top of page

Summer Cybersecurity for Small Business: Why Vacation Season Is Peak Attack Season

May 7
14 min read

Updated: Aug 28



Summer cybersecurity for small business, covering how to protect your business and employees during vacation season.

Updated August 2026: I originally published this article in May as businesses were preparing for summer travel and vacation schedules. I have updated it as summer winds down because there is another part of vacation security that businesses should not overlook: reviewing what happened while people were away. I have also updated the travel security guidance based on new Microsoft threat intelligence involving hospitality networks and expanded the checklist to include a post summer review of Microsoft 365, devices, remote access, temporary permissions, backups, and security alerts.

Quick Answer

Summer changes how a small business operates. Owners travel, employees cover for one another, finance teams may be short staffed, company devices leave the office, people connect from unfamiliar locations, and normal approval processes can become more informal. Those changes can create opportunities for phishing, Business Email Compromise, account compromise, lost devices, and other security problems.


Summer cybersecurity for small business is not simply about adding another security product before everyone goes on vacation. It means making sure the security controls you already depend on continue working when people are away, employees know how to handle unusual requests, company devices remain managed, and someone is still reviewing alerts. As summer winds down, it also means looking back at what changed while everyone was traveling and making sure temporary access, overlooked alerts, delayed updates, and unusual account activity did not quietly follow everyone back into the office.


Why Vacation Season Changes the Risk for a Small Business

I think one of the biggest summer cybersecurity problems is that businesses temporarily stop operating the way they normally do. The owner may be unavailable. Someone in accounting may be covering another person's responsibilities. Employees may be working from hotels or vacation homes. A laptop that normally stays in an office may suddenly be several states away. An employee who normally uses a company computer may decide to check something quickly from a personal device.


None of those things automatically creates a security incident, but they change the context around normal business activity. An unusual request from the owner can seem more believable when everyone knows the owner is traveling. A vendor payment change may be harder to verify when the employee who normally handles the relationship is away. A Microsoft 365 sign in from a different location may be legitimate because the employee is traveling, or it may be something that needs to be investigated.


For a small business, summer can also create a coverage problem on the IT side. Security alerts, patching, backups, endpoint monitoring, RMM systems, Microsoft 365, and other parts of the environment do not stop producing information because the person who normally reviews them is on vacation. If one person is responsible for everything and nobody knows what to do while that person is unavailable, that is an IT process problem worth addressing before it becomes a security problem.


Six Summer Cybersecurity Risks Small Businesses Should Be Thinking About


1. Business Email Compromise and Payment Fraud

Business Email Compromise, commonly called BEC, is one of the risks I take particularly seriously when key decision makers are traveling. An attacker may impersonate an owner, executive, employee, or vendor and create an urgent request involving a payment, banking change, payroll information, gift cards, sensitive documents, or another action that normally requires trust.


Vacation schedules can make those requests more believable. If everyone knows the owner is away and difficult to reach, an email saying, “I need you to take care of this while I'm traveling” fits the circumstances.


Technology can help identify and block some of these attacks, but I do not want the entire defense against financial fraud depending on email security. Businesses should have a verification process for unusual financial requests and changes to payment information. For significant transactions, I like an independent verification method using contact information the business already knows to be legitimate, rather than a phone number or other contact information supplied in the request itself.


I discuss the technical side of impersonation, spoofing, mailbox compromise, SPF, DKIM, DMARC, and Microsoft Defender in Microsoft 365 Email Security for Law Firms and Business Email Compromise.


2. Hotel, Airport, and Other Guest Networks

This section became considerably more important after I originally published this article.

In July 2026, Microsoft Threat Intelligence disclosed a campaign it calls CaptiveCrunch. Microsoft reported that attackers had been manipulating traffic associated with hospitality captive portal networks, the type of sign in or registration systems travelers encounter when connecting to WiFi at hotels and other shared venues. Microsoft observed techniques that included redirecting traffic through attacker controlled infrastructure, lookalike Microsoft services, device code phishing, and malware delivery.


That does not mean every hotel or airport network is compromised. It does mean I do not want an employee assuming a network is trustworthy simply because a hotel, airport, conference center, or another venue provided it.


When practical, I prefer private connectivity such as cellular data or a company approved hotspot for business access while traveling. Depending on the company's environment and the resources employees need to reach, an appropriately configured business VPN or another secure remote access solution may also be part of the travel security design.


I also tell employees to be cautious about unexpected instructions presented by a guest network. A captive portal should not convince an employee to install a certificate, browser update, security utility, troubleshooting tool, or other software simply because the screen says it is required.


3. Public USB Charging

Public charging is another area where I prefer practical advice rather than trying to scare employees. CISA recommends avoiding connecting a mobile device to a computer or charging station you do not control because a USB connection can potentially allow more than electrical power. A USB connection can also provide a data connection between devices.


The easiest way around that problem is to carry your own charging equipment. I travel with my own charging bricks and power options rather than depending on an unknown USB port. For employees who travel regularly, a power bank or company supplied charging equipment is an inexpensive addition to the travel kit.


4. Travel Related Phishing and Unexpected Authentication Requests

Travel creates a lot of legitimate email. Flight changes, hotel confirmations, rental cars, conference registrations, receipts, itinerary changes, and rewards programs are all things an employee may genuinely expect to receive. That makes travel related phishing more believable because the message fits what is happening in the employee's life at that moment.


Microsoft authentication deserves attention here too. If an employee receives an unexpected Microsoft Authenticator request, device code prompt, or other authentication request while traveling, I do not want them approving it simply because they assume the hotel network or Microsoft needs something different while they are away.


The CaptiveCrunch campaign provides a current example of why this matters. Microsoft observed device code phishing being incorporated into malicious captive portal activity. A user could end up interacting with a legitimate Microsoft authentication page while still authorizing an attacker's session if they follow the attacker's device code instructions.

If an authentication request is unexpected, stop and verify why it is happening.


5. Out of Office Messages and Vacation Coverage

Out of office messages can provide more information than a business intends. An automatic response that identifies exactly who is traveling, when they will return, who is covering their responsibilities, and how that person can be reached can give someone useful context for a targeted social engineering attempt.


I prefer keeping external out of office responses simple. The exact wording should fit the business, but there is rarely a reason an unknown sender needs a detailed itinerary.

Vacation coverage also needs to be deliberate. If another employee needs temporary access to a mailbox, SharePoint location, accounting system, application, or other company resource while someone is away, I would rather grant that access intentionally than have employees sharing passwords or improvising workarounds.


Just as importantly, temporary access should actually be temporary. That is something worth checking again when everyone returns.


6. Security Alerts, Updates, and Backups Still Need Attention

Microsoft 365, endpoint security, RMM platforms, firewalls, backups, and other management systems do not know that it is vacation season. Alerts can still occur. Computers still need updates. Backup jobs can fail. Devices can stop checking into management systems. Vulnerabilities can still require attention.


This is why I want IT coverage documented instead of depending entirely on one person's memory. If the normal IT contact is unavailable, someone should know which systems need attention, how important alerts are handled, who can be contacted if something happens, and where the relevant documentation is stored.


This is also where runbooks become useful. A good runbook is not just documentation for a future disaster. It gives another qualified person enough information to understand the environment and the normal process when the primary person is unavailable.


What Should a Small Business Do Before Employees Travel?

I would rather prepare a business for travel before someone is sitting in an airport trying to figure out how to connect a laptop. The exact controls depend on the business, but these are some of the areas I look at.


Review Microsoft 365 Security

Microsoft 365 is often one of the most important systems employees access while traveling. Before vacation season, I want to know whether authentication is properly configured, administrative access is controlled, Conditional Access is being used where appropriate, email protections are configured, and company devices are being managed according to the business's requirements.


Owning Microsoft 365 licensing and having Microsoft 365 properly configured are two different things. I go much deeper into that distinction in Microsoft 365 Security for Small Business: What Actually Needs to Be Configured.


Make Sure Company Devices Are Centrally Managed

If a company laptop leaves the office, I still want visibility into it.

Depending on the environment, that can involve Microsoft Intune, an RMM platform, endpoint security, BitLocker encryption, Windows update management, application management, device compliance policies, and other controls. The goal is not simply to be able to remotely wipe a computer. I want to know which devices are in scope, whether they are receiving the policies they should receive, whether security software is active, and whether something stops reporting while the employee is away.


For businesses that allow BYOD, the conversation becomes more nuanced. Personal devices are not automatically unsafe, but access to company information should be intentional and designed around what data employees need, what applications they use, and what controls the business can reasonably enforce.


Establish Financial Verification Procedures

Do not wait until the owner is on vacation to decide how a wire transfer, ACH change, payroll request, or vendor banking change should be verified.


Create the process ahead of time. For sensitive financial changes, verification should use a trusted contact method already known to the business. Some businesses may also choose to establish an internal verbal code or another secondary verification process for unusual requests.


The important part is that employees know they are allowed to slow an urgent request down long enough to verify it.


Review Out of Office Procedures

Decide what employees should include in external automatic replies and how work should be routed while someone is away. If another employee needs temporary access, grant it through the appropriate application or administrative process rather than sharing credentials.

Then document what needs to be removed when the employee returns.


Verify Backups and Recovery

A green status indicator does not tell me everything I need to know about a backup strategy. I want to know what is being backed up, where the backup is stored, how long it is retained, whether failures are being monitored, and whether the business knows how recovery would actually work.


Microsoft 365 is an area where I frequently find confusion about responsibility and recoverability. I cover that in more detail in Microsoft 365 Backup for Small Business: Is Your Data Actually Recoverable?.


Summer Is Winding Down. What Should Your Business Check Now?

This is the part of summer cybersecurity that is easy to overlook. Employees may have connected from new locations, used different devices, covered responsibilities they do not normally handle, received temporary permissions, delayed updates, or encountered security alerts that seemed unimportant at the time. Most of those things may be completely legitimate. I still want to make sure the environment has returned to the state we expect now that normal schedules are returning.

A post summer IT and cybersecurity review can include:

  • Review Microsoft 365 sign in activity for anything that needs investigation

  • Review Risky Users and Risky Sign Ins where the appropriate Entra ID Protection capabilities are available

  • Ask whether employees received unexpected MFA or authentication requests while traveling

  • Remove temporary mailbox, SharePoint, application, or administrative permissions that are no longer needed

  • Review external email forwarding and unexpected mailbox rules where appropriate

  • Verify company laptops and other managed devices are reporting normally to RMM, Intune, endpoint security, or other management systems

  • Confirm operating systems, applications, browsers, firmware, and other managed software are current according to the company's update process

  • Review unresolved endpoint, firewall, identity, and other security alerts

  • Verify backups continued successfully and investigate failures rather than simply restarting the job

  • Confirm lost, replaced, or retired devices no longer have access they should not have

  • Review any personal device access or temporary workarounds that were introduced during vacation coverage

  • Document anything that changed so the current IT documentation still matches the environment

This is not about assuming every unusual event from the summer was malicious. It is about making sure someone actually looks.


If something does not make sense during that review, I would not automatically start deleting information or making a long list of changes before understanding what happened. I recently updated 7 Warning Signs Your Small Business May Have Been Hacked to cover the warning signs I look for across Microsoft 365, email, endpoints, and networks, as well as why screenshots, timestamps, logs, and other evidence can become important if a possible compromise needs to be investigated.


What About Cyber Insurance?

Vacation season does not create a separate category of cyber insurance. What matters is whether the business understands the representations, controls, notification requirements, exclusions, and other terms associated with its actual policy.


Cyber insurance applications and policies may ask about or require controls involving MFA, endpoint protection, backups, security awareness, email security, privileged access, or other areas. Those requirements vary by carrier, policy, business, and application, which is why I do not like telling a business owner that “cyber insurance requires X” unless we are looking at the actual requirements that apply to that business.


I discuss this in much more detail in Cyber Insurance Requirements for Small Businesses, including why I think the technical answers on an insurance application should be verified against the actual environment rather than answered from assumption.


Special Considerations for Law Firms and Government Contractors

For law firms, working while traveling can involve confidential client information, email, documents, cloud applications, and other systems that deserve the same care outside the office that they receive inside it. Travel security should be part of the firm's broader approach to protecting client information rather than a separate checklist that only matters during vacation season.


Government contractors have another layer to consider. CMMC and NIST requirements do not disappear because employees are traveling or staff members are on vacation. The controls that apply depend on the contractor's environment, the information it handles, and the applicable CMMC level and requirements. Secure remote access, access control, authentication, logging, protection of CUI where applicable, and other requirements need to be addressed according to the actual system design.


I would not reduce that to “CMMC requires a VPN.” A VPN can be one technical component of a remote access architecture, but the requirement is to satisfy the applicable security requirements, not simply to own a particular product.


Download the Summer IT Security Checklist for Small Business


I built a printable Summer IT Security Checklist to help small businesses work through these issues before, during, and after vacation season. It can be used by an owner, office manager, or whoever is responsible for coordinating IT with the company's technology provider.

Download the Summer IT Security Checklist


Frequently Asked Questions About Summer Cybersecurity


Why Does Vacation Season Create Cybersecurity Risk for a Small Business?

Vacation season changes normal business processes. Decision makers may be unavailable, employees cover unfamiliar responsibilities, company devices travel, people connect from new locations, and IT coverage may be thinner. Those changes can make phishing and social engineering more believable and can make unusual technical activity harder to distinguish from legitimate travel.


The answer is not to stop employees from traveling. It is to make sure security and business processes continue working while they do.


Is It Safe to Check Work Email From Hotel WiFi?

I would treat hotel, airport, conference center, and other guest networks as untrusted rather than assuming they are safe because a legitimate business operates them. Microsoft's 2026 CaptiveCrunch research gives us a current example of attackers manipulating traffic associated with hospitality captive portal networks.


When practical, I prefer cellular connectivity or a company approved hotspot for business access. If a business uses a VPN or another secure remote access solution, it should be configured and managed as part of the company's overall security architecture. Employees should also be cautious about captive portals asking them to install software, certificates, browser updates, or other unexpected tools.


Do Employees Always Need a VPN When They Work Remotely?

Not necessarily. The answer depends on what the employee is accessing and how the company's systems are designed. Modern cloud applications can use encrypted connections directly, while access to internal business resources may require a VPN, Zero Trust access solution, remote desktop architecture, or another secure method.

I do not recommend deploying a VPN simply so a business can say it has one. I want remote access designed around the actual resources employees need to reach and the security requirements of the business.


What Is Juice Jacking, and Should Employees Avoid Public USB Ports?

The practical concern is that USB can carry both power and data. CISA recommends avoiding connecting mobile devices to computers or charging stations you do not control because software on another system may be able to interact with the device in unexpected ways.


The simple solution is to carry your own charging brick, cable, or power bank. That avoids depending on an unknown USB connection in the first place.


Should Employees Use Personal Devices to Check Work Email While on Vacation?

That depends on the company's BYOD policy, the sensitivity of the information, the Microsoft 365 configuration, the device, and the controls the business has implemented. I would not make personal device access an informal decision employees make while standing in an airport.


If BYOD is permitted, the business should define what access is allowed and what controls apply. If it is not permitted, employees need to know that before they travel.


What Should We Check When Employees Return From Summer Vacation?

I would review temporary permissions, unusual Microsoft 365 sign ins, Risky Users and Risky Sign Ins where available, unexpected MFA activity, mailbox forwarding and suspicious rules where appropriate, device management status, endpoint security alerts, software updates, backup failures, and any temporary workarounds employees created while people were away.


The purpose is not to assume something bad happened. It is to close the loop on the changes that vacation season introduced.


What Should an Employee Do if They Received a Strange MFA Request While Traveling?

Do not approve an authentication request you did not initiate just because you are traveling or connected through an unfamiliar network. Report it to whoever manages the company's IT or security so the associated account and sign in activity can be reviewed.

An unexpected MFA request may have a legitimate explanation, but it is information worth investigating.


Does Cyber Insurance Cover a Cyberattack That Happens While Someone Is Traveling?

Coverage depends on the actual policy and circumstances. Businesses should not assume either that an incident is covered or that it is excluded simply because an employee was traveling. If an incident occurs, review the policy and follow the carrier's notification and response requirements.


Does CMMC Require Employees to Use a VPN While Traveling?

CMMC does not simply create a universal rule that every traveling employee must use a particular VPN product. Government contractors need to implement the applicable security requirements for their environment, including requirements related to access control and protection of information. The correct remote access design depends on the systems being accessed and where CUI or other sensitive information is handled.


Summer Security Should Become Part of Normal IT Management

The best outcome from a summer cybersecurity review is not creating another seasonal checklist that gets forgotten in September. The things that matter during vacation season are largely the same things that matter throughout the rest of the year: knowing which devices access company information, managing identities and permissions, reviewing alerts, maintaining backups, controlling remote access, keeping systems updated, documenting the environment, and making sure employees know how to respond when something does not look right.


Summer simply puts those processes under a different kind of pressure.

As normal schedules return, this is a good time to ask whether your technology held up the way you expected. Did every managed device remain visible? Did security alerts get reviewed? Did backups continue running? Did temporary access get removed? Did employees know what to do when they were away from the office? If the answer to any of those questions is unclear, that tells us something useful about where the environment may need more attention.


If you are not sure how well you know the environment underneath your business, my Small Business IT Checklist: How Well Do You Know Your Technology? is a good next step. It walks through the broader questions around Microsoft 365, devices, networks, backups, security, documentation, vendors, and the other technology a business depends on throughout the year.


ADDITIONAL RESOURCES

Microsoft Security: CaptiveCrunch, Midnight Blizzard Targets Travelers Worldwide for Malware Delivery and Credential Theft

Microsoft Threat Intelligence's July 2026 research on attacks involving hospitality captive portal networks, device code phishing, credential theft, malware delivery, and recommended protections for travelers.Read Microsoft's CaptiveCrunch research


CISA: Holiday Traveling With Personal Internet Enabled Devices

CISA guidance covering public WiFi, mobile device security, Bluetooth, and precautions when using charging stations or computers you do not control.Read CISA's travel cybersecurity guidance


CISA: Cybersecurity While Traveling

CISA guidance covering device updates, backups, public wireless networks, mobile connectivity, phishing, and physical protection of devices while traveling.Read CISA's Cybersecurity While Traveling guidance

Comments


bottom of page