Cybersecurity in Summer (1)

It has become an ordinary scene: on a beautiful Greek beach, an executive rereads a contract on a tablet, answers two urgent emails, then absent-mindedly slides it under a towel while going for a swim. Ten minutes later: no more tablet. No serious password. No encryption. And, of course, sensitive data inside.
This type of incident, once rare, has become a summer classic. Because summer suspends neither security obligations nor cyber threats. While the offices empty out, hackers never really go on vacation.
So how can you enjoy your time off without putting your company’s data at risk? How can you stay vigilant without becoming paranoid or sabotaging your ten days by the sea?
AgencePDN gets pirated content removed: see our solutions by sector.
In our August theme, we give you the best advice for a worry-free summer and a good return to work without giving up on cybersecurity.

Illusory Disconnection, Real Vulnerability
We often think vacation means a digital pause. In reality, it is one of the riskiest times for IT security: employees connecting from public networks, equipment taken on the road, lower vigilance, less internal supervision.
Some figures speak for themselves: according to a NordLayer study (2023), more than a third of corporate cybersecurity incidents occur during holiday periods, notably July–August and December.
Last August, a lawyer at a large French industrial group logged in to their webmail from Athens airport. They entered their credentials on what they thought was the airport’s Wi-Fi portal. In reality, it was a malicious copy. The next day, their access was compromised and confidential documents were exfiltrated. The incident required an alert to the CNIL and a full audit of connections.
Why Summer Amplifies the Risks
It is the context that weakens defences.
- First, attention drops. The mind is elsewhere, priorities are different.
- Second, environments are less controlled: hotels, vacation homes, cafés, trains, airports…
- Finally, IT and security teams are also running at half speed, and emergency procedures are sometimes poorly defined.
- Add to this a psychological factor: excessive trust in personal technology. Many people assume their phone, tablet or PC is “safe,” without checking that encryption is enabled or that connections are secure.
VPNs, Segregation, Access Management: The Habits That Really Help
You don’t need to be a cybersecurity expert to take effective measures. But you do need to plan them before leaving. A professional VPN, for example, remains one of the simplest and most effective ways to secure communications — even on dubious connections.
Another often-neglected point: the separation between work and personal life. Using one device for everything is a common habit, but a risky one. Creating separate sessions, enabling a secure workspace, or even taking two devices if possible, considerably limits the damage in the event of an incident.
And of course, password management remains central. Too many users take advantage of summer to “keep it simple”: the same password across several services, no two-factor authentication… All open doors that compromise security. A secure password manager not only strengthens security but also saves time, even when travelling.
Keep Working… Without Exposing the Organization
Let’s be realistic: many executives and managers never fully switch off. And that is not necessarily a problem in itself. But it means treating mobility as a full cybersecurity scenario, not as a parenthesis.
Take another real case: in 2022, a director on vacation takes their work computer along in the car. They stop at a highway rest area. When they come back, the car window is smashed and the computer is gone. The computer was neither encrypted nor locked. It contained sensitive files, accessible without a password. The result: a customer data leak, and all the trouble that follows.
Enabled encryption, a properly configured session lock or the ability to “remote wipe” would have been enough to limit the impact.
Legal Liability Doesn’t Stop in Summer
From a regulatory standpoint, notably under the GDPR, a company’s responsibility knows no summer truce. Any personal data breach — whether it happens in August on a beach or in the middle of a January meeting — is subject to the same obligations: risk analysis, possible notification to the CNIL, documentation of the measures taken.
And behind the company, it is also executives and technical managers (CIOs, CISOs) who can be held to account for negligence, especially if basic measures were not in place.
Several recent rulings have reminded us that, when it comes to security, the absence of adequate means is a fault in its own right. It is not enough to say that an employee “acted wrongly”: you must also prove that the company had given them the right tools and the right instructions.
Anticipate, Train, Delegate: Good Summer Habits
So what should you do before shutting down your computer and packing your bags?
- Have a quick check-in with your security team: what remains accessible? Who has access to what? Can temporary privileges be reduced?
- Plan a clear procedure in case of an incident: who should a loss be reported to? Who can step in remotely? Is a written delegation needed?
- Briefly train employees who are leaving with equipment or access: a one-page memo can be enough if it is well done.
- Share emergency contacts in an easily accessible format (QR code, secure cloud).
It is not summer that creates the risk. It is the momentary forgetting of professional reflexes. Cybersecurity on vacation does not mean distrusting everything, all the time. It simply means planning for the tipping points, where a moment of relaxation can be costly.
And paradoxically, it is also a good opportunity to review internal practices: who has access to what? Why keep certain resources open all summer? Why not train teams in mobile use?
Summer can be a pause. But cybersecurity must remain a routine.
Join us in mid-August for the second part of our article on cybersecurity on vacation. In the meantime, if you have a film, a series, software or an ebook to protect, don’t hesitate to call on our services by contacting one of our account managers; PDN has been a pioneer in cybersecurity and anti-piracy for more than ten years, and we are bound to have a solution to help you. Happy reading, and see you soon!
Share this article


