Labor Day is the kind of day a small business stops thinking about its network. The office is closed, the phones are forwarded, and whoever normally notices that something looks wrong is at a barbecue. That gap is not incidental to how ransomware crews operate. It is the point.
The Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency published a joint advisory on this pattern, Ransomware Awareness for Holidays and Weekends, after observing an increase in highly impactful ransomware attacks occurring on holidays and weekends when offices are normally closed. The advisory is several years old now, and the pattern it described has not gone away. It has hardened into a business practice.
The timing is a decision, not a coincidence
An intrusion has two clocks running. The first is how long the attacker needs to move from an initial foothold to something that hurts, which usually means locating backups, disabling them, and encrypting enough systems that the business cannot operate. The second is how long the organization needs to notice and interrupt that work.
An attacker cannot make the first clock much faster. What an attacker can do is choose a moment when the second clock barely runs at all. Friday evening before a three day weekend buys roughly seventy two hours of quiet. Nobody is reading alerts. Nobody notices that a file server is suddenly working very hard. The person who would recognize a login from an unfamiliar location as wrong is not looking at email until Tuesday.
That is the entire strategy. It does not require a novel exploit. It requires a calendar.
The staffing math is worse than most owners assume
Research published by Semperis in its 2025 Ransomware Holiday Risk Report put numbers to the gap. Fifty two percent of surveyed organizations reported being targeted on a holiday or a weekend. Seventy eight percent said they reduce security operations center staffing by fifty percent or more during holidays and weekends, and six percent said they cut that coverage entirely.
Those figures come from organizations large enough to have a security operations center in the first place. A ten person firm in San Diego does not have one. It has an owner who checks email, and a managed service provider whose after hours agreement may or may not include anyone watching for intrusions rather than waiting for a ticket. Practical coverage over a long weekend is frequently zero, and an attacker has no way to distinguish that from a deliberate reduction. Either way, the window is open.
How they get in has not changed much
The federal advisory names two initial access methods as the most common: phishing, and brute force attacks against unsecured Remote Desktop Protocol endpoints. Both are unglamorous. Both remain effective.
Remote Desktop Protocol deserves particular attention in small businesses because it tends to get exposed for a practical reason and then never revisited. Someone needed to reach a machine from home during a busy stretch, a port was opened, the immediate problem was solved, and the exposure outlived the reason for it. Nobody wrote it down. It appears on no inventory, because there is no inventory.
Phishing over a holiday weekend also gets a seasonal assist. Out of office replies confirm who is away and for how long, and frequently name a colleague as the backup contact. A message arriving on Saturday claiming a vendor needs an urgent payment change lands on a person with less context, less access to verify, and less appetite to interrupt someone's holiday to ask. We have written before about what happens when a vendor relationship degrades quietly, and the verification problem is the same one, compressed by the calendar.
Five things worth doing before the office closes
None of these require a purchase. All of them are achievable in an afternoon.
Confirm a backup exists and is offline. Not that a backup job ran. That a copy of the data exists somewhere an attacker holding domain credentials cannot reach or delete. The advisory is direct about this: make an offline backup of your data. A backup on the same network, reachable with the same credentials, is inventory for the attacker rather than insurance for you. Restore one file from it. That is the only test that means anything.
Turn off what does not need to be reachable. If Remote Desktop Protocol is exposed to the internet, close it or place it behind a virtual private network before the weekend. If a service was opened months ago for a reason that has since passed, this is the moment to notice. Reducing what is reachable over a long weekend costs nothing when nobody is working anyway.
Require multifactor authentication on email and remote access. Stolen credentials are worth far less when a second factor stands behind them. Where multifactor authentication is enabled for some accounts and not others, the gaps are usually the accounts that predate the policy, including service accounts and the owner's own login.
Decide, in writing, who is reachable and how. Most small businesses have never answered a simple question: if something looks wrong at nine on Sunday night, who does an employee call, and on what number. Write down two names, two phone numbers, and the sentence that grants permission to call. An employee who suspects something and does not want to ruin somebody's holiday will wait until Tuesday, and Tuesday is far too late.
Tell staff what to expect. A single message before the weekend, saying that requests to change payment details or send credentials will not arrive during the holiday and that anything claiming urgency should wait for verification, removes most of the pressure that makes holiday phishing work.
If something does happen while you are closed
The instinct is to change passwords and move on. That is not sufficient on its own, because a password reset does not necessarily end an intrusion. Sessions established before the reset can survive it, which we covered in why a password reset may not end an intrusion. Resetting credentials without revoking active sessions leaves the attacker logged in behind the new password.
Preserve what happened before cleaning it up. Logs, the affected machine, and the timeline are what an insurer, a client, or a regulator will ask for later. A machine that has been wiped and rebuilt answers no questions at all.
The Tuesday review
Returning from a long weekend is a reasonable moment for a short, specific check rather than a general sense that things seem fine. Look at successful logins across the closure and ask whether each one has an explanation. Look at any account created or permission granted while the office was closed. Look at whether backup jobs ran and whether any failed quietly. Look at mailbox rules, because an attacker who reaches an inbox frequently adds a rule that hides replies from the owner.
That review takes under an hour and catches the category of intrusion designed to stay invisible. An organization running protective domain name system filtering has an additional log worth reading, since blocked lookups over a quiet weekend are a useful signal that something on the network tried to reach infrastructure it should not have.
The underlying problem is coverage, not tooling
Small businesses tend to respond to this by asking which product closes the gap. Usually the honest answer is that no product does, because the gap is not detection capability. It is that nobody is assigned to look, and nobody has been told what to do if they see something.
Assigning one person per closure, giving that person a short list of what to check and a phone number to call, and confirming that an offline backup exists is a control. It is not a sophisticated one, and it will not appear on any product comparison chart. It is also the difference between an intrusion interrupted on day one and one granted seventy two uninterrupted hours to finish.
The attackers already know the calendar. Planning around it is not paranoia. It is the same operational discipline as locking the door on the way out.
Related reading: Your Office Network Is Flat. Here Is Why That Is a Problem. and Session Tokens: Why a Password Reset May Not End an Intrusion. If you handle Controlled Unclassified Information or protected health information, see our CMMC assessment and HIPAA assessment pages.
Sources: Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation, Joint Cybersecurity Advisory AA21-243A, Ransomware Awareness for Holidays and Weekends. Semperis, 2025 Ransomware Holiday Risk Report.
Not sure who is watching the network when you are closed?
Adams Cloud helps small businesses and defense contractors build practical holiday coverage plans, verify that backups are genuinely offline, and document incident response for NIST 800-171, CMMC, and HIPAA.
Book a free thirty minute consultation