Over the past year, more than half of all ransomware attacks landed on a weekend or holiday. It’s a number worth keeping in mind as vacation season hits full stride.
If your Sage 100, Sage 300, or Sage X3 environment is still running in a server room down the hall, the calendar on your wall is also the attacker’s calendar. Memorial Day weekend is already in the rear view, the Fourth of July is coming up, and Labor Day is right behind it. Most IT teams will lose key people for stretches of all three, and attackers plan around it.
Attackers don’t break for summer
More than three-quarters of companies cut security staffing by at least half during weekends and holidays, and roughly one in five run a skeleton crew with reductions as steep as 90%. Those numbers are consistent across the major industry surveys.
The history matches the data. Several of the largest U.S. ransomware events of the past five years, including Colonial Pipeline, JBS, and Kaseya, kicked off around summer holiday weekends in 2021. The strategy is still working, and none of the major ransomware groups are pausing for the season.
Patches age in hours, not weeks
Mandiant’s M-Trends 2026 report puts the mean time to exploit a newly disclosed vulnerability below 24 hours. For some flaws it’s negative, meaning attackers are already using them before the vendor announces anything at all.
SAP disclosed a critical NetWeaver vulnerability last year, and Medusa ransomware affiliates were exploiting it within a single day. A recent analysis of ransomware cases from the prior twelve months found that 90% involved firewall compromise through unpatched software or a compromised account. The fastest incident in that dataset went from initial access to full encryption in three hours.
For a mid-market company running Sage on its own hardware, this timeline is uncomfortable. Monthly patch cycles, scheduled around the close and run by one or two IT generalists, are no match for the current pace of disclosure-to-exploit. By the time a critical CVE (Common Vulnerabilities and Exposures) reaches the front of next month’s patching queue, attackers have already tested it, exploited it, and moved on the next opportunity.
The ERP is the target now
Attacks against ERP systems, virtualization layers, identity services, and remote access tools have become the most common path to a full operational shutdown, according to industrial threat researchers reporting on the first quarter of this year. Attackers are going there on purpose. The ERP may not always be the first door attackers open, but it is often one of the systems that gives them the most leverage.
A Sage 100, Sage 300, or Sage X3 environment is a particularly rich target because every customer record, banking detail, open AR balance, and quarter of historical transaction data sits in one database that touches every department. Encrypting it halts the business. Exfiltrating it gives the attacker months of leverage even when backups recover cleanly. The ransom itself is often the smaller line item. Notification obligations, regulatory exposure, customer churn, and the executive hours absorbed by incident response usually add up to more.
Cyber insurance carriers know all of this, which is why renewal questionnaires increasingly ask pointed questions about ERP segmentation, backup immutability, MFA coverage on the database, and time-to-detect on the hosting environment. Premiums have hardened over the past two renewal cycles, and underwriters are pricing in the gap between operations that can demonstrate continuous monitoring and those that can’t. The good news is that reducing this risk does not require a mid-market company to build a full security operations center from scratch. It does require a different operating model.
What hosted Sage looks like in practice
Moving Sage to a managed hosting environment doesn’t make any of this go away. What it changes is who’s watching around the clock and what’s already in place before an attack shows up.
With Cloud at Work, customers can choose the hosting model that best fits their business: a managed virtual private environment or a public cloud hosting option on Microsoft Azure. The delivery model may differ, but the Cloud at Work services remain the same. Infrastructure patching runs on a tested cadence. Backups are immutable, snapshotted regularly, and verified through restore testing. Network activity is monitored against a baseline of what normal looks like for that specific Sage environment.
The difference is not only the technology. It is the coverage model. The environment is watched by a team that understands the patterns of attacks aimed at business-critical systems like Sage.
That’s the hosting layer. For companies that want broader protection, Cloud at Work can extend that hosted foundation with two connected services.
- Managed Cybersecurity brings endpoint detection and response, vulnerability scanning, identity and access controls, log monitoring, and incident response into one coordinated security stack. Because the same team understands the Sage hosting environment and the surrounding telemetry, there are fewer seams between the people patching, monitoring, and responding.
- Managed Services helps close the operational gaps around Sage: user provisioning, workstation management, helpdesk support, and the administrative work that often gets pushed aside when internal IT is stretched. Since many ransomware incidents begin on a workstation before moving toward core systems, protecting the environment around the ERP is part of protecting the ERP itself.
Together, the three layers make the 72-hour weekend window much harder for attackers to exploit. Coverage stays continuous through the whole summer, regardless of who happens to be in the office that week.
The cost of staying put
For a finance or IT leader running the numbers, the comparison comes down to one line in the budget. A predictable monthly invoice for hosted Sage with managed security and managed services goes on the books the same way a utility bill does. The alternative is staffing for around-the-clock monitoring, building a patch program that can keep pace with sub-24-hour exploits, hardening every endpoint that touches the ERP, and absorbing whatever the next incident costs when the in-house setup misses something.
Most mid-market companies that get hit hard didn’t pick the wrong vendor. They didn’t pick at all, and the threat picture moved while they were holding still. Summer is a fair time to stop holding still.
Before the next holiday weekend, schedule a 30-minute Sage environment review with Cloud at Work. You’ll see where the biggest risks sit today and what it would take to close them.