The academic platform going down during final exams is a clear example of something usually missing from security planning: not every hour offline costs the same.
Every system has seasonality, and it's rarely written down anywhere. Retail has peak dates, manufacturing has production close-outs, accounting has tax deadlines, education has exam weeks. Outside those windows, the same interruption is inconvenient; inside them, it's a crisis.
Attackers know that calendar, because it's public. Tax filing deadlines, enrolment dates and reporting periods are no secret, and choosing the window increases pressure without requiring additional technical effort.
The practical consequence for defenders is about scheduling before tooling. Maintenance, recovery testing and access reviews have to happen off-peak, and the ability to operate in degraded mode has to be ready before the window opens.
It's the kind of preparation that shows up in no metric while nothing happens, and that decides the size of the damage when it does.
