All Posts
6 min
min read
September 25, 2026
A PwC study reveals that mid-sized companies overestimate their cyber defenses by one to two maturity levels—with consequences for supply chains, budgets, and personnel.

If you believe your cyber defense is strong enough, you are likely significantly overestimating it. This is shown by a recent PwC study in which 400 executives from mid-sized companies were surveyed about their IT security: self-assessments are on average one to two maturity levels higher than what independent benchmark analyses actually measure. At the same time, the threat landscape is growing—via supply chains, AI-supported attacks, and simply insufficient budgets.
This article summarizes the key findings of the study and shows where mid-sized companies should draw concrete conclusions from these misjudgments—from controlling remote access by suppliers to the decision to outsource parts of their defense to a managed security partner.
Key Takeaways
For the "Deceptive Security" study, PwC surveyed 400 executives from mid-sized companies about their cybersecurity and compared their responses with independent maturity benchmarks—including technical IT infrastructure inspections, security documentation reviews, and interviews with departments. The result: self-assessments are consistently one to two maturity levels higher than the measured level of protection.
This gap is no mere academic detail. Overestimating your level of protection leads to delayed investment decisions, underestimated residual risks, and being caught unprepared in the event of an incident that you believed was already under control on paper.

This misjudgment is particularly evident in the supply chain. Nearly half of the companies surveyed reported cybercrime incidents originating within their own supplier network—not in-house. Only one in two companies feels confident in its ability to identify such risks early on. For attackers, the math is simple: a compromised remote maintenance access point at a service provider often opens up not just one system, but an entire network.
This is exactly where a remote PAM platform like VISULOX comes in: It limits every external access by suppliers and service providers to a single authorized system, rather than granting blanket VPN access to the network, and keeps every session verifiable through audit-proof recording . Our article on PAM, PIM, and IAMexplains the technical differences between privileged access and standard user rights.
According to PwC, two-thirds of companies with increasing security budgets cite AI-related risks as the primary driver for their investment decisions—and for good reason. Attackers are using artificial intelligence to detect vulnerabilities faster, launch mass-scale campaigns, and craft phishing emails that even attentive employees can barely distinguish from legitimate communication.
The defense side is catching up: pattern recognition in data streams and automated incident response have become standard tools in the modern security team's toolkit. Those who cannot keep up with this escalation are increasingly relying on external specialists.
The investment figures are surprising, even to experienced auditors: some larger mid-sized companies settle for less than 50,000 euros per year for their entire cyber defense. This amount is not enough to fund a professional monitoring platform or a tested emergency plan, let alone specialized analysts.
The math rarely adds up: in a worst-case scenario, a successful attack costs many times the amount saved due to operational downtime, recovery efforts, and, in the worst case, fines under NIS-2 or GDPR. Anyone who takes their obligations from the NIS-2 checklist seriously cannot avoid a realistic budget.
Even with a sufficient budget, many mid-sized companies simply lack the staff. On average, only three full-time employees are available for information security—not enough to monitor sophisticated threat scenarios around the clock. Consequently, according to PwC, around 78 percent of companies rely on external managed security providers to handle monitoring, vulnerability analysis, and incident response as an ongoing service.
Outsourcing does not mean abdicating responsibility. It means relieving your own organization of routine tasks and freeing up internal capacity for governance, vendor management, and a more realistic self-assessment.
All findings point to a common message: cybersecurity is not a topic that can be delegated to the server room. Realistic assessments instead of wishful thinking, targeted rather than symbolic budgets, and a clear view of your own supply chain belong on the management agenda—not just the IT department's. For those looking to close this maturity gap, a centrally controlled remote PAM platform like VISULOX offers a concrete first step.
Contact
Speak directly with a cybersecurity expert.
The PwC study reveals a dangerous gap between perceived and actual cyber defense in German SMEs: a discrepancy of one to two maturity levels, with nearly half of companies reporting supply chain incidents, budgets under 50,000 euros, and an average of only three security specialists. Closing this gap requires an honest assessment, controlled access for suppliers and service providers, and, where necessary, an external managed security partner. Our PAM beginner's guide shows how privileged remote access can be specifically secured using a German remote PAM platform like VISULOX.
Table Of Content:
Talk to Our Experts
Speak directly with a VISULOX security expert and find out how to protect your infrastructure.
Share:
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Expert knowledge, practical tips, and the latest trends in PAM, compliance, and secure remote work — straight from the amitego team.