Small and mid-sized organisations
You have an IT team. You do not have a CISO.
Somewhere between twenty people and a few hundred, security stops being a technical question and becomes a leadership one. The tools are bought, somebody in IT is doing their best, and nobody owns the programme. That is a different problem from the one an enterprise has, and it needs a different answer.
45%
of surveyed organisations had a cybersecurity incident in the last 12 months.
75%
said they were confident in their resilience to an attack — 26% very, 49% slightly.
25%
said cybersecurity is part of an IT specialist’s broader role, rather than anyone’s actual job.
ESET SMB Cyber Readiness Index 2026 — 4,400 organisations with 25–1,000 endpoints across 13 countries, fielded by Go4insight.
Confidence is not evidence
The report those figures come from draws its own conclusion: many respondents misperceive their security posture, shaped by headlines about AI-driven attacks while the routine risks go underestimated. Its three most-cited causes of actual incidents were phishing at 26%, unpatched vulnerabilities at 23% and lack of security monitoring at 22% — none of them exotic, and all three the kind of thing that goes unattended when security is somebody’s second job.
Twenty people and two hundred are different companies
The same survey found its smallest organisations — those with 25 to 99 endpoints — reported fewer incidents than those at 500 to 1,000, and outsourced security more often. Growing across that range is what turns an IT problem into a governance one: more systems, more suppliers, more people who can click something, and the same one or two people carrying all of it.
A separate and independent measurement points the same way. Munster Technological University, working with Ireland’s National Cyber Security Centre, scored 894 Irish organisations against a framework based on NIST CSF 2.0. It found 81% of firms with fewer than ten employees in the bottom two resilience categories — against 45% of those with 50 to 249. Being bigger helps. It does not get you out of the bottom half.
71%
of surveyed organisations carry cyber insurance.
37%
of all surveyed organisations carry it with specific security control requirements attached by the insurer.
55%
is that share among organisations that had more than one incident.
ESET SMB Cyber Readiness Index 2026 (n=4,400).
It is not only the money
Asked what currently stops them improving, respondents put budget first, at 24% — and yet 80% of the same people called their cybersecurity budget sufficient or more than sufficient. What comes after budget on that list is the more useful part.
- 01
Complexity and integration — 21%
Tools bought separately, which do not talk to each other and each need somebody to watch them. The more you buy, the more this costs in attention rather than in money.
- 02
Talent and skills — 20%
Not a shortage of people who can run IT. A shortage of people who can decide what good looks like in your industry, against the framework your largest customer is about to ask you about.
- 03
Competing priorities — 14%
Security loses to the thing with a delivery date, and it has no delivery date of its own — until a regulator, an insurer or a customer hands it one.
- 04
No clear strategy or roadmap — 10%
Joint-smallest on the list, and the one that explains the others. Without a sequence, every finding is equally urgent, which means none of them gets done.
- 05
Leadership buy-in — 10%
The other joint-smallest, and worth saying plainly on a page like this one: in this data the obstacle is rarely a management that refuses.
- 06
Responsibility nobody wrote down
A review of the research literature puts it plainly: smaller organisations trust their IT service provider to take care of cybersecurity “without the necessary contractual arrangements in place or clear definition of the responsibilities”. Everyone assumes somebody else has it. (Chidukwani, Zander and Koutsakis, IEEE Access, 2022.)
The order is not a matter of taste
That same review found a consensus among experts on sequence: governance, risk management, asset management, vulnerability management and business continuity first — then detection and continuous monitoring on top of them. It is the order we work in, and the reason we will not sell you monitoring for an estate nobody has inventoried yet.
- 01
Know what you have, and who owns it
An inventory of systems, data and suppliers; a named owner for security; and a risk picture that reflects your business rather than a generic list of threats.
- 02
Fix what the risk picture says, in its order
Policies written and controls built against the priorities you just set, each with a date and an owner — and somebody chasing them who does not also have a day job.
- 03
Then watch it
Monitoring, detection and a response plan that has been tested. Worth paying for once there is a known estate to watch and somebody who will act on what it finds.
The problem, and the thing that answers it
Most organisations this size need two or three of these, in an order that depends on what is already true and on who is asking.
Nobody owns security
The decisions made, the roadmap set and the reporting produced — without creating a full-time executive post. A team rather than one person, on a twelve-month minimum term.
There is a date
NIS2, ISO 27001, or a customer’s audit. A risk-based programme that goes from unclear scope to a mock-audited GO or NO-GO, built for organisations with 180 days rather than a year.
Phishing is still how it starts
The most-cited cause of incidents in the survey above — and not for want of training: 87% of those organisations called training critical or very important, and two thirds train more often than once a year. Frequency is not the gap. Training written for people who are busy rather than careless is.
The controls are specified, nobody can build them
For when complexity and integration are the barrier: multi-factor authentication, logging, backup and hardening actually deployed and handed over, rather than added to a list.
No one is watching
Lack of monitoring is the third most-cited cause, and 59% of investigations take two weeks or more. Detection and response run by an analyst team, instead of an alert nobody reads.
An investor or a buyer is coming
The IT and security chapter of a transaction, from either side of it — diligence, carve-out and the first hundred days after signing.
About these figures
Two measurements, both named, both with limits worth knowing before you weigh them.
The ESET SMB Cyber Readiness Index 2026 is research published by a security vendor, though it was fielded by an independent agency and its method is disclosed in full. We use it because its smallest band starts at 25 endpoints, which is about where our smallest client sits. What it does not give us is the bottom of that range: by headcount its sample leans large, with 39% of respondents at 500 to 1,000 employees and 16% above 1,000. A forty-person reader sits at the thin end of it, and these figures describe the range rather than its floor.
The Munster Technological University and NCSC study is publicly funded and has no vendor behind it, but its sample was self-selected: 894 Irish organisations that went looking for a free security assessment, 88% of them with fewer than ten employees. That is not this page’s reader, so we cite it only for its comparison between size bands — the part its sample can carry.
Frequently asked questions
The questions we hear most often from security and IT leaders.
Something not covered here? Ask us directly
It might. The survey cannot tell you, and it is honest about why: its answer option is not “no” but “not that I know of”, chosen by 54% of respondents overall and 60% of those with 25 to 99 endpoints. Everything around that answer points one way without proving it — lack of security monitoring is the third most-cited cause of the incidents that were noticed, and the report’s own conclusion is that many respondents misperceive their posture. A clean record and no monitoring look identical from the inside. Finding out which one you have is what an assessment is for, and it is the cheapest thing on this page.
Possibly both, about different questions. Your provider can answer for the controls they operate. They cannot answer for whether the programme is complete, evidenced and defensible to an auditor or an insurer — that was never their job, and it is usually not in their contract. Worth knowing that 16% of surveyed organisations named underperforming IT service providers among the causes of their own incident. In our engagements the provider is not something we replace or grade: they keep the technical work, and their part of the controls gets evidenced through their contracts and their own reporting, which is a different thing from their reassurance.
Twenty and up is who we work with, and under ten is not. Two things you are entitled to know. Forty people sits at the bottom of both studies on this page rather than in the middle of them — only 16% of the ESET sample has fewer than 100 employees — so those figures describe the range you are in, not its floor. And at forty people the engagement is a real version of the service rather than a reduced one: the same team, the same platform, the same twelve-month minimum. What scales with you is the scope, which is also what sets the fee.
You are right that whoever you ask will recommend what they sell, and we are not exempt from that. Two things push back on it. First, the order is not ours to choose: governance, knowing what you have, and a risk picture come before monitoring and detection — which is why we will not sell you monitoring for an estate nobody has inventoried. Second, you can find out cheaply before committing to anything: the assessment on this site is free and self-service, and a paid one-off assessment produces a prioritised picture that is yours to take to anyone. Proposing the ranking is our job; approving it is yours.
Then possibly not now, and we would rather say that than manufacture a reason. We have no defensible loss figure for a company of your size in these markets, and we are not going to invent one. What the data does show is that the requirement usually arrives after the event rather than before it: 37% of surveyed organisations carry cyber insurance with specific security control requirements attached, rising to 55% among those that had more than one incident.
The second route is the one we now see most often. Obligations that do not reach you directly reach your customers, and both NIS2 and DORA require them to identify their critical ICT suppliers and satisfy themselves about their security. As those programmes move from paper into operation the questions travel outward — a firm writing software for a bank, or maintaining plant for an energy utility, lands in somebody’s supplier register without ever being in scope itself. It arrives as a questionnaire with a return date on it, from a customer you cannot afford to answer badly, and the work behind a good answer takes months rather than weeks.
We don’t just provide tools; we provide integrated advisory and technical leadership. By combining our ISO/IEC 27001 certified expertise with an AI-powered Virtual CISO platform, we bridge the gap between complex IT security and business strategy. Our goal is to drive cyber risk down to zero while ensuring your business remains agile and compliant.
Start with where you actually are
A short conversation is usually enough to tell which two or three of these you need first. If you would rather see something before you speak to anyone, the security assessment takes a few minutes and gives you a posture you can argue with.