A growing market, but not an easy one

Cybersecurity has become a boardroom expense for companies that are too large to rely on basic IT support and too small to staff a full security department. That midmarket gap is where Black-owned cybersecurity firms could build durable, recurring revenue businesses.

The opportunity is not theoretical. Ransomware, business email compromise, vendor risk reviews and cyber insurance questionnaires now hit regional manufacturers, health care providers, professional services firms, government contractors and financial firms. These companies often need managed detection and response, virtual chief information security officer services, compliance documentation, incident response planning and help answering customer security audits.

That creates a lane for founders such as J.D. Harris of Minneapolis-based Ascent Solutions, which describes itself as a minority-owned cybersecurity consulting and services firm. Ascent’s site lists services that include security advisory, cloud security, managed security and compliance support, the kinds of offerings midmarket buyers increasingly seek when they cannot hire every specialist internally.

Other Black-led firms, including Cybastion, led by Cameroonian-born founder Thierry Wandji, have also positioned themselves around cybersecurity, digital infrastructure and risk management. The broader question is whether firms like these can convert rising demand into repeatable enterprise sales, not just one-off assessments.

The answer appears to be yes, for some. But the path runs through an expensive set of trust signals: certifications, audited processes, liability insurance, talent depth, partner ecosystems and proof that the provider can perform under pressure.

Why midsize companies are buying more security

The midmarket is exposed because attackers do not reserve sophisticated tactics for the Fortune 500. Sophos’ latest ransomware research, based on a survey of organizations with 100 to 5,000 employees, found that 59% reported being hit by ransomware in the prior year, according to its State of Ransomware 2024 report.

That matters for Black-owned security firms because many midsize customers do not want to buy a pile of tools and figure out how to staff them. They want outcomes: monitor the network, prepare for an audit, respond when something breaks, and keep insurance coverage in force.

Regulation is adding pressure. The Federal Trade Commission’s amended Safeguards Rule requires covered financial institutions, including many nonbank businesses, to maintain a written information security program, designate a qualified person and address areas such as access controls, encryption and incident response. The FTC explains the requirements in its business guidance on the Safeguards Rule.

Public companies face a different pressure point. The Securities and Exchange Commission adopted rules requiring disclosure of material cybersecurity incidents and more information about cybersecurity risk management, strategy and governance, according to the SEC’s 2023 rule announcement. Even private suppliers can feel the effect when larger customers tighten vendor requirements downstream.

Defense contractors and subcontractors have another standard to watch. The Defense Department announced the final rule for the Cybersecurity Maturity Model Certification program in 2024, a framework tied to protecting federal contract information and controlled unclassified information. The department’s CMMC announcement signaled that compliance will shape access to defense work.

For cybersecurity providers, these rules create demand. They also raise the bar for anyone selling into regulated industries.

The certifications problem

Enterprise buyers often ask cybersecurity vendors for the same proof they ask of software firms and cloud providers: audited controls, formal policies, trained staff and evidence that security is not improvised.

That usually pushes firms toward recognized frameworks and certifications. SOC 2 reports, overseen through the AICPA’s system and organization controls suite, have become a common vendor trust document for service providers. The AICPA describes the SOC suite on its SOC services resource page. ISO/IEC 27001, the international information security management standard, is another signal that a company has formal controls in place, as outlined by ISO.

For companies supporting federal contractors, NIST frameworks and CMMC-related controls are often central. NIST’s Cybersecurity Framework, now widely used beyond government, gives organizations a common language for identifying, protecting, detecting, responding and recovering from cyber risk. NIST maintains the framework at its Cybersecurity Framework site.

These credentials help open doors, but they cost money. A small Black-owned provider may need to hire consultants, document controls, buy governance tools, pay auditors and allocate staff time before the certification generates revenue. That matters because Black founders have historically received a tiny share of venture capital. Crunchbase reported that U.S. Black-founded startups raised less than 1% of all venture funding in 2023, according to its analysis of startup funding.

For a cybersecurity services firm, the funding gap can show up as a slower path to certification, fewer salespeople, less working capital to float long enterprise payment terms and less room to bid aggressively on large contracts.

Insurance has become part of the sales process

Cybersecurity firms also face insurance demands from two sides.

Their customers need help qualifying for cyber insurance or keeping premiums manageable. Insurers increasingly ask about multifactor authentication, endpoint detection and response, backup practices, privileged access, patching and incident response plans. A midmarket company that cannot answer those questions may struggle to obtain favorable coverage.

At the same time, the cybersecurity provider must carry its own coverage. Enterprise customers often require technology errors and omissions coverage, cyber liability insurance, general liability coverage and contractual indemnification. A managed security provider that monitors customer environments or responds to breaches carries real operational risk.

This creates a credibility test. A provider that wants to be trusted during a ransomware event must show that it has its own house in order. For Black-owned firms, especially younger ones, insurance costs and contract requirements can become another barrier to scaling.

Talent remains the constraint behind the opportunity

The cyber talent shortage gives services firms a business case. If a manufacturer or regional law firm cannot hire a security operations center team, it may outsource monitoring and response.

But the same shortage hits the provider. ISC2 has estimated a global cybersecurity workforce gap in the millions, and its research continues to track pressure on staffing and skills development through its cybersecurity workforce studies.

For Black-owned firms, talent strategy can determine whether they stay in project-based consulting or move into higher-value recurring services. Managed detection and response requires 24/7 coverage, escalation procedures, threat analysts, engineers and customer success staff. Compliance support requires people who understand frameworks, can write policies, can translate technical controls into audit evidence and can speak to executives.

That mix is difficult to build cheaply. Some firms may rely on partnerships with cloud platforms, security tool vendors or larger integrators. Others may specialize in narrower areas such as CMMC readiness, incident response planning, Microsoft security environments, identity and access management, or virtual CISO services.

Specialization may be the more realistic midmarket strategy. A Black-owned firm does not need to compete with every global managed security provider. It can win where it has domain knowledge, community trust, faster service or experience with a specific regulatory burden.

Customer acquisition is the hardest sale

Midmarket cybersecurity is not a consumer app business. Buyers move slowly. They ask for references. They involve legal, finance, IT, operations and sometimes the board. They may want to see a provider’s own security policies before discussing their own weaknesses.

That puts Black-owned firms in a familiar enterprise sales bind. They need marquee customers to win marquee customers. Certifications, channel partnerships and supplier diversity programs can help, but they do not replace performance history.

Supplier diversity can open the first meeting, especially with corporations that track spending with minority-owned businesses. But cybersecurity buyers tend to make final decisions based on risk. A procurement team may want to support a Black-owned vendor, while the chief information security officer wants proof that the firm can detect threats, protect privileged credentials and respond at 2 a.m.

That is why managed security and compliance firms often grow through a wedge. They start with an assessment, penetration test, cloud security review, incident response tabletop exercise or compliance gap analysis. From there, they expand into recurring monitoring, remediation, virtual CISO support or annual audit preparation.

This model gives Black-owned firms a path into the midmarket without pretending that every prospect will immediately sign a multiyear managed services contract.

Where Black-owned firms can compete

The strongest opportunities appear to sit where midmarket pain is high and trust can be built through expertise.

CMMC readiness is one lane, especially for defense suppliers that lack in-house compliance teams. Financial services compliance is another, given the FTC Safeguards Rule and customer due diligence requirements. Health care and professional services also need security help, though those markets carry their own regulatory and liability concerns.

Cloud security may be especially important. Many midsize companies now run on Microsoft 365, Azure, AWS, Google Cloud or industry-specific software platforms. A provider that can harden identity systems, configure logging, deploy endpoint protection and help executives understand residual risk can offer practical value without selling fear.

Incident response planning is another entry point. Companies often wait until a breach to discover that they lack decision trees, legal contacts, backup verification, communication templates and cyber insurance reporting procedures. A Black-owned firm that helps clients rehearse before a crisis can move from consultant to trusted advisor.

The recurring revenue comes after that trust is established.

Can they win?

Black-owned cybersecurity firms can win the midmarket, but not simply because demand is rising. They will win if they can prove operational maturity, manage insurance and certification costs, hire and retain scarce talent, and build sales channels that reduce the burden of cold enterprise selling.

The market is moving in their favor in one important respect: midsize companies need more help than their internal teams can provide. Cyber risk, insurance underwriting and compliance pressure have made security services less optional.

Still, the firms best positioned to benefit will be those that pair technical credibility with disciplined business infrastructure. In cybersecurity, trust is the product before the contract is signed.