Cybercrime Inc.: Hackers Now Have HR Departments
These are structured, well-organized criminal outfits that run like legitimate businesses.
In nearly two decades covering technology, the threat landscape has evolved from simple viruses and nuisances written by script kiddies into a far more complex, sophisticated—and increasingly aggressive—battle zone. Recent reports that cybercriminal organizations now have human resources departments underscore just how far this evolution has gone.
According to research from Kaspersky analyzing hundreds of thousands of employment-related websites on the dark web, cybercriminal gangs conduct formal job interviews, requiring candidates to submit CVs and portfolios demonstrating their skill level.
Additional research from ReliaQuest found that recruitment posts on cybercriminal forums have already matched last year’s total in just seven months—and demand is surging for AI specialists, English-speaking social engineers, and IoT-focused attackers.
This is no longer about lone wolves in dark hoodies. These are structured, well-organized criminal operations that run like legitimate businesses.
And midmarket organizations are in their crosshairs.
The Castle Has Already Been Stormed
The traditional model of network security—strengthening the perimeter and keeping threats out—is no longer sufficient.
Threat actors are already inside many environments—sitting, waiting, watching, and moving laterally, often gaining access through the supply chain.
The Target breach remains a clear example. Attackers entered through an HVAC vendor with network access, then moved laterally to payment systems, resulting in more than 40 million compromised customer records.
Trust No One, Suspect Everyone
The principle of “trust no one, suspect everyone” aligns closely with the tenets of zero trust security—well before the term became mainstream.
Zero trust has become a survival strategy for midmarket organizations, which often operate with lean security resources.
As MES Computing has reported, midmarket CISOs are increasingly prioritizing zero trust as a foundational architecture. On the Ready.Set.Midmarket! podcast, security leaders highlighted a shift from broad coverage to deeper control—where zero trust plays a central role.
Gary Barlet, federal CTO at Illumio and a retired U.S. Air Force lieutenant colonel, told MES Computing that zero trust segmentation extends this model further. He compares it to a checkerboard, with each piece isolated in its own square and strict rules governing what can move between them.
[RELATED: There's Zero Trust And Then There's Zero Trust Segmentation]
The threat actor ecosystem is becoming more organized and more aggressive. Defensive strategies need to keep pace.
Zero Trust Fundamentals for the Midmarket
Identity security is critical. Most breaches involve compromised credentials. Identity and access management (IAM) remains a core pillar of zero trust. Vendors such as CyberArk and ManageEngine are developing platforms tailored to midsized organizations.
Limit lateral movement. Segmentation tools from vendors like Illumio and Zero Networks create boundaries around applications and systems, reducing the impact of a compromised entry point.
Audit third-party access. Organizations need clear visibility into who has access to their networks, what they can reach, and when that access should be revoked.