On 18 August 2026, Black Kite published Mid-Market Is the Routine Target: Ransomware, Third-Party Risk, and the Widening AI Gap, with the trade press picking it up through the following week. The headline number is stark, but the number that matters for compliance is the one underneath it.

Black Kite analysed 13,336 disclosed ransomware and data-extortion incidents with a verifiable revenue figure across North America and Europe from January 2023 through June 2026, alongside external attack-surface assessments of 120,128 mid-market organisations. Seventy-three per cent of those incidents struck organisations with annual revenue between $10 million and $1 billion.

What makes the finding hard to dismiss as an artefact of one bad year is its stability. The mid-market share was 74.6% in 2023, 72.1% in 2024, 74.0% in 2025, and 72.3% in the first half of 2026 โ€” while absolute volume grew 44%, from 2,320 incidents in 2023 to 3,340 in 2025. The attack surface expanded; the target profile did not shift. More than half of mid-market victims earned under $50 million a year. Manufacturing was the most-targeted sector, accounting for roughly 26% of mid-market victims โ€” more than the next two sectors, professional/scientific/technical services and construction, combined โ€” with its share rising from 20.7% in 2023 to a peak of 28.0% in 2025 before easing to 27.0% in H1 2026.

The exposure data explains the targeting without any theory about attacker preference. Across the 120,128 organisations assessed, 54.7% had significant patch-management gaps on public-facing systems, 48.1% carried vulnerabilities scoring CVSS 8.0 or above, 28.3% carried at least one CISA Known Exploited Vulnerability, 32.3% appeared in infostealer logs, and 46.8% lacked adequate DMARC enforcement. That is not a portrait of a segment being singled out. It is a portrait of a segment that is reachable.

The compliance problem this creates is structural, and it is the subject of this article: nearly every modern cyber regulation is scoped by size, and the segment absorbing three-quarters of the incidents sits precisely where direct statutory supervision is thinnest. The mid-market is not unregulated. It is regulated indirectly โ€” by contract, by procurement, and by underwriting โ€” and most mid-market compliance functions are scoping themselves against the wrong instrument.

The Size Cap Is a Design Feature, Not an Oversight

Every regime below deliberately calibrates obligation to organisational scale, and the policy logic is sound: regulators do not want a fifty-person firm carrying a supervisory burden designed for a systemically important institution. The unintended consequence is that a threat actorโ€™s economics and a legislatureโ€™s proportionality analysis point in opposite directions. Ransomware operators do not price a target by systemic importance. They price it by the cost of intrusion against the probability of payment โ€” and a $40 million manufacturer with an unpatched VPN appliance, a two-person IT team, and production lines that stop when the ERP does is a better trade than a bank with a 24/7 SOC.

NIS2: In Scope, But Supervised After the Fact

Directive (EU) 2022/2555 builds its scope on the size-cap rule in Article 2(1), which uses the enterprise-size definitions in Commission Recommendation 2003/361/EC and then splits scoped entities into two tiers under Article 3:

  • Essential entities are, broadly, entities in an Annex I sector that exceed the ceilings for medium-sized enterprises โ€” 250 or more employees, or an annual turnover above โ‚ฌ50 million together with a balance sheet total above โ‚ฌ43 million.
  • Important entities are, broadly, medium-sized entities in an Annex I or Annex II sector โ€” at least 50 employees, or turnover and balance sheet total both above โ‚ฌ10 million.

Note what this means for the Black Kite population. A large part of the $10Mโ€“$1B revenue band is in scope, generally as important entities. The gap is not primarily one of scope; it is one of supervision.

Article 32 governs supervision of essential entities and permits competent authorities to act ex ante โ€” on-site inspections, off-site supervision, regular and targeted security audits, security scans, and requests for information, all available without any indication of an infringement. Article 33 governs important entities and is explicitly ex post: authorities act โ€œwhen provided with evidence, indication or information that an important entity allegedly does not comply.โ€ The substantive duties under Article 21 are materially the same for both tiers. The verification is not.

That distinction shapes behaviour. An organisation expecting a scheduled audit builds an evidence trail; an organisation that will only be examined after something goes wrong builds one after something goes wrong. The fine ceilings reinforce the asymmetry โ€” Article 34 sets a maximum of at least โ‚ฌ10 million or 2% of worldwide annual turnover for essential entities, against โ‚ฌ7 million or 1.4% for important entities โ€” but the fine is only reached through the ex post route in the first place.

Two further points are routinely missed by mid-market firms that conclude they are under the cap and therefore out of scope.

First, Article 2(2) pulls entities in regardless of size: where the entity is the sole provider in a Member State of a service essential for critical societal or economic activities; where disruption could significantly affect public safety, security or health or induce systemic risk across sectors; where the entity is critical because of its specific importance at national or regional level; and for categories such as DNS service providers, TLD name registries, qualified trust service providers, and providers of public electronic communications networks or services. A single-source component supplier to a national utility can be small and still be scoped โ€” and it is the Member State, through the Article 3(3) identification process, that decides, not the entity.

Second, transposition is not uniform: Member States implemented the size cap with local variation and several applied broader sector coverage, so a group with subsidiaries across the EU cannot scope itself once and apply the answer everywhere. On the October milestones and the management-liability dimension, see our briefing on the NIS2 October 2026 deadline and DORA management-body liability.

DORA: Proportionality Inside the Perimeter, Contracts Outside It

Regulation (EU) 2022/2554 takes a different approach. Scope is defined by entity type rather than headcount โ€” the financial entities listed in Article 2 โ€” and size enters through proportionality instead.

Article 4 requires financial entities to implement the ICT risk management framework โ€œin accordance with the principle of proportionality, taking into account their size and overall risk profile, and the nature, scale and complexity of their services, activities and operations.โ€ Article 16 provides a simplified ICT risk management framework for defined categories โ€” including small and non-interconnected investment firms and small institutions for occupational retirement provision โ€” which are exempt from the full Articles 5 to 15 apparatus but must still maintain sound ICT internal governance, continuously monitor system security, minimise impact through appropriate controls, and hold continuity and response plans.

The consequence for the mid-market is asymmetric, and it is the key point. A small regulated financial entity gets a reduced internal framework; a mid-market ICT service provider to financial entities gets no such relief. The critical ICT third-party provider (CTPP) oversight regime under Articles 31 to 44 does apply only to providers designated as critical by the European Supervisory Authorities, on criteria few mid-market vendors will meet. But the obligations that actually reach the vendor arrive through its customers:

  • Article 28(3) requires every financial entity to maintain a register of information on all contractual arrangements for ICT services, reported to competent authorities. Your customer will demand structured data on your entity identifiers, subcontracting chain, data locations, and service criticality โ€” regardless of your size.
  • Article 30 mandates the contractual content of every ICT services agreement, with a heavier schedule under Article 30(3) for services supporting critical or important functions: quantitative service level targets, data location and processing terms, incident notification to the financial entity, cooperation with competent authorities, participation in threat-led penetration testing, unrestricted audit and access rights, and defined exit strategies.
  • Article 29 requires financial entities to assess concentration risk and the subcontracting conditions of ICT providers, which flows straight into diligence questionnaires and restrictions on your own supply chain.

None of that is size-scoped. A twelve-person SaaS vendor supporting a bankโ€™s critical function inherits the same contractual schedule as a global hyperscaler. Our analysis of the DORA and NIS2 enforcement wave through 2026 covers how supervisors have begun testing these registers.

CIRCIA: The SBA Threshold Is Higher Than People Assume

In the United States, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 defines a covered entity through CISAโ€™s rulemaking, using two independent tests. The size-based test covers any entity in a critical infrastructure sector that exceeds the applicable Small Business Administration size standard for its NAICS code. The sector-based test covers entities meeting specified criteria regardless of size โ€” including certain hospitals, communications providers, defense contractors, and operators of critical manufacturing systems.

This is where mid-market firms miscalculate most often. โ€œSmall businessโ€ under SBA standards is not colloquial smallness: many manufacturing NAICS codes set the threshold at 500 to 1,500 employees, while many service codes use receipts thresholds well below the $10Mโ€“$1B band. A $60 million manufacturer with 180 employees may sit under its employee-based size standard and outside the size-based test โ€” while sitting squarely inside the sector-based test if it operates critical manufacturing systems. The analysis is per-NAICS and cannot be done on revenue alone.

The final rule has slipped repeatedly โ€” from an October 2025 statutory expectation to May 2026, and now to a September 2026 target, with the June 2026 town halls reopening the size-based criteria, the sector-based criteria, and the treatment of cloud and managed service providers. CISA estimates the rule would reach more than 300,000 entities. The clocks are statutory and short: 72 hours from reasonable belief a covered cyber incident occurred, and 24 hours from making a ransom payment. That ransom-payment clock matters most to this segment, because this segment is the one paying. See our readiness analysis of the September 2026 CIRCIA final-rule timeline.

SEC Disclosure: No Small-Company Relief

For SEC registrants there is no size gradient in the operative rule. Item 1.05 of Form 8-K requires disclosure of a material cybersecurity incident within four business days of the materiality determination, which must itself be made without unreasonable delay. Smaller reporting companies received a delayed compliance date when the rules took effect in December 2023 โ€” not an exemption. Item 106 of Regulation S-K requires annual disclosure of cybersecurity risk-management processes, governance, and board oversight from every registrant.

A $300 million public company therefore carries the full disclosure obligation while sitting, on Black Kiteโ€™s data, in the most-attacked revenue band โ€” and because materiality is assessed against that companyโ€™s financials, an incident immaterial to a large-cap is frequently material to a mid-cap. The size gradient runs the wrong way: smaller registrants have a lower materiality threshold and the same four-day clock.

What Actually Regulates the Mid-Market: Flow-Down

Set the statutes aside and look at what a mid-market compliance owner spends the year responding to. It is almost never a regulator. It is customers.

NIS2 Article 21(2)(d) requires in-scope entities to address supply chain security, including security-related aspects of relationships with direct suppliers and service providers, and Article 21(3) requires them to take into account the vulnerabilities specific to each direct supplier and the overall quality of products and cybersecurity practices of their suppliers. An essential entity does not satisfy that duty with an attestation form; it satisfies it by imposing terms. The obligation therefore propagates: the large in-scope customer converts its statutory duty into your contractual duty. You are supervised not by the competent authority but by your customerโ€™s procurement function, which has more leverage than any regulator because it controls renewal.

The same mechanism operates through every other regime:

  • GDPR Article 28(3) requires the processor contract to bind the processor to Article 32 security measures, to assist the controller with Articles 32 to 36, to notify breaches without undue delay, to submit to audits and inspections, and to impose the same terms on sub-processors under Article 28(4). There is no processor size threshold. The only real GDPR size concession โ€” the Article 30(5) record-of-processing derogation for organisations under 250 employees โ€” is itself disapplied where processing is not occasional, risks rights and freedoms, or involves special categories, which covers most commercial processing.
  • HIPAA business associate agreements under 45 CFR 164.502(e) and 164.308(b) flow the Security Rule down to business associates and subcontractors of any size, and OCR has enforced directly against small vendors.
  • CMMC and DFARS: clause 252.204-7012 flows NIST SP 800-171 and 72-hour DoD incident reporting to subcontractors handling covered defense information, and 252.204-7021 flows the CMMC level down the tiers. A ten-person machine shop three tiers below a prime carries a certification obligation set by rules it will never be consulted on. Our coverage of the CMMC Phase 2 November 2026 certification deadline sets out the phase-in.
  • Customer security schedules and questionnaires, increasingly where MFA mandates, EDR coverage, log retention, patch SLAs, and notification windows actually become binding. A twelve-hour notification clause in a customer security addendum is stricter than anything in NIS2, DORA or CIRCIA โ€” and is enforceable as breach of contract, immediately, without a regulator.

The result is a segment that inherits large-enterprise obligations without large-enterprise budgets, and without the interpretive support a supervisory relationship provides. A regulated entity gets guidance, dialogue, and sometimes a transition period. A supplier gets a redline deadline.

Manufacturing: OT Convergence Meets a Sector That Was Never Regulated for Security

The 26% manufacturing share deserves separate treatment, because manufacturing is the sector where the size-cap gap and the technical exposure compound.

Mid-market manufacturers are the segment where IT/OT convergence happened without a security programme: ERP connected to MES connected to line controllers, remote vendor access for machine maintenance, and a flat network because segmentation would have meant unplanned downtime. IEC 62443 is the applicable standard family โ€” 62443-2-1 for the operatorโ€™s IACS security programme, 62443-3-2 for zones and conduits, 62443-3-3 for system security requirements, 62443-4-1/4-2 for product suppliers โ€” but it is voluntary, and mid-market adoption has been driven by OEM and customer demand rather than by law.

Two regulatory developments cut against the assumption that manufacturing is out of scope. NIS2 Annex II brings named manufacturing sub-sectors into the important-entity tier: medical devices and in vitro diagnostics, computer, electronic and optical products, electrical equipment, machinery and equipment n.e.c., motor vehicles and trailers, and other transport equipment. And the Cyber Resilience Act, Regulation (EU) 2024/2847, applies to manufacturers of products with digital elements irrespective of size โ€” its Article 14 reporting obligations apply from 11 September 2026, requiring an early warning within 24 hours of awareness of an actively exploited vulnerability or severe incident, full notification within 72 hours, and a final report within 14 days for vulnerabilities, with the remaining obligations following on 11 December 2027.

For a mid-market machinery manufacturer, that means a 24-hour reporting duty arrives in September 2026 with no size relief whatsoever โ€” while the same firm may reasonably have concluded it was below the NIS2 threshold. These are the compounding OT and third-party exposures our Verizon DBIR 2026 analysis traced through the vulnerability-exploitation data.

Cyber Insurance as the De Facto Regulator

For most of this segment, the entity performing the annual control assessment is the underwriter. Applications function as compliance audits, and the answers are warranties. Coverage commonly turns on conditions precedent: MFA on all remote access, privileged accounts and email; EDR across a stated percentage of endpoints; immutable or offline backups with documented restoration testing; a defined patch cadence for critical and KEV-listed vulnerabilities; and DMARC enforcement.

Two consequences follow. A misstatement on a renewal application can void coverage at the exact moment it is needed, because the misrepresentation surfaces during the claim. And the insurance control set is, in practice, the most concrete cybersecurity standard many mid-market firms will ever be measured against โ€” enforced by a private party with no obligation to be proportionate. The premium trajectory in our piece on European law firms facing a 60% ransomware surge is the same dynamic in a different sector.

Determining Your Actual Scope: A Decision Sequence

Run these four layers in order. Most mid-market organisations run only the first and stop.

Layer 1 โ€” Direct statutory scope. For each legal entity and jurisdiction, record headcount, annual turnover, and balance sheet total, and test against the NIS2 Article 2/Article 3 thresholds as transposed locally, not as drafted. Separately test Article 2(2): are you the sole provider of anything, or has the Member State identified you under Article 3(3)? For US operations, identify your NAICS code and the applicable SBA size standard โ€” the actual standard, not an assumption โ€” and test both CIRCIA criteria. If you are an SEC registrant, Item 1.05 and Item 106 apply now, with no size relief.

Layer 2 โ€” Sectoral and product rules. Financial services: DORA by entity type, with Article 16 simplification if you qualify. Healthcare: HIPAA covered-entity or business-associate status. Defense: DFARS and CMMC by contract clause. Manufacturers of products with digital elements placed on the EU market: CRA Article 14 from 11 September 2026, size-irrelevant. Medical devices, machinery, and radio equipment carry their own converging cybersecurity essential requirements.

Layer 3 โ€” Contractual flow-down. This layer is almost never inventoried and is usually the binding one. Build a register of every customer contract containing a security schedule, DPA, BAA, or incident-notification clause, and extract for each: the notification deadline (12, 24 and 48-hour windows are common and beat every statutory clock), audit and inspection rights, mandated controls, certification requirements, subcontractor flow-down duties, and liability caps for security failures. Your operative incident-response clock is the shortest deadline in this register โ€” and most organisations discover it is contractual, not regulatory. The mechanics of that register are covered in our guide to data processing agreements and third-party compliance.

Layer 4 โ€” Insurance conditions. Extract every warranty, condition precedent, and control representation from the current policy and last application, assign each an internal owner and an evidence artefact, and verify before renewal that every representation is still true. Control drift between renewals is the most common route to a denied claim.

A Proportionate Baseline That Satisfies the Common Denominator

Across NIS2 Article 21(2), the DORA Article 16 simplified framework, NIST SP 800-171, the HIPAA Security Rule, and standard insurance conditions, the intersection is smaller than the union and largely consistent. A programme implementing the following can evidence substantial compliance against all of them:

  1. Asset and external attack-surface inventory, refreshed at least monthly, covering internet-facing services, remote access appliances, and third-party-hosted systems. With 54.7% carrying public-facing patch gaps, you cannot patch what is not enumerated.
  2. KEV-driven vulnerability management with defined remediation SLAs โ€” CISA KEV entries as the top tier, CVSS 8.0+ next. This addresses the 28.3% and 48.1% findings and maps to NIS2 Article 21(2)(e), 800-171 3.11, and insurance patch warranties.
  3. Phishing-resistant MFA on all remote access, privileged accounts, and email, plus credential-exposure monitoring against infostealer log feeds โ€” 32.3% of assessed organisations already appear in those logs, and stolen credentials remain the cheapest route to a mid-market network.
  4. Tested, immutable, offline backups with documented restoration exercises and recorded recovery times โ€” simultaneously a NIS2 Article 21(2)(c) continuity control, a DORA Article 16 requirement, a HIPAA contingency-plan requirement, and an insurance condition.
  5. Network segmentation between IT and OT, and between production and corporate environments, with IEC 62443-3-2 zone and conduit definitions where an industrial control environment exists.
  6. An incident-response plan with a notification matrix listing every deadline โ€” NIS2 Article 23โ€™s 24-hour early warning and 72-hour notification, GDPR Article 33โ€™s 72 hours, CRA Article 14โ€™s 24 hours, CIRCIAโ€™s 72-hour and 24-hour ransom-payment clocks, SEC Item 1.05โ€™s four business days, and every contractual window from your Layer 3 register โ€” with a named owner per row and pre-drafted templates, tested against a ransomware scenario annually.
  7. A supplier register with tiering, contractual security terms, and evidence review for anything supporting a critical function. Black Kiteโ€™s finding that a typical two-person vendor-risk team manages over 300 suppliers makes untiered review arithmetic fiction: tier by function criticality and data access, and accept documented lighter treatment for the tail.
  8. Documented management-body approval and training. NIS2 Article 20 requires management bodies to approve the risk-management measures, oversee implementation, and undergo training โ€” and the approval trail is the first thing an ex post investigation asks for. See the Latvia CSDD board-resignation case for what that looks like when it is missing.
  9. DMARC at enforcement, closing the 46.8% gap and removing a low-cost brand-impersonation vector against your own customers.

Conclusion

The stability of Black Kiteโ€™s number across three and a half years is the finding, not the number itself. A 73% concentration holding at 74.6%, 72.1%, 74.0% and 72.3% while total volume rises 44% describes a stable equilibrium: the mid-market is not caught in a wave aimed at someone else, it is the operating market.

Regulation is not organised around that equilibrium, and for defensible reasons: proportionality is a legitimate principle, and ex post supervision of important entities is a rational allocation of scarce supervisory capacity. But the practical effect is that the most-attacked segment of the economy is governed less by statute than by the terms its customers impose on it โ€” obligations that arrive without transition periods, without guidance, and without the option of dialogue.

The response is not to wait for the size cap to move. It is to stop scoping against statutes alone. Inventory the flow-down, find the shortest notification clock in your contract portfolio and build to it, and read the insurance conditions as a control standard, because that is how they will be enforced. Treat the September 2026 CRA reporting date and the pending CIRCIA final rule as the direction of travel: size-based exemptions are narrowing, and the obligations that are not size-scoped at all are the ones arriving first.

Sources: Black Kite โ€” Mid-Market Ransomware Report 2026, PRNewswire โ€” Black Kite Research Reveals That Ransomwareโ€™s Primary Target Is the Mid-Market (18 August 2026), Help Net Security โ€” Ransomware attackers are zeroing in on mid-market companies (24 August 2026), Cybersecurity Dive โ€” Ransomware disproportionately targets medium-sized firms, Infosecurity Magazine โ€” Three-quarters of Ransomware Attacks Target Mid-Market Firms, European Commission โ€” Cyber Resilience Act reporting obligations

This article is provided for informational purposes only and does not constitute legal advice.