Reported data points to sustained ransomware exposure among mid-market firms
THE BRIEF
Help Net Security reports a Black Kite analysis covering 13,336 North American and European incidents with known revenue from January 2023 through June 2026. It says mid-market companies represented 73% of those incidents, but the supplied verification note says the claim is not independently confirmed.
WHY IT MATTERS
Banks and larger enterprises often depend on mid-market suppliers that may have limited recovery capacity. The exact percentage should not be used as a benchmark without reviewing the underlying methodology.
WHO SHOULD CARE
Third-party risk teams, commercial banks, insurers, private-equity firms and procurement leaders.
WHAT TO DO NOW
- Identify critical suppliers with annual revenue in the cited range or comparable operational capacity.
- Require evidence of tested backups, recovery time objectives and privileged-access controls.
- Include ransomware notification and cooperation duties in supplier contracts.
- Test whether a supplier outage can be handled without bypassing security controls.
- Use the reported figure as a discussion prompt, not as independently established evidence.
VERIFICATION NOTE
Single-source attacker or extortion-site claim; it remains unverified pending independent or primary confirmation.