A hand is pressing a large glowing keyboard key labeled “24/7 Support” with surrounding computer keys, highlighting constant support availability.

Attackers Work Nights and Weekends. Does Your IT Support? The Case for 24/7/365 Emergency Support

By Jason Russell · August 31, 2026

Here is a pattern I have watched repeat itself for fifteen years of running a managed services company. The call comes in Monday morning. Something is wrong. Files will not open, the server is unresponsive, or there is a text file on a desktop that nobody put there. The owner assumes the problem started when the first employee walked in and flipped on the lights. It almost never did.

The logs tell the same story nearly every time. The intruder was working while everyone else was asleep, and the real damage was done somewhere between Friday evening and Sunday night. By the time a human noticed, the only open question was how much it was going to cost.

This post is about the gap between the moment trouble starts and the moment someone qualified starts working on it. Emergency support that is available 24 hours a day, 365 days a year, exists to close that gap. I want to make the case with data rather than adjectives, and I want to be honest about what round-the-clock support can and cannot do for a small business.

Attackers keep a schedule. It is the opposite of yours.

Sophos publishes an annual Active Adversary Report built from its own incident response and managed detection cases. It is one of the few public datasets that records what time of day, in the victim’s local time, an attack actually happened. The 2026 edition covers 661 cases handled between November 2024 and October 2025 across 70 countries.

The timing findings are the reason this post exists:

  • 88 percent of ransomware payloads were deployed outside the victim’s normal business hours.
  • 79 percent of data theft (the exfiltration that precedes an extortion demand) also happened off-hours.
  • The busiest four hours of the day for attackers were 11 p.m. to 3 a.m. More than a third of attacks with a known start time (37.1 percent) began in that window.
  • Attacks were spread almost evenly across the week, with a slight rise on Thursdays and Fridays. Attackers are not waiting for a specific day. They are waiting for you to go home.

This is not a one-year blip. Sophos first reported the pattern in 2023 and has tracked it since: 94 percent of ransomware deployments were off-hours in 2022, 91 percent in 2023, 83 percent in 2024, and the all-time figure across the full dataset sits at 88 percent. Worth noting for this audience: Sophos has said its incident response caseload skews heavily toward organizations under 1,000 employees, and more than half of the cases in its 2024 report came from companies with 250 employees or fewer. This is small-business data, not Fortune 500 data.

The federal government reached the same conclusion from a different direction. In 2021, the FBI and CISA issued a joint advisory (AA21-243A) after a run of high-impact ransomware attacks that landed on holiday weekends: the Colonial Pipeline attack leading into Mother’s Day, the JBS attack over Memorial Day weekend, and the Kaseya attack on the Fourth of July. The advisory stated plainly that attackers had been timing their operations for when offices are normally closed, and it recommended that organizations identify IT security personnel who would be available on weekends and holidays. That advisory is five years old now. The Sophos data says nothing about the pattern has changed.

None of this is an accident. Attackers choose off-hours for the same reason a burglar prefers an empty house: the odds of being interrupted are lower and the time available to work is longer.

Why the first few hours decide the outcome

Once an attacker has a foothold, the clock starts. Sophos measured the median time from initial access to the moment the attacker reached Active Directory, the system that controls every login and every permission on a Windows network. In its 2025 report, that median was 0.46 days, or roughly 11 hours. Once they own Active Directory, they can reach every server, every workstation, and very often the backups.

Now do the weekend arithmetic. Suppose an attacker gets in at 7 p.m. on a Friday through a phished password or an unpatched firewall. If nobody looks at the network until 8 a.m. Monday, that is 61 hours of uninterrupted access. With an 11-hour median to Active Directory, the attacker has domain control by Saturday morning and roughly two more days to find the data worth stealing, disable the backups, and stage the encryption. Everything you see Monday morning is the last step of a job that was mostly finished by Saturday lunch.

Contrast that with a business where a suspicious login at 7:40 p.m. Friday reaches an engineer who can isolate the machine and reset credentials within the hour. The attacker never gets to Active Directory. The Monday morning call never happens. Same attacker, same phishing email, same firewall. The only variable is whether someone was there to answer.

One honest caveat. That contrast assumes something raised an alarm at 7:40 p.m. Emergency support is the response half of the equation. Detection is the other half, and they are not the same thing. I cover the difference below, because plenty of providers sell one while implying they deliver both.

What downtime actually costs a small business

You have probably seen the big numbers: the average breach costs millions, and so on. I do not use those figures in front of clients. They are averages pulled from datasets dominated by large enterprises, and an average with a few $20 million outliers in it tells a 30-person company nothing useful about its own risk.

In June 2026, the team that writes the Verizon Data Breach Investigations Report released something better: the first Breach Impact Study, built with the cyber insurance data consortium CyberAcuView. It analyzes roughly 70,000 U.S. cyber insurance claims from January 2019 through October 2025, about 38,000 of which had losses actually paid out. The authors deliberately report medians instead of averages, and they said outright that they refused to publish the average so it would not get repeated around the internet. That is the kind of source I trust.

Here is what it says about companies under $25 million in annual revenue, which covers nearly every business we serve:

  • The median claim impact for a small business was about $38,000. That is the middle of the distribution, not the worst case.
  • In the top 10 percent of small-business claims, losses reached 3 percent of annual revenue. In the top 2.5 percent, they exceeded 7 percent of revenue. For comparison, mid-market and enterprise losses never crossed 2 percent of revenue even in their most extreme cases. The smaller you are, the larger a breach is relative to your ability to absorb it.
  • Ransomware drove 39 percent of small-business claims and business email compromise drove another 19 percent. Between them, that is nearly six in ten claims.
  • Business interruption is now the single largest loss category. Across the whole dataset, it carries the highest median loss of any category at roughly $90,000, and it grew from 21 percent of known losses in 2023 to 32 percent in 2024. The study also began tracking losses caused by a third party’s outage, such as a cloud vendor going down, and that category alone was 13 percent of known losses in its first year.
  • The authors are careful to point out that insured losses are a floor, not a ceiling. Deductibles, sublimits, and everything a policy does not cover sit on top of these numbers.

Read that list with response time in mind. The ransom is something you can decline; Verizon’s 2026 DBIR found that 69 percent of victims did not pay. The regulatory exposure is something your attorney handles over months. But business interruption is the one loss category that is governed almost entirely by hours, and hours are exactly what after-hours support buys back.

Do your own math instead of trusting mine

I would rather you calculate your own downtime cost than borrow someone else’s statistic. Two numbers get you most of the way there.

Revenue at risk per business hour: annual revenue divided by 2,080 working hours. A $4 million company is producing roughly $1,900 of revenue for every hour its systems are up. Not all of it evaporates during an outage, but some of it does, and the rest gets delayed.

Payroll burning per hour: the number of people who cannot work without their systems, multiplied by their loaded hourly cost. Twenty people at $35 an hour is $700 an hour spent watching a spinning cursor.

For that example company, an incident that starts Friday night and gets discovered Monday morning has a bill somewhere around $2,600 for every business hour of the recovery, before anyone has paid an engineer, an attorney, or a ransom. Then consider how long recovery takes. Sophos’ 2025 State of Ransomware survey of 3,400 organizations that had been hit found that just over half were fully recovered within a week, but 18 percent took more than a month. A month of that arithmetic is a number most owners have never actually written down. I recommend writing it down.

Not every emergency is a hacker

I have spent most of this post on security because that is where the data is, but a large share of the after-hours calls we take have nothing to do with an attacker.

  • A server’s RAID controller fails at 2 a.m. and the practice management system is down when the first patient arrives at 7:30.
  • A fiber line gets cut on a Saturday and the point-of-sale terminals at every location lose connectivity in the middle of the weekend rush.
  • A managing partner is locked out of email at 6 a.m. on the day a filing is due.
  • A cloud vendor has an outage, and someone needs to figure out within minutes whether the problem is theirs, yours, or the internet in between. The Breach Impact Study’s finding that third-party outages now account for 13 percent of insured losses tells you how common this has become.
  • Here in Central Florida, there is a stretch of every year when the question is not whether a storm will knock out power somewhere in the service area, but which weekend it will happen on.

An emergency is defined by business impact, not by cause. If people cannot work or customers cannot be served, it does not matter whether the reason is criminal, mechanical, or meteorological. Someone needs to pick up the phone.

What 24/7/365 emergency support is, and what it is not

Since this phrase gets stretched in marketing copy, let me define it the way we use it.

What it is: a qualified engineer, not an answering service, who can be reached at any hour on any day, who has the documented access and authority to take action remotely within minutes, and who is backed by current, tested backups and a written plan for what to do when things go wrong. That last part matters. An engineer without a break-glass administrator account or a known-good backup is a sympathetic voice on the phone, not a fix. (We wrote about why that documentation matters in IT Asset and Documentation Management.)

What it is not, part one: monitoring. Support is reactive. If nobody calls, nobody comes. The thing that catches a suspicious login at 7:40 on a Friday evening is a detection system, typically some combination of endpoint protection, log monitoring, and a security operations team that watches the alerts and pages the on-call engineer. A provider can honestly offer 24/7 support while offering no after-hours detection at all. Ask which one you have. You want both, and you want the detection to feed directly into the response. We covered the detection side in What Happens at 2 a.m.: Why 24/7/365 SOC Monitoring and Response Is the Control Most Small Businesses Skip.

What it is not, part two: prevention. Round-the-clock response does not stop the phishing email from arriving or the firewall from having a vulnerability. Patching, multifactor authentication, and staff training do that work. What emergency support changes is the distance between intrusion and containment. It turns a 61-hour head start into a 40-minute one.

What counts as an emergency: a system or site that is down, an active security incident or a credible sign of one, data that is lost or inaccessible, or anything that prevents staff from working or customers from being served. What does not count: a printer, a new-user request, or a question about a spreadsheet formula. Those wait until morning, and any provider worth hiring will tell you so up front. A support team that treats everything as an emergency will burn out its engineers, and eventually one of them will miss the call that was.

Why we include it in every plan, and why that also serves us

Harmony MSP includes 24/7/365 emergency support in every managed services agreement. There is no premium tier that unlocks it and no after-hours surcharge. I want to be plain about why, because the reasons are not purely altruistic.

  • It is cheaper for us. An intrusion we catch at 8 p.m. is a two-hour cleanup. The same intrusion discovered Monday morning is a week of rebuilding servers, restoring data, and fielding calls, and that labor costs us far more than any after-hours fee would have brought in. Staffing nights and weekends is a real expense. Not staffing them is a larger one.
  • Billing for emergencies creates the wrong incentive. If calling at midnight costs $300 an hour, clients hesitate. They wait to see if the problem resolves itself. That hesitation is exactly the delay the attacker is counting on. Removing the fee removes the hesitation.
  • Clients who go down over a weekend and cannot reach anyone do not renew. That is not a complaint. It is a perfectly reasonable response to being left alone at the worst possible moment, and it is a business risk we would rather not carry.

I made the same argument about daytime support in Unlimited Remote and Onsite IT Support: Why the Flat Fee Usually Costs Less. The principle is identical: the moment calling for help carries a price tag, some people will wait, and the outcome when it goes wrong is bad for them and bad for us.

Six questions to ask any IT provider, including us

If you already have a provider, this is the part of the post to print out. Ask these questions and pay attention to how specific the answers are.

Question What a good answer sounds like
Who answers if I call at 2 a.m. on a Sunday? A named engineer or an on-call rotation of named engineers. Not a call center that takes a message and promises a callback.
How quickly will someone start working on it? A response target measured in minutes, written into the agreement, with a definition of what starts the clock.
Is after-hours support included or billed? Included. If it is billed, you should know the rate, whether there is a minimum, and whether there is a cap.
Will you know about a problem before I do? Yes, because monitoring and detection alerts page the on-call engineer directly. If the honest answer is no, that is worth knowing now.
Do you have what you need to act at 2 a.m.? Documented administrative access, tested break-glass accounts, and a backup that was verified this week, not one that was assumed to be working.
What do you consider an emergency? A written definition that you have seen and agreed to, so there is no debate about it while something is on fire.

If a provider cannot answer these in writing, the after-hours coverage on their website is a promise, not a plan.

A closing thought

Every owner I have ever talked to after a bad weekend says some version of the same thing: I wish someone had been watching. The data says that wish is well founded. Attackers do most of their work between 11 p.m. and 3 a.m. and on the days you are not in the office, they need about 11 hours to take control of a network, and the losses that hurt small businesses most are the ones measured in hours of interruption. None of that is theoretical. All of it is in the sources below.

If you are not sure how your current provider would answer the six questions above, ask them this week. If you would rather talk it through with someone who has taken a lot of Monday morning calls, we are at (407) 720-6540. There is no pitch attached. We will tell you what we would do in your situation, and you can take it from there.

Frequently asked questions

Is 24/7 emergency support the same as 24/7 monitoring?

No. Emergency support is a person you can reach who will take action. Monitoring is the system that notices a problem and raises the alarm, often before you know anything is wrong. A provider can offer one without the other. For after-hours protection you need both, with the monitoring wired directly to whoever is on call.

What counts as an IT emergency?

A system or location that is down, an active security incident or a credible sign of one, lost or inaccessible data, or anything that stops staff from working or customers from being served. Routine requests such as new user setup, printer issues, or software questions are not emergencies and should wait for business hours.

How much does downtime cost a small business?

It depends on your revenue and headcount, which is why we recommend calculating it yourself: annual revenue divided by 2,080 gives revenue per business hour, and idle staff times their loaded hourly cost gives payroll burn. For context, the Verizon 2026 Breach Impact Study found the median insured loss for businesses under $25 million in revenue was about $38,000, with business interruption the largest single loss category.

Why do attackers strike at night and on weekends?

Because response is slower. Sophos’ incident response data shows 88 percent of ransomware is deployed outside business hours, with the busiest window between 11 p.m. and 3 a.m. The FBI and CISA have documented the same pattern around holiday weekends. Attackers want the longest possible window before anyone notices.

Related reading

Sources

A note on statistics: attack timing figures are Sophos’ findings from its own incident response caseload. Loss figures are from the Verizon Breach Impact Study’s analysis of U.S. cyber insurance claims and reflect insured losses only. Downtime cost examples in this post are illustrative arithmetic, not survey statistics.

Our latest posts