Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

92459

Ransomware Is Targeting the Mid-Market: Risk Is Not Limited to Large Enterprises

What the Report Shows

Black Kite published an analysis indicating that mid-market companies are a primary ransomware target across North America and Europe.

The report examines 13,336 ransomware incidents with verifiable revenue data from January 2023 to June 2026. According to the analysis, 73% of those incidents affected companies with annual revenue between $10 million and $1 billion.

Manufacturing was the most targeted sector in this group, representing more than a quarter of mid-market ransomware victims. This is an important signal for manufacturers, suppliers, logistics operators and organizations that are part of larger supply chains.

Why the Mid-Market Is Under Pressure

Mid-market companies often hold enough value to attract attackers, but they do not always have the scale, budget or internal capacity of large enterprises.

They run real business processes, customer data, production systems, suppliers, financial flows and partner integrations. At the same time, their security teams are often limited, and their IT environments combine legacy systems, external providers, cloud services and public-facing applications.

This creates a practical risk: attackers are not only looking for the largest organization. They are looking for an organization where access, weak patch discipline, exposed credentials or a third party can create a workable path.

Visible Signals Before an Attack

Black Kite highlights several externally visible weaknesses across mid-market organizations:

  • 28.3% had at least one Known Exploited Vulnerability (KEV);
  • 54.7% had at least one significant patch management finding on public-facing software;
  • 48.1% had at least one vulnerability with a CVSS score of 8.0 or higher;
  • 32.3% had at least one stealer log finding linked to compromised credentials;
  • 46.8% had missing or insufficient DMARC protection.

These indicators do not mean a company will automatically be attacked. But they show how an organization looks from the outside — through the eyes of an attacker searching for an accessible entry point.

Why Manufacturing Matters

Manufacturing companies are sensitive to disruption. A ransomware incident can affect not only office systems, but orders, planning, logistics, warehouses, production lines, suppliers and customers.

In manufacturing, risk often comes from several directions at once:

  • public-facing systems and portals;
  • older applications that are difficult to update;
  • IT/OT integrations;
  • external providers and service partners;
  • engineering and production data;
  • short recovery windows because downtime has direct cost.

This explains why ransomware groups view the sector not only as a technical target, but as a business environment where pressure to recover is high.

The Operational Question

The issue for the mid-market is not lack of intent to protect. Often, the constraint is capacity.

Teams need to monitor vulnerabilities, accounts, email protection, vendors, cloud services, endpoint signals and backup readiness. When these activities are managed separately, prioritization becomes difficult.

This is why vulnerability management cannot be only a CVE list. It needs to show which systems are exposed, which vulnerabilities are already being exploited, which accounts are compromised and which business processes depend on the affected system.

What Organizations Should Check

Practical checks for mid-market and manufacturing companies:

  • which public-facing systems have known exploited vulnerabilities;
  • whether critical vulnerabilities remain unpatched after incidents or audits;
  • whether leaked credentials are linked to employees, vendors or administrators;
  • whether MFA (Multi-Factor Authentication) is enforced for critical access;
  • whether DMARC, SPF and DKIM controls are in place for domains;
  • which suppliers have access to critical systems;
  • whether backup and recovery processes have been tested;
  • whether the response plan includes production, IT, legal, communications and management.

The main question is not only “are we protected.” The more precise question is “which of our weaknesses are visible from the outside, and which one could be used first.”

DIAMATIX Comment

From the DIAMATIX perspective, this report matters because it describes the reality of many mid-sized organizations: they are large enough to be valuable targets and stretched enough to have limited internal capacity.

For these companies, security needs to be organized around risk, not noise. Actively exploited vulnerabilities, exposed credentials, public-facing services and weak email authentication carry different weight when they connect to real business processes.

SOC (Security Operations Center) and MDR (Managed Detection and Response) processes help when they bring these signals into one working operating model. The goal is not more alerts, but better prioritization: what needs to be fixed first, what needs to be monitored and where risk is already moving.

Questions for CISO, IT and Leadership Teams

  • Which of our systems are visible from the internet?
  • Which of them carry Known Exploited Vulnerabilities?
  • Can we see leaked credentials linked to our organization?
  • How do we prioritize patching — by CVSS, exploitation or business criticality?
  • Which vendors have access to critical systems?
  • Have we tested recovery, not only the existence of backups?
  • Can we prove readiness to customers, regulators and partners?

The practical takeaway: ransomware risk in the mid-market is not smaller because the company is not a global giant. It is often more operational, because capacity is limited and dependencies are many.

Link to Manufacturing Practice

The topic of ransomware risk in the mid-market is especially relevant for manufacturing organizations. They often operate under strict timelines, partner requirements, engineering data dependencies, supplier relationships and regulatory expectations, while downtime has a direct business cost.

In our case study “SIGMATECH Builds Compliance-Ready Security with DIAMATIX”, we show how a manufacturing company can build a more structured security model: infrastructure assessment, access control, multi-factor authentication, backup, policies, documentation and continuous SOC (Security Operations Center) monitoring.

Read the case study here:
SIGMATECH Builds Compliance-Ready Security with DIAMATIX

Check which risks are visible to attackers

DIAMATIX can help assess external exposure, vulnerabilities, access, backup readiness and response capability for ransomware scenarios.

Request a ransomware readiness review with DIAMATIX.
Trusted · Innovative · Vigilant


Sources

  • Black Kite. Mid-Market Is the Routine Target: Ransomware, Third-Party Risk, and the Widening AI Gap.
  • Black Kite / PRNewswire. Black Kite Research Reveals That Ransomware’s Primary Target Is the Mid-Market, Not Enterprises as Widely Assumed.
  • Black Kite. 2026 Ransomware Report: Why Every Year Becomes the Worst Year on Record.
  • Infosecurity Magazine. Three-quarters of Ransomware Attacks Target Mid-Market Firms.

This article summarizes publicly available information as of August 2026.

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.