Cyber Risk in 2026: What Mid-Market Firms Still Get Wrong

Cyber Risk in 2026: What Mid-Market Firms Still Get Wrong
News 27th March, 2026

Attackers are not choosing targets by revenue. They are choosing them by friction. Mid-market organisations often present the most attractive combination available: enough value to be worth the effort, and rarely enough defence to make it hard.

1. Treating cyber as an IT budget line

Cyber exposure is a business risk with an IT component, not the other way round. The most expensive part of a serious incident is almost never the technical remediation — it is the lost trading days, the contractual penalties, and the management time consumed for months afterwards.

2. Buying a policy without reading the conditions

Cyber policies increasingly carry conditions precedent: multi-factor authentication on remote access, tested offline backups, timely patching of critical vulnerabilities. These are not suggestions. A claim can fail on a control the insured believed was in place and was not.

3. Untested backups

Almost every organisation we assess has backups. Far fewer have restored from them under time pressure. A backup you have never tested is a hypothesis, not a control.

4. Ignoring the supply chain

Your exposure now includes your payroll provider, your logistics platform, and the small agency with standing access to your content management system. Map who can reach your data, and make sure your contracts say what happens when one of them is breached.

5. No plan for the first six hours

Decisions made in the first six hours shape everything that follows. Who declares an incident? Who speaks to customers? Who authorises taking systems offline during peak trading? If those answers live in one person, you have a single point of failure.

Where to start

Pick the three controls that would most reduce your worst realistic scenario, fund them properly, and rehearse the response once. That is a better use of a year than a broad programme that is never finished.