Midmarket IT Faces Enterprise-Scale Threats On A Smaller Budget. Here’s How Leaders Are Rethinking Zero Trust.
For midmarket IT leaders, zero trust may be one of cybersecurity’s most overused and misunderstood terms.
But beneath the marketing language, the concept remains highly relevant as organizations contend with increasing threats from phishing, identity theft, remote work, cloud adoption and a growing number of connected devices.
During a recent discussion on the Ready.Set.Midmarket! Podcast, Denny LeCompte, CEO of access control vendor Portnox, and James Cusack, CIO of Van Eerden Foodservice, argue that midmarket organizations face the same security challenges as larger enterprises—without the same resources to address them.
“The midmarket has 80 percent of the same problem and 20 percent of the budget,” LeCompte said.
Here are several key takeaways from the episode:
No. 1: Zero trust is really about preventing breaches, not just detecting them
LeCompte said zero trust has become so heavily marketed that it can be difficult to define.
His practical definition: reduce the probability of a successful attack and reduce the damage if one occurs.
For years, organizations emphasized threat detection under the assumption that breaches were inevitable. But LeCompte said today’s focus has shifted to prevention, particularly following high-profile incidents like the SolarWinds breach.
“Zero trust is all about trying to minimize the probability that I get hacked and then the blast radius if I do.”
For midmarket leaders, that means ensuring users only have access to the systems they need rather than granting broad access after authentication happens.
No. 2: Identity is becoming the new security perimeter
Both LeCompte and Cusack emphasized that identity has replaced the traditional network perimeter as the primary security focus.
For organizations operating warehouses, delivery fleets, branch offices or distributed workforces, users and devices now connect from numerous locations and networks.
Cusack noted that food service operations rely on a growing mix of connected technologies, including warehouse devices, handheld scanners, tablets and logistics systems.
As a result, organizations must continuously authenticate users and devices rather than trusting anyone or anything already inside the network.
LeCompte said that organizations should increasingly verify the identity of the user, the security posture of devices, and whether devices comply with organizational policy.
“We try to help customers lock down the right person on the right device that’s managed and following policy,” he said.
No. 3: Passwords remain one of the biggest weaknesses
According to LeCompte, many breaches still originate from stolen credentials, often obtained through phishing attacks.
He recommends organizations begin moving toward passwordless authentication models that combine device-based trust with biometric verification such as fingerprint or facial recognition.
This strategy makes the device itself part of the authentication process, creating an added layer of security.
“If a user has a password, even the smartest user on their worst day might give it away to a phishing scammer,” LeCompte said.
Cusack acknowledged that user adoption remains a problem, particularly in environments where employees already struggle with the authentication process.
No. 4: VPN replacement is becoming a practical security discussion
The conversation also focused on the growing shift from traditional VPNs to Zero Trust Network Access (ZTNA).
VPN is a technology designed around an older perimeter-centric security model, LeCompte explained.
Access through VPN often provides users (and attackers) with broader network visibility than what they may actually require.
ZTNA takes a different approach by granting access to specific applications rather than to the entire network.
Cusack said his organization is seeing benefits from cloud-based security tools and application-level access controls that allow employees to securely access resources with VPN.
“VPN really is opening the front door,” Cusack said. “Once you’re in the front door, you can go into any room you want. We don’t want that.”
No. 5: Security investment must deliver high value for limited budgets
Perhaps the most important takeaway for midmarket leaders was the need to prioritize security investments that provide the greatest risk reduction.
LeCompte recommended focusing on controls that reduce credential theft risk, limiting lateral movements inside the network, and automating policy enforcement where possible.
“You can always do more,” he said. “Nobody’s going to have perfect security. You’re trying to get a very high bang for the buck.
The full episode can be watched on YouTube and heard on Spotify and Apple Podcasts.
Previous RSM! episodes are here.