

It built a small number of mechanisms on purpose — a light architect at the centre of government, a talent engine, a venture template, a research pipeline — and ran them inside a threat environment nobody would choose. The environment cannot be copied. The mechanisms can.
ENSI research — built on a library of 115 primary documents and 52 company dossiers.
On the International Telecommunication Union’s Global Cybersecurity Index 2024, Israel is not in the top tier. It sits in Tier 2 with a score of about 93.6 out of 100, below Estonia, Finland, Singapore, the UK and the US — and in the same band as the Czech Republic (ITU 2024). On almost any measure of what a cyber nation actually produces, the order reverses. In 2020 Israel took 37% of the world’s venture funding for cybersecurity companies and had 42 firms on the Cybersecurity 500, second only to the United States (IISS 2021). In 2024, a year of war and reserve call-ups, its cyber start-ups raised $4B across 89 rounds (YL Ventures 2025). The IISS net assessment puts the United States alone in its first tier and judges that, on security, intelligence, offence and alliances together, Israel and the UK “would probably be top” of the second (IISS 2021).
The gap between those two rankings is the subject of this report. The ITU index records whether laws, agencies and strategies exist; by its own account it “does not measure the quality of actions” (ITU 2024). Czechia has the institutions. It passed one of the world’s first comprehensive cyber security acts in 2014, created NÚKIB in 2017, and has just adopted a new national strategy that takes effect in 2026 (NÚKIB 2026). Israel, by contrast, became a cyber power before it had most of the formal machinery: “without an official national cyber strategy, a committed government agency to coordinate cyber activity, a unified military command, a national CERT, or a dedicated academic thrust” (Tabansky, TAU 2016). Neither the legal checklist nor the start-up count explains what happened.
The reframe we propose is this: Israel’s cyber power is an emergent property of a few deliberately designed mechanisms, running inside an unusual threat environment. Each mechanism has a named exemplar:
A light architect at the centre of government. Resolution 3611 (August 2011) created a National Cyber Bureau in the Prime Minister’s Office with a 2011 budget capped at NIS 4.5M. Resolutions 2443 and 2444 (2015) put cyber regulation inside the existing sectoral regulators and created a civilian operational authority that was deliberately given no police powers. The two merged into the Israel National Cyber Directorate (INCD) in 2017–18.
A talent engine. Unit 8200 selects on raw aptitude at eighteen, Talpiot runs a roughly nine-year elite science track, and Magshimim trains teenagers from the periphery from age fifteen. Reserve duty then keeps graduates moving between the army, universities and companies.
A venture template. Yozma (1992–93) put $100M into ten private funds on terms that shared the upside and required a foreign partner. Israeli venture investment went from $5M in 1990 to $3.3B in 2000 (Avnimelech, Kenney and Teubal, BRIE 2004).
A research pipeline. The INCD co-funded cyber research centres at six of the seven research universities on a matching basis, about $60M in the first five years (ICDK 2020). By 2021 the centres had produced more than 500 papers (INCD 2021).
Planted clusters and foundries. Beersheba’s CyberSpark (2014) put the national CERT, Ben-Gurion University and a technology park within walking distance of each other. Team8, founded the same year by 8200 veterans, built Claroty and Sygnia on a thesis-first foundry model wired to corporate security chiefs.
The environment is the other half, and it is not a model. Israel sees about 1,000 cyber attacks a minute (Benoliel, U Haifa 2015). It spends 5–6% of GDP on defence, roughly four times the Western average (Tabansky, TAU 2020). It conscripts its eighteen-year-olds, and it puts the damage from cyber attacks at about NIS 12B a year (INCD 2025). The threat gave the mechanisms their urgency and their customers. It also produced the model’s two worst failures. The pipeline that trains defenders also trains the mercenary-spyware industry: of the 74 governments known to have bought commercial spyware or forensics tools, 56 bought from firms based in or connected to Israel (Feldstein and Kot, Carnegie 2023). And faith in technical intelligence was one cause of the surprise on 7 October 2023 (Wyss, CTC Sentinel 2024; Bar, NIPP 2024). The mechanisms can be copied. The environment cannot — and no state should want it.
The actor in this story is the state, but not as an owner or a picker of winners. Israeli cyber companies “are not national champions directly subsidized by the government” (Lewis, CSIS 2016). The state designed the conditions, took some of the risk and let the market select. Its most important policy inventions came from a small, low-prestige agency, the Office of the Chief Scientist (Breznitz and Ornston 2012).
For a mid-sized European state (our home example is the Czech Republic) the question is not whether to copy Israel but which parts of its causal logic travel. NÚKIB’s 2026 strategy sets out both halves of the answer. It lists strengths Israel would recognise: an advanced national system, internationally respected experts, a working community across the state, business and academia, and security tools “developed by Czech companies or [with] domestic origins”. It is just as frank about the gaps: too few people and too little money in both the public and private sectors, a state that is still reactive, and a “shortage of secure and competitive domestic technological alternatives, which deepens dependence on the technologies of foreign rivals” (NÚKIB 2026). Czechia has the talent and it faces a threat. What it lacks is the machinery that turns the two into capability and companies.
This is the second report in a series: the first ranked the fifty companies Israel’s machine produced, and the third described the twenty-four features of the most advanced defence they could build. This one asks why the machine exists at all, and distils its logic into sixteen principles that a state, its companies and its investors can act on.
The engine is the mechanisms, not the threat. A small central architect, a talent pipeline, upside-sharing public capital, matched academic centres and planted foundries. The threat environment, conscription and a war economy should not be imported.
The state designs the system but does not own it. Its tools were a bureau in the Prime Minister’s Office with a NIS 4.5M first-year budget (3611), a civilian defender with no police powers (2444), demand created through existing regulators (2443), and neutral R&D grants rather than subsidised champions.
Talent is the base layer. The pipeline selects early on aptitude, gives recruits real missions at nineteen, releases most of them within six years and keeps them in circulation through reserve duty. Reservists teach at least 97% of the advanced classes at the IDF’s computer school (Breznitz, MIT 2002).
The funnel is too narrow, and that is Israel’s biggest self-inflicted limit. About 94% of high-tech workers are non-Haredi Jews and only a third are women (Taub 2025). Only 6% of fourteen-year-old girls aspire to a tech job (Budge et al 2023).
Capital was designed, not found. Yozma shared the upside, capped the state’s loss and required foreign partners. Specialist seed funds and foundries (Cyberstarts, Team8, YL Ventures) now carry the model.
Every exit is recycled. Adallom’s sale produced both Wiz and Armis, and Cybereason’s collapse produced 7AI. But 89% of Israeli tech firms followed a venture-only or venture-then-trade-sale path and only about 6% reached public markets (Hashai and Menuhin 2006), so decision rights leave the country.
The research pipeline publishes the attack together with the fix. Tel Aviv University’s NXNSAttack was patched across the DNS backbone, including in CZ.NIC’s Knot resolver.
Israel specifies security against a named adversary, from a national “threat of reference” required by Resolution 3611 to the SL1–SL5 security levels for AI model weights that an Israeli start-up co-wrote with RAND.
The guardrails lagged the capability, and the whole ecosystem paid for it. Israel accounts for 43.9% of the entities in the Atlantic Council’s global spyware dataset. The US blacklisting did more to discipline NSO than Israel’s own export licensing did.
A machine cannot replace the dissenter. Before October 7 an 8200 analyst’s warning was dismissed as “aspirational”, and the unit’s open-source intelligence team had been disbanded on the strength of machine translation.
If a state is starting today, four principles matter most: treat talent as national infrastructure (5), make the state the first demanding customer (4), share the upside (9) and build the guardrails with the capability (15). Principle 2, a central architect, is the precondition for all four.
The principles follow the causal chain of the Israeli system, from the state that designs it to the guardrails that keep it legitimate and ahead of its adversaries. There are four clusters of four:
I · The State: designing the system · 1 decide what cyber power is for · 2 put one architect at the centre of government · 3 separate the civil defender from the spy · 4 make the state the first demanding customer
II · The People: the talent engine · 5 treat talent as national infrastructure · 6 give the young real missions · 7 keep people circulating · 8 widen the funnel before it narrows you
III · The Capital and the Market: the company machine · 9 share the upside, never insure the downside · 10 put domain experts behind the first cheque · 11 borrow the reach a small country lacks · 12 recycle every exit
IV · The Guardrails and the Frontier: legitimate and ahead · 13 specify security against a named adversary · 14 publish the attack with the fix · 15 build the guardrails with the capability · 16 protect the dissenter from the machine
Each principle gets the same six-part brief: the principle in one line · the Israeli evidence (research cited by author or institution and year, plus named companies from the dossiers) · why it works · where it fails or is contested · how to transfer it (to the Czech Republic or a comparable EU state) · the first move (something concrete to start within twelve months). Company figures come from the dossiers and are often company-reported. Several of the most-quoted Israeli statistics rest on weaker evidence than their fame suggests, and we say so where it matters.
Israel’s state did four things well. It decided what cyber was for, put a small architect where turf wars could be settled, kept the civilian defender trusted by keeping it apart from the spies, and turned its own needs into demand. None of it required a large budget. All of it required design.
The principle in one line. Tie cyber to national ends first, prosperity as well as security, and let the means follow. A strategy is a process to be revised, not a document to be finished.
The Israeli evidence. Israeli cyber power grew out of a much older security concept: qualitative superiority to offset small numbers, alliance with a superpower, early warning to offset the lack of strategic depth, and an ultimate deterrent. Heavy investment in science education and signals intelligence ran for decades before anyone said “cyber” (Tabansky, TAU 2016). When the state formalised its approach, the 2010 National Cyber Initiative (about 80 experts, led by Isaac Ben-Israel) set a goal of making Israel a top-five cyber nation. Resolution 3611 listed Israel as “a global IT centre” among its four priorities, beside protecting infrastructure (Housen-Couriel, CCDCOE 2017). The 2017 strategy called cyber “an engine of economic growth, social welfare and national security” (INCD 2017). The 2025 strategy moves the weight towards securing core national processes and adopts a three-year horizon (INCD 2025).
Why it works. Ends give ministries a reason to cooperate and a yardstick for judging means. Framing cyber as both an economic engine and a security problem gave the treasury and the defence establishment a stake in the same programme. Tabansky’s diagnosis of Western failure is a focus on means (tools and headcount) that are never tied, through ends, ways and means, to political goals.
Where it fails or is contested. Tabansky himself warns that turning Israel’s lessons into a checklist (”invest more in R&D, attract FDI”) repeats the error. Israel’s strategy documents also lag its practice: the 2025 work plan did not yet reflect the new strategy, and one of its authors argues it “should be updated every three years, not every eight” (Shabtai, BESA 2025). The growth end was only half met. High tech’s gains did not spread to the rest of the economy, and two thirds of workers are in sectors with below-OECD productivity (OECD 2025).
How to transfer it. NÚKIB’s 2026 strategy already states a vision and calls cyber investment “a competitive advantage”. But it “does not itself establish specific financial requirements”, and by law it need only be updated every five years (NÚKIB 2026). The missing step is to name a small number of national ends that can be measured and to give each an owner. A comparison of ten national strategies found implementation plans, budgets and annual reporting “either absent or inadequately expressed”; Estonia stood out for building on lessons learned rather than accomplishments (Odebade and Benkhelifa 2023). Every leading state is on its second or third strategy, and it is “better to act now than wait for the perfect strategy” (Lewis, CSIS 2016).
The first move. Attach to the NCSS Action Plan a one-page statement of three to five measurable national ends. Examples are the number of secure domestic or allied alternatives in strategic infrastructure, qualified experts added each year, and time from disclosure to mitigation in regulated entities. Report on them in NÚKIB’s annual evaluation to the government, and commit to a three-year refresh.
The principle in one line. Place a small coordinating body under the head of government, let it pay market salaries, and expect to reorganise it every few years.
The Israeli evidence. Resolution 3611 made the head of the National Cyber Bureau report directly to the Prime Minister, capped its 2011 budget at NIS 4.5M, and told the PMO to solve “the high salaries needed to staff the Bureau”: market pay from day one. The bureau began as a “rather modest thirty-employee core” that coordinated rather than operated (Benoliel, U Haifa 2015). It sat in the PMO because in Israel only that office can settle disputes between ministries (ICDK 2020). Then it was redesigned again and again: from Shin Bet custody of critical infrastructure (B/84, 2002) to the bureau (3611, 2011), a separate civilian authority (2444, 2015) and a merged directorate (3270, 2017) with about 250 staff and a budget of $32–64M by 2019 (Frei, ETH CSS 2020).
Why it works. Authority to arbitrate plus small size forces the architect to coordinate rather than build an empire. Market pay lets it hire operators rather than administrators. Redesign without embarrassment lets each version fix the failure of the last. A coordinating authority at the top is “essential ... if a strategy is to be more than a piece of paper” (Lewis 2016).
Where it fails or is contested. Concentrating power in the PMO has a price. The 2018 draft Cyber Defence Bill would have let the INCD seize equipment without a court order and monitor all internet traffic, and critics warned of “unchecked powers” (Frei 2020; IISS 2021). The bill stalled, and Israel’s legal framework still lags its capability. The turf war with the Shin Bet lasted about two years, until the Prime Minister overruled it in September 2014 (Raska, RSIS 2015). A coordinator without political backing fails quietly: Estonia’s Cyber Security Council was “impeded by organisational deficiencies” from 2009 to 2013 and did not, in practice, fulfil its supervisory role (Osula, CCDCOE 2015).
How to transfer it. Czechia already has the architect. NÚKIB is the central administrative authority for cyber security, and the Czech system has run on continuous strategic planning for fifteen years. What NÚKIB’s own strategy says it lacks is money and people: allocations “insufficient ... for expert salaries” and “rigidly set remuneration rules” (NÚKIB 2026). The Israeli lesson is to fix pay at the founding resolution and to give the architect a mandate that reaches into the industrial, educational and research ministries, not only the security ones.
The first move. Prepare a government resolution modelled on 3611 with three clauses. The first exempts a defined number of NÚKIB and national CERT expert posts from standard civil-service pay tables. The second mandates a joint cyber-industrial work plan co-signed by the Ministries of Industry and Trade, Education, Youth and Sports, and Defence. The third fixes a review of the whole architecture after three years. Keep the new unit small.
The principle in one line. Make the civilian defender a trusted service with no police or intelligence powers, keep offence and military self-defence elsewhere, and agree in advance who leads when peace turns into war.
The Israeli evidence. Resolution 3611 wrote the boundary into the founding text: it “does not apply to special bodies”, meaning the IDF, police, Shin Bet, Mossad and the defence establishment. The operational authority created by Resolution 2444 in 2015 was deliberately given no law-enforcement powers, “to prevent any ongoing suspicion of NSA-like practices, to build trust”, and infrastructure protection moved out of the Shin Bet (Tabansky 2020). Its first head likened the service to a public water system: “When we will find contamination, we will not suspect who contaminated it.” Responsibility rises with the threat across three layers. Organisations own robustness, the CERT and sector centres own resilience, and the security bodies own national defence (INCD 2017). The INCD leads in peacetime and the IDF in war (Frei 2020). The payoff is sharing: CERT-IL handled about 9,000 incidents and issued about 300 alerts in 2020, and CyberNet links company security chiefs in a trusted national network (INCD 2021).
Why it works. Companies report to a body that cannot prosecute them or spy on them. A no-blame service gets more reports, and clear roles mean less time lost in arguments during a crisis. The move to a civilian authority was partly economic, because the Shin Bet-run regime “seemed to stifle innovation and economic growth” (Frei 2020). The INCD’s influence rests on competence rather than coercion, “like the Mossad” (Shabtai, BESA 2025).
Where it fails or is contested. The boundary is permanently disputed. Agencies with different core values fought “month-long turf wars” over infrastructure protection, and dependence on 8200 and Shin Bet expertise is “a double-edged sword” (Frei 2020). Critical infrastructure is still guided jointly by the Shin Bet and the INCD (INCD 2025). A voluntary, trust-based model also leaves gaps. The B/84 regime left small businesses, NGOs and citizens “without cybersecurity” until the 2010s (Tabansky 2020), and public and SME awareness is still low (INCD 2025).
How to transfer it. The Czech map already separates NÚKIB and the national and government CERTs from the Security Information Service (BIS), the Office for Foreign Relations and Information (ÚZSI), military intelligence and the Cyber and Information Warfare Command. Unlike the Israeli authority, though, NÚKIB is also a regulator that monitors and enforces compliance (NÚKIB 2026). The transferable idea is therefore a firewall inside the civil side, between the service that receives reports and the supervisor that fines. NÚKIB’s strategy also asks for a legal framework for action “both in peacetime and in the event of a transition to crisis”, and admits that processes for sharing “sensitive but unclassified information” are complex or missing.
The first move. Publish a joint hand-off protocol between NÚKIB, the Cyber and Information Warfare Command and the intelligence services that says who leads at each threat level. At the same time, issue a no-fault guarantee: information an organisation reports voluntarily to the national CERT cannot be used for enforcement against it. Then open a trusted exchange for security chiefs on the CyberNet model.
The principle in one line. Use regulation and procurement to create sophisticated demand, working through existing regulators and named entities, without picking national champions.
The Israeli evidence. Resolution B/84 (2002), one of the first critical-infrastructure policies anywhere, regulated named entities rather than whole sectors. Those entities appointed security staff, paid for the mandated measures and shared information, and negligent executives faced sanctions (Tabansky 2020). Resolution 2443 (2015) added a double lever. Each sectoral regulator took on cyber for its own sector (demand), and the national bureau regulated the market for cyber professionals, products and services (supply), with five licensed professions and periodic re-testing. Bank of Israel Directive 361 put a cyber strategy and an accountable senior officer in every bank (Housen-Couriel 2017). The dossiers show demand working at firm level. Auditors and insurers wrote CyberArk’s privileged-access controls into requirements. Waterfall “made the regulator [its] sales team” through NERC CIP, NRC and ANSSI rules. Axonius built a FedRAMP-authorised federal arm that serves more than 90 US agencies, and Sweet Security grew out of the pain of a state modernisation programme, Nimbus.
Why it works. A demanding buyer with a real problem pulls product quality up faster than a grant does. Regulation turns security into a budget line, and naming entities keeps the burden on those that matter. The state buys outcomes, and the market picks the vendor.
Where it fails or is contested. Demand can become a burden. B/84 put all compliance costs on the supervised entities, and sector obligations “evolved organically” and differ from one to the next. Essential organisations that are not critical infrastructure still fall into a regulatory gap (Frei 2020; INCD 2025). Protecting a domestic champion that is not globally competitive “can backfire” (Lewis 2016). “Sovereign” procurement carries its own risk: Dream Security reached more than $130M in annual sales in about two years through political access, and its dossier concludes that “sovereignty rented from a foreign vendor is still dependency”.
How to transfer it. Europe’s rules are our demand lever: Czechia’s new Cyber Security Act (2025) and the fast-growing body of EU legislation behind it turn security into an obligation, and therefore a budget line. NÚKIB’s strategy commits the state to “prefer security solutions of domestic origin or from reliable partner and allied countries”, to create “secure technology alternatives” in selected areas, and to support “certification bodies and testing laboratories” (NÚKIB 2026). Those commitments become a market only if public and regulated buyers publish real problems and pay to have them solved.
The first move. NÚKIB and the Ministry of Industry and Trade publish ten problem statements drawn from regulated entities in energy, water, health and finance. Each sponsoring buyer commits to one paid pilot a year with a young EU vendor, evaluated in a national test laboratory. Contracts carry fixed sovereignty terms: source-code escrow, local hosting, open data export and clean exit clauses.
Every serious assessment names the same binding constraint. The workforce is the limit on national cyber capacity everywhere, “with perhaps only Israel having adopted a sufficiently radical approach to upskilling its citizens” (IISS 2021). The Israeli answer is not one institution but a chain: find them at fifteen, select on aptitude at eighteen, give them real missions at nineteen, release them at twenty-four and keep them circulating for the next twenty years. Three of the four principles below are copyable without conscription. The fourth is the one Israel itself has failed.
The principle in one line. Fund the talent pipeline the way you fund a road: from school, with public money, against a named national need, and measured in cohorts rather than in graduates.
The Israeli evidence. Cyber is a school subject, army officers scout in high schools, and a National Center for Cyber Education opened in 2017 (IISS 2021). Magshimim, funded by the state and the Rashi Foundation, takes fifteen- and sixteen-year-olds from the periphery for three years. It draws more than 2,000 applicants a year and teaches “cyber ethics” to keep talent away from black-hat hacking (Cordey, ETH CSS 2019). It was designed for “girls, religious students, and children outside the major cities”, and grew from about 400 to 4,800 participants in five years. In one cohort, 61 of 234 graduates were already working in high tech before military service, earning about 2.5 times their peers (Government of British Columbia 2019). About 75% go on to IDF cyber and intelligence units (Frei 2020). The Atuda programme funds about 1,000 degrees a year in exchange for six to ten years of service (ICDK 2020).
Why it works. The pipeline turns a national need into a visible career ladder with public money behind it, starting long before universities can act. Selecting on aptitude rather than experience widens the supply: Unit 8200 takes candidates at or above the 89th percentile of the national psychometric test, and explicitly tests raw potential (Rousseau, Ohio 2017). Teaching ethics inside the programme is a cheap way to keep a generation of skilled teenagers on the defensive side.
Where it fails or is contested. The pipeline still does not meet demand: Israel is roughly 10,000 cyber workers short (Hatuka and Carmel, TAU 2021) and about 18,000 engineers short overall (Noël, Ifri 2020). Early programmes such as Gvahim, which put programming into fourth grade in 70 schools, skew to the wealthier centre (Cordey 2019). The state loses the bidding war for its own graduates, because the private sector pays more (Antebi, INSS 2021), and the 2025 strategy still has to name the “juniors barrier” as a problem. The Magshimim numbers are programme claims, not evaluations.
How to transfer it. NÚKIB’s strategy already commits to a National Cyber Security Education Plan, inclusive programmes and the linking of initial with further education, against an EU-wide shortage of up to 300,000 experts (NÚKIB 2026). Without conscription, the state has to buy the part the army supplies in Israel: the afternoon programme, the selection test and the guaranteed first job.
The first move. Launch a three-year after-school cyber track for fifteen- to eighteen-year-olds in at least eight regions outside Prague, with a single national entry quiz, ethics in the syllabus, industry and reserve volunteers teaching, and a guaranteed interview at NÚKIB, the Cyber and Information Warfare Command or a partner company for everyone who finishes. First cohort within twelve months.
The principle in one line. Train backwards from a real job in months rather than years, then hand nineteen-year-olds responsibility they would not get anywhere else.
The Israeli evidence. Mamram’s six-month core course runs eight or nine hours of class and six or seven of laboratory a day, and needs no prior programming. It trains about 300 programmers a year, who then serve five and a half to six years; by twenty-one, one in four manages a team and one in ten runs a section with a budget (Breznitz, MIT 2002). Every course is designed backwards from a capstone that simulates the real job. Unit 8200’s six-month course runs sixteen- to eighteen-hour days in small teams and ends in a capstone that joins a technical task to an intelligence one (Rousseau 2017). Responsibility is structural. The IDF’s senior-officer-to-troop ratio is about 1:9, against 1:5 in the US Army, and since the 1973 Agranat Commission questioning authority has been expected. After 1973, 8200 was rebuilt into “small, flexible teams tasked with finding quick technical solutions” (Cordey 2019). The dossiers show the output. Check Point’s firewall grew from Gil Shwed’s military work linking classified and unclassified networks, and Pentera automated its founders’ red-team routine. Sweet Security began with the IDF information-security chief’s failed search for a product that did not exist.
Why it works. Short courses beat degrees on time to competence, because they are designed backwards from the mission. Real responsibility under budget scarcity — what Breznitz calls a “selective factor disadvantage” — produces people who improvise and who have already carried consequences. The problems are national in scale, so the threat models the graduates later build products against are real ones.
Where it fails or is contested. The famous numbers are weakly evidenced. The claim that IDF veterans are about three times more likely to found a unicorn traces back to LinkedIn posts (Suss 2025), and the best academic test uses a five-firm sample with only marginally significant results (Rousseau 2017). Military training produces operators, not businesses: interviewees describe Israel as “a startup nation, not a scale up nation”, with founders “product focused not business focused”. Military capital also needs a civilian conversion layer (Grassiani, U Amsterdam 2018). And the unit is not a prerequisite: SentinelOne’s founders had no 8200 network, were rejected by Israeli investors and built a company now worth about $8.3B; Irregular was founded by AI researchers and debaters.
How to transfer it. The copyable part is course design and delegated responsibility, not conscription. A mid-sized state can run the same six-month, mission-designed course through its military cyber command and its national CERT, and can give twenty-two-year-olds ownership of real systems. NÚKIB’s strategy asks for exactly this emphasis on “the practical application of the knowledge acquired” (NÚKIB 2026).
The first move. The Cyber and Information Warfare Command and NÚKIB jointly run one full-time six-month operator course a year, open to school-leavers and career changers without a degree, designed backwards from a capstone on a live sector range, taught largely by industry and reserve instructors, with a service commitment and a guaranteed posting at the end.
The principle in one line. Make the border between state, academia and industry porous, trusted and free of intellectual-property claims, and keep the traffic dense enough to carry tacit knowledge.
The Israeli evidence. The least-celebrated mechanism is reserve duty. The IDF computer school’s roughly 400 reservists contribute about 20,000 days a year, equal to 100 work-years, and teach at least 97% of the advanced classes. Industry experts share tacit knowledge there that they withhold in paid settings, and the IDF claims no “property rights or patents on technologies developed under its sponsorship” (Breznitz 2002). Churn is designed in. About a quarter of 8200 turns over each year, reservists return for up to three weeks a year into their forties, and the 15,000-member alumni association exists for business and hiring rather than commemoration (Cordey 2019). INSS calls the result “double-feeding”: the same people circulate between army, industry and academia (Antebi 2021). Anchor firms such as Check Point and foreign R&D centres such as Microsoft’s and Symantec’s became founder academies (principle 12). Density matters too. 120 firms sit on about 8 sq km of central Tel Aviv, where every Israeli cyber firm with more than 100 staff is based (Hatuka and Carmel 2021).
Why it works. Circulation moves the knowledge that documents cannot carry, and it does so in both directions: the state learns what industry has built, and industry learns what the state actually needs. A no-IP rule removes the friction that would otherwise stop the flow. Density makes each exchange cheap.
Where it fails or is contested. You cannot decree a cluster. Beersheba got a prime-ministerial declaration, the national CERT, a university centre, a technology park and tax discounts, and still went from one start-up founded in 2013 to eight in 2020, against 337 in Tel Aviv; its status is “not advancing, and perhaps is even eroding” (Getz, Buchnik and Zatcovetsky 2024). Only 19% of the relevant career military staff said they would move south, and 66% preferred Tel Aviv (Gal et al 2017). Circulation also has a club problem: knowledge stays inside a reservist “club membership” (Breznitz 2002), and recruitment skews to the Tel Aviv area and elite schools (Cordey 2019). And in war the circuit reverses: about 10% of high-tech and management staff were called up after October 2023 (Taub 2025).
How to transfer it. Czechia’s strategy already names enhanced civilian-military cooperation and “making use of non-state capabilities to address crises” (NÚKIB 2026). Estonia has already shown an EU-and-NATO version of the mechanism: the Defence League’s Cyber Defence Unit, a volunteer body of public- and private-sector professionals given a statutory mandate in 2014 (Osula, CCDCOE 2015). The missing pieces for us are the mechanics: a standing reserve of civilian experts with clearances handled once, a no-IP rule on state-funded training and tooling, and the discipline to concentrate the traffic in Prague and Brno rather than spreading it thin across the regions.
The first move. Stand up a cyber reserve corps of about 200 named industry experts contracted for ten to fifteen days a year to teach on state courses, staff crisis rotas and play in sector exercises, with security clearance processed once and centrally. Publish a rule that the state claims no IP on training materials or tools produced under its sponsorship.
The principle in one line. Decide who belongs in cyber at fourteen, not at twenty-four, because belonging — not ability — is what determines who enters.
The Israeli evidence. In a survey of 912 Israeli ninth-graders, 36% of Jewish boys, 18% of Arab/Palestinian boys and 6% of girls in both sectors wanted a technology job at thirty. The strongest predictor was identity: students who felt similar to programmers were more than nine times more likely to aspire to such a job, while liking mathematics explained nothing (Budge, Charles, Feniger and Pinson 2023). The adult numbers follow. About 94% of high-tech workers are non-Haredi Jews and about a third are women (Taub 2025), and only 23% of AI professionals are women (OECD 2025). Breznitz called the exclusion of Arab and ultra-Orthodox citizens “the vast waste of human resource from a national point of view” as early as 2002. Israel knows it: Magshimim targets the periphery, and the 2025 strategy commits to widening entry and to hiring wounded veterans into junior roles (INCD 2025). The counter-examples show what is possible. About 70% of staff in the 1991–98 incubator wave were recent immigrants (Trajtenberg, NBER 2000), and Zafran’s chief executive arrived as an Iranian-born teenage refugee and rose to major in 8200.
Why it works — when it does. Widening the intake is the cheapest capacity increase available, because the constraint is people, and because the marginal recruit from an excluded group is competing against nobody. It also reduces concentration risk in the economy: Israeli high-tech workers pay about 6.3 times more income tax than other workers and provided about 36% of all wage-based income tax in 2021 (Taub 2025). A narrow base carries a whole state.
Where it fails or is contested. This is the principle Israel has least delivered on. The gender gap is larger in Hebrew-language than Arabic-language schools, and the cultural association of computing with Jewish military service reinforces it (Budge et al 2023). Structural exclusion from the military route cannot be fixed by an after-school course. And the consequences are now visible as brain drain, more company registrations in the US and net emigration of skilled workers (Taub 2025).
How to transfer it. NÚKIB has already written the commitment: inclusive training, and explicit attention to “equality of employment opportunities and conditions for women, experts without a university degree and graduates of non-technical disciplines” (NÚKIB 2026). What the Israeli research adds is the measurement point. Do not measure diversity at the hiring stage, where the funnel has already closed. Measure it at fourteen, and treat “feeling similar to a programmer” as the policy target.
The first move. Run an annual survey of technology aspiration among fourteen- and fifteen-year-olds, disaggregated by gender and region, and publish it as one of NÚKIB’s indicators. Tie the funding of new education programmes to moving that number, and open every state-run cyber course to applicants without a university degree.
Israel’s cyber industry was not the natural result of having clever engineers. Venture capital emerges only on top of pre-existing research and human capital, and even then it has to be engineered (Avnimelech, Kenney and Teubal 2004). Israel engineered it in the early 1990s with about $100M and a good contract, then rebuilt the layer twice: first as specialist seed funds and foundries, and now, as private fundraising thins, as public patient capital again. The four principles in this cluster are the most directly copyable in the report, and the cheapest.
The principle in one line. Public money should take a minority position, bring in a foreign partner, and let private investors buy the state out cheaply if they win.
The Israeli evidence. Yozma (1992–93) was a $100M government fund. It put $8M into each of ten private funds, never more than 40% of any fund, and required each fund to bring in an established foreign financial institution, because the skills and networks “did not exist in Israel”. Private partners held a five-year option to buy out the state’s stake at cost plus 5–7% interest. The designers’ logic was that “successes should be highly profitable, while failure would be subsidized only to the extent that the government investments were lost” (Avnimelech, Kenney and Teubal, BRIE 2004). Venture investment rose from $5M in 1990 to $3.3B in 2000. Yozma-descended funds held about 55% of the pool and had the highest survival rates through the 2001–03 crash. Its predecessor, Inbal (1992), insured the downside and failed. The same logic ran through the incubators, where the state recovered its money only if a venture succeeded (Noël 2020), and through the 1984 R&D Law’s neutral, demand-driven grants (Trajtenberg 2000). Israel is now re-running the play. Yozma 2.0 (2024) pays institutional investors extra yield to enter venture capital (OECD 2025), and a NIS 250M fund-of-funds inside the Yozma Fund targets deep tech (IIA 2025).
Why it works. Asymmetric terms make the state a cheap, temporary partner rather than a shareholder to be managed. The mandatory foreign partner imports judgement and networks alongside the money, and officials sitting on fund boards learn what they are subsidising. Neutrality — funding any qualifying project rather than a chosen sector — reinforces emerging comparative advantage instead of guessing at it.
Where it fails or is contested. Yozma worked because decades of defence R&D and university training had already produced the deal flow; sequencing matters. The agency that invented it then lost most of its freedom: its budget allocation by 2005 was “barely above a third” of the 2000 level (Breznitz and Ornston 2012). Fund clocks are a structural problem in their own right — with ten-year lives, general partners abandon good but slow projects, at an efficiency loss that “can be in excess of 25%” (Kandel, Leshchinskii and Yuklea 2005). And the model has not produced durable domestic scale: new Israeli tech companies fell from a peak of 1,404 in 2014 to about 500 in 2024 (IIA 2025).
How to transfer it. The Czech gap is not the absence of money but the absence of terms. NÚKIB’s strategy records that funding conditions and EU rules “are unclear and continue to grow in complexity”, that procedural barriers stop organisations drawing available funds, and that NÚKIB will build “a professional structure for providers of state aid for research and development whose programmes focus on cyber security” (NÚKIB 2026). A Yozma-style instrument is a single contract, not a new agency.
The first move. Design one fund-of-funds instrument on Yozma terms: state money capped at 40% of each fund, a mandatory tier-one international co-investor in every fund, a five-year buy-out option at cost plus a small interest rate, and a state observer on each board whose job is to report what is being learned. Anchor three or four specialist funds with it, and publish the terms before the call.
The principle in one line. The first investor should know the buyer’s problem better than the founder does, and should bring the buyer with them.
The Israeli evidence. A handful of domain-expert seed investors shaped a generation. Cyberstarts wrote the first cheque into Wiz and backed Cyera, Island, Upwind, Glow, Zafran and Legit; Wiz alone returned it around $1.5B. YL Ventures seeded Axonius with $4M in 2017 and sold the stake for $270M in 2021. Team8, founded in 2014 by 8200 veterans with corporate backers from Microsoft to Temasek, works as a foundry. It starts with a thesis, then recruits founders, and opens its network of corporate security chiefs from day one. It produced Claroty and Sygnia, which raised about $4.3M and sold to Temasek for a reported $250M within three years. The model has become market structure. In 2024 Israeli cyber had a record 50 seed rounds worth $400M, tier-one global funds joined 22 seed rounds (against 10 a year earlier), and 12 “split-seed” rounds were co-led by an Israeli specialist and a global fund (YL Ventures 2025).
Why it works. Domain investors can judge whether a problem has a budget line before it has a product, and their networks turn the first customer conversation into design input. A foundry compresses the riskiest year of a company’s life: the thesis is validated by buyers before a founder is hired. Split seeds combine local judgement with the global follow-on capital that the local market cannot supply.
Where it fails or is contested. The same layer of specialist capital also financed the other Israeli cyber industry: the Atlantic Council counts 14 US investors in spyware vendors, 12 of them in Israel (Atlantic Council 2024). Specialist funds also concentrate risk in fashionable categories — new firms crowd into cyber and fintech even as formation collapses (IIA 2025) — and the Series A and B layer thinned in 2024 while seed boomed. Peak-cycle prices did real damage: Transmit Security’s $543M Series A and Snyk’s 2022 valuation both became exit constraints. And even a well-backed thesis can lose: Hunters was right about the data-lake SIEM and beaten by platforms that owned the telemetry.
How to transfer it. For a country our size, the scarce asset is not capital but a general partner with a security-chief network and the standing to convene buyers. That person can be recruited, and the state can make the job attractive by pairing the Yozma instrument with privileged access to the operators regulated under the Cyber Security Act. Report 1 sets out the foundry model in detail; the principle here is narrower — never let public money be the only money, and never let it be the expert money.
The first move. Assemble a register of 30 chief information security officers from regulated operators who agree to act as design partners and, under published conflict-of-interest rules, as angel investors. Make state co-investment conditional on a round being co-led by a domain specialist and an international fund — the split-seed rule, written into the term sheet.
The principle in one line. A small state cannot manufacture proximity to the world’s customers, capital, research and intelligence, so it should import them deliberately and on terms.
The Israeli evidence. The cluster’s first economic job was to overcome distance from the market. Venture capital, US-based management, acquisitions as “a shortcut to the market” and early Nasdaq listings gave Israeli firms the reach their geography denied them (de Fontenay and Carmel, Stanford SIEPR 2001). Yozma imported foreign partners for their know-how. About 300 multinational R&D centres (Noël 2020), 47 of them in cyber (ICDK 2020), became founder schools. The company template is explicit: Island builds 95% of its product in Israel with a US executive team, and Salt Security’s lesson is to “hire the US seller as a co-founder, not as an early employee”. Reach is also state business. Israel “lacks the global intelligence reach” of the largest powers and compensates through its alliance with the US (IISS 2021). The US–Israel Cybersecurity Cooperation Enhancement Act (2016) created a DHS grant line for joint ventures, with at least 50% private cost share, merit review and governance by the binational research foundations. The INCD works with more than 90 CERT partners and calls cyber defence “a global ‘team sport’” (INCD 2021).
Why it works. Imported reach is cheaper than building a domestic market that does not exist. Multinational centres bring frontier problems to local engineers and then lose those engineers to start-ups. Alliances buy early warning that no small state can collect alone. And capacity building abroad turns technical excellence into diplomatic standing (Tabansky 2016).
Where it fails or is contested. Borrowed reach means borrowed control. Four of the five largest acquirers of Israeli cyber firms are in the San Francisco Bay Area (Hatuka and Carmel 2021). The dual-headquarters model leaves the headquarters, sales and much of the value in California, and R&D can drain too: Snyk’s Israeli team fell from several hundred to about 90 while the company passed 1,500 staff. Alliance dependence cuts both ways — the same United States that amplifies Israeli capability blacklisted NSO and stopped the L3Harris deal.
How to transfer it. Our borrowed reach is institutional: NATO, the EU and the single market. NÚKIB’s strategy is explicit that for resource-constrained states “the solution ... lies in intensive cooperation with reliable partners”, names cyber attachés and the NATO Integrated Cyber Defence Centre, and singles out Czechia’s “multi-layered relationship with Israel” (NÚKIB 2026). Cato Networks is already tripling its Prague R&D centre. The task is to convert relationships into instruments with money attached.
The first move. Create a binational co-funded industrial R&D instrument with Israel on the DHS–BIRD model: joint ventures only, at least 50% private cost share, merit review, unclassified projects, and a sunset clause. Pair it with a landing programme that makes Prague and Brno the default second R&D site for scale-ups, on the condition that local teams are allowed to spin out.
The principle in one line. Treat an acquisition as the start of the next three companies, and design tax, liquidity and R&D rules so that the people and the money stay.
The Israeli evidence. Recycling is the most consistent finding across the fifty dossiers. Microsoft’s ~$320M purchase of Adallom (2015) produced both Wiz and Armis. Symantec’s purchase of Luminate produced Torq, NetApp’s purchase of Spot.io produced Upwind, and Aorato’s founders went on from Microsoft to build Apiiro. Failure recycles too: Cybereason’s collapse produced 7AI, and IntSights and Argus alumni built Guardz. Check Point plays the “Fairchild” role, its alumni founding or seeding Palo Alto Networks, Imperva, SentinelOne and Illusive (Hatuka and Carmel 2021). In 2024, 15 new Israeli cyber start-ups were founded by entrepreneurs who had already sold a company, and five Israeli start-ups bought other Israeli start-ups (YL Ventures 2025). Wiz’s sale alone is estimated to have produced about NIS 10B in Israeli tax revenue, roughly $1.5B for one seed fund and about 1,000 newly liquid engineers.
Why it works. An exit returns three things at once — capital, experienced operators and buyer relationships — and it returns them into a network dense enough to reuse them within months. The acquirer’s local R&D centre then becomes the next founder school, which is why the Imperva dossier’s lesson for states is to negotiate R&D continuity at exit rather than to mourn the deal.
Where it fails or is contested. The exit is also the leak. Between 1995 and 2005, 89% of Israeli tech firms followed one of two paths, venture-only or venture-then-trade-sale, and only about 6% touched public markets (Hashai and Menuhin 2006). “The products created by the Israeli digital industry are in fact the companies themselves” (Noël 2020). Decision rights go with the sale: CyberArk cut about 500 jobs within days of closing, and Israel no longer has an independent anchor in either cloud or identity. The OECD names the structural cause as “a comparatively low base of long-term capital” (OECD 2025), and the Taub Center now records contraction in start-up formation, skilled emigration and a rise in US company registrations.
How to transfer it. Czechia will not have a $32B exit soon, but it already has acquisitions, foreign R&D centres and senior engineers with option packages. The policy surface is small and specific: taxation of employee options at exit rather than at grant, enforceable limits on non-competes, room for secondary sales so staff can take liquidity without forcing an early sale (the Island and Claroty pattern), and commitments on local R&D negotiated when a state-supported company is bought.
The first move. Write an “exit covenant” into every state-backed instrument: any company that has taken public research or venture money commits, on acquisition, to maintain its local R&D headcount for a defined period and to report it. Pair it with a matched pre-seed facility open only to founders and senior engineers who start a new company within twenty-four months of an exit, and publish an annual register of where R&D and decision rights actually sit.
The first twelve principles explain how Israel built capability and companies. The last four explain what keeps them ahead of adversaries and able to operate in the world. Two are about the frontier: design against a real attacker, and publish what you learn. Two are about the guardrails. This is the cluster Israel executed least evenly, and the evidence for it is Israel’s own worst years.
The principle in one line. For every asset, first ask which actor it must withstand, then build and test to that tier. Publish a national threat of reference and revise it every year.
The Israeli evidence. Resolution 3611 made an annual “national threat of reference” one of the bureau’s nineteen founding tasks, and Israeli cyber policy grew from national-security threats rather than cybercrime (Benoliel 2015). The habit reaches the frontier. Pattern Labs, now Irregular, co-wrote with RAND the model-weight security framework used by leading AI labs. It identifies about 38 attack vectors and sets five levels, from SL1 (amateurs) to SL5 (the most capable nation-states) (Nevo et al, RAND 2024). Offence taught defence. Stuxnet’s roots were “not in the IT domain but in nuclear counter-proliferation”, and in industrial systems “the worst vulnerabilities are not bugs, they are features” (Langner 2013). The defensive record follows. Iran has been “forced to focus mainly on soft targets” (Anderson and Sadjadpour, Carnegie 2018). An Iranian attack on the grid in 2015–16 hit honeypot decoys, and wartime DDoS peaking at a million attempted logons a second in 2023 had no significant impact (Freilich, INSS 2024). In June 2025 Israel “emerged largely unscathed in the cyber domain” (Sharma, MP-IDSA 2025). Firms sell the same logic: Waterfall sells “certainty to buyers facing physical consequences”, and XM Cyber made “the attacker’s mental model the product”.
Why it works. A named adversary makes security investment proportionate, because not everything needs SL5. It gives buyers and vendors a specification that can be tested, and it lets offensive knowledge inform defence.
Where it fails or is contested. A named adversary can harden into a “conception”. Hamas showed no cyber spike before 7 October (Google TAG and Mandiant 2024), and low-end vectors were missed. Palestinian Islamic Jihad intercepted unencrypted IDF drone feeds for two years and hacked road cameras for rocket targeting. In June 2025 Iranian actors used weakly secured Israeli security cameras to adjust missile fire (Freilich 2024; Sharma 2025). Ransomware locked every system at Hillel Yaffe hospital in October 2021 and bed occupancy fell from 83% to 64% (Abbou et al 2024); a threat model built around states has to cover that too. A perimeter defined by named entities also misses consumer IoT: 1,355 hijacked smart sprinklers could empty a water tower in an hour (Nassi et al, BGU 2018).
How to transfer it. NÚKIB already names its adversaries. It calls Russia “the biggest direct and long-term threat” and also names China, North Korea and Iran, and it records Iranian activity against Czech water-management infrastructure. Czechia made its first public attributions in May 2024 and May 2025 (NÚKIB 2026). What remains is to turn those names into specifications. The comparative literature adds a budget rule: rank critical infrastructure by importance, so a smaller state protects its most important assets first (Tvaronavičienė et al 2020).
The first move. NÚKIB issues an annual national threat of reference, classified in full with a public summary. Starting with water utilities, each designated operator assigns an adversary tier to its most critical systems and has them tested against that tier. Cameras, remote-access paths and consumer-side devices count as in scope.
The principle in one line. Fund deep, open research in a few elite laboratories, and make every attack they publish arrive with a coordinated disclosure and a mitigation that can be deployed.
The Israeli evidence. The base is decades of theory. Shamir co-invented RSA (Rivest, Shamir and Adleman 1978). Biham and Shamir’s differential cryptanalysis rediscovered in public an attack that IBM and the NSA had kept secret for eighteen years (Biham and Shamir 1993). Goldreich and Wigderson co-proved that every NP statement has a zero-knowledge proof (Goldreich, Micali and Wigderson 1991). After a 2012–13 funding call, matched, excellence-based academic cyber centres produced more than 500 papers (Cohen et al, New America 2017; ICDK 2020; INCD 2021). The signature is attack plus fix. Tel Aviv University’s NXNSAttack found DNS amplification above 1,620 times. BIND, Unbound, PowerDNS and CZ.NIC’s Knot shipped fixes, and Google, Cloudflare, Amazon and Microsoft patched, mostly with the authors’ MaxFetch mitigation (Afek, Bremler-Barr and Shafir 2020). Rogue7 was disclosed to Siemens alongside publication (Biham et al 2019). The Technion’s Morris II AI worm came with a guardrail that caught it at a true-positive rate of 1.0 (Cohen, Bitton and Nassi 2024). Companies copy the habit: Claroty’s Team82, Oligo, Zenity Labs in OWASP, and Koi, whose thirty minutes on the Darcula attack produced its thesis, first product and press coverage.
Why it works. Publishing an attack together with its fix earns trust from vendors and regulators and sets standards. It also turns a lab into a school: Daniel Genkin, whose acoustic key-extraction work with Shamir and Tromer produced a GnuPG patch, went on to co-author Spectre. Start-ups get their theses from the same work, and in the dossiers research is repeatedly “the go-to-market”.
Where it fails or is contested. The academic base is thinning. Israel’s share of world publications fell from 0.94% to 0.67% between 2000 and 2022, only 1.3% of its papers are highly cited (last among eight peers), and international co-authorship is falling (Getz and Barzani, Neaman 2024). Industry funds only about 7% of university research, and more than 90% of commercialisation income comes from one institute (Bentur et al 2019). The capability is dual-use: people who can break ciphers are also recruits for offence. Israel also has no public equivalent of DARPA’s AI Cyber Challenge or the Five Eyes’ CAGE competitions for autonomous defence (Standen et al 2021; Zhang et al 2026).
How to transfer it. Czech institutions are already in the loop. CZ.NIC’s Knot was among the resolvers fixed after NXNSAttack, and Masaryk University co-authored NATO’s reference architecture for autonomous cyber-defence agents (Kott et al 2019). NÚKIB coordinates national cyber research. Its own strategy admits, though, that “the practical use and deployment of research results is often problematic” (NÚKIB 2026). The international frameworks list what is missing. The Oxford model’s top stage of responsible disclosure requires legal protection for those who disclose flaws responsibly (Oxford GCSCC 2021). ENISA asks: “Is there a plan to link R&D initiatives with real economy?” (ENISA 2020).
The first move. Run a matched-funding call on Israeli terms for two or three university cyber research centres: awards on excellence criteria, with each university matching the funding. Add a disclosure clause: every attack a centre publishes goes through coordinated disclosure via the national CERT and ships with a mitigation. Legislate a safe harbour for good-faith security research in the same session.
The principle in one line. Put export control, end-use vetting and domestic oversight in place while offensive-grade skill is being built, not after, because the reputational cost falls on the whole ecosystem.
The Israeli evidence. Resolution 3611’s work plan already called for better export procedures and oversight in 2011. What followed shows the cost of letting capability outrun governance. Eight Israeli vendors make up 43.9% of the 435 entities in the Atlantic Council’s global spyware dataset (Roberts et al 2024). Of the 74 governments known to have bought spyware or forensics tools, 56 bought from firms based in or connected to Israel. A study cited by Haaretz found that 80% of the founders of Israel’s roughly 700 cyber companies had served in IDF intelligence (Feldstein and Kot, Carnegie 2023). Candiru “reportedly recruits from the ranks of Unit 8200” and ran more than 750 sites impersonating Amnesty, the WHO and others, and Israel’s export licensing is “almost entirely opaque” (Citizen Lab 2021). Licensing followed geopolitics. Ukraine was blocked from buying Pegasus and Estonia barred from using it against Russian targets. Israel is not a formal Wassenaar member, and when rules tightened, firms moved export desks to Cyprus (Feldstein and Kot 2023). The check that worked came from outside: the US Entity List designation of November 2021 pushed NSO towards bankruptcy, while regulators at home seemed “largely unfazed” (Kotliar and Carmi 2024). At firm level, Cellebrite suspended Serbian customers but dismissed similar evidence on Jordan and Kenya, an inconsistency its dossier says investors price in.
Why it works — where it is done. Guardrails are a licence to operate in allied markets. They protect clean firms from being tarred by others, keep the alliance that supplies reach (principle 11), and give talented people an ethical line. Magshimim teaches “cyber ethics” for this reason.
Where it fails or is contested. Export control is also foreign policy, and secrecy limits transparency. Demand does not go away: when one supplier is sanctioned, buyers move to others, and vendors change jurisdiction and name. Candiru has traded under at least five names.
How to transfer it. Czechia is today more buyer than producer, which makes this the cheapest moment to act. 14 of the 27 EU member states bought from NSO (Atlantic Council 2024). The European Parliament recommends import controls, an EU entity list and more transparency. The Atlantic Council recommends “Know Your Vendor” rules for government buyers, beneficial-ownership registries and published export licences. NÚKIB’s strategy already commits to regulation “balancing national security and individual rights”, with powers subject to monitoring (NÚKIB 2026).
The first move. Attach a guardrail clause to every state instrument proposed in this report: the fund, the pilots, the R&D centres and the binational fund. The clause requires a published end-use policy for dual-use products, disclosure of beneficial ownership, and no sales of intrusion tools to unvetted end users. The state, as a buyer, adopts “Know Your Vendor” rules and publishes an annual aggregate report on intrusion-tool procurement.
The principle in one line. Automate collection and triage, but do not automate away the person who notices what the model does not expect. Warnings should be pushed to decision-makers, not left in a pool.
The Israeli evidence. October 7 was “not the result of a single glaring failure”, but its causes included “an overestimation of Israel’s technological capabilities” and a drift from human to technical collection. Monitoring of Hamas hand-held radios reportedly stopped a year earlier, while Hamas used wired phones and fed deception through channels it knew were watched. The IDF had held the “Jericho Wall” attack plan for more than a year. A Unit 8200 NCO who warned in July 2023 that Hamas exercises matched it was dismissed as “aspirational” (Wyss, CTC Sentinel 2024). A former senior officer blames a “love affair” with cyber intelligence and AI. In his account, automated processing “with little or no human intervention” replaced pushed warnings with an “intelligence pool”, and 8200’s open-source unit, Hatzav, was dismantled in 2021 on the strength of machine translation (Bar, NIPP 2024). The chief of staff had warned in 2018 that “too much information is not a guarantee for better command and control” (Eizenkot 2018). Civilian cyber defence, by contrast, held through 2023–25. The technical literature agrees that machine-learning defences can never be the only layer, because adversarial training “should have no effect” on adversarial examples (Shamir et al 2019).
Why it works. A record of technical superiority breeds a fixed belief about what the enemy will do, and automation removes the friction where anomalies used to surface. A protected dissenter puts that friction back on purpose. It matters most exactly when it feels least necessary, because the riskier a surprise attack looks, the more readily it is dismissed (Wyss 2024).
Where it fails or is contested. Dissent channels decay into ritual. Israel created a “Devil’s Advocate” unit after 1973 (Rousseau 2017), and fifty years later such mechanisms had become “routinized and ritualized” (Wyss 2024). A speak-up culture in a hierarchy is “easier in theory than in practice”. Israel’s 2025 strategy now writes in countermeasures against the biases that lead analysts to underrate strategic surprise (Shabtai 2025), but a written rule is not proof that behaviour has changed.
How to transfer it. NÚKIB plans AI-based detection and the automation of routine work so that savings can be redirected to salaries (NÚKIB 2026). That is the right direction, provided each automation decision is weighed against the human capability it removes, and the analyst who disagrees has a guaranteed route to the top.
The first move. Adopt a written push rule for the national CERT, the National Cyber Operations Centre and the intelligence assessment staff. Any analyst may escalate a warning to the director and must receive a written reply within 72 hours, and every escalation is logged and reviewed each year. Before any analytic unit is cut or replaced by automation, a red team reviews which human capabilities will be lost.
Some of Israel’s advantages are side effects of conditions no democracy should create on purpose. Others are choices that Israel’s own research now treats as mistakes. The following should stay in Israel.
The threat as the engine. Conscription-scale selection and a permanent existential threat gave Israel its workforce advantage (”Israel’s tech-heavy military and national conscription gave it an advantage”, Lewis 2016). A state cannot import them, and should not try. Czechia’s route to scale runs through coalitions, EU funds and certification.
Spyware as an export industry. Opaque, geopolitics-driven licensing made Israel-linked firms the supplier to 56 of 74 known spyware-buying governments, invited a Cyprus workaround and imposed a reputational cost on the whole ecosystem. No one should copy it.
Deniable tit-for-tat as deterrence. Israel-linked personas have taken Iranian petrol stations and banks offline (Google TAG and Mandiant 2024; Sharma 2025). But Israel’s reported counter-strike after the 2020 water attacks did not deter Iran, whose attacks resumed within weeks (Freilich 2024), and in the 2025 war cyber gave only an “incremental edge” (Sharma 2025). NÚKIB commits to developing offensive and multi-domain capabilities. They belong under law and allied coordination, not in signalling games.
Powers ahead of oversight. The 2018 draft bill would have allowed equipment seizure without a court order and monitoring of all internet traffic. Israel’s legal dimension is its weakest, rated only “established” (Lewis 2016).
The exit-only default and peak-cycle capital. Selling anchors without negotiating anything, $543M Series A rounds and hiring to the size of the round (Transmit, Snyk, Deep Instinct) are costs of the Israeli model, not features of it.
A cluster by decree. Beersheba has a declaration, a CERT, a university and tax discounts, and saw eight start-ups founded in 2020. Buildings do not move people.
A closed elite. A pipeline that reproduces one demographic runs out of people and concentrates national risk in a narrow, mobile workforce.
The sixteen principles are not a menu. Israel’s advantage comes from how they feed each other, and its current weaknesses show where the loop leaks. The flywheel runs in six steps:
Ends and an architect (1, 2) create a mandate and remove the turf friction that stops everything else.
A trusted civil defender and a demanding state customer (3, 4) turn the threat into problems that companies can solve and data that defenders can share.
The talent engine (5–8) turns those problems into people who have already solved them at national scale.
Capital and reach (9–11) turn those people into companies with global customers.
Exits (12) return money, experienced operators and buyer relationships to the start of the loop, along with tax revenue that funds step one.
The frontier and the guardrails (13–16) keep the problems hard, the research ahead of the attacker, and the licence to operate intact.
Five pairs do most of the reinforcing:
4 and 13: a named-adversary specification is what makes the state a demanding customer rather than a grant office.
3 and 14: a trusted, no-fault CERT is also the channel for coordinated disclosure.
6, 7 and 12: missions, circulation and exits together produce the repeat founder, the most valuable asset in the dossiers.
9 and 10: Yozma’s foreign partners created the venture layer from which the specialist funds later grew.
11 and 15: alliances supply reach, and guardrails keep them. The US Entity List showed that an ally can also close the door.
The loop now leaks at three points. The narrow funnel (8) is starving the pipeline: the number of new companies has halved from its peak, skilled workers are emigrating and more companies are registering in the US. Exits (12) are sending decision rights abroad. And the dissent failure (16) contributed to a surprise that Israeli analysts now compare with 1973 (Bar 2024). A state copying the model should build these three points more strongly than Israel did, not less.
If a state is starting today, four principles matter most:
Treat talent as national infrastructure (5). It has the longest lead time: a fifteen-year-old recruited in 2027 is a founder in 2037. It is also the constraint every comparative study names.
Make the state the first demanding customer (4). It is the cheapest principle, because it uses rules already in force. It is also the fastest, because pilots can start this year.
Share the upside, never insure the downside (9). A single well-drafted contract brings in the capital and the know-how a mid-sized market lacks, and Israel is running the same play again with Yozma 2.0.
Build the guardrails with the capability (15). It is almost free at the start and ruinously expensive to retrofit, as NSO showed.
Principle 2 is the precondition for all four. Without market pay and the authority to arbitrate between ministries, none of them gets done.
How to know it is working. Measure capability, not commitment. The ITU index put Israel below Estonia and beside Czechia, and ENISA concedes that its own framework measures maturity rather than effectiveness (ENISA 2020). Use outcome indicators instead: the technology aspiration of fourteen-year-olds, operator-course graduates placed each year, paid pilots with young vendors, split-seed rounds, companies started by founders after an exit, disclosures shipped with fixes, and median time from disclosure to mitigation in regulated entities. Top that list with the Oxford model’s own definition of the highest stage for a national cyber marketplace: “Domestic cybersecurity products are exported to other nations and are considered superior products” (Oxford GCSCC 2021).
Israel’s cyber power is often explained by its enemies, its army or its culture. The evidence points elsewhere. Across 78 nations, regional differences in cyber culture disappear once development and the scale of internet use are accounted for (Creese, Dutton and Esteve-González 2021). Israel became a cyber power before it had a strategy, then built the machinery to keep that power and turn it into an industry: a NIS 4.5M bureau, a civil defender without police powers, a six-month course designed backwards from a real mission, a $100M fund with a buy-out clause, and matched academic centres that publish the fix with the attack. Where Israel failed, the causes were choices, not fate: a narrow funnel, opaque export licensing, and faith in machines over the analyst who disagreed.
A mid-sized European state can copy the mechanisms without the threat, and it can build the guardrails that Israel added late. Czechia starts with more than it thinks: a comprehensive cyber law since 2014, a respected agency, a strategy that already names the right gaps, and Czech code and researchers inside the global disclosure loop. What it lacks is the engine: the pipeline, the terms, the first customers and the recycling that turn talent into capability and companies. Each of those is cheap next to the threat it answers, and each takes years to mature. The option value lies in starting all four first moves this year, because every year of delay is another cohort of fifteen-year-olds who never find out that the field was meant for them.