All Posts

Security Trends

6 min

 min read

September 25, 2026

SMEs overestimate their cyber defense (PwC study)

A PwC study reveals that mid-sized companies overestimate their cyber defenses by one to two maturity levels—with consequences for supply chains, budgets, and personnel.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Introduction

If you believe your cyber defense is strong enough, you are likely significantly overestimating it. This is shown by a recent PwC study in which 400 executives from mid-sized companies were surveyed about their IT security: self-assessments are on average one to two maturity levels higher than what independent benchmark analyses actually measure. At the same time, the threat landscape is growing—via supply chains, AI-supported attacks, and simply insufficient budgets.

This article summarizes the key findings of the study and shows where mid-sized companies should draw concrete conclusions from these misjudgments—from controlling remote access by suppliers to the decision to outsource parts of their defense to a managed security partner.

Key Takeaways

  • Self-assessments of cyber defense capabilities are on average one to two maturity levels higher than what independent PwC benchmarks actually measure (based on 400 surveyed mid-sized company executives).
  • Almost half of all companies have already experienced cybercrime incidents via their supplier network—yet only one in two can detect such risks quickly enough.
  • Two-thirds of companies with increasing security budgets cite AI-related risks as the primary investment driver; attackers have long been using AI to scale phishing and vulnerability scanning.
  • Even larger mid-sized companies sometimes invest less than 50,000 euros annually in their cyber defense—too little for professional monitoring and emergency plans.
  • On average, a mid-sized company has only three full-time employees available for information security; 78 percent therefore outsource parts of their defense to managed security providers.
  • Controlled, logged access for suppliers and service providers—for example, via a remote PAM platform like VISULOX—specifically mitigates the supply chain risk mentioned in point two.

Between wishful thinking and reality: the maturity gap in the mid-market

For the "Deceptive Security" study, PwC surveyed 400 executives from mid-sized companies about their cybersecurity and compared their responses with independent maturity benchmarks—including technical IT infrastructure inspections, security documentation reviews, and interviews with departments. The result: self-assessments are consistently one to two maturity levels higher than the measured level of protection.

This gap is no mere academic detail. Overestimating your level of protection leads to delayed investment decisions, underestimated residual risks, and being caught unprepared in the event of an incident that you believed was already under control on paper.

The supply chain risk: when one supplier drags everyone down

This misjudgment is particularly evident in the supply chain. Nearly half of the companies surveyed reported cybercrime incidents originating within their own supplier network—not in-house. Only one in two companies feels confident in its ability to identify such risks early on. For attackers, the math is simple: a compromised remote maintenance access point at a service provider often opens up not just one system, but an entire network.

This is exactly where a remote PAM platform like VISULOX comes in: It limits every external access by suppliers and service providers to a single authorized system, rather than granting blanket VPN access to the network, and keeps every session verifiable through audit-proof recording . Our article on PAM, PIM, and IAMexplains the technical differences between privileged access and standard user rights.

AI vs. AI: the new dimension of threats

According to PwC, two-thirds of companies with increasing security budgets cite AI-related risks as the primary driver for their investment decisions—and for good reason. Attackers are using artificial intelligence to detect vulnerabilities faster, launch mass-scale campaigns, and craft phishing emails that even attentive employees can barely distinguish from legitimate communication.

The defense side is catching up: pattern recognition in data streams and automated incident response have become standard tools in the modern security team's toolkit. Those who cannot keep up with this escalation are increasingly relying on external specialists.

The boomerang effect of budget cuts: insufficient IT security budgets

The investment figures are surprising, even to experienced auditors: some larger mid-sized companies settle for less than 50,000 euros per year for their entire cyber defense. This amount is not enough to fund a professional monitoring platform or a tested emergency plan, let alone specialized analysts.

The math rarely adds up: in a worst-case scenario, a successful attack costs many times the amount saved due to operational downtime, recovery efforts, and, in the worst case, fines under NIS-2 or GDPR. Anyone who takes their obligations from the NIS-2 checklist seriously cannot avoid a realistic budget.

Staff shortages force outsourcing

Even with a sufficient budget, many mid-sized companies simply lack the staff. On average, only three full-time employees are available for information security—not enough to monitor sophisticated threat scenarios around the clock. Consequently, according to PwC, around 78 percent of companies rely on external managed security providers to handle monitoring, vulnerability analysis, and incident response as an ongoing service.

Outsourcing does not mean abdicating responsibility. It means relieving your own organization of routine tasks and freeing up internal capacity for governance, vendor management, and a more realistic self-assessment.

What this means for the executive suite

All findings point to a common message: cybersecurity is not a topic that can be delegated to the server room. Realistic assessments instead of wishful thinking, targeted rather than symbolic budgets, and a clear view of your own supply chain belong on the management agenda—not just the IT department's. For those looking to close this maturity gap, a centrally controlled remote PAM platform like VISULOX offers a concrete first step.

Contact

Your Direct Path to Secure Remote Access

Speak directly with a cybersecurity expert.

Personal Meeting
Personal Meeting
Personal Meeting

Conclusion

The PwC study reveals a dangerous gap between perceived and actual cyber defense in German SMEs: a discrepancy of one to two maturity levels, with nearly half of companies reporting supply chain incidents, budgets under 50,000 euros, and an average of only three security specialists. Closing this gap requires an honest assessment, controlled access for suppliers and service providers, and, where necessary, an external managed security partner. Our PAM beginner's guide shows how privileged remote access can be specifically secured using a German remote PAM platform like VISULOX.

Jan Zeppernick - Amitego CEO

Jan Zeppernick

Management

Jan has over 12 years of consulting experience at PwC and Ernst & Young, focusing on information security and compliance for critical infrastructure and the automotive industry. As a certified ISO 27001 Lead Auditor and strategy expert, he advises organizations on establishing and auditing security management systems in accordance with ISO 27001 and TISAX.