Features Hub

The Goldilocks Zone: Why the UK’s Mid-sized Businesses Are the Optimum Target for Cyberattacks

Fri 5 Jun 2026 | Sarah Armstrong-Smith | Strategic Advisor to the Softwerx Executive Committee (ExCom)

Digital globe surrounded by interconnected network nodes, representing global data infrastructure and connectivity.

Mid-sized businesses are the backbone of the UK economy. Their role as essential suppliers, logistics providers and professional services firms means that their resilience is vital – not just for their own operations but for the broader supply chain and the communities they serve. It also makes them a prime target for cyberattacks.

Business leaders could be forgiven for assuming it’s only large enterprises that are targeted by cybercriminals. Whilst cyberattacks impacting well-known high-street brands are more likely to hit media headlines, they are often not the prime target.

These mid-sized businesses are an essential powerhouse for the economy, employing one in six of the UK’s workforce. Although NatWest research reveals that what it calls the “critical middle” only represents 0.5% of the total number of businesses in the UK, they deliver a quarter of the country’s turnover with a net contribution of 30% to the economy’s GVA (Gross Value Added).

They are often the vital cogs in keeping the wheels of commerce productive. They are the manufacturers making essential components that larger customers cannot do without. They are the logistics firms that deliver those components and final products, the constructors who build the plants and warehouses. They’re the professional services firms without whom maintenance, sales, marketing, training, legal advice or hiring is hampered. They might not always see it themselves, but if an attacker disrupts one of them, the ramifications are felt throughout the supply chain.

Why Are Mid-sized Businesses Targets?

It is the economy’s reliance on mid-sized businesses that makes them such an attractive proposition for threat actors. They sit at the centre of the so-called ‘Goldilocks’ zone because they are big enough to pay an extortion demand but small enough to have less protection.

Although larger enterprises may have more resources and data, they are tougher to crack, as the threat actor is more likely to be detected and stopped in their tracks. Conversely, whilst small companies may be easier to compromise with, they have fewer resources and financial means to pay. That leaves mid-sized businesses right in the middle, the optimum target for cyberattackers intent on achieving the biggest return on investment, when balancing risk versus reward.

Attacking a well-defended enterprise is hard, noisy and slow. Large organisations can often absorb prolonged disruption. They may have higher levels of insurance, cash reserves, specialist teams and time to recover. For mid-sized businesses, a serious cyberattack is not just an operational incident; it is a crisis of trust, reputation and survival. Cash flow dries up quickly. Contracts are questioned. Clients lose confidence. In many cases, the business may never fully recover.

These businesses are attacked not because they are weak but because they are integral to the functionality of larger organisations and the wider economy. Their central position and trusted relationships make them an attractive proposition for a range of threat actors.

It’s also important to recognise that not all attackers are motivated by financial gain. Some are driven by ideology or activism, targeting suppliers based on perceived associations or as a pivot point to reach larger, more prominent organisations. For example, a mid-sized accountancy firm providing services to a multinational in a politically sensitive region may become a target, not because of its own profile, but because of its connections. This highlights the need for a holistic approach to cyber risk – one that considers not just direct threats but also the broader geopolitical, social and economic ecosystem it operates within.

Cybersecurity is a business risk that directly affects continuity, credibility and economic resilience, and needs to be a regular board-level conversation.

When companies are being targeted because of the impact they will have on the supply chain, they need to invest in an effective cybersecurity strategy that protects vital products and services.

Responsible businesses will seize the opportunity to present themselves as well-protected partners who can be relied on for business continuity. Cybersecurity is not just a defensive measure; it’s a core strategy to signal commercial resilience and readiness as a trusted partner.

Opportunities for Mid-sized Businesses

It may feel daunting for organisations that need to balance risk with investment, and hence a good place to start is having a deep appreciation of the upstream and downstream impact that a major incident or cyberattack would have on the company, as well as their position in the supply chain.

What matters is establishing solid security foundations, where safety, security and resilience are treated as a core fundamental business discipline, and a culture that embeds these principles by design, not as an afterthought.

This starts with understanding sensitive data and critical assets and having a mindset of assuming compromise and failure. Performing due diligence and being honest and transparent on the current state, means that organisations can be better prepared for the investment decisions that need to be made to lower the risk and increase resilience.

Practical measures such as enforcing multi-factor authentication for every role, embedding robust identity and access controls, automating hardware and software updates, maintaining robust backup and incident response plans can significantly reduce risk. Leveraging managed security services and unified platforms can further enhance monitoring and protection capabilities.

From Protection to Growth Accelerator

Equally important is fostering a culture of security preparedness throughout the organisation. Top-down leadership engagement can help ensure that everyone understands their role in protecting the business.

Security is more than just protection; it’s a demonstration of collective resilience and a signal of commercial readiness. Performed correctly, cybersecurity can become a business growth enabler, cementing mid-sized businesses as trusted partners in the supply chain.

By investing in proportionate, practical security measures and fostering a culture of transparency and trust, mid-sized businesses can turn cybersecurity into a source of opportunity and competitiveness in the UK marketplace.

Experts featured:

Send us a correction Send us a news tip

Subscribe for News in Your Inbox