← כל הכתבות דוח נתונים

Small Business Cyber Gap: Data Reveals Critical Security Lapses in SMB Infrastructure

New monitoring data shows that 92% of sampled small business endpoints carry active security alerts, with unpatched vulnerabilities dating back to 2020.

מאת אושרי פנחס · 21/09/2026

In the global cybersecurity landscape, small and medium-sized businesses (SMBs) are often described as the 'soft underbelly' of the digital economy. While large enterprises invest millions in automated defense, smaller firms frequently struggle with basic digital hygiene. New monitoring data released on September 21, 2026, by XIT’s monitoring system, provides a stark look at this reality through a sample of 12 endpoints within the Israeli small business sector.

The findings are a warning for SMBs worldwide: 11 out of the 12 computers sampled (92%) had at least one active security alert. The data highlights a dangerous lag between the release of security patches and their actual implementation, creating a wide window of opportunity for threat actors to exploit known weaknesses.

The Patching Gap: Years of Exposure

The XIT data reveals that 50% of the fleet is currently waiting for critical updates, with 11 total updates pending across the sample. This delay is not merely a matter of days; the system identified 231 open vulnerability findings across the 12 machines, representing 28 unique CVE identifiers. Most alarmingly, 17 of these CVEs are listed on CISA’s Known Exploited Vulnerabilities (KEV) catalog—meaning they are not just theoretical risks, but flaws actively used by hackers in the wild.

The oldest unpatched vulnerability found was CVE-2020-0878 in Microsoft Edge. Despite being added to the CISA catalog on November 3, 2021, this flaw remains open on systems nearly five years after its initial discovery. More recent threats were also detected, including CVE-2025-0411 in 7-Zip 24.07 (CVSS score 7.0, with a 67.1% exploitation probability) and CVE-2025-15556 in Notepad++ (CVSS score 7.5). Both are currently being exploited globally.

The risk is compounded by aging infrastructure. Two of the 12 computers are running end-of-life operating systems (Windows 10 or older). For these machines, the window of exposure will never close, as they no longer receive security updates from the manufacturer, making them permanent liabilities for the businesses that rely on them.

Systemic Neglect and Operational Instability

Security is often tied to general system health, and the XIT report paints a troubling picture of maintenance. Beyond the threat of intrusion, these businesses face significant operational risks. Five computers (42%) suffer from driver errors, and 33% are under high memory stress, with two machines exceeding 85% memory utilization. This neglect manifests in the 'Blue Screen of Death' (BSOD), which occurred 9 times across 3 different computers in the last 30 days.

The data suggests a lack of basic oversight: the average uptime between reboots is 267 hours, and two computers had not been restarted for over 720 hours (a full month). Because many critical patches require a reboot to finalize installation, this 'always-on' behavior effectively blocks security updates from taking effect. In the 24 hours preceding the report, 40 system errors were recorded in the event logs across the fleet, indicating persistent operational friction.

Why the SMB Context Matters

While this data originates from small businesses in Israel—a nation often considered a global cybersecurity hub—the findings reflect a universal SMB crisis. Small businesses often lack dedicated IT staff, leading to 'security by obscurity'—the false belief that they are too small to be targeted. However, as the XIT data shows, automated scanners used by attackers do not care about the size of the company; they only care about the 17 KEV-listed vulnerabilities left open on the network.

With average memory consumption at 61% and CPU usage at 16%, these systems are already strained. When combined with active antivirus threats (found on 17% of the machines) and disabled firewalls, the result is an environment where a single ransomware attack could lead to total operational collapse. For the international reader, this serves as a reminder that the most sophisticated cyber defense strategy is useless if the basics—rebooting, patching, and upgrading hardware—are ignored.