“Mid-market organizations face the same security threats as large global enterprises, but they do so with a fraction of the resources,” Kevin Charest, CISO & VP of Cyber Governance Services, warned. “What I see repeatedly is understaffed IT teams trying to stitch together fragmented tools, leading to a reactive posture instead of a resilient one.”
Why mid-market security looks different — and why it matters
Last year, cybersecurity ranked among the highest business concerns for small- and medium-sized businesses (SMBs). The source material makes clear why: SMBs and mid-market firms often lack the funding and staffing to keep pace with new technologies, and in many cases IT leaders also serve as the organization’s security leaders. That combination — elevated risk concern with constrained resources and dual roles — creates a tactical environment in which security can too easily slip from strategic priority to an afterthought.
Clear visibility across the environment
Charest identifies “clear visibility across their environment” as the first of three fundamentals mid-market IT leaders must adopt. In the account he provides, lack of visibility is a root cause of the reactive posture he observes: when teams are understaffed and tools are fragmented, blind spots grow and response becomes piecemeal. Visibility, in this framing, is not an optional optimization; it is the baseline capability that enables confident, timely decisions about threats and operations.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildOutcome-driven security aligned to regulatory requirements
The second fundamental Charest highlights is “outcome-driven security aligned to regulatory requirements.” The phrasing implies a shift from tool- and checkbox-oriented programs toward controls and processes measured by the concrete outcomes they produce and by how well they meet applicable regulations. For mid-market organizations operating with limited staff and budget, alignment to regulatory outcomes helps prioritize effort and expenditures where they reduce legal and operational exposure most directly.
A realistic plan for ‘unpatchable’ technical debt and compensating controls
The third fundamental is a “realistic plan to address ‘unpatchable’ technical debt through compensating controls.” The source emphasizes that not every vulnerability can be patched immediately — and some legacy or embedded systems may be effectively unpatchable. Charest urges leaders to plan for those realities instead of deferring them; compensating controls are positioned as the practical alternative that protects day-to-day operations while longer-term remediation or replacement is pursued.
What this means for mid-market IT leaders, security teams, and procurement leaders
- Mid-market IT leaders: Treat cybersecurity as a business imperative rather than a discretionary line item; prioritize visibility, outcomes, and realistic mitigation plans so the organization can “withstand and recover from attacks” and protect daily operations.
- Security teams and technologists: Expect to operate with fewer resources and fragmented toolsets; focus on consolidating visibility and defining measurable outcomes that align to regulatory requirements, while documenting compensating controls for systems that cannot be patched immediately.
- Procurement leaders: When budgets are tight, acquisitions should favor solutions that improve overall visibility and demonstrably contribute to regulatory-aligned outcomes, rather than adding point tools that increase fragmentation.
Charest’s argument is straightforward and consequential: mid-market organizations face the same threats as large enterprises but cannot afford identical programs. The practical path he prescribes — clear visibility, outcome-focused controls tied to regulation, and a realistic approach to unpatchable technical debt — reframes cybersecurity from a cost center into a capacity that determines how quickly an organization can withstand and recover from attacks. For IT leaders operating without the headcount or budgets of larger firms, those three fundamentals are not optional checkboxes; they are the core of a defensible, resilient posture.



