rsmus.com Middle Market Cybersecurity Risks Heightened by AI Adoption
Article Content
- •18% of U.S. middle-market executives reported a data breach in the last year.
- •Only 35% of executives have formal AI governance frameworks in place.
- •24% of middle-market companies experienced a ransomware attack in the past year.
A recent survey revealed that 18% of U.S. middle-market executives reported experiencing a data breach in the past year, with midsize companies facing the highest rates at 21%. The rapid adoption of AI technologies is outpacing the development of corresponding cybersecurity measures, with only 35% of executives implementing formal AI governance frameworks. Despite a high level of confidence in their security measures (96%), significant gaps exist in incident response preparedness and core security controls. Ransomware remains a critical threat, with 24% of companies reporting at least one ransomware attack in the last year. The survey, conducted by RSM US and The Harris Poll, included responses from over 500 U.S. executives and 101 Canadian executives, highlighting the growing cybersecurity challenges in the middle market. The findings indicate a concerning disconnect between perceived security and actual preparedness against emerging threats, particularly those related to AI.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Red Heron Exploits Gitea RCE Flaw in Multinational Campaign A Chinese-speaking threat actor, tracked as Red Heron, exploited the CVE-2026-60004 remote code execution vulnerability in Gitea, compromising 1,386 instances across seven countries. The campaign involved source-code theft, credential collection, and lateral movement, affecting organizations in Canada, Argentina…