Vacation – datensicherheit.de Informationen zu Datensicherheit und Datenschutz https://www.datensicherheit.de Datensicherheit und Datenschutz im Überblick Sun, 09 Aug 2026 13:51:23 +0000 de hourly 1 6 Strategies for Maintaining Cyber Resilience During Peak Vacation Periods https://www.datensicherheit.de/6-strategies-cyber-resilience-maintain-vacation https://www.datensicherheit.de/6-strategies-cyber-resilience-maintain-vacation#respond Sun, 09 Aug 2026 13:51:22 +0000 https://www.datensicherheit.de/?p=56196 Summer vacations can create unexpected vulnerabilities in an organization’s cyber resilience. Reduced IT staffing, unclear responsibilities, and poorly coordinated recovery processes can delay an effective response when incidents occur. To help organizations remain prepared during periods of increased absences, Mark Molyneux, Field CTO at Commvault, outlines six practical recommendations for maintaining cyber resilience and ensuring recovery processes remain effective—even when key IT personnel are away.

[datensicherheit.de, 08/09/2026] Many IT managers are currently on their “summer break”—hackers, on the other hand, don’t seem to be taking any time off. In fact, it’s safe to assume they’re currently very active, because when IT departments and those responsible for cyber resilience go on vacation, the processes for ensuring cyber resilience in an emergency may be noticeably compromised. The problem apparently lies not only in a lack of on-site personnel but also in the flawed organization of “recovery” processes. For example, if an IT administrator has not designated a substitute or if the dual-control principle is not followed when the relevant personnel are absent, there is a risk of
a delay in recovery right from the start. Under the motto “Vacation Time – Summer Time – Incident Time,” Mark Molyneux, “Field CTO” at Commvault, offers six pieces of advice for times of reduced staffing in his latest comment.

commvault-mark-molyneux

Foto: Commvault

Mark Molyneux appeals not to let the summer vacation season turn into a “summer of crisis,” but rather to make it a time when team members can fully demonstrate their strengths

Vacation and Holiday Season: Peak Season for the Tourism Industry and Cybercrime

The vacation season is considered a period of “special operating mode with increased control requirements”—in bureaucratic terms, known among technicians as “heightened vigilance.” “This summer, IT teams should focus more on vulnerabilities, accelerated patch cycles, and incident management, because ‘Mythos’ and other ‘Frontier AI’ models have changed the landscape of risk assessment” Molyneux suggests.

More vulnerabilities are evidently being disclosed that could threaten an organization’s resilience. It is essential to refocus efforts before these new AI threats impact day-to-day operations.

In a 2025 analysis, CheckPoint highlighted the following connection: “We’ve arrived in the middle of the vacation and holiday season. But for two industries, peak season has now begun: the tourism industry and cybercrime.” According to the “The State of Cyber Security 2025” report, the number of cyberattacks on tour operators and travel agencies has increased significantly. These companies have apparently become a greater target for cybercriminals during these months, as they are heavily dependent on functioning IT systems during their peak revenue season and are therefore easier to blackmail with ransomware.

The summer vacation season must be well prepared for, securely supported, and carefully evaluated

Another threat to the tourism industry is data espionage attacks. Statistics from the European Union Agency for Cybersecurity (ENISA) and the “Computer Emergency Response Team” (CERT-EU) confirm the general risk that the total number of attacks across all industries is rising steadily year after year.

Checkpoint had documented a year-over-year increase in hacker activity for the summer quarter of 2025 based on an analysis of data leakage sites” reports Molyneux.

To successfully navigate this important but risky vacation period, ENISA, other organizations, and IT consultants therefore recommend a clear strategy: “Prepare before the summer period, implement stricter controls during these months, and analyze the insights gained after the summer to adjust measures for the winter vacation season!”

6 Commvault Recommendations for Strengthening Operational Security and Resilience

Commvault’s cyber resilience experts therefore offer six practical tips on how IT managers can adequately prepare for the holiday season:

  1. Officially define the summer operating mode!
    Security experts have called for clear roles, responsibilities, and the availability of security functions. The BSI also warns that staff absences and knowledge silos could jeopardize business processes. Those responsible for the security, protection, and availability of IT and data should therefore declare and define a “Reduced Staff Operating Mode” for the months of July and August.
    This mode should prioritize critical services and account for the minimum requirements for necessary operational capability. It should also designate those responsible, their deputies, and on-call staff; document the relevant contacts in the “supply chain”; and define escalation times.
  2. Appoint deputies and enforce the dual-control principle!
    No critical process should depend on a single person: Administrators, the “Security Operations Center” (SOC), and those responsible for “Network,” “Identity and Access Management” (IAM), “Backup,” “Cloud,” “Service Desk,” “Procurement/Finance,” and “Communication Approvals” all need designated deputies. Equally important are inventory lists of privileged accounts and their regular validation.
  3. Keep patch and vulnerability monitoring active!
    The number of vulnerabilities disclosed by AI models such as “Mythos” will increase. The resulting acceleration and increased frequency of attacks or attempted attacks may require additional attention. Critical vulnerabilities should not be left until after the holidays:
    IT security managers must ensure that daily or regular checks of CERT/CSIRT, vendor, and threat feeds are conducted and that risks are prioritized. Mitigation measures should be tested, implemented, and documented in advance. The general recommendation is to monitor relevant vulnerability channels, perform scans, and address critical vulnerabilities quickly.
  4. Freeze non-critical changes—define critical and emergency changes
    During the vacation period, the following applies: Emergency procedures for critical patches and incidents must be maintained, while non-critical changes should be postponed.
    Industry-standard emergency management requires that patches and changes be planned, approved, documented, tested, and safeguarded by a “recovery” solution. Equally important are change procedures that include risk analysis, testing, rollback, and documentation.
  5. Ensure Backup & Recovery Readiness!
    Especially ahead of the summer operating mode, it is important to verify that backups are functioning properly. Those responsible should not only ensure that backups are running, but also that they can actually restore critical services with them:
    The test catalog includes “restore” tests as well as verifying data integrity, “offsite/offline/immutable” copies, separate administrator rights, and access to a documented “recovery” plan even when the corporate network is unavailable. Commvault experts also strongly recommend backup plans, secure and separate storage, integrity checks, and regular recovery tests.
  6. Run through your “incident response runbooks”!
    Especially before the summer vacation season, I recommend conducting a “tabletop exercise” for at least three incident scenarios: “phishing/account takeover,” “ransomware/backup tampering,” and “critical SaaS/cloud outage.”
    ENISA recommends tested “incident response” procedures, “playbooks/runbooks,” and annual tests that incorporate “lessons learned.”

Cyber resilience in the summer therefore requires strong coordination of human and technical capabilities, especially given the increasing use of artificial intelligence (AI). Molyneux concludes with this advice: “It also requires backing and support from business units to minimize non-critical business changes and reduce pressure on teams. This gives them more time to adapt their processes. Summer shouldn’t turn into a crisis-filled summer—rather, it should be the moment when team members develop their strengths!”

Key findings:

  • Summer vacation, in particular—like other periods of collective distraction—is considered peak season for cybercrime and must be properly planned for and followed up on to continuously and consistently minimize the attack surface.
  • Security and resilience, as essential criteria, are a “top priority” for executives—in general, a security culture that promotes responsibility and proactive thinking should be embedded and exemplified.
  • Since the summer vacation period in particular is considered a time of “special operating mode with heightened control requirements,” the company’s overall security strategy should take this into account—because, in a sense, it is then the “weakest link” in the IT security chain.
  • No matter how sophisticated the security measures may be, one should always assume that malicious incidents—that is, breaches of cyber or IT security and data protection—will occur; thus, proven emergency and recovery plans must be able to stand the test of time, especially during such a phase.
  • Molyneux concluded by stating that, despite the summer vacation season, security and resilience are fundamentally cross-functional operational responsibilities.

More information on this topic:

Commvault
What Commvault Does for Our Customers / Commvault Cloud delivers unified resilience at enterprise scale — bringing together data security, identity resilience, and cyber recovery into one simple, powerful, cloud-native platform.

Linkedin
Mark Molyneux

SECURITY INSIDER, 23.06.2025
The State of Cyber Security 2025 Check Point zeigt Risiken für Tourismusbranche auf

HOGAPAGE, Sarah Kleinen, 30.07.2026
Datenklau / Cyberangriff auf Hotel-Softwaredienstleister: Das sollten Betriebe jetzt tun / Nach einem Cyberangriff auf einen bundesweit agierenden Hotel-Softwaredienstleister sind personenbezogene Gästedaten abgeflossen. Was betroffene Hotels und Gäste jetzt beachten sollten.

enisa EUROPEAN UNION AGENCY FOR CYBERSECURITY, 01.10.2025
ENISA Threat Landscape 2025

CERT-EU, 08.04.2026
Threat Landscape Report 2025: A Year in Review

Netzpalaver, 17.11.2025
Über 500 neue Opfer von Ransomware pro Monat

michael wessel THINK DIGITAL, Juni 2025
Sommerzeit = Risikozeit: Warum Cyberangriffe in der Urlaubszeit zunehmen

datensicherheit.de, 27.07.2026
Wenn die Erwartungshaltung mit auf Reisen geht: Zwei Drittel der Berufstätigen auch im Urlaub erreichbar / Repräsentative Bitkom-Umfrage offenbart abermals Kehrseite der ständigen Verfügbarkeit bzw. Erreichbarkeit auch im Urlaub

datensicherheit.de, 05.08.2025
Ferienzeit als Hochsaison für Angreifer – DNS kann bei pre-emptive Security und Zero Trust für Entlastung sorgen / Da nahezu die gesamte Kommunikation über das „Domain Name System“ (DNS) läuft, ist es der ideale Ansatzpunkt für eine Sicherheitslösung

datensicherheit.de, 02.07.2024
Urlaub kommt so unerwartet wie Weihnachten: Aufmerksamkeitsdefizite bei der Cyber-Sicherheit drohen / Sophos gibt Tipps, um insbesondere die Ferienzeit ohne „Cyber-Frust“ genießen zu können

]]>
https://www.datensicherheit.de/6-strategies-cyber-resilience-maintain-vacation/feed 0