By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: IntruderPublished May 5, 2026

TL;DR: Cloud, SIEM, WAF, DSPM, and EDR dominate, while visibility-focused tools such as ASM and CTEM lag despite 28% citing exposure blind spots, according to Intruder’s Security Middle Child survey of 500 midmarket decision-makers. The result is a stack that is broader, more alert-heavy, and harder to govern than the teams buying it can comfortably operate.


At a glance

What this is: Intruder’s survey shows midmarket security teams are buying broad, fragmented stacks, but visibility, prioritisation, and compliance automation still lag behind the problems they are meant to solve.

Why it matters: For IAM and security practitioners, the lesson is that tool sprawl changes governance as much as coverage, because fragmented control planes make identity, access, and remediation harder to sustain across cloud and SaaS estates.

By the numbers:

  • Intruder surveyed 500 senior security decision-makers at companies with 400-6,000 employees across the US and UK to understand how midmarket security stacks are changing in 2026.
  • 55%, ud Security Posture Management was the most adopted control at 55%, while SIEM and WAF followed at 47% each.

👉 Read Intruder's survey of midmarket security stack fragmentation and AI pentesting adoption


Context

Midmarket security teams are facing the same cloud, SaaS, API, and endpoint risks as larger enterprises, but with far fewer people to operate the controls. That creates a governance problem as much as a tooling problem, because each added platform creates another policy surface, another alert stream, and another place where identity and access decisions can drift.

In this data set, the primary issue is not lack of investment. It is misalignment between the problems teams say they face, such as exposure visibility and hygiene reporting, and the categories they are adopting fastest. That pattern matters to IAM and NHI programmes because fragmented security stacks often hide weak credential governance, inconsistent access review, and unmanaged service-account sprawl.

The midmarket pattern is not unusual anymore. It reflects a broader security reality in which teams buy for compliance, then struggle to convert those controls into operational visibility and response.


Key questions

Q: How should security teams reduce AppSec tool sprawl without losing coverage?

A: Start by mapping every tool to a specific control purpose and threat path, then remove overlap where two products answer the same question. Keep the controls that improve visibility, correlation, and response speed, and retire the ones that only add dashboards or duplicate alerts. Coverage matters, but coverage without ownership and triage discipline creates more noise than value.

Q: Why does exposure visibility matter more than adding another security platform?

A: Because most real failures happen when teams cannot see what is exposed soon enough to act. More platforms rarely fix that on their own. Visibility is what lets security teams decide which assets, identities, and permissions deserve immediate attention, especially in cloud and SaaS environments where change is constant.

Q: What do security teams get wrong about automated compliance workflows?

A: They often assume the workflow itself is the control. In practice, the control is the combination of entitlement data, review logic, exception handling, and documented follow-through. If any of those pieces are weak, automation only accelerates the production of incomplete evidence.

Q: Who should own remediation when CSPM finds a serious cloud exposure?

A: Ownership should sit with both cloud operations and identity governance when the issue involves access, not just settings. If a finding can be recreated by a standing credential or inherited role, the remediation belongs in the same workflow as access review and secret management.


Technical breakdown

Why CSPM leads while exposure tooling lags

Cloud Security Posture Management tends to win budget because it maps cleanly to compliance evidence and continuous configuration checking. It is easier to justify a tool that produces audit artefacts than one that requires teams to investigate unknown exposure. But posture tools do not, by themselves, solve the harder problem of knowing what is exposed, how it is reachable, and whether identity permissions make that exposure exploitable. That gap is especially relevant when cloud access is mediated through service accounts, tokens, and workload identities rather than humans.

Practical implication: treat CSPM as a compliance and drift-detection layer, not as a substitute for exposure management or identity governance.

How tool sprawl turns visibility into an operational failure

When security teams accumulate CSPM, SIEM, WAF, DSPM, EDR, SSPM, SOAR, and more, the issue is not just overlap. Each platform emits different signals, expects different operators, and often lacks a shared asset or identity model. That fragmentation slows triage and makes it harder to answer basic questions such as who owns a system, which credentials touch it, and which alerts actually represent risk. In practice, the stack becomes a coordination problem before it becomes a detection problem.

Practical implication: rationalise tooling around shared identities, shared assets, and shared response workflows before adding another control category.

Why AI pentesting is rising without clear category maturity

The 41% adoption figure for AI pentesting suggests teams are experimenting with automation to offset headcount limits, but it also points to category ambiguity. Some buyers may be testing adversarial simulation, others may be using the label for broader automated assessment. That matters because automation only helps if the output can be validated, prioritised, and tied to remediation ownership. In identity-heavy environments, especially SaaS and cloud, simulated attacks are only useful when they expose weak privilege boundaries, stale secrets, or mis-scoped access.

Practical implication: define what AI pentesting must prove, then tie its findings to identity and remediation controls rather than treating it as a standalone test.


Threat narrative

Attacker objective: The objective is to exploit visibility gaps and identity weakness faster than defenders can correlate, prioritise, and contain them.

  1. Entry begins when exposed cloud, SaaS, or API surfaces are not visible enough for teams to prioritise them quickly.
  2. Escalation follows when fragmented tooling leaves identity and access issues, including over-permissioned accounts, outside the operator’s line of sight.
  3. Impact is operational rather than dramatic first: slower response, more false positives, weaker compliance evidence, and longer dwell time for real exposure.

NHI Mgmt Group analysis

Tool sprawl is becoming a governance problem, not just an operational annoyance. Once teams have separate controls for cloud, SaaS, data, endpoint, and web apps, the real challenge becomes coordination across overlapping telemetry and ownership boundaries. That fragmentation makes it harder to maintain consistent identity governance, especially where service accounts and API credentials cross multiple platforms. The broader lesson is that the security stack now fails most often at the seams, not within any single tool.

Exposure visibility is the named concept midmarket teams still underinvest in. The survey shows 28% citing lack of visibility into what is exposed, yet ASM and CTEM remain among the least adopted categories. That disconnect suggests organisations are still funding controls that are easier to justify than controls that close the actual blind spot. For identity programmes, the same logic applies to unmanaged secrets, stale access, and non-human identities that sit outside normal review cycles.

Compliance automation is being treated as a reportability problem when it is really an operating model problem. If evidence collection stays manual, teams will keep producing point-in-time compliance artefacts while the underlying stack keeps changing. That is a weak fit for environments where cloud configuration, SaaS permissions, and NHI credentials change continuously. The practitioner conclusion is that automation has to connect policy, identity, and evidence in one workflow.

AI-driven assessment is entering the stack faster than teams have resolved the basics of control ownership. The 41% AI pentesting figure is less a sign of maturity than a sign of pressure to do more with less. But any automated testing model still depends on a clean inventory, clear access boundaries, and a response path that can translate findings into action. The field should read this as an early signal that identity-aware automation is becoming a prerequisite, not a luxury.

For midmarket programmes, the next phase of security maturity will be measured by consolidation quality, not tool count. Buying fewer tools is not the real goal if the remaining stack cannot express shared ownership, shared identity context, and shared remediation. The organisations that get ahead will be those that align cloud, data, endpoint, and identity controls around a smaller number of operational decisions.

What this signals

The signal for programme owners is that stack growth is now a governance load issue, not just a procurement issue. As security tools multiply, the control plane becomes harder to defend, and that is where identity context matters most, especially for cloud accounts, SaaS permissions, and workload credentials.

Exposure-to-ownership gap: this is the pattern midmarket teams need to watch. If a finding cannot be tied quickly to an accountable owner and a shared remediation path, the organisation has not really improved security, only reporting volume. That is true whether the issue starts in cloud posture, SaaS misconfiguration, or non-human identity sprawl.

For identity-heavy environments, the near-term priority is to reduce the number of places where access decisions are made without a common lifecycle view. The practical next step is not another dashboard, but a smaller set of controls that can prove who has access, why they have it, and when that access should end.


For practitioners

  • Map controls to the top exposure gaps Start with the 28% visibility blind spot and identify which alerts, assets, and identities are actually creating risk, then remove duplicate controls that do not improve that view.
  • Rationalise overlapping tool categories Compare CSPM, SIEM, WAF, DSPM, EDR, and SSPM by the decisions they support, not by the dashboards they produce, and retire tools that add noise without changing response.
  • Tie identity ownership to every exposed system Require each cloud account, SaaS tenant, API, and workload identity to have a named owner and a review path so exposure findings can be acted on instead of merely reported.
  • Define what automation must prove before buying more For AI pentesting and other automated assessment tools, specify which privilege boundaries, secrets, or exposure conditions must be validated before the output is accepted.

Key takeaways

  • Midmarket security stacks are expanding, but the main failure is coordination across controls, not a lack of controls.
  • Visibility gaps, alert overload, and manual compliance work show that the stack is not yet aligned to the problems teams say matter most.
  • The next governance gain will come from tighter ownership, fewer overlapping tools, and better identity context across cloud and SaaS estates.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Visibility and alert overload are central to the survey findings.
NIST SP 800-53 Rev 5AU-6The article highlights poor prioritisation and hard-to-use monitoring outputs.
CIS Controls v8CIS-8 , Audit Log ManagementFragmented alerting and poor prioritisation make log management a core issue.
ISO/IEC 27001:2022A.8.16Monitoring activities and tool sprawl both affect control effectiveness.
NIST Zero Trust (SP 800-207)Section 2.2Identity-aware access decisions are needed across cloud and SaaS estates.

Use DE.CM-1 to assess whether security telemetry is actually giving you actionable exposure visibility.


Key terms

  • Tool Sprawl: Tool sprawl is the accumulation of overlapping systems that each solve part of the same identity or operations problem. In practice, it creates duplicate workflows, inconsistent policy enforcement, and more manual reconciliation, which weakens confidence in access decisions and slows down secure scaling.
  • Real-time exposure visibility: Real-time exposure visibility means seeing current agent permissions, connectors, and configuration state as they change, rather than relying on the last scan. It is essential where AI systems evolve continuously and stale posture data can no longer support trustworthy decisions.
  • Compliance Automation: Compliance automation is the use of software to collect evidence, track controls, and keep audit workflows moving with less manual effort. It helps organisations document compliance more efficiently, but it does not automatically prove that access decisions are correct or that identities have been governed properly.
  • AI pentesting: AI pentesting is the use of autonomous or semi-autonomous systems to identify, validate, and report security weaknesses in software or infrastructure. In practice, the value depends on whether the system can discover real assets, produce reproducible evidence, and support repeatable operational workflows rather than just generating vulnerability labels.

What's in the full report

Intruder's full report covers the operational detail this post intentionally leaves for the source:

  • Category-by-category tooling breakdown across 14 security domains and how adoption shifts by sector.
  • Survey responses on confidence, investment priorities, and how cyber risk reaches the boardroom.
  • Sector-specific stack profiles for financial services, healthcare, manufacturing, retail, SaaS, and more.
  • The report's commentary on how lean teams are handling compliance, visibility, and stack fragmentation.

👉 The full Intruder report includes the sector-by-sector stack data and the pressures behind tool sprawl.

Deepen your knowledge

NHI Mgmt Group’s NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, secrets management, and access lifecycle control. It helps practitioners connect identity discipline to the broader security programme they run.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 18, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org