6 minutes
Last summer, I was still inside with my laptop open, while my wife and the kids were already waiting in the car. I just had to quickly set up my out-of-office email, and then the vacation could begin. In just a few seconds, I typed in when I’d be back, who would be covering for me, and where people could go in case of an emergency. Sent. Bag in the trunk, door shut, and off we went.
What I didn’t realize at the time was that, in those few hastily written sentences, I had almost sent out a complete organizational chart. Not for my clients. For anyone reading along with ulterior motives.
This happens to almost every small and medium-sized business. An out-of-office email feels like a formality—something you do between packing your bags and double-checking the back door three times. Yet it’s one of the few messages that’s sent automatically and without a second thought to everyone who emails, including people who aren’t even customers.
Do we actually talk more at work than at home?
Most people are cautious on social media. No one posts that their house has been empty for three weeks or that the bedroom window doesn’t close properly. Yet, in a business context, those same people often automatically send a similar message to everyone who emails them.
An average out-of-office email contains three types of information that an attacker needs: how long someone will be away, who their replacement is, and which department or person handles payments or approvals. That’s not just noise. For someone trying to map out an organization, it’s a ready-made roadmap.
I saw just how close this comes to reality at a client’s office. While an employee was on vacation, the financial department received an “urgent” invoice, reportedly approved by the absent colleague. The sender knew exactly who was away, who the substitute was, and that no one else had approval authority that week. All the details came directly from the out-of-office email. Only because someone took the time to call back the familiar number was the payment prevented.
What are the risks of submitting an overly detailed absence report?
Situations like these are no longer isolated incidents; they’re a pattern. According to the National Cyber Security Center, 79 percent of small and medium-sized businesses face an attempted Business Email Compromise every week—a form of fraud that includes CEO fraud and invoice fraud. The average loss per successful attack is around 118,000 euros (source: ncsc.nl).
Even aside from money, there’s something else at play. Attackers are increasingly combining multiple small details into a credible story: an out-of-office email, a LinkedIn profile, a name in an email signature. According to the Fraud Help Desk, more than 1,100 reports of sales fraud were filed by business owners in 2025 (source: atradius.nl). Some of these scams start with simple, publicly available information.
So the problem isn’t that you’re absent. The problem is how much context you automatically provide along with that.
What does work if you still want to communicate your availability?
An out-of-office message doesn’t have to be an organizational chart. A short, general message often does the job just as well, without the extra information:
- Indicate that you are temporarily unavailable, without specifying exact dates.
- Refer to a general email address or phone number instead of a specific colleague by name and title.
- Omit details about invoices, approvals, or payments, even if the intention is to make things easier for customers.
- Establish a clear internal distinction between what can and cannot be disclosed externally.
That sounds simple, and it is. The biggest risk isn’t in complicated technology, but in a habit that no one has ever questioned.
Isn’t a brief “out of office” message unfriendly to customers?
My clients probably want to know when I’ll be back, right?
That’s right, but it doesn’t have to be down to the day. “I’m currently away and will respond when I return,” a customer says—just enough to encourage patience, without giving an exact timeline to someone who might have other intentions.
My replacement should still be available to customers, right?
Sure, but that can be done using a central address or a team name instead of an individual’s name and title. That works just as well for customers, and doesn’t give an attacker any names to work with.
We’re a small business—who would even target us?
Smaller organizations are particularly attractive targets. Short lines of communication and informal arrangements make it easier for an attacker to pose as a trusted individual, and the likelihood that someone will double-check an unusual request internally is lower than at large companies with established processes.
How do you set up a secure out-of-office message in just a few steps?
- Limit the content to what is necessary: absent, no specific end date, general point of contact.
- Avoid mentioning the names, job titles, and departments of specific substitutes whenever possible.
- Agree in advance on a verification process for urgent payments, regardless of who requests them.
- Always verify urgent requests by phone, using a number you already know—never a number provided in the message itself.
- Have a second person approve payments or changes before you make them.
- Discuss these kinds of scenarios briefly with the team before summer, not only after an incident has occurred.
Why do these kinds of risks often go unnoticed in small and medium-sized businesses?
What I’m seeing more and more often is that small and medium-sized businesses do invest in technology such as spam filters and backups, but rarely give much thought to practices like out-of-office messages or public email addresses that include their full job title. Not because it isn’t important, but because no one has ever explicitly looked into it.
At New Yard, we work alongside you as a strategic partner for small and medium-sized businesses in the digital workplace. No lengthy reports or complicated assessments—just a clear discussion about where the vulnerabilities lie in your organization and which steps will actually make a difference.
Would you like to know how vulnerable your organization is this summer?
Setting up a well-configured out-of-office email takes five minutes. A successful invoice fraud costs an average of 100,000, and often even more in terms of trust and the time it takes to rectify the situation. That difference is worth taking a critical look at—preferably before summer starts, not after.
Would you like to work with us to identify where your organization is vulnerable this summer? Schedule a no-obligation introductory meeting with New Yard, and we’ll help you figure it out.
