Security advice for mid-market companies tends to arrive as a list of forty controls with no ordering, which produces either paralysis or expensive work on the wrong things. What follows is ordered by risk reduction per dollar spent, based on what we actually find during assessments.
1. Multi-factor authentication everywhere, no exceptions
Credential compromise is the entry point in the majority of incidents we investigate. MFA on email, cloud infrastructure, VPN, financial systems and any administrative interface eliminates most of that risk for close to zero cost. The exceptions people carve out — the shared account, the executive who finds it inconvenient, the legacy system — are precisely where attackers enter.
2. Remove access that is no longer needed
Every assessment finds active accounts for departed staff, contractors with production access from a project two years ago, and service accounts with administrative rights nobody can explain. Run an access review quarterly and document it. This costs staff time and nothing else, and it removes a large share of your attack surface.
3. Patch on a schedule, and know your inventory
You cannot patch what you have not inventoried. Build an asset register first, then a patch cadence with tested maintenance windows. Internet-facing systems need the fastest cycle. Automated patching for workstations, scheduled for servers, and an exception register for anything that cannot be patched with a documented compensating control.
4. Test your backups by restoring them
Configured backups and working backups are different things. We routinely find backup jobs that have failed silently for months, or backups stored where the same ransomware event would encrypt them. The control is: at least one immutable off-site copy, and a restore test performed and documented quarterly. A backup you have not restored is a hypothesis.
5. Train people on the attacks they will actually face
Not generic awareness videos. Specific, current scenarios: invoice fraud and payment redirection, credential phishing on your actual login pages, and voice-based social engineering of your finance team. Combine short training with periodic simulation, and measure the click rate over time rather than the completion rate.
6. Enforce device encryption and basic hardening
Full-disk encryption on every laptop and phone. Automatic screen lock. Remote wipe capability. This turns a lost device from a potential breach into an inconvenience, and modern device management makes it enforceable rather than advisory.
7. Segment your network and limit lateral movement
Flat networks mean one compromised workstation reaches your file server, your finance system and your backups. Segmentation limits blast radius. For most mid-market companies, separating user devices, servers, guest access and any operational technology is sufficient and achievable with existing equipment.
8. Log centrally and review what matters
Logs that exist only on the compromised system are useless post-incident. Centralise authentication events, administrative actions, and access to sensitive data. Then define a small number of alerts you will actually act on — impossible-travel logins, privilege escalation, bulk data access. Ten tuned alerts beat five hundred ignored ones.
9. Secure the software you build or buy
If you develop software, add dependency scanning to your pipeline, keep secrets in a managed vault rather than configuration files, and perform authenticated penetration testing before major releases. If you buy software, assess vendor security posture before signing and record it in a third-party risk register.
10. Write an incident response plan and rehearse it
Not a document filed and forgotten. A plan naming who decides, who communicates, which systems get isolated first, and what your legal notification obligations are. Then run a tabletop exercise annually. The first time you use the plan should not be during an actual incident.
11. Manage third-party and supply-chain risk
Your vendors' security is part of yours. Maintain a register of who holds your data and what access they have, require security evidence proportionate to that access, and ensure contracts include breach notification obligations. Integration credentials should be scoped narrowly and rotated.
12. Get an independent assessment
Internal teams cannot easily see their own blind spots, and clients increasingly require third-party evidence. A focused external assessment — ours starts at $1,499 — produces a prioritised, validated finding list. The value is in the ordering as much as the findings.
What this does not cover
This list addresses common risk, not specialised exposure. Regulated industries, operational technology environments and companies holding large volumes of consumer data need controls beyond it. But a mid-market company with all twelve in place is substantially harder to compromise than most of its peers — and the first five cost almost nothing but discipline.
Want this applied to your operation?
A free 45-minute discovery call will establish whether the framework above applies to your situation, and what it would cost to act on it.