Full Report
A survey of mid-sized businesses revealed common cybersecurity vulnerabilities. Learn what they are and how to improve your security posture in 2023.
Analysis Summary
# Industry News: Mid-Market Security Gaps Exposed in 2023 Survey
## Summary
A 2023 study by Virtual Intelligence Briefing (VIB) reveals that mid-sized businesses (SMBs) are struggling with a significant "readiness gap" despite increasing threat levels. The survey highlights that nearly a quarter of these organizations suffered attacks in the past year, yet many remain dangerously under-resourced in both personnel and incident response planning.
## Key Details
- **Date:** Published March 28, 2023
- **Companies Involved:** Huntress (Primary), Virtual Intelligence Briefing (Research Partner)
- **Category:** Market Analysis / Industry Report
## The Story
The report surveys over 250 mid-sized businesses across the US and Canada to assess the health of the mid-market security landscape. The data paints a picture of a "Wild West" environment where businesses are armed with tools but lack the expertise to use them effectively. Key findings indicate that while 24% of respondents were hit by cyberattacks in the last year, a startling 61% operate without dedicated cybersecurity experts, and 47% lack a formalized incident response plan.
The research further emphasizes the failure of the "human firewall." While 59% of businesses conduct formal security awareness training, employee adherence remains low. Conversely, 40% of mid-market firms conduct no formal training at all, leaving them highly vulnerable to social engineering and identity-based threats.
## Business Impact
### For the Companies Involved (Huntress)
- **Direct Implications:** Huntress positions itself as the primary solution for the "99%"—mid-market firms that cannot afford internal SOCs. This report validates their business model of providing Managed Detection and Response (MDR) and security awareness tools.
### For Competitors
- **Competitive Landscape Impact:** Managed Service Providers (MSPs) and MDR providers are seeing a surge in demand as mid-market firms realize they cannot manage security in-house. Competitors will likely pivot their marketing to emphasize "ease of use" and "automated response" to appeal to understaffed teams.
### For Customers
- **Impact on End Users:** Mid-sized businesses face increasing pressure to adopt multi-layered security. The lack of incident response planning means that when a breach occurs, the operational and financial recovery time for these customers will be significantly longer.
### For the Market
- **Broader Market Implications:** There is a clear shift from "tool acquisition" to "operational execution." The market is moving away from just selling software (AV/EDR) toward selling outcomes (MDR/Managed Services) because the mid-market lacks the talent to run the software they buy.
## Technical Implications
The report highlights that even with "an arsenal of security tools" like email security and endpoint protection, technical debt and misconfigurations remain. The shift from traditional antivirus to identity-centric security (SSO/MFA) and NIST-aligned frameworks is becoming the technical standard for 2023.
## Strategic Analysis
- **Market Positioning:** Huntress is positioning itself as an essential partner for the resource-constrained mid-market by focusing on the gap between "having tools" and "having talent."
- **Strategic Benefits:** By highlighting the 47% lack of incident response plans, Huntress creates a strategic entry point for their managed services and consulting.
- **Challenges:** The primary obstacle is "security fatigue" and low employee adherence. Technology alone cannot solve the human element, which remains the weakest link in the SMB sector.
## Industry Reactions
- **Analyst Opinions:** Analysts suggest that mid-market firms are increasingly being targeted as "low-hanging fruit" compared to hardened enterprises.
- **Expert Commentary:** Cybersecurity experts emphasize that a "tools-only" approach is failing; the focus must shift to human-centric security and rapid response capabilities.
## Future Outlook
- **Predictions:** Expect a consolidation of security stacks in the mid-market as companies trade multiple disparate tools for integrated platforms that offer managed oversight.
- **What to Watch For:** Watch for increased regulatory pressure or insurance requirements that will eventually force the 47% of businesses without incident response plans to formalize their procedures.
## For Security Professionals
Practitioners should focus on **simplification and automation**. If your organization falls into the 61% without dedicated experts, prioritizing a "Managed" approach (MDR) and automating security awareness training is critical to reducing the daily burden on general IT staff. Documenting an Incident Response Plan should be the immediate priority for any professional in a firm currently lacking one.