FireEye: 76% of all enterprise ransomware attacks occur outside business hours, when IT staff support is reduced, overall ransomware attacks up 860% since 2017
Context & Ripple Effects
FireEye's timing data lands mid-arc in a ransomware escalation that has been compounding for years: attacks had already quadrupled year over year back in 2016 and were shifting from individual PCs to whole networks, and by early 2020 Trustwave found ransomware had overtaken credit card theft as the most common form of cybercrime. The 860% growth figure since 2017 confirms that trajectory accelerating rather than plateauing.
What makes this report distinct is the operational insight buried in the headline number: attackers are deliberately scheduling strikes for nights and weekends, when enterprise IT staffing thins out. Later survey data bears this out — by late 2022, [[a:984961|more than one-third of cybersecurity professionals said their firm lost more money from holiday or weekend ransomware attacks]], up sharply from the prior year.
First-order effects
- Enterprises can no longer treat business-hours monitoring as adequate coverage — the majority of attack volume now arrives precisely when in-house IT and security teams are least staffed, forcing immediate rethinking of on-call rotations and alert triage.
- FireEye's Mandiant-side incident response business gains a concrete selling point: the finding converts an abstract threat statistic into a direct argument for outsourced 24/7 detection and response.
Second-order effects
- Cyber insurers are positioned to price off-hours exposure into premiums and policy requirements, extending the trend where ransomware already drove 41% of H1 2020 cyber insurance claims and rising average demands.
- Attackers' preference for reduced-staffing windows increases the value of insider access, consistent with surveys showing 65% of large IT firms reporting approaches to help hackers establish insider access — recruitment pressure on employees likely intensifies for after-hours entry points.
Third-order effects
- If the pattern holds, enterprise security structurally migrates toward always-on managed detection and response, because few organizations can staff equivalent expertise around the clock internally — shifting spend from headcount to service contracts.
- Ransomware consolidating as the dominant cybercrime category, timed against organizational weak points, points regulators toward mandatory incident reporting and minimum-response standards of the kind FireEye itself urged at the SolarWinds hearing.
The trend: Ransomware is industrializing into a scheduled campaign discipline that targets enterprise staffing gaps, pushing security economics from in-house coverage toward continuous outsourced defense.