Securitybrief Midmarket Firms Struggle with Cybersecurity Confidence and Tool Gaps
Article Content
- •94% of midmarket cybersecurity leaders express confidence in managing risks.
- •42% of teams report being overwhelmed and unable to keep up with cybersecurity demands.
- •46% find enterprise cybersecurity tools unsuitable for their needs.
A survey by Intruder reveals that midmarket cybersecurity leaders in the UK and US exhibit high confidence in managing critical risks, with 94% believing they can identify and remediate threats before exploitation. However, 42% of respondents report their teams are overwhelmed and unable to keep pace with demands. The survey, which included 502 security decision-makers from companies with 400 to 6,000 employees and at least $50 million in revenue, highlights a disconnect between confidence and operational capability. Many firms face a 'security middle child problem,' feeling overlooked by vendors who cater to either large enterprises or small businesses. Key challenges include inadequate technology, with 46% stating enterprise solutions are not suitable, and 29% indicating that tools for smaller firms no longer meet their needs. Speed of response is also a concern, as 51% estimate it would take about a week to assess exposure to critical vulnerabilities. Confidence levels vary significantly by seniority, with C-suite executives showing the highest assurance. Despite positive signals regarding budget and staffing growth, a significant gap remains between digital estate expansion and headcount increase.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…