• TRUSTED RESEARCH

    TRUSTED RESEARCH | STRATEGIC INSIGHT

    SMB. CORE MIDMARKET. UPPER MIDMARKET. ECOSYSTEM
    LEARN MORE
  • COMMS, COLLAB, CONTACT CENTER

    COMMS, COLLAB, CONTACT CENTER

    SMB & Midmarket Buyers Collaboration, Contact Center Study
    LATEST RESEARCH
  • DATACENTER SOLUTIONS

    DATACENTER SOLUTIONS

    SMB & Midmarket Datacenter Solution Adoption Trends
    LATEST RESEARCH
  • PARTNER ECOSYSTEM

    PARTNER ECOSYSTEM

    CHANNEL PARTNER ECOSYSTEM TRENDS STUDY
    LATEST RESEARCH
  • BUYER JOURNEY

    BUYER JOURNEY

    SMB & Midmarket Buyers Journey Research
    LATEST RESEARCH
  • BUYER PERSONAS

    BUYER PERSONAS

    SMB & Midmarket Technology Buyer Persona Research
    LATEST RESEARCH
  • ARTIFICIAL INTELLIGENCE

    ARTIFICIAL INTELLIGENCE

    SMB & Midmarket Analytics & Artificial Intelligence Adoption
    LATEST RESEARCH
  • IT SECURITY TRENDS

    IT SECURITY TRENDS

    SMB & Midmarket Security Solutions Adoption Trends
    LATEST RESEARCH
  • 2026 TOP 10 SMB BUSINESS ISSUES, IT PRIORITIES, IT CHALLENGES

    2026 TOP 10 SMB BUSINESS ISSUES, IT PRIORITIES, IT CHALLENGES

  • 2026 TOP 10 SMB PREDICTIONS

    2026 TOP 10 SMB PREDICTIONS

    SMB & Midmarket: Autonomous Business
    READ
  • 2026 TOP 10 PARTNER PREDICTIONS

    2026 TOP 10 PARTNER PREDICTIONS

    Partner & Ecosystem: Next Horizon
    READ

Techaisle Analyst Insights

Trusted research and strategic insight decoding SMBs, the Midmarket, and the Partner Ecosystem.
Anurag Agrawal

WW Midmarket Hybrid Cloud penetration has reached 37 percent and 17 percent workload

Techaisle’s SMB and Midmarket Cloud adoption survey of 3200 midmarket firms and 3000 small businesses globally shows that hybrid cloud has been gaining momentum in small businesses, and is already entrenched in the mid-market firms. Hybrid accounts for 37 percent of cloud using mid-market businesses today, up 28% from 2018, and is expected to capture a lot higher proportion of new spending in the next one year. Midmarket firms are moving from public clouds to hybrid deployments with current hybrid workload at 17%, up from 12% in 2018. The current penetration is the highest in the US but planned usage is highest in Europe and Asia/Pacific.

There is no clear trend on the types of workloads on hybrid environments which shows that most deployments are very specific to a customer’s needs and application delivery partner’s expertise. Typical hybrid workloads include ERP, HR, CRM, finance, operations, IoT, analytics, AI, Machine Learning, SAP 4/HANA deployments, disaster recovery, critical event management, mass storage, cloud security and cloud database. Both Azure and AWS are being used by over 90% of US midmarket firms. Red Hat OpenStack is the preferred private cloud platform for 74% of US firms and Red Hat Cloudforms is the most used cloud management solution by 80% of US midmarket firms followed by VMware vRealize. Hypergrid, Morpheus, platform9 and Scalr are in low single digits. Ansible is being used by most channel partners for orchestration and automation.

Corresponding Techaisle survey with partners delivering cloud solutions to SMBs and midmarket customers reveals that Azure Stack is the most popular platform because of Microsoft’s proactive engagement, powerful and extensive Microsoft ecosystem as well as deep product portfolio. Google Anthos and AWS Outposts are picking up pace. Interesting trend is being seen from AWS partners who are beginning to use Google Anthos instead of AWS Outposts. These partners are not only working with AWS native solutions, but offering cloud solutions which are based around other cloud platforms like GCP, Oracle or Microsoft. Some of these partners prefer to use Anthos because they find it to be more of an open technology and AWS Outposts and can be easily implemented across other environments. It gives them a wider approach in terms of compatibility. They have to pay a fixed amount when using using Anthos which is variable with Outposts. None of the application delivery partners are using tools and technology from only a single vendor. The use of Open Source is dominant.

Another view of the data collected in the survey provides fascinating insight into the extent that midmarket cloud users are willing to align different delivery methods with internal requirements. Detailed analysis and segmentation of data reveals that there are pockets of demand (and overlap in these pockets) that exist for public, private and hybrid models in each segment.

Mid-market businesses
Looking at the mid-market segmentation, we see that larger firms are likely to employ multiple cloud delivery strategies. Overall, 51 percent rely on a single delivery approach for cloud, for example, 31 percent use only private. 29 percent of mid-market businesses use two different delivery approaches, with the most common being a combination of private and public models (but not in a hybrid setting). Firms in these overlap areas are not, on average, larger than those using a single delivery method, but they do face added complexity in that they tend to have more locations.

Anurag Agrawal

Top 10 SMB and Midmarket Predictions for 2020

1. Connected business will be everyone’s problem.

The key focus of business investment will be more about the “work”: the ways that an increasingly-connected business can support pursuit of previously-unattainable objectives. The most important SMB & Midmarket technology-related adoption in 2020 will be this focus on connectedness – cloud, platforms, edge, devices, applications, security, collaboration, workspaces and insights. With the connective fabric rapidly becoming ubiquitous, businesses of all types and sizes will move beyond just the network access, and concentrate instead on using technologies to drive progress across the four pillars of digital transformation: operational effi-ciency, customer intimacy, employee empowerment and product innovation.

2. Momentum building for consumption-based IT acquisition.

Increasingly within SMBs and midmarket firms discrete sales of individual products or integrated systems will be replaced by agreements to provide IT capacity and business functionality “as-a-Service”. In 2020, the trend will be more midmarket driven than small businesses. 20% of midmarket firms will move towards OPEX-based agreements where these firms will look for flexibility and will prefer to acquire technology based on usage – namely IT consumption model – driven primarily because of current IT asset under-utilization.

3. Customer intimacy will take a whole new meaning.

Every SMBs’ survival is dependent upon customers and 2020 will see a ground-breaking year when customer intimacy (acquisition, retention, experience & satisfaction) will drive IT adoption and business process evolution. By the end of 2020, for 45% of SMBs, need for customer intimacy will drive IT adoption and 76% of new SaaS adoption will be customer focused. As a result, 15% of small businesses and 24% of midmarket firms will have “Top Notch” customer facing digital presence.

4. Need for Embedded Collaboration will be clear and present.

Anywhere, anytime also means any type of collaboration. Collaboration solutions cannot be deployed on stand-alone platforms – they need to be viewed as a framework for integrating multiple capabilities, native to multiple applications. By the end of 2020, 80% of SMBs will benefit from embedded collaboration and for high-growth, innovative businesses, effective, e¬fficient collaboration will be in their organizational DNA to deliver decision agility, business agility and innovation agility.

5. Regardless of the question, analytics will provide an answer.

In 2020, SMBs will see a new attitude and culture that will value and use data as a meaningful way to gauge overall performance and specific areas of interest at a glance will become prevalent. SMBs will demand Key Performance Indicators (KPIs) as a standard part of application architectures as well as a meta-directory of KPIs that all applications can access. It may finally become possible for SMBs and Midmarket firms measure and optimize for elusive objectives like Return on Marketing Investment, Optimal Pricing, Cost of Acquisition and Lifetime Customer Value. By the end of 2020, 15% of SMBs will be highly data driven and 30% will be using cloud-based prescriptive analytics and 50% of midmarket firms will demand AI-driven analytical platforms to proactively prescribe actions that will mitigate risk / increase opportunity within the predicted future.

Anurag Agrawal

Cybersecurity - SMBs are maneuvering around the edges of flame

Techaisle’s SMB and Midmarket security solutions adoption research shows that although security is a top IT priority for 85% of SMBs, cybersecurity is still not the most pressing security issue for 80% of SMBs. These SMB firms maybe maneuvering around the edges of cybersecurity flame as 19% of small businesses and 28% of midmarket firms believe that they have established best practices to control cyber-attacks. 31% of SMBs report that they are very confident of recovering from a cybersecurity incident and another 20% say the recovery is dependent upon the type of incidence. Is it really the case that the security-confident SMBs have taken all necessary steps to safeguard data, user and environment? Answer lies in the next set of data points. Only 8% of small businesses and 24% of midmarket firms have tested their responses to breaches or security incidents to ensure that their protocols will be effective in a crisis situation. Less than 10% of SMBs are covered by cyber-insurance and only 5% are considering cyber-insurance.

 techaisle smb midmarket cyber attack priority

SMBs that build effective, responsive security frameworks will be positioned to capitalize on new technologies and on the new efficiencies that they enable. There is no denying that the threats that IT security frameworks address are becoming both more pernicious and a greater threat to the success of IT-dependent businesses – which is to say, nearly all businesses.

In the Techaisle survey, respondents were asked “– what would be the impact on your organization if there was a security/data breach of corporate information?” Responses indicate that the damage would be widespread and substantial. As the chart below demonstrates, the most severe consequence of a breach would be damage to customer privacy and trust, but there would also be damage to corporate reputations and profitability, difficulty in meeting regulatory requirements, and personal reputation damage for both business and IT professionals within the firm.

techaisle smb midmarket impact security breach

The NIST framework does a good job of describing a business’s approach to cyber security, but it doesn’t actually address the approaches used by ‘bad actors’ to attack data and users. To understand how attackers work (and might be stopped), IT security professionals often turn to the cyber (or intrusion) kill chain. This seven-stage view of an attacker’s process, developed by Lockheed Martin in 2011, helps technical leads to align security technology and processes against an attacker’s progressive objectives.

techaisle smb midmarket cyber attacker process
There are many variants on the diagram. Some include responses to the intrusion kill chain, urging businesses to “detect, deny, disrupt, degrade, deceive and destroy” attackers and their malware. Others highlight the key technologies and technology processes used to support these responses: for example, security professionals combating intruders at the reconnaissance stage might use web analytics to detect an intruder’s activities, and then firewall technology to deny access to corporate systems. The specific details vary from scenario to scenario, and evolve over time. What is constant, though, is the need for technically-adept security professionals to invest in capable technologies, to integrate these systems with each other, to develop processes that connect effectively with threats and technology-based ‘shields’, and to align these systems and processes with management’s corporate objectives.

It isn’t an exaggeration to state that in today’s business world, IT infrastructure is business critical infrastructure. SMBs are heavily invested in IT, with IT-dependent processes throughout their operations. This ubiquitous dependence on technology means that systems failure will reverberate throughout all of a company’s daily operations. There is no way to disaster-proof against IT failure with insurance; appropriate investment in IT security processes, technologies and management strategies is the only way to capitalize on the productivity benefits of IT without creating exposure to organizational paralysis in the event of a malware invasion, a hacker attack or an employee’s negligence or malfeasance.

The lack of understanding of a threat associated with a widely-used cloud platform on one hand (and likely, additional confusion with respect to security issues associated with other technologies), and the lack of IT staff resources available to address security concerns on the other, produces a clear conclusion: SMBs need suppliers to step up to delivery of secure IT environments and prevent cyber-attacks.

In many cases, these suppliers will be the mainstream channel partners who supply the SMB’s technology, who act as the IT management presence within the SMB’s business. In other cases, including in many midmarket environments, the source of security products and services will be specialized managed security providers who focus tightly on operating SOCs and protecting client environments. In some scenarios, firms will ‘land’ by entering a client account from one of these positions, and then ‘expand’ to serve a wider range of IT supply needs – crowding out competitors who can’t address the risk and compliance issues that are central to the CEO’s mandate.

Related research

US SMB and Midmarket Security adoption trends

Europe SMB and Midmarket Security adoption trends

Asia/Pacific SMB and Midmarket Security adoption trends

Latin America SMB and Midmarket Security adoption trends

 

Anurag Agrawal

Balancing cloud threats and security measures challenging European SMBs and Midmarket firms

Techaisle’s Europe SMB and Midmarket security adoption trends survey shows that both small businesses and midmarket firms recognize that cloud poses a risk to their data: “cloud usage/services put us at a higher risk of a data breach” is the security-related statement that resonates most with small businesses, and it is one of the top three issues identified by midmarket respondents. However, 24% believe that they are better prepared than most to address cloud security issues. “Our security budget is sufficient to meet our needs” is the most commonly-advanced statement on IT security by small businesses but 52% of midmarket firms believe that their "budget is not sufficient to meet their security needs". Only 8% of European small businesses have formal security protocols in place to respond to a security incident as compared to 32% of midmarket firms.

There is no denying the threats that IT security frameworks address are becoming both more pernicious and a greater threat to the success of IT-dependent businesses – which is to say, nearly all businesses. Survey data also shows that in Europe, 52% of small businesses and 62% of midmarket firms experienced one or more security incidents in the last one year.

At least within the European SMBs and midmarket firms there seems to be adequate awareness of the quantity, variety and severity of threat sources but the unpreparedness is in part due to weak reporting of breaches when they occur, with only events too big to hide becoming the subjects of public discussion. Tougher disclosure legislation will make SMBs more aware of the extent of IT security issues – which in turn will likely boost investment in security solutions and reduce the number of respondents expressing comfort with their current state of readiness.

Despite the dichotomy of potential of security threats and overconfidence, SMBs are concerned about their threat landscape, both at the PC-level as well as with cloud.

Data clearly shows that small businesses and midmarket firms have very different perceptions of cyber-security risks, security approach and attitude, cloud and end-point security concerns and most effective security solutions to protect cloud data.

A review of cloud security threats and mitigation options available to European SMBs illustrates the fact that while cloud brings unique challenges, the measures used to address the expanded threat profile are consistent with those that would represent good practice in any infrastructure context. 37% of SMB survey respondents are concerned with data exposure during transfers to remote locations, 35% are concerned with the potential for cloud-based accounts to be hijacked, and 28% are worried about unauthorized access to or breaches of data repositories in the cloud, insecure interfaces used to access cloud-based systems, the potential for insiders within a cloud service provider to exfiltrate information, and denial of service (DDoS) attacks – all of which represent cloud-specific threats.

SMBs have very strong perception and understanding of technologies and practices that are considered most effective at protecting data in the cloud and addressing their cloud security concerns. These include data and network encryption, intrusion detection and prevention (IDP), the setting and enforcement of security policies, the creation of data boundaries that separate different information sets, use of access control technologies, and unified threat management. Unlike the threats, though, that are specific to cloud/hybrid IT infrastructure, these approaches do not arise uniquely from use of cloud: they can and should be applied within environments that are not cloud based as well. Any business that relies on a network and supports mobile users (necessitating access control) would do well to implement all of these measures.

Techaisle believes that there are different take-aways for suppliers focused on small and midmarket customers. In small business, there is a need to educate buyers about the gaps that exist between current preparedness and risks, and between small business readiness and the approaches that are common within larger organizations: small businesses need to understand where and how to invest in a wider range of security solutions, especially with respect to covering threats associated with mobility and cloud. There is also a need to respond to price-performance pressures.

Clearly, security itself is a complex solution area, and the marketing challenges faced by suppliers – which need to articulate solutions in terms that are appropriate to small and midmarket businesses, to BDMs and ITDMs, and via sources and channels that are relevant to the evaluation and purchase process – are complex in their own right. Security permeates all aspects of IT service delivery – and as a result, success in navigating the solution and marketing needs offers great upside for successful suppliers.

Trusted Research | Strategic Insight

Techaisle - TA