92% of Small Businesses Face Critical Cybersecurity Gaps, Study Reveals
A new data analysis from XIT monitoring system exposes widespread cybersecurity and operational failures in small businesses, leaving them vulnerable to exploitation.
A recent analysis of anonymized data from the XIT monitoring system, based on a sample of 13 endpoints in small businesses in Israel, paints a concerning picture of computer maintenance and information security. The findings indicate that 12 out of the 13 computers examined (approximately 92%) suffer from at least one active alert, pointing to a lack of routine maintenance and a high potential for operational and security risks. These figures highlight a significant gap between the need for robust information security and the reality on the ground, particularly among small businesses that often struggle to allocate sufficient resources to this critical area. While the study focuses on Israel, the challenges faced by small businesses there are indicative of a global trend where resource constraints often lead to overlooked cybersecurity hygiene, making them attractive targets for cybercriminals worldwide.
Neglected Vulnerabilities: An Open Door for Attackers
One of the most striking findings from the sample is the presence of known and documented security vulnerabilities that remain unaddressed for extended periods. The study identified 266 open vulnerability findings across the 13 computers, including 32 unique CVEs. Of these, 21 CVEs are listed on CISA's KEV (Known Exploited Vulnerabilities) catalog, meaning they have been actively exploited by attackers globally. For instance, CVE-2020-0878 in Microsoft Edge, which was added to CISA's exploitation catalog on November 3, 2021, remains unpatched on the examined computers. This means over 1,000 days have passed since an official warning about the vulnerability's exploitation was issued, yet it has not been remediated. Such a prolonged window of exposure provides attackers ample opportunity to exploit these weaknesses using readily available and well-known tools and techniques.
The reason older, documented vulnerabilities are frequently exploited is their familiarity within the attacker community and the availability of easy-to-use exploits. Small businesses, often lax in regular security updates and vulnerability management, become easy targets. For example, vulnerabilities like CVE-2025-8088 and CVE-2025-6218 in WinRAR 5.91 (64-bit), with high CVSS scores (8.8 and 7.8 respectively) and exploitation probabilities of 94.6% and 90.5% respectively, were found to be actively exploited and still open on the systems. These vulnerabilities, despite being documented and known, remain 'open doors' for attackers, potentially leading to breaches, data theft, system shutdowns, and significant financial and reputational damage.
Common Operational and Security Failures
Beyond security vulnerabilities, the data reveals a series of common operational failures that impact computer performance and pose security risks. 12 out of 13 computers in the sample suffer from at least one active alert. The most common issues include: pending updates (7 out of 13 computers, 54%), driver errors (5 out of 13, 38%), and high memory load (4 out of 13, 31%). Additionally, 4 computers (31%) experienced a Blue Screen of Death (BSOD), and 3 computers (23%) suffered from a lack of security updates, unexpected shutdowns, and active antivirus threats (av_threat).
Computers with pending updates are exposed to known security vulnerabilities, as these updates often include critical patch fixes. Failure to install them leaves the system vulnerable. Driver errors can cause system instability, slow down work, and even lead to crashes. High memory load (31% of computers) degrades computer performance and slows down work, directly impacting productivity. BSODs and unexpected shutdowns indicate severe hardware or software problems, potentially leading to data loss and work disruption. Active antivirus threats signal malware infiltration, posing an immediate risk of information theft, file encryption (ransomware), or disruption of business operations.
Furthermore, 3 out of the 13 computers in the sample are running an operating system that is out of support (Windows 10 and below), meaning they will no longer receive security updates. This leaves them completely exposed to both new and old threats, making them particularly easy targets for attackers. Nearly full disks (2 out of 13 computers, 15%) can significantly slow down the system, prevent important updates from being installed, and even cause crashes. A disabled firewall (1 out of 13 computers, 8%) removes a critical layer of protection against unauthorized access to the local network. All these issues underscore the need for continuous management and oversight, even in small businesses.
Professional Recommendations: The Importance of Routine Maintenance
The data from the XIT sample highlights the critical importance of routine and proactive maintenance of computer systems, even for small businesses. The professional recommendation is to adopt a holistic approach that includes several key steps. First, ensure regular and prompt installation of security and software updates as soon as they are released. This includes updates for the operating system, browsers, office software, and any other applications installed on the computers. Second, actively monitor and address security vulnerabilities, prioritizing those on CISA's KEV list. Third, it is recommended to use updated and active antivirus and firewall solutions, and to perform periodic scans for threats. Fourth, continuously monitor computer performance, address issues such as high memory load or nearly full disks, and ensure regular system reboots. Finally, replace or upgrade out-of-support operating systems to supported versions to ensure critical security updates are received. Implementing these steps, even on a limited scale, can dramatically reduce business risk and secure sensitive business information.