Cybersecurity Crisis: 92% of Small Businesses in Israel Exposed to Critical Vulnerabilities
A new report reveals alarming cybersecurity and maintenance deficiencies in Israeli small businesses, with nearly all surveyed endpoints exhibiting active security alerts and critical unpatched vulnerabilities.
A recent data-journalism analysis, based on anonymous monitoring data from the XIT system, has uncovered a troubling landscape of computer maintenance and cybersecurity practices within small businesses in Israel. The findings, drawn from a sample of 12 endpoints, indicate that a staggering 11 out of 12 computers (92%) suffer from at least one active security alert. This widespread exposure suggests significant operational and security risks, not just for Israeli businesses but for any small enterprise globally facing similar resource constraints.
The XIT data highlights critical gaps in routine maintenance and security updates, potentially turning small businesses into easy targets for cyber attackers. Within the examined sample, 4 out of 12 computers were awaiting updates, with a total of 8 pending updates across the entire fleet. More critically, 3 out of 12 computers lacked essential security updates, leaving them vulnerable to known and documented exploits.
Critical Security Gaps and Their Implications
Neglecting security updates is one of the most significant risks for small businesses. These updates are designed to patch vulnerabilities in software and operating systems, preventing attackers from exploiting these weaknesses to infiltrate systems. The data shows that 25% of the sampled computers lacked security updates, and 33% were awaiting them. This situation exposes businesses to multiple dangers, including ransomware, malware, and data theft.
Vulnerability intelligence, gathered from the XIT system and cross-referenced with leading databases like CISA KEV (Known Exploited Vulnerabilities), EPSS, and NVD, underscores the severity of the situation. The sample revealed 231 open vulnerability findings across the 12 computers, representing 28 unique CVE vulnerabilities. Of these, 17 CVEs have already been actively exploited in the wild and are listed in CISA's KEV catalog, indicating an immediate and tangible threat.
For instance, the oldest actively exploited vulnerability still open is CVE-2020-0878 in Microsoft Edge, which entered CISA's exploitation catalog in November 2021. Additionally, critical vulnerabilities such as CVE-2025-0411 in 7-Zip, with an exploitation probability of 67.1%, and CVE-2025-15556 in Notepad++ (32-bit x86), with an exploitation probability of 1.7%, were identified as actively exploited.
For a small business, the consequences of an unpatched computer can be devastating. Attackers constantly scan networks for systems with known, unaddressed vulnerabilities. A successful breach can lead to business disruption, loss of invaluable data, reputational damage, and heavy regulatory fines. Small businesses, often lacking dedicated IT staff, struggle to independently manage these threats.
Beyond Security: General Maintenance and Additional Risks
Beyond security update deficiencies, XIT data reveals a broad spectrum of additional maintenance issues indicative of ongoing neglect. Common problems include driver errors (42% of computers), Blue Screens of Death (BSOD) (42%), and unexpected shutdowns (33%). These issues not only impair employee productivity but can also signal more severe hardware or software failures, potentially leading to data loss.
Further performance metrics reinforce this concerning picture: average memory consumption stands at 66%, with 2 out of 12 computers experiencing high memory load (above 85%). High memory usage slows down systems and can cause crashes. Average free disk space is 54%, but one computer in the sample suffered from a nearly full disk (below 15%). A full disk can prevent system updates, the creation of essential temporary files, and even lead to operating system crashes.
In terms of security, 17% of computers suffered from active antivirus threats, and one computer was operating with its firewall disabled. A disabled firewall leaves a computer completely exposed to unauthorized external communication, making it an easy target for intrusions. Furthermore, one computer had a certificate nearing expiration, which could disrupt essential encryption-based services.
A particularly alarming point is that 3 out of 12 computers in the sample were running an unsupported operating system (Windows 10 or older). These computers will never receive security updates again, even if critical vulnerabilities are discovered. This situation poses a severe and irreversible security risk, endangering the entire business.
The findings underscore the critical need for proactive IT and information security management in small businesses. Neglecting routine maintenance and security updates is not merely an inconvenience but a significant business risk. As demonstrated by the high number of Blue Screens (12 in 30 days across the fleet) and system errors (59 in 24 hours across the fleet), accumulated operational problems can lead to systemic failures.
The professional recommendation for small businesses is to adopt a holistic approach to maintenance and information security. This includes ensuring regular security updates for all software and operating systems, continuous monitoring of system status for early problem detection (as enabled by the XIT system), regular backups of critical data, and the use of comprehensive security solutions including active antivirus and firewalls. In cases where internal capabilities are lacking, leveraging managed IT services that provide professional and continuous support is advisable. Investing in maintenance and information security is not an expense but a necessary investment in business continuity and the protection of its most valuable assets.