What the 73% Ransomware Figure Really Says About Mid-Market Risk

what-73-percent-ransomware-statistic-means

The headline is alarming, but understanding the denominator, methodology and separate vulnerability dataset matters.

A cybersecurity statistic is making the rounds: 73 percent of ransomware victims are mid-market companies.

It is striking. It is also easy to misuse.

Black Kite’s 2026 Mid-Market Ransomware Report analyzed publicly disclosed ransomware and data-extortion incidents from January 2023 through June 2026 across North America and Europe. The company’s methodology began with 21,520 disclosed records. After filtering for publication-ready incidents and the report’s geographic scope, 13,336 incidents remained with a verifiable annual revenue figure. Of those, 9,781 fell into Black Kite’s mid-market definition of $10 million to $1 billion in annual revenue.

That is where the 73 percent comes from.

The figure does not mean 73 percent of all mid-market companies were attacked. It does not mean 73 percent of every ransomware incident worldwide involved a mid-sized organization. It means 73 percent of the report’s disclosed incidents with known revenue were mid-market victims.

That difference is not a footnote. It is the difference between a useful risk signal and an exaggerated claim.

What the dataset actually shows?

Within the report’s defined population, the concentration is persistent.

Mid-market organizations represented 74.6 percent of qualifying victims in 2023, 72.1 percent in 2024, 74 percent in 2025 and 72.3 percent in the first half of 2026. The mid-market share therefore stayed within a relatively narrow range even as the total number of disclosed incidents changed.

That consistency is more informative than the single headline number. It suggests the mid-market is not appearing in the data because of one unusual quarter or one especially active ransomware group.

The lower portion of the mid-market also matters. Black Kite reports that companies earning $10 million to $50 million represented the largest share of mid-market victims each year, accounting for between 50.5 percent and 57.2 percent of the segment’s victims across the periods examined.

Manufacturing represented 25.8 percent of the 9,781 mid-market incidents. Professional and technical services and construction were also prominent. North America accounted for 7,079 of the mid-market incidents.

Those details strengthen the case that ransomware risk is not limited to global enterprises with massive IT estates.

What the dataset cannot tell us?

A disclosed-incident dataset has limitations.

First, ransomware is underreported. Organizations may not publicly disclose every incident, and revenue information may be unavailable or unreliable for some victims. Black Kite excludes records without a verifiable revenue figure from the percentage calculation.

Second, the data measures incidents, not the probability that any individual mid-market company will be attacked. To estimate attack probability, researchers would need a denominator representing the full population of comparable businesses and a consistent way to observe both attacked and non-attacked firms.

Third, disclosure patterns can vary by jurisdiction, industry and victim behavior. Publicly visible ransomware records are useful for describing known incidents, but they are not a perfect census of cybercrime.

None of those limitations makes the finding meaningless. They tell us how far the conclusion can responsibly travel.

The vulnerability statistics come from a different dataset

The report’s second major set of numbers deserves the same scrutiny.

Black Kite assessed 120,128 mid-market organizations from an external perspective in June 2026. This was not the same population as the 13,336 incident records, and the assessment was not designed to prove that a specific external weakness caused a specific ransomware attack.

The company found that 54.7 percent of the assessed organizations had at least one significant patch-management issue involving public-facing software. Some 48.1 percent had at least one disclosed vulnerability rated 8.0 or higher on the CVSS scale. Another 28.3 percent exposed a known exploited vulnerability, and 32.3 percent had credentials appearing in information-stealer logs.

Those categories can overlap. They should not be added together.

The external scan is a snapshot, not a trend line. Black Kite explicitly notes that the June 2026 exposure dataset is separate from the incident history.

What can we reasonably conclude? A substantial share of the assessed mid-market organizations exposed weaknesses that could matter to attackers. What can we not conclude? That those exact weaknesses caused the ransomware incidents in the report’s victim dataset.

That methodological line is important because security marketing often jumps from correlation to causation.

Does independent evidence support the broader risk argument?

Yes, although not the exact 73 percent figure.

The Canadian Centre for Cyber Security’s Ransomware Threat Outlook 2025 to 2027 assesses ransomware actors affecting Canadian organizations as almost certainly opportunistic and financially motivated. It also states that organizations of all sizes are at risk and that ransomware activity in Canada is rising overall.

The Cyber Centre reports that ransomware has evolved beyond simple file encryption to include data theft and extortion. It also emphasizes baseline practices such as software updates, multifactor authentication, backups and phishing awareness.

CISA recommends similar controls for U.S. organizations, including multifactor authentication, offline encrypted backups and regular recovery testing.

Those government sources do not validate Black Kite’s exact incident percentages. They do independently support the underlying proposition that ransomware is a broad organizational risk, not a threat confined to the largest enterprises.

What about the claim that customers are paying more attention?

This part also needs careful wording.

There is clear evidence that cybersecurity is embedded in supplier-risk guidance. The Canadian Cyber Centre tells businesses to inventory third parties, classify them by criticality, set minimum security requirements, ask suppliers how they protect data and include security expectations in contracts.

CISA provides a vendor-assessment template for small and medium-sized businesses that includes questions on security policy, network access, staff training, incident detection and recovery.

That is strong evidence that buyers are encouraged to evaluate supplier cybersecurity.

It is not evidence that every company now sends detailed security questionnaires, nor does it quantify how many sales are lost because a supplier cannot answer them.

A careful article should therefore say that cybersecurity can affect supplier qualification and procurement, not that a specific percentage of customers will walk away.

The most useful conclusion is less dramatic than the headline

The strongest takeaway is not that mid-market companies are doomed or that three quarters will be hit.

It is that the mid-market appears consistently in a large disclosed-incident dataset, while a separate external scan shows common security exposures across a broad population of similarly sized organizations.

That combination is enough to challenge complacency.

A business with $20 million, $100 million or $700 million in revenue can hold valuable data, operate critical systems and connect to larger customers. It may also have fewer dedicated security resources than a global enterprise.

That creates an attractive operating environment for opportunistic criminals.

What should readers do with the 73 percent figure?

Use it as a signal, not as a probability forecast.

It tells executives that ransomware victims in the mid-market are not rare exceptions within Black Kite’s disclosed dataset. It justifies a closer look at externally visible systems, credentials, patching, backups and incident planning.

It also supports a broader management question: can the business prove to customers and suppliers that basic controls exist and are maintained?

That is where the story becomes more useful than the statistic.

The exact number may change as disclosure patterns, ransomware groups and business populations change. The management disciplines do not.

Patch critical systems. Protect accounts with strong MFA. Test backups. Limit privileged access. Build an incident-response plan. Review important vendors. Know which systems the business cannot operate without.

The 73 percent headline is worth attention. The methodology is worth just as much.

Read together, they point to a serious but manageable conclusion: mid-market ransomware risk is real, and the best response is evidence-based preparation rather than inflated fear.

Comments are off for this post.

Stay in the loop