Three-quarters of disclosed ransomware incidents hit companies with $10 million to $1 billion in revenue, and the smaller the company, the less survivable the incident. The controls that close most of the gap cost attention, not budget.
In August, Black Kite published an analysis of 13,336 ransomware and data-extortion incidents disclosed in North America and Europe between January 2023 and June 2026, limited to victims whose revenue was known.1 Companies with annual revenue between $10 million and $1 billion accounted for 73 percent of them, a share that never moved outside a band of 72 to 75 percent in any period studied. That range is wide, so it is worth breaking down: the report splits it into three bands, and the concentration sits at the bottom. Companies in the $10 million to $50 million band alone made up 50 to 57 percent of mid-market victims every year, and in 2024, when victim counts fell in the two larger bands, attacks on that lowest band grew 18.8 percent.2
Manufacturing accounted for more than a quarter of mid-market victims, followed by professional, scientific, and technical services, then construction.2
The objection we hear in mid-market boardrooms is rarely we're a target. It is we don't have the budget for cybersecurity — and often there is no dedicated technology leadership to spend it anyway. That objection deserves an answer, not a dismissal: attackers do not select on size; they select on access, and a mid-market company can carry the attack surface of an enterprise on the security staffing of a small business. What the data changes is not whether the money exists. It changes what an unaddressed gap costs if this is the year it stays unaddressed. A larger business absorbs an incident with reserves, insurance, and a response team on retainer. For a $30 million company with thin margins and one overloaded operations leader, the same ten days of downtime can threaten the business itself — which is the argument for treating this as a near-term priority, not a line item to defer until there is room in next year's budget.
The part of the report that deserves the most attention is not the headline number. It is the observation that mid-market companies are suppliers and customers at the same time, and that those two roles are usually treated as separate problems, handled by separate teams, with separate budgets. In a company of 200 people, they are often handled by nobody.3
The scale of the gap is concrete. Black Kite describes a typical vendor-risk function as two people responsible for more than 300 suppliers, with some software and services sitting outside any formal inventory.1 A related Black Kite study found that once an attacker gains access to a vendor environment, handoff to a ransomware operator now takes a median of 22 seconds, down from eight hours in 2022.4 A point-in-time supplier questionnaire, answered once a year, cannot see a timeline measured in seconds.
The other direction matters just as much. If you supply a larger company, that company's security questionnaire is the audit you did not schedule. Answer it badly and you do not lose the account immediately; you lose it at the next renewal, quietly, to a competitor who answered it well.
Of the 60 ransomware operators active against the mid-market in 2023, only 17 remained active by the first half of 2026, and roughly one in three groups active in any six-month period had never been seen before.2 A security program built around named adversaries has a short shelf life.
What does not change is the short list of conditions that let them in. Nearly 30 percent of the mid-market organizations Black Kite scanned had at least one known exploited vulnerability exposed.3 More than 48,000 vulnerabilities were published in 2025; roughly 800 were ever exploited in the wild.2 The work is not patching everything. It is knowing which 800 matter and whether any of them are yours.
Email authentication tells the same story. DMARC was missing or insufficiently configured at 46.8 percent of the companies scanned, and DKIM at 24.2 percent.2 Neither requires a purchase. Both are configuration discipline, and both are what a customer's questionnaire checks first.
Consider a $40 million manufacturer. Ten days of disrupted shipping is roughly $1.1 million of revenue deferred or lost, before recovery cost, before the customers who found a second source, and before the insurance conversation. The cost of confirming that no known exploited vulnerability is reachable from the internet, that email authentication is enforced, and that the suppliers who can stop your line have been identified, is a few weeks of attention and very little money.
That ratio is the answer to the budget objection. The companies that treat a security program as the first line item to cut are the ones for which an incident is least survivable, and the controls that close most of the gap cost attention, not budget.
None of the above requires a new tool, a new vendor, or a new headcount. Most of it is deciding who owns it. We would resist any proposal that starts with a purchase and ends with a dashboard, because the organizations in this dataset were not defeated by sophisticated, novel attacks. They fell to a known vulnerability, a spoofable email domain, or a supplier nobody was watching.
The ten-minute Business Resiliency Scorecard benchmarks against NIST CSF 2.0 and will tell you which of these is your weakest area. If a question on it does not have a ready answer, that gap is the finding — and if the team cannot answer it internally, start a conversation and we will help you work through it.
The Business Resiliency Scorecard benchmarks your continuity readiness against NIST CSF 2.0 in ten minutes — free, no signup.
No SDR layer. We sell expertise, not products.