← כל הכתבות דוח נתונים

A 100% Failure Rate: Why Small Business Cybersecurity is Reaching a Breaking Point

New data from Israeli small businesses reveals a startling reality where every single workstation monitored carries active security threats or critical operational failures.

מאת אושרי פנחס · 04/09/2026

In the global cybersecurity landscape, small and medium-sized businesses (SMBs) are often described as the 'soft underbelly' of the digital economy. New data released on September 4, 2026, by the XIT monitoring system provides a stark validation of this vulnerability. An analysis of a sample of 13 endpoints within small businesses in Israel found that 100% of the computers—every single one—had at least one active alert indicating either a critical operational failure or a significant security gap.

While the sample size is focused on the Israeli market, the findings serve as a universal warning. Small businesses worldwide share a common profile: limited IT budgets, a lack of dedicated security personnel, and a reliance on aging hardware. In a hyper-connected world, a compromised workstation in a small firm can serve as a beachhead for larger supply-chain attacks, making these local failures a global concern.

The Stability Crisis: Beyond Blue Screens

The data paints a picture of a fleet struggling to stay functional. Operational failures are rampant, with 6 out of 13 computers (46%) suffering from a 'Blue Screen of Death' (BSOD) within the last month, and 5 out of 13 (38%) experiencing unexpected shutdowns. These aren't merely inconveniences; they represent potential data loss and system corruption.

Furthermore, 38% of the machines suffered from driver errors, and 31% showed high memory stress. The average memory consumption across the fleet stands at 62%, a high baseline that stifles productivity. Maintenance hygiene is equally poor: 31% of the computers are currently pending updates, with a total of 7 updates waiting across the small fleet. While the average uptime between reboots is 206 hours, the presence of 34 system errors in the event log over just 24 hours suggests a deep-seated instability.

A Welcome Mat for Attackers

The security findings are even more alarming. The audit discovered that 23% of the computers have missing security updates, and another 23% are currently hosting active antivirus threats (av_threat). One machine (8%) was found with its firewall disabled, and another was running on an expiring security certificate.

Perhaps most dangerous is the persistence of 'ghost' software—older applications that remain installed but ignored. The analysis identified 266 open vulnerability findings across the 13 computers, representing 32 unique CVE identifiers. Crucially, 21 of these CVEs appear on CISA’s Known Exploited Vulnerabilities (KEV) catalog, meaning they are actively being used by hackers in the wild.

The oldest unpatched flaw found was CVE-2020-0878 (Microsoft Edge), which has been on the CISA list since November 3, 2021. More recent threats like CVE-2025-8088 and CVE-2025-6218 in WinRAR 5.91 (64-bit) were also identified. These carry high CVSS scores of 8.8 and 7.8 respectively, with exploitation probabilities as high as 94.6%.

The Danger of the 'Unused' App

The study highlights a critical misconception among small business owners: the idea that if a program isn't being used, it isn't a threat. Software like old versions of WinRAR or outdated Java environments often run background services or contain libraries that can be exploited remotely without any user interaction.

With 23% of the fleet still running end-of-life operating systems (Windows 10 or older), these businesses are effectively operating without a safety net. For the international community, this data is a reminder that the 'low-hanging fruit' for cybercriminals isn't just a metaphor—it is the current reality for the small business sector. Experts recommend that rather than attempting to patch ancient, unused software, businesses should move toward a 'zero-footprint' policy, removing unnecessary applications entirely to shrink their attack surface.