Small and Mid-Size Doesn't Mean Small and Mid-Risk
April 11, 2026 · 5 min read
The ransomware operator targeting a 50-person law firm does not offer a discount because the firm is small. The attack is the same. The impact, relative to the organization's ability to absorb it, is often worse.
I spend a significant portion of my time working with small and mid-size organizations, and the conversation I have most often starts the same way: "We're too small to be a target."
That statement has never been true. It is especially not true now. Automated attacks do not discriminate by organization size. Ransomware-as-a-service platforms target opportunity, not scale. And the data held by a 50-person accounting firm, a 200-person healthcare provider, or a 100-person manufacturer is often just as valuable — and just as regulated — as the data held by organizations ten times their size.
What is different is the capacity to respond. A large enterprise that experiences a ransomware incident has dedicated incident response teams, outside counsel on retainer, cyber insurance with meaningful limits, and the financial reserves to sustain operations during recovery. A small firm often has none of these things. The same event that is a major but survivable disruption for a large organization can be an existential threat for a smaller one.
The Asymmetry of Security Investment
The fundamental challenge of security for small and mid-size organizations is economic. The threats are the same as those facing large enterprises. The available budget and staff are a fraction. This creates an asymmetry that no amount of awareness or good intention resolves on its own.
A large organization can afford a SIEM, a 24/7 SOC, an endpoint detection platform, a vulnerability management program, and a team to operate all of it. A 50-person firm cannot. And the vendor market, which generates most of its revenue from enterprise customers, often offers solutions that are priced and architected for organizations that have dedicated security staff.
The security market has gotten better at serving small organizations, but the gap between what is available and what is implemented remains significant. The problem is rarely that solutions do not exist. It is that the guidance on which solutions matter most for a given organization's risk profile is missing.
What Actually Matters Most
When I work with small and mid-size organizations on security, the first conversation is about prioritization, because there will never be enough budget to do everything.
The controls that provide the most risk reduction per dollar for most small organizations are not exotic. Multi-factor authentication on everything that supports it. Regular, tested, offline backups. Endpoint detection and response — which has become affordable enough that cost is no longer a legitimate barrier. Email security that goes beyond basic spam filtering. And a relationship with a managed security provider who can serve as the security team the organization cannot afford to build internally.
That short list, implemented well, addresses the entry vectors responsible for the vast majority of incidents I respond to in organizations of this size. It does not eliminate risk. Nothing does. But it closes the doors that attackers walk through most frequently.
The Insurance Question
Cyber insurance deserves special mention for small and mid-size organizations because it serves a different strategic purpose than it does for large enterprises. For a large organization, cyber insurance is one layer of a multi-layered risk management strategy. For a small organization, it may be the difference between surviving an incident and closing the business.
The challenge is that the insurance market has tightened its requirements significantly. The same controls I just listed — MFA, EDR, backups, email security — are increasingly prerequisites for coverage, not nice-to-haves. Small organizations that cannot demonstrate these controls may find themselves unable to obtain coverage at reasonable premiums, or at all.
This creates a virtuous cycle for organizations that invest in basic security: better coverage, better premiums, and better resilience. And a vicious cycle for those that do not.
Where to Start
If you lead a small or mid-size organization and security has been on the "we'll get to it" list, here is where I would start.
Have an honest conversation with an IT provider or managed security provider about your current state. Not a sales pitch. A conversation. What do you have in place? What are the most significant gaps? What would it cost to close the three most critical ones?
Review your cyber insurance — or get it if you do not have it. The process of applying for coverage will force you to assess your current controls, and the underwriting requirements will tell you what the market considers baseline.
And accept that security is not a project with a completion date. It is an ongoing operational cost, like accounting or legal compliance. The organizations that treat it as a one-time expense are the ones that end up spending far more when something goes wrong.
Next Step
Ready to strengthen your organization's resilience?
A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.