Share This Article
A cyber attack during holidays is not a harder technical problem than one in March, it is a harder decision-making problem. The systems fail in the same way, the forensics follow the same method, and the regulatory clocks run at the same speed. What changes is that the people named in the incident response plan are unreachable, the supplier that caused the incident is running on a skeleton crew, and whoever happens to be at the desk usually believes they have no authority to act.
Threat actors have understood this calendar for years. This article collects what a month of discussion on the subject produced, organised in the order that matters to an organisation dealing with an attack right now.
A real story
A few days before Christmas some years ago, my phone rang while I was in a pub with old friends. It was my criminal law partner. A retail client had just been hit by ransomware, at the busiest trading point of their year.
We were on a call with the client’s head of compliance within twenty minutes, and a team was assembled within the hour. The work that followed ran for six months and involved negotiating with the threat actors over the ransom, advising on regulatory action across more than forty jurisdictions, and managing the reputational consequences. I set out the full account in this real story of a cyber attack at Christmas.
The part worth extracting is the first hour. Nothing that happened over the following six months would have gone better if the first hour had gone worse, and the first hour depended entirely on somebody being reachable and somebody being entitled to decide.
Why a cyber attack during holidays behaves differently
Attacks cluster around long weekends, national holidays like Christmas or Easter and the second and third weeks of August because detection slows and escalation stalls. Analysts have recorded a marked rise in attempted ransomware attacks across the November to January window, when retailers in particular are more likely to pay in order to protect their most profitable trading period.
The mechanics are ordinary. Phishing volumes rise while attention falls, staff work remotely from unfamiliar and often unsecured networks, and transaction volumes peak precisely when supervision thins. Human error remains the dominant entry route in the great majority of incidents, and the holiday period maximises the conditions under which people make mistakes.
Three failures then recur, and none of them is technical.
- The first is authority. A decision worth several million euro, whether to isolate a revenue-generating system, whether to notify a regulator, whether to instruct external counsel, sits unmade because the individual entitled to take it has switched the phone off. The person covering the desk escalates rather than decides, and escalation to someone unreachable consumes hours that no regime gives back. The exposure of the individuals concerned is a separate question, addressed in this analysis of directors’ liability for a cyber attack.
- The second is the supplier. Incidents surfacing in August and in general during the holiday season frequently originate in a provider’s infrastructure, and the provider is operating with the same reduced staffing. Requests for scope, indicators of compromise or evidence preservation go unanswered until the account manager returns.
- The third is the record. Nobody documents the timeline during a holiday period, because the people who ordinarily would are elsewhere. Reconstructing the moment of awareness three weeks later, in front of a supervisory authority, is an exercise that rarely persuades.
Hour zero: establishing who decides
The first task in handling a cyber attack during the holiday period is not containment. It is identifying who currently holds authority.
That question should be answered before an incident, and answered in writing. Named deputies, with express delegated authority, communicated to the board and to the relevant committee. A deputy who suspects they lack authority behaves exactly like an organisation with no plan at all.
Where this has not been done in advance, the position can still be salvaged. Confirm the delegation by email at the outset, record who granted it, and proceed. An imperfect written delegation created during an incident is defensible. An undocumented decision taken by someone who was never authorised is not.
Four questions establish the position quickly, and an organisation that cannot answer all four within an hour is operating on paper only:
- Who can activate the incident response plan, including shutting down a system that generates revenue?
- Which technical and legal advisers will be instructed, and are they retained already?
- Who communicates with the regulator inside the first 24 hours?
- Who decides on a ransom payment, and against which criteria?
The first twenty-four hours: a working sequence
For an organisation dealing with an attack as this is read, the sequence below preserves the widest range of options.
- Record the moment of awareness. Note the exact time, in writing, together with the source. Every deadline runs from this point.
- Resolve authority. Confirm in writing who is deciding, before anything irreversible happens.
- Resist the panicked decision. Shutting down every server destroys forensic evidence, extends the outage and rarely improves containment. Contain by segment, on advice.
- Preserve evidence. Logs rotate within hours. Instruct any supplier involved to preserve theirs, in writing, immediately.
- Classify provisionally against GDPR, NIS 2 and DORA, and from 11 September against the Cyber Resilience Act. Provisional classification with documented reasoning beats delayed certainty.
- Instruct legal advisers early, so that privilege attaches to the investigation rather than to its conclusions.
- Notify inside the applicable window even where the picture is incomplete. Every regime contemplates a first report followed by updates. None accepts silence pending clarity.
- Open a decision log. One document, one owner, every decision timestamped with its reason and its author. That document shapes the following twelve months.
The clocks do not observe the holiday calendar
Four regimes may apply to the same event, each with a different trigger and addressee.
| Regime | First deadline | What starts it |
|---|---|---|
| GDPR, Article 33 | 72 hours | Awareness of a personal data breach |
| NIS 2, Article 23 | 24 hours, early warning | Awareness of a significant incident |
| DORA, Article 19, and RTS 2025/301 | 4 hours from classification as major, and in any case 24 hours from awareness | Classification as major |
| Cyber Resilience Act, Article 14, from 11 September 2026 | 24 hours, early warning | Awareness of an actively exploited vulnerability or a severe incident |
The DORA structure repays close reading, because the four-hour deadline attaches to classification rather than to detection. Slow classification buys no time. It moves the exposure to the twenty-four hour cap measured from awareness, and it invites a supervisor to ask why classification took as long as it did.
One point deserves particular attention in August. Article 5 of Commission Delegated Regulation (EU) 2025/301 contains an extension where a deadline expires on a weekend or a bank holiday, but that extension excludes credit institutions, central counterparties, operators of trading venues, and entities classified as essential or important under NIS 2. The population under the heaviest supervisory scrutiny therefore receives no accommodation for Ferragosto. Organisations should verify the position against the text before relying on any extension, particularly across group entities falling in different categories.
When the attack arrives through a supplier
Most organisations do not discover a serious incident through their own monitoring. They receive an email from a provider, often late on a Friday, describing an incident that may have affected some customers and promising further information in due course, with no scope and no indicators of compromise.
That email starts the clock. The awareness triggering GDPR, NIS 2 and DORA is the organisation’s own awareness, not the supplier’s confirmation of the facts. Waiting for the provider to finish its analysis is not a position that survives contact with a regulator, and it tends to read instead as evidence that the contract was never negotiated properly.
Cloud, software and ICT outsourcing agreements commonly contain notification clauses drafted at a level of generality that suits the supplier alone. The provisions worth insisting on are specific: a notification period measured in hours rather than in reasonable time, a named contact reachable outside business hours, a defined minimum content for the first notification, and an express obligation to cooperate and preserve evidence.
Before any extended shutdown period, a short written reminder to principal suppliers, restating those obligations and confirming out-of-hours contacts on both sides, costs very little and changes the first forty-eight hours considerably.
The plan that was never tested
Incident response policies drafted for GDPR, NIS 2 or DORA purposes are frequently accurate, internally consistent and untested. That combination creates a compliance exposure of its own. An organisation that has never exercised its plan cannot know where the plan fails, and it cannot credibly argue that it had taken all appropriate measures.
Discovering the gaps during a live attack produces the panicked decisions, and the most common of them destroys the evidence that the subsequent regulatory defence depends on.
A tabletop exercise run specifically against holiday conditions, with the primary decision-makers declared unavailable, surfaces the authority gap in under two hours. Very few organisations run that version of the exercise, and it is the version that matters.
What changes on 11 September
The Cyber Resilience Act reporting obligations under Article 14 start applying on 11 September 2026. Manufacturers of products with digital elements must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident, a fuller notification within 72 hours, and a final report thereafter, through the ENISA Single Reporting Platform.
Two features matter for anyone planning the return from the summer. The obligation covers products already placed on the market, including products shipped years earlier for which no internal owner remains identifiable. And the Single Reporting Platform was still undergoing functional and security testing over the summer, which makes registration a task for August rather than for the second week of September. The scope questions, and what the European Commission guidance of 27 July 2026 settles, are covered in this article on which products and obligations the CRA captures.
Before the next shutdown period
August is the most exposed window in the European calendar, but it is not the only one. The same conditions return at Christmas, over Easter and across long national weekends, and the preparation is identical each time.
Name the deputies and grant authority in writing. Run one tabletop exercise under holiday conditions. Send the reminder to principal suppliers. Confirm that the decision log has an owner who will actually be present. Check that external advisers are retained rather than merely known, because the retainer cannot be negotiated at two in the morning.
Support during an incident
Our team handles cyber attacks across jurisdictions throughout the year, including during the holiday periods when they are most likely to occur. The support we provide includes:
- A dedicated hotline at databreachsupport@dlapiper.com, with a first assessment call within four working hours, understood as 8am to 10pm, seven days a week, bank holidays included.
- Assessment of the attack and of the resulting obligations in every affected jurisdiction, under both data protection and cybersecurity laws, supported by our Notify legal tech tool and our cyber law mapping report.
- Management of the obligations toward authorities and affected individuals across all jurisdictions involved, through a single point of contact and a dedicated project manager, with data protection, litigation and criminal law colleagues, and with attention to the conditions under which legal privilege attaches in each country.
- Support in negotiations with the threat actor on any ransom demand, including the legal assessment of whether payment is permissible.
- Quantification of exposure in regulatory fines and claims, including class actions, using our GDPR fine calculator built on the EDPB criteria for the calculation of fines.
- Assistance with the cyber insurance position, including disputes with the insurer.
- Representation in disputes with regulators, affected individuals and suppliers arising from the attack.
An attack does not wait for the return to the office. The organisations that handle a cyber attack during holidays well are the ones that settled the question of who decides several weeks before anything happened.

