Skip to content
NEWSR
Digital Safety · 4 min read

Why Mid-Market Ransomware Risk Is Becoming a Budget Problem

A Black Kite study finds mid-market companies accounted for 73% of ransomware incidents with known revenue from 2023 through the first half of 2026. The durable issue is not only who gets attacked, but whether smaller security teams can reduce exposure without enterprise-scale resources.

Jordan Ellis
· Updated
In this story
Mid-market ransomware risk becoming a budget problem — Newsr illustration
Newsr illustration

Key takeaways

  • 73% of 13,336 disclosed incidents with verifiable revenue hit mid-market companies from 2023 through June 2026.
  • The mid-market share stayed near 72% to 75% even as incidents rose 44% from 2023 to 2025.
  • Manufacturing represented more than 25% of mid-market victims in Black Kite's analysis.
  • Black Kite's scan found known exploited vulnerabilities at 28.3% of 120,128 assessed organizations.
  • The study does not establish victim overlap, individual losses or causation between scan findings and attacks.

Mid-market companies are not a fringe ransomware target. According to Black Kite’s 2026 study, organizations earning $10 million to $1 billion a year accounted for 73% of 13,336 disclosed ransomware and extortion incidents with a verifiable revenue figure across North America and Europe from January 2023 through June 2026.

That finding matters because the share barely changed while the number of incidents increased. For security leaders, the consequence is a sustained budgeting problem: exposure is concentrated among companies that may not have the staffing, redundancy or purchasing power associated with the largest enterprises. The evidence does not quantify ransom payments, downtime or recovery costs, so it cannot show the financial loss per victim. It does show where the pressure is landing.

The pattern held as incident volume rose

Black Kite’s annual shares were 74.6% in 2023, 72.1% in 2024, 74% in 2025 and 72.3% in the first half of 2026. The company also reported that the absolute number of incidents rose 44%, from 2,320 in 2023 to 3,340 in 2025.

Infosecurity Magazine independently summarized the same study and described the mid-market as three segments based on revenue: $10 million to $50 million, $50 million to $500 million and $500 million to $1 billion. The lower mid-market represented the largest share of victims in the publication’s account, at 54%, while its victim count rose from 1,391 in 2024 to 1,821 in 2025. Those figures point to a concentration of risk below the largest end of the segment, although the supplied evidence does not establish why those companies were selected or compromised.

Manufacturers face the sharpest operational stakes

Manufacturing was the most targeted industry, representing more than 25% of mid-market ransomware victims in Black Kite’s report. Professional, scientific and technical services and construction followed. Infosecurity Magazine put manufacturing’s share at 26% and noted that production businesses generally have limited tolerance for outages and may hold sensitive operational information.

That does not mean every manufacturer faces the same threat or that industry membership caused an attack. It does clarify the practical trade-off. A company that cannot quickly isolate systems or restore operations may have to weigh security spending against the cost of interrupted production, delayed customer commitments and supplier disruption. The evidence pack does not provide a Black Kite estimate for any of those costs.

What the scan can—and cannot—say about readiness

Black Kite said it assessed 120,128 mid-market organizations across North America and Europe through an external internet-facing scan. It reported that 28.3% had at least one known exploited vulnerability and that 54.7% had at least one significant patch-management finding.

These are exposure indicators, not proof that a specific company will be attacked or that a particular weakness caused one of the incidents in the 13,336-event dataset. The report also does not, in the supplied material, explain the overlap between scanned organizations and disclosed victims. That distinction is important for boards and IT teams: a scan can identify a condition to investigate, but it cannot by itself measure exploitability, business impact or recovery readiness.

The turning point is resource allocation, not another headline statistic

The stable 72% to 75% range changes how the result should be read. This is not simply a one-year spike in attention around smaller companies. It is a multi-year pattern in the data Black Kite examined, while the overall count grew.

For mid-market teams, that makes prioritization the immediate issue. They may need to decide whether scarce capacity goes first to exposed internet-facing systems, patch-management gaps, supplier visibility or recovery exercises. Black Kite’s press release frames its work as support for smaller security teams, but that is a manufacturer claim rather than independent evidence that any product or program reduces ransomware losses.

The central limitation remains scope. The 73% figure covers disclosed incidents in North America and Europe with a verifiable revenue figure, not necessarily every attack. It also comes from Black Kite’s analysis, and the supplied evidence does not include a full methodology or an independent audit of the underlying records.

What to watch next

The next meaningful signal is not a more dramatic annual slogan. It is fuller methodological detail: how incidents were identified, how revenue was verified, how the scan findings overlap with victims and whether the proportions hold in later reporting. Until that information is available, the responsible conclusion is narrower but still consequential: mid-market companies were the majority of known-revenue victims in this dataset, and their share remained high as incident volume increased.

Newsr Reframed

The durable significance of Black Kite's 2026 report is the consistency of the target profile. Mid-market organizations represented 72% to 75% of the study's known-revenue victims each year from 2023 through the first half of 2026, even as incident volume grew. That makes the finding more useful as a resource-allocation warning than as a prediction about any individual company. The evidence supports attention to exposure and patch-management gaps, but it does not independently prove causation, quantify recovery costs or show that a particular security product reduces risk. The next test is fuller methodology and later data.

Sources and methodology

Share this story Facebook X LinkedIn Reddit WhatsApp Email

Latest stories