Enterprise Security Wasn’t Built For Small Organisations

A professional services firm in Melbourne. A healthcare provider in Auckland. A financial services company in Sydney. 

None of them have are big enough to afford a security operations centre. None employ a dedicated security analyst. All three face the same ransomware groups, nation-state reconnaissance, and supply chain attacks targeting ASX 200 and NZX 50 companies. 

The threats don’t scale down. Your resources can’t scale up. This gap is the security paradox faced by mid-market organisations across ANZ. The backbone of the economy is being left behind when it comes to access to the cyber protection they need. Fit for size, sector and capability.  

It affects every mid-market organisation across Australia and New Zealand. And the security industry, for the most part, hasn’t built anything to close it. 

This blog series maps the paradox across five dimensions. Each one deserves its own conversation but here’s where they connect. 

The Threats Aimed at You Aren’t “Mid-market” Threats 

Ransomware operators don’t segment by company size. They segment by vulnerability. 

In late 2025, IKAD Engineering, a defence supply chain contractor, lost 800GB of data to an organised attack group. Manage My Health, a patient portal serving 1.8 million New Zealanders, was breached through a single valid password. Benedict Industries, a 100-employee landscaping firm, had 270GB stolen by the INC Ransom gang. This is happening every day, and many organisations simply don’t survive the impact of downtime or the reputational damage.  

These aren’t enterprise-scale organisations. They’re businesses that look like yours with limited budget and lean IT teams. 

Attackers target what they call the “awkward middle.” Large enough to hold valuable data and supply chain connections. Too small to staff 24/7 security operations. And if you’re part of a wider supply chain, your security posture becomes the entry point to someone else’s breach. 

Read more: [The Threat Sophistication Gap →]

The Maths of “Proper” Security Doesn’t Work at Your Scale 

What does it actually cost to build an internal security capability? 

One security analyst is a senior salary. However, round-the-clock coverage requires three to four analysts, an architect, and an operations manager. That’s $780K to $1.2M per year. The maths works at 1,000-plus users, but where do you start when that’s simply not close to a reality for you 

More often than not, security falls to the IT manager. And that IT manager is already running infrastructure, managing user support, delivering roadmap projects, handling compliance, and reporting to executives. They’re good at their job. But security operations is a different discipline, and pretending otherwise puts both the person and the organisation in an impossible position. 

Read more: [The Impossible Job You’ve Given Your IT Manager →]

Attackers Can See Your Resource Constraints 

Here’s what makes the paradox dangerous: attackers don’t just exploit technical gaps. They exploit operational ones. They probe for slow response times. They look for misconfigurations in public-facing services. They test for tools that generate alerts nobody reads. 

Most mid-market organisations have invested in endpoint protection (EDR). It’s accessible, well-understood, and addresses an obvious need. Some have added identity monitoring (ITDR), particularly in regulated industries where authentication security is a compliance requirement. 

But network-layer visibility, where lateral movement occurs, where command and control traffic flows, where data gets staged for exfiltration, is either missing entirely or deployed without the operational capability to act on what it sees. 

That’s the three-layer problem: EDR is deployed, ITDR is growing, and the network layer (what we call ZDR) is where the gap opens widest. Each layer generates signals. Nobody’s correlating them. 

Read more: [How Attackers Breach Mid-Market Organisations →]

You’ve Been Sold Software, Not Security 

Vendors sell platform licences. Partners deploy them. And the assumption baked into every sales conversation is that your team will operate what they’ve just purchased. 

That assumption is wrong for most organisations with tens to hundreds of users. 

“Cloud-delivered” doesn’t mean “easy to operate.” Moving complexity to a vendor’s infrastructure doesn’t eliminate it. It just changes where it lives. Buying a commercial kitchen’s worth of equipment doesn’t mean you’re running a restaurant. 

The vendor business model is optimised for licence volume. Partner ecosystems reward deployment metrics, not protection outcomes. And traditional managed service providers resell licences with break-fix support, which covers uptime but rarely touches security operations. 

Managed Services vs. Managed Security.  

Unlike most MSPs, VITG is an expert Managed Security Services Provider with an independent 24×7 Security Operations Centre. That distinction matters. Most managed services contracts cover infrastructure availability. Ours cover security outcomes: detection, investigation, and response, around the clock. 

Read more: [The SaaS Security Trap →]

Your VPN Was Built For a World That No Longer Exists 

VPNs rest on two assumptions: users work inside corporate walls, and applications live in data centres. 

Both assumptions are dead for most mid-market organisations. Your people work from home, from client sites, from airport lounges. Your applications live in Microsoft 365, Xero, Salesforce, and a dozen other SaaS platforms. 

When attackers compromise VPN credentials, they get the same broad network access as legitimate users. Lateral movement, internal reconnaissance, privilege escalation, all enabled by the open-door design VPNs were built around. You know this is a problem. But rebuilding your entire network architecture feels operationally impossible, so the VPN stays. 

That’s the paradox within the paradox: accepting risk because the alternative seems out of reach. 

Read more: [The VPN Problem →]

What Needs to Change From Here 

The security paradox is real. It’s structural. And it’s not your fault. 

What changes isn’t your budget or your headcount. It’s the questions you ask and the expectations you set for anyone claiming to protect your business. 

Three questions worth asking today: 

  1. “Are we buying protection, or just buying software?” Platform licensing gives you access to technology. It doesn’t give you the team to run it. 
  2. “Who’s watching at 2 AM?” If the answer is “nobody,” you have monitoring without security. 
  3. “Can we prove our security posture to our insurer?” Cyber insurance underwriters are asking harder questions every renewal. You need answers that go beyond “we have the tools installed.” 

This is the first in a six-part series exploring the security paradox across threat intelligence, cost reality, attacker tactics, vendor economics, and network architecture. Each piece goes deeper into one dimension of the gap and what mid-market organisations can do about it. 

→ Zero Trust Detection & Response (ZDR): Learn More

→ Assess Your Organisation: Request a Security Assessment 

→ Close Your Security Gaps: Book a Security Consultation 

 Follow Virtual IT Group on LinkedIn for ongoing insights on security. 

The question was never whether you need enterprise-grade security. The question is who will actually run it for you. 

 

Other recent articles

Great IT
starts here

Ready to take the next step? Talk to our
team about how we can support your
business objectives with award-winning
IT support and services.