Attackers are not choosing targets by revenue. They are choosing them by friction. Mid-market organisations often present the most attractive combination available: enough value to be worth the effort, and rarely enough defence to make it hard.
1. Treating cyber as an IT budget line
Cyber exposure is a business risk with an IT component, not the other way round. The most expensive part of a serious incident is almost never the technical remediation — it is the lost trading days, the contractual penalties, and the management time consumed for months afterwards.
2. Buying a policy without reading the conditions
Cyber policies increasingly carry conditions precedent: multi-factor authentication on remote access, tested offline backups, timely patching of critical vulnerabilities. These are not suggestions. A claim can fail on a control the insured believed was in place and was not.
3. Untested backups
Almost every organisation we assess has backups. Far fewer have restored from them under time pressure. A backup you have never tested is a hypothesis, not a control.
4. Ignoring the supply chain
Your exposure now includes your payroll provider, your logistics platform, and the small agency with standing access to your content management system. Map who can reach your data, and make sure your contracts say what happens when one of them is breached.
5. No plan for the first six hours
Decisions made in the first six hours shape everything that follows. Who declares an incident? Who speaks to customers? Who authorises taking systems offline during peak trading? If those answers live in one person, you have a single point of failure.
Where to start
Pick the three controls that would most reduce your worst realistic scenario, fund them properly, and rehearse the response once. That is a better use of a year than a broad programme that is never finished.