Mid-Market Under Cyber Attack
Attackers don’t need to know your headcount or your security budget. They can infer your resource constraints from your behaviour.
They see security tools deployed but not fully configured. They detect monitoring systems that aren’t actively watched. They probe for response times that suggest nobody’s paying attention outside business hours. They test defences and find gaps between what you’ve purchased and what you’re operating.
Those signals tell attackers that you have defences in place, but nobody’s really watching.
What Cyber Attackers Look For
Four patterns give mid-market organisations away:
- Slow response times to initial probing. This indicates monitoring without active analysis. Tools are generating alerts. Nobody’s reading them.
- Misconfigurations in public-facing services. Deployment happened, but ongoing management didn’t. Default settings, expired certificates, open ports that should have been closed months ago.
- Predictable patterns in network access. Broad VPN access rather than application-specific controls. Everyone is connecting the same way, to the same resources, with the same permissions.
- Tool signatures without corresponding behaviour. Security products are installed and reporting, but nobody’s acting on what they report. The tools are visible to attackers. The operational response behind them isn’t.
The Three-layer Problem
Security works in layers. Endpoint protection watches devices. Identity systems monitor authentication and access. Network security observes traffic between users, applications, and the internet. Each layer is supposed to catch what the others miss.
Here’s the reality in most mid-market environments:
Layer 1 — Endpoint Detection & Response (EDR).
Usually deployed and working. It’s accessible, well-understood, and addresses an obvious need. Malware hits endpoints. Endpoint tools catch malware. The value proposition is clear.
Layer 2 — Identity Threat Detection & Response (ITDR).
Growing adoption, particularly in regulated industries where authentication security is a compliance requirement. Azure AD Protection, Okta, or similar tools monitoring for credential theft and unusual authentication patterns.
Layer 3 — Zero Trust Detection & Response (ZDR).
This is where the gap opens. Network-layer visibility, where command and control traffic flows, where lateral movement happens, where data exfiltration occurs, is either missing entirely or deployed without the operational capability to act on it.
Most mid-market organisations have Layer 1. Some have Layer 2. Almost none have Layer 3 covered operationally.
How Attacks Actually Unfold
Initial Compromise (Identity Layer)
An attacker obtains credentials through phishing or credential stuffing. Your identity tools flag an unusual authentication location. The alert sits uninvestigated because your IT manager is handling an infrastructure outage.
Lateral Movement (Network Layer Gap)
The attacker uses valid credentials to explore your network. Without network-layer detection, this reconnaissance goes unnoticed. They map your environment, identify valuable targets, and position for impact. This can run for months. Broad VPN access makes this worse [Read: The VPN Problem ←], attackers move freely because VPNs were never designed to assume a breach has occurred.
Privilege Escalation (Endpoint Layer)
The attacker attempts to gain administrative access. Endpoint protection detects suspicious activity and generates alerts. Without someone correlating this with the earlier authentication anomaly, it looks like an isolated incident rather than part of an active attack chain.
Data Staging & Exfiltration (Network Layer Gap)
Sensitive data gets copied to external storage. This happens over your network, but without active traffic analysis, large transfers to unusual destinations don’t trigger investigation.
Ransomware Deployment (Endpoint Layer)
Ransomware deploys across multiple endpoints. Endpoint tools detect and block some instances, but by then data is already exfiltrated and backups are potentially compromised.
Each individual tool worked as designed. Each layer generated appropriate alerts. The failure wasn’t technological but operational. Nobody had the time, training, or visibility to correlate signals across all three layers and recognise an attack in progress.
The Detection Timeline Problem
What should happen: threat detected at initial compromise (minutes to hours).
What actually happens: threat detected at ransomware deployment (days to weeks, sometimes months).
The difference: someone actively correlating signals across all three layers. Not just tools generating alerts but security operations connecting the dots.
This mid-market security gap is the space between tools that generate signals and people who connect them. That’s the security paradox [Read: The Mid-Market Security Paradox ←] at its most dangerous, and it’s where the real breach examples from across Australia and New Zealand play out.
→ Zero Trust Detection & Response (ZDR): Learn More
→ Assess Your Organisation: Request a Security Assessment
→ Close Your Security Gaps: Book a Security Consultation
→ Follow Virtual IT Group on LinkedIn for ongoing insights on security



