When security teams step away, attackers step in
- The UK Government’s Cyber Security Breaches Survey found that more than 60% of security incidents occur outside of standard business hours.
- This deliberate timing to take advantage of security teams being understaffed or distracted means that cybersecurity strategies must include processes that maintain protection around the clock.
- Small and medium-sized businesses (SMBs) often occupy a dangerous ‘sweet spot’ for cyber criminals. Many SMBs hold valuable customer data, are big enough to pay a substantial ransom, and there is an assumption that many do not allocate the appropriate resources needed to maintain appropriate cyber security.
- Attackers increasingly exploit moments when defenders are distracted, making automation and continuous visibility essential components of business resilience.
There are more burglaries in the UK in November than any other month. Most break-ins don’t happen in the middle of the night, but during the day. The earlier sunset of November gives thieves the cover of darkness during working hours, when they know their targets are more likely to be away from home.
For similar reasons, the UK Government’s Cyber Security Breaches Survey found that more than 60% of security incidents occur outside of standard business hours. Threat actors have long taken advantage of periods when defenders are less likely to be on high alert, including weekends and holidays. Increasingly, however, they are targeting moments when security teams are occupied elsewhere. N-able’s 2026 State of the SOC report noted a spike in the number of attacks during Black Hat USA 2025 – a time when many security experts were focused on learning about new risks and trends.
This deliberate timing to take advantage of security teams being understaffed or distracted means that cybersecurity strategies must include processes that maintain protection around the clock. Security teams cannot realistically stay switched on 24/7 and need to prioritise automated response capabilities that can detect, contain, and limit the impact of an attack when a human response is not immediately available.
High risk, limited visibility, and alert fatigue
Small and medium-sized businesses (SMBs) often occupy a dangerous ‘sweet spot’ for cyber criminals and many face the same level of risk as much larger companies. Many SMBs hold valuable customer data, are big enough to pay a substantial ransom, and there is an assumption that many do not allocate the appropriate resources needed to maintain appropriate cyber security.
But budgets aren’t the only limiting factor for these smaller businesses. Often, security teams within smaller organisations lack the structural foundations to be properly prepared for a cyberattack. Lean IT teams often have little capacity for proactive threat hunting. As a result, attackers, if undetected, can spend days moving through environments unnoticed until their actions become visible – and that is often too late to prevent data exfiltration or a ransomware attack.
This challenge becomes even more significant when we consider the sheer volume of threats, and their increasing sophistication. Our own research found that there were over 900,000 alerts processed by the N-able SOC between March and December 2025, nearly two alerts every minute. No human team can realistically keep pace with that volume, creating blind spots where missed alerts can evolve into serious security incidents.
However, managing an overwhelming number of alerts doesn’t require eye-watering investment or overstretching staff, even in distracting or busy times. Security teams can work smarter.
Automating our way to security that never sleeps
Automation can be a security team’s greatest ally, driving instant visibility and response across a security stack. For example, analysts can use SOAR (Security Orchestration and Response) workflows to cope with the massive number of security alerts, by triaging the most important alerts and performing automatic threat containment where possible.
Automation executes repetitive, high-volume tasks, allowing analysts some breathing room to tackle those alerts that cannot be automated. This allows security teams to spend more time investigating active threats and use their own judgement and experience rather than perform rote tasks.
However, automation isn’t enough on its own. True business resilience can only come when it is paired with layered visibility.
Individual incidents typically don’t give you all of the information you need. For example, a failed login, a password reset and a change to user’s normal login location may appear routine when viewed in isolation. However, correlation can reveal the early stages of an attack – even if the incidents are benign on their own. SMBs therefore must move away from an overreliance on single-layer security and redirect resources towards building resilience that takes context from the perimeter, network, cloud, identity, and endpoint layers.
Automation can then be used as a tool to streamline and map out threats for SOC teams to prioritise and plan appropriate containment mechanisms. Even when teams aren’t readily available or are understaffed, the combination of automation and visibility can help eliminate the spread of an attack, minimising the damage.
Building resilience alongside a security stack
Cyber resilience is defined by how an organisation’s tools can work together when an attacker strikes. For SMBs in particular, success depends on being strategic and building an architecture that provides continuous visibility and using that to effectively correlate signals across an environment.
Just as homeowners rely on alarms, locks, and cameras when they are away, organisations must ensure their security operations remain effective even when teams are occupied elsewhere. Attackers increasingly exploit moments when defenders are distracted, making automation and continuous visibility essential components of business resilience.
Find out about cybercrime and how AI is changing the landscape in the video below.
Will Ledesma is director of managed detection and response at N-able.
Read more
What the first 24 hours of a cyber incident should look like – The early stages following a cyber incident are arguably the most important. Here’s how to manage it and learn from it
The importance of disaster recovery and backup in your cybersecurity strategy – A strong disaster recovery as-a-service (DRaaS) solution can prove the difference between success and failure when it comes to keeping data protected
Keys to effective cybersecurity threat monitoring – A strong cybersecurity threat monitoring strategy that evolves with current and prospective threats is crucial towards long-term company-wide protection