← כל הכתבות דוח נתונים

Poor IT Hygiene Leaves 92% of Small Business PCs Vulnerable to Cyber Threats

A new monitoring report reveals widespread technical neglect and security risks in small business computer systems, with 92% of endpoints showing active alerts.

מאת אושרי פנחס · 27/09/2026

A new data-driven report, based on anonymized information from the XIT monitoring system, paints a concerning picture of IT maintenance and cybersecurity practices within the small business sector. The findings, drawn from a sample of 12 active endpoints, indicate that approximately 92% of computers (11 out of 12) had at least one active alert signaling a technical failure or security risk. This highlights a significant gap between the need for business continuity and the actual management of IT infrastructure, with only 8% of the sampled computers deemed fully functional and alert-free.

The Cost of Continuous Uptime: Memory Leaks and System Errors

One of the most striking findings in the sample relates to employee usage habits and resource management. The average uptime for a computer between reboots was 388 hours, equivalent to roughly 16 consecutive days. However, the data also revealed extreme cases where 17% of computers (2 out of 12) had not been rebooted for over 720 hours, or at least one full month. This prolonged uptime has a direct impact on system stability: average RAM consumption across the fleet stood at 66%, with 33% of computers experiencing high load and two endpoints exceeding 85% utilization.

From a technical standpoint, extended uptime isn't merely an inconvenience. Modern operating systems require reboots to clear memory leaks from applications, refresh stalled system processes, and apply critical kernel updates. When a computer runs for weeks without interruption, a sharp increase in system errors is observed. The sample showed 61 system errors recorded in the fleet's event logs within just 24 hours, and high resource consumption led to 5 instances of 'Blue Screens of Death' (BSOD) over the last 30 days. Each such event translates directly into lost work hours and a tangible hit to business productivity.

Active Security Exploits: The Small Business Update Gap

In the realm of information security, the findings reveal significant exposure to external threats. The sample identified 231 open vulnerability findings across just 12 computers, encompassing 28 unique CVE identifiers. More alarmingly, 17 of these vulnerabilities are listed in the US Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) Catalog, which tracks flaws actively exploited by attackers in the wild. A prominent example is CVE-2020-0878 in Microsoft Edge, which remained unpatched in the system despite being a known exploited vulnerability since 2021.

The risk isn't limited to older software. The monitoring detected new and critical vulnerabilities from 2025 in popular software like 7-Zip (CVE-2025-0411) with a high exploitation probability of 67.1%, and Notepad++ (CVE-2025-15556). Despite these risks, 50% of the sampled computers were awaiting software updates ('Updates Pending'), and 25% lacked critical security updates. The link between lack of reboots and security is direct: most Windows and third-party software security updates require a full system reboot to take effect. Without a reboot, the computer remains exposed even if the update has been automatically downloaded.

Outdated Systems and Business Continuity Risks

Another layer of threat to small business security is the use of unsupported operating systems. 17% of the sampled computers were running versions of Windows 10 or older that are no longer within their official support lifecycle. For business owners, this means these computers will never receive further security patches, making them easy targets for ransomware and malware attacks.

Additionally, the report found that 25% of computers had an active antivirus alert ('AV Threat'), and on one computer, the firewall was completely disabled. In summary, the XIT data paints a picture of accumulating 'technical debt' in small businesses. The combination of infrequent reboots, poor memory management, and neglect of critical security updates creates an unstable and cyber-exposed work environment. IT experts recommend that these businesses implement a policy of at least weekly reboots, migrate to supported operating systems, and conduct regular checks on update status to prevent a simple technical glitch from escalating into a full-scale business disruption.