December is the most wonderful time of the year for ransomware operators. Reduced staffing. Distracted employees clicking on shipping notification phishing. Pressure to keep systems running through the holiday rush. IT teams hesitant to make changes during critical business periods.
I've lived through three holiday-season incidents across my career - two at the company and one at a client site. None of them were fun. Here's what I do every year to prepare, and what you should be doing too.
Why Attackers Love the Holidays
The data is clear. FBI and CISA have warned about holiday ransomware spikes for years. The Colonial Pipeline attack happened over Memorial Day weekend. JBS was hit over Memorial Day weekend. The Kaseya attack happened July 4th weekend. Pattern recognition isn't hard here.
Attackers pick these windows deliberately:
Reduced monitoring: Security operations centers run skeleton crews. Alert fatigue is higher because everyone wants to get home. The person who would normally investigate that weird login at 11 PM might be at a company holiday party.
Pressure to pay: If ransomware hits on December 23rd and you're a retailer, you don't have the luxury of methodical recovery. The pressure to pay and restore operations is enormous. Attackers know this and price their demands accordingly.
Phishing paradise: Everyone's expecting shipping notifications, gift card confirmations, and holiday greetings from vendors. Malicious emails blend right in. "Your package couldn't be delivered" gets clicked without thinking.
IT change freezes: Most organizations implement change freezes from mid-December through early January. This means vulnerabilities discovered in November often don't get patched until January. Attackers know your patch window.
What I'm Doing This Year
Here's my actual holiday security checklist for Julius Silvert. Steal it. Adapt it. Use it.
Two Weeks Before (Early December)
Patch everything patchable. Before the change freeze hits, we push every pending update. Windows, firmware, applications - everything. If something breaks, we have time to fix it before the holiday crunch.
Verify backups work. Not just "backups are running" - actually restore something. We pick a random server and restore it to our DR environment. If we can't restore now, we definitely can't restore during an incident.
Update incident response contacts. People change phones, go on vacation, leave the company. Our incident response plan has escalation lists that get stale. Every December, I verify every phone number and email on that list.
Brief the leadership team. I send a memo to the CEO and CFO explaining holiday cyber risks and what our response would look like. If they need to make a ransom decision at 2 AM on Christmas Eve, they shouldn't be learning about our policies for the first time.
One Week Before
Reduce privileged access. We audit who has admin rights and temporarily revoke anything that isn't actively needed. The DBA who's on vacation doesn't need SA rights while she's in Cancun.
Increase logging verbosity. I turn up the sensitivity on our SIEM. Yes, this creates more alerts. Yes, it creates more noise. But I'd rather deal with false positives in December than miss the real thing.
Pre-position response resources. Our MDR provider knows we're a food distribution company with holiday criticality. They put us on their enhanced monitoring list. Our cyber insurance carrier has our policy details ready for quick claims if needed.
Test the on-call rotation. I actually call the on-call numbers to make sure they work and someone answers. Sounds paranoid. Saved us once when an on-call engineer had changed his number without updating the system.
During the Holiday Period
Daily security standup. 10 minutes every morning, including holidays, with whoever's working. What alerts triggered overnight? Anything unusual? Any user complaints that might indicate compromise?
No remote access exceptions. Every year, someone's nephew wants to VPN in from their gaming PC to "check something." No. If it's not a managed device with our security tools, it's not connecting to our network.
Watch for gift card scams. CEO fraud spikes in December. "Hey, I need you to buy some Amazon gift cards for the team" emails are incredibly common and incredibly effective. Our finance team has standing instructions: any gift card request requires voice verification.
Every December, someone at some company falls for this. The email looks like it's from the CEO, requests iTunes or Amazon gift cards for "employee rewards," and asks for the codes to be sent back via email. Millions of dollars are lost this way annually. Train your team and require verification.
The Phishing Gauntlet
December phishing campaigns are sophisticated because they're contextually relevant. Here's what we're seeing this year:
Fake shipping notifications: "Your UPS package couldn't be delivered." Links go to credential harvesting sites that look exactly like UPS/FedEx login pages.
Holiday party invites: Calendar invitations from "HR" with malicious links to "RSVP" for holiday events.
Year-end tax documents: "Your W-2 is ready for review" or "401k year-end statement available."
Vendor holiday greetings: Malicious attachments disguised as holiday cards from "partners."
Charity donation requests: Fake charity campaigns exploiting holiday generosity.
We run targeted phishing simulations in early December to test awareness. Anyone who clicks gets immediate coaching, not punishment. The goal is education, not gotcha.
Physical Security Doesn't Take Holidays
Digital security gets all the attention, but physical risks increase during holidays too. Our warehouse locations have reduced staffing. Delivery volume is high, which means more unfamiliar faces. Tailgating through secured doors is easier when everyone's carrying packages.
We remind all staff: challenge people you don't recognize, even during the busy season. Close and lock doors behind you. Report anything unusual.
The Incident Response Readiness Test
Before every holiday season, I run a tabletop exercise with my team. The scenario is always the same: ransomware hits at 6 PM on December 23rd. What do we do?
We walk through the decisions:
- Who gets called first?
- How do we communicate if email is down?
- What systems are critical to restore first?
- Who has authority to make ransom decisions?
- Where are the backup credentials stored?
- How do we notify customers and partners?
This exercise takes 90 minutes and reveals gaps every single year. Last year, we discovered that our emergency communication plan relied on a Slack channel that would be inaccessible if our SSO was compromised. We now have a separate, standalone communication method.
The Zero-Ransom Philosophy
I've been involved in three ransomware incidents and we've paid zero ransoms. This isn't luck - it's preparation. Good backups, tested recovery procedures, and business continuity planning mean we've always had options beyond paying criminals.
The worst incident was at the company in 2018. Full encryption of our file servers two days before a major acquisition milestone. We recovered from backups in 36 hours. It was brutal, exhausting, and expensive in terms of overtime and lost productivity. But we didn't fund criminal operations and we didn't negotiate with extortionists.
Holiday preparation is part of maintaining that zero-ransom capability. If our backups fail in December, we've lost our leverage.
What To Do If It Happens
Despite all preparation, incidents can still occur. If you find yourself dealing with a security incident during the holidays:
Don't panic. Panic leads to bad decisions. Take a breath, consult your incident response plan, and follow the process.
Isolate first. Network isolation limits the blast radius. Better to take systems offline proactively than watch encryption spread.
Document everything. Timestamps, screenshots, log exports. You'll need this for insurance claims, law enforcement, and post-incident analysis.
Engage your vendors. Your MDR provider, cyber insurance carrier, and legal counsel all need to know immediately. They have resources and experience you don't.
Communicate internally. Staff need to know what's happening and what they should do. Silence breeds panic and bad decisions.
Don't negotiate alone. If you're considering paying a ransom (I hope you're not), engage professional negotiators. They understand the criminal ecosystem better than you do.
The Investment Pays Off
Every year I put 40+ hours into holiday security preparation. Every year, someone asks if it's really necessary. The answer is yes.
The one year you skip this preparation is the year you'll wish you hadn't. Security is about consistency, not heroics. Do the boring work before the crisis, and the crisis either doesn't happen or is manageable when it does.
Happy holidays. Stay vigilant.
Planning an ERP modernization?
6 SAP-to-Dynamics conversions with zero business disruption. Let's discuss your project.
ERP Services Book a Call