🇩🇪
Central IT Security – Server Room with Security Monitoring

IT Security for Mid-Sized Businesses: What Companies Need to Know in 2026

IT-Sicherheit • 4 May 2026

As of: 23 June 2026 · Reading time: 7 min

Teilen:

Key takeaways

  • Ransomware, data leaks, NIS2 slogans: IT security is no longer an optional topic for medium-sized companies.
  • This guide shows where the greatest risks are, what measures are priority and what the new legal requirements are concrete.

Ransomware, data leaks, NIS2 slogans: IT security is no longer an optional topic for medium-sized companies. This guide shows where the greatest risks are, what measures are priority and what the new legal requirements are concrete.

Digitalization is not an IT project—it is a business strategy.

Björn Groenewold, Managing Director, Groenewold IT Solutions

IT security in mid-sized businesses: What companies 2026 need to know

Short: IT security in mid-sized businesses is 2026 not a question of whether, but of how.

IT security in mid-sized businesses is 2026 not a question of whether, but of how.

According to the BSI report, medium-sized companies in Germany recently recorded 2.3 successful cyberattacks per month on average – with damage levels that companies with 50 to 500 employees can meet in an existential manner.

At the same time, the NIS2 directive tightens the legal requirements for around 30,000 additional companies in Germany.

This contribution gives decision-makers a resilient orientation: where are the real risks, what measures are priority, and what are the new rules specifically for operation?

Why medium level is especially targeted

Short: Short answer: Ransomware, data leaks, NIS2 slogans: IT security is no longer an optional topic for medium-sized companies.

Short answer: Ransomware, data leaks, NIS2 slogans: IT security is no longer an optional topic for medium-sized companies.

Those who plan IT security in mid-sized businesses: What companies need to know in 2026 from idea to implementation will find appropriate entry on our website with IT-security, digitalization in mid-sized businesses and IT- & digital consulting.

Attackers follow the cost-benefit calculus. Large corporations have dedicated security teams, multi-level defence lines and incident reps.

Small companies carry too little attack area. mid-sized businesses does not meet both: ** Sufficiently valuable data and processes**, at the same time often no full-time IT security specialists.

Production data, customer master data, manufacturing recipes, ERP accesses – for ransomware groups, these are lucrative goals.

In addition, the supply chain dimension is added: medium-sized enterprises are often suppliers or service providers for larger companies. A compromised supplier opens the way for attackers to significantly larger networks.

This also increases the target probability – and the liability risks in an incident.

The five most common attack vectors 2026

Short: Phishing and Social Engineering remain the number one deposit gate.

Phishing and Social Engineering remain the number one deposit gate. AI-generated, personalized phishing emails are hardly distinguishable from real emails; the click rate increases industry-wide.

Technical filters help, but do not replace employee training.

Unpatched software and outdated systems are the second most common vector. If you are still running Windows servers from 2016, un updated firewall firmware or end-of-life database systems, you will provide known, publicly documented gaps. Legacy systems are a special risk factor here: What is no longer manageable can no longer be kept safe. .Completed remote access (VPN, RDP) was created during home office expansion and were not consistently secured. Weak passwords, missing multi-factor authentication and broad access rights are typical findings.

Supply-Chain attacks via software updates increase. When an attacker compromises the update of a widely used tool, he meets many goals simultaneously. Own software development also means keeping in mind the security of your own supply chain – dependencies, build pipelines, repositories.

Insider risks are statistically underestimated: faults and negligent actions of their own employees cause a considerable proportion of all data panels – not malicious, but because processes and access rights have not been consistently designed.

NIS2: What specifically requires the directive

Short: The NIS2 Directive (replaced in Germany by the NIS2UmsuCG) significantly expands the circle of companies concerned.

The NIS2 Directive (replaced in Germany by the NIS2UmsuCG) significantly expands the circle of companies concerned. Companies are affected from 50 employees or 10 million.

Euro annual turnover in certain sectors (energy, transport, health, digital infrastructure, mechanical engineering, chemistry, etc.) and their important suppliers.

The specific duties include:

Duty What that means
Risk Management Formal IT Risk Management System Document and operate
Reporting obligations Report significant security incidents within 24h (report) and 72h (complete)
Business Continuity Backup concept, recovery plans, crisis management
Supply Chain Security Suppliers and service providers review safety standards
Encryption End-to-end encryption for critical communication
Training obligation Regular Awareness training for all employees
MFA Multi-factor authentication for privileged accesses

Violations can be fined up to 10 million. Euro or 2% of global annual turnover. Managing Directors are personally liable for gross violations of supervisory duty.

What first?

No medium-sized company can implement everything simultaneously. A meaningful prioritization follows the risk-impact calculus:

Sofort measures (week 1–4):

  • Multi-factor authentication for all external accesses (email, VPN, remote desktop)
  • Visualize patch management: Critical patches within 72 hours, all other weekly
  • Check backup concept: At least an offline copy, regular recovery tests
  • Invent privileged accounts and limit them to minimum (Least Privilege)

Medium-term (month 2–6):

  • Network segmentation: separate production, office and guest WiFi- Endpoint detection and repository (EDR) instead of classic virus scanner
  • Security awareness training for all employees, at least annually
  • Document Incident Response Plan: Who does what if it burns?

Strategic (from month 6):

  • Conduct penetration test to find blind spots
  • Building ISMS according to ISO 27001 or BSI basic protection
  • Integrate supplier safety assessment into purchasing processes

Typical mistakes that meanwhile come expensive

Short: **Contain security as a one-time project.

**Contain security as a one-time project. ** IT security is not a project with completion, but a continuous process.

If you do not plan ongoing checks after the initial equipment, you will quickly lose the connection to new threats.

Do not apply for awareness training. The best technical infrastructure fails when an employee clicks on a phishing link. Technical and organizational measures must go hand in hand.

Do not test backups. backups that have never been restored are no backups – they are files with unknown condition. At least quarterly, real recovery should be tried.

IT service provider without security requirements. Anyone who grants external service providers full access to systems without agreeing minimum standards creates risks that he does not see.

Contractual security requirements and regular audits are mandatory.

IT security and software development: The direct connection

Short: Anyone who makes individual software develop is responsible for their safety.

Anyone who makes individual software develop is responsible for their safety. Secure-by-design principles – secure standard values, input validation, encryption of sensitive data, secure dependencies – must be part of the development order, not subsequent supplement. Our GDPR-compliant software development integrates security requirements from the start into the development process – not as a checklist at the end, but as a quality feature of architecture.

Who is running existing software needs clear agreements for software maintenance and care: Who is responsible for security patches in which time window, and who ensures that no critical gaps remain open?

Conclusion: IT security is chief thing

Short: IT security in mid-sized businesses is 2026 a leadership task, no IT department task.

IT security in mid-sized businesses is 2026 a leadership task, no IT department task. NIS2 makes this explicit: Managing Directors are liable, Boards are responsible. Anyone who is now structuring – with clear priorities, documented processes and regular reviews – is more legally and operationally established than competitors who regard IT security as a cost factor. .Our IT-Safety Consulting provides a first overview of your security level – with concrete measures that match your company size and industry.

Frequently Asked Questions (FAQ)

Am I affected by NIS2?

Sector, company size (from 50 MA or 10 million € turnover) and function as critical infrastructure or its suppliers are decisive.

In case of doubt, a short examination by a consultant specialising in NIS2 is worthwhile.

What costs an appropriate IT security level for an SME?

Target: 5–10 % of the IT budget for security measures is an international orientation.

In absolute numbers this varies greatly; a first audit and action plan typically costs 5,000–15,000 € – a fraction of the average damage to a successful ransomware attack (2024: > 200,000 €).

Do I need to inform my customers about vulnerabilities as a software manufacturer?

Yes. Product liability, GDPR and in future the Cyber Resilience Act commit software manufacturers to transparent communication and timely patches in known vulnerabilities.

What is the difference between ISO 27001 and BSI basic protection?

ISO 27001 is internationally recognised and risk-oriented. BSI-Grundschutz is more effective and publicly accepted in Germany. For many medium-sized companies, a BSI basic protection profile is the more practical entry.

Short: The following independent references complement the classification on the topics of this Article:

The following independent references complement the classification on the topics of this Article:

"DevOps means less tool sense than common responsibility for quality and rollout – without that, automation remains superficial."

— *Björn Groenewold, Managing Director, Groenewold IT Solutions *

About the author

Björn Groenewold
Björn Groenewold(Dipl.-Inf.)

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH

Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2012) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.

Software ArchitectureAI IntegrationLegacy ModernisationProject Management

Blog recommendations

Related articles

These posts might also interest you.

Free download

Checklist: 10 questions before software development

Key points before you start: budget, timeline, and requirements.

Get the checklist in a consultation

Relevant next steps

Related services & solutions

Based on this article's topic, these pages are often the most useful next steps.

More on this topic

More on IT-Sicherheit and next steps

This article is in the IT-Sicherheit topic. In our blog overview you will find all articles; under category IT-Sicherheit more posts on this subject.

For NIS2 duties, notification timelines and ISMS alignment, see NIS-2 for mid-sized companies.

For topics like IT-Sicherheit we offer matching services – from app development and AI integration to legacy modernisation and maintenance. We describe typical use cases under solutions. Our cost calculators give initial estimates. Key terms are in the IT glossary. Books and long-form guides appear on the publications page; deeper articles live under topics.

If you have questions about this article or want a non-binding discussion about your project, you can book a consultation or reach us via contact. We usually respond within one working day.

Next Step

Questions about this topic? We're happy to help.

Our experts are available for in-depth conversations – practical and without obligation.

30 min strategy call – 100% free & non-binding