As of: 23 June 2026 · Reading time: 7 min
Key takeaways
- Ransomware, data leaks, NIS2 slogans: IT security is no longer an optional topic for medium-sized companies.
- This guide shows where the greatest risks are, what measures are priority and what the new legal requirements are concrete.
Ransomware, data leaks, NIS2 slogans: IT security is no longer an optional topic for medium-sized companies. This guide shows where the greatest risks are, what measures are priority and what the new legal requirements are concrete.
“Digitalization is not an IT project—it is a business strategy.”
– Björn Groenewold, Managing Director, Groenewold IT Solutions
IT security in mid-sized businesses: What companies 2026 need to know
IT security in mid-sized firms is 2026 not a question of whether, but of how.
According to the BSI report, midsize companies in Germany recently recorded 2.3 successful cyberattacks per month on average – with damage levels that companies with 50 to 500 employees can meet in an existential manner.
At the same time, the NIS2 directive tightens the legal needs for around 30,000 extra companies in Germany. This contribution gives leaders a resilient orientation.
Where are the real risks, what measures are priority. And what are the new rules clearly for operation?
Why medium level is particularly targeted
Ransomware, data leaks, NIS2 slogans: IT security is no longer an optional topic for midsize companies.
Those who plan IT security in mid-sized firms: What companies need to know in 2026 from idea to rollout will find appropriate entry on our website with IT-security, digitalization in mid-sized businesses and IT- & digital consulting.
Attackers follow the cost-benefit calculus. Large corporations have dedicated security teams, multi-level defence lines and incident reps.
Small companies carry too little attack area. mid-sized firms does not meet both: ** Sufficiently valuable data and processes**, at the same time often no full-time IT security specialists.
Production data, customer master data, manufacturing recipes, ERP accesses – for ransomware groups, these are lucrative goals.
In addition, the supply chain dimension is added. Midsize companies are often suppliers or service providers for larger companies.
A compromised supplier opens the way for attackers to significantly larger networks. This also increases the target probability – and the liability risks in an incident.
The five most common attack vectors 2026
Short: Phishing and Social Engineering remain the number one deposit gate.
Phishing and Social Engineering remain the number one deposit gate. AI-generated, tailored phishing emails are hardly distinguishable from real emails; the click rate increases industry-wide.
Technical filters help, but do not replace employee training.
Unpatched software and outdated systems are the second most common vector.
If you are still running Windows servers from 2016, un updated firewall firmware or end-of-life database systems, you will provide known, publicly recorded gaps. Legacy systems are a special risk factor here.
What is no longer manageable can no longer be kept safe. .Completed remote access (VPN, RDP) was created during home office expansion and were not consistently secured.
Weak passwords, missing multi-factor authentication and broad access rights are typical findings.
Supply-Chain attacks via software updates increase. When an attacker compromises the update of a widely used tool, he meets many goals simultaneously.
Own software development also means keeping in mind the security of your own supply chain – dependencies, build pipelines, repositories.
Insider risks are statistically underestimated. Faults and negligent actions of their own employees cause a considerable proportion of all data panels – not malicious.
However, because processes and access rights have not been consistently designed.
NIS2: What specifically requires the directive
The NIS2 Directive (replaced in Germany by the NIS2UmsuCG) significantly expands the circle of companies concerned.
Companies are affected from 50 employees or 10 million.
Euro annual turnover in certain sectors (energy, transport, health, digital infrastructure, mechanical engineering, chemistry, etc.) and their important suppliers.
The specific duties include:
| Duty | What that means |
|---|---|
| Risk Management | Formal IT Risk Management System Document and operate |
| Reporting duties | Report major security incidents within 24h (report) and 72h (complete) |
| Business Continuity | Backup concept, recovery plans, crisis management |
| Supply Chain Security | Suppliers and service providers review safety standards |
| Encryption | End-to-end encryption for critical communication |
| Training obligation | Regular Awareness training for all employees |
| MFA | Multi-factor authentication for privileged accesses |
Violations can be fined up to 10 million. Euro or 2% of global annual turnover. Managing Directors are personally liable for gross violations of supervisory duty.
What first?
No midsize company can implement everything simultaneously. A meaningful prioritization follows the risk-impact calculus:
Sofort measures (week 1–4):
- Multi-factor authentication for all external accesses (email, VPN, remote desktop).
- Visualize patch management: Critical patches within 72 hours, all other weekly.
- Check backup concept: At least an offline copy, regular recovery tests.
- Invent privileged accounts and limit them to minimum (Least Privilege).
Medium-term (month 2–6):
- Network segmentation: separate production, office and guest WiFi- Endpoint detection and repository (EDR) instead of classic virus scanner.
- Security awareness training for all employees, at least annually.
- Document Incident Response Plan: Who does what if it burns?
Strategic (from month 6):
- Conduct penetration test to find blind spots.
- Building ISMS according to ISO 27001 or BSI basic protection.
- Integrate supplier safety assessment into purchasing processes.
Typical mistakes that meanwhile come expensive
**Contain security as a one-time project. ** IT security is not a project with completion. However, a continuous process.
If you do not plan ongoing checks after the initial equipment, you will quickly lose the connection to new threats.
Do not apply for awareness training. The best technical infrastructure fails when an employee clicks on a phishing link. Technical and organizational measures must go hand in hand.
Do not test backups. backups that have never been restored are no backups – they are files with unknown condition. At least quarterly, real recovery should be tried.
IT service provider without security needs. Anyone who grants external service providers full access to systems without agreeing minimum standards creates risks that he does not see.
Contractual security needs and regular audits are mandatory.
IT security and software development: The direct connection
Anyone who makes individual software develop is responsible for their safety.
Secure-by-design principles – secure standard values, input validation, encryption of sensitive data, secure dependencies – must be part of the development order, not subsequent supplement.
Our GDPR-compliant software development integrates security needs from the start into the development process – not as a checklist at the end.
However, as a quality feature of architecture.
Who is running existing software needs clear agreements for software maintenance and care. Who is responsible for security patches in which time window.
And who ensures that no critical gaps remain open?
Conclusion: IT security is chief thing
Short: IT security in mid-sized firms is 2026 a leadership task, no IT department task.
IT security in mid-sized firms is 2026 a leadership task, no IT department task. NIS2 makes this explicit: Managing Directors are liable, Boards are responsible.
Anyone who is now structuring – with clear priorities, recorded processes and regular reviews – is more legally and operationally proven than competitors who regard IT security as a cost factor. .Our IT-Safety Consulting provides a first overview of your security level – with concrete measures that match your company size and industry.
Frequently Asked Questions (FAQ)
Am I affected by NIS2?
Sector, company size (from 50 MA or 10 million € turnover) and function as critical infrastructure or its suppliers are decisive.
In case of doubt, a short examination by a consultant specialising in NIS2 is worthwhile.
What costs an appropriate IT security level for an SME?
Target: 5–10 % of the IT budget for security measures is an international orientation. In absolute numbers this varies greatly.
A first audit and action plan typically costs 5,000–15,000 € – a fraction of the average damage to a successful ransomware attack (2024: > 200,000 €).
Do I need to inform my customers about vulnerabilities as a software manufacturer?
Yes. Product liability, GDPR and in future the Cyber Resilience Act commit software makers to transparent communication and timely patches in known vulnerabilities.
What is the difference between ISO 27001 and BSI basic protection?
ISO 27001 is internationally recognised and risk-oriented. BSI-Grundschutz is more effective and publicly accepted in Germany.
For many midsize companies, a BSI basic protection profile is the more practical entry.
Technical sources and further links
The following separate references complement the grouping on the topics of this Article:
- Bitkom – Digital Economy Association.
- BSI – Federal Office for Information Security.
- European Commission – Digital Strategy.
- MDN Web Docs (Mozilla)
- W3C – World Wide Web Consortium.
"DevOps means less tool sense than common ownership for quality and rollout – without that, automation remains superficial."
— *Björn Groenewold, Managing Director, Groenewold IT Solutions *
About the author

Managing Director of Groenewold IT Solutions GmbH and Hyperspace GmbH
Since 2009 Björn Groenewold has been developing software solutions for the mid-market. He is Managing Director of Groenewold IT Solutions GmbH (founded 2010) and Hyperspace GmbH. As founder of Groenewold IT Solutions he has successfully supported more than 250 projects – from legacy modernisation to AI integration.
Blog recommendations
Related articles
These posts might also interest you.

Penetration Test vs. Security Audit: What does your company really need?
Penetration test or security audit? Both terms cure in tenders and recommendations for consultants – but they mean very different. This article explains the difference, explaining when the instrument…

Zero Trust for mid-sized businesses: Security architecture without enterprise budget
Zero Trust is not a product you buy – it is an architectural principle. And it is no longer only relevant to large companies. How Mittelständler pragmatically implement the core principles of Zero…

Combine funding: How to maximize your support
In today's digital landscape, the development of tailor-made software for many companies is a key factor in growth and competitiveness. But the investments...
Free download
Checklist: 10 questions before software development
Key points before you start: budget, timeline, and requirements.
Get the checklist in a consultationRelevant next steps
Related services & solutions
Based on this article's topic, these pages are often the most useful next steps.
Related services
Related solutions
Cost calculators
Practical next steps after IT Security for Mid-Sized Businesses: What Companies Need to Know in 2026
IT Security for Mid-Sized Businesses: What Companies Need to Know in 2026 addresses a practical choice for product and IT teams. Start with one clear goal: align software scope, technical risk, and business value before the next investment.
Check the current process, the data involved, and the result users need. Then record the main risks and define a small first step. This keeps the decision easy to review and gives your team a shared basis.
For NIS2 duties, notification timelines and ISMS alignment, see NIS-2 for mid-sized companies.
For implementation support, our custom software development connects the article's guidance with architecture, delivery, and stable operations. Engineering and project ownership stay with our team in Leer, Germany.
This post belongs to IT-Sicherheit. Browse the related IT-Sicherheit articles or use the English software blog for other topics.
When budget is the next question, the software cost calculators provide planning ranges. The IT glossary explains key terms, while in-depth technology guides cover wider decisions.
If the topic affects a live project, book a technical consultation or send the context through our project contact form. We usually reply within one working day.
