
Executive Summary
The summer holiday period is already well underway. Key employees may be away, colleagues may be covering unfamiliar responsibilities, and normal approval processes may not be working as smoothly as usual.
That can create small security gaps. An unexpected payment request may be approved without the usual checks. Temporary access may have been granted and forgotten. Employees working away from the office may be using devices or networks differently.
Now is a good time to pause and check that your business is still protected.
A few simple actions can reduce the risk, including reviewing payment approvals, checking temporary access, reminding staff how to report suspicious messages and making sure work devices are secure.
Introduction
The summer holidays are already underway, so your business may already be operating with fewer people in the office.
Perhaps your finance manager is away. A colleague may be covering a senior employee’s inbox. Members of staff could be working from home, travelling or fitting work around childcare.
Most businesses can manage these changes without any major problems. However, annual leave can disrupt the familiar checks and routines that help keep a business secure.
A fraudulent payment request may be more convincing when the usual approver is unavailable. A member of staff covering an unfamiliar task may not know what looks normal. Temporary permissions may have been granted without a clear date for removing them.
It is not too late to address these risks. A quick mid-summer security check can help you spot gaps before they become larger problems.
Why annual leave can create security gaps
Businesses rely on more than written policies.
They also rely on everyday familiarity.
A finance employee may recognise how a director normally requests a payment. An office manager may know which supplier details are correct. A team member might usually confirm an unusual request by speaking to someone across the office.
When people are away, those informal checks can disappear.
Someone providing holiday cover may not know what is normal. They may also feel under pressure to act quickly, particularly when a request appears to come from a senior colleague, customer or supplier.
The main risk is not simply having fewer people at work. It is that responsibilities, approval processes and lines of communication can become less clear.
1. Check who can approve payments and important changes
Payment fraud is a particular concern when key employees are away.
A fraudulent email may claim that an invoice needs to be paid urgently or that a supplier’s bank details have changed. The sender may even mention that the usual contact is on holiday.
Check that your team knows:
- Who is currently authorised to approve payments
- Whether any temporary payment limits apply
- How changes to bank details should be verified
- Who to contact if a request seems unusual
- Which decisions should wait until the usual person returns
Any unexpected change to payment details should be confirmed using contact information your business already holds.
Do not rely on the phone number included in the request itself. If the email is fraudulent, those contact details may also belong to the criminal.
Staff should feel supported when they pause to check something. It is better to delay a genuine payment briefly than to send money to the wrong account.
2. Review temporary access and holiday cover
Temporary access is often provided so that colleagues can cover important work.
That may be necessary, but it should still be controlled carefully.
Check whether any employees have been given additional access during the summer period. Confirm that they only have the permissions needed for the work they are covering.
Avoid sharing passwords or allowing someone to use an absent colleague’s account. Each employee should use their own login so that accounts remain secure and activity can be traced to the right person.
It is also worth checking when temporary access will be removed. Permissions granted for a two-week holiday should not remain in place for months afterwards.
A clear holiday handover should explain:
- Which responsibilities have been transferred
- What the cover person is allowed to approve
- Which issues need to be escalated
- Who the alternative decision-maker is
- How to contact IT support
- Which tasks should wait until the employee returns
3. Revisit out-of-office messages
Out-of-office replies can reveal more information than intended.
A detailed message might confirm that a senior employee is away, give the dates of their absence and name the person covering their work. That information could help a criminal create a more convincing fraudulent request.
Review the messages currently being used across your business.
External replies should be brief. They can explain that the person is unavailable and provide a general team email address or main office number.
Detailed handover arrangements should be shared internally with the people who need them.
Employees should also think carefully about how much information they share publicly on social media. Holiday posts can reveal that someone is away from the office and may be unavailable for several days.
4. Make sure devices are protected away from the office
Some employees may be travelling with work laptops or checking messages from home, hotels, trains or other locations.
Before taking work devices on holiday or abroad, it is worth deciding whether they are genuinely needed. There is no single right answer. The decision should depend on the needs of the business, the sensitivity of the data on the device, the destination, and whether the employee can keep the device secure throughout the trip.
Remember that data on a laptop or phone travels with the person carrying it. In some countries, border authorities may have powers to inspect devices or require access to them. Even on a routine trip, there may be practical questions to consider, such as whether a laptop would be left in a car, hotel room or shared accommodation, and whether a managed loan device or secure remote access would be safer than taking the usual work device.
A quick reminder can help prevent common problems.
Staff should:
- Keep laptops and phones safe and secure while travelling
- Avoid leaving devices visible in parked vehicles
- Use a screen lock, password, PIN or biometric sign-in
- Avoid sending business documents to personal email accounts
- Be careful when using public Wi-Fi
- Prevent friends or family members from using work equipment
- Report a lost or stolen device immediately
Business devices should be encrypted and managed wherever possible. This helps protect the information stored on them and may allow the device to be locked or wiped remotely if it is lost.
Employees should not wait until they return to the office to report a missing device. The sooner your IT support provider knows, the sooner they can take action.
5. Remind staff how to report suspicious activity
People are more likely to report a suspicious email or mistake when the process is simple.
Check that everyone knows:
- How to report a suspicious message
- Who to contact if their manager is away
- What to do after clicking a suspicious link
- How to report a lost device
- How to reach your IT support provider
- Who can make decisions during an incident
An employee who thinks they may have made a mistake should not need to search through policies or work out who is available.
They should have one clear contact route.
It is also important to respond supportively. Staff should feel able to report problems quickly without worrying that they will automatically be blamed.
Early reporting can turn a serious-looking incident into something that is contained and resolved quickly.
Your mid-summer security check
Take a few minutes to check whether:
- Holiday cover and responsibilities are clear
- Payment authority has been agreed
- Changes to bank details require independent verification
- Temporary system access is still appropriate
- Multi-factor authentication is enabled on important accounts
- Business devices are updated and protected
- Backups are completing successfully
- Staff know how to report suspicious activity
- Lost device procedures are understood
- IT support contact details are easy to find
- Temporary permissions have a date for removal
You may find that everything is already in order. If not, most of these gaps can be addressed quickly.
Final Thoughts
The summer holiday period is not over, and neither are the security risks that come with disrupted routines.
The aim is not to create more work for employees or expect people to monitor emails while they are on leave.
It is to make sure the business can continue operating safely without depending on one person being available.
Clear responsibilities, sensible approval processes and an easy way to report problems can make a significant difference.
A quick check now could prevent an unclear request, lost device or forgotten permission from becoming a much larger issue.
Is your business secure for the rest of the summer?
Get Support can help you review your current holiday cover, account security, payment processes and device protection.
We can review user access, secure Microsoft 365 accounts, configure multi-factor authentication, manage laptops and mobile devices, check backups and make sure your team has a reliable way to get help.
We can also identify temporary permissions that should be removed and help put practical incident-reporting processes in place.
Contact Get Support to arrange a mid-summer IT and security review.
FAQs
No. Many employees will continue taking annual leave throughout the rest of the summer. A review now can identify unclear responsibilities, unnecessary access and weak approval processes before they cause a problem.
Nominate an authorised alternative and make sure their limits and responsibilities are clear. Unexpected payment requests and changes to bank details should always be verified independently.
A clear handover is usually better than expecting employees to monitor email during annual leave. Important responsibilities should be assigned to an authorised colleague, with an agreed contact for genuine emergencies.
The employee should report it immediately to the business and its IT support provider. The device may need to be locked or remotely wiped, and the incident may need to be assessed as a possible data breach.
Get Support can review account security, temporary access, devices, backups and support arrangements. We can also help address any gaps that have appeared since the holiday period began.