With the rapid adoption of AI tools and the acceleration of digital attack capabilities, the gap between the sophistication of attackers and the defensive capabilities of midsize businesses has widened significantly. These companies now operate in highly technological environments such as cloud infrastructure, SaaS applications, remote work models, and complex identity frameworks, but often rely on small in-house security teams or outsourced IT providers. As is often the case during times of rapid technological change, organizations without the right operational framework are unduly exposed.
Most cyber security solutions on the market, whether developed by global vendors or startups, are primarily designed for large corporate environments, such as multinational banks with hundreds of thousands of employees and highly complex infrastructures. As a result, small businesses often lack solutions tailored to their specific business realities.
To address this gap, Ro’ee Margalit (CEO) and Avidan Barak (CTO) founded Rotate. With years of experience in cyber security and AI, and having previously worked together in cutting-edge technology military forces, the two recognized the disparity between the sophisticated security architectures available to enterprise organizations and the reality faced by small businesses operating in the same cloud environment but without a dedicated security team.
“We saw first-hand how advanced technology is being used to build complex attack campaigns,” Margalit says. “The question was, how do we bring a similar level of sophistication to the defense of smaller organizations?”
Rotate views the workspace as a single ecosystem and has developed a unified platform that unifies email, identity, cloud applications, endpoints, and remote access under one management layer. By correlating events across these domains and identifying anomalies in real-time, the platform enables effective protection even for organizations without extensive security infrastructure.
The data highlights this change. According to Check Point data, attack attempts targeting this sector increased by 36% globally in the second half of 2025, although the level of attacks against large enterprises remained relatively stable. It’s not just the absolute volume that signals a structural change in threat patterns, but the acceleration in pace.
According to Margalit, the main factor is the impact of AI on attack economics. “The ability to generate automated, highly personalized campaigns at scale means that attackers no longer need to focus solely on large enterprises,” he explains. “Organizations with hundreds or even thousands of employees can be viable targets.”
Approximately 43% of cyberattacks are currently directed at this segment. This segment typically does not have a dedicated CISO and often lacks ongoing monitoring capabilities. At the same time, 62% of these companies have experienced communication with a malicious website, and 34% have faced an exploitation attempt from outside their organization’s network. In large enterprises, such incidents may be absorbed as part of daily operations, but in smaller organizations, these events accumulate into operational burdens that are difficult to manage without centralized visibility.
A central element of the company’s strategy is working through managed IT and security service providers that monitor multiple clients simultaneously. “Most small and medium-sized businesses do not purchase cybersecurity solutions directly from vendors,” points out Margalit. “These work through external providers, so it was important to us to be able to centrally manage thousands of organizations without requiring complex infrastructure for each organization.”
Joining Check Point enables us to scale globally. “The goal was to make integrated protection available to a wider range of users,” says Margalit. “To reach millions of organizations, we need international reach and a comprehensive platform.”
“Small businesses are not alien to the economy,” he concludes. “Their level of protection needs to reflect their level of exposure.”
