TL;DR: Cloud, SIEM, WAF, DSPM, and EDR dominate, while visibility-focused tools such as ASM and CTEM lag despite 28% citing exposure blind spots, according to Intruder’s Security Middle Child survey of 500 midmarket decision-makers. The result is a stack that is broader, more alert-heavy, and harder to govern than the teams buying it can comfortably operate.
NHIMG editorial — based on content published by Intruder: Security Middle Child and the 2026 midmarket cybersecurity stack
By the numbers:
- Cloud Security Posture Management was the most adopted control at 55%, while SIEM and WAF followed at 47% each.
Questions worth separating out
Q: How should security teams reduce AppSec tool sprawl without losing coverage?
A: Start by mapping every tool to a specific control purpose and threat path, then remove overlap where two products answer the same question.
Q: Why does exposure visibility matter more than adding another security platform?
A: Because most real failures happen when teams cannot see what is exposed soon enough to act.
Q: What do security teams get wrong about automated compliance workflows?
A: They often assume the workflow itself is the control.
Practitioner guidance
- Map controls to the top exposure gaps Start with the 28% visibility blind spot and identify which alerts, assets, and identities are actually creating risk, then remove duplicate controls that do not improve that view.
- Rationalise overlapping tool categories Compare CSPM, SIEM, WAF, DSPM, EDR, and SSPM by the decisions they support, not by the dashboards they produce, and retire tools that add noise without changing response.
- Tie identity ownership to every exposed system Require each cloud account, SaaS tenant, API, and workload identity to have a named owner and a review path so exposure findings can be acted on instead of merely reported.
What's in the full report
Intruder's full report covers the operational detail this post intentionally leaves for the source:
- Category-by-category tooling breakdown across 14 security domains and how adoption shifts by sector.
- Survey responses on confidence, investment priorities, and how cyber risk reaches the boardroom.
- Sector-specific stack profiles for financial services, healthcare, manufacturing, retail, SaaS, and more.
- The report's commentary on how lean teams are handling compliance, visibility, and stack fragmentation.
👉 Read Intruder's survey of midmarket security stack fragmentation and AI pentesting adoption →
Cybersecurity stack sprawl in midmarket teams: what is breaking down?
Explore further
Tool sprawl is becoming a governance problem, not just an operational annoyance. Once teams have separate controls for cloud, SaaS, data, endpoint, and web apps, the real challenge becomes coordination across overlapping telemetry and ownership boundaries. That fragmentation makes it harder to maintain consistent identity governance, especially where service accounts and API credentials cross multiple platforms. The broader lesson is that the security stack now fails most often at the seams, not within any single tool.
A question worth separating out:
Q: Who should own remediation when CSPM finds a serious cloud exposure?
A: Ownership should sit with both cloud operations and identity governance when the issue involves access, not just settings. If a finding can be recreated by a standing credential or inherited role, the remediation belongs in the same workflow as access review and secret management.
👉 Read our full editorial: Midmarket security stacks are fragmenting faster than teams can govern