Cybertech's Sixteen Principles — What Israel Teaches the World About Building Cyber Power

September 27, 2026
blog image

It built a small number of mechanisms on purpose — a light architect at the centre of government, a talent engine, a venture template, a research pipeline — and ran them inside a threat environment nobody would choose. The environment cannot be copied. The mechanisms can.

ENSI research — built on a library of 115 primary documents and 52 company dossiers.


The argument, before the list

On the International Telecommunication Union’s Global Cybersecurity Index 2024, Israel is not in the top tier. It sits in Tier 2 with a score of about 93.6 out of 100, below Estonia, Finland, Singapore, the UK and the US — and in the same band as the Czech Republic (ITU 2024). On almost any measure of what a cyber nation actually produces, the order reverses. In 2020 Israel took 37% of the world’s venture funding for cybersecurity companies and had 42 firms on the Cybersecurity 500, second only to the United States (IISS 2021). In 2024, a year of war and reserve call-ups, its cyber start-ups raised $4B across 89 rounds (YL Ventures 2025). The IISS net assessment puts the United States alone in its first tier and judges that, on security, intelligence, offence and alliances together, Israel and the UK “would probably be top” of the second (IISS 2021).

The gap between those two rankings is the subject of this report. The ITU index records whether laws, agencies and strategies exist; by its own account it “does not measure the quality of actions” (ITU 2024). Czechia has the institutions. It passed one of the world’s first comprehensive cyber security acts in 2014, created NÚKIB in 2017, and has just adopted a new national strategy that takes effect in 2026 (NÚKIB 2026). Israel, by contrast, became a cyber power before it had most of the formal machinery: “without an official national cyber strategy, a committed government agency to coordinate cyber activity, a unified military command, a national CERT, or a dedicated academic thrust” (Tabansky, TAU 2016). Neither the legal checklist nor the start-up count explains what happened.

The reframe we propose is this: Israel’s cyber power is an emergent property of a few deliberately designed mechanisms, running inside an unusual threat environment. Each mechanism has a named exemplar:

  1. A light architect at the centre of government. Resolution 3611 (August 2011) created a National Cyber Bureau in the Prime Minister’s Office with a 2011 budget capped at NIS 4.5M. Resolutions 2443 and 2444 (2015) put cyber regulation inside the existing sectoral regulators and created a civilian operational authority that was deliberately given no police powers. The two merged into the Israel National Cyber Directorate (INCD) in 2017–18.

  2. A talent engine. Unit 8200 selects on raw aptitude at eighteen, Talpiot runs a roughly nine-year elite science track, and Magshimim trains teenagers from the periphery from age fifteen. Reserve duty then keeps graduates moving between the army, universities and companies.

  3. A venture template. Yozma (1992–93) put $100M into ten private funds on terms that shared the upside and required a foreign partner. Israeli venture investment went from $5M in 1990 to $3.3B in 2000 (Avnimelech, Kenney and Teubal, BRIE 2004).

  4. A research pipeline. The INCD co-funded cyber research centres at six of the seven research universities on a matching basis, about $60M in the first five years (ICDK 2020). By 2021 the centres had produced more than 500 papers (INCD 2021).

  5. Planted clusters and foundries. Beersheba’s CyberSpark (2014) put the national CERT, Ben-Gurion University and a technology park within walking distance of each other. Team8, founded the same year by 8200 veterans, built Claroty and Sygnia on a thesis-first foundry model wired to corporate security chiefs.

The environment is the other half, and it is not a model. Israel sees about 1,000 cyber attacks a minute (Benoliel, U Haifa 2015). It spends 5–6% of GDP on defence, roughly four times the Western average (Tabansky, TAU 2020). It conscripts its eighteen-year-olds, and it puts the damage from cyber attacks at about NIS 12B a year (INCD 2025). The threat gave the mechanisms their urgency and their customers. It also produced the model’s two worst failures. The pipeline that trains defenders also trains the mercenary-spyware industry: of the 74 governments known to have bought commercial spyware or forensics tools, 56 bought from firms based in or connected to Israel (Feldstein and Kot, Carnegie 2023). And faith in technical intelligence was one cause of the surprise on 7 October 2023 (Wyss, CTC Sentinel 2024; Bar, NIPP 2024). The mechanisms can be copied. The environment cannot — and no state should want it.

The actor in this story is the state, but not as an owner or a picker of winners. Israeli cyber companies “are not national champions directly subsidized by the government” (Lewis, CSIS 2016). The state designed the conditions, took some of the risk and let the market select. Its most important policy inventions came from a small, low-prestige agency, the Office of the Chief Scientist (Breznitz and Ornston 2012).

For a mid-sized European state (our home example is the Czech Republic) the question is not whether to copy Israel but which parts of its causal logic travel. NÚKIB’s 2026 strategy sets out both halves of the answer. It lists strengths Israel would recognise: an advanced national system, internationally respected experts, a working community across the state, business and academia, and security tools “developed by Czech companies or [with] domestic origins”. It is just as frank about the gaps: too few people and too little money in both the public and private sectors, a state that is still reactive, and a “shortage of secure and competitive domestic technological alternatives, which deepens dependence on the technologies of foreign rivals” (NÚKIB 2026). Czechia has the talent and it faces a threat. What it lacks is the machinery that turns the two into capability and companies.

This is the second report in a series: the first ranked the fifty companies Israel’s machine produced, and the third described the twenty-four features of the most advanced defence they could build. This one asks why the machine exists at all, and distils its logic into sixteen principles that a state, its companies and its investors can act on.

Summary of main points

  • The engine is the mechanisms, not the threat. A small central architect, a talent pipeline, upside-sharing public capital, matched academic centres and planted foundries. The threat environment, conscription and a war economy should not be imported.

  • The state designs the system but does not own it. Its tools were a bureau in the Prime Minister’s Office with a NIS 4.5M first-year budget (3611), a civilian defender with no police powers (2444), demand created through existing regulators (2443), and neutral R&D grants rather than subsidised champions.

  • Talent is the base layer. The pipeline selects early on aptitude, gives recruits real missions at nineteen, releases most of them within six years and keeps them in circulation through reserve duty. Reservists teach at least 97% of the advanced classes at the IDF’s computer school (Breznitz, MIT 2002).

  • The funnel is too narrow, and that is Israel’s biggest self-inflicted limit. About 94% of high-tech workers are non-Haredi Jews and only a third are women (Taub 2025). Only 6% of fourteen-year-old girls aspire to a tech job (Budge et al 2023).

  • Capital was designed, not found. Yozma shared the upside, capped the state’s loss and required foreign partners. Specialist seed funds and foundries (Cyberstarts, Team8, YL Ventures) now carry the model.

  • Every exit is recycled. Adallom’s sale produced both Wiz and Armis, and Cybereason’s collapse produced 7AI. But 89% of Israeli tech firms followed a venture-only or venture-then-trade-sale path and only about 6% reached public markets (Hashai and Menuhin 2006), so decision rights leave the country.

  • The research pipeline publishes the attack together with the fix. Tel Aviv University’s NXNSAttack was patched across the DNS backbone, including in CZ.NIC’s Knot resolver.

  • Israel specifies security against a named adversary, from a national “threat of reference” required by Resolution 3611 to the SL1–SL5 security levels for AI model weights that an Israeli start-up co-wrote with RAND.

  • The guardrails lagged the capability, and the whole ecosystem paid for it. Israel accounts for 43.9% of the entities in the Atlantic Council’s global spyware dataset. The US blacklisting did more to discipline NSO than Israel’s own export licensing did.

  • A machine cannot replace the dissenter. Before October 7 an 8200 analyst’s warning was dismissed as “aspirational”, and the unit’s open-source intelligence team had been disbanded on the strength of machine translation.

  • If a state is starting today, four principles matter most: treat talent as national infrastructure (5), make the state the first demanding customer (4), share the upside (9) and build the guardrails with the capability (15). Principle 2, a central architect, is the precondition for all four.


How the sixteen are organised

The principles follow the causal chain of the Israeli system, from the state that designs it to the guardrails that keep it legitimate and ahead of its adversaries. There are four clusters of four:

  • I · The State: designing the system · 1 decide what cyber power is for · 2 put one architect at the centre of government · 3 separate the civil defender from the spy · 4 make the state the first demanding customer

  • II · The People: the talent engine · 5 treat talent as national infrastructure · 6 give the young real missions · 7 keep people circulating · 8 widen the funnel before it narrows you

  • III · The Capital and the Market: the company machine · 9 share the upside, never insure the downside · 10 put domain experts behind the first cheque · 11 borrow the reach a small country lacks · 12 recycle every exit

  • IV · The Guardrails and the Frontier: legitimate and ahead · 13 specify security against a named adversary · 14 publish the attack with the fix · 15 build the guardrails with the capability · 16 protect the dissenter from the machine

Each principle gets the same six-part brief: the principle in one line · the Israeli evidence (research cited by author or institution and year, plus named companies from the dossiers) · why it works · where it fails or is contested · how to transfer it (to the Czech Republic or a comparable EU state) · the first move (something concrete to start within twelve months). Company figures come from the dossiers and are often company-reported. Several of the most-quoted Israeli statistics rest on weaker evidence than their fame suggests, and we say so where it matters.


I · The State: designing the system

Israel’s state did four things well. It decided what cyber was for, put a small architect where turf wars could be settled, kept the civilian defender trusted by keeping it apart from the spies, and turned its own needs into demand. None of it required a large budget. All of it required design.

1. Decide what cyber power is for

  • The principle in one line. Tie cyber to national ends first, prosperity as well as security, and let the means follow. A strategy is a process to be revised, not a document to be finished.

  • The Israeli evidence. Israeli cyber power grew out of a much older security concept: qualitative superiority to offset small numbers, alliance with a superpower, early warning to offset the lack of strategic depth, and an ultimate deterrent. Heavy investment in science education and signals intelligence ran for decades before anyone said “cyber” (Tabansky, TAU 2016). When the state formalised its approach, the 2010 National Cyber Initiative (about 80 experts, led by Isaac Ben-Israel) set a goal of making Israel a top-five cyber nation. Resolution 3611 listed Israel as “a global IT centre” among its four priorities, beside protecting infrastructure (Housen-Couriel, CCDCOE 2017). The 2017 strategy called cyber “an engine of economic growth, social welfare and national security” (INCD 2017). The 2025 strategy moves the weight towards securing core national processes and adopts a three-year horizon (INCD 2025).

  • Why it works. Ends give ministries a reason to cooperate and a yardstick for judging means. Framing cyber as both an economic engine and a security problem gave the treasury and the defence establishment a stake in the same programme. Tabansky’s diagnosis of Western failure is a focus on means (tools and headcount) that are never tied, through ends, ways and means, to political goals.

  • Where it fails or is contested. Tabansky himself warns that turning Israel’s lessons into a checklist (”invest more in R&D, attract FDI”) repeats the error. Israel’s strategy documents also lag its practice: the 2025 work plan did not yet reflect the new strategy, and one of its authors argues it “should be updated every three years, not every eight” (Shabtai, BESA 2025). The growth end was only half met. High tech’s gains did not spread to the rest of the economy, and two thirds of workers are in sectors with below-OECD productivity (OECD 2025).

  • How to transfer it. NÚKIB’s 2026 strategy already states a vision and calls cyber investment “a competitive advantage”. But it “does not itself establish specific financial requirements”, and by law it need only be updated every five years (NÚKIB 2026). The missing step is to name a small number of national ends that can be measured and to give each an owner. A comparison of ten national strategies found implementation plans, budgets and annual reporting “either absent or inadequately expressed”; Estonia stood out for building on lessons learned rather than accomplishments (Odebade and Benkhelifa 2023). Every leading state is on its second or third strategy, and it is “better to act now than wait for the perfect strategy” (Lewis, CSIS 2016).

  • The first move. Attach to the NCSS Action Plan a one-page statement of three to five measurable national ends. Examples are the number of secure domestic or allied alternatives in strategic infrastructure, qualified experts added each year, and time from disclosure to mitigation in regulated entities. Report on them in NÚKIB’s annual evaluation to the government, and commit to a three-year refresh.

2. Put one architect at the centre of government — and keep redesigning it

  • The principle in one line. Place a small coordinating body under the head of government, let it pay market salaries, and expect to reorganise it every few years.

  • The Israeli evidence. Resolution 3611 made the head of the National Cyber Bureau report directly to the Prime Minister, capped its 2011 budget at NIS 4.5M, and told the PMO to solve “the high salaries needed to staff the Bureau”: market pay from day one. The bureau began as a “rather modest thirty-employee core” that coordinated rather than operated (Benoliel, U Haifa 2015). It sat in the PMO because in Israel only that office can settle disputes between ministries (ICDK 2020). Then it was redesigned again and again: from Shin Bet custody of critical infrastructure (B/84, 2002) to the bureau (3611, 2011), a separate civilian authority (2444, 2015) and a merged directorate (3270, 2017) with about 250 staff and a budget of $32–64M by 2019 (Frei, ETH CSS 2020).

  • Why it works. Authority to arbitrate plus small size forces the architect to coordinate rather than build an empire. Market pay lets it hire operators rather than administrators. Redesign without embarrassment lets each version fix the failure of the last. A coordinating authority at the top is “essential ... if a strategy is to be more than a piece of paper” (Lewis 2016).

  • Where it fails or is contested. Concentrating power in the PMO has a price. The 2018 draft Cyber Defence Bill would have let the INCD seize equipment without a court order and monitor all internet traffic, and critics warned of “unchecked powers” (Frei 2020; IISS 2021). The bill stalled, and Israel’s legal framework still lags its capability. The turf war with the Shin Bet lasted about two years, until the Prime Minister overruled it in September 2014 (Raska, RSIS 2015). A coordinator without political backing fails quietly: Estonia’s Cyber Security Council was “impeded by organisational deficiencies” from 2009 to 2013 and did not, in practice, fulfil its supervisory role (Osula, CCDCOE 2015).

  • How to transfer it. Czechia already has the architect. NÚKIB is the central administrative authority for cyber security, and the Czech system has run on continuous strategic planning for fifteen years. What NÚKIB’s own strategy says it lacks is money and people: allocations “insufficient ... for expert salaries” and “rigidly set remuneration rules” (NÚKIB 2026). The Israeli lesson is to fix pay at the founding resolution and to give the architect a mandate that reaches into the industrial, educational and research ministries, not only the security ones.

  • The first move. Prepare a government resolution modelled on 3611 with three clauses. The first exempts a defined number of NÚKIB and national CERT expert posts from standard civil-service pay tables. The second mandates a joint cyber-industrial work plan co-signed by the Ministries of Industry and Trade, Education, Youth and Sports, and Defence. The third fixes a review of the whole architecture after three years. Keep the new unit small.

3. Separate the civil defender from the spy

  • The principle in one line. Make the civilian defender a trusted service with no police or intelligence powers, keep offence and military self-defence elsewhere, and agree in advance who leads when peace turns into war.

  • The Israeli evidence. Resolution 3611 wrote the boundary into the founding text: it “does not apply to special bodies”, meaning the IDF, police, Shin Bet, Mossad and the defence establishment. The operational authority created by Resolution 2444 in 2015 was deliberately given no law-enforcement powers, “to prevent any ongoing suspicion of NSA-like practices, to build trust”, and infrastructure protection moved out of the Shin Bet (Tabansky 2020). Its first head likened the service to a public water system: “When we will find contamination, we will not suspect who contaminated it.” Responsibility rises with the threat across three layers. Organisations own robustness, the CERT and sector centres own resilience, and the security bodies own national defence (INCD 2017). The INCD leads in peacetime and the IDF in war (Frei 2020). The payoff is sharing: CERT-IL handled about 9,000 incidents and issued about 300 alerts in 2020, and CyberNet links company security chiefs in a trusted national network (INCD 2021).

  • Why it works. Companies report to a body that cannot prosecute them or spy on them. A no-blame service gets more reports, and clear roles mean less time lost in arguments during a crisis. The move to a civilian authority was partly economic, because the Shin Bet-run regime “seemed to stifle innovation and economic growth” (Frei 2020). The INCD’s influence rests on competence rather than coercion, “like the Mossad” (Shabtai, BESA 2025).

  • Where it fails or is contested. The boundary is permanently disputed. Agencies with different core values fought “month-long turf wars” over infrastructure protection, and dependence on 8200 and Shin Bet expertise is “a double-edged sword” (Frei 2020). Critical infrastructure is still guided jointly by the Shin Bet and the INCD (INCD 2025). A voluntary, trust-based model also leaves gaps. The B/84 regime left small businesses, NGOs and citizens “without cybersecurity” until the 2010s (Tabansky 2020), and public and SME awareness is still low (INCD 2025).

  • How to transfer it. The Czech map already separates NÚKIB and the national and government CERTs from the Security Information Service (BIS), the Office for Foreign Relations and Information (ÚZSI), military intelligence and the Cyber and Information Warfare Command. Unlike the Israeli authority, though, NÚKIB is also a regulator that monitors and enforces compliance (NÚKIB 2026). The transferable idea is therefore a firewall inside the civil side, between the service that receives reports and the supervisor that fines. NÚKIB’s strategy also asks for a legal framework for action “both in peacetime and in the event of a transition to crisis”, and admits that processes for sharing “sensitive but unclassified information” are complex or missing.

  • The first move. Publish a joint hand-off protocol between NÚKIB, the Cyber and Information Warfare Command and the intelligence services that says who leads at each threat level. At the same time, issue a no-fault guarantee: information an organisation reports voluntarily to the national CERT cannot be used for enforcement against it. Then open a trusted exchange for security chiefs on the CyberNet model.

4. Make the state the first demanding customer

  • The principle in one line. Use regulation and procurement to create sophisticated demand, working through existing regulators and named entities, without picking national champions.

  • The Israeli evidence. Resolution B/84 (2002), one of the first critical-infrastructure policies anywhere, regulated named entities rather than whole sectors. Those entities appointed security staff, paid for the mandated measures and shared information, and negligent executives faced sanctions (Tabansky 2020). Resolution 2443 (2015) added a double lever. Each sectoral regulator took on cyber for its own sector (demand), and the national bureau regulated the market for cyber professionals, products and services (supply), with five licensed professions and periodic re-testing. Bank of Israel Directive 361 put a cyber strategy and an accountable senior officer in every bank (Housen-Couriel 2017). The dossiers show demand working at firm level. Auditors and insurers wrote CyberArk’s privileged-access controls into requirements. Waterfall “made the regulator [its] sales team” through NERC CIP, NRC and ANSSI rules. Axonius built a FedRAMP-authorised federal arm that serves more than 90 US agencies, and Sweet Security grew out of the pain of a state modernisation programme, Nimbus.

  • Why it works. A demanding buyer with a real problem pulls product quality up faster than a grant does. Regulation turns security into a budget line, and naming entities keeps the burden on those that matter. The state buys outcomes, and the market picks the vendor.

  • Where it fails or is contested. Demand can become a burden. B/84 put all compliance costs on the supervised entities, and sector obligations “evolved organically” and differ from one to the next. Essential organisations that are not critical infrastructure still fall into a regulatory gap (Frei 2020; INCD 2025). Protecting a domestic champion that is not globally competitive “can backfire” (Lewis 2016). “Sovereign” procurement carries its own risk: Dream Security reached more than $130M in annual sales in about two years through political access, and its dossier concludes that “sovereignty rented from a foreign vendor is still dependency”.

  • How to transfer it. Europe’s rules are our demand lever: Czechia’s new Cyber Security Act (2025) and the fast-growing body of EU legislation behind it turn security into an obligation, and therefore a budget line. NÚKIB’s strategy commits the state to “prefer security solutions of domestic origin or from reliable partner and allied countries”, to create “secure technology alternatives” in selected areas, and to support “certification bodies and testing laboratories” (NÚKIB 2026). Those commitments become a market only if public and regulated buyers publish real problems and pay to have them solved.

  • The first move. NÚKIB and the Ministry of Industry and Trade publish ten problem statements drawn from regulated entities in energy, water, health and finance. Each sponsoring buyer commits to one paid pilot a year with a young EU vendor, evaluated in a national test laboratory. Contracts carry fixed sovereignty terms: source-code escrow, local hosting, open data export and clean exit clauses.


II · The People: the talent engine

Every serious assessment names the same binding constraint. The workforce is the limit on national cyber capacity everywhere, “with perhaps only Israel having adopted a sufficiently radical approach to upskilling its citizens” (IISS 2021). The Israeli answer is not one institution but a chain: find them at fifteen, select on aptitude at eighteen, give them real missions at nineteen, release them at twenty-four and keep them circulating for the next twenty years. Three of the four principles below are copyable without conscription. The fourth is the one Israel itself has failed.

5. Treat talent as national infrastructure

  • The principle in one line. Fund the talent pipeline the way you fund a road: from school, with public money, against a named national need, and measured in cohorts rather than in graduates.

  • The Israeli evidence. Cyber is a school subject, army officers scout in high schools, and a National Center for Cyber Education opened in 2017 (IISS 2021). Magshimim, funded by the state and the Rashi Foundation, takes fifteen- and sixteen-year-olds from the periphery for three years. It draws more than 2,000 applicants a year and teaches “cyber ethics” to keep talent away from black-hat hacking (Cordey, ETH CSS 2019). It was designed for “girls, religious students, and children outside the major cities”, and grew from about 400 to 4,800 participants in five years. In one cohort, 61 of 234 graduates were already working in high tech before military service, earning about 2.5 times their peers (Government of British Columbia 2019). About 75% go on to IDF cyber and intelligence units (Frei 2020). The Atuda programme funds about 1,000 degrees a year in exchange for six to ten years of service (ICDK 2020).

  • Why it works. The pipeline turns a national need into a visible career ladder with public money behind it, starting long before universities can act. Selecting on aptitude rather than experience widens the supply: Unit 8200 takes candidates at or above the 89th percentile of the national psychometric test, and explicitly tests raw potential (Rousseau, Ohio 2017). Teaching ethics inside the programme is a cheap way to keep a generation of skilled teenagers on the defensive side.

  • Where it fails or is contested. The pipeline still does not meet demand: Israel is roughly 10,000 cyber workers short (Hatuka and Carmel, TAU 2021) and about 18,000 engineers short overall (Noël, Ifri 2020). Early programmes such as Gvahim, which put programming into fourth grade in 70 schools, skew to the wealthier centre (Cordey 2019). The state loses the bidding war for its own graduates, because the private sector pays more (Antebi, INSS 2021), and the 2025 strategy still has to name the “juniors barrier” as a problem. The Magshimim numbers are programme claims, not evaluations.

  • How to transfer it. NÚKIB’s strategy already commits to a National Cyber Security Education Plan, inclusive programmes and the linking of initial with further education, against an EU-wide shortage of up to 300,000 experts (NÚKIB 2026). Without conscription, the state has to buy the part the army supplies in Israel: the afternoon programme, the selection test and the guaranteed first job.

  • The first move. Launch a three-year after-school cyber track for fifteen- to eighteen-year-olds in at least eight regions outside Prague, with a single national entry quiz, ethics in the syllabus, industry and reserve volunteers teaching, and a guaranteed interview at NÚKIB, the Cyber and Information Warfare Command or a partner company for everyone who finishes. First cohort within twelve months.

6. Give the young real missions

  • The principle in one line. Train backwards from a real job in months rather than years, then hand nineteen-year-olds responsibility they would not get anywhere else.

  • The Israeli evidence. Mamram’s six-month core course runs eight or nine hours of class and six or seven of laboratory a day, and needs no prior programming. It trains about 300 programmers a year, who then serve five and a half to six years; by twenty-one, one in four manages a team and one in ten runs a section with a budget (Breznitz, MIT 2002). Every course is designed backwards from a capstone that simulates the real job. Unit 8200’s six-month course runs sixteen- to eighteen-hour days in small teams and ends in a capstone that joins a technical task to an intelligence one (Rousseau 2017). Responsibility is structural. The IDF’s senior-officer-to-troop ratio is about 1:9, against 1:5 in the US Army, and since the 1973 Agranat Commission questioning authority has been expected. After 1973, 8200 was rebuilt into “small, flexible teams tasked with finding quick technical solutions” (Cordey 2019). The dossiers show the output. Check Point’s firewall grew from Gil Shwed’s military work linking classified and unclassified networks, and Pentera automated its founders’ red-team routine. Sweet Security began with the IDF information-security chief’s failed search for a product that did not exist.

  • Why it works. Short courses beat degrees on time to competence, because they are designed backwards from the mission. Real responsibility under budget scarcity — what Breznitz calls a “selective factor disadvantage” — produces people who improvise and who have already carried consequences. The problems are national in scale, so the threat models the graduates later build products against are real ones.

  • Where it fails or is contested. The famous numbers are weakly evidenced. The claim that IDF veterans are about three times more likely to found a unicorn traces back to LinkedIn posts (Suss 2025), and the best academic test uses a five-firm sample with only marginally significant results (Rousseau 2017). Military training produces operators, not businesses: interviewees describe Israel as “a startup nation, not a scale up nation”, with founders “product focused not business focused”. Military capital also needs a civilian conversion layer (Grassiani, U Amsterdam 2018). And the unit is not a prerequisite: SentinelOne’s founders had no 8200 network, were rejected by Israeli investors and built a company now worth about $8.3B; Irregular was founded by AI researchers and debaters.

  • How to transfer it. The copyable part is course design and delegated responsibility, not conscription. A mid-sized state can run the same six-month, mission-designed course through its military cyber command and its national CERT, and can give twenty-two-year-olds ownership of real systems. NÚKIB’s strategy asks for exactly this emphasis on “the practical application of the knowledge acquired” (NÚKIB 2026).

  • The first move. The Cyber and Information Warfare Command and NÚKIB jointly run one full-time six-month operator course a year, open to school-leavers and career changers without a degree, designed backwards from a capstone on a live sector range, taught largely by industry and reserve instructors, with a service commitment and a guaranteed posting at the end.