TL;DR: A sharp confidence gap appears in a survey of more than 500 security decision-makers at US and UK companies with 400 to 6,000 employees, with 65% of C-level leaders very confident in security posture versus 36% of middle managers, plus a one-week exposure assessment lag for 51% of teams, according to Intruder. That combination makes fragmented tooling and weak board visibility an operational risk, not just a budgeting issue.
NHIMG editorial — based on content published by Intruder: The Security Middle Child, a survey of midmarket security teams managing growth, complexity, and risk
By the numbers:
- 65% of C-level leaders say they are very confident in their security posture.
- 51% of respondents said it would take approximately, a week to assess exposure to a critical zero-day.
- 44% of teams have outgrown their security stack, or stitched it together from point solutions.
Questions worth separating out
Q: How should security teams reduce access risk when their stack is already fragmented?
A: Security teams should reduce access risk by consolidating trust decisions at the application layer instead of layering more tools on top of a fragmented stack.
Q: Why does board-level visibility matter for identity and exposure risk?
A: Because priorities follow what leadership measures.
Q: What do security teams get wrong about overgrown point-solution stacks?
A: They often treat tool sprawl as an integration problem rather than an operating-model problem.
Practitioner guidance
- Create a single exposure triage path Define one operational workflow for attack surface, vulnerability, cloud, and identity findings so teams do not debate which tool owns the issue.
- Add identity context to exposure reviews Include standing privilege, service account ownership, secrets location, and third-party access in every exposure review so asset risk is evaluated alongside access risk.
- Report control outcomes to the board Move beyond tool counts and report how quickly teams can identify exposure, revoke risky access, and close remediation loops.
What's in the full report
Intruder's full report covers the operational detail this post intentionally leaves for the source:
- Sector-by-sector breakdown of the top five security tools and how spending differs across midmarket organisations.
- Confidence scores by seniority, company size, and sector, which help benchmark where governance perceptions diverge.
- Board-level discussion patterns in the UK and US, useful for comparing how regulation affects risk visibility.
- How AI adoption is changing security investment priorities across companies with 400 to 6,000 employees.
👉 Read Intruder's report on the security middle child problem and midmarket risk →
Security middle child problem: what midmarket teams need to fix?
Explore further
Midmarket security debt is increasingly a governance problem, not just a tooling problem. The article shows that many teams have stitched together point solutions that do not produce a unified operational view. In identity terms, that same pattern usually produces fragmented account visibility, uneven privilege control, and weak lifecycle enforcement across humans and NHIs. Practitioners should treat stack fragmentation as governance debt because it degrades decision quality long before it becomes a breach.
A question worth separating out:
Q: What signals show that exposure management is working?
A: Look for shorter time to ownership, shorter time to prioritisation, fewer findings waiting in unresolved queues, and faster verified closure after remediation starts. A healthy programme reduces the interval between discovery and confirmed risk reduction. If ticket counts drop but validation does not improve, the organisation may be reporting less rather than fixing faster.
👉 Read our full editorial: Midmarket security confidence gaps are widening faster than exposure