An employee asks an AI assistant a routine question and receives a spreadsheet containing compensation data. A former employee still has an active administrator account. A customer delays signing a contract until a supplier can prove its security controls work.
These were among the situations discussed in the first session of Katalyst’s Cybersecurity Awareness Month webinar series. For mid-market organizations, they point to a practical set of cybersecurity priorities for 2026: govern access, understand where business data goes, test recovery, and give someone clear responsibility for ongoing security operations.
Katalyst CTO Steve Rattacasa and Jesse White explored those priorities in What We’re Actually Seeing (And What We’re Doing About It), drawing on client conversations and work in the field. Their discussion is especially relevant to IT directors and business leaders who need to support growth with limited staff and increasing expectations from customers, insurers, and leadership.
AI security starts with the data employees can already access
Jesse shared an example of an organization where an employee using Microsoft Copilot surfaced compensation information they should not have been able to see. The experience highlighted a problem that can exist long before an AI rollout: permissions that are broader than the business intends.
Microsoft documents that Microsoft 365 Copilot respects existing user permissions. That makes the quality of those permissions critical. Information employees could technically access but might never have found manually can become easier to discover through AI.
Before expanding AI use, identify sensitive information, review who can access it, and assign owners to correct oversharing. Establish which AI tools employees may use and what data they may enter. Include connected applications and agents in that review.
For a credit union, that might mean examining access to member information. For a healthcare organization, it could mean reviewing patient and employee records. A manufacturer may need to protect design files and supplier pricing. These are practical applications of the same principle: AI adoption and data governance need to move together.
Identity and access management requires more than MFA
Multi-factor authentication is an important control, but it does not determine whether an account should still exist or whether its permissions are appropriate.
Jesse described recurring issues involving excessive privileges, inactive administrator accounts, and employees using the same identity for routine work and administrative tasks. He also called out the habit of copying an existing employee’s permissions when someone new joins. That can carry unnecessary access from one person to the next.
A useful identity and access management review should answer four questions:
- Which accounts belong to people who have left or changed roles?
- Which employees have administrative access they no longer need?
- Are privileged identities separate from everyday user accounts?
- Are permissions based on approved job responsibilities and reviewed regularly?
For a lean IT team, these questions create a focused starting point. They turn a broad goal such as improving Microsoft 365 security into a review with specific owners and observable results.
Business applications need visibility and ownership
The webinar’s discussion of tool sprawl extended beyond security software. Departments can purchase a business application, connect it to other systems, and gradually create a network of integrations that IT does not fully understand.
Jesse used marketing software as an example. A platform may begin with a straightforward purpose, then gain access to customer records, communications, and other applications as integrations accumulate.
The response is to make technology review part of purchasing and onboarding. Maintain an inventory that records each application’s business owner, data access, authentication method, and integrations. Where supported and appropriate, connect applications to centrally managed identity and access processes.
This also makes offboarding more reliable. Removing an employee from one directory is not enough if separate accounts remain active in departmental tools. Leaders need to know which applications follow the central process and which require additional action.
Security operations need clear responsibility after hours
A security platform still needs people to configure it, investigate alerts, maintain documentation, and take action. During the session, Jesse described clients reassessing their staffing approach after an employee left and took essential institutional knowledge with them.
The operational question is whether those responsibilities remain covered during turnover, vacations, and nights or weekends.
For some organizations, co-managed IT or managed security services can supplement an internal team. Fractional security leadership can also help connect technical priorities to budgets and business risk when a full-time CISO role does not fit the organization.
Evaluate the division of responsibility carefully. Who reviews an alert at 2 a.m.? Who can authorize containment? Who maintains the runbook? Who tells leadership what happened? Answering those questions makes the service model useful and helps prevent gaps between internal staff and outside providers.
Proving security can affect revenue and recovery
Jesse described organizations facing a commercial obstacle: customers wanted evidence of security practices before moving forward with work. That expectation can reach professional services firms and other suppliers serving regulated industries, even when those suppliers are not subject to the same regulatory requirements themselves.
Steve emphasized the connection between policies, implemented controls, and testing. A written policy establishes an expectation. Configuration records, monitoring evidence, and test results help show whether the organization meets it.
Backups are a clear example. A successful backup job does not establish that a critical application can be restored within the time the business can tolerate. Backup and disaster recovery planning should include restoration testing and documentation of the results.
A tabletop exercise tests a different part of readiness: decisions. Can leaders agree on who declares an incident, who communicates with customers, and how operations continue? An exercise that exposes an unanswered question gives the team something concrete to fix before an actual disruption.
Growth introduces security work that needs an owner
The speakers also discussed mergers, acquisitions, and employee onboarding. Combining organizations means reconciling different identities, tools, policies, and recovery processes. Public announcements can give impersonators useful context for convincing messages.
Security work should therefore be part of the integration plan. Assign owners to review inherited access, connected systems, and control gaps. Include fraud awareness in onboarding so employees know how to verify unusual payment or purchase requests, including requests that appear to come from an executive.
For a growing mid-market business, this makes cybersecurity part of how growth is managed day to day.
A practical cybersecurity roadmap for the next 90 days
The following sequence adapts the webinar’s recommendations into a starting point. Adjust it to your most significant exposures and business dependencies.
- Start now with access and recovery. Review privileged and inactive accounts, separate administrative access, and test restoration of a critical system.
- Over the next month, confirm who monitors and responds after hours. Review remote access, inventory departmental applications, and identify sensitive data exposed through overly broad permissions.
- Across the quarter, address vulnerabilities on an ongoing schedule, run a tabletop exercise, and collect evidence that priority controls are working.
Tie each action to a business outcome. A manufacturer may prioritize restoring production dependencies. A local government may focus on continuity of public services. A professional services firm may need evidence for a customer security review. The priorities should reflect what the organization needs to keep operating.
Frequently asked questions
What cybersecurity priorities should a mid market organization address first
Start with identity and access, tested recovery, and clear monitoring and response responsibilities. Then prioritize application visibility, AI data access, and vulnerability management according to the systems and services your organization depends on.
Is MFA enough to protect Microsoft 365
MFA is one part of identity security. Organizations also need appropriate permissions, separate privileged access, effective offboarding, and ongoing review of account activity. An account can have MFA enabled and still retain access its owner should no longer have.
How should a business prepare for Microsoft Copilot securely
Review sensitive data and existing permissions, correct oversharing, establish approved uses, and evaluate connected applications. Microsoft 365 Copilot respects existing permissions, so preparation needs to include whether those permissions match the organization’s intent.
How can a small IT team improve cybersecurity coverage
Define which responsibilities the internal team can reliably own and where additional support is needed. Co-managed services, managed detection and response, or fractional leadership can help address specific gaps when responsibilities and escalation paths are clear.
Turn the discussion into a plan for your organization
Katalyst helps mid-market organizations assess, transform, and manage the Digital Backbone their operations depend on. If your team is weighing AI adoption, identity gaps, or recovery readiness, schedule a conversation with Katalyst to identify priorities and define practical next steps.
Explore the 2026 Cybersecurity Executive Reports for additional context, or visit the Cybersecurity Awareness Month series for more conversations with business and technology leaders.



