack happen.

Organisations should also focus on building more resilience in their networks to combat the never-ending onslaught of ransomware attacks. Seeing how vulnerable AD is, corporate leaders should reevaluate risk from an operational resilience perspective to better understand the exposure of their IT infrastructure. Every corporate board should ask their CISO what their level of risk is and which systems, if taken out, would completely cripple their business. And then address any security gaps surrounding those systems.

And what about for 2025?

The ransomware epidemic will not go away. Already, we know that companies suffered ransomware attacks multiple times within the same year. 83% of companies we surveyed were targeted over a period of 12 months and of those, three quarters suffered multiple strikes, many within the span of a week. Few companies today see an alternative to ransom payments and even for those that pay the ransom, these attacks can cause ongoing business disruption.

To combat the threat, organisations will need to move their focus from cyber resilience to operational resilience overall. Improving their resilience will demand ongoing attention from organisations. There needs to be a focus not only on having the right defence processes in place but on people, too.

At the same time, for many organisations, cybersecurity spending will continue to reduce as a percentage of their revenue. With budgets being looked at more stringently, security teams will need to put a renewed focus on getting the basics right. Fundamental security steps such as managing endpoints, immediate patching, enforcing strict access management policies and employee training may seem boring but these cyber hygiene measures can be hugely effective.

Finally, for management and the Board to make an educated decision not to pay ransom, they need to know how long recovery will take and have confidence in the process. Organisations must therefore test their ransomware recovery plan in as close to a real-world scenario as possible before an attack occurs. That way, when disaster strikes, decision-makers will be confident in their ability to say โ€˜noโ€™ to attackersโ€™ demands.

With a lack of skilled staff, is there any way for companies to implement an AI-based SOC?

I think a better starting approach would be to maximise the value of your existing security stack. Most tools have automation and rules that can be customised to perform certain actions after detecting an unusual sequence or behaviour. This can help reduce the need for as many staff and make the existing team more productive. Doing the basics right, ensuring the organisation assumes there will be a breach and has a plan to try and contain, respond and recover from a breach is the foundation that more advanced tools and processes like AI can be built on.

Thinking in terms of risk, do you think companies underestimate the chances and the effectiveness of cyber attacks?  If so, why is that when so many headlines warn of the problems? 

The challenge is that risk is subjective. You could ask three people with security expertise about the probability of a ransomware attack impacting their business, and you will get three different responses. This makes having risk-based discussions challenging. Today, there are several common models used to standardise risk measurement. However, to be most effective, these models require the updating of information that is constantly changing. For instance, because threat groups rise to prominence and then disband and resurface with a new name and new members fairly frequently, it is essential to regularly update model data, including the attack techniques the groups use, which industries they typically target, what controls they have in place and more.

Based on your time working with government agencies, whilst you were at CyberArk, is there a lesson that other organisations and businesses can take from the way that governments protect themselves from cyber attacks?

Governments have a few advantages in that they are collaborative and can share huge amounts of information with each other and corporations. This allows them to use their collective knowledge to assess threats and to learn from each other about how to defend themselves or approach new issues in a new way.

Another common thing the government does, specifically when looking at creating a large impactful project, is to vet their idea by welcoming insights from industry experts as part of an โ€˜industry review’. In these sessions, a department will outline its goals and what they wish to achieve with a given project. They will then ask a large group of independent thinkers and industry experts, including suppliers and integrators, to challenge the legitimacy of their idea by strengthening it or debunking it.

And finally, do you want to make any predictions about this coming holiday season?

Unfortunately, it is very unlikely that threat actors will be taking time off to spend time with their families. Be diligent, prepare now during peacetime and upgrade your backup and recovery plans before threats turn your holiday cheer into a headache.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.