At 5pm on a Friday, most Auckland businesses wrap up and leave. IT support goes offline or moves to on-call. The security alerts that accumulated during the day sit in a queue. Nobody is watching.
That window - Friday evening through Monday morning - is 60 hours of reduced visibility in the environment your business depends on. And it's the window attackers specifically plan around.
The Semperis 2025 Holiday Ransomware Risk Report, which surveyed organisations across ten countries including New Zealand, found that 52% of organisations that experienced a ransomware event in the past year were hit during a weekend or holiday. The same report found that 78% of companies cut their security operations centre staffing by 50% or more during those periods.
Attackers know this. It's not coincidence - it's timing. The ZenTech ransomware attack confirmed in September 2026, the ManageMyHealth breach, the cluster of NZ incidents earlier this year: in each case the forensic picture showed access and activity that extended beyond business hours. Detection, by contrast, happened during business hours when someone eventually checked.
For Auckland SMEs running lean IT teams - one or two people managing devices, Microsoft 365, user support, and security simultaneously - continuous after-hours monitoring isn't realistic alongside the day job. That gap is where this year's NZ breach pattern has concentrated.
The logic is straightforward. An attacker who gains initial access on a Friday evening has the weekend to move through an environment before anyone is likely to investigate. CrowdStrike's 2026 Global Threat Report found the average time for an attacker to move from one system to another is 29 minutes. By Monday morning, a weekend's worth of undetected access has been put to use.
The Sophos Active Adversary Report 2026 - based on 661 incident response cases - confirmed that ransomware payload deployment is specifically timed outside standard business hours. Attackers access environments during the week through credential theft or phishing, move quietly through the environment, and deploy ransomware when they're confident the response will be slow.
The Semperis research adds the operational detail: 78% of organisations reduce their security monitoring capacity by half or more on weekends and holidays. For smaller Auckland businesses with no dedicated security function, that reduction is effectively 100% - there's nobody watching between Friday evening and Monday morning.
This isn't a new pattern. It's a well-documented, consistent feature of how ransomware groups operate. What's changed in 2026 is the frequency - Q1 2026 recorded a 126% year-over-year surge in ransomware incidents globally, the steepest single-quarter increase on record.
Consider what after-hours coverage actually looks like for a business with 20 to 80 staff in Auckland.
The IT function - whether internal or outsourced to an MSP - handles devices, Microsoft 365, user support, and day-to-day infrastructure. Security is one responsibility among many. After 5pm, the helpdesk goes to voicemail or on-call. Alerts generated by security tools sit in queues that get checked the following business day.
If a phishing email compromises an employee's credentials on Friday at 4pm, the sign-in risk alert generated by Microsoft Entra ID sits unreviewed until Monday. By Monday, the attacker has had the weekend.
This is the monitoring gap that matters most for Auckland businesses, and it's structural rather than negligent. A small IT team cannot realistically maintain 24-hour security operations alongside operational responsibilities. The choice most businesses have made - implicitly, without a formal decision - is to accept that gap.
What's changed is how consequential that choice is. The ZenTech breach in Dunedin, the Thankyou Payroll incident, the earlier Waikato DHB attack - each involved an access period that extended well beyond business hours. Each was detected after the access had occurred, not during it.
Auckland's role as New Zealand's largest business hub creates a specific risk profile. The city concentrates professional services, legal firms, accounting practices, financial services, technology companies, and construction businesses in a way that makes it a disproportionate target for financially motivated attacks.
Business email compromise - targeting financial transactions, particularly in property and professional services - is consistently the NCSC's highest-loss category. The law firms, real estate agencies, and accounting practices concentrated in Auckland's CBD and suburbs are the primary targets for BEC precisely because of the financial transactions that flow through them daily.
Those transactions don't stop on Friday afternoon. Settlement payments, deposit instructions, and invoice approvals often have Monday deadlines. An attacker who accesses an email account on Friday evening has the weekend to observe those pending transactions and position to intercept them - with nobody monitoring to catch the access.
The Semperis research finding that 60% of ransomware attacks occurred after a merger, acquisition, or significant business change is also relevant for Auckland's active commercial environment. Businesses going through growth, acquisition, or restructuring are specifically targeted during those periods because identity environments are in flux, exceptions are made, and oversight is stretched.
The case for after-hours monitoring comes down to one question: what happens differently when someone is watching?
When a suspicious sign-in occurs at 11pm, a security analyst who is actively monitoring sees it in real time. They review the account's recent activity, check whether the sign-in location is plausible, look for correlated activity across the environment, and make a decision - investigate further, contain the account, or clear it as legitimate.
When no one is monitoring, the same sign-in sits in a queue. The account continues to be accessible. Whatever the attacker does with it between 11pm and Monday morning goes unobserved.
Mandiant's M-Trends 2026 data shows that organisations detecting intrusions internally do so in a median of nine days. Those that rely on external notification take 25 days. The difference - 16 days - is broadly the gap between active monitoring and periodic checking.
For a ransomware attack timed over a weekend, nine days versus 25 days means the difference between detecting movement before deployment and discovering the breach after systems are encrypted.
NSP's Managed Detection and Response service provides continuous monitoring across Auckland SME environments - endpoints, Microsoft 365 identity, email, cloud activity, and network traffic - 24 hours a day, seven days a week, including weekends and public holidays. When something anomalous occurs, an analyst investigates it during that same session, not the following business day. Powered by Adlumin's detection platform and backed by a local security operations team, it's built for exactly the coverage gap Auckland businesses carry but rarely name explicitly.
These are direct questions worth putting to your IT provider or internal team.
If suspicious activity occurred in your Microsoft 365 environment at 8pm on a Friday, what is the process for detecting and responding to it? Not theoretically - who specifically would see it, and how quickly?
When your IT support goes to on-call or offline cover on weekends, does security monitoring continue at the same level as during business hours? If staffing is reduced, what is covered and what isn't?
Are the security alerts generated by your tools reviewed continuously, or are they checked during business hours when someone has time? If it's the latter, what is the realistic review window for an alert generated on Saturday afternoon?
Has your business had a conversation about after-hours monitoring specifically, or has the assumption been that existing arrangements cover it?
These aren't questions with wrong answers. They're questions that produce clarity about a gap that most Auckland businesses carry without having made a deliberate decision about it.
Why do attackers specifically target weekends and holidays?
Reduced monitoring is the primary reason. Semperis's research found 78% of organisations cut security operations staffing by 50% or more on weekends and holidays. Attackers who gain access during the week often time payload deployment - ransomware encryption, data exfiltration - for these windows because the response is slower and detection is less likely. The same research found 52% of ransomware events in surveyed organisations including New Zealand occurred on weekends or holidays.
Can my IT provider cover after-hours security monitoring?
It depends entirely on what the engagement covers. Managed IT services and managed security operations are different capabilities. An IT provider handling helpdesk, devices, and Microsoft 365 administration is not necessarily providing 24/7 security monitoring and alert investigation. Asking specifically whether security alerts are monitored outside business hours, and what the response process is when something is detected, gives you the clarity you need.
What does MDR cover that my current security tools don't?
Security tools detect and alert. MDR adds continuous human monitoring, alert investigation, and active response. When a suspicious event occurs, an analyst reviews it, determines whether it represents a genuine threat, and acts - isolating a compromised account, blocking suspicious activity, or escalating to the business. Tools generate the information. MDR determines what it means and what happens next, around the clock.
Is 24/7 monitoring realistic for a small Auckland business?
Through MDR, yes. The point of Managed Detection and Response is that it provides continuous security operations capability without requiring a business to staff a security operations function internally. NSP's MDR service is specifically built for NZ SMEs - businesses that need enterprise-grade monitoring without the cost and complexity of building it themselves.
What should I do if I'm not sure whether our environment is being monitored after hours?
Ask directly. The question to your IT provider or internal team is: if a security alert was generated at 9pm on a Saturday, what is the process for detecting it and responding? If the answer involves checking on Monday, that's the gap. A 30-minute conversation with NSP will give you a clear picture of what continuous monitoring would look like for your specific environment.
Most Auckland businesses find out their monitoring has gaps when something happens outside business hours. A free consultation with NSP covers what your current after-hours coverage looks like, what the gap is, and what continuous monitoring would change for your specific environment.
Book your free consultation with NSP
Or call us directly: 0508 010 101