According to Kukk, the following scenario is very common. It’s a Friday evening, the office is empty, the weekend is ahead, and you finally feel like you can switch off from work. Then suddenly, a message arrives—not necessarily on your phone, but on a colleague’s. A business partner has sent updated payment details. The message is marked “urgent.” You start wondering: is this notification real? At first glance, everything seems logical—the tone is correct, the signature is right, even the previous conversation is there. Only one detail is different—the bank account number.
“This is exactly where the biggest vulnerability lies for small and medium-sized businesses. Attacks don’t come when everyone is at their desks, calmly analyzing the situation. You’ve probably noticed that phishing emails about ‘updating bank details’ often arrive during holidays. Attacks come when things are quiet—on Friday evenings, weekends, and during vacations. Not because it’s romantic, but because it’s effective. Two questions determine how big this story becomes: does someone notice the alert immediately, and does someone act immediately—or only on Monday?” says Kukk.
Often, such incidents begin in a very ordinary way: someone enters login credentials into what appears to be a legitimate page. Sometimes it’s a fake login page, sometimes a third-party integration, sometimes just one wrong click caused by fatigue. An attacker doesn’t need to break down a “thick door” if they can simply get the key from the user.
Once access is gained, the next steps are not taken loudly but quietly. Email forwarding rules are set up, alerts are hidden, communication is monitored. The attacker waits for the right moment—one that fits naturally into the company’s workflow—and then sends “updated payment details” or a “payment requiring urgent confirmation” to a partner or customer. Very often, it doesn’t look like a technical or business crisis—just a normal workday.
According to Kukk, this leads to the first important realization: “having tools” does not mean “having protection.” Many small and medium-sized companies rely on the Microsoft ecosystem as the backbone of their operations—identity, email, devices, cloud. Security features are often available as well. But a tool alone is like a smoke detector with a battery installed—if nobody is there to hear it, it doesn’t help. The tool may raise an alert.
“What happens next determines whether this is a real attack, how critical it is, and whether immediate action is taken to stop the threat. Do we lock the account, terminate sessions, remove malicious rules, restore access in a controlled way, and limit damage before money leaves the bank account?” Kukk explains.
If you want to understand as a leader whether such an incident is just an inconvenience or a serious financial hit, a simple exercise can help: assign a price tag to potential downtime—not to create fear, but to make decisions proportional to real risk.
Let’s start with a formula:
Downtime cost €/day ≈ (annual revenue ÷ 12 ÷ 22) + [critical employees × (gross salary × 1.35 ÷ 22)]
If the impact is customer-critical (sales/payments/deliveries halted), add a conservative buffer: ×1.5.
Based on this, consider a simple example. A company has annual revenue of €2 million. Think about how many employees are critical but unable to work during downtime. With an average gross salary of €2,500, the revenue loss component is €2,000,000 ÷ 12 ÷ 22 ≈ €7,576 per day. Salary costs are roughly: 6 × (€2,500 × 1.35 ÷ 22) ≈ €920 per day.
“Even this simple calculation shows that one day of downtime costs about €8,500, and if there is direct customer impact, it can conservatively rise to nearly €13,000 per day. This is why ‘let’s look at it on Monday’ is not a neutral decision—it has a very specific price tag,” Kukk emphasizes.
In public discussions, SOCs (Security Operations Centers) and 24/7 monitoring are increasingly highlighted—and rightly so. Many cybersecurity service descriptions stress the same principles: continuous monitoring, early detection, and immediate response. However, for small and medium-sized companies, the question is usually not whether someone is “watching a screen.” The question is whether you have the team, processes, and automation to quickly answer three key questions: is it real, what is the impact, and what do we do immediately?
The logic of MDR (Managed Detection and Response) is built precisely to go beyond simply “passing on alerts.” It combines 24/7 threat detection and rapid response with clear roles and escalation processes, ensuring incidents move from identification to containment, recovery, and lessons learned.
Instead of just “collecting logs,” the approach is methodical: mapping business-critical services, analyzing architecture and attack paths, and aligning detection with real risks in your environment. Based on KPMG’s experience, this helps avoid two common extremes: “silence” (no detection) or “noise” (too many false positives).
It’s also important that detection is not a one-off project. Managed cybersecurity treats detection like product development: rules, playbooks, and procedures evolve, expand, and become automated over time. Scalability matters too—covering hundreds of rules and leveraging automation ensures fast response even at inconvenient times. While the default focus is often the Microsoft ecosystem, the same operational capability can be applied to other XDR/SIEM solutions if needed.
Returning to that Friday evening scenario, the real question is not whether such incidents can happen—yes, they can. The real question is whether your organization has a clear, tested, and 24/7 operational capability to respond before the damage reaches your bank account, customers, or production. If you don’t have that capability today, the good news is that you don’t need to build it from scratch or place a 24/7 burden on your internal team.
Cybersecurity Strategic Advisor
Organizations can no longer view cyber risk as a separate issue; it is an integral part of the b..
Companies that rely on external service providers for data processing increasingly face a key que..
Over the past few years, the number of cyber incidents in Estonia has tripled, and this worrying..
In today’s cybersecurity landscape, most organizations are caught between two realities: they kn..
Over the past several years, our red team has conducted extensive offensive security assessments..
Provide a safe and sustainable business environment for your company. We help build a resilient and reliable digital landscape, even in the face of changing threats.
Analysis of employee awareness focuses on mapping the skills and increasing the competencies of the weakest link in cyber security: the users, the employees.
Threat assessment is a tactical and technical service that allows a company to get a quick overview of external threats.
Maturity assessment helps plan IT investments and design further steps to mitigate vulnerabilities and ensure better security.