What Cybertech Actually Is — The Israeli Example

September 26, 2026
blog image

Israel is the only country that built all four inside a decade and kept them able to talk to each other, because it published its definitions before it built its institutions. What it actually built is a translation layer: the machinery that converts an intelligence problem into a product category. That is what cybertech is, and the edges of the definition decide what a country cannot see.

ENSI research — built on a library of 164 primary documents and 52 company dossiers


The argument, before the list

Three institutions with nothing in common have independently reached the same conclusion about the word at the centre of this series. In 2014, researchers at Canada’s signals-intelligence establishment harvested nine published definitions of cybersecurity — from the ITU, the CNSS, DHS, Public Safety Canada, Oxford and four individual scholars — and found them mutually inconsistent and overwhelmingly technical (Craigen, Diakun-Thibault and Purse 2014, pp. 14–15). In 2018, a British professor of international politics concluded that “cyber” has become “so nebulous that it has essentially become meaningless; it simply refers to too many different things at different times for different people” (Futter 2018, p. 202). And in 2020, the product-development team that maintains a listed cyber-security equity index — people whose job is to decide, every quarter, which companies are cyber companies — conceded in print that “there is no one consistent technology or segment” (Jones, Nasdaq 2020, p. 3).

A spy agency, a political scientist and a stock exchange, approaching from opposite ends, all report that the object does not hold still. The usual response is to treat this as a failure of the field and to propose a tenth definition. That is the wrong reading, and correcting it is the point of this report.

The absence of one definition is not a deficiency. It is evidence that there are four definitions, each doing a different institutional job, and each of them load-bearing. The academic definition exists to make an interdisciplinary field arguable: Craigen’s replacement — cybersecurity as “the organization and collection of resources, processes, and structures used to protect cyberspace and cyberspace-enabled systems from occurrences that misalign de jure from de facto property rights” (2014, p. 13) — is deliberately non-technical, because its purpose is to get engineers, lawyers, economists and psychologists into one conversation. The standards definition exists to be audited: NIST’s Cybersecurity Framework 2.0 is “a taxonomy of high-level cybersecurity outcomes” that is explicitly “sector-, country-, and technology-neutral” and contains no adversary, no offence and no state (NIST 2024, pp. i–ii). The doctrinal definition exists to allocate war-fighting responsibility, which is why Israel’s own operative definition of cyberspace deliberately excludes organisational and ideological properties as contingent rather than inherent (Tabansky 2011, p. 78). And the market definition exists so that capital can be allocated and membership adjudicated — Nasdaq’s classification is what it is because a committee has to be able to decide it, not because it is conceptually superior (Jones 2020, p. 5).

Borrow one of the four and you get an institution shaped like it. Take the standards definition as your national definition and you build a compliance regulator that is excellent at producing maturity scores and has no view on an adversary. Take the doctrinal definition alone and you build a command that cannot talk to a bank. Take the market definition — which is what happens by default, because it arrives free with every vendor briefing — and you build a trade association that mistakes a category map for a threat picture. Craigen’s warning is institutional rather than semantic, and it is the sentence this whole report turns on: the absence of a shared definition “impedes technological and scientific advances by reinforcing the predominantly technical view of cybersecurity while separating disciplines that should be acting in concert” (2014, p. 13). A state that defines cyber narrowly as an IT problem gets a narrow IT institution, and then wonders why it has no answer to everything the institution was not built to see.

Israel is the best place in the world to watch this happen, for a reason that has nothing to do with how many start-ups it has. Between roughly 2010 and 2018 it built all four definitions, and — this is the unusual part — kept them mutually translatable. The sequence matters more than the content. In May 2011, three months before the government resolution that created its first cyber institution, Lior Tabansky published an essay at the Institute for National Security Studies whose stated purpose was to “survey the field and create a common language for a fruitful public discussion of the developing issue of cyber security, proposing operative definitions… that can be applied in a discussion of Israel’s national security” (Tabansky 2011, p. 76). In December of the same year, Isaac Ben-Israel — the physicist and reserve major-general who had run the 2010 National Cyber Initiative — co-authored the companion essay, which builds its case for cyber policy not out of weapons but out of Popper’s three worlds, the Tofflers’ three waves and Romer’s endogenous growth theory, arriving at knowledge as “a non-rival, partially excludable good” before it reaches a single threat (Ben-Israel and Tabansky 2011, pp. 22–24). Resolution 3611 followed in August 2011 with a National Cyber Bureau of about thirty people and a first-year budget of NIS 4.5M; the operational authority came in 2015, the merged Directorate in 2017–18, and the Israeli Cyber Defense Methodology — built directly on NIST’s framework and its SP 800-53 controls — was published in June 2017 and adopted by the whole Israeli government in 2018 (NIST and INCD 2020, pp. 1–2).

Israel published its definitions before it built its institutions. Almost every other state does the reverse: it creates an agency, gives it a budget line, and then commissions a strategy that reverse-engineers a definition from whatever the agency already does. The Israeli order is cheap to copy and almost never copied. It costs nothing but authority, and it buys something no reorganisation can retrofit — a vocabulary that the general staff, the regulator, the university and the venture fund all use in the same sense.

The deeper reframe follows from that. If you ask why one small country produces both Unit 8200 and Wiz, the usual answers — conscription, threat, chutzpah — explain the supply of people but not the shape of the output. The better answer is definitional. Cybertech is an institutional translation layer: the machinery that converts an intelligence problem into a product category, and occasionally converts it back. Tabansky’s 2011 taxonomy of cyber weapons has three groups — unequivocally offensive, unequivocally defensive, and a dual-use middle of network monitoring, vulnerability scanning, penetration testing, encryption and the camouflage of content and communications (2011, p. 80). Read that middle category again in 2026 and it is not a doctrinal list. It is a product catalogue. Network monitoring became Armis and Axonius; vulnerability scanning became Orca and Wiz; penetration testing became Pentera, Cymulate and XM Cyber. The doctrine wrote the segment map fifteen years before the segments had names.

That translation is also where the model’s costs live. A definition built on means rather than effects — Ben-Israel and Tabansky’s precise and correct claim that information warfare is ancient and only computer warfare is new (2011, p. 28) — has two consequences a state must accept together. It makes the dual-use export problem structural rather than accidental, because an intrusion tool and an assurance tool are the same object under different licences. And it leaves the cognitive domain outside the definition and therefore, unless someone says otherwise in the same document, outside everybody’s mandate. Report 6 in this series documented exactly that hole in the Israeli case: a 2025 national strategy that lists a public mindspace resilient to foreign influence among its objectives, names no owner, and gives nobody the legal power to act.

For a mid-sized European state — the Czech Republic is our default home example — the practical question is not “what is the correct definition of cyber”. There isn’t one. It is: which of the four definitions is your agency actually running on, which of the other three have you quietly imported from a vendor, and what has the combination made you blind to. Report 1 ranked the fifty companies Israel’s machine produced; Report 2 distilled sixteen principles a state can act on; Report 3 specified the twenty-four features of the best defence anyone could assemble; Report 5 sorted the 2026 threat claims by the evidence behind them; Report 6 examined what happens when a first-rank cyber power meets an adversary it has decided not to treat as one. This report sits underneath all of them and asks the question they assumed an answer to.

Summary of main points

  • There are four working definitions of cyber, not one, and each builds a different institution. The academic (Craigen et al. 2014 — interdisciplinary, property-rights based), the standards definition (NIST CSF 2.0 — six outcome Functions, no adversary in it), the doctrinal (Tabansky and Ben-Israel — computer warfare as a means-defined subset of information warfare) and the market definition (Nasdaq’s two classes, Deloitte’s sixteen Israeli segments, ENISA’s value stack). Adopt one by accident and you get an agency shaped like it.

  • Israel published its definitions before it built its institutions, and defined cyber as economics first. Tabansky’s INSS essay in May 2011 explicitly to create “a common language”; Ben-Israel’s companion essay grounded in Popper, Toffler and Romer; Resolution 3611 in August 2011 with thirty staff and NIS 4.5M. The order is the cheapest transferable feature in this entire library.

  • The load-bearing Israeli concept is the boundary between information warfare and computer warfare. “What is new about Third Wave warfare… is not information warfare per se, but computer warfare” (Ben-Israel and Tabansky 2011, p. 28). Cyber is defined by means: bombing a data centre is not cyberwar, however destructive. Futter reaches the identical line from Leicester seven years later.

  • Defining cyber by means leaves the cognitive domain to nobody. Psychological warfare and media management sit inside information warfare and outside cyber. That is analytically right and institutionally catastrophic if no one else is named — the structural gap Report 6 documents in the Israeli response to Russia.

  • Most of what states do to each other in cyberspace is an intelligence contest, not war. Rovner’s definition — “an information duel… about maintaining an information advantage” — and his verdict that these activities “differ from traditional intelligence activities in degree, not kind” (TNSR 2020, pp. 11–12). The answer decides who owns cyber: the spies or the military.

  • Cybertech is an institutional translation layer. Tabansky’s 2011 “dual-use” middle category of cyber weapons — network monitoring, vulnerability scanning, penetration testing, encryption, camouflage — is, read in 2026, a list of product categories worth tens of billions. The doctrine drew the segment map before the segments existed.

  • The industry has roughly twelve real segments, and only eleven are defined by what they protect. The twelfth — the SMB and MSP platform layer — is defined by who buys. That tells you what a “segment” actually is: an administered answer to a buyer’s assessment problem.

  • Category creation and vendor consolidation are the same problem solved from opposite ends. The World Bank’s account of cyber as a market for lemons — returns “unquantifiable”, buyers unable to judge effectiveness before an attack (Vergara Cobos 2024, pp. 73–74) — explains both. Vendors invent labels because a label is the cheapest way to be legible; buyers consolidate because one large vendor is the cheapest way to reduce assessment cost. More than 75% of CISOs are pursuing consolidation, and for risk reasons rather than budget ones (Deloitte 2024, p. 14).

  • The market perimeter is administered, not natural, and its demand base is one country. Nasdaq runs a classification committee, reviews quarterly and rules that companies “may not apply, and may not be nominated for inclusion” (Jones 2020, p. 5). Meanwhile North America is about 54% of global cybersecurity spending — sixteen times all of Latin America and the Caribbean — and governments are roughly 36% of the market, “primarily driven by demand from the United States” (Vergara Cobos 2024, pp. 75, 79).

  • The definition decides the measurement, and the measurement decides the politics. The ITU index records whether laws and agencies exist and says itself that it does not measure the quality of actions; Israel sits in Tier 2 beside Czechia. Belfer ranks it outside the top ten and says it is under-ranked because it is opaque. IISS puts it top of the second tier, behind only the United States. Three indices, three answers, because three definitions of cyber power.

  • For a mid-sized EU state the instruction is a sequence, not a menu: define in public, adopt the international taxonomy for organisations, diffuse through sectoral regulators rather than a general law, make market analysis a statutory duty, choose three or four segments deliberately instead of importing a category map — and name the owner of everything the definition leaves outside, in the same document that draws the boundary.


How this report is organised

Six sections and eighteen numbered points. Section I sets out the four definitions of cyber, one at a time, with what each makes visible and what each hides. Section II draws the three boundaries that matter — with IT security, with intelligence, and with information and influence operations. Section III is the anatomy of cybertech as an industry: twelve segments drawn from the fifty-two company dossiers behind this series, then the lifecycle of a segment from birth to absorption, and the economics that explain both. Section IV shows the Israeli concept becoming machinery. Section V is the argument that the definition decides the outcome — which agency exists, who owns the budget, what gets measured, and what a country is therefore structurally blind to. Section VI is the transfer.

Sources are cited inline by lead author or institution and year, and every one of them sits in the library behind this series. Company facts come from the fifty-two dossiers and are often company-reported; where a figure is contested or thin we say so. This report deliberately does not repeat Report 2’s principles or Report 3’s features — it explains the concepts underneath them.


I · The four definitions of cyber

Four definitions, four purposes, four institutions. They are not competing answers to one question. They are answers to four different questions that happen to share a prefix. The order below runs from the most abstract to the most consequential in money terms, and each point closes with the same two-part test: what does this definition make visible, and what does it hide.

1. The academic definition — cyber as a socio-technical field nobody can fence

Craigen, Diakun-Thibault and Purse open their paper with an epigraph from Charles Leslie Stevenson that should be printed on the wall of every national cyber agency: “To choose a definition is to plead a cause.” Their survey of the nine existing definitions finds five recurring themes, and the list is a usable checklist for any state drafting its own: technological solutions · events · strategies, processes and methods · human engagement · referent objects of security (2014, p. 15). Most published definitions cover two or three of the five and are silent on the rest. A state can audit its own strategy against that list in an afternoon and will usually find that “human engagement” and “referent objects” are missing — which is to say, it has not said who is being protected or by whom.

Their own replacement definition does two useful things. It moves the referent object from “data” and “assets” to property rights — borrowed from Ostrom and Hess — so that the protected thing is anything with meaning or value, and the protected relations include access, extraction, contribution, removal, management, exclusion and alienation (2014, p. 18). And it explicitly includes “cyberspace-enabled systems”, which puts operational technology, industrial control and medical devices inside the definition rather than bolted on afterwards as a special case. Any state whose definition of cyber does not do that second thing will spend the next decade arguing about whether the water utility is in scope.

The paper’s other contribution is structural. It characterises cybersecurity as a scale-free network with high degrees of change, connectedness and speed of interaction, in which “the capabilities of actors in the network are potentially broadly similar” (pp. 15–16). This is the academic root of the claim that a small state can punch above its weight — and note that the claim is a property of network topology, not of national character. Nye reaches the same place from international-relations theory: “The low price of entry, anonymity, and asymmetries in vulnerability means that smaller actors have more capacity to exercise hard and soft power in cyberspace than in many more traditional domains”, and “it makes little sense to speak of dominance in cyber space as in sea power or air power” (Nye 2010, abstract and p. 4). He is careful about the limit, too: “Power diffusion is not the same as power equalization” (p. 11). A teenager and a government can both do damage, but only states can mount sophisticated attacks on hardened targets, because those require “large intelligence agencies to intrude physically and/or crack highly encrypted codes”.

Then there is Futter, who is not offering a better definition but arguing that the word should be retired. His case is that “cyber” is a prefix that could almost always be replaced by “information”, “computer”, “digital” or “electronic” without loss, that social science “hijacked a concept that emerged from the hard sciences”, and that the resulting vagueness “often drives … misunderstanding and bad policy” (2018, pp. 201, 212–213). His most uncomfortable observation is about who benefits: “military officials and computer security companies have used imprecise language to help bolster budgets and business through nurturing a bleak and scary picture of the current information environment” (p. 210). Anyone reading a vendor category map — or a national threat assessment written with one open on the desk — should keep that sentence in view.

But Futter also supplies the finding that rescues the whole enterprise, and it is easy to miss. The precise vocabulary never died; it simply left the public debate. “US Cyber Command, UK National Cyber Security Centre, and the Israeli National Cyber Security Authority all have CNO policies and doctrine, but this is conspicuous by its absence in much academic writing and policy discussion” (p. 210). The mush is in the conference programme. Inside the agencies, people still say computer network exploitation when they mean computer network exploitation. A state that wants a serious cyber institution does not need to invent language. It needs to make the internal language the public one.

What it makes visible: the interdisciplinary object, the non-technical stakeholders, operational technology, and the fact that every definition is an argument for a budget. What it hides: operational specificity. You cannot task a unit, write a control or price a contract from Craigen’s definition, which is precisely why the other three exist.

2. The standards definition — cyber as a governed process

The most widely used definition of cybersecurity on earth is not a sentence. It is a taxonomy of six words, and its authority comes from the fact that it can be audited.

NIST’s Cybersecurity Framework 2.0, published in February 2024, defines cybersecurity by outcomes rather than technology: it “offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity”, and it “does not prescribe how outcomes should be achieved” (NIST 2024, p. i). The Core is a three-level hierarchy of Function → Category → Subcategory, described explicitly as “not a checklist of actions to perform” (p. 3). The six Functions are the operative definition:

GOVERN · risk-management strategy, expectations and policy are established, communicated and monitored · IDENTIFY · current risks are understood · PROTECT · safeguards are used · DETECT · possible attacks and compromises are found and analysed · RESPOND · actions on a detected incident are taken · RECOVER · assets and operations are restored.

The addition of GOVERN in version 2.0 is itself a definitional statement, and the most consequential one NIST has made in a decade. It moves cybersecurity from a technical function to an enterprise-risk and board question. A CISO who reported to the head of IT in 2013 and reports to the board in 2026 is living inside that edit.

Two design choices make this framework the one that travels. The first is neutrality: the outcomes are “sector-, country-, and technology-neutral” (p. ii), which means a national methodology can be built on top without importing another country’s controls, politics or legal assumptions wholesale. The second is the measurement layer — Profiles, which describe current versus target posture, and Tiers, which describe the rigour of risk governance from Partial to Adaptive (pp. 6–8). Neither is a score of whether you are secure. Both are scores of whether you are organised.

Israel is the best available evidence that the neutrality is real, because Israel used it. The INCD explicitly did not invent its own framework: “INCD chose NIST Cybersecurity Framework as the basis for building the methodology for the Israeli economy. Most of the controls that allow the method to be implemented are also derived from NIST (Special Publication 800-53)” (NIST and INCD 2020, p. 1). The reason given by Igal Unna, then the Directorate’s Director General, is strategic rather than technical and is the single most quotable sentence in this section: “harmonizing our methodology with leading standards creates an international cyber defense language which supports collaboration against global cyber threats” (p. 1). A country with world-class offensive capability, an independent doctrinal tradition and every incentive to assert sovereignty over its own standard chose instead to be intelligible. That choice should end the sovereignty argument in any mid-sized European capital where it is still running.

The adoption also fixed a real gap rather than merely importing prestige. Legacy Israeli methodologies “focused on ‘Identify, Protect and Recover’ outcomes; the application of the NIST Cybersecurity Framework is seen as strengthening ‘Detect and Respond’ considerations” (p. 1). A foreign taxonomy corrected a domestic doctrinal blind spot — which is the argument for borrowing one, stated by the borrower.

The European counterpart to the standards definition is ENISA’s, and it is worth naming because it does something NIST does not. ENISA’s Cybersecurity Market Analysis Framework exists because Article 8(7) of the Cybersecurity Act obliges the agency to “perform and disseminate regular analyses of the main trends in the cybersecurity market on both the demand and supply sides” (ENISA 2026, p. 9). Market analysis is a statutory duty of the EU’s cyber agency. Its seven-step workflow turns “what is a cyber market segment” into a repeatable procedure rather than a matter of taste, and its analytical core is the value stack: “the layered structure of the collection of services contributing to the value proposition of an organisation… bundles together products, services, processes or value streams” (p. 27). Version 3.0 aligns it with the Cyber Resilience Act and “products with digital elements”, and supports “recurrent market analysis and continuous monitoring of market dynamics, and comparability across studies” (pp. 9–10) — market monitoring as a standing capability, not a one-off report. It is also portable by design: “the structure and logic of the framework are sufficiently generic to allow its application, with limited customisation, by organisations other than ENISA” (p. 10).

One feature of ENISA’s taxonomy deserves to be lifted out, because almost every national industrial strategy gets it wrong. Its worked classification — built with the European Cyber Security Organisation and the Commission’s Joint Research Centre — puts R&D and education inside the value stack, alongside software, hardware, distribution channels and professional services: academia, professional training, awareness platforms, threat and cryptography research, standards and certification R&D, AI security research (ENISA 2026, Annex G, pp. 76–79). A country that counts only vendors when it measures its cyber industry is measuring the wrong thing, and will conclude it has no industry at exactly the moment it is building one.

What it makes visible: governance, comparability, the audit trail, and an international language that makes cross-border incident response possible. What it hides: the adversary. There is no threat actor anywhere in the CSF, no offence, and no concept of national power. It tells an organisation what “good” looks like and says nothing about who is coming. Used alone as a national definition of cyber, the standards definition produces compliance rather than capability — the same critique the ITU’s Global Cybersecurity Index attracts, and for the same structural reason.

3. The doctrinal definition — cyber as a subset of information warfare, defined by means

This is where Israel’s contribution is genuinely original, and where the vocabulary is at its sharpest.

Start with the object. Tabansky’s operative definition of cyberspace is “inter-connected networks of information technology infrastructures, including the internet, telecommunication networks, mission-specific networks, computers, and computer embedded systems”, with the virtual environment — “data stored and information processed by computers and transferred over these networks” — included (2011, p. 78). The definition deliberately excludes organisational and ideological properties, on the grounds that those are contingent rather than inherent. And the object is layered from the start: a physical layer of energy, circuits, processors, storage, cable and fibre; a logical layer of software; and a data and information layer (pp. 77–78). Nye, arriving from Harvard the year before, describes the same thing as “a unique hybrid regime of physical and virtual properties”: a physical infrastructure obeying rival-goods economics and sovereign jurisdiction, and an informational layer with increasing returns to scale and weak jurisdictional control, where attacks are cheap (Nye 2010, p. 3). Tabansky adds the line that keeps the whole subject honest: “cyberspace is not part of nature and would not exist without the information technologies that were developed in past decades” (pp. 76–77). Everything in it was built, which means everything in it was a decision.

Then the definitional move that matters most. Ben-Israel and Tabansky’s companion essay draws the boundary that every subsequent argument has to cross: “while information warfare is not new, this is not true of computer-based information systems… What is new about Third Wave warfare or war in the information age is not information warfare per se, but computer warfare” (2011, p. 28). Information warfare is as old as deception. What is new is that information systems now run on computers. Cyber is therefore a subset of information warfare, and the subset is defined by its medium.

The Israeli definition of computer warfare follows, together with the exclusion that gives it teeth: “unauthorized access to the adversary’s computer systems for the purpose of intelligence gathering, disruption, deception, and prevention and delay of the use of information, while preventing the enemy from doing the same to one’s own computer systems”, and — “A traditional attack (barrage, bombing, physical sabotage) on computer systems… is not classified as cyberwar” (p. 28). Effect does not define cyber. Means do. Destroying a data centre with a cruise missile produces the same outage as destroying it with malware, and only one of them is a cyber operation. This is not pedantry; it is the rule that decides which service is tasked, which budget pays and which legal regime applies.

Under the same framing, information warfare decomposes into four things: computer warfare, electronic warfare, psychological warfare and media management (p. 25). Futter draws the identical map seven years later from Leicester, with the operational vocabulary attached: the top-level split is between Information Warfare and Computer Network Operations, with CNO able to be a component of IW, while jamming radar or communications is Electronic Warfare and neither (2018, p. 210). Within CNO he restores the distinctions the word “cyber” erased — Computer Network Attack (disruption or physical damage), Computer Network Exploitation (theft of information: Moonlight Maze, the OPM breach) and Computer Network Defence, itself split into information, network and computer security (pp. 210–211). Only “the most sophisticated and destructive CNAs” qualify as using weapons. His worked example is the 2016 DNC hack: CNE to acquire the data, IW to use it. One operation, two disciplines, and a national system that owns only one of them will describe it as half an attack.

The Israeli doctrinal layer supplies three further instruments that a mid-sized state can lift directly. The first is the three-group taxonomy of cyber weapons: unequivocally offensive (malware, worms, Trojans, logic bombs, denial of service); dual use (network monitoring, vulnerability scanning, penetration testing, encryption, camouflage of content and communications); and unequivocally defensive (firewall, disaster recovery) (Tabansky 2011, p. 80). The middle category is simultaneously the root of Israel’s export-control problem and the root of its product industry, and we return to it in Section IV.