Fewer staff, more risk: Commvault Field CTO Mark Molyneux advises IT teams to prepare deliberately for the summer holiday period as vulnerability counts rise and frontier AI models reshape risk assessment, ranging from a defined operating mode to tested incident-response plans.

The holiday season is widely regarded as a period of reduced staffing in many organizations – and therefore also a time requiring heightened attention to IT security. According to Mark Molyneux, Field CTO at Commvault, IT teams should place greater focus this summer on vulnerability management, earlier patch cycles and incident management. He points to a changed risk assessment driven by frontier AI models, which in his view are leading to the disclosure of more vulnerabilities that threaten organizational resilience.

An analysis of the past three summers shows no significant overall increase in cyberattacks, according to Commvault. Even so, risks are said to be higher for industries with particularly high seasonal revenue during the summer months, including tourism, tour operators, hotels and logistics companies. Security firm Check Point highlighted this pattern in a recent analysis: such companies reportedly become a more frequent target for cybercriminals during their peak revenue season, as they depend heavily on functioning IT systems and are therefore more vulnerable to ransomware extortion. For the tourism sector, the risk of data espionage is cited as an additional threat.

Statistics from the European Union Agency for Cybersecurity (ENISA) and the Computer Emergency Response Team CERT-EU also indicate that the overall number of cyberattacks across all sectors continues to rise year over year. Check Point reportedly documented increasing attacker activity for the 2025 summer quarter based on an analysis of data-leak sites, compared with the previous year.

To get through the holiday period without major incidents, ENISA and other organizations and IT consultants recommend a three-part strategy: preparation before the summer period, stricter controls during these months, and a follow-up review of lessons learned afterward to adjust measures for the winter holiday season.

Against this backdrop, Commvault names six recommendations for IT leaders:

First, organizations should formally define a summer operating mode that sets out roles, responsibilities and the availability of security functions for July and August, including designated deputies, on-call arrangements and escalation timelines. Germany’s Federal Office for Information Security (BSI) also notes that staff absences and knowledge silos can put business processes at risk.

Second, deputies should be appointed and a four-eyes principle enforced so that no critical process depends on a single person – covering administrators, the security operations center, and those responsible for network, identity and access management, backup, cloud, and the service desk. Inventories of privileged accounts are also considered important.

Third, patch and vulnerability monitoring should remain active. As the number of vulnerabilities disclosed with the help of AI models is said to be increasing, Commvault points to the need for regular checks of CERT, vendor and threat feeds, along with prioritization of risks.

Fourth, non-critical changes should be frozen while processes for critical and emergency changes are clearly defined. Emergency processes for critical patches are meant to remain in place, while non-critical changes are postponed.

Fifth, Commvault advises actively testing backup and recovery – not only whether backups are running, but whether critical services can actually be restored from them. This includes restore tests, data-integrity checks, offsite, offline and immutable copies, and access to a documented recovery solution.

Sixth, the company recommends running incident-response runbooks through a tabletop exercise before the summer break – for scenarios such as phishing, ransomware, or a critical SaaS or cloud outage. ENISA recommends tested incident-response procedures, documented playbooks and annual exercises with a follow-up evaluation.

According to Commvault, cyber resilience over the summer requires close coordination between human and technical capabilities, particularly given the growing role of AI systems in vulnerability analysis. Support from business units is also considered important so that non-critical changes are reduced and pressure on IT teams is eased.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner