If customers have to trust your systems and data practices, weak security is no longer somebody else’s technical problem.
Too many mid-sized companies still talk about cybersecurity as if it were a tax imposed by the IT department.
That mindset is getting expensive.
Black Kite’s 2026 Mid-Market Ransomware Report examined 13,336 publicly disclosed ransomware and extortion incidents across North America and Europe from January 2023 through June 2026 where victim revenue could be verified. Mid-market organizations with annual revenue between $10 million and $1 billion represented 73 percent of that qualifying dataset.
No, that does not mean 73 percent of mid-sized businesses were hacked. It means nearly three quarters of the disclosed victims in the analyzed set fell into the mid-market. The proportion was also stubbornly consistent, staying between 72.1 percent and 74.6 percent across the years examined.
That should end the lazy argument that attackers only care about giant corporations.
More importantly, it should end another lazy argument: that cybersecurity is only about preventing technical damage.
If your company stores customer information, connects to customer systems, processes payments, manages payroll, ships critical components or depends on digital services to deliver what it sells, security is already part of the product.
Your customer does not care which department failed
Imagine a larger company is evaluating two suppliers.
Both can deliver. Both are competitive on price. Both have decent references.
One can show that multifactor authentication is required, critical systems are patched, backups are tested, former employee accounts are removed and an incident-response plan exists.
The other says, “Our IT guy handles that.”
Which one looks easier to trust?
There is no credible public statistic that tells us exactly how many deals are lost because a supplier gives weak cybersecurity answers. We should not invent one. But procurement guidance from both Canada and the United States makes the direction obvious.
The Canadian Centre for Cyber Security tells small and medium-sized organizations to evaluate suppliers, classify them by criticality, set minimum security requirements and include cybersecurity obligations in contracts. It gives buyers concrete questions to ask about data protection, vulnerabilities, recovery and incident notification.
CISA publishes a vendor-assessment resource for American small and medium-sized businesses covering security policies, access controls, training, incident detection and recovery.
That means your customers are being told to ask harder questions about you.
“We take security seriously” is not evidence
Every company says it takes security seriously. So does every company that gets breached.
The useful question is what you can prove.
Can you show that MFA is active for email, remote access and administrative accounts? Can you demonstrate that internet-facing systems are patched on a defined schedule? Do you know which vendors have privileged access? Have you tested a backup recently? Is there a written plan for a ransomware incident?
This is not enterprise theater. It is operational competence.
Black Kite’s separate external scan of 120,128 mid-market organizations in June 2026 illustrates the problem. The company found significant patch-management issues affecting public-facing software at 54.7 percent of the assessed organizations. It found high or critical vulnerabilities at 48.1 percent, known exploited vulnerabilities at 28.3 percent and credentials appearing in information-stealer logs at 32.3 percent.
Those numbers are from a separate dataset and do not prove what caused the ransomware incidents. They do show how much weakness can be visible from outside.
Attackers notice. So can security-conscious customers.
Cybersecurity debt eventually lands on the commercial side
Businesses are comfortable talking about technical debt. Cybersecurity debt is often treated differently because the cost can stay hidden for years.
An old server keeps running. A former employee account is never disabled. A remote-access tool remains exposed. A backup job reports success every night, but nobody has tested a full restore. A vendor retains more access than it needs.
Nothing bad happens, so management concludes the risk was overstated.
That is the trap.
The absence of an incident is not evidence that the controls are good. It may simply mean nobody has exploited the gap yet.
When a ransomware event finally happens, the bill does not stay inside IT. Sales stops when systems are unavailable. Customer service slows down. Orders cannot be processed. Finance may struggle to invoice or pay staff. Operations may lose access to schedules, inventory or production systems.
If data was stolen, the problem gets worse.
Canada’s national cyber authority explicitly recognizes that modern ransomware can involve data theft and extortion, even without encryption. That means a clean restore does not end the crisis. The company still has to understand what left the network, which accounts were compromised and who must be notified.
Backups are necessary, but they are not a business plan
Executives love the sentence, “We have backups.”
Good. Have you restored from them lately?
CISA recommends offline, encrypted backups and regular restoration testing because ransomware variants often try to delete or encrypt accessible backups. It also recommends a documented incident-response plan and communications plan.
Those are management responsibilities.
If your accounting platform is down for three days, who decides what gets restored first? If customer records were stolen, who calls key accounts? If your managed service provider is the source of the problem, what is the backup plan for the backup plan?
A ransomware response that begins with executives asking where the incident plan is stored is already late.
Your vendors can embarrass you too
There is another uncomfortable truth: your company can do everything right internally and still inherit risk from a supplier.
Payroll, cloud storage, managed IT, customer-management software, payment systems and logistics platforms can all become part of your attack surface.
The Canadian Cyber Centre recommends classifying vendors by criticality because not every supplier deserves the same level of scrutiny. That is common sense. A company delivering office furniture is not the same risk as a provider with administrative access to your network.
The mistake is assuming a professional-looking vendor is a secure vendor.
Ask what data they handle. Ask who can access it. Ask how they patch systems. Ask how they notify customers after a breach. Ask what happens if their service becomes unavailable.
If you are uncomfortable asking those questions, imagine how your customer feels asking them about you.
Security can be a sales asset, but only if it is real
There is a positive side to all of this.
A company with disciplined cyber controls can turn security into evidence of reliability.
Not marketing slogans. Evidence.
Documented policies. MFA coverage. Training records. Tested backups. Vendor reviews. Incident exercises. Clear ownership. Proof that obvious exposures are found and fixed.
That makes the company easier to evaluate. It can reduce the number of awkward answers during procurement. It can give sales teams something concrete when a customer asks how data and operations are protected.
Again, nobody should promise that cybersecurity will win every deal. It will not. But if security expectations are becoming a standard part of supplier evaluation, being prepared is better than being surprised.
Stop calling it an IT problem
The 73 percent figure is not a reason to panic. It is a reason to stop pretending the mid-market sits outside the real ransomware target zone.
The data says otherwise. Government guidance says all organizations should build resilience. Procurement guidance says businesses should scrutinize suppliers.
Put those pieces together and the conclusion is simple.
Cybersecurity neglect is no longer just a technical weakness. It can become an operational weakness, a trust weakness and a sales weakness.
If your company expects customers to trust it with money, data, access or continuity, then proving basic cyber discipline is part of earning that trust.
That is not IT’s job alone. It is management’s job.
