Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

株式会社ヤグラ

Select Language

Choose your language

Insight

Why Night and Weekend Security Operations Fail: The Pitfalls of 'Outsourcing Peace of Mind'

Over half of ransomware attacks occur during weekends and holidays. In an era of labor shortages, here is why relying on human staff for night shifts structurally weakens security.

AI SOCとは? 仕組み・従来型SOCとの違い

June 8, 2024, 3:30 AM. A system failure occurred across multiple services, including Niconico Douga, at a KADOKAWA Group data center. It was not until around 8:00 AM that this failure was identified as a ransomware attack. Several hours elapsed from the first signs in the middle of the night to the organization recognizing the event as an "attack."

This "several hours" gap is not unique to KADOKAWA. Many Japanese companies face the same vulnerability during late-night hours and holidays. This article explores why this gap occurs and why outsourcing to an MSSP alone cannot bridge it, based on industry data.

Is "24/7 Peace of Mind with an MSSP" a Myth?

For companies requiring 24/7/365 monitoring, running in-house night shifts is impractical. Maintaining a 3-shift SOC requires at least 10 dedicated security professionals, making hiring and retention extremely difficult. Consequently, outsourcing night and holiday monitoring to Managed Security Service Providers (MSSPs) has become the industry standard.

However, there is an often-overlooked premise: MSSPs recruit from the exact same talent pool.

According to the (ISC)2 Cybersecurity Workforce Study 2024, the global cybersecurity workforce gap has reached 4.8 million, a 19% increase year-over-year, while the talent pool itself grew by only 0.1%. In Japan, reports from IPA and the Ministry of Economy, Trade and Industry estimate a shortage of approximately 110,000 security professionals. Switching providers does not solve this structural talent shortage.

What is the result? According to the Semperis 2025 Ransomware Holiday Risk Report, 78% of organizations globally reduce their SOC staffing by 50% or more during nights, weekends, and holidays, and 6% leave off-hours completely unstaffed. Behind the promise of "24/7 monitoring," the reality is that nighttime initial triage is handled by significantly reduced teams compared to daytime hours.

Attackers Exploit Vulnerable Hours

Threat actors target this asymmetry with precision.

The same Semperis study shows that 52% of actual ransomware attacks occur on weekends and holidays. Cybereason's research also reveals that in over 70% of incidents handled in 2024, encryption began between 6:00 PM and 8:00 AM the following morning, with 30% starting on weekends. The execution of attacks directly aligns with the period when defense teams are at their thinnest. This is hardly a coincidence.

Furthermore, attacks do not give you time to react after they happen. According to Mandiant's M-Trends 2025, the median dwell time from intrusion to detection is 11 days, and 45.1% of intrusions are detected within a week. This means attackers move to achieve their objectives within days of entry. While some cases, like the ASKUL incident in 2025, involve a dwell time of about four and a half months, the final encryption and data exfiltration phases are executed rapidly within a few hours in the middle of the night. IBM research shows that identifying and containing a breach takes an average of 241 days; any delay in initial response impacts all subsequent recovery phases.

For a 3:00 AM alert, relying on a workflow where "the person in charge checks it after arriving at the office the next morning" effectively grants attackers hours of unrestricted access.

The Issue is Human-Dependent Workflow Design, Not the MSSP

This does not mean MSSPs are underperforming. MSSP analysts face massive volumes of alerts with limited resources, and the value of their expertise remains critical.

The core problem lies elsewhere: the contradiction of **relying on human-dependent initial response workflows during hours when human resources are most scarce**.

Typically, nighttime alert response flows as follows: monitoring tool detects threat -> MSSP analyst performs initial triage -> if deemed critical, escalates to the customer via phone or email -> customer contact wakes up, assesses the situation, and makes a decision -> actual containment/deactivation is executed. Every step relies on human availability. If one link in the chain is weak, the entire response slows down. Nights and holidays are when all these links weaken simultaneously.

"Doesn't It Ultimately Require Human Action in the Middle of the Night?"

A natural question arises: "Even with AI, isn't it the same if it just raises an alert? If humans don't respond at night, it's meaningless." This is correct. Tools that only improve detection and notification cannot close this gap.

The key is **whether you can complete initial investigation, triage, and containment without relying on human availability**.

Yagura's AI SOC deploys AI agents directly on your proprietary SIEM and data lake infrastructure. When an alert is triggered, the AI agent conducts a cross-sectional investigation of related logs, assesses the scope and severity, and—if necessary—executes initial containment across APIs (such as disabling suspicious accounts or blocking traffic) within seconds or minutes. For a 3:30 AM alert, the hours before a human can respond are transformed from a "defenseless gap" into a "safely contained state awaiting human decision." This is what differentiates it from AI that only performs triage.

This is not about replacing night-shift MSSP staff with AI. It is a fundamental shift from a workflow designed around human limitations to one built on AI-driven automation.

Where to Leverage AI vs. Where to Keep Humans

We must also avoid exaggeration. AI does not mean 100% automated safety at night.

Risk of false positives in AI triage remains. For high-severity incidents or decisions with business impact—such as shutting down core services—human escalation paths and on-call rotations are still required. AI handles initial investigation, triage, and immediate containment; final decisions and complex incident orchestration remain human responsibilities.

This is a rational division of labor. AI guarantees rapid response at night, freeing human analysts from alert fatigue so they can focus on high-value analysis, decisions, and security posture improvement during the day. Given the structural talent shortage, the central design question is how to allocate your limited experts.

Summary: Shift from "Who to Outsource To" to "How to Structure Response"

The failure of night and holiday SOC operations is not due to a lack of effort by providers, but a structural issue of maintaining human-dependent workflows during a talent shortage. Data showing that over half of attacks occur on weekends and holidays, and over 70% of encryption starts at night, suggests that attackers actively exploit temporal gaps in defense.

When reviewing your organization's security posture, we recommend starting with these questions rather than just asking if you have a 24/7 monitoring contract:

  • When an alert triggers at 3:00 AM, **how many minutes does it take to execute initial containment**?

  • How many steps in that workflow rely on waiting for someone to wake up?

  • If initial response is automated, can night-time on-calls be restricted to exceptions only?

True 24/7/365 security is achieved not by hiring more people or changing providers, but by building a response structure that does not depend on the time of day. Yagura helps you transition to this structure using our SIEM, data lake, and AI agents.

Related Service: Learn more about Yagura AI SOC, delivering 24/7/365 alert monitoring, investigation, and response powered by AI agents.

References

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化や

サービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。

ヤグラAIセキュリティ

丸わかり資料を

無料でダウンロード

生成AI時代に求められるサイバー環境の変化やサービスの概要資料についてお送りいたします。