Thursday, 1 October 2026

Where technology leaders come to think out loud

The BriefCybersecurity

Mid-market security teams are caught between SMB and enterprise tools

Intruder’s own survey of 502 UK and US security leaders finds confidence falling the closer respondents sit to the work, and cyber risk rarely reaching the board

The facts
  • Sample: 502 security decision-makers, 200 in the UK and 302 in the US, surveyed on 11–18 February 2026
  • Sectors covered: financial services, fintech, healthcare, manufacturing, professional services, retail and SaaS
  • Cyber risk discussed at board level: 9%; reaching executive leadership: 34%
  • Cyber risk kept within security or IT leadership: 51%; confined to the security team alone: 7%
What to do now

Run the zero-day drill before an advisory forces it: take a recent critical flaw and time how long it takes to list every exposed asset. If the answer runs to days, the problem is visibility, and another point product may make it worse. Ask the people who run the tools, not only the leadership team, how confident they are, and take that answer to the board.

“This is a structural problem, the majority of solutions available to midmarket security teams were never built for the position they’re now in.”Chris Wallis, CEO and founder, Intruder

Intruder, which sells an exposure management platform to lean security teams, published a survey of security decision-makers at UK and US companies with 400 to 6,000 employees on 12 March. Almost half (46%) said enterprise security platforms assume more staff, budget or complexity than they can support, while 29% said tools built for small businesses no longer meet their needs.

The research is Intruder’s own, carried out by Censuswide. Intruder calls these teams’ position the ‘security middle child problem’: overlooked by vendors focused on the largest companies or on small businesses. Some 44% said they had outgrown their security stack or stitched it together from point solutions without a unified view, yet a third (33%) plan to add new solutions in 2026.

Confidence depends on who answers. Some 65% of C-suite respondents said they were very confident in their ability to catch critical threats, against 35% of middle managers. And 51% said it would take about a week to assess exposure to a critical zero-day, while Intruder says that exploitation can follow disclosure within 24 to 48 hours.

Sources
  1. Intruder, “Intruder Releases the Security Middle Child Report, Revealing How the Cybersecurity Industry Is Leaving Midmarket Businesses Behind”, press release via Business Wire, 12 March 2026. https://finance.yahoo.com/news/intruder-releases-security-middle-child-110000557.html
  2. Intruder, The Security Middle Child report landing page (undated). https://www.intruder.io/downloads/security-middle-child-report
AdvertisementZoomInfo
More from The BriefAll briefs
PXC

PXC brings CityFibre’s Ethernet Flex to its SMB connectivity partners

ClearCourse

ClearCourse buys garage software firm Motasoft to add embedded payments

hedgehog lab

Malcolm Seagrave succeeds co-founder as chief executive of hedgehog lab

Google DeepMind

DeepMind CEO questions OpenAI’s fast move to ads in ChatGPT

Get the briefs every week in The VETTDD Briefing.