Survey of 1,203 cybersecurity professionals: more than one-third said their firm lost more money from holiday or weekend ransomware attacks, up from 13% in 2021
Meridith Levinson / Cybersecurity Software :
Context & Ripple Effects
The financial skew of ransomware toward off-hours attacks has been building for years: FireEye found back in 2020 that 76% of enterprise ransomware attacks occur outside business hours, when IT staffing is thinnest. What this new survey of 1,203 cybersecurity professionals adds is the money trail — more than a third of firms now say holiday and weekend strikes cost them more than weekday ones, nearly triple the 13% who said so in 2021.
That tracks with the broader escalation documented across related coverage: a CrowdStrike survey of 2,200 organizations found 56% hit by ransomware within a year, and follow-up research showed paying up doesn't end the ordeal — 80% of organizations that paid a ransom were hit again. Attackers appear to have learned that reduced-staff windows are where defenses and response slow down most.
First-order effects
- Security teams at the surveyed firms face immediate pressure to staff or automate monitoring for weekends and holidays, since those windows now carry the highest measured financial losses.
Second-order effects
- Cyber insurers, who already saw ransomware drive 41% of claims in H1 2020 per an earlier report, have grounds to price premiums around off-hours readiness — making weekend coverage a condition of affordable policies.
Third-order effects
- If off-hours targeting keeps paying, enterprise security shifts from office-hours incident response to always-on models — managed detection services and on-call staffing become baseline costs rather than premium options.
The trend: Ransomware operators are systematically timing attacks for weekends and holidays when IT support is reduced, converting understaffed hours into their most profitable window.