We’re rushing headlong into the holiday season, and while the rest of the office is preparing fancy dress costumes and secret Santas, the IT team need to be focused on a particularly risky time of year. The seasonal increase in remote working and security attacks, combined with operating with fewer IT staff, is not an ideal combination. Here, then, is a checklist of items that IT managers need to be working through at this time of year.
1. Prepare for remote working
The Christmas holidays will result in an increase in remote working in many firms, especially during that awkward interregnum between Christmas and New Year. IT teams must prepare for this in advance by:
- Checking multi-factor authentication is enforced everywhere, especially on VPN and privileged accounts.
- Ensuring that password-reset procedures are watertight, especially when people are not in the office to verify face-to-face. Huge ransomware attacks at retailers such as Marks & Spencer this year were blamed on inadequate password-reset procedures. Retailers must be particularly wary of falling foul at their busiest time of year.
- Check VPN capacity is adequate to cope with an increase in people working from home โ you don’t want to be fielding angry calls over the holidays when staff can’t access the network.
2. Plug any holes
This should be standard practice, but it’s especially important at this time of year to:
- Disable any stale accounts, such as those of former employees, interns, former contractors or seasonal staff.
- Audit firewall rules to check for anything that was opened temporarily, but never closed again.
3. Harden monitoring and alerts
With IT teams likely to be running on skeleton crews over the Christmas period, it’s important to:
- Ensure out-of-hours alerts are reaching the right on-call staff.
- Test logging and alert systems before the Christmas break to ensure everything is working as expected.
- Ensure that alerting systems are set up for the most high-risk activity, such as failed logins, logins from unusual locations (remembering that staff may be travelling over the holidays) and unexpected outbound traffic.
4. Plan your patches
Patches from major vendors tend to die down at this time of year, not least because they’re on holiday along with everyone else. But you still need to ensure there’s a plan in place if an emergency patch is released that needs urgent attention โ something on the scale of the Windows CrowdStrike issue that struck in 2024. If a similar event were to happen over the holidays, do you have a plan to cope with it?
You also need to make sure that all essential patches are in place before everyone breaks for the holidays. Prioritise public-facing systems and critical vulnerabilities. You don’t want to be leaving routine patching to a skeleton IT staff over the holidays, in case something goes wrong. Create a hard freeze for any major infrastructure changes.
5. Prepare for a surge in attacks
Christmas is a peak ransomware period, with attackers targeting Christmas shoppers and encouraging people to click on links for what they think are parcel delivery updates, but are actually malware.
In preparation you should consider:
- Tightening email filtering and attachment rules.
- Check endpoint detection is up to date and running correctly.
- Communicating with staff about the dangers of clicking on links in emails at this time of year, perhaps with examples of malicious messages.
- Checking privilege lists to ensure nobody has elevated privileges that doesn’t require them.
6. Check for building issues
Companies often perform building maintenance works over holiday periods while the office is quiet. However, this can create issues for IT teams and equipment that need to be considered, such as:
- Can you get physical access to the building if required?
- Are server rooms going to be affected by scheduled maintenance?
- Could maintenance to air-conditioning systems create over-heating issues?
- Are UPS batteries healthy in case of power cuts?
- Do you have alerts set up for temperature and power issues?
Make sure you’re able to answer all of these questions before you leave for the holidays.
7. Prepare for reduced staffing
At this time of year, you’re almost certainly going to have fewer IT staff on duty than normal. Junior staff may be given greater responsibility than they’ve ever faced before. That requires a clear plan and procedures, so that if the worst does happen, staff know what to do.
First, you need a clear escalation plan, so that on-duty staff know who to contact if an incident occurs and how to get hold of them. Staff may also need key contacts at partners such as cloud providers, so they’re able to report outages or check for service updates.
You should ensure emergency plans or “runbooks” are up to date, so there are clear procedures for events such as VPN resets or firewall failures. Christmas morning is not the time to discover the recovery plan is two years out of date.
8. Communicate with the rest of the company
It’s not only vital that the IT team knows what they’re doing over the Christmas break, it’s vital that the rest of the company knows how to reach IT staff too.
- Make sure that everyone in the company knows how to reach IT staff during the break.
- Remind staff of procedures for eventualities such as lost or stolen devices.
- Reinforce ground rules: for example, it’s not acceptable to download data from the corporate network and work without the VPN just because you’re spending Christmas with the in-laws!
Do all this, and you truly can enjoy your break!
Articles by our “friendly” IT manager Michael Dear on TechFinitive