Original research
The State of Compliance
in the Israeli Mid-Market
Findings from 40+ security and compliance assessments of Israeli mid-market companies. What we found in their cloud, their endpoints, their identity providers, and their policies, and how far it had moved from what they believed, and from what their certificates said.
Selected findings
Every one of these companies
had a dashboard that said green.
Production databases open to the internet
Live databases reachable directly from the public internet on default ports, one running an unsupported version with a known unauthenticated flaw. No VPN, no allow-list, nothing in front of them.
The firewall’s own admin panel was public
The management login of the perimeter firewall, the device that is supposed to be the boundary, was exposed to the open internet. So were a virtualization console and dozens of camera and DVR interfaces.
Admin access by editing a browser cookie
The application decided who was an administrator by reading an “IsAdmin” flag in a cookie the user controls. Flip it from false to true and you are an admin. No server-side check at all.
Login tokens that worked from any device
Authentication tokens were accepted from any machine or IP with no session binding and no revocation. Copy one token elsewhere and you are fully logged in as that user.
A health API handed back full medical records
A single authenticated call returned complete medical data, no data minimization, no field-level control. One exposed token would have been a privacy breach under Amendment 13 and GDPR.
A cloud account with no audit log at all
API activity logging was off across all eighteen regions. Any unauthorised action, in either direction, would have been completely invisible. The console still showed healthy.
Full admin rights, and no second factor
Unrestricted administrator permissions handed to multiple identities, console users with no MFA, and access keys that had never been rotated. No alert would fire if the root account were used.
Employee passwords for sale on the darknet
Valid staff credentials, harvested by infostealer malware, found already circulating on criminal markets, dated and active. The accounts were still live.
Email anyone could send as the company
Spoofing protection was set to monitor-only or missing entirely, so a forged message from a company address would land in the inbox. This is the mechanism behind most business email compromise.
No scan in two years, no tested backup
No vulnerability scan had been run in over two years, the core system had no ransomware-proof backup, and production, test, and development shared one flat network. The recovery plan had never been exercised.
Because drift is not a warning.
It is a measurement.
Security marketing runs on fear, and the people who buy security are immune to it. So we are not going to tell you that you might be exposed. We are going to show you what we found in forty companies that looked exactly like yours, and let you do the arithmetic.
Then, if you want, we will run the same assessment on you, free, and you can stop estimating.
Do not wait for the report.
Run the same assessment on your own environment, free, and stop estimating from someone else's numbers.
Get your free assessmentRead-only. No obligation. No sales call required.