The gaps aren’t in the basics. They are in what nobody had time to check.
Most mid-market businesses already have the basics in place. Endpoint protection is running. Firewalls are up. Backups are taken.
But the gaps attackers exploit sit elsewhere. A lookalike domain nobody registered. An endpoint outside your EDR’s reach. An account nobody removed when the contractor left. A phishing email that arrives at the wrong moment.
Closing those gaps requires continuous effort, specialist expertise and a clear view of your environment, something most IT teams simply don’t have the time or resources to maintain. So the gaps stay open. And the business keeps running on the assumption that detection will catch what gets through.