Node4’s recently released Mid-Market IT Priorities Report 2024 reveals a detailed picture of the cyber security landscape across UK mid-market companies. It also highlights the top ten mid-market cyber security threats for the next 12 months. Top of the list is insider threats, followed by AI-related threats.
The full list of top ten cyber threats is:
- Insider threat
- AI-related threats.
- Ransomware
- Deep fakes
- Malware
- DoS attacks
- Supply chain attacks
- Phishing
- Zero-day attacks
- Scams/fraud
The high level of concern around insider threats could be attributed to the large number of job transitions and redundancies over the past 12 months, coupled with the growing reliance on contractors to address IT and cyber security skills gaps. It might also be linked to long-term, security-related worries, flexible working and the increased potential for cyber attacks on a distributed workforce.
Paul Bryce, Managing Director, Node4
The research also points to significant adoption of pre-crime and preventative cyber security measures, with around 40% of respondents stating they currently have dark web intelligence and incident response capabilities —suggesting a growing level of maturity in cyber security policy adoption across the mid-market.
Perhaps linked to the above findings, the report reveals a high degree of optimism surrounding cyber security defence capabilities. Over three-quarters of IT decision-makers said they were confident in their organization’s ability to prevent and respond to cyber attacks, despite the research being conducted at a time of increased cyber attacks aimed squarely at small and mid-sized organizations. Breaking down these results by vertical sector, IT decision-makers working in private healthcare were the most confident, while those in retail were least so.
Despite this confidence there is concern about the change in threat level that AI will quickly create.
Over a quarter of respondents said that they believe AI could expose their organization to new cyber security risks in the future and that dealing with AI-related threats is their top priority for the next 12 months. Further, around one-third of compliance challenges identified by respondents in this research are directly linked to IT security and cyber security risk mitigation — pointing to the ongoing complex issues at play in ensuring secure remote access to corporate data. Taken together, these findings indicate that now is not the time for complacency, and the mid-market’s IT decision-makers need to double down on their proactive, vigilant cyber security stance.
Less than 15% of mid-market IT decision-makers manage cyber security defences with internal staff, while over a third outsource to managed service providers. Meanwhile, the majority rely on a combination of in-house resources and their managed service provider (MSP). This could explain why nearly a quarter of respondents said the need to enhance data security and compliance was driving their digital transformation efforts.






