Most Mid-Market Security Problems Are Ownership Problems
Walk into a mid-market organization and you will usually find a reasonable amount of security technology, purchased over several years by several people, partially configured, and monitored by nobody in particular. The endpoint tool is deployed to eighty percent of the fleet because the last twenty percent belongs to a team that pushed back. Logs are collected but no one reviews them. There is a policy document that describes controls that were never implemented. None of this is solved by buying another product, and every vendor conversation will suggest that it is. What resolves it is naming an owner for each control, agreeing what evidence proves the control is working, and accepting that a smaller set of controls actually operated beats a larger set nominally owned.
