
Sun, sea… and spear phishing?
As the summer holiday season kicks in, it’s not just airports that get busier — so do cybercriminals. Whether you’re logging in from a hotel lobby or just setting your out-of-office, time away can create real vulnerabilities if you’re not careful.
Here’s how to keep you, your business and your staff secure while off chasing the sun — without turning every trip into a cyber incident waiting to happen.
☀️ Out-of-Office Messages: Mind What You Share
Most people see OoO replies as harmless admin. But include the wrong info, and you might as well hang a “Gone Phishing” sign on your email.
Avoid including:
- Return dates
- Colleague names
- Phone numbers
🛡️ Best practice:
Use different messages for internal and external contacts.
Keep it vague externally – “I’m currently unavailable” is enough.
🐟 Phishing While You’re Poolside
Holiday mode = lower guard. And attackers know it. That fake flight refund or urgent Apple Pay message? It’s likely phishing.
📊 According to the Cyber Security Breaches Survey 2025, phishing accounts for:
- 85% of attacks on UK businesses
- Over 7.8 million incidents in a year
🛡️ What to remind staff of:
- Don’t click on suspicious links or attachments
- Verify travel emails via official sites
- Report dodgy messages to report@phishing.gov.uk or text 7726
🧳 On the Move? Lock Down Your Tech
Roaming devices face higher risks – from dodgy public Wi-Fi to malicious charging stations.
🛡️ Before they go, ensure staff:
- Use a VPN
- Keep software updated
- Disable Wi-Fi/Bluetooth auto-connect
- Avoid public USB chargers
- Use MFA on all work accounts
Bonus tip: Issue a temporary device for travel with minimal data and remote wipe enabled.
📱 Lost or Stolen? Have a Plan
Losing a laptop or phone while away isn’t just inconvenient — it’s a potential breach.
🛡️ Must-haves:
- Full-disk encryption
- Auto lock after inactivity
- Remote tracking and wipe
- Clear reporting process if a device goes missing
📸 Oversharing = Overexposing
“Off to Corfu for 2 weeks! ☀️🍹”
Harmless? Maybe. But that post just told the world (and any watching threat actor) that you’re not at your desk.
🛡️ Guidance:
- Avoid sharing travel plans publicly
- Keep holiday photos for after you’re home
- Never post boarding passes or passport info
✅ What This Means for Your Business
This isn’t theoretical. Cybercriminals thrive on routine oversights — and staff holidays are prime time.
Whether it’s a badly written OoO message, a click on a phishing email, or unsecured Wi-Fi abroad, the impact can be significant: reputational damage, data loss, or worse.
🛠️ Quick wins:
- Share a pre-holiday cyber checklist
- Set defaults for secure out-of-office replies
- Reinforce phishing awareness
- Encourage common-sense device habits
Remember: you don’t need to be paranoid — just prepared.
Final Thought 💬
Time off is vital — but cyber risk doesn’t take a holiday. With a few simple habits and clear expectations, your team can stay safe, even when they’re away.
And that means you can relax too. 😎
