Skip to main content

Why cyberattacks often strike when businesses are least prepared

At 11 pm on a friday night, most business owners are no longer thinking about their IT infrastructure. The working week is over, employees have logged off and, in many companies, nobody is actively watching what is happening across the network.

The infrastructure, however, is still running. Remote access services remain available, cloud systems continue to communicate, VPN connections can still be established and internet-facing services remain exposed.

Cyberattacks can happen at any time, and many attack techniques are automated. Periods of reduced staffing, slower response and limited monitoring can therefore create a useful window for an attacker. Suspicious activity that would be investigated within minutes during working hours may remain unnoticed considerably longer during a night, weekend or public holiday.

That additional time matters because the visible attack is often only the final stage of the incident.

A cyberattack is rarely a single event

When employees arrive on monday morning and discover encrypted files, unavailable applications or inaccessible servers, it can look as though the attack happened overnight.

In reality, the attacker may have gained initial access much earlier.

The entry point could have been a phishing email, stolen credentials, an exposed remote access service, an incorrectly configured system or an unpatched vulnerability. After gaining access, an attacker may spend time exploring the environment, identifying valuable systems and looking for opportunities to obtain additional privileges.

There may be very little visible disruption during this stage. Systems continue working, employees continue using them and, without appropriate monitoring, the activity may not immediately appear unusual.

Eventually, the attacker may be ready to steal data, disable services, deploy ransomware or take another action that makes the incident impossible to ignore.

So when we talk about when a cyberattack “happens”, there may not be a single moment at all.

Why nights and weekends matter

The reason is less technical than it might seem: people.

A company's infrastructure normally operates 24 hours a day, while the people responsible for maintaining and protecting it often work standard business hours. This difference becomes particularly important for SMEs that do not have continuous internal IT or security coverage.

Outside normal working hours, an alert may still be generated, but who receives it? Is somebody expected to investigate it? Does that person have access to the information needed to understand what is happening? And if the event turns out to be serious, is there a defined escalation process?

Without clear answers, several hours can pass before anyone begins investigating.

For a company operating multiple locations, production systems or centralised infrastructure, those hours can have a significant impact. If several sites depend on the same authentication service, network connection, server infrastructure or business application, a security incident can quickly develop into an operational problem.

SMEs are not invisible

“We are too small to be a target” is still a surprisingly common assumption.

The problem is that many cyberattacks do not begin with somebody selecting a particular company. Automated systems can continuously search internet-facing infrastructure for opportunities, looking for exposed services, vulnerable software, weak credentials, open ports or incorrectly configured remote access.

From that perspective, the attacker may initially know very little about the company behind the IP address.

What matters is that something appears exploitable.

This changes the risk calculation for smaller businesses. An SME does not need to be strategically important or individually selected to become the victim of an attack. If its infrastructure presents an accessible opportunity, automated scanning and attack tools can potentially find it.

What happens after someone gets in?

There is no single sequence that describes every cyberattack, but gaining initial access is often only the beginning.

An attacker may try to understand the network, discover other devices, identify administrator accounts, find business-critical systems or obtain higher privileges. From there, the activity can spread beyond the original compromised account or device.

A simplified progression might look like this:

  • initial access
  • discovery of systems and accounts
  • privilege escalation
  • access to additional resources
  • movement between systems
  • data collection or extraction
  • disruption, encryption or extortion

Some attacks progress quickly, while others develop over a much longer period. The attacker's objective may also be different: ransomware, data theft, fraud, persistence or access that can later be exploited.

This is why detection time matters so much. Finding suspicious behaviour during the early stages creates a very different situation from discovering an incident after critical systems have already been affected.

One security product will not solve this

Companies sometimes approach cybersecurity by asking which product they should buy next. In practice, the more important question is whether the controls they already have provide meaningful protection together.

A firewall controls network communication. Endpoint protection operates on individual devices. Multi-factor authentication helps protect accounts. Monitoring provides visibility into activity. Backups support recovery.

None of them replaces the others.

The problem begins when these technologies exist but operate as separate islands. A firewall can generate useful information, but that information has little value if nobody reviews it. A backup can run successfully every night, but that does not prove that the business can actually restore from it. Multi-factor authentication may protect one service while another remote access method still relies only on a password.

Cybersecurity therefore needs to be considered as an operating model, not simply as a collection of products.

Visibility is often the missing layer

Before deciding what else needs to be protected, a company needs to understand what is already there.

Which devices are active? Which services can be reached from outside the organisation? Who has remote access? Where is critical business data stored? Which connections exist between offices, cloud services and external partners?

These questions sound basic, but the answers become less obvious as an organisation grows.

A new office is connected. A supplier receives VPN access. A cloud application is introduced. A temporary remote access rule is created. An employee leaves. Another server is installed.

Individually, none of these changes appears dramatic. Over several years, however, they can create an infrastructure that nobody fully understands anymore.

Without that visibility, identifying unusual activity becomes much more difficult because there is no reliable picture of what “normal” should look like.

Access should reflect what people actually need

If one employee account is compromised, the potential impact depends heavily on what that account can reach.

An employee who only needs access to a CRM system should not automatically have access to administrative interfaces, backup infrastructure or unrelated internal systems. The same principle applies to suppliers, external IT providers and temporary users.

Multi-factor authentication can make stolen credentials more difficult to exploit, while appropriate permissions can limit what happens if an account is compromised despite those controls.

Access also needs to change when the business changes. Employees move between roles, suppliers finish projects and temporary permissions are easily forgotten.

For this reason, access management is not something that should only be configured when an account is created.

A firewall needs someone to manage it

A business firewall is a fundamental security control, but installing one is only the beginning.

Networks change constantly. New services are introduced, remote connections are created and business requirements evolve. Firewall policies that made sense two years ago may no longer be appropriate today.

A temporary rule is a good example. Someone needs access to a service, a firewall rule is created and the immediate problem is solved. Months later, the project has ended but the rule remains.

The same can happen with old VPN accounts, exposed management interfaces and services that nobody remembers using.

This is why firewall security is not primarily about owning a particular appliance. Its effectiveness depends on configuration, maintenance, logging, monitoring and regular review.

Backup becomes important when prevention fails

Backups play a different role.

They do not stop someone from stealing a password, exploiting a vulnerable service or entering the network. Their value becomes critical when systems or data have already been affected and the business needs to recover.

That is also why simply seeing a successful backup job every morning is not enough.

A useful backup strategy needs to consider whether copies are appropriately separated from production systems, whether access to them is protected and whether restoration is regularly tested.

There is a significant difference between having data stored somewhere and being able to rebuild a working business environment from it.

For management, the practical question is therefore: if critical systems became unavailable tonight, how long would it take before the company could operate again?

The answer may be very different from “we have backups”.

Does every company need 24/7 monitoring?

Not necessarily in the same form.

A ten-person company with relatively simple infrastructure has different requirements from a manufacturer operating several locations and production systems. The potential impact, exposure and complexity should determine the level of monitoring and response capability.

Even basic monitoring can make a substantial difference if important events generate meaningful alerts and those alerts actually reach somebody who can act on them.

As infrastructure becomes more complex, the need for structured escalation and response increases as well.

The goal is not a dashboard full of thousands of events. More data does not automatically mean better security.

What matters is recognising the events that require attention.

The problem is often between the tools

Many SMEs already have more cybersecurity technology than they realise. There may be a firewall at the internet connection, endpoint protection on computers, Microsoft 365 security features, VPN access, a backup system and several different logs.

Yet nobody has a complete picture.

The firewall reports unusual traffic, but nobody looks at the report until weeks later. A former supplier still has VPN access. Backups are running, but restoration has not been tested recently. An old server remains reachable because another system might still depend on it.

None of these situations necessarily causes an incident by itself.

Together, however, they create blind spots.

This is where looking at cybersecurity as a connected environment becomes more useful than evaluating every product separately.

The IT-Pack Shield approach

The IT-Pack Shield approach follows this principle by treating cybersecurity as an interconnected operational environment rather than a collection of independent security products.

Firewall and network protection, monitoring and visibility, secure connectivity, access management, backup and recovery, and compliance-related requirements all address different parts of the same business risk.

The objective is not to add another layer of complexity. It is to understand what is happening across the environment, reduce unnecessary exposure and make important security events visible early enough to act on them.

This becomes especially relevant outside normal working hours.

If unusual activity begins at 11 pm on a friday, the technology will continue operating regardless of whether anyone is in the office. The real difference is whether that activity remains invisible until monday morning or whether the organisation has the visibility and processes needed to recognise it earlier.

Questions worth asking before friday night

A business owner does not need to understand firewall rules, log formats or network protocols, but should be able to get clear answers about what happens when something goes wrong.

For example

  • who receives an important security alert outside working hours?
  • which systems can currently be accessed remotely?
  • are critical accounts protected with multi-factor authentication?
  • who still has VPN or administrative access?
  • where are the company's critical data and backups stored?
  • when was the last successful restore test?
  • who makes the decision if systems need to be isolated during an incident?
  • how long would it realistically take to restore critical operations?

If these questions are difficult to answer, buying another security product may not be the first priority.

Understanding the environment probably is.

See the ITPACK SHIELD Platform in Action

Explore the capabilities of the ITPACK SHIELD Platform through our interactive demonstration.

Stay informed with the latest cybersecurity insights, IT best practices, and industry updates.

Subscribe to Our Newsletter

©  Heftner Group Kft