
September 26, 2026

Israel is the only country that built all four inside a decade and kept them able to talk to each other, because it published its definitions before it built its institutions. What it actually built is a translation layer: the machinery that converts an intelligence problem into a product category. That is what cybertech is, and the edges of the definition decide what a country cannot see.
ENSI research — built on a library of 164 primary documents and 52 company dossiers
Three institutions with nothing in common have independently reached the same conclusion about the word at the centre of this series. In 2014, researchers at Canada’s signals-intelligence establishment harvested nine published definitions of cybersecurity — from the ITU, the CNSS, DHS, Public Safety Canada, Oxford and four individual scholars — and found them mutually inconsistent and overwhelmingly technical (Craigen, Diakun-Thibault and Purse 2014, pp. 14–15). In 2018, a British professor of international politics concluded that “cyber” has become “so nebulous that it has essentially become meaningless; it simply refers to too many different things at different times for different people” (Futter 2018, p. 202). And in 2020, the product-development team that maintains a listed cyber-security equity index — people whose job is to decide, every quarter, which companies are cyber companies — conceded in print that “there is no one consistent technology or segment” (Jones, Nasdaq 2020, p. 3).
A spy agency, a political scientist and a stock exchange, approaching from opposite ends, all report that the object does not hold still. The usual response is to treat this as a failure of the field and to propose a tenth definition. That is the wrong reading, and correcting it is the point of this report.
The absence of one definition is not a deficiency. It is evidence that there are four definitions, each doing a different institutional job, and each of them load-bearing. The academic definition exists to make an interdisciplinary field arguable: Craigen’s replacement — cybersecurity as “the organization and collection of resources, processes, and structures used to protect cyberspace and cyberspace-enabled systems from occurrences that misalign de jure from de facto property rights” (2014, p. 13) — is deliberately non-technical, because its purpose is to get engineers, lawyers, economists and psychologists into one conversation. The standards definition exists to be audited: NIST’s Cybersecurity Framework 2.0 is “a taxonomy of high-level cybersecurity outcomes” that is explicitly “sector-, country-, and technology-neutral” and contains no adversary, no offence and no state (NIST 2024, pp. i–ii). The doctrinal definition exists to allocate war-fighting responsibility, which is why Israel’s own operative definition of cyberspace deliberately excludes organisational and ideological properties as contingent rather than inherent (Tabansky 2011, p. 78). And the market definition exists so that capital can be allocated and membership adjudicated — Nasdaq’s classification is what it is because a committee has to be able to decide it, not because it is conceptually superior (Jones 2020, p. 5).
Borrow one of the four and you get an institution shaped like it. Take the standards definition as your national definition and you build a compliance regulator that is excellent at producing maturity scores and has no view on an adversary. Take the doctrinal definition alone and you build a command that cannot talk to a bank. Take the market definition — which is what happens by default, because it arrives free with every vendor briefing — and you build a trade association that mistakes a category map for a threat picture. Craigen’s warning is institutional rather than semantic, and it is the sentence this whole report turns on: the absence of a shared definition “impedes technological and scientific advances by reinforcing the predominantly technical view of cybersecurity while separating disciplines that should be acting in concert” (2014, p. 13). A state that defines cyber narrowly as an IT problem gets a narrow IT institution, and then wonders why it has no answer to everything the institution was not built to see.
Israel is the best place in the world to watch this happen, for a reason that has nothing to do with how many start-ups it has. Between roughly 2010 and 2018 it built all four definitions, and — this is the unusual part — kept them mutually translatable. The sequence matters more than the content. In May 2011, three months before the government resolution that created its first cyber institution, Lior Tabansky published an essay at the Institute for National Security Studies whose stated purpose was to “survey the field and create a common language for a fruitful public discussion of the developing issue of cyber security, proposing operative definitions… that can be applied in a discussion of Israel’s national security” (Tabansky 2011, p. 76). In December of the same year, Isaac Ben-Israel — the physicist and reserve major-general who had run the 2010 National Cyber Initiative — co-authored the companion essay, which builds its case for cyber policy not out of weapons but out of Popper’s three worlds, the Tofflers’ three waves and Romer’s endogenous growth theory, arriving at knowledge as “a non-rival, partially excludable good” before it reaches a single threat (Ben-Israel and Tabansky 2011, pp. 22–24). Resolution 3611 followed in August 2011 with a National Cyber Bureau of about thirty people and a first-year budget of NIS 4.5M; the operational authority came in 2015, the merged Directorate in 2017–18, and the Israeli Cyber Defense Methodology — built directly on NIST’s framework and its SP 800-53 controls — was published in June 2017 and adopted by the whole Israeli government in 2018 (NIST and INCD 2020, pp. 1–2).
Israel published its definitions before it built its institutions. Almost every other state does the reverse: it creates an agency, gives it a budget line, and then commissions a strategy that reverse-engineers a definition from whatever the agency already does. The Israeli order is cheap to copy and almost never copied. It costs nothing but authority, and it buys something no reorganisation can retrofit — a vocabulary that the general staff, the regulator, the university and the venture fund all use in the same sense.
The deeper reframe follows from that. If you ask why one small country produces both Unit 8200 and Wiz, the usual answers — conscription, threat, chutzpah — explain the supply of people but not the shape of the output. The better answer is definitional. Cybertech is an institutional translation layer: the machinery that converts an intelligence problem into a product category, and occasionally converts it back. Tabansky’s 2011 taxonomy of cyber weapons has three groups — unequivocally offensive, unequivocally defensive, and a dual-use middle of network monitoring, vulnerability scanning, penetration testing, encryption and the camouflage of content and communications (2011, p. 80). Read that middle category again in 2026 and it is not a doctrinal list. It is a product catalogue. Network monitoring became Armis and Axonius; vulnerability scanning became Orca and Wiz; penetration testing became Pentera, Cymulate and XM Cyber. The doctrine wrote the segment map fifteen years before the segments had names.
That translation is also where the model’s costs live. A definition built on means rather than effects — Ben-Israel and Tabansky’s precise and correct claim that information warfare is ancient and only computer warfare is new (2011, p. 28) — has two consequences a state must accept together. It makes the dual-use export problem structural rather than accidental, because an intrusion tool and an assurance tool are the same object under different licences. And it leaves the cognitive domain outside the definition and therefore, unless someone says otherwise in the same document, outside everybody’s mandate. Report 6 in this series documented exactly that hole in the Israeli case: a 2025 national strategy that lists a public mindspace resilient to foreign influence among its objectives, names no owner, and gives nobody the legal power to act.
For a mid-sized European state — the Czech Republic is our default home example — the practical question is not “what is the correct definition of cyber”. There isn’t one. It is: which of the four definitions is your agency actually running on, which of the other three have you quietly imported from a vendor, and what has the combination made you blind to. Report 1 ranked the fifty companies Israel’s machine produced; Report 2 distilled sixteen principles a state can act on; Report 3 specified the twenty-four features of the best defence anyone could assemble; Report 5 sorted the 2026 threat claims by the evidence behind them; Report 6 examined what happens when a first-rank cyber power meets an adversary it has decided not to treat as one. This report sits underneath all of them and asks the question they assumed an answer to.
There are four working definitions of cyber, not one, and each builds a different institution. The academic (Craigen et al. 2014 — interdisciplinary, property-rights based), the standards definition (NIST CSF 2.0 — six outcome Functions, no adversary in it), the doctrinal (Tabansky and Ben-Israel — computer warfare as a means-defined subset of information warfare) and the market definition (Nasdaq’s two classes, Deloitte’s sixteen Israeli segments, ENISA’s value stack). Adopt one by accident and you get an agency shaped like it.
Israel published its definitions before it built its institutions, and defined cyber as economics first. Tabansky’s INSS essay in May 2011 explicitly to create “a common language”; Ben-Israel’s companion essay grounded in Popper, Toffler and Romer; Resolution 3611 in August 2011 with thirty staff and NIS 4.5M. The order is the cheapest transferable feature in this entire library.
The load-bearing Israeli concept is the boundary between information warfare and computer warfare. “What is new about Third Wave warfare… is not information warfare per se, but computer warfare” (Ben-Israel and Tabansky 2011, p. 28). Cyber is defined by means: bombing a data centre is not cyberwar, however destructive. Futter reaches the identical line from Leicester seven years later.
Defining cyber by means leaves the cognitive domain to nobody. Psychological warfare and media management sit inside information warfare and outside cyber. That is analytically right and institutionally catastrophic if no one else is named — the structural gap Report 6 documents in the Israeli response to Russia.
Most of what states do to each other in cyberspace is an intelligence contest, not war. Rovner’s definition — “an information duel… about maintaining an information advantage” — and his verdict that these activities “differ from traditional intelligence activities in degree, not kind” (TNSR 2020, pp. 11–12). The answer decides who owns cyber: the spies or the military.
Cybertech is an institutional translation layer. Tabansky’s 2011 “dual-use” middle category of cyber weapons — network monitoring, vulnerability scanning, penetration testing, encryption, camouflage — is, read in 2026, a list of product categories worth tens of billions. The doctrine drew the segment map before the segments existed.
The industry has roughly twelve real segments, and only eleven are defined by what they protect. The twelfth — the SMB and MSP platform layer — is defined by who buys. That tells you what a “segment” actually is: an administered answer to a buyer’s assessment problem.
Category creation and vendor consolidation are the same problem solved from opposite ends. The World Bank’s account of cyber as a market for lemons — returns “unquantifiable”, buyers unable to judge effectiveness before an attack (Vergara Cobos 2024, pp. 73–74) — explains both. Vendors invent labels because a label is the cheapest way to be legible; buyers consolidate because one large vendor is the cheapest way to reduce assessment cost. More than 75% of CISOs are pursuing consolidation, and for risk reasons rather than budget ones (Deloitte 2024, p. 14).
The market perimeter is administered, not natural, and its demand base is one country. Nasdaq runs a classification committee, reviews quarterly and rules that companies “may not apply, and may not be nominated for inclusion” (Jones 2020, p. 5). Meanwhile North America is about 54% of global cybersecurity spending — sixteen times all of Latin America and the Caribbean — and governments are roughly 36% of the market, “primarily driven by demand from the United States” (Vergara Cobos 2024, pp. 75, 79).
The definition decides the measurement, and the measurement decides the politics. The ITU index records whether laws and agencies exist and says itself that it does not measure the quality of actions; Israel sits in Tier 2 beside Czechia. Belfer ranks it outside the top ten and says it is under-ranked because it is opaque. IISS puts it top of the second tier, behind only the United States. Three indices, three answers, because three definitions of cyber power.
For a mid-sized EU state the instruction is a sequence, not a menu: define in public, adopt the international taxonomy for organisations, diffuse through sectoral regulators rather than a general law, make market analysis a statutory duty, choose three or four segments deliberately instead of importing a category map — and name the owner of everything the definition leaves outside, in the same document that draws the boundary.
Six sections and eighteen numbered points. Section I sets out the four definitions of cyber, one at a time, with what each makes visible and what each hides. Section II draws the three boundaries that matter — with IT security, with intelligence, and with information and influence operations. Section III is the anatomy of cybertech as an industry: twelve segments drawn from the fifty-two company dossiers behind this series, then the lifecycle of a segment from birth to absorption, and the economics that explain both. Section IV shows the Israeli concept becoming machinery. Section V is the argument that the definition decides the outcome — which agency exists, who owns the budget, what gets measured, and what a country is therefore structurally blind to. Section VI is the transfer.
Sources are cited inline by lead author or institution and year, and every one of them sits in the library behind this series. Company facts come from the fifty-two dossiers and are often company-reported; where a figure is contested or thin we say so. This report deliberately does not repeat Report 2’s principles or Report 3’s features — it explains the concepts underneath them.
Four definitions, four purposes, four institutions. They are not competing answers to one question. They are answers to four different questions that happen to share a prefix. The order below runs from the most abstract to the most consequential in money terms, and each point closes with the same two-part test: what does this definition make visible, and what does it hide.
Craigen, Diakun-Thibault and Purse open their paper with an epigraph from Charles Leslie Stevenson that should be printed on the wall of every national cyber agency: “To choose a definition is to plead a cause.” Their survey of the nine existing definitions finds five recurring themes, and the list is a usable checklist for any state drafting its own: technological solutions · events · strategies, processes and methods · human engagement · referent objects of security (2014, p. 15). Most published definitions cover two or three of the five and are silent on the rest. A state can audit its own strategy against that list in an afternoon and will usually find that “human engagement” and “referent objects” are missing — which is to say, it has not said who is being protected or by whom.
Their own replacement definition does two useful things. It moves the referent object from “data” and “assets” to property rights — borrowed from Ostrom and Hess — so that the protected thing is anything with meaning or value, and the protected relations include access, extraction, contribution, removal, management, exclusion and alienation (2014, p. 18). And it explicitly includes “cyberspace-enabled systems”, which puts operational technology, industrial control and medical devices inside the definition rather than bolted on afterwards as a special case. Any state whose definition of cyber does not do that second thing will spend the next decade arguing about whether the water utility is in scope.
The paper’s other contribution is structural. It characterises cybersecurity as a scale-free network with high degrees of change, connectedness and speed of interaction, in which “the capabilities of actors in the network are potentially broadly similar” (pp. 15–16). This is the academic root of the claim that a small state can punch above its weight — and note that the claim is a property of network topology, not of national character. Nye reaches the same place from international-relations theory: “The low price of entry, anonymity, and asymmetries in vulnerability means that smaller actors have more capacity to exercise hard and soft power in cyberspace than in many more traditional domains”, and “it makes little sense to speak of dominance in cyber space as in sea power or air power” (Nye 2010, abstract and p. 4). He is careful about the limit, too: “Power diffusion is not the same as power equalization” (p. 11). A teenager and a government can both do damage, but only states can mount sophisticated attacks on hardened targets, because those require “large intelligence agencies to intrude physically and/or crack highly encrypted codes”.
Then there is Futter, who is not offering a better definition but arguing that the word should be retired. His case is that “cyber” is a prefix that could almost always be replaced by “information”, “computer”, “digital” or “electronic” without loss, that social science “hijacked a concept that emerged from the hard sciences”, and that the resulting vagueness “often drives … misunderstanding and bad policy” (2018, pp. 201, 212–213). His most uncomfortable observation is about who benefits: “military officials and computer security companies have used imprecise language to help bolster budgets and business through nurturing a bleak and scary picture of the current information environment” (p. 210). Anyone reading a vendor category map — or a national threat assessment written with one open on the desk — should keep that sentence in view.
But Futter also supplies the finding that rescues the whole enterprise, and it is easy to miss. The precise vocabulary never died; it simply left the public debate. “US Cyber Command, UK National Cyber Security Centre, and the Israeli National Cyber Security Authority all have CNO policies and doctrine, but this is conspicuous by its absence in much academic writing and policy discussion” (p. 210). The mush is in the conference programme. Inside the agencies, people still say computer network exploitation when they mean computer network exploitation. A state that wants a serious cyber institution does not need to invent language. It needs to make the internal language the public one.
What it makes visible: the interdisciplinary object, the non-technical stakeholders, operational technology, and the fact that every definition is an argument for a budget. What it hides: operational specificity. You cannot task a unit, write a control or price a contract from Craigen’s definition, which is precisely why the other three exist.
The most widely used definition of cybersecurity on earth is not a sentence. It is a taxonomy of six words, and its authority comes from the fact that it can be audited.
NIST’s Cybersecurity Framework 2.0, published in February 2024, defines cybersecurity by outcomes rather than technology: it “offers a taxonomy of high-level cybersecurity outcomes that can be used by any organization — regardless of its size, sector, or maturity”, and it “does not prescribe how outcomes should be achieved” (NIST 2024, p. i). The Core is a three-level hierarchy of Function → Category → Subcategory, described explicitly as “not a checklist of actions to perform” (p. 3). The six Functions are the operative definition:
GOVERN · risk-management strategy, expectations and policy are established, communicated and monitored · IDENTIFY · current risks are understood · PROTECT · safeguards are used · DETECT · possible attacks and compromises are found and analysed · RESPOND · actions on a detected incident are taken · RECOVER · assets and operations are restored.
The addition of GOVERN in version 2.0 is itself a definitional statement, and the most consequential one NIST has made in a decade. It moves cybersecurity from a technical function to an enterprise-risk and board question. A CISO who reported to the head of IT in 2013 and reports to the board in 2026 is living inside that edit.
Two design choices make this framework the one that travels. The first is neutrality: the outcomes are “sector-, country-, and technology-neutral” (p. ii), which means a national methodology can be built on top without importing another country’s controls, politics or legal assumptions wholesale. The second is the measurement layer — Profiles, which describe current versus target posture, and Tiers, which describe the rigour of risk governance from Partial to Adaptive (pp. 6–8). Neither is a score of whether you are secure. Both are scores of whether you are organised.
Israel is the best available evidence that the neutrality is real, because Israel used it. The INCD explicitly did not invent its own framework: “INCD chose NIST Cybersecurity Framework as the basis for building the methodology for the Israeli economy. Most of the controls that allow the method to be implemented are also derived from NIST (Special Publication 800-53)” (NIST and INCD 2020, p. 1). The reason given by Igal Unna, then the Directorate’s Director General, is strategic rather than technical and is the single most quotable sentence in this section: “harmonizing our methodology with leading standards creates an international cyber defense language which supports collaboration against global cyber threats” (p. 1). A country with world-class offensive capability, an independent doctrinal tradition and every incentive to assert sovereignty over its own standard chose instead to be intelligible. That choice should end the sovereignty argument in any mid-sized European capital where it is still running.
The adoption also fixed a real gap rather than merely importing prestige. Legacy Israeli methodologies “focused on ‘Identify, Protect and Recover’ outcomes; the application of the NIST Cybersecurity Framework is seen as strengthening ‘Detect and Respond’ considerations” (p. 1). A foreign taxonomy corrected a domestic doctrinal blind spot — which is the argument for borrowing one, stated by the borrower.
The European counterpart to the standards definition is ENISA’s, and it is worth naming because it does something NIST does not. ENISA’s Cybersecurity Market Analysis Framework exists because Article 8(7) of the Cybersecurity Act obliges the agency to “perform and disseminate regular analyses of the main trends in the cybersecurity market on both the demand and supply sides” (ENISA 2026, p. 9). Market analysis is a statutory duty of the EU’s cyber agency. Its seven-step workflow turns “what is a cyber market segment” into a repeatable procedure rather than a matter of taste, and its analytical core is the value stack: “the layered structure of the collection of services contributing to the value proposition of an organisation… bundles together products, services, processes or value streams” (p. 27). Version 3.0 aligns it with the Cyber Resilience Act and “products with digital elements”, and supports “recurrent market analysis and continuous monitoring of market dynamics, and comparability across studies” (pp. 9–10) — market monitoring as a standing capability, not a one-off report. It is also portable by design: “the structure and logic of the framework are sufficiently generic to allow its application, with limited customisation, by organisations other than ENISA” (p. 10).
One feature of ENISA’s taxonomy deserves to be lifted out, because almost every national industrial strategy gets it wrong. Its worked classification — built with the European Cyber Security Organisation and the Commission’s Joint Research Centre — puts R&D and education inside the value stack, alongside software, hardware, distribution channels and professional services: academia, professional training, awareness platforms, threat and cryptography research, standards and certification R&D, AI security research (ENISA 2026, Annex G, pp. 76–79). A country that counts only vendors when it measures its cyber industry is measuring the wrong thing, and will conclude it has no industry at exactly the moment it is building one.
What it makes visible: governance, comparability, the audit trail, and an international language that makes cross-border incident response possible. What it hides: the adversary. There is no threat actor anywhere in the CSF, no offence, and no concept of national power. It tells an organisation what “good” looks like and says nothing about who is coming. Used alone as a national definition of cyber, the standards definition produces compliance rather than capability — the same critique the ITU’s Global Cybersecurity Index attracts, and for the same structural reason.
This is where Israel’s contribution is genuinely original, and where the vocabulary is at its sharpest.
Start with the object. Tabansky’s operative definition of cyberspace is “inter-connected networks of information technology infrastructures, including the internet, telecommunication networks, mission-specific networks, computers, and computer embedded systems”, with the virtual environment — “data stored and information processed by computers and transferred over these networks” — included (2011, p. 78). The definition deliberately excludes organisational and ideological properties, on the grounds that those are contingent rather than inherent. And the object is layered from the start: a physical layer of energy, circuits, processors, storage, cable and fibre; a logical layer of software; and a data and information layer (pp. 77–78). Nye, arriving from Harvard the year before, describes the same thing as “a unique hybrid regime of physical and virtual properties”: a physical infrastructure obeying rival-goods economics and sovereign jurisdiction, and an informational layer with increasing returns to scale and weak jurisdictional control, where attacks are cheap (Nye 2010, p. 3). Tabansky adds the line that keeps the whole subject honest: “cyberspace is not part of nature and would not exist without the information technologies that were developed in past decades” (pp. 76–77). Everything in it was built, which means everything in it was a decision.
Then the definitional move that matters most. Ben-Israel and Tabansky’s companion essay draws the boundary that every subsequent argument has to cross: “while information warfare is not new, this is not true of computer-based information systems… What is new about Third Wave warfare or war in the information age is not information warfare per se, but computer warfare” (2011, p. 28). Information warfare is as old as deception. What is new is that information systems now run on computers. Cyber is therefore a subset of information warfare, and the subset is defined by its medium.
The Israeli definition of computer warfare follows, together with the exclusion that gives it teeth: “unauthorized access to the adversary’s computer systems for the purpose of intelligence gathering, disruption, deception, and prevention and delay of the use of information, while preventing the enemy from doing the same to one’s own computer systems”, and — “A traditional attack (barrage, bombing, physical sabotage) on computer systems… is not classified as cyberwar” (p. 28). Effect does not define cyber. Means do. Destroying a data centre with a cruise missile produces the same outage as destroying it with malware, and only one of them is a cyber operation. This is not pedantry; it is the rule that decides which service is tasked, which budget pays and which legal regime applies.
Under the same framing, information warfare decomposes into four things: computer warfare, electronic warfare, psychological warfare and media management (p. 25). Futter draws the identical map seven years later from Leicester, with the operational vocabulary attached: the top-level split is between Information Warfare and Computer Network Operations, with CNO able to be a component of IW, while jamming radar or communications is Electronic Warfare and neither (2018, p. 210). Within CNO he restores the distinctions the word “cyber” erased — Computer Network Attack (disruption or physical damage), Computer Network Exploitation (theft of information: Moonlight Maze, the OPM breach) and Computer Network Defence, itself split into information, network and computer security (pp. 210–211). Only “the most sophisticated and destructive CNAs” qualify as using weapons. His worked example is the 2016 DNC hack: CNE to acquire the data, IW to use it. One operation, two disciplines, and a national system that owns only one of them will describe it as half an attack.
The Israeli doctrinal layer supplies three further instruments that a mid-sized state can lift directly. The first is the three-group taxonomy of cyber weapons: unequivocally offensive (malware, worms, Trojans, logic bombs, denial of service); dual use (network monitoring, vulnerability scanning, penetration testing, encryption, camouflage of content and communications); and unequivocally defensive (firewall, disaster recovery) (Tabansky 2011, p. 80). The middle category is simultaneously the root of Israel’s export-control problem and the root of its product industry, and we return to it in Section IV.
The second is an eight-level severity ladder of hostile cyber activity, descending in order: attack on civilian targets causing physical damage · attack on critical national information infrastructures causing physical damage · attack on military targets inside sovereign territory · attack on military targets outside it · insertion of dormant attack tools as attack preparation · crime and industrial espionage · use of dual-use tools for intelligence gathering and penetration testing · propaganda, abuse and defacement of official websites (p. 82). A ladder of this kind is what allows a state to route an incident automatically to the right responder, and most national systems do not have one written down.
The third is the split that does the most institutional work of anything in this literature: risks to cyberspace versus risks through cyberspace (p. 85). Threats to the infrastructure itself are answered by critical information infrastructure protection. Crime, espionage, terrorist coordination and malware travel through it and are answered by police, intelligence and regulators. Two categories, two very different agencies — and the failure to draw the line is why so many national cyber agencies spend their first five years arguing with their interior ministry.
Israeli doctrine is also unusually blunt about what does not work. On deterrence: “the Cold War model of nuclear deterrence is utterly impracticable in the cyber battlefield”, and because attribution is slow and uncertain, “any deterrence in cyberspace today must be based on preventing the attacker from scoring an achievement” (p. 83) — deterrence by denial, and the doctrinal origin of Israel’s investment in defence in depth and of the Iron Dome analogy that later became the “Cyber Dome”. On prioritisation: there is no objective way to rank what deserves protection, because “the relative importance of a computer system, and as a result, the amount of public investment required to defend it, are subject to a public discussion and a political fight” (p. 84). Ben-Israel and Tabansky add four tests for calling a cyber attack an act of war — organisational and geographic source, motive, level of complexity, and results including what would have happened without the defence — then concede that “answers sufficient for setting policy will undoubtedly be lacking” (2011, pp. 29–30). Their own list of open questions from 2011 is still open in 2026: is crashing a national banking system an act of war if nobody dies; are civilians who conduct computer warfare legitimate targets; is computer warfare between friendly states for economic intelligence “warfare” at all (pp. 31–32).
The third doctrinal position, and the one that has moved furthest since 2020, is that most of this is not warfare at all. The Texas National Security Review roundtable opens with the state of the field in five words — “Cyber war is out. But what is in?” — and reports that scholars “generally recognize the limits of cyber war as a useful concept” (Chesney and Smeets 2020, p. 2). Joshua Rovner’s candidate replacement is the cleanest boundary marker available: “An intelligence contest is an information duel… about maintaining an information advantage. All things being equal, the goal is to have more and better information, and success means keeping the other side in the dark” (p. 11) — as against war, “the use of organized violence to compel enemies to change their behavior”, and against arms racing, which requires transparency to work. His five defining characteristics are a usable taxonomy: collecting more and better information on adversary capabilities and intentions · exploiting what is discovered for practical gain, including reverse-engineering stolen intellectual property · a reciprocal effort to undermine adversary morale, institutions and alliances · sabotage of rival organisations · a contest run largely below the threshold of violence (pp. 13–14). His verdict is that these “differ from traditional intelligence activities in degree, not kind” (p. 12), and he explains why states prefer sabotage to war in terms any minister can follow: the results are “both practical and psychological… It may not be necessary to cause physical damage if personnel in target organizations fall victim to frustration and finger pointing” (p. 16). Two of his three examples — Natanz and Saudi Aramco — are the Israel–Iran file.
The panel splits roughly evenly, and the split is the useful part. Warner, Fischerkeller and Harknett argue that scale changes the quality of the activity and pushes it beyond intelligence; Lindsay and Rovner argue that the functional imperatives of intelligence and counter-intelligence explain the behaviour without a new framework (p. 6). A national doctrine has to pick, because the answer determines who owns cyber — the intelligence services or the military — and no organisational chart survives leaving it open. The roundtable closes with the governance warning that belongs in the founding legislation: intelligence officials “will also face increasing scrutiny from overseers, who have legitimate questions about how states compete in a domain they share with civilians. Allies and partner states, meanwhile, will likely have questions about activities on their own networks” (p. 17).
What it makes visible: the adversary, the threshold, the tasking, the escalation ladder, and the honest limits of deterrence. What it hides: everything that is information warfare but not computer warfare — which is to say, the half of the problem Russia actually runs. Section II takes that up.
The fourth definition is the one most people encounter first, and almost nobody reads as what it is: a governed standard with a committee, a rulebook and a revision cycle.
Nasdaq’s index classification is the purest specimen because it has to be adjudicable. Its definition — cyber security as “enabling the protection of and secure communication between unique nodes of the internet from both external and internal threats” (Jones 2020, p. 5) — is not an attempt at conceptual precision. It is an attempt at decidability, because a committee has to say yes or no about a specific company by a specific date. The industry is then split into exactly two classes: an Infrastructure Provider, “a direct provider of hardware or software for cyber security and for which cyber security business activities are the key driver of the business”, and a Service Provider, “a company whose business model is defined by its role in providing secure cyber based services”. The distinction is crisp: “Service Providers allow for their clients to conduct business securely while Infrastructure Providers are providing security itself” (pp. 5–6). As of 30 September 2020 the index stood at 63% infrastructure and 37% services.
Read the governance, which is where the real lesson is. An ISE Cyber Security Industry Classification Committee vets companies using “published audited annual reports and discussions with company investor relations groups, industry participants and experts”. Each company is assigned to a single category by principal business activity, with revenue the key determinant. Companies “may not apply, and may not be nominated for inclusion”. Reviews are quarterly, plus ad hoc on mergers, bankruptcy or delisting (p. 5). The perimeter of “cybertech” is an administered boundary, redrawn four times a year by people you cannot lobby. Every market map, magic quadrant and category listing a founder or an official reads is an artefact of the same kind, with an owner, a method and an incentive — and should be read that way rather than as a fact of nature.
The index also settles an empirical question that national industrial strategies routinely get wrong. Measured against the Nasdaq Global Benchmark Technology Index, the cyber index is about 54.9% software and 25.1% computer services, against 28.5% and 6.2% for technology as a whole — and it has zero semiconductor and computer-hardware exposure and only 2.5% internet, against 19.2%, 20.8% and 19.4% (p. 6). Cybertech is empirically a software-and-services industry, not a hardware one. A country planning a cyber industrial policy around fabrication or appliances is planning around the 2005 version of the market.
Two further things in this document are worth keeping. The first is that the index provider concedes its own instability: “just like the dynamic nature of the cyber threats, cyber security technology is also dynamic and is a moving target for many cyber security customers. In essence, there is no one consistent technology or segment” (p. 3). Any taxonomy — Nasdaq’s, Deloitte’s, ENISA’s, or the twelve segments in Section III of this report — is a snapshot with a shelf life. The second is that the paper’s economics are cited from vendor-adjacent sources: a $6 trillion cybercrime-damage figure for 2021 from Cybersecurity Ventures, and a $161bn-to-$363bn market forecast from Mordor Intelligence (p. 1). That is exactly the circularity Futter warned about — the market sizes the threat that sizes the market — appearing inside an investment-grade document that will be quoted in parliamentary committees for a decade.
The second market definition is the one that actually describes Israel. Deloitte’s Israel Cyber Industry Overview builds its taxonomy from “nearly 300 private Israeli or Israeli-affiliated cybersecurity companies (with Israeli founders)”, excluding listed and acquired firms, and sorts them into sixteen categories, each with a working definition: Vulnerability & Risk Management · IoT · Data Security & Privacy · Security Operations · Web Security · Application Security · Identity & Access Management · Fraud & Transactions · Endpoint Security · Network Security · Cloud Security · Threat Intelligence · SaaS Security · Blockchain Security · Email Security · Mobile Security (Deloitte 2024, pp. 16–23).
The shape of that industry differs depending on which unit you count, and the differences are informative. By company count the leaders are Vulnerability & Risk Management with 39 firms, IoT with 33, Data Security & Privacy with 28, Application Security with 24 and Security Operations with 24. By capital raised the order changes: Vulnerability & Risk Management $2,606m, Application Security $2,317m, Cloud Security $2,107m, Network Security $1,410m, Endpoint Security $1,335m. By employment it changes again: Application Security 3,068, Vulnerability & Risk Management 2,965, Cloud Security 2,648, Endpoint Security 2,326, IoT 1,829 (p. 16). Cloud Security is the extreme case and the most instructive: only fourteen companies, yet 2,648 employees and $2.1bn raised — which is what a segment looks like when three firms (Wiz, Orca, Aqua) have captured it. The sector as a whole “employs over 23,500 individuals, with a majority in Israel”, and “the top 10 companies collectively account for more than 7,500” (p. 16).
Deloitte also records the demand-side shift that redefines the category more profoundly than any taxonomy revision. Cyber spending by financial institutions fell from 0.72% of revenue in 2021 to 0.54% in 2023 — and the fact that it is now measured against revenue rather than against the IT budget “is a direct outcome of the broad impact of cyber on the entire business activities” (p. 11). Cyber has migrated from a line item inside IT to a line item beside it. That migration is the market’s version of NIST adding GOVERN.
The third market definition is economic, and it explains why the other two behave as they do. The World Bank’s Cybersecurity Economics for Emerging Markets treats the industry as an economy rather than a product catalogue. Global spending on information security and risk management “grew at twice the rate of the global economy in 2022, and it is projected to grow at over four times in 2024, representing spending of almost 0.2 percent of the world’s gross domestic product” (Vergara Cobos 2024, p. 75). The market is forecast to grow at an 11% compound rate from 2020 to 2027, with government buyers about 36% of it, “primarily driven by demand from the United States” (p. 79). And it is extraordinarily concentrated: “Approximately 54 percent of global spending on cybersecurity comes from North America, which is 16 times larger than the combined spending of all the countries in Latin America and the Caribbean” (p. 75).
Two implications follow immediately and neither is usually stated. First, any exporting cyber industry is built for one customer base, and a European state deciding to build one must decide consciously whether to replicate that dependence or hedge it. Second, the state is not a bystander in this market: per-capita government cybersecurity budgets exceed US$30 in Canada and the United States and are “less than US$1 in highly targeted developing countries like India and Mexico” (p. 74). Governments in high-income countries shape the market through procurement, standards, certification and R&D — Germany’s BSI standards are cited as setting de facto European market terms (p. 79). Where a state spends, a segment appears.
What the market definition makes visible: money, employment, concentration, the shape of demand, and the fact that categories are governed objects with owners. What it hides: everything the buyer does not buy. Nothing that cannot be sold appears in it — not doctrine, not deterrence, not the cognitive domain, not the unglamorous work of a national CERT. The gravest error in national cyber policy is letting the market’s definition, which exists to sell products, quietly become the state’s, which exists to allocate sovereign capability.
A definition is only as useful as its edges. Three edges do the institutional work, and the third one is where states get hurt.
The first boundary is the one Tabansky drew in 2011 and it separates risks to cyberspace from risks through cyberspace (2011, p. 85). Threats to the infrastructure itself — to the routers, the fibre, the control systems, the resolvers — are answered by critical information infrastructure protection, and they are a national-security matter because the asset is national. Crime, espionage, fraud, terrorist coordination and commodity malware merely travel through the infrastructure, and they are answered by police, regulators, sectoral supervisors and the organisations themselves. Both are commonly called “cyber”. They require different agencies, different powers, different evidentiary standards and different budgets.
Futter puts the same test in a form a minister can apply: separate “the everyday challenges of the digital age (which might have to be managed individually or by organisations) from new risks that are posed to national security (which should be managed by governments)” (2018, p. 210). A national cyber agency that does not enforce this line ends up as a very expensive help desk, because the volume of the first category is effectively infinite and the second category generates no tickets at all until it generates a catastrophe.
The practical marker of the boundary is who is the referent object. If the answer is “this organisation’s data and uptime”, it is information security, and the right instruments are standards, insurance, procurement and liability. If the answer is “a function the country cannot do without”, it is cyber defence, and the right instruments are regulation of named entities, national situational awareness and state capability. Israel’s architecture enforces this by regulating named critical-infrastructure entities rather than whole sectors and reaching everything else through guidance, sectoral regulators and market mechanisms — which is why its critical infrastructure “has been guided, but not extensively regulated, by the state since 2002” and “most of the market is not regulated for cybersecurity risk management” (NIST and INCD 2020, p. 1). Light regulation is not an absence of a decision. It is the decision.
The second boundary is the one the TNSR roundtable spent a special issue failing to agree on, which is itself the finding. If Rovner is right that state cyber activity is an intelligence contest differing from classical espionage “in degree, not kind” (2020, p. 12), then the institution that should own most of it already exists in every country, has a legal framework, an oversight regime and a professional culture — and creating a “cyber command” to do it again is duplication with worse oversight. If Warner, Fischerkeller and Harknett are right that scale changes the quality of the activity, then a new institution and a new doctrine of persistent engagement are justified.
Most European states have resolved this by not resolving it, which produces the characteristic pathology: an intelligence service running operations, a military command writing doctrine about them, and a civilian agency issuing advisories about their consequences, with no single threat picture. The transferable discipline here is not a preferred answer but the requirement to give one in writing. Name, in the founding document, whether cyber operations are an intelligence function that the military supports or a military function that intelligence supports. Israel’s answer is that the IDF leads in war and the civilian Directorate leads in peacetime, with the special bodies explicitly carved out of the 2011 resolution — a published division of labour with a switch, rather than a permanent ambiguity.
The boundary also has a measurement consequence. If cyber is mostly an intelligence contest, then the indicators of success are intelligence indicators — access maintained, access denied, adversary operations exposed and burned — and none of them appear in a national dashboard of incidents. A country that measures its cyber performance by incident counts is measuring the smallest and least strategic part of what is happening to it.
The third boundary is the important one, and it is the reason this report exists in a series that includes Report 6.
The Israeli doctrinal definition is means-based and therefore precise: information warfare decomposes into computer warfare, electronic warfare, psychological warfare and media management, and only the first is cyber (Ben-Israel and Tabansky 2011, p. 25). Futter’s map is identical: Information Warfare and Computer Network Operations are distinct top-level categories, CNO can be a component of IW, and jamming is neither (2018, p. 210). Both are analytically correct. Both are institutionally dangerous, and for the same reason.
If cyber is defined by means, then the cognitive domain sits outside the definition — and unless the same document names its owner, it sits outside everybody’s mandate. This is not a hypothetical. Report 6 in this series documented it in the Israeli case in detail: a February 2025 national cyber strategy that lists a public mindspace resilient to foreign influence among its objectives, names no owner for it, and is accompanied by no law giving anyone the power to act; a former Israeli intelligence officer writing that “Israel lacks a national strategy for dealing with such foreign interventions: the Israeli Security Agency has insufficient legal powers to act, and the government’s cooperation with civil society bodies on this issue is in its infancy” (Rakov, JISS 2025, p. 9); and, since April 2023, a Kremlin-steered Hebrew-language influence operation running inside Israel with media clones, bought placements in mainstream outlets and a costed plan to seat a party in the Knesset. The country with the world’s second-best technical cyber defence has no institution for the other half of the same adversary’s mission.
The adversary, meanwhile, does not recognise the boundary at all. Russian doctrine operates informatsionnoe protivoborstvo — information confrontation — with an information-technical limb and an information-psychological limb under one chain of command, and Russian theorists “generally do not use the terms cyber (kiber) or cyberwarfare (kibervoyna), except when referring to Western or other foreign writings on the topic” (Connell and Vogler, CNA 2017, p. 11, cited in Report 6). Futter’s worked example makes the point without Russia: the 2016 DNC operation was computer network exploitation to acquire the material and information warfare to use it. One operation, two disciplines. A state with an agency for only one of them will see half of it, report half of it, and attribute half of it.
The resolution is not to stretch “cyber” until it covers the cognitive domain. That is what produces the mush Futter objects to, and it would put a technical agency in charge of speech — which is both incompetent and constitutionally alarming. The resolution is to keep the boundary and name the owner on both sides of it in the same act. Draw the line where Ben-Israel and Tabansky drew it, then immediately say: computer network operations here, foreign information manipulation there, one shared threat picture, one joint assessment, two mandates with different powers. Report 6 sets out the European models to copy for the second half — Sweden’s peacetime psychological-defence agency, France’s VIGINUM publishing attribution-grade technical dossiers with no takedown powers, the EEAS vocabulary and its enabler-focused deterrence playbook. The only novel instruction from this report is about sequencing: the hole is created at the moment of definition, so it has to be closed in the same document. A boundary drawn in a strategy and an owner named three years later in a different ministry is not a system; it is a gap with a timestamp.
If the four definitions explain what cyber is, the industry explains what cybertech is. The taxonomy below is drawn from the fifty-two company dossiers behind this series rather than from an analyst’s quadrant, and it is offered with the same warning Nasdaq gives about its own: it is a snapshot. Deloitte counts sixteen Israeli categories; ENISA’s value stack groups the same firms five ways; Nasdaq sorts them into two. The twelve below are the segments that the evidence of actual companies, actual buyers and actual acquisitions supports in 2026.
Network and edge — protects the path between things, and increasingly is the path. Check Point (the stateful-inspection firewall, 1993, and a $13.7B installed-base business), Cato Networks (one networking-and-security stack on its own global backbone, SASE), Radware (carrier-grade DDoS), Zero Networks (automated microsegmentation, agentless, deployed in weeks), Imperva (web application and database protection, now inside Thales).
Endpoint — protects the device where code actually executes. SentinelOne (autonomous single-agent XDR on its own data lake, with half of ARR now beyond endpoint), Glow (AI agents making application allow-listing workable at enterprise scale), Cynet (all-in-one XDR with bundled MDR for smaller enterprises). Deep Instinct sits here as a cautionary case: a genuine deep-learning prevention edge that lasted about five years and did not become a scaled business.
Cloud — protects workloads and configurations in infrastructure nobody owns. Wiz (agentless graph-based risk prioritisation; acquired by Google for $32B in cash, closed March 2026), Orca (which invented agentless SideScanning and patented it), Upwind (runtime-first, the leading independent alternative), Aqua (container and runtime security since 2015, with the open-source Trivy funnel), Sweet Security (eBPF runtime sensor).
Identity — human, non-human and agent — protects the act of being trusted. CyberArk (privileged access; for two decades “PAM meant CyberArk”; acquired by Palo Alto Networks for ~$25B), Silverfort (enforcing MFA inside the authentication layer, reaching legacy systems others cannot), Transmit Security (customer identity and passwordless), Astrix (which named non-human identity early enough to make it a budget line, and sold to Cisco for ~$400M), Zenity (security and governance for AI agents).
Data — protects the thing everything else is a proxy for. Varonis (twenty years of permissions metadata with automated remediation, made urgent again by AI), Cyera (AI-native classification plus a data-and-identity trust layer, valued at $12B in June 2026 after buying Oasis, Ryft and Genie).
Application and software supply chain — protects what you built and what you imported. Snyk (developer-first security, distributed through developers), Checkmarx (SAST deep in 60% of the Fortune 100), Apiiro and Cycode and Legit (application security posture management, code-to-runtime context), Oligo (eBPF proving which vulnerable library functions actually execute), Salt Security (standalone API security), Koi (user-installed extensions, packages, MCP servers and agent skills — an unclaimed control point, bought by Palo Alto Networks).
Exposure and validation — protects nothing directly; it tells you which of the other eleven to fix first. Armis (agentless discovery and a compounding device knowledge base across IT, OT and medical; acquired by ServiceNow for $7.75B), Axonius (a neutral correlation layer over 1,400+ data sources), XM Cyber (attack-graph choke-point prioritisation), Pentera (real exploits run safely in production), Cymulate (breach and attack simulation at SaaS scale), Zafran (mitigation through controls the customer already owns, cutting “critical” findings to the exploitable ~1%).
SOC and automation — protects the defenders’ own throughput. Torq (hyperautomation whose engine and integrations were in place when AI arrived), 7AI (agentic SOC from repeat Cybereason founders, riding on existing tools). Hunters is the cautionary case: an early and correct bet on the data-lake SIEM that learned “SIEM is a platform market”.
Fraud and identity trust — protects a transaction where the credentials are genuine. BioCatch (behavioural biometrics across ~19B sessions a month at 350+ banks; Visa agreed to acquire for $2.4B), Forter (a cross-merchant identity graph sold with a chargeback guarantee — an outcome, not a score), Transmit again on the consumer side.
OT and cyber-physical — protects processes that can injure people. Claroty (industrial protocol depth plus distribution through Siemens, Rockwell and Schneider), Waterfall (hardware-enforced unidirectional gateways that NERC CIP, NRC and ANSSI rules reward or require), Armis again on the medical and device side.
Threat intelligence and response services — protects by knowing, and by turning up. KELA (fifteen years of underground data with law-enforcement credibility), Sygnia (ex-8200 breach responders whose crisis wins convert into retainers), Cellebrite (court-accepted digital forensics), Dream Security (AI-native “sovereign cyber” sold to heads of state — and carrying heavy NSO-lineage risk).
AI security — protects models, agents and the pipelines around them, and is about eighteen months old as a discipline. Noma (discover, govern, red-team and runtime-protect AI agents), Zenity (agent governance, Microsoft-aligned, Fortune 50 deployments), Irregular (embedded evaluator for OpenAI, Anthropic and Google DeepMind; co-authored RAND’s SL1–SL5 model-weight security levels), Alice, formerly ActiveFence (a real-world adversarial dataset), plus Cyera, Oligo and Glow extending from adjacent segments.
The SMB and MSP platform layer — protects an organisation that has no security staff at all. Guardz (MSP-native multi-tenant console with bundled engines and AI-plus-human MDR), Coro (one modular agent for lean-IT mid-market, sold 100% through channel), Cynet again.
Now notice the thing that list is designed to expose. Eleven of the twelve segments are defined by what is protected. The twelfth is defined by who buys. That is not an inconsistency in the taxonomy; it is the taxonomy telling the truth about itself. A segment is not a natural kind. It is an administered answer to a buyer’s assessment problem — and when the buyer changes shape, the segment does too. The next two points explain the mechanism.
Segments are not discovered. They are declared, and the declaration succeeds or fails on three conditions that recur across the dossiers with unusual consistency.
The first is an unclaimed control point: a place in the stack where something consequential happens and no incumbent has a right to stand. Island found it in the browser, the last mile between a governed enterprise and an ungoverned internet, and created the enterprise-browser category outright. Koi found it in the things users install themselves — extensions, packages, MCP servers and, latterly, agent skills — a surface that belonged to no product until it belonged to Koi’s. Astrix found it in the credentials that are not people: service accounts, tokens, integrations, and now agents. Zero Networks found it in the east-west traffic that firewalls were never placed to see. In each case the company did not compete for an existing budget; it argued that a budget was missing.
The second is removal of deployment friction, which is more often the real invention than the detection logic. “No agents, results in minutes” was worth more to Wiz than any single capability it shipped, and the same agentless logic powers Orca, Armis, Axonius, Salt and Zero Networks. Pentera’s one-day proof of value and Zafran’s use of controls the customer already owns are versions of the same move. This matters for a definitional reason: under conditions where the buyer cannot verify effectiveness, time-to-first-evidence substitutes for evidence. A product that shows you something true about your own estate in an afternoon has solved the buyer’s epistemic problem, not just a security problem.
The third is naming, and it is a deliberate, budgeted activity rather than a marketing afterthought. Astrix kept saying “non-human identity” until it became a line in procurement systems; Cycode rebranded early enough to appear in the first analyst quadrants of two categories; Zenity’s CTO co-leads OWASP projects; Irregular co-authored RAND’s SL1–SL5 model-weight security levels. Research functions — Claroty’s Team82, Orca’s Research Pod, Salt Labs, Oligo, Zenity Labs, Legit — win buyers with published disclosures rather than advertising, which is simultaneously a marketing channel and a contribution to the commons. The naming of a category is a standards activity performed by a company, and a state that wants its firms to create categories rather than fill them should fund the standards seats, the disclosure programmes and the research labs, not the advertising.
Israel is unusually good at all three, and Report 1 traces the lineage in detail — stateful inspection in 1993, privileged access in 1999, the web application firewall in 2003, behavioural biometrics from 2011, SASE and developer-first security in 2015, API security in 2016, cyber asset attack surface management in 2017, agentless cloud scanning in 2019–20, the enterprise browser in 2020, non-human identity and AI-native data posture in 2021. What Report 1 did not ask is why the same country keeps doing it, and the answer is in Section IV: the categories are downstream of a doctrine that named the tool classes first.
Then the categories collapse. Since late 2023 the fifty have produced five exits at or above $2.4B — Wiz to Google at $32B, CyberArk to Palo Alto Networks at ~$25B, Armis to ServiceNow at $7.75B, Imperva to Thales at $3.6B, BioCatch to Visa at $2.4B pending — plus a long tail of $200–400M acquisitions of companies one to five years old, including Astrix to Cisco and Koi to Palo Alto Networks. The fifty are, in effect, the outsourced R&D pipeline of about eight platforms.
The demand-side driver is explicit. More than 75% of CISOs say they are pursuing vendor consolidation, and Deloitte’s finding about their motive is the one worth carrying away: they are “motivated by risk posture improvement, rather than from budget needs” (2024, p. 14). Consolidation is not a cost programme. It is buyers deciding that fewer, larger relationships produce better security than more, better products — which is a statement about their own ability to assess products, not about the products.
And that is exactly where the World Bank’s economics become load-bearing. Vergara Cobos names six market failures in cybersecurity: non-internalised systemic and third-party risk · underinvestment in R&D · information asymmetry · vendor risk exposure · misaligned incentives · and unquantifiable returns (2024, pp. 73–74, 80–84). Two of them do most of the work here. “Unlike other cost-saving projects, the returns to cybersecurity investment are unquantifiable” (p. 74) — you cannot price the attacks that did not happen. And buyers cannot judge a product’s effectiveness before an attack, which, combined with low awareness, “creates downward pressure on both the prices and quality of resilient products” (p. 73). That is Akerlof’s market for lemons, stated by a development bank about a $200bn industry.
Put the two sides together and the lifecycle stops looking like a fashion cycle and starts looking like an equilibrium. Category creation and vendor consolidation are the same information problem solved from opposite ends. Under information asymmetry a buyer cannot evaluate the good, so it substitutes a proxy. Two proxies are available. One is the category label — if the thing belongs to a recognised class, it can be compared, budgeted and defended to an audit committee — and this is why vendors invent labels, because a label is the cheapest route to legibility. The other is the size and survival of the vendor — if a large company with a long history sells it, the assessment cost falls to almost nothing — and this is why buyers consolidate. Supply-side incentives proliferate categories; demand-side incentives absorb them. Deloitte predicts precisely this asymmetric outcome: the number of categories a customer buys will shrink even as the taxonomy stays wide (2024, p. 14, and the four M&A scenarios at p. 14: scale up for IPO readiness, acquisition by a multinational, merger into a titan, and failure).
The same economics produce three further effects that any European policymaker should recognise before designing an intervention.
Prices carry the losses. “Firms translate losses from cyber incidents into price hikes, which are assumed by consumers” (Vergara Cobos 2024, p. 73). The cost of insecurity is socialised through the price level, which is why private investment sits below the social optimum and stays there without regulation.
Interdependence makes rational actors insecure. The World Bank models it as a prisoner’s dilemma: both firms gain more from securing themselves than from free-riding, but the individually rational move is to stay insecure, because “the resilience of one digital asset is contingent on the resilience of others, and the overall resilience of cyberspace depends on the security of its most vulnerable components” (p. 80). This is the formal argument for mandatory baselines, and it is stronger than the usual appeals to national security because it survives the assumption that everyone is behaving rationally.
The small end of the market is being abandoned. Top vendors report falling sales to SMEs, and small organisations are three to four times less likely than large ones to hold cyber insurance (pp. 73, 78). More than four million cyber security posts were unfilled in 2023, and 78% of non-military government sectors worldwide reported staffing shortages (pp. xviii, 79). An unserved buyer with a real problem is the textbook definition of a segment — which is why the SMB and MSP layer in the previous point exists at all, and why it is the most under-appreciated opening for a mid-sized European industry.
Finally, the shakeout is real and should temper any national ambition modelled on the Israeli boom: “nearly 40% of companies within this sector have less than a 6-month runway”, 70% of the $10–30m-revenue growth-stage cohort last raised at 2021–22 peak valuations, and hyper-growth firms trade at 15–20x ARR while slow-growth firms are “reluctantly being valued at 4x-6x ARR” (Deloitte 2024, pp. 4, 10, 13). The industry that produced the cleanest segment taxonomy in the world is describing itself mid-shakeout. One further property matters for any imitator: the correlation between global and Israeli cyber capital raised is above 0.9 (p. 10). Israeli cyber is the Israeli sector least insulated from world conditions and least penalised by local ones — after 7 October it was recovering while the wider ecosystem was not. A segment strategy built on a global category is a hedge against your own country’s politics, and that cuts both ways.
Definitions become institutions through a small number of moves. Israel made four, and they can be described in order.
Tabansky’s 2011 model of cyberspace has three layers — physical, logical, data (2011, pp. 77–78). The INCD’s concept of operations, published six years later, also has three layers, but they are layers of responsibility: Aggregate Cyber Robustness, where organisations repel routine attacks themselves and the state raises the baseline through guidance, regulation and incentives; Systemic Cyber Resilience, where the state detects, removes, recovers and “immunises” the market with a defence cycle designed to outpace the adversary’s; and National Cyber Defense, an all-of-government mix of diplomatic, legal, economic, military and cyber instruments used against attackers, “beyond Israeli borders when needed” (INCD 2017, p. 9; INCD 2021, pp. 8–9). All three rest on an explicit ecosystem layer of people, knowledge and facilities.
The layering of the object became the layering of the duty. Responsibility escalates from the organisation to the state as severity rises, which is exactly the eight-level ladder of hostile activity turned into an operating model. Successive Israeli strategies keep re-describing the same architecture — Raska’s 2014 “national cyber defensive envelope” modelled on Iron Dome’s radar–interceptor–command logic, the 2017 robustness/resilience/defence triad, the 2021 market-resilience/operational-response/national-defence formulation, and the 2025 “joint security, active security, resilience” strategy with a Cyber Dome and a National SOC. The labels move; the logic does not. That stability is what a published definition buys.
The boundary this draws inside the state is worth stating precisely. The Directorate is “not at all involved” in national defence in the third sense; that layer belongs to the IDF and the defence bodies, with INCD support (ETH CSS, reporting Unna). The civilian agency owns hygiene and recovery; the military owns the adversary. The definition, not an org chart, is what makes that separation legible to a bank, a hospital or a water utility.
Israel’s second move was to decide that the state would set the definition and other people’s regulators would enforce it. Resolution 2443 (2015) placed cyber regulation inside the existing sectoral regulators rather than creating a general cyber law, and it regulated the supply side too — professionals, products and services — as well as the users. The INCD regulates named critical-infrastructure entities, not whole sectors. For everything else the instrument is a voluntary methodology.
The Israeli Cyber Defense Methodology is that instrument, and its diffusion mechanics are the most copyable thing in this angle. It spread by five mechanisms, none of which is legislation (NIST and INCD 2020, pp. 1–2):
Proof of concept in government first. The state was its own first adopter, which produced both evidence and a procurement lever.
Sectoral regulators writing it into laws that already exist. The Environment Protection sector wrote the ICDM into the Hazardous Materials Act, which made it binding on every company handling hazardous materials — without a cyber law and without a parliamentary fight.
Shipping a control as a product, not as a paragraph. “Each control contains layers of information including the requirement, explanations and examples, links to best implementation practices, example templates, relevance to confidentiality/integrity/availability, selected standards and regulations compatibility.” Plus a free automation app, with the supply-chain module released first.
Direct outreach and a hotline. CISO and C-level engagement, and CERT-IL’s 119 training.
An English translation, explicitly to help Israeli companies sell abroad.
That last item is the tell, and it deserves to be stated plainly. Israel translated its national security methodology into English as an export instrument. The stated next step in 2019–20 was a national ICDM-based certification scheme harmonised with international standards, plus an organisational maturity model. Israel’s ultimate answer to “what is cyber, in the market” is a certification — which is to say, a tradeable object. The definition becomes a document, the document becomes a control set, the control set becomes a certificate, and the certificate becomes something a domestic vendor can sell in Frankfurt.
Two honest caveats. Light regulation leaves real gaps: essential-but-not-critical organisations are unregulated, and Israel’s comprehensive cyber bill has been stuck since 2018. And the governance risks are concentrated ones — a directorate inside the Prime Minister’s Office, a vague legal basis, and draft powers to seize equipment and monitor traffic without a court order have all drawn sustained criticism from Israeli legal scholars. A European state copying the diffusion mechanics should not copy the legal thinness; it has the NIS2 architecture to hang them on instead.
The third move is the one that makes the second possible. Resolution 3611 excluded the “special bodies” from the new bureau’s remit. Resolution 2444 created a civilian operational authority and deliberately denied it law-enforcement powers. Critical-infrastructure protection was moved out of the Shin Bet. CERT-IL runs a public 119 hotline, open to any citizen, from Beersheba, with a no-fault ethos that INCD officials have compared to a public water system. CyberNet links more than ninety partner CISOs in a trusted sharing network. The Directorate’s influence rests on competence rather than coercion.
The definitional point is that this is a choice about the referent object, not about powers. If cyber is defined as the security of the state’s own systems, the natural home is the security service. If it is defined, as Ben-Israel and Tabansky defined it, as a knowledge-economy phenomenon with a security expression — “a non-rival, partially excludable good” that is a new source of growth (2011, pp. 22–24) — then the natural home is a civilian body whose customers are companies, and whose currency is trust. Everything else follows: no-fault reporting works because the reporter is not talking to a police force; voluntary methodologies spread because the issuer has no power to compel and therefore has to be useful.
Report 2 treats this as Principle 3 and Report 3 as an operating feature. Here it is a definitional consequence, and that framing matters for transfer: a state that has defined cyber as a policing problem cannot fix the resulting distrust with a communications strategy. It has to change the definition.
Now the reframe, with the evidence behind it.
Go back to Tabansky’s three groups of cyber weapons and read the dual-use middle again: network monitoring · vulnerability scanning · penetration testing · encryption · camouflage of content and communications (2011, p. 80). In 2011 that was a doctrinal category, written to explain why export control in this field is hard. Read as a market map in 2026, it is the spine of the industry:
Network monitoring → live asset intelligence across IT, OT and medical: Armis, sold to ServiceNow at $7.75B; Axonius, correlating 1,400-plus sources.
Vulnerability scanning → cloud posture and exposure: Orca’s agentless SideScanning, Wiz’s graph, Zafran’s exploitable-1% triage.
Penetration testing → automated adversarial validation: Pentera running real exploits safely in production, Cymulate’s simulation at SaaS scale, XM Cyber’s attack-graph choke points.
Encryption and data protection → Varonis, Cyera.
Camouflage of content and communications → the enterprise browser and the governed last mile (Island), and its mirror image in lawful forensics (Cellebrite).
Israel’s 2011 list of dual-use cyber tools is, read fifteen years later, a list of product categories worth tens of billions of dollars. That is not a coincidence and it is not hindsight. It is the mechanism this report is named for. Cybertech is an institutional translation layer: a state defines a capability class for doctrinal reasons, trains thousands of people inside that class at national scale, releases them on a five-to-six-year cycle, and the capability class re-emerges as a market category because the people who leave have a shared vocabulary for what the problem is.
The dossiers show the translation happening at the level of individual firms. Claroty was founded inside the Team8 foundry in 2014–15 and turned industrial-process knowledge into distribution through Siemens, Rockwell and Schneider — the commercial form of the same domain-intelligence-plus-engineering fusion that Report 3 and the offensive literature describe behind Stuxnet. Sygnia sells ex-8200 breach responders into corporate crises, converting crisis wins into retainers. XM Cyber sells an offensive-intelligence mindset as a prioritisation engine. KELA sells fifteen years of underground collection to enterprises and police forces. Irregular sells frontier-model evaluation to OpenAI, Anthropic and Google DeepMind and co-writes the security-level scale that will govern model weights. Dream Security sells “sovereign cyber” to heads of state and carries the NSO lineage with it. Each of these is a national-security function with a price list.
And the translation runs in both directions, which is the part most imitators miss. The industry functions as a national sensor network — Report 6 makes that argument in detail — and the state’s own defence consumes commercial products built by people it trained. The INCD’s platforms for real-time risk exposure and threat sharing sit on top of an ecosystem it did not have to build. That loop is what a translation layer looks like when it works: the doctrine names the class, the class trains the people, the people build the products, the products defend the state, and the state’s next problem names the next class.
It is also where the model’s worst failure lives, and the failure is definitional rather than moral. Because cyber is defined by means, an intrusion tool and an assurance tool are the same object under different licences. The dual-use middle category is not a grey zone at the edge of the industry; it is the industry’s centre of gravity. That is why Israel accounts for 43.9% of the entities in the Atlantic Council’s global spyware dataset, and why of the 74 governments known to have bought commercial spyware or forensics tools, 56 bought from firms based in or connected to Israel (Feldstein and Kot, Carnegie 2023). A state that adopts a means-based definition of cyber inherits the export-control problem on day one, whether or not it has noticed. Report 2 argues that the guardrails must be built with the capability rather than retrofitted. This report adds the reason: the guardrail is not a policy attached to the industry, it is the other side of the definition that created it.
The claim in this section is stronger than “words matter”. It is that the definition of cyber a state adopts determines, mechanically and in a predictable order, four things it will later experience as facts about the world.
Craigen and his co-authors put it as a diagnosis rather than an aphorism: the absence of a shared definition “impedes technological and scientific advances by reinforcing the predominantly technical view of cybersecurity while separating disciplines that should be acting in concert” (2014, p. 13). Institutions inherit the scope of the sentence that created them.
Compare two founding documents. NIST CSF 2.0 defines cybersecurity as six outcomes and contains no adversary; an agency founded on that sentence will be excellent at maturity assessment and will have no view on Iran. Israel’s Resolution 3611 gave its new bureau nineteen goals, and the list is worth reading as a definition in disguise: an annual national threat of reference · promoting R&D in cyber and supercomputing · encouraging the cyber industry · a national emergency concept · national and international exercises · a combined intelligence picture and national situation status · public warnings · national education plans · international cooperation · legislation and regulation. That is not a CERT’s mandate. It is the mandate of a body that has defined cyber as a knowledge-economy phenomenon with a security expression, and it produced, over fifteen years, both a national defence architecture and an export industry — from the same programme, because the programme’s definition covered both.
The corollary for a mid-sized state is uncomfortable but actionable. If your national cyber strategy describes cyber security as the protection of information systems, then your agency’s education, industry, research and exercise functions are all extras that a future budget round can cut without contradicting the strategy. Anything not in the definition is discretionary, and discretionary functions do not survive austerity.
Tabansky’s most honest sentence is about money: “the relative importance of a computer system, and as a result, the amount of public investment required to defend it, are subject to a public discussion and a political fight” (2011, p. 84). There is no technical method that ranks what deserves protection. A definition is the instrument that decides which fights are winnable.
Two mechanisms follow. The first is the denominator. If cyber is defined as part of IT, spending is measured against the IT budget and competes with servers; if it is defined as business risk, it is measured against revenue and competes with insurance. Deloitte’s finding that financial institutions now measure cyber spend against revenue — 0.72% in 2021, 0.54% in 2023 — and that this is “a direct outcome of the broad impact of cyber on the entire business activities” (2024, p. 11) is a definitional change appearing as an accounting change. The same shift at national level is the difference between a cyber agency funded from the interior ministry’s IT line and one funded as a security service.
The second is state purchasing power. Per-capita government cyber budgets exceed US$30 in Canada and the United States and fall below US$1 in highly targeted developing countries like India and Mexico (Vergara Cobos 2024, p. 74), and governments are roughly 36% of global demand. Where a state defines a problem and then buys against it, a segment appears — Germany’s BSI standards are cited as setting de facto European market terms (p. 79). Procurement is the most under-used definitional instrument a mid-sized state possesses, because it converts a sentence into a revenue line for firms that do not yet exist.
Three respectable bodies rank Israel three different ways, and the spread is not noise. The ITU’s Global Cybersecurity Index 2024 places Israel in Tier 2 at about 93.6 out of 100 — below Estonia, Finland, Singapore, the UK and the US, and in the same band as the Czech Republic. Harvard’s Belfer National Cyber Power Index places it outside the top ten, around nineteenth of thirty, and says explicitly that Israel is under-ranked because it keeps its capabilities opaque. The IISS net assessment places it at the top of the second tier alongside the UK, behind only the United States. On market measures it is second in the world.
The explanation is definitional, not methodological. Compliance indices score whether formal institutions and paperwork exist. Power indices score publicly demonstrated capability. Market measures score revenue. The ITU index says of itself that it does not measure the quality of actions; ENISA concedes that its own national framework measures maturity rather than effectiveness. A state that adopts the standards definition of cyber will find itself optimising against an index that rewards the existence of a document — and Czechia, which passed one of the world’s first comprehensive cyber security acts in 2014 and created NÚKIB in 2017, scores well on exactly that basis while its own 2026 strategy names the real gaps: too few people and too little money in both the public and private sectors, a state that is still reactive, and a “shortage of secure and competitive domestic technological alternatives, which deepens dependence on the technologies of foreign rivals”.
The instruction is the one Report 2 gave and this report can now justify from first principles: measure the thing your definition says cyber is for. If cyber is national capability, the indicators are capability indicators — operator-course graduates placed, paid pilots with young vendors, disclosures shipped with fixes, median time from disclosure to mitigation in regulated entities, and the Oxford model’s own top stage for a national cyber marketplace, “Domestic cybersecurity products are exported to other nations and are considered superior products” (Oxford GCSCC 2021).
This is the point the whole report has been walking towards, and it is short.
Every definition is a boundary, and a boundary has an outside. The means-based doctrinal definition puts psychological warfare and media management outside cyber — correctly. The standards definition puts the adversary outside — deliberately. The market definition puts everything unsaleable outside — structurally. The academic definition puts operational specificity outside — by design.
A state can survive any one of these exclusions. What it cannot survive is an exclusion nobody has been made responsible for, and that is the failure mode this series has documented twice. Israel’s cognitive gap is not a consequence of incompetence; it is the logical output of a precise definition that was never paired with a second mandate. The 2025 strategy names a resilient public mindspace as an objective and names no owner. The security service lacks the legal powers. Cooperation with civil society is “in its infancy”. Meanwhile the adversary runs both limbs under one command and does not use the word “cyber” at all.
So the operational test for any national definition is a single question, asked once, in the drafting room: what does this sentence put outside, and who owns that? If the answer to the second half is silence, the definition has just created a gap that will take a decade and a crisis to close.
Four instructions and eight moves, for a mid-sized European state and for the founders and investors inside it. The Czech Republic is the home example; the logic generalises to any country with real talent, a competent agency and no category of its own.
The single cheapest transferable feature in this entire library is the order in which Israel did things: definitions in public first, institutions second. Nothing about it requires an army, a threat or a start-up scene. It requires the people who will run the programme to write down, in the open and under their own names, what they think the object is.
A European state writing that document now has an advantage Israel did not: it can write all four definitions in one act, and say which is which. The academic definition to fix scope and referent objects. The standards definition, adopted from NIST or its EU mappings, to govern organisations. The doctrinal definition, with layers, a severity ladder and the risks-to versus risks-through split, to allocate national responsibility. And an explicit statement that the market’s taxonomy is not the state’s.
A national industry strategy that takes Deloitte’s sixteen categories or a vendor quadrant as its target list is optimising against someone else’s snapshot of someone else’s market. The three conditions from Point 9 are the better filter, and they can be applied in a workshop: is there an unclaimed control point; can deployment friction be removed to produce evidence in an afternoon; and can the thing be named before the analysts name it?
Applied to Czechia, the evidence in this library supports four candidates rather than sixteen. Operational technology and cyber-physical security, because the industrial base is real, because NÚKIB recorded Russian-speaking hacktivists attacking weakly secured water-utility OT in 2024, and because this is the one segment where hardware-enforced approaches still win (Waterfall’s gateways exist because NERC CIP, NRC and ANSSI rules reward them — regulation creates the category). Resolver, routing and DDoS resilience, because CZ.NIC’s Knot was one of the four resolvers patched in the global NXNSAttack remediation and Czech code is therefore already inside the internet’s disclosure loop — a credential most countries cannot buy. Identity for machines and agents, because it is eighteen months old, because Astrix and Zenity proved the naming play works, and because no incumbent has a defensible position yet. And the SMB and MSP layer, because the World Bank documents vendors abandoning that buyer and Deloitte shows the Israeli market ignoring it — an unserved buyer with a real problem is the definition of a segment, and European SMEs are a larger unserved population than American ones.
Nasdaq’s committee meets quarterly, assigns each company to exactly one class on revenue grounds, and rules that companies “may not apply, and may not be nominated for inclusion”. Deloitte’s sixteen categories are built from a specific 300-company sample with listed and acquired firms excluded. ENISA’s value stack is a statutory instrument produced under Article 8(7) of the Cybersecurity Act. Each is a considered, defensible, useful artefact — and each has an owner, a method, an incentive and a revision cycle. None is a fact about the world.
For an official, the discipline is to ask three questions of any category before budgeting against it: who adjudicates membership, on what evidence, and how often is it redrawn. For a founder, the discipline is the mirror image: a category is a governed object, so entering one is a standards activity — publish, disclose, take the OWASP seat, co-author the scale — and creating one is cheaper than winning one.
Publish a one-page national definition of cyber, signed by the people who will run the programme, before the next institutional reform. Four parts: the layers of cyberspace; the risks-to versus risks-through split; the dual-use middle category of tools named as such; and an explicit statement of what is outside the definition and who owns it. Israel’s cost for this was two journal essays.
Adopt the international organisational taxonomy, and say out loud why. NIST CSF 2.0 or its EU mappings, for Unna’s reason — “an international cyber defense language which supports collaboration against global cyber threats” — which beats any sovereignty argument, and was good enough for a country with far more reason than Czechia to assert its own.
Ship controls as products, and diffuse through the regulators you already have. Copy the ICDM’s mechanics, not its content: government as first adopter; sectoral regulators writing the methodology into existing sectoral law, as the Environment Protection regulator did with the Hazardous Materials Act; each control shipped with explanations, templates, mappings and a free automation tool; the supply-chain module first; and an English version so domestic vendors can sell the compliance abroad.
Make market analysis a statutory duty of the national cyber agency, and run it annually. ECSMAF is explicitly designed to be run “with limited customisation, by organisations other than ENISA”. Running it once will answer a question NÚKIB cannot currently answer: whether Czechia has categories or only companies. Keep academia, training and awareness inside the value stack when you count, as ENISA does — a country that counts only vendors will conclude it has no industry at the exact moment it is building one.
Pick three or four segments and buy against them. Procurement is the definitional instrument with the shortest lead time. Paid pilots with young domestic vendors in OT, resolver and routing resilience, machine and agent identity, and the MSP layer — with published evaluation criteria, because the criteria are themselves a standards contribution and will be read by buyers abroad.
Name the owner of the cognitive domain in the same act that defines cyber. Not inside the cyber agency, which should not have speech powers, and not three years later in another ministry. Report 6 sets out the models: a small unit under the head of government on the VIGINUM pattern with a mandate to investigate and publish and no power to order removals, sharing one threat picture and one quarterly assessment with the technical agency.
Write the export-control regime at the same time as the industrial strategy, because they are two sides of one definition. A means-based definition makes the dual-use middle the industry’s centre of gravity, not its edge. Israel’s cost for discovering this late is 43.9% of the entities in the Atlantic Council’s spyware dataset and a reputational liability its own firms now manage around. Published criteria, published refusals, and a licensing decision that does not move with the week’s diplomacy.
Measure what the definition says cyber is for, and publish the scorecard. Capability indicators over compliance indicators; the ITU tier as a footnote rather than a target; and the Oxford marketplace stage — exported domestic products considered superior — as the honest long-run goal.
The question this report was asked to answer was “what actually is cyber”. The answer is that the question has four correct answers and a state has to hold all of them at once.
Cyber is an interdisciplinary object whose referent is anything with meaning or value, and whose study is a plea for a cause. It is a taxonomy of six governed outcomes that can be audited, compared across borders and used to run an economy’s hygiene. It is a subset of information warfare defined by its means, sitting on a layered domain that did not exist before people built it, contested mostly below the threshold of violence in what is probably an intelligence contest rather than a war. And it is an administered market category, redrawn quarterly by committees, behaving like a market for lemons because its buyers cannot price what they are buying until after they have needed it.
Israel is the clearest case not because it got any one of these right but because it wrote all four down, in that order, before the institutions existed, and then kept them translatable — which is why one small country produces both a signals-intelligence unit and a $32B cloud-security company, and why its 2011 doctrinal list of dual-use tools reads today as a product catalogue. Cybertech is the translation layer: the machinery that converts an intelligence problem into a product category, and the state’s next problem into the next category. That machinery is what a mid-sized European state should be trying to build. Not the threat environment, which nobody should want, and not the fifty companies, which are an output.
The last thing to carry away is the warning, because it is the cheapest to act on and the most expensive to ignore. Every definition has an outside. Israel drew its boundary precisely and left the cognitive domain beyond it with no owner, and a Kremlin directorate has been operating in that space in Hebrew since April 2023 against the best technical cyber defence in the world outside the United States. A definition is not a description of a field. It is an allocation of responsibility, and the part you leave out is allocated to nobody. Write the sentence, and then — in the same document, on the same day — say who owns everything the sentence excludes.