51% of middle market organisations stated they outsourced cybersecurity risk and compliance management. Other leading functions outsourced include cyber incident response and forensics (46%), the security operations center (46%), security awareness training (44%), and vulnerability management (44%).
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
Only 46% of larger and 37% of smaller middle market companies reported collaborating with external partners for coordinated resilience planning.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
ResilienceMiddle market
24% of respondents in larger middle market organisations (with revenue between $50 million to $1 billion) reported a breach.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
Data breachMiddle market
18% of middle market organisations experienced a data breach in the last year.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
Data breachMiddle market
On average, Canadian respondents at middle market organisations have larger cybersecurity teams, with 39% saying they have 16 or more employees, compared to 11% in the U.S..
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
StaffPersonnelCanadaUSMiddle market
34% of smaller middle market companies noted that AI governance steps are not yet in place.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
AI governanceMiddle market
33% of respondents at middle market organisations indicated they have five or fewer data security and privacy employees.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
Data security employeePrivacy employeeStaffPersonnelMiddle market
Among middle market companies that experienced at least one ransomware attack, 31% said existing security measures were unsuccessful.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
RansomwareSecurity measuresMiddle market
Familiarity with policy coverages dropped to 69% from 75% in the 2024 data at middle market organisations.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
25% of surveyed executives at middle market organisations reported experiencing at least one ransomware attack or demand in the previous 12 months.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
RansomwareMiddle market
47% of larger middle market firms reported that their top continuity strategy is leveraging technology to hunt for threats and respond to cyber events.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
While most respondents from smaller middle market companies cited having 0-5 internal personnel focused on data security and privacy, 36% of larger middle market organisations reported having 6-10 employees and another 36% said they have 11-15 employees in this area.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025
StaffPersonnelMiddle market
28% of respondents at middle market organisations said their existing security measures were partially successful against ransomware attacks.
RSM US LLPRSM US Middle Market Business Index Special Report: Cybersecurity 2025·Apr 17, 2025