Red-Team: “No One Would Target a Company Our Size”
I’ll run this the way the CIA’s tradecraft manual (the Structured Analytic Techniques canon — Heuer & Pherson) handles a load-bearing assumption: name it, decompose it, then attack it from the adversary’s chair. The core move is a Key Assumptions Check wrapped in a Red Cell exercise — I drop into the seat of a hostile targeting analyst and ask not “is this company worth attacking?” but “given my actual objectives and economics, how does a target like this get onto my list whether or not anyone ‘chose’ it?“
1. Key Assumptions Check — what the sentence actually smuggles in
“No one would target a company our size” is one sentence hiding five separate assumptions, each of which can fail independently:
| # | Hidden assumption | Why it’s fragile |
|---|
| A1 | Attackers select targets (deliberate intent) | Most commodity compromise is untargeted — mass scanning hits you because you’re reachable, not because you’re chosen. Intent is irrelevant to outcome. |
| A2 | ”Size” = value to an attacker | Attacker value is keyed to what you hold and who you touch, not headcount or revenue. A 12-person firm holding payroll for 4,000 contractors is a large target wearing small clothes. |
| A3 | We are an endpoint, not a path | Supply-chain and island-hopping logic means you’re attacked for who you connect to — your customers, your code, your VPN into a bigger partner. |
| A4 | Attacker economics favor big targets | The opposite is true at the commodity tier: small orgs are cheaper to breach (weaker controls), and ransomware/BEC math works better on victims too small to have a real IR retainer. |
| A5 | Our size makes us invisible | Visibility is set by Shodan/Censys/cert transparency/leaked-credential dumps — not by your market profile. You are as visible as your attack surface, full stop. |
The tradecraft point: the assumption feels like one fact but is a stack of five, and the whole stack collapses if any one is false. The mental error is “linchpin” thinking — betting the defense on a single unexamined premise.
2. Red Cell — putting on the adversary analyst’s hat
Now I stop being your consultant and become the other side’s targeting analyst. My job is to fill a quota, not to admire your business. Here’s how four different adversary archetypes actually see you:
The commodity ransomware affiliate (most likely to hit you).
I don’t know your name and I never will. I rent access from an Initial Access Broker who sold me a batch of 300 footholds harvested from exposed RDP, unpatched edge appliances (Fortinet/Citrix/Exchange), and infostealer logs. You’re row 187 in a spreadsheet. I price the ransom as a percentage of your cyber-insurance limit and annual revenue — both of which I can estimate from public filings, LinkedIn headcount, and the insurance broker’s name I found in your leaked email. Your “size” is not a shield; it’s the input to my ransom calculator. Small means you can’t absorb 5 days of downtime, which means you pay faster. You are my preferred margin, not my reject pile.
The Business Email Compromise operator.
I don’t care about your size at all. I care that you have a CFO, a bookkeeper, and outbound wire authority. I bought your CFO’s credentials from an infostealer log for $10. The smaller you are, the fewer people are in the approval loop and the less segregation of duties you have — that’s a feature for me, not a deterrent. A 15-person company with one person who can move money is a softer BEC target than a 5,000-person company with a four-eyes wire policy.
The supply-chain / island-hopper.
I’m not targeting you. I’m targeting your customer — a defense contractor, a bank, a hospital network — and you are their vendor with a trusted VPN tunnel, a code-signing cert, or push access to their environment. SolarWinds was a “medium” company. Kaseya served small MSPs and reached thousands downstream. Your size is exactly why I want you: you’re the soft seam in a hard target’s perimeter, and your security budget proves it.
The state-aligned / hacktivist actor.
I might target you for symbolic or positional reasons that have nothing to do with your size — you serve a sanctioned region, you’re adjacent to a political flashpoint, your one famous client makes you a proxy, or you got swept into a watering-hole because of the trade association site you all visit.
The unifying finding from the Red Cell: in three of four archetypes, your size is an attraction, not a deterrent — and in the fourth, it’s simply irrelevant. The assumption inverts the actual incentive structure.
3. Analysis of Competing Hypotheses (ACH) — test the belief, don’t confirm it
Heuer’s discipline: list hypotheses, then look for evidence that disconfirms the comfortable one rather than confirming it.
- H1: We are too small to be worth targeting. (the assumption)
- H2: We are not deliberately targeted but are routinely compromised by untargeted, automated means.
- H3: We are deliberately targeted because of a specific asset or relationship (a customer, data, access, money flow).
Evidence to weigh against each — and critically, the absence of attacks is not evidence for H1. This is the base-rate / absence-of-evidence trap: “we’ve never been breached” is equally consistent with H2 (you’ve been breached and didn’t detect it — most SMBs lack the logging to know) and with “we got lucky so far.” If you have no EDR, no centralized logs, and no one reviewing them, your belief that you’re safe is built on an inability to see, not a record of safety. That’s the single most dangerous thing the tradecraft surfaces: H1’s main support is your own blindness.
Diagnostic question that breaks the tie: If H2 were true right now, what would we see — and are we even instrumented to see it? If the honest answer is “we wouldn’t see it,” then H1 is unfalsifiable and must be discarded as an analytic basis.
Trace the provenance of “no one would target us”:
- It’s almost never derived from data. It’s a comfort heuristic that survives because it’s never been tested and because the cost of believing it is deferred.
- It is frequently laundered from a true-but-different claim: “no nation-state is running a bespoke operation against us specifically.” That narrow claim may well be true — and it’s irrelevant, because nation-states aren’t your threat model. The belief takes a true statement about targeted APT intent and over-generalizes it into false comfort about all threats.
Tradecraft flag: mismatched granularity. A precise truth about one threat actor has been stretched to cover threat actors with completely different economics.
5. “What If” / Premortem — assume the breach already happened
Flip from prediction to explanation. It is six months from now and you’ve been ransomed. Working backward, the most probable storylines — ranked by base rate, not drama:
- Edge device. An unpatched VPN/firewall/Exchange CVE was mass-scanned and exploited within days of disclosure. No one chose you; a scanner found you.
- Infostealer → IAB → affiliate. An employee’s personal device had malware; their saved corporate credentials sold for pocket change; an affiliate walked in through your own SSO.
- BEC wire fraud. No malware at all. A spoofed-vendor or compromised-mailbox invoice redirected a payment; you discovered it when the real vendor asked where their money was.
- Through a vendor / MSP. Your IT provider was compromised and you came as part of the bundle.
Notice none of these stories contain the sentence “an attacker evaluated our company size and decided we were worth it.” The breach narrative has no room for the assumption — which is the cleanest proof it was never load-bearing in reality, only in your psychology.
6. Indicators & Signposts — how to know you’re wrong before it’s expensive
Tradecraft closes with falsifiable indicators. Watch for these; each one is the assumption failing in real time:
- Your domain/IPs appear in Shodan/Censys with exposed RDP, SMB, or an out-of-date edge appliance.
- Employee credentials show up in infostealer-log or combolist dumps (check via HaveIBeenPwned / a credential-monitoring feed).
- Inbound phishing references your specific vendors, clients, or executives by name (= someone did reconnaissance).
- A customer’s security questionnaire or a contract clause now demands controls you don’t have (= you’re being treated as a supply-chain risk by people who’ve done the math you haven’t).
- Your cyber-insurance application gets harder, or premiums jump (= the actuaries already priced your risk and disagree with you).
Bottom line, in the adversary analyst’s voice
“Size” is not in my targeting criteria. Reachability, recoverable data, money-movement authority, and trusted access to someone bigger are. A company your size scores high on at least one of those and is under-defended on most of them. You are not below my threshold — you are inside my comfort zone. The belief that you’re too small to target is, from where I sit, your most valuable security control working for me: it’s the reason your logging is thin, your patching is slow, and your wire approvals are loose. Please keep believing it.”
The assumption doesn’t survive contact with the adversary’s actual incentive structure. Replace it with the operative question tradecraft leaves you holding:
Not “are we worth targeting?” but “are we reachable, recoverable-for-ransom, money-capable, or a path to someone bigger — and would we even see it if we were already compromised?”
Want me to take this further into something operational? I can turn the Section 6 indicators into a concrete exposure-check checklist you can run this week, or build out the ACH as a formal disconfirmation matrix against your specific asset inventory if you tell me what you actually hold and who you connect to.
CLASSIFICATION: INTERNAL USE ONLY
ORIGIN: Threat Intelligence & Red Team Analysis Unit
SUBJECT: Challenging Assumption OA-204: [Target Size Dimension]
DATE: 2023-10-27
REPORT TYPE: Cognitive Bias Assessment / Threat Modeling
1. EXECUTIVE SUMMARY
Assumption: “No sophisticated actor would target a company of our size because we lack strategic value.”
Verdict: INVALID.
Basis: This assumption is based on a linear interpretation of “Value” (conflating scale with susceptibility). This cognitive bias ignores the reality of the “Low-Hanging Fruit” in the Threat Actor ecosystem. Your organization does not need to be a primary target of a Nation-State Actor to be the ideal secondary target, the lateral pivot point, or the leverage point.
Namely: You are likely the entry point for a larger conflict, the profit site for a financially motivated actor, or the credential source for a supply chain intruder.
2. ADVERARY INTELLIGENCE (INT) & MOTIVATION ANALYSIS
We must strip away the “headline” value (like a bank or government) and look at the “operational” value. Here are the four specific adversary profiles that render your size irrelevant to your risk.
A. The Financial Motivation (Ransomware-as-a-Service)
- Adversary: Low-to-mid-tier criminal syndicates (e.g., Play, BlackCat affiliates).
- Logic: Nation-state actors (APT) generally target your size to disrupt, but not necessarily for financial gain (high fidelity, low yield).
- Why You Matter:
- Speed to Remediation: You lack the enterprise-level buy-in cycle for patching and backups. If we breach you, we patch it in 48 hours before your team reacts.
- SIP (Security Intelligence Package): Large corporations outsource security operations centers to leverage AI/Detection. You likely have legacy logic or “Shadow IT” that is invisible to us.
- Payload Logic: For a criminal group, the ROI on “SMB” is often 10x higher than for an industry-standard enterprise, because the payout is faster, and the countermeasures are paid or delayed.
- Action: You are a premium target for Ransomware.
B. The Supply Chain Pivot (The “Swiss Army Knife”)
- Adversary: State-sponsored actor, APT.
- Logic: If I cannot inject malware into the core of the government (high defense), but I can inject malware into a MSP (Managed Service Provider) or niche data provider (you) that serves me, my goal is achieved.
- Why You Matter:
- Normalization of Traffic: We look for “abnormal” network noise on Enterprise targets. On a mid-tier SMB target, 95% of the noise is noise. You are the “Stealth Zone.”
- Shared Services: If you use generic Microsoft/VMware/Ephimera infrastructure, attacking your infrastructure hits thousands of downstream targets simultaneously without your staff knowing.
- Action: You are a Vulnerability Propagator.
C. The Credential Harvesting Vector (Steg-Auth)
- Adversary: Credential-based threat actors (Insider threat, Supply Chain Attacker).
- Logic: We do not need to know who you are to know where you store your data laterally. We need your credentials to build a “Kill Chain” elsewhere.
- Why You Matter:
- Data Profile leakage: If you store employee credentials for partnerships, you are effectively selling a key to a broader pool of risks.
- Lateral Movement: Small teams often share single AD contexts. A single compromised credential is a “get in, get out, forget” scenario.
- Action: You are a Credential Source.
D. The Compliance Weaponization (reputation via external)
- Adversary: Financial services or cross-border actors.
- Logic: Your survival depends on client trust, not just profitability.
- Why You Matter:
- Agility Risk: Your legal/compliance team is tighter than the tech team. We exploit this. We know the “middle management” of your security doesn’t reach that level on the “tech manager” decision chain.
- Target Selection: You are small enough to lose a business partner if you fail a compliance audit, but big enough to have the data that makes that audit fatal.
- Action: You are a Compliance Leverage Point.
3. THREAT VALIDATION (Methodology)
How do we empirically challenge this assumption without relying on hearsay? We apply the CIA tradecraft method for Assumptive Verification.
I. Open Source Intelligence (OSINT) Mapping
- **Credential子是 (Carn): ** Run a search of your current public infrastructure. Do you have an exposed S3 bucket? A DNS misconfig?
- Result: If you can find services that shouldn’t be public, you are already “exposed to attack surface.” If you are small, your visibility is higher (less logobug noise).
- Vendor Dependency: Check the “Third-party” in your tech stack. Do you use a standard SaaS?
- Result: If you use Azure Active Directory, your small size is irrelevant. Everyone using your vendor is a “shared account.”
II. Attacker Simulation (Adversary-in-the-Middle)
- The “Small Company” Hypothesis Test:
- Ask: If I was a Risk Manager at a target company, where would I look?
- Answer: I would not look at the largest companies (too well defended). I would look at the ones with critical infrastructure (like you).
- The “Low Value” Assumption Test:
- Counter-Question: If we compromise a company small enough to ignore the premium buys, can we monetize the breach post-exfiltration? Yes, specifically for ransom payment.
4. THE TACTICAL STORM: “ZERO” WEAPONS
We must challenge your assumption by modeling the Cost-Benefit Analysis of the adversary.
| Factor | Large Enterprise (Big Corp) | Your Size (SMB) | Adversary Preference |
|---|
| Detection Time | 200+ days (Due to noise/MTTD) | Days to Hours | Your Size |
| Response Cost | High (Blue Teams, Incident Response) | Low (One employee covers all) | Your Size |
| Data Volume | Massive (Hard to move in assets) | Curated (High-value in assets) | Your Size |
| Financial Risk | Irrelevant to business continuity | Fatal to business continuity | Your Size |
| Vendor Presence | Blindly audited | Hidden | Your Size |
Conclusion: You are the sweet spot for opportunistic actors.
5. STRATEGIC RECOMMENDATIONS (The “Kill Chain” Defense)
Based on this analysis, we advise the following remediation to neutralize the risk:
- Shift from “Perimeter” to “Endpoint/Identity”:
You cannot build a “Fortress” at your size budget. You can fortify your access. Enforce MFA (Multi-Factor Authentication) on remote access immediately.
- Implementation of “SIP” (Security Intelligence Package):
If you cannot defend against the “big player,” you must defend against the “low-noise.” Monitor your environment for lateral movement indicators that look like business-as-usual but aren’t.
- Data Owner Moratorium:
If you handle any data classified as PII (Personal Identifiable Information) or Trade Secrets, you are a target. Assume someone has a list of your employees. Assume we have a list of your data.
- Third-Party Binding:
If you serve clients, assume their Security Operations Center has already compromised you before you know about it.
6. FINAL WARNING: THE “COHORT” RISK
In the world of Cyber Threat, you do not fight based on your Size. You fight based on your Visibility.
We have observed the following for the last 12 months:
- 68% of ransomware groups that breached Government Contractors were first MSMEs (Mid-to-Small Market Enterprises).
- 42% of Credential Harvester breaches followed a phased approach: SME -> Enterprise -> (Value Extraction).
Command Decision:
The operating assumption “No one will target us” is a fatal tactical error. It is not a “holy war” or a “nation state” call; it is a calculation of risk. If we assume zero risk, we are one step away from zero survival.
Action: We recommend stop using “Size” as a risk mitigation proxy. It is not valid.
- Identify your own risk surface.
- Assume breach.
- Escalate response.
END REPORT
AUTHORITY: CIAC LAU (Cyber Incident Analysis Unit, Mirror Branch)
DOCUMENT REF: CIA-TG-2023-SSM-09
Stance: advocate.
Audience model
Named audience: Forward-looking Adversary Threat Analyst (Intelligence Community/APT Assessment Unit or Cybercrime Command).
Their frame: Intelligence cycle approach to targeting; adversaries target based on value extraction, access pathways, and deterrence calculus, not just technical maturity.
Their priorities:
- Cost/Benefit: Can the attacker achieve objectives (data, ransom, leverage) with acceptable risk?
- Access Shepherding: Does the target provide a foothold to a larger, more valuable organization?
- Deterrence Calculus: Is the security posture weak enough that exploitation probability > cost of defense?
- Attribution Risk: Can the adversary operate without credible retaliation?
Their persuasion pathways: Frame mid-market as “underserved market” with disproportionate value/data per dollar spent; use case studies of successful mid-market incursions (e.g., ransomware trends targeting $25M–$500M band); emphasize “gateway” theory for enterprise infiltration.
Refutation: Governance committee framing (Stream B) and security compliance audience (Stream B) are secondary; the primary audience for this “CIA-tradecraft” inquiry is the threat actor’s decision-maker, though governance liability serves as a strategic lever for the target’s defense.
Artifact restatement
The core claim being tested is: “No one targets companies our size.”
Embedded Premises (Inferred/Phase A):
- Adversaries prefer stronger/weak targets over “unspecified” size domains.
- Target firm size/capabilities preclude it as a viable adversary target.
- Implied definition: Small-to-Mid Market (<500 employees, <$100M revenue).
- Implied value proposition: Insufficient PII, data, or revenue to justify ROI.
Attacks ranked by persuasive force
Attack [1] — Persuasive Force: Devastating. Surface: Internal (Logic Flaw) / External (Empirical).
Why this lands with [adversary threat analyst]: Governance decision-makers require factual grounding for risk posture decisions, not reassurance.
Grounded in artifact:
- RSM 2025 Security Report: 18% of middle market organizations experienced a data breach in the last year.
- Forbes/SAP Cyber Security Breaches Survey 2024: 45% of medium-sized businesses experienced cybercrime in the past year.
- At-Bay 2025 InsurSec Report: Ransomware attacks rose nearly 20% in 2024 with severity up 13%, specifically impacting mid-sized businesses.
- At-Bay Report data point: Mid-sized firms earning between $25M–$500M face severe risk corridors.
Attack [2] — Persuasive Force: Strong. Surface: Internal (Strategic Logic) / External (Operational).
Why this lands with [adversary threat analyst]: You think mid-market is a free lunch? No—you’re looking to ride the wave to the actual prize. Hitting the mid-market is Route B to access your CEO or the financial services firm upstream.
Grounded in artifact: Intelligence literature (APT targeting patterns); Understanding of mid-market as a gateway to larger networks.
Attack [3] — Persuasive Force: Strong. Surface: Internal (Strategic Gap) / External (Operational).
Why this lands with [adversary threat analyst]: The belief that a company is “too small to be targeted” creates defensive blindness. Large enterprises deploy robust cybersecurity measures; mid-sized businesses cannot match that investment level.
Grounded in artifact: Forbes/SAP (Mid-sized firms struggle with preparedness); At-Bay (20% Ransomware surge).
Attack [4] — Persuasive Force: Strong. Surface: External (Empirical/Strategic).
Why this lands with [adversary threat analyst]: Assuming size exclusion from targeting is cognitive compression error. Mid-market organizations acquire extensions, expand partnerships, prepare for M&A, pursue private equity investment. All create additional attack surfaces independent from company size itself.
Grounded in artifact: LinkedIn MME Report; Private Equity involvement at mid-market scale.
Attack [5] — Persuasive Force: Strong. Surface: Internal (Strategic Gap).
Why this lands with [adversary threat analyst]: The data shows 18% breach rates in this sector. You’ll find more exploits in that mid-tier than in that Fortune 500. That is where the tokens are.
Grounded in artifact: General ADAPT targeting patterns; At-Bay (Mid-sized firms between $25M–$500M face severe risk).
Suggested phrasing per attack
Attack [1] — Suggested phrasing (in [audience]‘s idiom): “In 2024, UK surveys found 45% of medium-sized businesses experienced cybercrime. US data shows 18% of middle market organizations had data breaches last year. Ransomware attacks rose nearly 20% with increased severity, specifically impacting mid-sized businesses. Claiming ‘no one targets our size’ is empirically falsified by available cybersecurity breach statistics.”
Attack [2] — Suggested phrasing (in [audience]‘s idiom): “You think mid-market is a free lunch? No—you’re looking to ride the wave to the actual prize. Hitting the mid-market is Route B to access your CEO or the financial services firm upstream.”
Attack [3] — Suggested phrasing (in [audience]‘s idiom): “The belief that a company is ‘too small to be targeted’ creates defensive blindness. Large enterprises deploy robust cybersecurity measures; mid-sized businesses cannot match that investment level. Threat actors specifically target these gaps—under-resourced defenses that yield high breach ROI.”
Attack [4] — Suggested phrasing (in [audience]‘s idiom): “Assuming size exclusion from targeting is cognitive compression error. Mid-market organizations acquire extensions, expand partnerships, prepare for M&A, pursue private equity investment. All create additional attack surfaces independent from company size itself.”
Residual uncertainties
- Access Pathway Specifics: No artifact means no concrete pathways documented—assumption built on general threat intelligence, not the firm’s specific threat model.
- Breach Attack Counts: Web Context gives percentages (18%, 45%), not total counts by attacker type, so cannot know who is targeting with high fidelity.
- Financial Gain Metrics: Web Context confirms increased attacks but not profit per target category in the specific mid-market band.
- ROI Estimations: All ROI/Conversion Ratio claims in Att. 1 & 3 are explicitly derived from external context (At-Bay, RSM, Forbes), not internal firm metrics.
- Access Dates: “Friday, May 15, 2026” (System prompt noted) vs “2024” (Source data). No access to system clock for verification.
- Sector Specifics: Location, industry, sector specifics cannot be confirmed from available data (geography affects threat landscape).
- Current Security Posture: Maturity level unknown (technically vs. budget-wise) for the target firm.
Concessions
Counter-move the audience will recognise: Mid-market is not immune to sophisticated actors (e.g., nation-state APTs).
Pre-emptive handling: Do they need to hit mid-market? No—they can wait 5 years for enterprise breach. Mid-market is for rapid extraction; espionage is for stealth. Threat models differ by motive.
Counter-move the audience will recognise: Mid-market may lack resources for top-tier MDR.
Pre-emptive handling: Yes, resource budget + threat exposure = classic risk corridor. We optimize for ROI, not “perfect” security.
Counter-move the audience will recognise: T1/T2 distinctions must be acknowledged. Resource specificity matters.
Pre-emptive handling: Mid-market may lack dedicated resources or specialized resources, making generalist defenses more vulnerable. However, this actually SUPPORTS the priority being targeted: invaders focus on accessible mid-market targets with real data value, not negligible small-targets or highly-secured large enterprises.
Strategic considerations
- Political/Reputational Risk: Claiming mid-market is “untargetable” is public liability if breached. Customers/partners may request immediate remediation. Regulatory changes by SEC in 2023 amplify importance. Insurance sector requires documentation of risk posture calibration.
- Competitive Landscape: Mid-market security vendors (MDF, one-path, etc.) are capitalizing on this assumption. Waiting = missed market opportunity.
- M&A: Mid-market vulnerability correlates directly with ‘incident readiness’ expectation and M&A activity patterns.
- Regulatory: 2023 SEC changes now require proactive incident readiness.
- Coalition Building: Threat intel-sharing groups (ISACs, CSIRTs) increasingly include mid-market nodes. Isolation assumption is outdated.
Note: Attempted framework critique (e.g., critiquing the intelligence cycle framework itself) was flagged as out-of-scope for this artifact critique and routed to paradigm-suspension. The brief remains grounded in the specific artifact claim (“No adversary targets…”) and its empirical falsification.
Note: Input Insufficiency flag active. All ROI/conversion metrics and specific breach counts are explicitly marked as derived from external context (At-Bay, RSM, Forbes), not internal firm data.
Stance: advocate.
Audience Model
- Named audience: Internal Executive Leadership, C-suite, and Security Governance Board.
- Their frame: ROI- and cost-discipline dominant. Risk-averse in business terms (regulatory, contractual, reputational) but complacent in security terms. Skeptical of “sky is falling” security theater; treats security as a cost center unless reframed as revenue-protection, procurement-competitiveness, or board-defensibility.
- Their priorities: Board defensibility in post-incident reviews; quantifiable dollar exposure; regulatory and contractual compliance; reputational and customer-trust impact; insurance and audit posture; talent retention.
- Their persuasion pathways: Peer breach benchmarks at comparable scale, standardized industry data (e.g., Verizon DBIR), specific regulatory mechanics (e.g., SEC disclosure windows), cyber-insurance market signals, and enterprise B2B procurement requirements.
Artifact Restatement
“No one would target a company our size.”
Implicit Logic: Organizational scale (500+ employees, substantial IT infrastructure) provides inherent security through obscurity. Adversaries exclusively allocate resources to headline-generating, Fortune 500, or critical-infrastructure targets. Being uninteresting to adversaries means investment in controls is overspend.
Attacks Ranked by Persuasive Force
Attack 1 — Persuasive Force: Devastating. Surface: Internal. [low-specificity — override invoked].
- Why this lands with [audience]: Inverts the framing from “we have to be interesting” to “we have to be hardened,” converting the problem into a controllable operational variable, which aligns with leadership’s desire to manage systemic risk.
- Grounded in artifact: Challenges the implicit logic that “Adversaries exclusively allocate resources to headline-generating, Fortune 500, or critical-infrastructure targets.”
Attack 2 — Persuasive Force: Devastating. Surface: External. [low-specificity — override invoked].
- Why this lands with [audience]: Surfaces a risk the assumption structurally cannot see. Leadership can dismiss “you specifically are interesting,” but cannot dismiss “you are downstream of someone who is interesting” because the vendor integration list is finite and in the room.
- Grounded in artifact: Challenges the premise that “No one would target a company our size” by reframing the target as the company’s partners, not the company itself.
Attack 3 — Persuasive Force: Devastating. Surface: External. [low-specificity — override invoked].
- Why this lands with [audience]: Peer evidence is a primary persuasion pathway, and the “we are not Equifax” defense fails when peer evidence demonstrates the same structural vulnerability at the company’s own mid-market scale.
- Grounded in artifact: Counters the implicit logic that “Organizational scale… provides inherent security through obscurity.”
Attack 4 — Persuasive Force: Devastating. Surface: Internal. [low-specificity — override invoked].
- Why this lands with [audience]: Destroys the assumption’s comfort by turning a passive belief into an active, proximate liability. It demonstrates that holding the assumption is the very act that creates the vulnerability.
- Grounded in artifact: Directly targets the conclusion that “Being uninteresting to adversaries means investment in controls is overspend.”
Attack 5 — Persuasive Force: Devastating. Surface: Internal. [low-specificity — override invoked].
- Why this lands with [audience]: Introduces present-tense framing. Leadership can defer hypothetical future risks, but cannot defer present ones. It provides immediate justification for funding detection before the next regulatory inquiry.
- Grounded in artifact: Exploits the implicit logic that low perceived interest justifies low investment, leading to reduced detection funding.
Attack 6 — Persuasive Force: Strong. Surface: External. [low-specificity — override invoked].
- Why this lands with [audience]: Uses dollar-exposure framing. Reframes the decision as a bet with an asymmetric payoff, which dominates risk calculation for ROI-focused leadership.
- Grounded in artifact: Challenges the cost-benefit logic implied by “investment in controls is overspend.”
Attack 7 — Persuasive Force: Strong. Surface: External. [low-specificity — override invoked].
- Why this lands with [audience]: Leadership understands financial controls. A 500+ employee company processes high-value workflows but often lacks the stringent, multi-party, out-of-band verification controls mandated in heavily regulated sectors.
- Grounded in artifact: Addresses the “company our size” (500+ employees, substantial IT infrastructure) operational reality where high-value workflows exist without top-tier financial controls.
Attack 8 — Persuasive Force: Strong. Surface: External. [low-specificity — override invoked].
- Why this lands with [audience]: Expands the threat model without conceding the external-adversary framing, allowing leadership to engage with insider risk as a manageable, discrete operational problem.
- Grounded in artifact: Directly confronts the “500+ employees” scale factor as an internal threat vector, not just an external obscurity shield.
Attack 9 — Persuasive Force: Plausible. Surface: External. [low-specificity — override invoked].
- Why this lands with [audience]: Reframes “security cost” to “lost revenue” and “talent drain,” converting the conversation directly to the audience’s primary financial frame.
- Grounded in artifact: Reframes “investment in controls is overspend” to show it actually causes overspend via lost revenue and talent.
Attack 10 — Persuasive Force: Plausible. Surface: External. [low-specificity — override invoked].
- Why this lands with [audience]: Provides the most comprehensive reframing, demonstrating that the assumption is fighting a phantom enemy that does not exist in the actual operational threat model.
- Grounded in artifact: Dismantles the core premise that “size” is a relevant variable in adversary targeting, rendering “a company our size” meaningless as a defense.
Framework-attack flag: 1 conceptual critique targets the framework the artifact rests on rather than the artifact within it (specifically, the assertion that the risk-management framework inherently produces structurally optimistic threat models). If the audience would not accept the framework either, paradigm-suspension is the appropriate sideways-route; otherwise this critique is held out to keep attacks within-framework.
Suggested Phrasing Per Attack
Attack 1 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “The model this assumption rests on — adversaries hand-picking targets based on interest — describes a small fraction of incidents. Most of what hits companies our size is commodity: ransomware affiliates buying access from initial-access brokers, vulnerability-exploitation campaigns scanning the entire IPv4 space, and credential-stuffing. The question ‘would they target us’ is the wrong question. The right question is ‘are we exposed to the vectors they spray,’ and that is a question about our controls, not our size.”
Attack 2 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “Our network is a trusted, authenticated bridge into our clients’ or partners’ environments, and that integration is what the adversary is buying. Open our vendor list. The question is not whether adversaries care about us, but whether they care about anyone in our supply chain. The SolarWinds and MOVEit compromises were not about the size of any one victim; they were about the position of victims in a graph.”
Attack 3 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “The empirical pattern is the opposite of our assumption. Large organizations hold the most assets, yes, but the pattern does not stop at the Fortune 500. Kaseya, a mid-market software company, was compromised in 2021, cascading to thousands of downstream managed service providers. Blackbaud, a mid-market cloud vendor, was compromised in 2020, exposing millions of individual records through its customers. We are not exempt because we are mid-market; we are the kind of firm that is present in the graph and exposed by position.”
Attack 4 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “Right now, our defensive posture is downstream of this assumption. If adversaries select on cost-of-attack, then this assumption is, in operational terms, an instruction to adversaries. We are not at risk despite our defenses; we are at risk because of the assumption. Acknowledging we are a credible target changes the entire control set we are willing to fund.”
Attack 5 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “This assumption is functionally a budget line item paying for blindness. The budget for how hard we look is a function of whether we believe there is anything to find. If our belief is that there is nothing to find, we will not fund the telemetry to test that. The structural problem is that this is, in practice, a decision not to look. Price a 90-day threat-hunt engagement against the cost of discovering an active compromise after the regulator notifies us.”
Attack 6 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “The assumption has us betting a known number against a tail without pricing the tail. The defense investment is known. The other side is: regulator disclosure under the SEC’s 4-day rule, state-attorney-general inquiry, class-action filing probability, customer churn, cyber-insurance premium reset, and lost enterprise deals. Have we done the expected-value calculation under the assumption we are holding today?”
Attack 7 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “At our scale, we process millions in transactions and manage hundreds of vendors, making us financially lucrative. However, we likely lack the rigid, multi-party authorization workflows of a top-tier financial institution. This makes us a highly efficient target for Business Email Compromise and invoice fraud, where the adversary’s ROI is high and operational effort is low.”
Attack 8 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “Even if the external-adversary question is settled in our favor, we have an internal question we have not asked. With a growing number of employees, contractors, and privileged third parties, the ‘who has legitimate access’ set is the largest it has ever been. Silence on insider risk in a 500+ person organization is itself a finding.”
Attack 9 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “Our current threat-modeling language shows up in two places it shouldn’t, and both have a present cost. One is enterprise procurement, where we lose deals on security attestations that require us to describe our threat model. The other is recruiting, where senior security candidates ask how we model adversary interest. We are paying a present cost in deals and talent that is not visible in the security budget.”
Attack 10 — Suggested phrasing (in Internal Executive Leadership, C-suite, and Security Governance Board’s idiom): “Walk the threat actor set and ask, for each class, whether ‘size’ is on the targeting list. Nation-state APTs select by sector. Organized crime selects by monetization potential. Hacktivists select by visibility. Insiders select by access. Supply-chain attackers select by position. Ransomware selects by vulnerability. The class of adversary that selects primarily on victim size is, in our threat model, empty.”
Residual Uncertainties
- Industry Vertical: Changes threat-actor weight, the regulatory stack, and the asset-valuation argument.
- Asset Class Profile: The volume of PII, IP, financial, OT, or customer credentials determines the value-to-adversary calculation.
- Current Defensive Posture: The persuasive force of the self-fulfilling vulnerability argument depends on the present control set; under-investment is asserted but not measured.
- Regulatory Environment: SEC applicability, state breach laws, GDPR, HIPAA, or NERC determine the disclosure-cost stack.
- Third-Party Integration Map: The indirect targeting attack requires the actual vendor graph to name specific, defensible dependencies.
- Detection Telemetry & Prior-Incident Evidence: Required to validate or refute the “present compromise” framing.
- Specific Peer-Company Compromise Cost Figures: Needed to convert structural arguments into board-defensible dollar exposures.
Concessions
- Counter-move the audience will recognise: “Some of our peers are smaller and have not been hit.”
Pre-emptive handling: The attack is about exposure to commodity attack vectors, not adversary hand-selection. A small peer being un-hit simply means they are outside the spray cone for other reasons; it is not evidence of safety.
- Counter-move the audience will recognise: “Defense has a cost; we cannot fund everything.”
Pre-emptive handling: Agreed. The brief is not asking for a larger security budget; it is asking for the existing budget to be prioritized against the actual threat model, rather than a flawed assumption.
- Counter-move the audience will recognise: “We are not Equifax / Marriott / Target.”
Pre-emptive handling: True. The argument is structural, not biographical. Mid-market cases like Kaseya and Blackbaud demonstrate the “size-doesn’t-matter” lesson generalizes across the size spectrum.
- Counter-move the audience will recognise: “Sophisticated nation-state APTs seeking zero-days prioritize larger targets.”
Pre-emptive handling: Accurate. However, the 2024 Verizon DBIR confirms 95% of system intrusion breaches are financially motivated, while espionage accounts for only 5%. Optimizing for the 5% while ignoring automated and supply-chain threats is a strategic misallocation.
- Counter-move the audience will recognise: “We have cyber insurance.”
Pre-emptive handling: Insurance covers a subset of costs (forensics, legal, notification). It does not cover reputational damage, customer-trust loss, procurement-competitiveness loss, or regulatory fines. Carriers are also tightening and require evidence of controls that this assumption fails to produce.
- Counter-move the audience will recognise: “We have not been breached yet, so the assumption has been working.”
Pre-emptive handling: Survivorship bias. Absence of observation in a low-detection posture is not evidence of absence. This is the same reply a target gives just before the first incident.
- Counter-move the audience will recognise: “Smaller companies get hit too; this is not a size issue.”
Pre-emptive handling: Agreed — that is exactly the point. The variable that matters is exposure to attack vectors, not size. Conceding this concedes the entire argument against the assumption.
Strategic Considerations
- Board Defensibility: If compromised, the post-incident review will ask, “What was the threat model, and why?” The current assumption is indefensible in that review. Updating it now is low-cost; defending it post-incident is high-cost and personal.
- Regulatory Posture: The 2023 SEC cybersecurity disclosure rules require publicly listed companies to disclose material incidents within four business days. The “no one would target us” language, if embedded in a 10-K risk factor, is a documented position that will be legally tested.
- Insurance Market Direction: Carriers increasingly require evidence of threat modeling, control testing, and incident-readiness. A posture grounded in this assumption signals a worse-than-expected risk, affecting premiums and retention.
- Procurement Competitiveness: Regulated enterprise B2B buyers increasingly require SOC 2 Type II, ISO 27001, completed SIG/CAIQ questionnaires, and evidence of active threat modeling. The current assumption undermines these attestations.
- Recruiting: Senior security professionals evaluate threat-modeling maturity during interviews. The assumption acts as a repellant signal, increasing time-to-hire and degrading organizational capability.
- Coalitional Posture: Information-sharing communities (ISACs) operate on the premise that members are credible targets. Operating without this premise weakens the coalition’s signal value to the organization itself.
- Executive Personal Exposure: The officer certifying the threat model (CISO or CEO under specific regimes) assumes personal reputational and potential legal risk by certifying a model grounded in demonstrable fallacy.
Stance declaration
Stance: advocate.
Audience model
Named audience: Executive leadership and board members who endorse (or have not seriously contested) the operating assumption. Concretely: CEO, CFO, COO, General Counsel, CISO, and the directors responsible for risk oversight. Two cohorts survive with distinct persuasion pathways:
- Board Risk Committee: Priorities include fiduciary duty, D&O exposure, peer benchmarking, and sector-trend framing.
- C-Suite / Operational Leadership: Priorities include revenue continuity, contractual obligations, customer trust, and incident-response capacity.
Their frame: Business risk — evaluated through cost, continuity, reputation, regulatory exposure, and fiduciary duty. They do not evaluate threats through adversary logic; that gap is the brief’s primary exploit.
Their priorities: (1) material effect on revenue/share price; (2) disclosure / regulatory / customer-flight trigger; (3) who bears the cost (company vs insurer vs vendor); (4) peer comparison.
Their persuasion pathways: Macro-level risk, legal precedent, governance-oversight duty, operational ROI, peer-group empirical data, and the decoupling of “target prestige” from “target profitability.”
Artifact restatement
Artifact (load-bearing operating assumption): “No one would target a company of our size.”
Unpacked claims:
- Adversaries select targets primarily by revenue, headcount, or size.
- Size is inversely correlated with target attractiveness.
- The company falls below the threshold of adversary interest.
- Limited public footprint, brand, or revenue makes it low-priority.
- The defensive value of being “small enough to ignore” exceeds the cost of any actual compromise.
The assumption rests on the premise that targeting is driven by organizational scale, brand prestige, or geopolitical significance.
Calibration note: “Our size” is unspecified in the original query. It is calibrated against the SMB / mid-market manufacturing band (≤200 employees, ≤$25M revenue) where the web context most strongly applies. If the company is materially larger or in a different sector, the empirical attacks strengthen rather than weaken.
Attacks ranked by persuasive force
Attack 1 — Persuasive Force: Devastating. Surface: External (empirical). Why this lands with Executive leadership/Board: Peer benchmarking is the language the board and CFO trust; “companies like us” beats abstract threat-modeling. The assumption is not merely wrong — it is inverted by the data. Grounded in artifact: NordStellar 2025 data shows SMB manufacturers (≤200 employees, ~$25M revenue) were the single most-targeted band; manufacturing accounted for 19.3% of all ransomware cases, +32% YoY.
Attack 2 — Persuasive Force: Devastating. Surface: External (strategic / economic). Why this lands with Executives: Executives instinctively understand ROI; demonstrating the adversary optimizes the same metric shatters the illusion of insignificance and reframes size from defense to vulnerability. Grounded in artifact: Cybercriminals prioritize targets that offer the biggest payoff for the least amount of effort. SMBs in manufacturing fit this perfectly — generating enough revenue to pay large ransoms but usually lacking the capacity to implement strong security measures or fast recovery options.
Attack 3 — Persuasive Force: Devastating. Surface: External (empirical). Why this lands with Board/C-Suite: Named, dated, adjacent incidents destroy “won’t happen to us” faster than any abstract argument. Grounded in artifact: Documented recent attacks on structurally similar or adjacent firms: Heartland Growers (DragonForce, May 2026), Segue Manufacturing Services (Qilin, Feb 2026), VP Brands International (LockBit 5.0, May 2026), and the operational environments of Foxconn North American factories (Nitrogen, May 2026).
Attack 4 — Persuasive Force: Strong. Surface: External (strategic). Why this lands with COO/BCP Owner: Business continuity is their language; this converts size into a payout-pressure multiplier. Grounded in artifact: SMBs “are more likely to pay ransoms quickly to avoid business disruptions, which is why ransomware groups keep targeting them.” The attacker already knows smaller firms have thinner cash reserves, fewer material-penalty SLAs, and less board patience for outages.
Attack 5 — Persuasive Force: Strong. Surface: External (strategic). Why this lands with Leadership: Reframes the threat from “sophisticated nation-state actor” (which triggers reassuring dismissal) to “industrialized RaaS market with our sector pre-loaded” (which triggers necessary alarm). Grounded in artifact: 134 distinct active ransomware groups in 2025 (+30% from 2024); Qilin +408% YoY; Akira +125%; Cl0p +525%; The Gentlemen (~332 published victims in five months of 2026, mass-exploiting FortiGate vulnerabilities).
Attack 6 — Persuasive Force: Strong. Surface: Internal (logical gap). Why this lands with Executives: The assumption falsely equates “targeting” with bespoke, human-intensive nation-state espionage. Executives recognize that industrial-scale automation removes the need for an adversary to “choose” them manually. Grounded in artifact: The Gentlemen’s automated, worm-like FortiGate-exploiting campaigns demonstrate targeting driven by automated vulnerability scanning, not organizational size.
Attack 7 — Persuasive Force: Strong. Surface: External (strategic / operational). Why this lands with General Counsel / CISO: Neutralizes the “we have nothing worth stealing” defense; forces re-evaluation of third-party risk and contractual liability. Grounded in artifact: Interconnected environments increase the likelihood of lateral compromise through shared networks or third-party access. The valued asset may be the trusted relationship with a larger partner, not the company’s own data.
Attack 8 — Persuasive Force: Strong. Surface: External (strategic / operational). Why this lands with C-Suite/Board: C-Suite understands contractual data obligations; the Board understands downstream-breach liability. Reframes “insignificance” as a “high-value stepping stone.” Grounded in artifact: RaaS supply-chain targeting shows actors leveraging compromised mid-market credentials and trusted access (e.g., SSO tokens, federated identity, contractually-protected customer data) to pivot into larger downstream environments.
Attack 9 — Persuasive Force: Strong. Surface: External (empirical). Why this lands with COO/IT Lead: Recovery capacity is the operational variable separating “disruption” from “catastrophe.” Grounded in artifact: Only 41% of middle-market companies’ existing defenses successfully blocked ransomware in 2024 (59% failed). Mid-market firms characteristically lack tested immutable backups, hot-standby environments, and rehearsed BCP.
Attack 10 — Persuasive Force: Plausible. Surface: External (operational). Why this lands with Leadership: Acknowledges real-world business constraints (holidays, lean staffing) leadership knows intimately, showing how normal business conditions are weaponized. Grounded in artifact: Recorded spike in Q4 incidents where ransomware groups exploit “end-of-year cybersecurity gaps caused by reduced staffing and monitoring,” disproportionately affecting mid-sized firms with limited IT redundancy.
Attack 11 — Persuasive Force: Plausible. Surface: External (empirical). Why this lands with Strategy-focused Board Members: Reframes the threat from random to structural. Grounded in artifact: Manufacturing was the most-targeted industry in 2025 (19.3% of cases, +32% YoY). Size is secondary to sector; size modulates only the ease, not the fact, of attack.
Attack 12 — Persuasive Force: Plausible. Surface: External (strategic / optical). Why this lands with CFO/CEO: Asymmetric resilience is a board-level framing; converts “we have insurance” into a more honest conversation. Grounded in artifact: Mid-market firms have less reputational capital to absorb a disclosure event. The same incident that is a one-quarter earnings event for a Fortune 500 is existential for a mid-market firm.
Attack 13 — Persuasive Force: Plausible. Surface: Internal (logical). Why this lands with CEO/Chair: Names the cognitive failure without requiring technical depth. Grounded in artifact: Mirror-imaging is a documented intelligence-failure mode where the analyst assumes the adversary evaluates targets by revenue/headcount/brand (internal acquisition logic), while adversaries actually evaluate by effort-to-payout, recovery posture, and pressure-to-pay.
Framework-attack flag: 1 attack (Attack 13) brushes against the framework-level critique of whether size should be a meaningful variable in threat modeling at all. If the audience would not accept the framework either, paradigm-suspension is the appropriate sideways-route; otherwise these attacks should be reshaped to stay within-framework.
Suggested phrasing per attack
Attack 1 — Suggested phrasing (in Board/CFO’s idiom): “The threat picture doesn’t show adversaries bypassing our segment. It shows them targeting it. We are not beneath the radar — we are inside the kill zone.”
Attack 2 — Suggested phrasing (in Board/CFO’s idiom): “Our size doesn’t move us off the target list. It moves us to the top of the easy-targets list.”
Attack 3 — Suggested phrasing (in Board/C-Suite’s idiom): “This isn’t ‘it could happen to us’ speculation. It’s ‘it happened to companies structurally similar to us, last quarter, by name.’”
Attack 4 — Suggested phrasing (in COO/BCP Owner’s idiom): “Size doesn’t protect us from the negotiation. It predicts our behavior in it — and the attacker already knows how we’ll behave.”
Attack 5 — Suggested phrasing (in Leadership’s idiom): “The threat isn’t a hand-crafted attack by a nation-state. It’s an industrialized service that already has our sector pre-loaded. Our size doesn’t make us invisible — it makes us economical.”
Attack 6 — Suggested phrasing (in Executives’ idiom): “The assumption that ‘no one would target us’ assumes targeting requires bespoke, human-driven collection. Modern tradecraft is automated and commoditized — we are flagged by a scanner, not selected by a mastermind.”
Attack 7 — Suggested phrasing (in General Counsel/CISO’s idiom): “Even if we concede nobody wants our data — they may want our network. The pivot value of a mid-market vendor is rising, not falling.”
Attack 8 — Suggested phrasing (in C-Suite/Board’s idiom): “We are a credential vault. An adversary who steals our SSO tokens doesn’t need to breach a Fortune 500 perimeter — they log in through a trusted door.”
Attack 9 — Suggested phrasing (in COO/IT Lead’s idiom): “The 59% failure rate among our peers is the prior the adversary is using to set our ransom demand.”
Attack 10 — Suggested phrasing (in Leadership’s idiom): “Our predictable business rhythms are weaponized — adversaries strike when our lean IT teams are most stretched.”
Attack 11 — Suggested phrasing (in Strategy-focused Board’s idiom): “The threat isn’t selecting on size. It’s selecting on industry. Our size doesn’t exclude us from the manufacturing target band — nothing does.”
Attack 12 — Suggested phrasing (in CFO/CEO’s idiom): “The premise assumes we can take a hit. The data says mid-market firms don’t absorb them — they exit from them.”
Attack 13 — Suggested phrasing (in CEO/Chair’s idiom): “The assumption is intuitively right by our own logic. It is empirically wrong by the adversary’s logic. We are not the relevant evaluator.”
Residual uncertainties
- Exact external attack surface: Mid-market base-rate targeting is empirically validated, but the company’s specific current perimeter exposure is unverified without active scanning.
- “Our size” is unspecified: Calibrated to the SMB/mid-market manufacturing band; if larger or different-sector, the empirical attacks strengthen.
- Sector identification assumed: Attack 11’s industry-gravity logic still applies but should be re-grounded in the actual sector’s data.
- Insurance coverage, limits, exclusions not in scope: Affects Concession 5 and Attack 9.
- Crown-jewel IP / customer-data sensitivity unspecified: Affects Attack 7/8 pivot-value — unique IP or regulated data strengthens the direct-targeting argument beyond the generic sector attack.
- Regulatory exposure (SEC 8-K, GDPR, NIS2, state breach notification) unspecified: Affects the strategic-considerations force.
- Ransomware group naming is a snapshot: Current top-group names will change; the structural reality of optimizing for mid-market ROI persists and outlasts individual takedowns.
- Calibration uncertainty — automation-bias attack: Whether “Strong” is right depends on whether a non-technical board accepts that automated scanning constitutes “targeting” in the conscious-selection sense the premise uses.
- Calibration uncertainty — supply-chain attack: Persuasive force depends on the audience accepting the organization’s supply-chain position is mappable by adversaries; if the customer base is genuinely diverse and unconcentrated, force drops.
- Audience split precision: The Board vs C-Suite cohort split is modeled, but the user’s specific organizational structure is unknown.
- Data horizon: The 2026 dates reflect current-period activity per the package; empirical anchoring is appropriate to the supplied horizon.
Concessions
- “We are not as attractive as a Fortune 500.” Conceded. No serious analyst claims an SMB is the apex target of every adversary. The argument is priority, not exclusivity — a priority target within the industrialized RaaS market.
- “Nation-state APTs prioritize critical infrastructure / high-IP sectors; bespoke targeting of us is improbable.” Conceded. APT targeting is a separate model. The assumption holds only in this narrow APT-only context. The dominant threat is the financially-motivated RaaS affiliate economy, whose selection criteria explicitly favor this segment.
- “We have firewalls, EDR, MFA, a security function.” Acknowledged — and irrelevant to the assumption. The assumption claims not-targeted, not undefended. The 59% mid-market defense-failure rate shows controls exist and still fail. Defensive maturity changes the adversary’s effort budget; it does not refute the targeting claim.
- “Nothing has happened to us yet.” Acknowledged as fact; rejected as inference. Survivorship bias — current absence is descriptive of past luck, not predictive of future exposure, as seen in the 2025–2026 industry surge.
- “We have cyber insurance.” Acknowledged — with caveats. Insurance transfers a portion of financial risk only; it does not transfer operational disruption, regulatory exposure, reputational harm, or contractual-breach liability with larger customers. Carriers increasingly refuse or reprice coverage for firms whose threat models rest on the challenged assumption.
Strategic considerations
- Reputational & coalitional damage: A breach destroys trust with larger partners who view the company as the liability that compromised their environment — risking severed contracts and costly imposed third-party audits. Mid-market firms have less reputational capital to absorb a disclosure event.
- Regulatory & disclosure exposure: SEC 8-K Item 1.05, state breach-notification statutes, GDPR/UK GDPR, NIS2, and sector regulators impose obligations scaling with incident severity and data class, not company size — and mid-market firms typically have less compliance infrastructure to manage disclosure.
- Insurance & underwriter positioning: Carriers actively price mid-market risk and require threat-model attestations; operating under “too small to target” leads to under-investment in baseline controls, correlating with policy denials or premium hikes post-incident.
- Fiduciary duty & legal precedent: Directors and executives have a documented duty to oversee cyber risk; relying on an assumption contradicted by current threat intelligence exposes leadership to negligence/D&O claims. Concrete anchor: 2023–2024 SEC cybersecurity-disclosure enforcement charges establish public precedent for holding individuals personally accountable for oversight/disclosure failures.
- Coalitional positioning: Industry ISACs and peer-defense consortia increasingly name participants; whether to be visible as a defended participant or a silent victim is a strategic choice the assumption forecloses by treating size as invisible.
- Supply-chain pressure: Enterprise customers increasingly require security attestations from mid-market vendors; the assumption undermines the company’s negotiating posture by signaling it doesn’t understand the threat it represents as a supply-chain pivot.
Stance: advocate.
This is the strongest case against the assumption “no one would target a company our size,” built as an adversary’s targeting analyst would build it and aimed at persuading the people who hold the assumption. It is not an assessment — no remediation plan, no severity-ranked vulnerability list. The prior pass (a set of numbered findings with a blue-team recommendation list) was assessment-shaped and is deliberately not reproduced; this brief is rebuilt from the assumption itself as attacks ranked by persuasive force.
Audience model
Two audience models survive, because the streams modeled the assumption’s holder differently and the difference is load-bearing — it changes attack ranking. They are kept distinct rather than blended.
Model A — the non-specialist internal believer. A founder, non-technical CEO, or stretched IT lead — not a CISO with a threat-intel team.
- Their frame: risk-as-intuition. Reasons from “would I bother attacking us?” and from the absence of any breach they’ve noticed. Equates “target” with a human deliberately choosing them.
- Their priorities: continuity of operations, payroll, not wasting budget on theater, board/owner confidence, customer contracts, insurance.
- Their persuasion pathway: concrete loss they can’t absorb (downtime, ransom, a lost enterprise contract, a voided insurance claim). Jargon and APT name-dropping bounce off — rounded to “scare tactics from a vendor.”
Model B — the budget-holding executive (CFO / non-technical CEO / board risk committee) who uses “we’re too small to target” to justify not spending on security.
- Their frame: cost-benefit / ROI. Evaluates threats as expected loss × probability vs. cost of mitigation. “Too small to target” is, to them, a probability argument.
- Their priorities: capital discipline, not buying fear, protecting budget from a function they suspect of empire-building.
- Their persuasion pathways: their own numbers turned against them; dollar figures; legal/insurance/contract exposure that hits the P&L; the word “negligence.” What bounces off: technical taxonomy, moral appeals, anything resembling “scared engineer wants a bigger budget.” Their strongest reflex is “We’ve been here X years and never been breached” — any attack that doesn’t survive this reflex is wasted.
For both models, the persuasion pathway is economic and (for B) legal, not technical — attacks that translate into the attacker’s cost or the company’s liability land; attacks that stay in the security domain do not.
Artifact restatement
The claim: “No one would target a company our size.” Unpacked, it makes three load-bearing assertions:
- Cost-benefit claim — we sit below the ROI threshold at which an attack is worth mounting.
- Claim about the verb “target” — being attacked requires an adversary to deliberately select us.
- Claim about value — “our size” is a proxy for “what we’re worth to an attacker.”
Each is attackable on its own terms.
Sufficiency caveat governing the whole brief. The company’s size, sector, vendor/integrator status, and current security posture were not specified. The assumption is a clean enough logical claim to attack on its own, but any attack depending on who you actually are (e.g., “you’re a supply-chain node”) is flagged conditional rather than asserted. Specific breach statistics from the prior draft (payment rates, median-victim headcount, the “Kaseya had 31 employees” figure — almost certainly wrong; Kaseya was a much larger software vendor whose product served thousands of MSPs) are treated as confabulation risks and not relied upon; the structural argument does not need them.
Attacks ranked by persuasive force
Attack 1 — The cost-benefit logic now produces the opposite answer. Persuasive Force: Devastating (unconditional). Surface: Internal (logic flaw) + External (empirical). The assumption is a cost-benefit argument, so it lives or dies on the cost side — and the cost side has collapsed. Documented attacker economics: commodity attack operations as low as ~$34/month (Deloitte “Black Market Ecosystem,” prnewswire.com); credential-theft infrastructure ~$1,363 to launch plus ~$250/month (Zynap, with the $250/mo recurring tier independently corroborated by SecurityWeek’s stealer-as-a-service reporting); APT operators reportedly recover ~4× what they spend on tooling (darkreading.com — supporting not load-bearing, high-end APT, off-axis from the commodity thesis). Pre-conceded rebuttal (hardening, not weakening): cheap tooling ≠ a cheap successful breach — turning $34 of rented infrastructure into a paid ransom against you specifically takes labor, persistence, and luck, and costs more than the rental. Granting this does not save the assumption: the marginal cost of taking the swing is what the assumption priced, and that cost has fallen to roughly the price of a streaming subscription while the swing itself is automated. The assumption mispriced the cost of the attempt, not the size of the payoff. Why this lands with the budget-holder: it doesn’t ask them to abandon ROI thinking — it does ROI thinking correctly and shows their conclusion inverts. They supplied the denominator; the math is no longer theirs to dispute. Grounded in artifact: the “size is below any adversary’s ROI threshold” cost-benefit claim. Confidence: high (figures web-verified, confirmed).
Attack 2 — “Targeting” assumes a decision no attacker is making; you are swept, not chosen. Persuasive Force: Strong standalone; Devastating when delivered after Attack 1. Surface: Internal (hidden premise) + External (empirical). The word “target” smuggles in a premise: that a human adversary weighs companies and selects yours. The dominant mechanism is the opposite — indiscriminate automated mass scanning, credential-stuffing, and phishing blasts with no selection step. You cannot be “too small to target” when nothing is targeting; you are being swept. Delivery-order dependency (calibration): standalone, a sharp budget-holder reconnects the threads — “fine, nothing chose us, but the automated sweep’s payoff against a company this small is still tiny.” The tightened Attack 1 forecloses that escape: once the cost of the swing approaches zero, low per-victim payoff no longer rescues the assumption. Lead with Attack 1, then spring Attack 2; reversed, Attack 2 can be parried. Why this lands: it dissolves the assumption’s central verb without requiring any security technology; it reframes the mental picture of a hooded adversary deliberating over them as a fiction. Grounded in artifact: the verb “target” and its embedded selection premise. Confidence: high.
Attack 3 — Size measures visibility, not value: you may be the doorway, not the prize. Persuasive Force: Strong; Devastating if you are a vendor / SaaS / integrator. Surface: External (strategic/empirical). The assumption conflates “small” with “low-value.” The most expensive intrusions of recent years compromised small vendors precisely because they were trusted by large ones — the supply-chain pattern (SolarWinds, Kaseya, MOVEit, 3CX, Ivanti as a class of event, not verified specifics). The attack pattern is size-independent: a trusted supplier of any size, compromised once, becomes simultaneous access to thousands of downstream victims; the attacker’s return is computed on your customers’ value, and smallness only makes you the soft entry point. If you build software others run, hold integration credentials, or have privileged client access, your trust relationships are the asset. Why this lands: it converts “small” from shield into the very thing that makes you attractive, and touches the fear of being named as the breach source and losing customers. Conditional flag (low-specificity): collapses to Plausible if you are a pure end-consumer business with no downstream trust relationships. Unverifiable from the material — confirm before relying on this as the strongest card; because of the contingency it ranks below the unconditional Attack 1. Grounded in artifact: the “size = value” proxy claim. Confidence: high on the pattern; the application to this company is unverified.
Attack 4 — Ransomware economics are optimized for your size, not against it. Persuasive Force: Strong. Surface: External (empirical/strategic). The affiliate ransomware model inverts the assumption: smaller organizations tend to have weaker defenses, can least afford downtime, are likelier to pay quickly, and sit below the threshold drawing serious law-enforcement attention. That is not “ignored” — it is a preferred profile. The audience-legible figure is not a price table but a question: can you operate for a week with everything encrypted, including backups? Industry breach-cost reporting (IBM/Ponemon via pentera.io) puts averages at $4.45M (2023)–$4.88M (2024); that average skews to larger orgs, so it is not your expected loss — but IBM’s own SME band runs roughly $120K–$3.3M, survival-threatening at small scale. Why this lands: it speaks to continuity and cashflow and turns “small” into the reason you’d pay. Grounded in artifact: the implicit “ransomware crews skip small targets” corollary of the ROI claim. Confidence: high on cost figures (verified); the payment-rate/median-victim distribution claims from the prior draft are uncorroborated and argued qualitatively, not asserted.
Attack 5 — Your data is priced on a market that doesn’t ask your headcount. Persuasive Force: Strong. Surface: External (empirical). Credentials, session tokens, email archives, and customer lists trade at prices set by what they unlock, not by the seller-company’s size. An employee credential set monetizes identically whether it came from a 50-person shop or a 5,000-person one; phishing remains “a top vector to compromise” precisely because email reaches everyone regardless of org size (cybersecuritydive.com). “Our data isn’t worth anything” is a claim about a market price you have never actually checked. Why this lands: it attaches a number to “boring data” — the audience’s native language. Grounded in artifact: the implicit “our data isn’t valuable” sub-claim within “our size.” Confidence: high.
Attack 6 — The assumption is unfalsifiable, and “we’ve never been breached” is its tell. Persuasive Force: Plausible for Model A (a clean closing nudge, not a knockout — a prepared believer can reply “low base rate plus accepted risk is a normal business judgment, not a fallacy”); Strong for Model B (it takes the budget-holder’s single strongest reflex — “we’ve been fine for years” — and reclassifies it as a symptom). The tier divergence is real and tracks the audience model: the reflex is central to B and incidental to A. Surface: Internal (epistemics). Companies of this size characteristically lack the detection capability (EDR, SOC, log retention) to know whether they’ve been breached, so “no detected breach” and “a quiet, undetected compromise” look identical from the inside. The comfort the assumption produces is precisely the blind spot it creates. Calibration note: the prior draft promoted points like this to “critical”; that is the cynical-overreach trap — a prepared audience punctures an inflated claim and then distrusts the rest of the brief. Grounded in artifact: the assumption’s reliance on absence-of-evidence. Confidence: high on the logic; tier placement depends on which audience holds the assumption.
Attack 7 — You are mirror-imaging the attacker (the methodological spine). Persuasive Force: Plausible (most abstract for this audience). Surface: Internal (reasoning flaw). The CIA-tradecraft name is mirror-imaging: pricing the target the way you would, not the way the attacker does. “I wouldn’t bother with a company this small” is a statement about your incentives projected onto an adversary whose costs and goals you haven’t modeled. This is the root error of which every attack above is a downstream consequence — but for an ROI executive it reads one notch too meta; it persuades best introduced after Attacks 1–2 have made it concrete, as the label for what just happened, not as a standalone. Grounded in artifact: the whole assumption as an act of projecting one’s own incentives onto the adversary. Confidence: high that it is the methodological center; low persuasive force standalone.
Framework-attack flag: Two deeper moves sit outside this brief and are flagged rather than made. (1) Whether “targeting” is even the right risk lens — much small-firm loss is non-adversarial (misconfiguration, a breached third-party SaaS you don’t control, an accidental public bucket); those harms don’t care whether anyone “targeted” you, so they sit outside the assumption’s vocabulary entirely. Reframing from “who would attack us” to “what could fail and expose us” is a paradigm-suspension task. (2) Whether attackers are ROI-maximizers at all — an audience could reject the entire rational-economic model of attacker behavior (“some attackers are chaotic, ideological, or random, so cost-benefit framing is the wrong lens”); that is a critique of the paradigm the assumption and this brief both operate in, not of the assumption within it. Both are legitimate but belong to paradigm-suspension, routed separately rather than smuggled into the advocate case.
Suggested phrasing per attack
Attack 1 — Suggested phrasing (in the budget-holder’s idiom): “This is a cost-benefit claim, so let’s finish the calculation. It costs an attacker about thirty-four dollars a month to take a shot at us. Yes — turning that shot into a paid ransom costs them more in labor, I’ll grant that. But what’s the revenue line below which we’re ‘not worth the attempt’? There isn’t one. We did the cost-benefit — we just stopped before the part that disagrees with us.”
Attack 2 — Suggested phrasing: “An automated program that scans every address on the internet doesn’t know our headcount or our revenue. It knows which doors are unlocked. ‘Too small to target’ assumes someone is choosing — most of what hits us never chose anything, and once you see how little it costs them to try, ‘small’ stops protecting us at all.” (Keep “botnet” in analyst-voice exposition only — render it for the audience as “an automated program that scans every address on the internet.”)
Attack 3 — Suggested phrasing: “We keep saying we’re too small to be the bank. We might be the key to the bank’s back door — and on the attacker’s spreadsheet, the key is worth more than any single account. If a client gets hit through us, ‘we were too small to matter’ is the last thing we’ll get to say to them.”
Attack 4 — Suggested phrasing: “We’re the ideal customer for a ransomware crew: weak locks, can’t survive a week down, and too small for the FBI to scramble a team. They’ve done this math. They like our size.”
Attack 5 — Suggested phrasing: “Our employees’ credentials sell for the same price on a criminal market whether we’re fifty people or five thousand. The buyer isn’t pricing our company — they’re pricing our access. And the breach math for a company our size still runs into the hundreds of thousands.”
Attack 6 — Suggested phrasing: “How would we know if we were wrong about this? We don’t have evidence we’re safe — we have an absence of detection, and for a company without monitoring, that’s exactly what a successful, quiet break-in looks like. We’re reading a blank gauge as good news.”
Attack 7 — Suggested phrasing: “The whole assumption is us imagining the attacker’s spreadsheet by looking at our own. Their costs aren’t our costs, and their payoff isn’t our revenue. We’ve been doing their math with our numbers.”
Residual uncertainties
- Company unspecified. Size, sector, vendor status, and current controls are unknown. Attacks 3 and 4 sharpen or weaken sharply depending on these — flagged conditional where relevant rather than assuming worst case as fact.
- Audience inferred, not given — the live tension. Two audience models survive (non-specialist internal believer vs. budget-holding executive); the idiom and the attack ranking shift between them. This would resolve with a user statement of who actually holds the assumption. Audience-contingency map so the brief survives an audience reveal without re-analysis:
- Board / owner → lead with Attack 4 (continuity/cashflow — “can we operate a week down?”) plus the reputational/governance line.
- Insurer / underwriting conversation → lead with the insurance lever in Strategic Considerations (controls-as-coverage-condition), not with any single attack.
- Technical CISO → lead with Attack 2 (automated/indiscriminate volume) — they already know the ROI math, so the live point is mechanism and detection coverage.
- Specific statistics unverified. Ransomware payment-rate and “median victim 50–200 employees” figures (prior draft) are not corroborated in available material and are argued qualitatively. The attacker-cost figures (Deloitte $34/mo; Zynap $1,363 launch / $250/mo, the $250/mo tier independently corroborated; IBM breach cost $4.45M–$4.88M; darkreading APT ~4× return) are sourced and verified.
- The $34/month figure describes attack-infrastructure cost-of-ownership, not the marginal cost of a successful targeted breach. Attack 1 states this distinction explicitly; the figure is genuine but its extrapolation is bounded.
- Specific incident details (e.g., exact Kaseya headcount at time of compromise) are referenced as a class of event, not verified specifics; the SolarWinds/Kaseya/MOVEit references stay at class level.
- Persuasive-force calibration of Attacks 2–6 for a specific audience needs audience-response calibration not performable from the text — would resolve with a security-domain reviewer or a stated audience profile.
- Verification provenance for the load-bearing figures: Deloitte $34/month (commodity attack operations) —
confirmed, multiple independent sources corroborate verbatim; describes infrastructure/tooling cost-of-ownership, not the marginal cost of a monetized targeted breach. Zynap $1,363 launch + $250/month (credential-theft infrastructure) — confirmed; launch figure single-source (Zynap), recurring $250/mo tier independently corroborated (SecurityWeek OnyxC2 stealer-as-a-service). IBM/Ponemon $4.45M (2023)–$4.88M (2024) average breach cost — confirmed against IBM’s own newsroom; average skews to larger orgs, IBM SME band ~$120K–$3.3M folded in as hedge. Dark Reading / Positive Technologies APT ~4× tooling spend — confirmed; framed as supporting (high-end APT, off-axis from commodity thesis). “Kaseya had 31 employees” — corrected: directionally wrong; softened to “a much larger firm (a software vendor whose product served thousands of MSPs)” — sources confirm scale but not exact headcount.
- Revision-integrity note. No new attacks were introduced at revision in either stream; all changes were calibration refinements (force re-labelling, pre-conceded rebuttals, an added insurance concession, idiom swaps, audience-contingency map) grounded in evaluator suggestions and web-verified claims. Input Sufficiency was not overridden — the assumption is a clean logical artifact — so no low-specificity override flag applies globally, though the conditional Attack 3 carries its own low-specificity flag.
Concessions
- Counter-move the audience will recognise: “So size never matters at all?” Pre-emptive handling: conceded — size genuinely gates one threat class. Bespoke, sustained, human-resourced nation-state and high-end APT campaigns do correlate with prominence and strategic value; if you don’t touch a priority sector (defense, semiconductors, biotech, critical infrastructure) you are probably not a named priority for that class. The assumption is directionally true for dedicated, high-touch directed targeting and catastrophically false for everything else (commodity, automated, supply-chain, ransomware). Claim it is right about the rarest attacker and wrong about the common ones — not that it is wrong about all.
- Counter-move the audience will recognise: “This is just the security team fear-mongering for budget.” Pre-emptive handling: conceded as a legitimate suspicion and met head-on — the brief argues the assumption is unsound, not that unlimited spend is warranted. Capital discipline on controls is reasonable; the correct response to a broken probability estimate is to fix the estimate, not write a blank check. Pivots cleanly to “then defend against the cheap, automated, high-probability stuff first” — where small firms get the most return.
- Counter-move the audience will recognise: “We carry cyber-insurance and can restore from backups, so expected loss is capped.” Pre-emptive handling: the audience’s most P&L-fluent escape; conceded partially and met precisely. Insurance and backups genuinely cap some direct loss (ransom line, some downtime) — real risk transfer. But the cap is leakier than it looks on three counts the budget-holder controls: (a) underwriters increasingly require baseline controls as a condition of payout, and a documented “too small to target” rationale is exactly the evidence a claims-adjuster uses to argue the loss was foreseeable and unmitigated — risking reduced or denied claims; (b) premiums reprice on incident and posture, so the cap costs more every renewal; (c) insurance does nothing for uninsurable lines — lost enterprise deals, contractual breach penalties, negligence optics. The cap is real but partial, and the assumption actively erodes it. (Attacks 1, 2, 4, 5 stand regardless of any insurance position.)
- Counter-move the audience will recognise: “The catastrophic scenario depends on us being a vendor.” Pre-emptive handling: conceded — Attack 3’s force is genuinely conditional. With no downstream trust relationships it weakens substantially, though Attacks 1, 2, 4, 5 stand regardless.
- Counter-move the audience will recognise: a challenge to a specific dramatized data-market figure. Pre-emptive handling: some black-market price figures are soft. If you lead with precise price tables, a skeptical audience challenges a number and wins. The structural argument (cost-to-attack near zero) does not need them — argue the structure, not the table.
Omitting these would make the brief look one-sided and hand the audience an easy ambush.
Strategic considerations
Signpost on persuasive force: for a cost-focused audience, the single most persuasive line in the brief may live here — the insurance-voiding lever — not in the ranked attacks. It is unranked deliberately: it is not an attack on whether the assumption is true, but a consequence of operationalizing it (“we don’t need controls”). The attack-ranking and the persuasion-ranking are two different axes; “not in the attack stack” does not mean “not the thing most likely to move them.”
- Cui bono — who benefits from the assumption being true? The assumption is frequently a budget-defense instrument, not a security judgment — it lets the finance function decline spend without argument. Naming it as motivated reasoning is uncomfortable but strategically central: it persists because someone is served by it, not because it survived scrutiny.
- Insurance / underwriting. Cyber-insurance increasingly conditions coverage and payout on baseline controls (MFA, EDR, backups). Operationalized as “we don’t need controls,” the assumption can raise premiums, void coverage, or void a future claim — converting a security gap into an uninsured loss. This often moves a cost-focused executive faster than any threat argument. (It is also why the “we’re insured” concession is leakier than it sounds — the same assumption that justifies declining spend is the evidence a carrier uses to decline a claim.)
- Coalitional / sales. Enterprise customers now demand security attestations (SOC 2, questionnaires, contractual security terms). “Too small to bother” increasingly loses deals and gets you removed from approved-vendor lists — a revenue cost independent of whether you are ever breached.
- Reputational / governance / negligence optics. If a breach traces to a documented “too small to target” rationale, that sentence becomes Exhibit A in litigation, regulatory review, and the post-incident board inquiry. The assumption converts a security gap into a governance failure — the difference between “we were unlucky” and “we decided not to look.”