By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: IntruderPublished March 23, 2026

TL;DR: A sharp confidence gap appears in a survey of more than 500 security decision-makers at US and UK companies with 400 to 6,000 employees, with 65% of C-level leaders very confident in security posture versus 36% of middle managers, plus a one-week exposure assessment lag for 51% of teams, according to Intruder. That combination makes fragmented tooling and weak board visibility an operational risk, not just a budgeting issue.


At a glance

What this is: This survey finds that midmarket security teams are overconfident at the top, understaffed in the middle, and increasingly constrained by fragmented tooling and slow exposure assessment.

Why it matters: For IAM and security practitioners, the same governance gap that hides attack surface and slows remediation also obscures identity risk, privilege sprawl, and accountability across human and machine access.

By the numbers:

👉 Read Intruder's report on the security middle child problem and midmarket risk


Context

Midmarket security programmes often sit in the awkward space between lightweight tooling and enterprise-scale complexity. That creates a governance gap: teams have real revenue, real data, and a real attack surface, but not enough headcount or integration maturity to keep visibility and response aligned. In identity-heavy environments, the same problem shows up as incomplete control over access, privileges, and secrets across users, service accounts, and cloud workloads.

This article is about the operational consequences of that mismatch, not just survey sentiment. The security middle child problem is typical of growing organisations that have outgrown entry-level tools but cannot support a large, stitched-together stack; the result is slower exposure assessment, weaker board visibility, and more difficult accountability across security and identity programmes.


Key questions

Q: How should security teams reduce access risk when their stack is already fragmented?

A: Security teams should reduce access risk by consolidating trust decisions at the application layer instead of layering more tools on top of a fragmented stack. The practical goal is to limit broad network reach, apply continuous checks, and remove duplicate approval paths. That approach reduces operational noise and makes access easier to audit and govern.

Q: Why does board-level visibility matter for identity and exposure risk?

A: Because priorities follow what leadership measures. If access risk, remediation speed, and privilege exposure never reach the board, they remain tactical problems that compete with everything else. Identity teams need executive visibility to secure resources for lifecycle enforcement, access review, and rationalisation of high-risk accounts and machine identities.

Q: What do security teams get wrong about overgrown point-solution stacks?

A: They often treat tool sprawl as an integration problem rather than an operating-model problem. The real issue is that every additional handoff creates more delay, more ambiguity, and more unowned risk, especially when the stack also has to cover identities, secrets, cloud assets, and remediation under pressure.

Q: What signals show that exposure management is working?

A: Look for shorter time to ownership, shorter time to prioritisation, fewer findings waiting in unresolved queues, and faster verified closure after remediation starts. A healthy programme reduces the interval between discovery and confirmed risk reduction. If ticket counts drop but validation does not improve, the organisation may be reporting less rather than fixing faster.


Technical breakdown

Why fragmented security stacks slow exposure assessment

A fragmented stack creates blind spots because asset discovery, vulnerability data, cloud posture, and access context live in separate tools with different refresh cycles. Security teams then spend time correlating outputs instead of reducing exposure. In practice, this means critical findings can linger while teams decide which system is authoritative, which is exactly the wrong operating model when exploitation follows disclosure quickly.

Practical implication: consolidate telemetry paths around the assets and identities that matter most, then define one operational source of truth for exposure triage.

What the midmarket confidence gap tells us about governance

A confidence gap between executives and operators usually signals weak feedback loops, not simply pessimism from the front line. Leaders see dashboards and budgets, while practitioners see exceptions, manual workarounds, and unresolved risk. In identity and security governance, that mismatch often hides unowned accounts, delayed remediation, and controls that exist on paper but not in practice.

Practical implication: tie reporting to measurable control outcomes, not just tool coverage or leadership assurances.

Board visibility and the security middle child problem

When cyber risk is kept below board level, it tends to remain a technical issue rather than a business constraint. That limits pressure to rationalise tooling, improve prioritisation, or invest in the controls that reduce real exposure. For identity programmes, low board visibility often means privilege risk and lifecycle gaps stay embedded in routine operations instead of becoming managed risk decisions.

Practical implication: escalate identity and exposure metrics into board reporting so resourcing and accountability follow the risk.


NHI Mgmt Group analysis

Midmarket security debt is increasingly a governance problem, not just a tooling problem. The article shows that many teams have stitched together point solutions that do not produce a unified operational view. In identity terms, that same pattern usually produces fragmented account visibility, uneven privilege control, and weak lifecycle enforcement across humans and NHIs. Practitioners should treat stack fragmentation as governance debt because it degrades decision quality long before it becomes a breach.

The confidence gap between executives and operators is a control signal. When C-level leaders report high confidence but middle managers do not, the programme is probably relying on abstract dashboards rather than validated operational evidence. That matters for IAM and PAM because access risk is rarely visible at the top of the stack until an audit, incident, or escalation exposes the gap. The right conclusion is not optimism, but a need for control validation.

Board-level silence creates an identity blind spot. If cyber risk is not discussed where business decisions are made, identity priorities tend to stay trapped inside tactical operations. That leaves privilege sprawl, access review debt, and unmanaged machine identities easier to defer. For identity teams, the lesson is clear: governance only changes when identity risk becomes a board-relevant business metric.

Unified exposure management should now include identity context. The article is about attack surface management, but the practical lesson extends into IAM and NHI governance. Exposure is not just about open services or missing patches. It also includes who or what can reach those assets, whether access is standing or ephemeral, and whether secrets and service accounts have been brought under lifecycle control.

Midmarket teams need a named concept for this pattern: the security middle child problem. It describes organisations that are too complex for entry-level tooling but too constrained for enterprise sprawl. That is a recurring control failure across cloud, endpoint, and identity domains because the operating model does not match the environment. The practitioner response is to simplify governance, not just add another tool.

What this signals

Security middle child conditions usually translate into identity control drift. When teams cannot support a full enterprise stack, identity governance becomes reactive, with access reviews, secret rotation, and offboarding handled inconsistently. That is where a programme should expect audit friction first, then escalation risk later.

Midmarket programmes should treat exposure speed as an identity metric, not just a vulnerability metric. If a team takes a week to assess a critical zero-day, it is unlikely to move faster on standing access, service account ownership, or stale credentials. The control model has to compress decision time across both assets and identities.

A useful next step is to anchor reporting around lifecycle controls and access scope, then connect those metrics to a board-level narrative. The question is not whether the stack is busy. The question is whether the organisation can see, decide, and revoke fast enough to keep pace with how modern environments fail.


For practitioners

  • Create a single exposure triage path Define one operational workflow for attack surface, vulnerability, cloud, and identity findings so teams do not debate which tool owns the issue. Align ownership, severity, and escalation rules before the next major disclosure window.
  • Add identity context to exposure reviews Include standing privilege, service account ownership, secrets location, and third-party access in every exposure review so asset risk is evaluated alongside access risk. This is especially important where NHIs touch cloud or internet-facing systems.
  • Report control outcomes to the board Move beyond tool counts and report how quickly teams can identify exposure, revoke risky access, and close remediation loops. Use a small set of business-facing metrics so board discussions can drive prioritisation rather than abstract awareness.
  • Rationalise overlapping security tools Identify where multiple products cover the same discovery or remediation task and remove duplicated workflows that consume analyst time. The aim is not fewer tools for its own sake, but fewer handoffs and faster decisions.

Key takeaways

  • Midmarket security teams are operating inside a structural governance gap where confidence, visibility, and response speed no longer align.
  • Fragmented tooling amplifies identity and exposure risk because it slows triage, obscures ownership, and weakens board-level accountability.
  • The practical fix is not another point tool, but a tighter operating model that links exposure management, identity context, and executive reporting.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.AM-1Asset visibility and ownership are central to the report's exposure-management gap.
NIST SP 800-53 Rev 5AC-6Over-privilege and unclear accountability make least privilege directly relevant.
CIS Controls v8CIS-1 , Inventory and Control of Enterprise AssetsThe report's core issue is incomplete visibility across a fractured stack.
NIST Zero Trust (SP 800-207)The report's visibility and access problems intersect with continuous verification.

Use Zero Trust principles to reduce reliance on implicit trust across fragmented environments.


Key terms

  • Security Middle Child Problem: A midmarket operating condition where an organisation has outgrown entry-level security tools but lacks the staff, budget, or process maturity for enterprise sprawl. The result is fragmented visibility, slower decisions, and controls that fail because the governance model does not match the environment.
  • Exposure Triage: The process of deciding which security findings matter first, who owns them, and how they are remediated. In practice, exposure triage depends on reliable asset context, clear authority, and fast coordination across vulnerability, cloud, and identity data sources.
  • Identity context: The entitlement, ownership, and purpose information that explains why an action occurred and whether it was expected. For security operations, identity context turns raw alerts into decisions by showing which human or non-human identity acted and what it was allowed to do.
  • Board Visibility: The degree to which cyber risk is translated into business-level reporting that leadership can act on. Strong board visibility does not mean more dashboards. It means fewer, better metrics that drive resourcing, accountability, and priority setting.

What's in the full report

Intruder's full report covers the operational detail this post intentionally leaves for the source:

  • Sector-by-sector breakdown of the top five security tools and how spending differs across midmarket organisations.
  • Confidence scores by seniority, company size, and sector, which help benchmark where governance perceptions diverge.
  • Board-level discussion patterns in the UK and US, useful for comparing how regulation affects risk visibility.
  • How AI adoption is changing security investment priorities across companies with 400 to 6,000 employees.

👉 The full Intruder report covers the survey breakdowns, tool investment patterns, and board visibility data.

Deepen your knowledge

NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the wider security operating model their programmes depend on.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org