When the IT Team Is at the Beach, Who's Watching the Alerts?
Summer holiday rotas leave security desks thin. Kaseya argues AI-driven automation can hold the line, but only if it's set up before the out-of-office replies start.

Key points
- Kaseya says summer staffing gaps leave many IT teams short-handed while cyberattacks continue at full pace.
- The company argues AI-driven automation can triage alerts, apply patches and flag suspicious logins without waiting for a human.
- Attackers often time campaigns around holidays and long weekends, when response times slow.
- Training junior staff and writing clear playbooks matter as much as the tools themselves.
Hackers don't take August off. IT teams often do.
That's the awkward gap Kaseya, a company that sells software for managing IT systems, wants to talk about. In a recent piece flagged by BleepingComputer, the vendor makes the case that automation powered by artificial intelligence can help keep the lights on in the security operations centre, the room (or these days, the shared screen) where analysts watch for signs of a break-in.
The pitch is simple. When half the team is away, the other half drowns in alerts. Something has to give, and usually it's the boring but important work: reviewing logs, applying patches, checking who logged in from where.
Why does summer make this worse?
Because attackers know the rota as well as you do.
Ransomware crews, criminals who encrypt a company's files and demand payment to restore access, have a long history of striking on Friday evenings and bank holidays. The FBI and the UK's National Cyber Security Centre have both warned about this pattern for years. The logic is grim: if the on-call engineer is three pints in at a wedding, the attack has more time to spread before anyone notices.
Summer stretches that problem across three months.
A mid-sized company might normally have six people watching for trouble. In August it might have two. Alerts still arrive at the same rate. Phishing emails, fake messages designed to trick staff into handing over passwords, keep landing in inboxes. Software vendors keep publishing patches that need testing and rollout.
Something gets dropped. Usually it's the thing that turns out to matter.
What can automation actually do?
Kaseya's argument is that a well-configured system handles the repetitive work on its own. That means sorting alerts by severity so a human sees only the ones that matter, applying routine software updates on a schedule, blocking obviously suspicious logins (an admin account signing in from a country the company doesn't operate in), and kicking off a standard response when a known attack type appears, such as isolating an infected laptop from the network.
None of this is magic. It's closer to a very patient junior analyst who never sleeps and never gets bored of the tenth phishing report of the morning. We've tracked this alert-triage problem across 28 SOC stories in the last 90 days, and the consistent finding is that automation helps most when the underlying rules are written by people who understand the environment.
The catch, and Kaseya's honest enough to hint at it, is that automation only works if those rules are written well. A badly tuned system will either flood the on-call engineer with false alarms or, worse, quietly ignore the one real attack in a sea of noise.
What should smaller organisations take from this?
You don't need an enterprise budget to plan for thin coverage.
A GP surgery, a law firm, a local charity: all face the same summer squeeze in miniature. The practical steps aren't glamorous. Write down who's on call and how to reach them. Make sure someone other than the head of IT knows the password vault recovery process. Turn on multi-factor authentication, the two-step login that asks for a code from your phone, so a stolen password alone isn't enough.
And tell staff, plainly, that attackers target holiday periods on purpose. A well-briefed receptionist has stopped more attacks than most people realise.
The machines can help. They just work better when the humans have done the thinking first.



