Mid-market companies are a persistent share of ransomware victims

Companies with $10 million to $1 billion in annual revenue made up between 72.1% and 74.6% of ransomware victims in Black Kite’s North American and European data from January 2023 through June 2026.

That figure describes the composition of observed victims. It does not measure the probability that an individual mid-market company will be attacked. Executives should keep that distinction clear when assessing ransomware risk.

Black Kite analyzed 13,336 ransomware incidents with verifiable revenue data between January 2023 and June 2026. The mid-market share stayed within a narrow range throughout the period.

Black Kite’s data also shows ransomware incidents rising between 2023 and 2025:

Measure Figure
Black Kite-reported incidents in 2023 2,320
Black Kite-reported incidents in 2025 3,340
Black Kite-reported increase from 2023 to 2025 44%

Black Kite argues that attackers continued to focus on companies smaller than large enterprises but substantial enough to offer a return. This is the security vendor’s interpretation of the pattern, and it has a commercial interest in organizations investing in security and third-party risk management.

Black Kite defines lower mid-market as $10 million to $50 million in annual revenue, core mid-market as $50 million to $500 million, and upper mid-market as $500 million to $1 billion.

Manufacturing accounted for more than a quarter of mid-market ransomware victims, making it the most targeted industry in Black Kite’s data.

A separate dataset shows widespread exposed weaknesses

Black Kite separately assessed 120,128 mid-market organisations for security weaknesses visible from the internet. This measures security posture, a different question from ransomware incidence.

Finding Share of organisations
Significant patch-management finding involving public-facing software 54.7%
Disclosed vulnerability with a CVSS score of 8.0 or higher 48.1%
Missing or insufficient DMARC protection 46.8%
At least one stealer log finding 32.3%
At least one known exploited vulnerability 28.3%

DMARC is an email-authentication mechanism designed to help protect domains against certain forms of email impersonation. A stealer log finding can indicate information captured by information-stealing malware. CVSS, or the Common Vulnerability Scoring System, assigns numerical severity scores to software vulnerabilities.

These measurements do not establish what caused any ransomware incident. Black Kite’s ransomware tracking covered North America and Europe, while the separate assessment measured how a monitored mid-market population appeared from the internet. An externally visible weakness alone does not establish a causal link to a ransomware attack.

Ferhat Dikbiyik, Chief Research & Intelligence Officer, Black Kite, said this was the first time the company examined the mid-market as a distinct segment; previous studies included these companies within larger groups. Dikbiyik works for a security vendor that benefits commercially from demand for security and third-party risk management.

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.

Enterprise expectations meet mid-market capacity

Black Kite points to the EU’s NIS2 Directive, New York’s NYCRR 500 and HIPAA as examples of regulatory pressure relevant to security. Applicability depends on jurisdiction, sector and each organisation’s circumstances.

Black Kite characterizes mid-market companies as having smaller security teams and fewer resources than large enterprises. That view comes from a vendor with a commercial interest in organizations investing in security capabilities.

The observed population shows widespread patch-management findings, high-severity vulnerabilities, email-protection gaps, stealer log findings and known exploited vulnerabilities. These give executives concrete areas to examine when deciding how much capacity their security operations require.

The same issue can affect supplier relationships. A company subject to customer security requirements has to determine whether it has enough people and budget to maintain the required controls over time.

AI adds another capability decision

ISC2’s 2025 Cybersecurity Workforce Study found that only 20% of mid-sized organisations had adopted AI tools in security operations.

Black Kite says tools that help defenders find software flaws are also available to criminal groups. That is the security vendor’s assessment of the technology’s dual use.

The adoption figure does not establish that AI will solve staffing or budget constraints. It shows that AI security tools were still a capability decision for most mid-sized organisations covered by the ISC2 study. Executives need to judge AI investments against the specific security work their teams need to perform.

Key takeaways for leaders

  • Ransomware remains concentrated in the mid-market: Companies with $10 million to $1 billion in revenue represented 72.1% to 74.6% of observed ransomware victims from January 2023 through June 2026. Leaders should treat this as evidence of persistent exposure, not an individual probability of attack.
  • Internet-facing weaknesses remain widespread: More than half of assessed mid-market organisations had significant patch-management findings, while vulnerabilities, weak email protection and stolen credentials were also common. Leaders should prioritize remediation based on exploitability and business impact rather than assuming these findings caused past ransomware incidents.
  • Security capacity must match growing obligations: Regulatory requirements and customer security expectations can stretch mid-market teams with fewer resources than large enterprises. Executives should assess whether staffing, budgets and controls can sustain compliance and supplier commitments over time.
  • AI requires a capability-based investment case: Only 20% of mid-sized organisations in ISC2’s 2025 study had adopted AI tools in security operations. Leaders should evaluate AI against specific security workloads and capacity needs rather than assume it will resolve staffing or budget constraints.

Alexander Procter

September 2, 2026

4 Min

Okoone experts
LET'S TALK!

A project in mind?
Schedule a 30-minute meeting with us.

Senior experts helping you move faster across product, engineering, cloud & AI.

Please enter a valid business email address.