TL;DR: Midmarket security teams are growing budgets but still face fragmented stacks, manual exposure tracking, and week-long visibility gaps, according to Pomerium’s analysis of Intruder survey data from more than 500 senior decision-makers. The structural problem is architectural, not resource scarcity: continuous verification and identity-aware access matter more than adding another tool.
Editorial analysis by NHI Mgmt Group, based on content published by Pomerium: “Midmarket Security Teams Deserve Better Than Enterprise Hand-Me-Downs”.
Key questions
Q: What breaks when midmarket teams rely on VPNs for internal application access?
A: VPNs break the visibility model by granting broad network reach after a single authentication event.
Q: Why does fragmented access management make zero trust harder in midmarket environments?
A: Fragmented access management forces teams to reason about identity, device posture, and application exposure across separate tools.
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Practitioner guidance
- Standardise request-level access enforcement Move internal application access decisions to a control point that evaluates identity and context on every request instead of relying on broad VPN reach after login.
- Replace manual exposure tracking Inventory internet-facing assets and internal access paths in one governed view so exposure can be assessed without spreadsheet-driven gap analysis.
- Define policy for AI agent identities Assign scoped permissions, audit logging, and explicit access boundaries before AI agents connect to internal tools, databases, or APIs.
Bottom line: Midmarket security teams are not short on ambition or spend, but many still lack an access architecture that gives them reliable visibility into exposure.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Midmarket security is experiencing an access architecture mismatch, not simply a tooling shortage. The report shows that budgets are rising while visibility and response remain slow, which means the operating model is out of step with the team size. Enterprise hand-me-downs tend to assume more staff, more orchestration, and more tolerance for integration overhead than midmarket teams can sustain. Practitioners should read this as an architectural warning, not a procurement problem.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to Ultimate Guide to NHIs.
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
A question worth separating out:
Q: What should security teams do when AI agents start accessing internal systems?
A: Security teams should place AI agents under the same identity and policy discipline used for humans, but with tighter scoping and explicit audit trails. Agents that query data or call APIs need request-level authorization, logged actions, and clear delegation boundaries. Treating them as unmanaged automation creates a new access class outside governance.
👉 Read our full editorial: Midmarket security teams need architecture, not enterprise hand-me-downs
Midmarket security is primarily an architecture problem, not a staffing problem: the article’s core signal is that budget growth does not automatically fix exposure when the access layer remains fragmented. Midmarket teams can add tools and still fail to see who can reach what, because visibility is split across VPNs, applications, and manual review processes. The practitioner conclusion is that architectural simplification has to precede tool accumulation.
A question worth separating out:
Q: When should organisations move from manual recertification to automated access reviews?
A: Organisations should move as soon as manual recertification starts slowing down approvals, creating inconsistent decisions, or leaving too little time before audit deadlines. Automation is especially justified when the same users must be reviewed across SAP and multiple connected applications. At that point, workflow standardisation, risk scoring, and faster remediation materially improve control quality.
👉 Read our full editorial: Midmarket security teams need architecture, not enterprise hand-me-downs